Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Ist Trojaner Trojan.Agent jemals aktiv geworden? (https://www.trojaner-board.de/91205-trojaner-trojan-agent-jemals-aktiv-geworden.html)

Herzmann 27.09.2010 14:48

Ist Trojaner Trojan.Agent jemals aktiv geworden?
 
Hallo,

erstmals im Board habe ich nun eine Frage:

Wie kann ich feststellen, ob der Trojaner Trojan.Agent jemals aktiv geworden ist, oder die verdächtige Datei nur dumm rum gelegen hat?
Die von Malwarebytes gefundene Datei befindet sich nämlich auch schon auf einem Backup, welches ich vor ca. 1 Jahr mal angefertigt habe, und habe bisher keine Ausspähungen bemerken können.

Hab schon einiges rumgegoogelt, konnte mir aber noch keine wirkliche Meinung bilden, ob nun mit dem Löschen der Datei schon alles getan ist.
Mir ist auch nicht so ganz klar, welche Art von Tätigkeit denn von dem Trojan.Agent so zu erwarten ist. Wenn ich richtig verstanden habe, soll das ja eine Java-Malware sein, die ohne laufendes Java ja dann harmlos sein müßte.
Die gleiche Frage auch wegen des Worm.Autorun.B.
Der war übrigens weg, nachdem ich Avast installiert hatte, und im Sicherheitscenter die AntiVirus-Überwachung wieder eingestellt hatte.
Da hatte meine bis dato installierte und upgedatete Version von NortonAV prof. 2004 wohl reingefunkt.

Drauf gekommen bin ich, weil ein bestimmter Browser-Plugin-Test Zicken macht.
Im Firefox-Forum gab es widersprüchliche Meinungen, ob das beobachtete Phänomen (2 plugin-container.exe Instanzen) auf aktive Malware hindeutet.

Malwarebytes log:
Code:

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Datenbank Version: 4629

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 6.0.2900.5512

    16.09.2010 18:58:14
    mbam-log-2010-09-16 (18-58-14).txt

    Art des Suchlaufs: Quick-Scan
    Durchsuchte Objekte: 159142
    Laufzeit: 18 Minute(n), 17 Sekunde(n)

    Infizierte Speicherprozesse: 0
    Infizierte Speichermodule: 0
    Infizierte Registrierungsschlüssel: 0
    Infizierte Registrierungswerte: 0
    Infizierte Dateiobjekte der Registrierung: 0
    Infizierte Verzeichnisse: 0
    Infizierte Dateien: 3

    Infizierte Speicherprozesse:
    (Keine bösartigen Objekte gefunden)

    Infizierte Speichermodule:
    (Keine bösartigen Objekte gefunden)

    Infizierte Registrierungsschlüssel:
    (Keine bösartigen Objekte gefunden)

    Infizierte Registrierungswerte:
    (Keine bösartigen Objekte gefunden)

    Infizierte Dateiobjekte der Registrierung:
    (Keine bösartigen Objekte gefunden)

    Infizierte Verzeichnisse:
    (Keine bösartigen Objekte gefunden)

    Infizierte Dateien:
    C:\RECYCLER\S-1-5-21-999901472-3601035388-3065584919-1005\Dc12892\HELP.exe (Worm.Autorun.B) -> No action taken.
    C:\Dokumente und Einstellungen\***\Cookies\MM2048.DAT (Trojan.Agent) -> No action taken.
    C:\Dokumente und Einstellungen\***\Cookies\MM256.DAT (Trojan.Agent) -> No action taken.


cosinus 28.09.2010 13:38

Hallo und :hallo:

Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Danach OTL:

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

Herzmann 28.09.2010 16:00

Code:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4666

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

22.09.2010 01:46:39
mbam-log-2010-09-22 (01-46-39).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|F:\|G:\|H:\|)
Durchsuchte Objekte: 724995
Laufzeit: 1 Stunde(n), 42 Minute(n), 44 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

OTL-Log (unter eingeschränktem Benutzer ausgeführt, hoffentlich OK so)
Code:

OTL logfile created on: 28.09.2010 16:39:54 - Run 1
OTL by OldTimer - Version 3.2.14.1    Folder = E:\Software\Ab 17.04.2009\Download\Sicherheit
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 44,00% Memory free
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 62,00% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1536 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 59,53 Gb Total Space | 5,43 Gb Free Space | 9,12% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 46,18 Gb Total Space | 0,08 Gb Free Space | 0,18% Space Free | Partition Type: FAT32
Drive F: | 4,00 Gb Total Space | 0,45 Gb Free Space | 11,32% Space Free | Partition Type: FAT32
Drive G: | 4,01 Gb Total Space | 0,46 Gb Free Space | 11,49% Space Free | Partition Type: FAT32
Drive H: | 25,27 Gb Total Space | 4,47 Gb Free Space | 17,68% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
 
Computer Name: MOBI
Current User Name: ***
NOT logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - E:\Software\Ab 17.04.2009\Download\Sicherheit\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
PRC - C:\Programme\Mozilla\Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Programme\Mozilla\Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Programme\TortoiseHg\TortoiseHgOverlayServer.exe ()
PRC - C:\Programme\TortoiseSVN\bin\TSVNCache.exe (hxxp://tortoisesvn.net)
PRC - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\TpShocks.exe (Lenovo.)
PRC - C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
PRC - C:\Programme\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Programme\Lenovo\Message Center Plus\MCPLaunch.exe ()
PRC - C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe (AVM Berlin)
PRC - C:\Programme\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
PRC - C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Programme\FRITZ!DSL\StCenter.exe (AVM Berlin)
PRC - C:\Programme\FRITZ!DSL\FwebProt.exe (AVM Berlin)
PRC - C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Programme\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Programme\Logitech\QuickCam10\QuickCam10.exe ()
PRC - C:\Programme\Gemeinsame Dateien\logishrd\LComMgr\Communications_Helper.exe (Logitech Inc.)
PRC - C:\Programme\Gemeinsame Dateien\logishrd\LQCVFX\COCIManager.exe (Logitech Inc.)
PRC - C:\Programme\Gemeinsame Dateien\logishrd\LComMgr\LVComSX.exe (Logitech Inc.)
PRC - C:\WINDOWS\tsnp2std.exe (SONIX)
PRC - C:\WINDOWS\vsnp2std.exe (Sonix)
PRC - C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.exe (Lenovo Group Limited)
PRC - C:\Programme\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\system32\dla\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\IBMTOOLS\utils\ibmprc.exe (IBM Corp.)
PRC - C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe (Teleca Software Solutions AB)
PRC - C:\Programme\Analog Devices\SoundMAX\SMax4.exe (Analog Devices, Inc.)
PRC - C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
PRC - C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Programme\Sony Ericsson\Mobile\Connectivity Pack\ConnMngMntBox.exe (Symbian Ltd.)
PRC - c:\Programme\Intuwave Ltd\Shared\mRouterRunTime\mRouterRuntime.exe (Intuwave Ltd.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
PRC - C:\Programme\Palm\Handspring\HOTSYNC.EXE (Palm, Inc.)
PRC - C:\WINDOWS\system32\TpScrLk.exe ()
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\2\fpdisp4.exe (FinePrint Software, LLC)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()
PRC - C:\WINDOWS\tppaldr.exe (In-System Design, Inc.)
PRC - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
PRC - C:\Programme\EPSON\SMART PANEL\SmaPanel.exe (NewSoft)
 
 
========== Modules (SafeList) ==========
 
MOD - E:\Software\Ab 17.04.2009\Download\Sicherheit\OTL.exe (OldTimer Tools)
MOD - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll ()
MOD - C:\WINDOWS\system32\msvcr71.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)
MOD - C:\Programme\Gemeinsame Dateien\logishrd\LVMVFM\LVPrcInj.dll (Logitech Inc.)
MOD - C:\WINDOWS\system32\msvcp71.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
 
========== Driver Services (SafeList) ==========
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.selectedEngine: "Google Deutschland - auf Deutsch"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.taz.de/|hxxp://www.oya-online.de/"
FF - prefs.js..extensions.enabledItems: en-GB@dictionaries.addons.mozilla.org:1.19
FF - prefs.js..extensions.enabledItems: {e1170235-2845-420c-acc3-42261a29dd46}:4.0.1
FF - prefs.js..extensions.enabledItems: pt-PT@dictionaries.addons.mozilla.org:9.10.13.6
FF - prefs.js..extensions.enabledItems: es-es@dictionaries.addons.mozilla.org:1.3.0
FF - prefs.js..extensions.enabledItems: {a0faa0a4-f1a7-4098-9a74-21efc3a92372}:4.0.0
FF - prefs.js..extensions.enabledItems: it-IT@dictionaries.addons.mozilla.org:3.1
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.1
FF - prefs.js..extensions.enabledItems: fb_add_on@avm.de:1.5.5
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.9
FF - prefs.js..extensions.enabledItems: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.85
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.5.4
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.1
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {28FAD68E-4001-48d5-B994-68069F7CFB1D}:0.4.7
FF - prefs.js..extensions.enabledItems: pagecompare_abk0680@yahoo.com:1.5
FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2.1
FF - prefs.js..extensions.enabledItems: savecomplete@perlprogrammer.com:1.0.1
FF - prefs.js..extensions.enabledItems: {53A03D43-5363-4669-8190-99061B2DEBA5}:1.3.7
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {29c4afe1-db19-4298-8785-fcc94d1d6c1d}:0.6.2009110501
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: tsvnmenu@pumacode.org:0.2.5
FF - prefs.js..extensions.enabledItems: {139a120b-c2ea-41d2-bf70-542d9f063dfd}:2.03.3
FF - prefs.js..extensions.enabledItems: {eecba28f-b68b-4b3a-b501-6ce12e6b8696}:0.7.2
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5
FF - prefs.js..extensions.enabledItems: ietab@ip.cn:1.94.20100904
FF - prefs.js..extensions.enabledItems: metatags@porton.ex-code.com:2.3.5.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {398e77b8-2304-11dc-8314-0800200c9a66}:0.3.13
FF - prefs.js..extensions.enabledItems: de_DE@dicts.j3e.de:20100720
FF - prefs.js..extensions.enabledItems: fr-moderne@dictionaries.addons.mozilla.org:3.8
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.09.07 00:35:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Programme\Mozilla\Firefox\components [2010.09.17 12:18:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Programme\Mozilla\Firefox\plugins [2010.09.17 12:24:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2010.09.17 12:18:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
 
[2010.01.19 19:43:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Extensions
[2010.01.19 19:43:44 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.09.27 19:47:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions
[2010.03.28 01:15:31 | 000,000,000 | ---D | M] (Screengrab) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010.09.16 14:28:25 | 000,000,000 | ---D | M] (Forecastfox Weather) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010.08.18 22:54:02 | 000,000,000 | ---D | M] (FireShot) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2009.11.04 11:06:03 | 000,000,000 | ---D | M] (URL Link) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{139a120b-c2ea-41d2-bf70-542d9f063dfd}
[2007.03.31 01:03:40 | 000,000,000 | ---D | M] (FlashGot) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(2)
[2008.03.13 21:48:21 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}(2)
[2010.04.30 19:39:30 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.01.29 15:55:11 | 000,000,000 | ---D | M] (MouseZoom) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{28FAD68E-4001-48d5-B994-68069F7CFB1D}
[2009.11.12 19:20:16 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010.09.08 12:27:24 | 000,000,000 | ---D | M] (Minimap Addon) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{398e77b8-2304-11dc-8314-0800200c9a66}
[2010.03.28 01:15:33 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2008.10.10 23:42:45 | 000,000,000 | ---D | M] (NoScript) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(2)
[2010.08.12 23:42:20 | 000,000,000 | ---D | M] (DictionarySearch) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}
[2008.03.02 22:09:45 | 000,000,000 | ---D | M] (DictionarySearch) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}(2)
[2010.06.07 15:22:21 | 000,000,000 | ---D | M] (FireFTP) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2010.09.01 13:54:51 | 000,000,000 | ---D | M] (Password Exporter) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2008.03.13 21:48:20 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
[2010.03.12 18:02:26 | 000,000,000 | ---D | M] (Web Developer) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010.09.01 13:54:50 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010.06.23 19:06:15 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2008.10.10 23:42:43 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{dc572301-7619-498c-a57d-39143191b318}(2)
[2010.06.07 15:22:23 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010.01.23 20:58:38 | 000,000,000 | ---D | M] (Clipmarks) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
[2010.04.09 17:27:54 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010.08.18 22:54:05 | 000,000,000 | ---D | M] (ViewSourceWith) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{eecba28f-b68b-4b3a-b501-6ce12e6b8696}
[2010.09.08 17:56:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\de_DE@dicts.j3e.de
[2010.02.19 13:03:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2007.10.23 10:03:51 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\en-GB@dictionaries.addons.mozilla.org
[2008.03.13 21:48:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\en-US@dictionaries.addons.mozilla(2).org
[2009.12.11 23:12:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\es-es@dictionaries.addons.mozilla.org
[2010.01.14 21:47:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\fb_add_on@avm.de
[2010.05.07 13:38:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\firebug@software.joehewitt.com
[2010.02.10 22:21:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\fr-FR@dictionaries.addons.mozilla.org
[2010.09.08 17:56:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\fr-moderne@dictionaries.addons.mozilla.org
[2010.09.16 14:28:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\ietab@ip.cn
[2007.10.23 10:03:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\it-IT@dictionaries.addons.mozilla.org
[2010.09.06 22:42:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\metatags@porton.ex-code.com
[2010.01.29 15:55:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\pagecompare_abk0680@yahoo.com
[2010.09.24 19:14:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\pt-PT@dictionaries.addons.mozilla.org
[2009.04.11 23:26:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\savecomplete@perlprogrammer.com
[2006.12.11 16:37:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\temp
[2010.02.10 22:21:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\tsvnmenu@pumacode.org
[2010.09.24 19:25:08 | 000,001,089 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\astalavista.xml
[2010.03.05 17:18:24 | 000,002,058 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\astalavistams.xml
[2006.11.17 20:43:24 | 000,002,088 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\flickr-tags.xml
[2009.07.02 10:25:13 | 000,001,157 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\freedict.xml
[2008.05.27 10:18:53 | 000,002,161 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\google-deutschland.xml
[2006.11.17 20:45:13 | 000,001,679 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\imdb.xml
[2010.09.24 19:25:08 | 000,002,008 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\leo-de-en.xml
[2010.09.24 19:25:08 | 000,002,016 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\leo-de-es.xml
[2010.09.24 19:25:08 | 000,002,020 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\leo-de-fr.xml
[2008.06.03 11:49:07 | 000,001,082 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\lonely-planet-online.xml
[2010.09.24 19:25:08 | 000,001,481 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\map24de.xml
[2008.06.03 11:49:06 | 000,001,317 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\wikipedia-en.xml
[2010.08.15 16:04:13 | 000,004,140 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\youtube.xml
 
O1 HOSTS File: ([2004.08.04 05:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ACTray] C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
O4 - HKLM..\Run: [ACWLIcon] C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [avast5] C:\Programme\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BLOG] C:\Programme\ThinkPad\Utilities\BATLOGEX.DLL ()
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\dla\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [EZEJMNAP] C:\Programme\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
O4 - HKLM..\Run: [FinePrint Dispatcher v4] C:\WINDOWS\system32\spool\drivers\w32x86\2\fpdisp4.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [ibmmessages] C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKLM..\Run: [IBMPRC] C:\IBMTOOLS\utils\ibmprc.exe (IBM Corp.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [KernelFaultCheck]  File not found
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Programme\Logitech\QuickCam10\QuickCam10.exe ()
O4 - HKLM..\Run: [Message Center Plus] C:\Programme\LENOVO\Message Center Plus\MCPLaunch.exe ()
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Programme\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [Microsoft Works Update Detection] C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [PWRMGRTR] C:\Programme\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [RemoteControl] C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SmcService] C:\Programme\Sygate\SPF\Smc.exe (Sygate Technologies, Inc.)
O4 - HKLM..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe (Sonix)
O4 - HKLM..\Run: [SoundMAX] C:\Programme\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [TkBellExe] C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TortoiseHgOverlayIconServer] C:\Programme\TortoiseHg\TortoiseHgOverlayServer.exe ()
O4 - HKLM..\Run: [TP4EX] C:\WINDOWS\System32\TP4EX.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe ()
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Programme\ThinkPad\Utilities\TpKmapAp.exe (IBM Corp.)
O4 - HKLM..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe (In-System Design, Inc.)
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe (SONIX)
O4 - HKLM..\Run: [TVT Scheduler Proxy] C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
O4 - HKCU..\Run: [AVMUSBFernanschluss] C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\AVMAutoStart.exe (AVM Berlin)
O4 - HKCU..\Run: [IBM RecordNow!] C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKCU..\Run: [ibmmessages] C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKCU..\Run: [Microsoft Works Update Detection] C:\Programme\Microsoft Works\WkDetect.exe File not found
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\BTTray.lnk = C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\EPSON SMART PANEL.lnk = C:\Programme\EPSON\SMART PANEL\SmaPanel.exe (NewSoft)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Erinnerungen in Microsoft Works-Kalender.lnk = C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Fax-Controller.lnk = C:\Programme\EPSON\SMART PANEL\faxicore.exe (NewSoft Technology Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Telefonverbindungsmonitor.lnk = C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe (Teleca Software Solutions AB)
O4 - Startup: C:\Dokumente und Einstellungen\***\Startmenü\Programme\Autostart\FRITZ!DSL Protect.lnk = C:\Programme\FRITZ!DSL\FwebProt.exe (AVM Berlin)
O4 - Startup: C:\Dokumente und Einstellungen\***\Startmenü\Programme\Autostart\FRITZ!DSL Startcenter.lnk = C:\Programme\FRITZ!DSL\StCenter.exe (AVM Berlin)
O4 - Startup: C:\Dokumente und Einstellungen\***\Startmenü\Programme\Autostart\HotSync Manager.lnk = C:\Programme\Palm\Handspring\HOTSYNC.EXE (Palm, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Senden an Bluetooth - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\FRITZ!DSL\\sarah.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} hxxp://www.alternatiff.com/install-ie/alttiff.cab (AlternaTIFF ActiveX)
O16 - DPF: {15A7CF10-CB3E-4265-8779-9FD22619E8ED} hxxp://192.168.1.205/XPanel.cab (XPanel Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} hxxp://www-307.ibm.com/pc/support/acpir.cab (IASRunner Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1164927521531 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} hxxp://java.sun.com/products/plugin/1.4.2/jinstall-142-win.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {F74959B0-1779-472E-BE6E-3023E1DBEC73} hxxp://192.168.1.205/XInit.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ACNotify: DllName - ACNotify.dll - C:\Programme\ThinkPad\ConnectUtilities\ACNotify.dll (Lenovo )
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\tpfnf2: DllName - C:\Programme\Lenovo\HOTKEY\notifyf2.dll - C:\Programme\Lenovo\HOTKEY\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - C:\Programme\Lenovo\HOTKEY\tphklock.dll - C:\Programme\Lenovo\HOTKEY\tphklock.dll ()
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.27 10:02:05 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\autoexec.rod -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\AUTOEXEC.ICR -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\autoexec.rod -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\AUTOEXEC.ICR -- [ FAT32 ]
O33 - MountPoints2\{12570190-b56a-11dc-ab3d-000e9bda3b35}\Shell - "" = AutoRun
O33 - MountPoints2\{12570190-b56a-11dc-ab3d-000e9bda3b35}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{12570190-b56a-11dc-ab3d-000e9bda3b35}\Shell\AutoRun\command - "" = F:\pushinst.exe -- File not found
O33 - MountPoints2\{91a2d536-d712-11db-aaea-000e9bda3b35}\Shell - "" = AutoRun
O33 - MountPoints2\{91a2d536-d712-11db-aaea-000e9bda3b35}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{91a2d536-d712-11db-aaea-000e9bda3b35}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{91a2d537-d712-11db-aaea-000e9bda3b35}\Shell\AutoRun\command - "" = G:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe -- File not found
O33 - MountPoints2\{f4f57244-35da-11de-9605-00505b002aa8}\Shell - "" = AutoRun
O33 - MountPoints2\{f4f57244-35da-11de-9605-00505b002aa8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f4f57244-35da-11de-9605-00505b002aa8}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O34 - HKLM BootExecute: (pgdfgsvc c 1) - C:\WINDOWS\System32\pgdfgsvc.exe (Sysinternals - www.sysinternals.com)
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.09.16 18:36:50 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Malwarebytes
[2010.09.16 18:36:33 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.09.16 18:36:31 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.09.16 18:36:31 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2010.09.16 18:36:30 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2010.09.09 01:36:21 | 000,165,584 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010.09.09 01:36:21 | 000,017,744 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010.09.09 01:36:20 | 000,023,376 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010.09.09 01:36:19 | 000,046,672 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010.09.09 01:36:18 | 000,100,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010.09.09 01:36:18 | 000,094,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010.09.09 01:36:17 | 000,028,880 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010.09.09 01:36:05 | 000,167,592 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010.09.09 01:36:05 | 000,038,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010.09.09 01:35:57 | 000,000,000 | ---D | C] -- C:\Programme\Alwil Software
[2010.09.09 01:35:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Alwil Software
[2010.09.08 11:17:46 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2010.09.08 11:17:46 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2010.09.07 00:34:37 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\xing shared
[2010.09.07 00:01:40 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.09.07 00:01:40 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.09.07 00:01:40 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.08.30 20:28:30 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\vlc
[2007.12.13 22:41:16 | 000,151,552 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnp2std.dll
[2007.12.13 22:41:14 | 000,077,824 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2std.dll
[2006.11.14 01:13:40 | 000,021,866 | ---- | C] (In-System Design, Inc.) -- C:\Programme\Gemeinsame Dateien\tppupd2k.dll
[2004.11.24 21:25:52 | 000,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010.09.28 15:52:54 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.09.28 15:50:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.09.28 15:50:41 | 2145,832,960 | -HS- | M] () -- C:\hiberfil.sys
[2010.09.28 14:21:51 | 015,990,784 | ---- | M] () -- C:\Dokumente und Einstellungen\***\ntuser.dat
[2010.09.28 14:21:46 | 000,000,300 | -HS- | M] () -- C:\Dokumente und Einstellungen\***\ntuser.ini
[2010.09.28 14:21:31 | 006,291,456 | -H-- | M] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\IconCache.db
[2010.09.28 14:20:05 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-999901472-3601035388-3065584919-1005.job
[2010.09.28 14:19:54 | 000,001,078 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.09.28 13:59:04 | 000,000,274 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-999901472-3601035388-3065584919-1005.job
[2010.09.28 13:47:00 | 000,001,082 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.09.27 18:44:41 | 000,000,296 | ---- | M] () -- C:\WINDOWS\tasks\PMTask.job
[2010.09.27 18:44:09 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.09.20 19:45:17 | 000,001,797 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Logitech QuickCam.lnk
[2010.09.16 20:09:02 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.09.15 23:05:26 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.09.09 01:36:22 | 000,001,672 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\avast! Free Antivirus.lnk
[2010.09.09 01:36:18 | 000,003,002 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010.09.08 11:17:46 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2010.09.08 11:17:46 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2010.09.07 17:12:17 | 000,038,848 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010.09.07 17:11:54 | 000,167,592 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010.09.07 16:52:25 | 000,046,672 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010.09.07 16:52:03 | 000,165,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010.09.07 16:47:46 | 000,023,376 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010.09.07 16:47:19 | 000,100,176 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010.09.07 16:47:16 | 000,094,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010.09.07 16:47:07 | 000,017,744 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010.09.07 16:46:51 | 000,028,880 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010.09.07 00:35:47 | 000,000,821 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\RealPlayer SP.lnk
[2010.09.07 00:35:17 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2010.09.07 00:34:54 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2010.09.07 00:34:54 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2010.09.07 00:33:10 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2010.09.07 00:10:45 | 000,001,717 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2010.09.02 00:07:28 | 000,168,088 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
[2010.09.02 00:04:08 | 000,505,008 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.09.01 22:37:21 | 000,000,699 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.09.09 01:36:22 | 000,001,672 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\avast! Free Antivirus.lnk
[2010.09.07 00:35:47 | 000,000,821 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\RealPlayer SP.lnk
[2010.09.01 22:37:21 | 000,000,699 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
[2010.04.13 21:40:03 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\EuEpmGdi.dll
[2010.04.13 21:40:03 | 000,013,192 | ---- | C] () -- C:\WINDOWS\System32\epmntdrv.sys
[2010.04.13 21:40:03 | 000,008,456 | ---- | C] () -- C:\WINDOWS\System32\EuGdiDrv.sys
[2010.04.12 01:17:54 | 000,000,600 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\winscp.rnd
[2009.10.21 03:54:22 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2009.10.17 01:55:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2009.10.06 09:11:50 | 000,091,648 | ---- | C] () -- C:\WINDOWS\System32\lua5.1a.dll
[2009.04.11 21:25:54 | 000,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008.12.19 18:51:56 | 000,000,734 | ---- | C] () -- C:\WINDOWS\wiso.ini
[2008.11.19 17:39:26 | 000,000,011 | ---- | C] () -- C:\WINDOWS\cmvpt32.ini
[2008.11.19 17:38:46 | 000,884,736 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2008.11.19 17:38:46 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\SSLeay32.dll
[2008.11.19 10:53:59 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\GCL52FW.DLL
[2008.11.19 10:48:43 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\Cmpnl32.dll
[2008.11.19 10:48:43 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\GCL52FWZ.DLL
[2008.11.19 10:48:42 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\CMUpdate.dll
[2008.03.20 23:39:08 | 000,000,030 | ---- | C] () -- C:\Programme\Exiferupdate.ini
[2008.03.03 00:55:21 | 000,661,504 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008.03.03 00:55:21 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2008.03.03 00:55:21 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008.03.03 00:55:21 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008.03.03 00:55:21 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\ffavisynth.dll
[2008.03.03 00:55:20 | 000,397,312 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2008.03.03 00:55:20 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2008.03.03 00:55:20 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2008.03.03 00:55:20 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2008.03.03 00:55:20 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\ff_realaac.dll
[2008.03.03 00:55:20 | 000,102,912 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2008.03.03 00:55:20 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2008.03.03 00:55:20 | 000,054,784 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2008.02.14 14:55:42 | 000,000,032 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ezsid.dat
[2008.01.14 20:50:44 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ZSubTimer.dll
[2008.01.10 13:40:29 | 000,015,360 | ---- | C] () -- C:\WINDOWS\System32\evntmsg.dll
[2008.01.04 16:13:58 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\DEVMAN.DLL
[2007.12.24 13:47:52 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007.12.24 13:40:26 | 000,405,504 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z444.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z443.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z442.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z440.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z439.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z438.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z437.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z436.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z435.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z434.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z433.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z432.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z444U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z443U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z442U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z440U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z439U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z438U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z437U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z436U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z435U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z434U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z433U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z432U.dll
[2007.12.22 22:02:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2007.12.22 21:27:22 | 003,138,048 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2007.12.13 22:41:22 | 000,015,497 | ---- | C] () -- C:\WINDOWS\snp2std.ini
[2007.12.13 22:41:20 | 000,025,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\sncamd.sys
[2007.12.13 22:41:19 | 012,039,552 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2sxp.sys
[2007.12.13 19:18:03 | 000,000,719 | R--- | C] () -- C:\WINDOWS\System32\InstExec.ini
[2007.12.13 19:17:25 | 000,057,126 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007.12.07 16:15:39 | 000,001,260 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2007.12.03 16:34:32 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2007.12.01 13:43:30 | 000,541,696 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2007.11.29 12:52:36 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007.11.26 16:56:04 | 002,842,624 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2007.11.26 16:43:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2007.09.04 23:56:09 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007.09.04 23:44:27 | 000,198,144 | ---- | C] () -- C:\WINDOWS\System32\_psisdecd.dll
[2007.02.27 18:12:06 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\USBaccess.dll
[2007.02.06 18:45:04 | 000,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007.02.06 18:42:40 | 001,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
[2007.01.29 00:03:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\IROTVIEW.INI
[2007.01.28 21:23:40 | 000,000,275 | ---- | C] () -- C:\WINDOWS\ddespy.ini
[2007.01.10 14:00:41 | 000,001,571 | ---- | C] () -- C:\WINDOWS\Faxcpp1.ini
[2007.01.10 14:00:41 | 000,000,422 | ---- | C] () -- C:\WINDOWS\Faxcpp.ini
[2007.01.10 12:52:58 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2006.12.30 20:09:45 | 000,000,240 | ---- | C] () -- C:\WINDOWS\BUHL.INI
[2006.12.24 23:39:33 | 000,000,040 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2006.12.24 22:11:08 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2006.12.21 02:21:58 | 000,144,656 | ---- | C] () -- C:\WINDOWS\System32\FAMCOM.dll
[2006.12.20 22:10:03 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\Gif89.dll
[2006.12.19 18:39:09 | 000,110,642 | ---- | C] () -- C:\WINDOWS\System32\pdfmona.dll
[2006.12.19 18:39:09 | 000,043,252 | ---- | C] () -- C:\WINDOWS\System32\pdfmon.dll
[2006.12.09 02:04:03 | 000,000,687 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006.11.30 22:27:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\FoneSync.INI
[2006.11.30 18:30:30 | 000,000,126 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2006.11.30 17:45:46 | 000,000,037 | ---- | C] () -- C:\WINDOWS\Viewer.ini
[2006.11.30 17:38:48 | 000,000,151 | ---- | C] () -- C:\WINDOWS\ccard100.ini
[2006.11.30 17:37:13 | 000,007,901 | ---- | C] () -- C:\WINDOWS\MSACC20.INI
[2006.11.30 17:30:38 | 000,001,245 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006.11.30 17:30:38 | 000,000,061 | ---- | C] () -- C:\WINDOWS\odbcisam.ini
[2006.11.30 17:30:37 | 000,000,914 | ---- | C] () -- C:\WINDOWS\MSOFFICE.INI
[2006.11.30 17:30:29 | 000,000,124 | ---- | C] () -- C:\WINDOWS\GRAPH5.INI
[2006.11.30 17:30:21 | 000,002,640 | ---- | C] () -- C:\WINDOWS\WINWORD6.INI
[2006.11.30 17:30:18 | 000,000,329 | ---- | C] () -- C:\WINDOWS\EXCEL5.INI
[2006.11.30 17:30:17 | 000,000,239 | ---- | C] () -- C:\WINDOWS\Winhelp.ini
[2006.11.30 17:30:17 | 000,000,110 | ---- | C] () -- C:\WINDOWS\msquery.ini
[2006.11.30 17:30:08 | 000,000,535 | ---- | C] () -- C:\WINDOWS\MSTXTCNV.INI
[2006.11.30 17:30:06 | 000,002,122 | ---- | C] () -- C:\WINDOWS\MSFNTMAP.INI
[2006.11.30 17:30:06 | 000,000,280 | ---- | C] () -- C:\WINDOWS\TTEMBED.INI
[2006.11.30 15:01:49 | 000,000,266 | ---- | C] () -- C:\WINDOWS\VISITE.INI
[2006.11.30 15:00:13 | 000,005,230 | ---- | C] () -- C:\WINDOWS\TOPDRAW.INI
[2006.11.30 14:26:24 | 000,112,688 | ---- | C] () -- C:\WINDOWS\System32\shw32.dll
[2006.11.29 18:34:56 | 000,000,044 | ---- | C] () -- C:\WINDOWS\SMWizard.INI
[2006.11.16 23:01:57 | 000,003,776 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006.11.14 02:05:27 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2006.11.13 00:24:27 | 000,015,576 | R--- | C] () -- C:\WINDOWS\System32\drivers\usbbc.sys
[2006.11.13 00:24:27 | 000,003,953 | R--- | C] () -- C:\WINDOWS\System32\coinst.dll
[2006.11.10 23:55:40 | 000,096,768 | ---- | C] () -- C:\WINDOWS\SlantAdj.dll
[2006.10.11 12:18:40 | 000,078,336 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006.10.10 09:46:17 | 000,003,252 | ---- | C] () -- C:\WINDOWS\System32\drivers\PQNTDRV.SYS
[2006.10.10 04:14:04 | 000,000,092 | ---- | C] () -- C:\WINDOWS\System32\ftdiun2k.ini
[2006.09.27 10:01:53 | 000,000,136 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2006.09.26 01:14:35 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006.09.26 01:13:47 | 000,004,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2006.09.26 01:10:01 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
[2006.09.26 01:09:38 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2006.09.26 01:09:38 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2006.09.26 01:09:10 | 000,004,224 | ---- | C] () -- C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2006.09.26 01:02:33 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006.09.26 01:02:33 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006.09.26 01:02:33 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006.09.26 01:02:33 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006.09.26 01:02:33 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006.09.26 01:02:33 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006.09.26 01:02:00 | 000,000,642 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006.09.26 00:53:24 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\FPCALL.dll
[2006.09.26 00:53:07 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2006.09.26 00:50:44 | 000,009,343 | ---- | C] () -- C:\WINDOWS\System32\drivers\TDSMAPI.SYS
[2006.09.26 00:39:34 | 000,002,458 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006.09.26 00:32:23 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\tphklock.dll
[2006.06.09 11:43:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005.09.01 14:11:52 | 000,016,768 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPrcMon.sys
[2005.07.06 00:45:08 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\notifyf2.dll
[2005.02.17 12:41:32 | 000,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005.02.17 12:41:30 | 000,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2004.12.16 03:41:58 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\pwdmon.dll
[2004.12.16 03:41:58 | 000,019,853 | ---- | C] () -- C:\WINDOWS\ibmprc.ini
[2004.10.15 19:31:56 | 000,218,264 | ---- | C] () -- C:\WINDOWS\System32\SetAid.dll
[2004.10.03 19:50:54 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004.08.10 13:48:32 | 000,000,849 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004.01.09 06:10:32 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\AIBMRUNL.dll
[2001.11.14 13:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1999.04.29 22:00:00 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998.04.24 01:00:00 | 000,000,218 | ---- | C] () -- C:\WINDOWS\FRONTPG.INI
[1996.04.03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
< End of report >

--- --- ---
Danke für die schnelle Anwort

cosinus 28.09.2010 17:55

Zitat:

Datenbank Version: 4666
Du hast Malwarebytes vorher nicht aktualisiert. Wir müssten jetzt bei DB-Version 4710 oder höher sein. Bitte updaten und einen Vollscan machen.

Herzmann 28.09.2010 18:19

Doch, hatte ich. Am 22.09.2010, wo der Scan lief, war das die aktuelle.

Da die betreffenden Dateien sich schon seit ca. 1 Jahr oder mehr auf dem Rechner vorhanden sind (kann ich durch ein früheres Backup erkennen), dachte ich, es käme auf 5 Tage dann auch nicht mehr an.
Deswegen bin ich ja auch recht zuversichtlich, daß der Trojaner nie aktiv geworden ist, denn alle meine Online-Konten sind nach wie vor in Ordnung, und auch sonst hatte ich nie was Verdächtiges bemerkt, und Norton AV auch nicht (der hätte doch meckern müssen, wenn irgend ein Programm da drauf zugegriffen hätte?).

cosinus 28.09.2010 18:33

Zitat:

Doch, hatte ich. Am 22.09.2010, wo der Scan lief, war das die aktuelle.
Ja am 22.09. ich wollte noch einen aktuellen Vollscan sehen ;)

Herzmann 28.09.2010 18:35

Zitat:

Zitat von cosinus (Beitrag 573003)
Ja am 22.09. ich wollte noch einen aktuellen Vollscan sehen ;)

OK, laß ich heute Nacht laufen.

Herzmann 29.09.2010 15:05

Der Vollscan hat nochwas entdeckt. (Bei genauerem Hinsehen: Der Scan vom 22.9. dauerte nur 1:45 Std., das war der, den ich vorzeitig abgebrochen hatte.)

Der heutige brachte noch einen Adware.ADON zum Vorschein. Den hatte ich übrigens auch schon auf meiner ca. 1 Jahr unbenutzten Backup-Platte gefunden.
Malwarebytes fror ein, als ich auf Löschen geklickt hatten. Ich mußte das Programm dann nach 10 Min. abschießen. Log war dann leider auch weg. Glücklicherweise hatte Malwarebytes den Schädling aber wenigstens in Quarantäne geschickt. Nach "Wiederherstellen" konnte ich dann über den Ordner noch einen Quicktest machen, sodaß folgendes Protokoll entstand. Erneutes Löschen ging wieder schief.
Mögliche Gründe:
- Ich hatte gleichzeitig den betreffenden Ordner im Windows-Ordner offen.
- parallel zum Admin-Benutzer, von welchem der Scan gestartet war, hatte ich per Benutzerwechsel noch einen 2. eingeschränkten Benutzer aktiv.

Code:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4715

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

29.09.2010 14:37:43
mbam-log-2010-09-29 (14-37-43).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 1
Laufzeit: 13 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> No action taken.


cosinus 30.09.2010 11:57

Auch im Vollscan wurde nur dieser Eintrag (...eBayShortcuts.exe (Adware.ADON)) entdeckt?

Herzmann 30.09.2010 12:29

Zitat:

Zitat von cosinus (Beitrag 573561)
Auch im Vollscan wurde nur dieser Eintrag (...eBayShortcuts.exe (Adware.ADON)) entdeckt?

Ja!

Allerdings dauerte dieser Vollscan während laufendem Betrieb auf 2. eingeschränkten Benutzer merkwürdigerweise nur ca. 5 Stunden auf meiner aktuellen 160 GB 2,5" Platte.
Auf meiner alten 80 GB 2,5" Platte (Inhalt wurde vor ca. 1 Jahr auf die neue geklont) dauerte er über Nacht über 8 Stunden.
Möglicherweise ist die alte Platte aber einfach nur langsamer.

cosinus 30.09.2010 15:27

Poste bitte nochmal ein frisches OTL.txt, im letzten fehlen einige Passagen...

Herzmann 01.10.2010 12:49

Zitat:

Zitat von cosinus (Beitrag 573646)
Poste bitte nochmal ein frisches OTL.txt, im letzten fehlen einige Passagen...

Meintest Du die Extras.txt (ich mache heute auch noch mal einen neuen)? :
Code:

OTL Extras logfile created on: 28.09.2010 16:39:54 - Run 1
OTL by OldTimer - Version 3.2.14.1    Folder = E:\Software\Ab 17.04.2009\Download\Sicherheit
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 44,00% Memory free
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 62,00% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1536 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 59,53 Gb Total Space | 5,43 Gb Free Space | 9,12% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 46,18 Gb Total Space | 0,08 Gb Free Space | 0,18% Space Free | Partition Type: FAT32
Drive F: | 4,00 Gb Total Space | 0,45 Gb Free Space | 11,32% Space Free | Partition Type: FAT32
Drive G: | 4,01 Gb Total Space | 0,46 Gb Free Space | 11,49% Space Free | Partition Type: FAT32
Drive H: | 25,27 Gb Total Space | 4,47 Gb Free Space | 17,68% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
 
Computer Name: XXX
Current User Name: ***
NOT logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla\Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Programme\Mozilla\Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Programme\Mozilla\Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Durchsuchen mit &IrfanView] -- "C:\Programme\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"6198:TCP" = 6198:TCP:*:Enabled:freenetSPEED
"3126:TCP" = 3126:TCP:*:Enabled:freenetSPEED
"3128:TCP" = 3128:TCP:*:Enabled:freenetSPEED
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Programme\IBM\Updater\jre\bin\java.exe" = C:\Programme\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\jre\bin\javaw.exe" = C:\Programme\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\ucsmb.exe" = C:\Programme\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector -- File not found
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Programme\IBM\Updater\jre\bin\java.exe" = C:\Programme\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\jre\bin\javaw.exe" = C:\Programme\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\ucsmb.exe" = C:\Programme\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector -- File not found
"D:\fsetup.exe" = D:\fsetup.exe:*:Enabled:AVM FSetup Application -- File not found
"C:\Programme\freenet\PxClient.exe" = C:\Programme\freenet\PxClient.exe:*:Enabled:freenetSPEED -- File not found
"C:\Programme\VoipDiscount.com\VoipDiscount\VoipDiscount.exe" = C:\Programme\VoipDiscount.com\VoipDiscount\VoipDiscount.exe:*:Enabled:VoipDiscount -- (VoipDiscount)
"C:\Programme\Mozilla Thunderbird\thunderbird.exe" = C:\Programme\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Mozilla Thunderbird -- (Mozilla Messaging)
"C:\Programme\Intuwave Ltd\Shared\mRouterRunTime\mRouterRuntime.exe" = C:\Programme\Intuwave Ltd\Shared\mRouterRunTime\mRouterRuntime.exe:*:Enabled:mRouterRuntime -- (Intuwave Ltd.)
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft  Fax Console -- (Microsoft Corporation)
"C:\Programme\Java\jdk1.6.0_01\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_01\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe" = C:\Programme\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe:*:Enabled:mysqld-nt -- ()
"C:\Programme\Java\jdk1.6.0_01\bin\java.exe" = C:\Programme\Java\jdk1.6.0_01\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Java\jdk1.6.0\bin\java.exe" = C:\Programme\Java\jdk1.6.0\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\FRITZ!DSL\FBOXUPD.EXE" = C:\Programme\FRITZ!DSL\FBOXUPD.EXE:*:Enabled:AVM FRITZ!Box Firmware-Update -- (AVM Berlin)
"C:\Programme\Java\jdk1.6.0_02\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_02\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Home Cinema\PowerCinema\PowerCinema.exe" = C:\Programme\Home Cinema\PowerCinema\PowerCinema.exe:*:Enabled:PowerCinema -- File not found
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_147a792107b9f781\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_147a792107b9f781\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Programme\WS_FTP\WS_FTP95.exe" = C:\Programme\WS_FTP\WS_FTP95.exe:*:Enabled:WS_FTP 95 -- (Ipswitch, Inc. 81 Hartwell Ave. Lexington, MA)
"C:\Programme\Java\jdk1.6.0_03\bin\java.exe" = C:\Programme\Java\jdk1.6.0_03\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Programme\Java\jdk1.6.0_03\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_03\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Programme\Java\jre1.6.0_03\bin\java.exe" = C:\Programme\Java\jre1.6.0_03\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Java\NetBeans 6.0 RC2\mobility8\WTK2.5.2\bin\emulator.exe" = C:\Programme\Java\NetBeans 6.0 RC2\mobility8\WTK2.5.2\bin\emulator.exe:*:Enabled:emulator -- File not found
"C:\Programme\Java\WTK22\bin\emulator.exe" = C:\Programme\Java\WTK22\bin\emulator.exe:*:Enabled:emulator -- ()
"C:\Programme\Java\NetBeans 6.0\mobility8\WTK2.5.2\bin\emulator.exe" = C:\Programme\Java\NetBeans 6.0\mobility8\WTK2.5.2\bin\emulator.exe:*:Enabled:emulator -- File not found
"C:\Programme\FRITZ!DSL\IGDCTRL.EXE" = C:\Programme\FRITZ!DSL\IGDCTRL.EXE:*:Enabled:AVM FRITZ!DSL - igdctrl.exe -- (AVM Berlin)
"C:\Programme\FRITZ!DSL\WebwaIgd.exe" = C:\Programme\FRITZ!DSL\WebwaIgd.exe:*:Enabled:AVM FRITZ!DSL - webwaigd.exe -- (AVM Berlin)
"C:\Programme\uTorrent\uTorrent.exe" = C:\Programme\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- File not found
"C:\Programme\Sony Ericsson\Update Service\ma3platform.exe" = C:\Programme\Sony Ericsson\Update Service\ma3platform.exe:*:Enabled:ma3platform -- File not found
"C:\Programme\Sony Ericsson\Update Service\Update Service.exe" = C:\Programme\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service -- File not found
"C:\Programme\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe" = C:\Programme\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.0 -- (Sony Creative Software Inc.)
"C:\Programme\Java\jdk1.6.0_04\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_04\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0e9add42c1\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0e9add42c1\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Programme\Java\jre1.6.0_04\bin\javaw.exe" = C:\Programme\Java\jre1.6.0_04\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Program Files\IBM\Java142\jre\bin\javaw.exe" = C:\Program Files\IBM\Java142\jre\bin\javaw.exe:*:Enabled:Java launcher -- (IBM)
"C:\Programme\Mozilla\Firefox\firefox.exe" = C:\Programme\Mozilla\Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Programme\Java\jdk1.6.0_06\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_06\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0f9b5c5281\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0f9b5c5281\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Programme\Java\jdk1.6.0_07\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_07\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Real\RealPlayer\realplay.exe" = C:\Programme\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- File not found
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf139d589181\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf139d589181\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf149dd7a141\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf149dd7a141\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- (AVM Berlin)
"C:\Programme\Java\jre6\bin\java.exe" = C:\Programme\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"C:\Programme\Java\jre6\bin\javaw.exe" = C:\Programme\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- (AVM Berlin)
"C:\WINDOWS\LMI35.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI35.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI60.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI60.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI33D.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI33D.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI3B2.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI3B2.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI3B7.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI3B7.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\Programme\BitTorrent\bittorrent.exe" = C:\Programme\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Programme\FRITZ!Box Monitor\FRITZBoxMonitor.exe" = C:\Programme\FRITZ!Box Monitor\FRITZBoxMonitor.exe:*:Enabled:FRITZ!Box Monitor -- (AVM Berlin)
"C:\Programme\FRITZ!vox\Fritz!vox.exe" = C:\Programme\FRITZ!vox\Fritz!vox.exe:*:Enabled:Fritz!vox -- (AVM Berlin)
"C:\CYGWIN\bin\rsync.exe" = C:\CYGWIN\bin\rsync.exe:*:Enabled:rsync -- ()
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000407-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium
"{00170407-78E1-11D2-B60F-006097C998E7}" = Microsoft Word 2000 SR-1
"{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}" = Java DB 10.5.3.0
"{01008202-823E-46CD-A70E-BEE818F97169}" = Microsoft Encarta Enzyklopädie 2002
"{01DA3FC4-CF94-4AAD-9127-C8F2E09F6E69}" = PowerArchiver 2010
"{024D73F0-1C49-2340-8AC3-5234AAA560C0}" = ccc-core-static
"{03B1BBDC-7FAA-4A03-9988-A85428BAD382}" = Sun ODF Plugin for Microsoft Office 3.0
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{05E9F134-07C9-4249-9B80-EE5D975F201B}" = Sony Ericsson Image Editor
"{0873B1A3-00A9-40D6-BACE-3DB4BC5DA840}" = ThinkPad SATA Power Management Driver
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Systemsteuerung
"{0D05C1D4-BB4C-4545-86DC-F5EA7D04121A}" = Vtpro-e Themes v1.3
"{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}" = HP USB Disk Storage Format Tool
"{1007F41F-7D69-468E-8017-3849A5A973C2}" = IBM ThinkVantage Technologies Welcome Message
"{11783F13-C3A9-44A8-929B-21A476F65272}" = IBM Rescue and Recovery with Rapid Restore
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1297C681-92D7-40EF-93BF-03F66EC5105C}" = ThinkPad-Dienstprogramm 'EasyEject'
"{13EDFFFE-DCF2-448A-A653-3C4CD60D99B4}" = Palm Desktop and Synchronization Software
"{1649C93D-C661-4C53-B8AE-DB3592150B34}" = Buhl finance - tax 2006 Professional
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = ThinkPad UltraNav Utility
"{1E5007FA-DA5E-4EDD-BDE5-14D128D66887}" = PowerQuest PartitionMagic 7.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = Dienstprogramm 'IBM ThinkPad-Tastaturanpassung'
"{23170F69-40C1-2701-0465-000001000000}" = 7-Zip 4.65
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{2457326B-C110-40C3-89B0-889CC913871A}" = AVM FRITZ!DSL
"{24F9E04D-4CD5-3979-76F9-C1C6E78471AB}" = CCC Help Italian
"{25F60491-F5AB-4985-9354-37C146783F35}" = Microsoft Works Suite-Add-Ins für Microsoft Word
"{2604C0F9-BFD3-4BA0-9EB5-22537C648F03}" = MobileMe Control Panel
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 21
"{2D230139-69DA-4CE8-83FB-EE5F522D2FF5}" = Praesideo Logging Server V2.32.1757
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator
"{2FEB25F8-C3CB-49A2-AE79-DE17FFAFB5D9}" = MySQL Server 5.0
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 3.108.00
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{31E1050B-F69F-4A16-8F5A-E44D31901250}" = Ulead DVD DiskRecorder 2.1.1
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{32A3A4F4-B792-11D6-A78A-00B0D0150100}" = J2SE Development Kit 5.0 Update 10
"{32A3A4F4-B792-11D6-A78A-00B0D0160030}" = Java(TM) SE Development Kit 6 Update 3
"{32A3A4F4-B792-11D6-A78A-00B0D0160180}" = Java(TM) SE Development Kit 6 Update 18
"{32A3A4F4-B792-11D6-A78A-00B0D0160200}" = Java(TM) SE Development Kit 6 Update 20
"{32A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java(TM) SE Development Kit 7
"{3305E24F-1192-0424-8A25-39713FD92728}" = Skins
"{34F0D55F-C386-4195-9A5B-961D3F6ACD46}" = InterVideo MediaOne Gallery
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B94A56F-9FDA-46CC-A3B6-07613A84200B}" = Buhl finance - tax 2007 Professional
"{3D289CAC-AD9F-45d9-9D36-524EB7B6C958}" = Lenovo Hard Drive Quick Test
"{3DA7A736-0B03-565C-1139-83FE890F0AF3}" = CCC Help French
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{3F71721C-E73D-481C-B926-C56B68D8F388}" = Praesideo Open Interface Library V2.32.1757
"{437C19B3-7E20-4E39-B868-CA6BAA820E1C}" = Microsoft Rechner-Plus
"{43A1FE83-D39F-3779-8D48-D6D19EE7AC48}" = CCC Help Chinese Traditional
"{443CBE24-0679-4027-9C36-66F129E009C5}" = Crestron Database
"{448AB2CB-C94A-47DE-80B8-9D7824DEFA57}" = Ulead FilmBrennerei 4.0
"{44B32F92-5A96-43D9-BCBE-0AD2CDC409E7}" = TortoiseHg 1.1.3 (x86)
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage System für aktiven Festplattenschutz
"{47CF8B92-4083-4F43-9680-6EDE10F812BD}" = Praesideo Logging Viewer V2.32.1757
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{55C28EF3-2EA3-46AB-B1E7-54B96C5A6921}" = Viewport v3.99.01
"{57FA0525-01F9-4051-8DE9-CBF43CAC68D9}" = Catalyst Control Center - Branding
"{5C72622B-643D-4296-B57D-5D53D0C68509}" = Sony Ericsson Media Manager 1.0
"{5D73F169-DD54-4C74-AEB0-CE72A4ED95E6}" = Algo Vision LuraTech Browser Plug-ins
"{5DE1B7CF-7429-40CA-987F-6BEE09B63787}" = Prime95
"{5F71EB81-C72E-4B28-8D90-FDEECFEBC2DE}" = Drive Image
"{61A17AE1-B4C3-4FC0-8563-684C23CBFA0F}" = SW-Entwicklung\Sun Java (TM) Wireless Toolkit 2.5.2 for CLDC
"{63F817ED-F710-481B-B332-7A356CE04E10}" = TortoiseOverlays
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6686F38D-1A32-4A8C-94D7-A2AA9C5F3C9B}" = Crestron Device Database
"{66CA5E58-0D03-A75D-16EF-68258DE0DFC3}" = CCC Help English
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BC292E6-5C85-4620-C1D0-A2FEAFD5D135}" = CCC Help Japanese
"{6C31E111-96BB-4ADC-9C81-E6D3EEDDD8D3}" = Powertoys For Windows XP
"{6CE96A14-61E2-48CC-837E-22710A953ADE}" = IBM Themes
"{7005C601-B415-4D77-B2ED-FF40E3DACDED}" = DEAL for Windows v4.00
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{735DEB9C-61BD-4D31-994B-92395BBB4E45}" = Microsoft XML Parser
"{75438C0E-9925-412E-AD85-D0E71C6CE2ED}" = USB2.0 PC Camera (SN9C201&202)
"{7579A17B-0E6C-9EF3-D022-30729A24B399}" = CCC Help Chinese Standard
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7BAA2000-5B8D-66DD-DBE7-089671AC118B}" = ccc-utility
"{7C2BD022-2B09-1F6D-D6C1-AD2A591E7537}" = Catalyst Control Center Core Implementation
"{7D2370AC-D8E6-4996-986A-19824F8A167C}" = Logitech QuickCam
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{806DB796-7082-C63F-284E-62245284A417}" = CCC Help Dutch
"{808FAA20-4C3A-11D4-8A57-00201853C903}" = PC-Linq
"{82512BC9-BD5D-4C50-BE4D-B98E7DF78687}" = ThinkPad-UltraNav-Assistent
"{8398B542-3CC4-44D9-83DF-696CCE70124B}" = Windows Support Tools
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{8675339C-128C-44DD-83BF-0A5D6ABD8297}" = System Update
"{8745DEAB-1126-42F5-9585-C66D5497B47B}" = EMEA Wallpaper
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D0E26CF-AA2F-48FF-A533-6207DE50B1C4}_is1" = Agendus for Windows Palm Desktop Edition
"{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2
"{8EAB2384-C794-40ED-A9DD-3270A0D2BB76}" = Ulead VideoStudio 9.0
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{91AF774D-8506-4194-9B77-9D803CBF5AC1}" = SIMPL Windows v2.10
"{925936AC-9C9A-4897-874B-60961AAB6D52}" = Disc2Phone
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{984E0622-29E5-44EA-A075-A0CE91B2CF13}" = TortoiseOverlays
"{A0E64EBA-8BF0-49FB-90C0-BB3D781A2016}" = ThinkPad Energie-Manager
"{A1A903C9-35DE-4770-9264-5F831E0A3A2E}" = SIMPL Windows Library v565
"{A2092B2A-A4FB-4464-A4C0-023D2C9993F8}" =
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3E23D97-145F-29BF-81DE-DAEC1E5AB237}" = Catalyst Control Center Graphics Full New
"{A8FA2AC0-3875-B59F-917F-719982FB1BE8}" = CCC Help Portuguese
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA3983BF-9B72-484E-972A-E47BBAFA9CCA}" = VisionTools Pro-e v3.8
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.4 - Deutsch
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AC849092-6F19-4395-8860-BC3B82CAFE51}" = funScreenScraping Microsoft Systemdateien
"{AE1A0B0E-2EC7-656A-711A-0E7E8D4AB5CF}" = CCC Help Spanish
"{B016DE7B-CA2D-5EFD-9591-A109E67119BD}" = CCC Help Swedish
"{B214C3C8-FC16-42EC-B7BB-703A1BB9C790}" = Lenovo Battery Program
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B5FE8184-DB90-4642-826C-096C6369B3DA}" = J2ME Wireless Toolkit 2.2
"{B6826FA8-04C8-4147-AA3C-5B900AB887A1}" = PowerArchiver 2007
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU
"{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU
"{C4A92EF9-D14C-937F-742E-D272938DC590}" = CCC Help Korean
"{C769A271-7E1C-48F9-B331-474600DD4C06}" = Microsoft Picture It! Foto 2002
"{C7B8E06E-EBBC-4210-93AB-DFC8760E3FC9}" = Works Suite-Betriebssystem-Pack
"{C9A87D86-FDFD-418B-BF96-EF09320973B3}" = PC Inspector smart recovery
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CD6EB005-957A-4191-93ED-6ECD5F7F931E}" = SKTimeStamp
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFEDA22F-435D-4891-913A-75B80D8159B8}" = Crestron Toolbox v1.12
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D121161E-AD64-4438-97A0-66A1AB7FFDE3}" = Works Suite-Betriebssystem-Pack
"{D2FEBD11-E587-4C41-AD33-0CD90D26A964}" = Client für die Windows-Rechteverwaltung mit Service Pack 2
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow! 1.0
"{D5881E4A-0764-11D6-9D93-DECCF2B3F57C}" = Praesideo Core V2.32.1757
"{D5A9B7C0-8751-11D8-9D75-000129760D75}" = MediaShow 3.0
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7 Anniversary Edition
"{D702172D-8D17-D9EC-B661-42FA268575AF}" = Catalyst Control Center Localization All
"{DAA3F236-CEEC-C6CC-12C2-AB1B75C8BC09}" = CCC Help German
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DEC2C123-3CE0-4669-B119-61519130CACD}" = TortoiseSVN 1.6.10.19898 (32 bit)
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E09CEE8B-1DCD-C628-A8EA-2B56D61DDEFA}" = ccc-core-preinstall
"{E258A840-7E9A-443A-B156-67102C48BF17}" = TPP Storage Driver Installation
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9-Reihe
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{E922961C-6DB6-41DE-9FEA-426DF3E9F81C}" = IBM 32-bit Runtime Environment for Java 2, v1.4.2
"{EA664480-3844-11D5-8C25-444553540000}" = Funktion "TrackPoint-Eingabehilfen"
"{EC6AF20D-4376-4070-BEE4-D3A0DFF7E140}" = Access IBM
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Rückwärtskompatibilität des Clients für die Windows-Rechteverwaltung SP2
"{ED5EDCD0-5745-4B13-8061-58C9833FD06D}" = Microsoft Works 6.0
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F18B31E4-E2E3-4F4F-A2C9-BA579D6AF400}" = TortoiseOverlays
"{F2260E94-80F2-4CB1-B6B1-6043D9BFFA47}" = Works-Synchronisierung
"{F22FD942-651D-4EE8-BD6F-7E0AF5E17625}" = Intel(R) PROSet/Wireless WiFi-Software
"{F3439243-1BAC-7250-D346-2642655F95ED}" = Catalyst Control Center Graphics Full Existing
"{F34D9A5F-484A-4E31-A9D3-908CB265B289}" = Sygate Personal Firewall
"{F3FAE3D8-A91D-4D11-90C1-27581C2C23B9}" = Sony Ericsson MMS Home Studio
"{F413B3A4-EE5D-457C-BAE5-6E58D9589ED5}" = Access IBM Message Center
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F63E8666-0F10-11D3-8258-00C04F6843FE}" = Microsoft Visual Keyboard
"{F705E3E1-A471-426B-9A09-73429F3418EE}" = System Migration Assistant
"{F7F2DC0A-C22E-49AD-AD37-797309A54E7B}" = Microsoft AutoRoute 2002
"{FB97A745-D1E6-435D-B942-264E94F89938}" = SIMPL+ Cross Compiler
"{FC081D4D-DF1B-4CF1-B530-027E4118D846}" = ThinkPad-Konfiguration
"{FC18114B-05A0-11D6-8140-000102E745A6}" = PC Suite for P800
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FD331A3B-F7A5-4C31-B8D4-DF413C85AF7A}" = Message Center Plus
"{FD9D4CA5-8F97-44A0-B17E-C2C77C824FA4}" = funScreenScraping Client Version
"{FF2AFF73-099E-0BB5-AE87-B044D3D7DE78}" = Catalyst Control Center Graphics Light
"1&1 Upload-Manager" = 1&1 Upload-Manager
"274c5407c4fa26908310cb5c1c5500001224356439" = NetBeans IDE 5.5
"312f77fc8b5965949add215dd8550000-1163196496" = NetBeans Profiler 5.5
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"All ATI Software" = ATI - Dienstprogramm zur Deinstallation der Software
"Any Video Converter_is1" = Any Video Converter 3.0.3
"ATI Display Driver" = ATI Display Driver
"Attribute Manager_is1" = Attribute Manager 2.35
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.9 (Unicode)
"Audacity_is1" = Audacity 1.2.6
"avast5" = avast! Free Antivirus
"AVIcodec" = AVIcodec (remove only)
"Avira UnErase Personal" = Avira UnErase Personal
"AVMFBox" = AVM FRITZ!Box Dokumentation
"AVMFBoxAnswerMachine" = AVM FRITZ!vox
"AVMFBoxMonitor" = AVM FRITZ!Box Monitor
"BitTorrent" = BitTorrent
"CCleaner" = CCleaner
"CD Audio Reader Filter" = CD Audio Reader Filter (remove only)
"CDCheck" = CDCheck
"CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_05591014" = ThinkPad Integrated 56K Modem
"CollabNet Automatic Update" = CollabNet Automatic Update 1.2
"CollabNet Subversion Client" = CollabNet Subversion Client 1.6.12
"Corel Applications" = Corel Applications
"CvsConflictEditor_is1" = CvsConflictEditor 1.2.0
"CVSNT_is1" = CVSNT
"D2D77DC2-8299-11D1-8949-444553540000_is1" = WinCvs 2.0
"Defraggler" = Defraggler
"DiffUtils-2.8.7_is1" = GnuWin32: DiffUtils version 2.8.7
"Digital Image Recovery_is1" = Digital Image Recovery 1.47
"DirectVobSub" = DirectVobSub (remove only)
"doPDF 7 printer_is1" = doPDF 7.1 printer
"EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 5.5.1 Home Edition
"EPSON SMART PANEL" = EPSON SMART PANEL
"EPSON Stylus Scan" = EPSON Stylus Scan FB TWAIN
"EPSON-Drucker und Utilities" = EPSON-Drucker-Software
"Exact Audio Copy" = Exact Audio Copy 0.99pb5
"Exifer_is1" = Exifer
"fcd569e3a3b8ade0f9366fc6625500001796351737" = NetBeans Mobility Pack 5.5
"Feurio" = Feurio! CD-Writer
"ffdshow_is1" = ffdshow [rev 1868] [2008-02-22]
"FFmpeg for Audacity on Windows_is1" = FFmpeg for Audacity on Windows
"FinePrint 2000" = FinePrint 2000
"FinePrint2000" = FinePrint 2000
"FolderSizes_is1" = FolderSizes 1.0
"frndial" = freenet.de
"FTDICOMM" = SEMC DSS-20 SyncStation Driver
"GMX Upload-Manager" = GMX Upload-Manager
"IE7 Standalone_is1" = Internet Explorer 7 Standalone
"InstallShield für Microsoft Visual C++ 6" = InstallShield für Microsoft Visual C++ 6
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{5D73F169-DD54-4C74-AEB0-CE72A4ED95E6}" = Algo Vision LuraTech Browser Plug-ins
"InstallShield_{E922961C-6DB6-41DE-9FEA-426DF3E9F81C}" = IBM 32-bit Runtime Environment for Java 2, v1.4.2
"IrfanView" = IrfanView (remove only)
"ISO Commander" = ISO Commander 1.6 (remove only)
"IsoBuster_is1" = IsoBuster 2.7
"jclasslib bytecode viewer 3.0" = jclasslib bytecode viewer 3.0
"KompoZer_is1" = KompoZer 0.77
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Lavasoft VX2 Cleaner" = Lavasoft VX2 Cleaner
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaInfo" = MediaInfo 0.7.29
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Developer Network - Visual Studio 6.0a (deu)" = MSDN Library - Visual Studio 6.0a (Deutsch)
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"Mozilla Thunderbird (3.1.4)" = Mozilla Thunderbird (3.1.4)
"Mp3tag" = Mp3tag v2.46a
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyDefrag v4.2.5_is1" = MyDefrag v4.2.5
"MyDefrag v4.2.9_is1" = MyDefrag v4.2.9
"nbi-nb-base-6.0.0.0.200711201000" = NetBeans IDE 6.0 RC2
"nbi-nb-base-6.1.0.0.200804211638" = NetBeans IDE 6.1
"nbi-nb-base-6.5.0.0.200811100001" = NetBeans IDE 6.5
"nbi-nb-base-6.7.1.0.0" = NetBeans IDE 6.7.1
"nbi-nb-base-6.9.0.0.0" = NetBeans IDE 6.9
"nbi-nb-base-6.9.1.0.201006282301" = NetBeans IDE 6.9.1 Build 201006282301
"Nero - Burning Rom!UninstallKey" = Ahead Nero - Burning Rom
"Notepad++" = Notepad++
"NTFSRatio_is1" = NTFSRatio V1.3
"Nvu_is1" = Nvu 1.0
"OnScreenDisplay" = Anzeige am Bildschirm
"PC-Doctor 5 for Windows" = PC-Doctor 5 für Windows
"PFrank_is1" = Peter's Flexible RenAmiNg Kit (PFrank) 2.13
"Power Management Driver" = ThinkPad Power Management Driver
"Praesideo PC Callstation" = Praesideo PC Callstation
"Presentation Director" = ThinkPad-Präsentationsdirektor
"ProInst" = Intel PROSet Wireless
"QcDrv" = Logitech® Camera-Treiber
"RealPlayer 12.0" = RealPlayer
"RealVNC_is1" = VNC Free Edition 4.1.2
"Rename-It!" = Rename-It!
"ReNamer_is1" = ReNamer
"Secunia PSI" = Secunia PSI
"SequoiaView" = SequoiaView
"SpeedFan" = SpeedFan (remove only)
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"ThinkPadSoftwareInstaller" = Installationsprogramm für ThinkPad-Software
"TPKBDLED" = Scroll Lock Indicator Utility
"TPP200" = USB Storage Adapter V2 (TPP)
"TPP300" = USB Storage Adapter V3 (TPP)
"TPP725" = USB Storage Adapter (TPP)
"TreeSize Free_is1" = TreeSize Free V2.2.1
"UltraDefrag" = Ultra Defragmenter
"Unlocker" = Unlocker 1.8.7
"VLC media player" = VLC media player 1.1.4
"VoipDiscount_is1" = VoipDiscount
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WebPost" = Microsoft Web Publishing Wizard 1.53
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9-Reihe
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinHex" = WinHex
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.43
"WinMerge_is1" = WinMerge 2.12.4
"WinRAR archiver" = WinRAR
"winscp3_is1" = WinSCP 4.2.7
"WinZip" = WinZip
"WinZip Self-Extractor" = WinZip Self-Extractor
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2002Setup" = Microsoft Works 2002-Setup-Start
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"X10Hardware" = X10 Hardware(TM)
"xdocdiff" = xdocdiff
"XP Codec Pack" = XP Codec Pack
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"Z-DBackup" = Z-DBackup
"ZoomPlayer" = Zoom Player (remove only)
"ZoomPlayerLang" = Zoom Player deutsche Sprachdateien (entfernen)
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01D5859C-5207-4183-B88D-3DCD2022BC54}" = t@x 2008 Professional
"{40030378-9EB9-482A-AC10-195097CA624D}" = t@x 2009 Professional
"f6791b188d8f3ff8" = AVM FRITZ!Box USB-Fernanschluss
"InstallShield_{5F71EB81-C72E-4B28-8D90-FDEECFEBC2DE}" = PowerQuest Drive Image 2002
"jIRCii" = jIRCii
"muCommander" = muCommander
"StackTrace" = StackTrace
 
========== Last 10 Event Log Errors ==========
 
Error: Unable to start EventLog service!
 
< End of report >


Herzmann 01.10.2010 13:08

OTL.txt:
Code:

OTL logfile created on: 01.10.2010 13:50:42 - Run 2
OTL by OldTimer - Version 3.2.14.1    Folder = E:\Software\Ab 17.04.2009\Download\Sicherheit
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 45,00% Memory free
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 61,00% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1536 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 59,53 Gb Total Space | 5,38 Gb Free Space | 9,04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 46,18 Gb Total Space | 2,20 Gb Free Space | 4,77% Space Free | Partition Type: FAT32
Drive F: | 4,00 Gb Total Space | 0,45 Gb Free Space | 11,32% Space Free | Partition Type: FAT32
Drive G: | 4,01 Gb Total Space | 0,46 Gb Free Space | 11,49% Space Free | Partition Type: FAT32
Drive H: | 25,27 Gb Total Space | 4,47 Gb Free Space | 17,68% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
 
Computer Name: XXX
Current User Name: ***
NOT logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - E:\Software\Ab 17.04.2009\Download\Sicherheit\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Mozilla\Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Programme\Mozilla\Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Programme\TortoiseHg\TortoiseHgOverlayServer.exe ()
PRC - C:\Programme\TortoiseSVN\bin\TSVNCache.exe (hxxp://tortoisesvn.net)
PRC - C:\Programme\TortoiseSVN\bin\TortoiseProc.exe (hxxp://tortoisesvn.net)
PRC - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\TpShocks.exe (Lenovo.)
PRC - C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
PRC - C:\Programme\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Programme\WinMerge\WinMergeU.exe (hxxp://winmerge.org)
PRC - C:\Programme\Lenovo\Message Center Plus\MCPLaunch.exe ()
PRC - C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe (AVM Berlin)
PRC - C:\Programme\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
PRC - C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Programme\FRITZ!DSL\StCenter.exe (AVM Berlin)
PRC - C:\Programme\FRITZ!DSL\FwebProt.exe (AVM Berlin)
PRC - C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Programme\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Programme\Logitech\QuickCam10\QuickCam10.exe ()
PRC - C:\Programme\Gemeinsame Dateien\logishrd\LComMgr\Communications_Helper.exe (Logitech Inc.)
PRC - C:\Programme\Gemeinsame Dateien\logishrd\LQCVFX\COCIManager.exe (Logitech Inc.)
PRC - C:\Programme\Gemeinsame Dateien\logishrd\LComMgr\LVComSX.exe (Logitech Inc.)
PRC - C:\WINDOWS\tsnp2std.exe (SONIX)
PRC - C:\WINDOWS\vsnp2std.exe (Sonix)
PRC - C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.exe (Lenovo Group Limited)
PRC - C:\Programme\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\system32\dla\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\IBMTOOLS\utils\ibmprc.exe (IBM Corp.)
PRC - C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe (Teleca Software Solutions AB)
PRC - C:\Programme\Analog Devices\SoundMAX\SMax4.exe (Analog Devices, Inc.)
PRC - C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
PRC - C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Programme\Sony Ericsson\Mobile\Connectivity Pack\ConnMngMntBox.exe (Symbian Ltd.)
PRC - c:\Programme\Intuwave Ltd\Shared\mRouterRunTime\mRouterRuntime.exe (Intuwave Ltd.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
PRC - C:\Programme\Palm\Handspring\HOTSYNC.EXE (Palm, Inc.)
PRC - C:\WINDOWS\system32\TpScrLk.exe ()
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\2\fpdisp4.exe (FinePrint Software, LLC)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()
PRC - C:\WINDOWS\tppaldr.exe (In-System Design, Inc.)
PRC - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
PRC - C:\Programme\EPSON\SMART PANEL\SmaPanel.exe (NewSoft)
 
 
========== Modules (SafeList) ==========
 
MOD - E:\Software\Ab 17.04.2009\Download\Sicherheit\OTL.exe (OldTimer Tools)
MOD - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll ()
MOD - C:\WINDOWS\system32\msvcr71.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)
MOD - C:\Programme\Gemeinsame Dateien\logishrd\LVMVFM\LVPrcInj.dll (Logitech Inc.)
MOD - C:\WINDOWS\system32\msvcp71.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
 
========== Driver Services (SafeList) ==========
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-999901472-3601035388-3065584919-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.selectedEngine: "LEO de<->en"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.taz.de/|hxxp://www.oya-online.de/"
FF - prefs.js..extensions.enabledItems: en-GB@dictionaries.addons.mozilla.org:1.19
FF - prefs.js..extensions.enabledItems: {e1170235-2845-420c-acc3-42261a29dd46}:4.0.1
FF - prefs.js..extensions.enabledItems: pt-PT@dictionaries.addons.mozilla.org:9.10.13.6
FF - prefs.js..extensions.enabledItems: es-es@dictionaries.addons.mozilla.org:1.3.1
FF - prefs.js..extensions.enabledItems: {a0faa0a4-f1a7-4098-9a74-21efc3a92372}:4.0.0
FF - prefs.js..extensions.enabledItems: it-IT@dictionaries.addons.mozilla.org:3.1
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.1
FF - prefs.js..extensions.enabledItems: fb_add_on@avm.de:1.5.5
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.9
FF - prefs.js..extensions.enabledItems: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.85
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.5.4
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {28FAD68E-4001-48d5-B994-68069F7CFB1D}:0.4.7
FF - prefs.js..extensions.enabledItems: pagecompare_abk0680@yahoo.com:1.5
FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2.1
FF - prefs.js..extensions.enabledItems: savecomplete@perlprogrammer.com:1.0.1
FF - prefs.js..extensions.enabledItems: {53A03D43-5363-4669-8190-99061B2DEBA5}:1.3.7
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {29c4afe1-db19-4298-8785-fcc94d1d6c1d}:0.6.2009110501
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: tsvnmenu@pumacode.org:0.2.5
FF - prefs.js..extensions.enabledItems: {139a120b-c2ea-41d2-bf70-542d9f063dfd}:2.03.3
FF - prefs.js..extensions.enabledItems: {eecba28f-b68b-4b3a-b501-6ce12e6b8696}:0.7.2
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5
FF - prefs.js..extensions.enabledItems: ietab@ip.cn:1.94.20100904
FF - prefs.js..extensions.enabledItems: metatags@porton.ex-code.com:2.3.5.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {398e77b8-2304-11dc-8314-0800200c9a66}:0.3.13
FF - prefs.js..extensions.enabledItems: de_DE@dicts.j3e.de:20100720
FF - prefs.js..extensions.enabledItems: fr-moderne@dictionaries.addons.mozilla.org:3.8
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.09.07 00:35:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Programme\Mozilla\Firefox\components [2010.09.17 12:18:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Programme\Mozilla\Firefox\plugins [2010.09.17 12:24:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2010.09.17 12:18:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
 
[2010.01.19 19:43:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Extensions
[2010.01.19 19:43:44 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.10.01 13:39:51 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions
[2010.03.28 01:15:31 | 000,000,000 | ---D | M] (Screengrab) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010.10.01 13:39:51 | 000,000,000 | ---D | M] (Forecastfox Weather) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010.08.18 22:54:02 | 000,000,000 | ---D | M] (FireShot) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2009.11.04 11:06:03 | 000,000,000 | ---D | M] (URL Link) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{139a120b-c2ea-41d2-bf70-542d9f063dfd}
[2007.03.31 01:03:40 | 000,000,000 | ---D | M] (FlashGot) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(2)
[2008.03.13 21:48:21 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}(2)
[2010.04.30 19:39:30 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.01.29 15:55:11 | 000,000,000 | ---D | M] (MouseZoom) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{28FAD68E-4001-48d5-B994-68069F7CFB1D}
[2009.11.12 19:20:16 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010.09.08 12:27:24 | 000,000,000 | ---D | M] (Minimap Addon) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{398e77b8-2304-11dc-8314-0800200c9a66}
[2010.03.28 01:15:33 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2008.10.10 23:42:45 | 000,000,000 | ---D | M] (NoScript) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(2)
[2010.08.12 23:42:20 | 000,000,000 | ---D | M] (DictionarySearch) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}
[2008.03.02 22:09:45 | 000,000,000 | ---D | M] (DictionarySearch) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}(2)
[2010.06.07 15:22:21 | 000,000,000 | ---D | M] (FireFTP) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2010.09.01 13:54:51 | 000,000,000 | ---D | M] (Password Exporter) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2008.03.13 21:48:20 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
[2010.03.12 18:02:26 | 000,000,000 | ---D | M] (Web Developer) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010.09.01 13:54:50 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010.06.23 19:06:15 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2008.10.10 23:42:43 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{dc572301-7619-498c-a57d-39143191b318}(2)
[2010.06.07 15:22:23 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010.01.23 20:58:38 | 000,000,000 | ---D | M] (Clipmarks) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
[2010.04.09 17:27:54 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010.08.18 22:54:05 | 000,000,000 | ---D | M] (ViewSourceWith) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\{eecba28f-b68b-4b3a-b501-6ce12e6b8696}
[2010.09.08 17:56:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\de_DE@dicts.j3e.de
[2010.02.19 13:03:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2007.10.23 10:03:51 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\en-GB@dictionaries.addons.mozilla.org
[2008.03.13 21:48:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\en-US@dictionaries.addons.mozilla(2).org
[2010.10.01 13:39:51 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\es-es@dictionaries.addons.mozilla.org
[2010.01.14 21:47:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\fb_add_on@avm.de
[2010.05.07 13:38:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\firebug@software.joehewitt.com
[2010.02.10 22:21:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\fr-FR@dictionaries.addons.mozilla.org
[2010.09.08 17:56:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\fr-moderne@dictionaries.addons.mozilla.org
[2010.09.16 14:28:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\ietab@ip.cn
[2007.10.23 10:03:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\it-IT@dictionaries.addons.mozilla.org
[2010.09.06 22:42:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\metatags@porton.ex-code.com
[2010.01.29 15:55:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\pagecompare_abk0680@yahoo.com
[2010.09.24 19:14:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\pt-PT@dictionaries.addons.mozilla.org
[2009.04.11 23:26:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\savecomplete@perlprogrammer.com
[2006.12.11 16:37:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\temp
[2010.02.10 22:21:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\extensions\tsvnmenu@pumacode.org
[2010.09.24 19:25:08 | 000,001,089 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\astalavista.xml
[2010.03.05 17:18:24 | 000,002,058 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\astalavistams.xml
[2006.11.17 20:43:24 | 000,002,088 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\flickr-tags.xml
[2009.07.02 10:25:13 | 000,001,157 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\freedict.xml
[2008.05.27 10:18:53 | 000,002,161 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\google-deutschland.xml
[2006.11.17 20:45:13 | 000,001,679 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\imdb.xml
[2010.09.24 19:25:08 | 000,002,008 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\leo-de-en.xml
[2010.09.24 19:25:08 | 000,002,016 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\leo-de-es.xml
[2010.09.24 19:25:08 | 000,002,020 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\leo-de-fr.xml
[2008.06.03 11:49:07 | 000,001,082 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\lonely-planet-online.xml
[2010.09.24 19:25:08 | 000,001,481 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\map24de.xml
[2008.06.03 11:49:06 | 000,001,317 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\wikipedia-en.xml
[2010.08.15 16:04:13 | 000,004,140 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\dv1sjd5g.default\searchplugins\youtube.xml
 
O1 HOSTS File: ([2004.08.04 05:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - No CLSID value found.
O3 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ACTray] C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
O4 - HKLM..\Run: [ACWLIcon] C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [avast5] C:\Programme\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BLOG] C:\Programme\ThinkPad\Utilities\BATLOGEX.DLL ()
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\dla\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [EZEJMNAP] C:\Programme\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
O4 - HKLM..\Run: [FinePrint Dispatcher v4] C:\WINDOWS\system32\spool\drivers\w32x86\2\fpdisp4.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [ibmmessages] C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKLM..\Run: [IBMPRC] C:\IBMTOOLS\utils\ibmprc.exe (IBM Corp.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [KernelFaultCheck]  File not found
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Programme\Logitech\QuickCam10\QuickCam10.exe ()
O4 - HKLM..\Run: [Message Center Plus] C:\Programme\LENOVO\Message Center Plus\MCPLaunch.exe ()
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Programme\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [Microsoft Works Update Detection] C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [PWRMGRTR] C:\Programme\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [RemoteControl] C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SmcService] C:\Programme\Sygate\SPF\Smc.exe (Sygate Technologies, Inc.)
O4 - HKLM..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe (Sonix)
O4 - HKLM..\Run: [SoundMAX] C:\Programme\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [TkBellExe] C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TortoiseHgOverlayIconServer] C:\Programme\TortoiseHg\TortoiseHgOverlayServer.exe ()
O4 - HKLM..\Run: [TP4EX] C:\WINDOWS\System32\TP4EX.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe ()
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Programme\ThinkPad\Utilities\TpKmapAp.exe (IBM Corp.)
O4 - HKLM..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe (In-System Design, Inc.)
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe (SONIX)
O4 - HKLM..\Run: [TVT Scheduler Proxy] C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
O4 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005..\Run: [AVMUSBFernanschluss] C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\AVMAutoStart.exe (AVM Berlin)
O4 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005..\Run: [IBM RecordNow!] C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005..\Run: [ibmmessages] C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005..\Run: [Microsoft Works Update Detection] C:\Programme\Microsoft Works\WkDetect.exe File not found
O4 - HKU\.DEFAULT..\RunOnce: [IETI] C:\Programme\Skype\Phone\IEPlugin\unins000.exe File not found
O4 - HKU\.DEFAULT..\RunOnce: [WUAppSetup] C:\Programme\Gemeinsame Dateien\logishrd\WUApp32.exe -v 0x046d -p 0x08c3 -f video -m logitech -d 11.0.0.1217 File not found
O4 - HKU\S-1-5-18..\RunOnce: [IETI] C:\Programme\Skype\Phone\IEPlugin\unins000.exe File not found
O4 - HKU\S-1-5-18..\RunOnce: [WUAppSetup] C:\Programme\Gemeinsame Dateien\logishrd\WUApp32.exe -v 0x046d -p 0x08c3 -f video -m logitech -d 11.0.0.1217 File not found
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\BTTray.lnk = C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\EPSON SMART PANEL.lnk = C:\Programme\EPSON\SMART PANEL\SmaPanel.exe (NewSoft)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Erinnerungen in Microsoft Works-Kalender.lnk = C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Fax-Controller.lnk = C:\Programme\EPSON\SMART PANEL\faxicore.exe (NewSoft Technology Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Telefonverbindungsmonitor.lnk = C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe (Teleca Software Solutions AB)
O4 - Startup: C:\Dokumente und Einstellungen\***\Startmenü\Programme\Autostart\FRITZ!DSL Protect.lnk = C:\Programme\FRITZ!DSL\FwebProt.exe (AVM Berlin)
O4 - Startup: C:\Dokumente und Einstellungen\***\Startmenü\Programme\Autostart\FRITZ!DSL Startcenter.lnk = C:\Programme\FRITZ!DSL\StCenter.exe (AVM Berlin)
O4 - Startup: C:\Dokumente und Einstellungen\***\Startmenü\Programme\Autostart\HotSync Manager.lnk = C:\Programme\Palm\Handspring\HOTSYNC.EXE (Palm, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00  [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00  [binary data]
O7 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Senden an Bluetooth - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\FRITZ!DSL\\sarah.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O15 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} hxxp://www.alternatiff.com/install-ie/alttiff.cab (AlternaTIFF ActiveX)
O16 - DPF: {15A7CF10-CB3E-4265-8779-9FD22619E8ED} hxxp://192.168.1.205/XPanel.cab (XPanel Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} hxxp://www-307.ibm.com/pc/support/acpir.cab (IASRunner Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1164927521531 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} hxxp://java.sun.com/products/plugin/1.4.2/jinstall-142-win.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {F74959B0-1779-472E-BE6E-3023E1DBEC73} hxxp://192.168.1.205/XInit.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ACNotify: DllName - ACNotify.dll - C:\Programme\ThinkPad\ConnectUtilities\ACNotify.dll (Lenovo )
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\tpfnf2: DllName - C:\Programme\Lenovo\HOTKEY\notifyf2.dll - C:\Programme\Lenovo\HOTKEY\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - C:\Programme\Lenovo\HOTKEY\tphklock.dll - C:\Programme\Lenovo\HOTKEY\tphklock.dll ()
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.27 10:02:05 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\autoexec.rod -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\AUTOEXEC.ICR -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\autoexec.rod -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\AUTOEXEC.ICR -- [ FAT32 ]
O33 - MountPoints2\{12570190-b56a-11dc-ab3d-000e9bda3b35}\Shell - "" = AutoRun
O33 - MountPoints2\{12570190-b56a-11dc-ab3d-000e9bda3b35}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{12570190-b56a-11dc-ab3d-000e9bda3b35}\Shell\AutoRun\command - "" = F:\pushinst.exe -- File not found
O33 - MountPoints2\{91a2d536-d712-11db-aaea-000e9bda3b35}\Shell - "" = AutoRun
O33 - MountPoints2\{91a2d536-d712-11db-aaea-000e9bda3b35}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{91a2d536-d712-11db-aaea-000e9bda3b35}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{91a2d537-d712-11db-aaea-000e9bda3b35}\Shell\AutoRun\command - "" = G:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe -- File not found
O33 - MountPoints2\{f4f57244-35da-11de-9605-00505b002aa8}\Shell - "" = AutoRun
O33 - MountPoints2\{f4f57244-35da-11de-9605-00505b002aa8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f4f57244-35da-11de-9605-00505b002aa8}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O34 - HKLM BootExecute: (pgdfgsvc c 1) - C:\WINDOWS\System32\pgdfgsvc.exe (Sysinternals - www.sysinternals.com)
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.09.16 18:36:50 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Malwarebytes
[2010.09.16 18:36:33 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.09.16 18:36:31 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.09.16 18:36:31 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2010.09.16 18:36:30 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2010.09.09 01:36:21 | 000,165,584 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010.09.09 01:36:21 | 000,017,744 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010.09.09 01:36:20 | 000,023,376 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010.09.09 01:36:19 | 000,046,672 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010.09.09 01:36:18 | 000,100,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010.09.09 01:36:18 | 000,094,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010.09.09 01:36:17 | 000,028,880 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010.09.09 01:36:05 | 000,167,592 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010.09.09 01:36:05 | 000,038,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010.09.09 01:35:57 | 000,000,000 | ---D | C] -- C:\Programme\Alwil Software
[2010.09.09 01:35:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Alwil Software
[2010.09.08 11:17:46 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2010.09.08 11:17:46 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2010.09.07 00:34:37 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\xing shared
[2010.09.07 00:01:40 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.09.07 00:01:40 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.09.07 00:01:40 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2007.12.13 22:41:16 | 000,151,552 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnp2std.dll
[2007.12.13 22:41:14 | 000,077,824 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2std.dll
[2006.11.14 01:13:40 | 000,021,866 | ---- | C] (In-System Design, Inc.) -- C:\Programme\Gemeinsame Dateien\tppupd2k.dll
[2004.11.24 21:25:52 | 000,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010.10.01 13:47:00 | 000,001,082 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.09.30 22:49:19 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.09.30 22:47:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.09.30 22:47:06 | 2145,832,960 | -HS- | M] () -- C:\hiberfil.sys
[2010.09.30 20:31:58 | 000,000,300 | -HS- | M] () -- C:\Dokumente und Einstellungen\***\ntuser.ini
[2010.09.30 20:31:34 | 001,445,318 | -H-- | M] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\IconCache.db
[2010.09.30 20:09:02 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.09.30 20:01:24 | 000,000,296 | ---- | M] () -- C:\WINDOWS\tasks\PMTask.job
[2010.09.30 20:00:58 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.09.29 22:47:00 | 000,001,078 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.09.29 10:09:09 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.09.28 21:47:58 | 015,990,784 | ---- | M] () -- C:\Dokumente und Einstellungen\***\ntuser.dat
[2010.09.28 21:46:38 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-999901472-3601035388-3065584919-1005.job
[2010.09.28 21:46:37 | 000,000,274 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-999901472-3601035388-3065584919-1005.job
[2010.09.20 19:45:17 | 000,001,797 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Logitech QuickCam.lnk
[2010.09.15 23:05:35 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.09.09 01:36:22 | 000,001,672 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\avast! Free Antivirus.lnk
[2010.09.09 01:36:18 | 000,003,002 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010.09.08 11:17:46 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2010.09.08 11:17:46 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2010.09.07 17:12:17 | 000,038,848 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010.09.07 17:11:54 | 000,167,592 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010.09.07 16:52:25 | 000,046,672 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010.09.07 16:52:03 | 000,165,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010.09.07 16:47:46 | 000,023,376 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010.09.07 16:47:19 | 000,100,176 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010.09.07 16:47:16 | 000,094,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010.09.07 16:47:07 | 000,017,744 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010.09.07 16:46:51 | 000,028,880 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010.09.07 00:35:47 | 000,000,821 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\RealPlayer SP.lnk
[2010.09.07 00:35:17 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2010.09.07 00:34:54 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2010.09.07 00:34:54 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2010.09.07 00:33:10 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2010.09.07 00:10:45 | 000,001,717 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2010.09.02 00:07:28 | 000,168,088 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
[2010.09.02 00:04:08 | 000,505,008 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.09.01 22:37:21 | 000,000,699 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.09.09 01:36:22 | 000,001,672 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\avast! Free Antivirus.lnk
[2010.09.07 00:35:47 | 000,000,821 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\RealPlayer SP.lnk
[2010.09.01 22:37:21 | 000,000,699 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
[2010.04.13 21:40:03 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\EuEpmGdi.dll
[2010.04.13 21:40:03 | 000,013,192 | ---- | C] () -- C:\WINDOWS\System32\epmntdrv.sys
[2010.04.13 21:40:03 | 000,008,456 | ---- | C] () -- C:\WINDOWS\System32\EuGdiDrv.sys
[2010.04.12 01:17:54 | 000,000,600 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\winscp.rnd
[2009.10.21 03:54:22 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2009.10.17 01:55:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2009.10.06 09:11:50 | 000,091,648 | ---- | C] () -- C:\WINDOWS\System32\lua5.1a.dll
[2009.04.11 21:25:54 | 000,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008.12.19 18:51:56 | 000,000,734 | ---- | C] () -- C:\WINDOWS\wiso.ini
[2008.11.19 17:39:26 | 000,000,011 | ---- | C] () -- C:\WINDOWS\cmvpt32.ini
[2008.11.19 17:38:46 | 000,884,736 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2008.11.19 17:38:46 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\SSLeay32.dll
[2008.11.19 10:53:59 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\GCL52FW.DLL
[2008.11.19 10:48:43 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\Cmpnl32.dll
[2008.11.19 10:48:43 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\GCL52FWZ.DLL
[2008.11.19 10:48:42 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\CMUpdate.dll
[2008.03.20 23:39:08 | 000,000,030 | ---- | C] () -- C:\Programme\Exiferupdate.ini
[2008.03.03 00:55:21 | 000,661,504 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008.03.03 00:55:21 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2008.03.03 00:55:21 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008.03.03 00:55:21 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008.03.03 00:55:21 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\ffavisynth.dll
[2008.03.03 00:55:20 | 000,397,312 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2008.03.03 00:55:20 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2008.03.03 00:55:20 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2008.03.03 00:55:20 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2008.03.03 00:55:20 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\ff_realaac.dll
[2008.03.03 00:55:20 | 000,102,912 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2008.03.03 00:55:20 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2008.03.03 00:55:20 | 000,054,784 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2008.02.14 14:55:42 | 000,000,032 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ezsid.dat
[2008.01.14 20:50:44 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ZSubTimer.dll
[2008.01.10 13:40:29 | 000,015,360 | ---- | C] () -- C:\WINDOWS\System32\evntmsg.dll
[2008.01.04 16:13:58 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\DEVMAN.DLL
[2007.12.24 13:47:52 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007.12.24 13:40:26 | 000,405,504 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z444.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z443.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z442.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z440.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z439.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z438.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z437.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z436.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z435.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z434.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z433.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z432.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z444U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z443U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z442U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z440U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z439U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z438U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z437U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z436U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z435U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z434U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z433U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z432U.dll
[2007.12.22 22:02:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2007.12.22 21:27:22 | 003,138,048 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2007.12.13 22:41:22 | 000,015,497 | ---- | C] () -- C:\WINDOWS\snp2std.ini
[2007.12.13 22:41:20 | 000,025,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\sncamd.sys
[2007.12.13 22:41:19 | 012,039,552 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2sxp.sys
[2007.12.13 19:18:03 | 000,000,719 | R--- | C] () -- C:\WINDOWS\System32\InstExec.ini
[2007.12.13 19:17:25 | 000,057,126 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007.12.07 16:15:39 | 000,001,260 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2007.12.03 16:34:32 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2007.12.01 13:43:30 | 000,541,696 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2007.11.29 12:52:36 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007.11.26 16:56:04 | 002,842,624 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2007.11.26 16:43:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2007.09.04 23:56:09 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007.09.04 23:44:27 | 000,198,144 | ---- | C] () -- C:\WINDOWS\System32\_psisdecd.dll
[2007.02.27 18:12:06 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\USBaccess.dll
[2007.02.06 18:45:04 | 000,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007.02.06 18:42:40 | 001,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
[2007.01.29 00:03:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\IROTVIEW.INI
[2007.01.28 21:23:40 | 000,000,275 | ---- | C] () -- C:\WINDOWS\ddespy.ini
[2007.01.10 14:00:41 | 000,001,571 | ---- | C] () -- C:\WINDOWS\Faxcpp1.ini
[2007.01.10 14:00:41 | 000,000,422 | ---- | C] () -- C:\WINDOWS\Faxcpp.ini
[2007.01.10 12:52:58 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2006.12.30 20:09:45 | 000,000,240 | ---- | C] () -- C:\WINDOWS\BUHL.INI
[2006.12.24 23:39:33 | 000,000,040 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2006.12.24 22:11:08 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2006.12.21 02:21:58 | 000,144,656 | ---- | C] () -- C:\WINDOWS\System32\FAMCOM.dll
[2006.12.20 22:10:03 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\Gif89.dll
[2006.12.19 18:39:09 | 000,110,642 | ---- | C] () -- C:\WINDOWS\System32\pdfmona.dll
[2006.12.19 18:39:09 | 000,043,252 | ---- | C] () -- C:\WINDOWS\System32\pdfmon.dll
[2006.12.09 02:04:03 | 000,000,687 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006.11.30 22:27:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\FoneSync.INI
[2006.11.30 18:30:30 | 000,000,126 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2006.11.30 17:45:46 | 000,000,037 | ---- | C] () -- C:\WINDOWS\Viewer.ini
[2006.11.30 17:38:48 | 000,000,151 | ---- | C] () -- C:\WINDOWS\ccard100.ini
[2006.11.30 17:37:13 | 000,007,901 | ---- | C] () -- C:\WINDOWS\MSACC20.INI
[2006.11.30 17:30:38 | 000,001,245 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006.11.30 17:30:38 | 000,000,061 | ---- | C] () -- C:\WINDOWS\odbcisam.ini
[2006.11.30 17:30:37 | 000,000,914 | ---- | C] () -- C:\WINDOWS\MSOFFICE.INI
[2006.11.30 17:30:29 | 000,000,124 | ---- | C] () -- C:\WINDOWS\GRAPH5.INI
[2006.11.30 17:30:21 | 000,002,640 | ---- | C] () -- C:\WINDOWS\WINWORD6.INI
[2006.11.30 17:30:18 | 000,000,329 | ---- | C] () -- C:\WINDOWS\EXCEL5.INI
[2006.11.30 17:30:17 | 000,000,239 | ---- | C] () -- C:\WINDOWS\Winhelp.ini
[2006.11.30 17:30:17 | 000,000,110 | ---- | C] () -- C:\WINDOWS\msquery.ini
[2006.11.30 17:30:08 | 000,000,535 | ---- | C] () -- C:\WINDOWS\MSTXTCNV.INI
[2006.11.30 17:30:06 | 000,002,122 | ---- | C] () -- C:\WINDOWS\MSFNTMAP.INI
[2006.11.30 17:30:06 | 000,000,280 | ---- | C] () -- C:\WINDOWS\TTEMBED.INI
[2006.11.30 15:01:49 | 000,000,266 | ---- | C] () -- C:\WINDOWS\VISITE.INI
[2006.11.30 15:00:13 | 000,005,230 | ---- | C] () -- C:\WINDOWS\TOPDRAW.INI
[2006.11.30 14:26:24 | 000,112,688 | ---- | C] () -- C:\WINDOWS\System32\shw32.dll
[2006.11.29 18:34:56 | 000,000,044 | ---- | C] () -- C:\WINDOWS\SMWizard.INI
[2006.11.16 23:01:57 | 000,003,776 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006.11.14 02:05:27 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2006.11.13 00:24:27 | 000,015,576 | R--- | C] () -- C:\WINDOWS\System32\drivers\usbbc.sys
[2006.11.13 00:24:27 | 000,003,953 | R--- | C] () -- C:\WINDOWS\System32\coinst.dll
[2006.11.10 23:55:40 | 000,096,768 | ---- | C] () -- C:\WINDOWS\SlantAdj.dll
[2006.10.11 12:18:40 | 000,078,336 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006.10.10 09:46:17 | 000,003,252 | ---- | C] () -- C:\WINDOWS\System32\drivers\PQNTDRV.SYS
[2006.10.10 04:14:04 | 000,000,092 | ---- | C] () -- C:\WINDOWS\System32\ftdiun2k.ini
[2006.09.27 10:01:53 | 000,000,136 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2006.09.26 01:14:35 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006.09.26 01:13:47 | 000,004,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2006.09.26 01:10:01 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
[2006.09.26 01:09:38 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2006.09.26 01:09:38 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2006.09.26 01:09:10 | 000,004,224 | ---- | C] () -- C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2006.09.26 01:02:33 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006.09.26 01:02:33 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006.09.26 01:02:33 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006.09.26 01:02:33 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006.09.26 01:02:33 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006.09.26 01:02:33 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006.09.26 01:02:00 | 000,000,642 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006.09.26 00:53:24 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\FPCALL.dll
[2006.09.26 00:53:07 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2006.09.26 00:50:44 | 000,009,343 | ---- | C] () -- C:\WINDOWS\System32\drivers\TDSMAPI.SYS
[2006.09.26 00:39:34 | 000,002,458 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006.09.26 00:32:23 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\tphklock.dll
[2006.06.09 11:43:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005.09.01 14:11:52 | 000,016,768 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPrcMon.sys
[2005.07.06 00:45:08 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\notifyf2.dll
[2005.02.17 12:41:32 | 000,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005.02.17 12:41:30 | 000,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2004.12.16 03:41:58 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\pwdmon.dll
[2004.12.16 03:41:58 | 000,019,853 | ---- | C] () -- C:\WINDOWS\ibmprc.ini
[2004.10.15 19:31:56 | 000,218,264 | ---- | C] () -- C:\WINDOWS\System32\SetAid.dll
[2004.10.03 19:50:54 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004.08.10 13:48:32 | 000,000,849 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004.01.09 06:10:32 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\AIBMRUNL.dll
[2001.11.14 13:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1999.04.29 22:00:00 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998.04.24 01:00:00 | 000,000,218 | ---- | C] () -- C:\WINDOWS\FRONTPG.INI
[1996.04.03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
< End of report >


Herzmann 01.10.2010 13:09

Extras.txt:
[CODE]14:00 01.10.2010OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 01.10.2010 13:50:42 - Run 2
OTL by OldTimer - Version 3.2.14.1    Folder = E:\Software\Ab 17.04.2009\Download\Sicherheit
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 45,00% Memory free
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 61,00% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1536 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 59,53 Gb Total Space | 5,38 Gb Free Space | 9,04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 46,18 Gb Total Space | 2,20 Gb Free Space | 4,77% Space Free | Partition Type: FAT32
Drive F: | 4,00 Gb Total Space | 0,45 Gb Free Space | 11,32% Space Free | Partition Type: FAT32
Drive G: | 4,01 Gb Total Space | 0,46 Gb Free Space | 11,49% Space Free | Partition Type: FAT32
Drive H: | 25,27 Gb Total Space | 4,47 Gb Free Space | 17,68% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
 
Computer Name: XXX
Current User Name: ***
NOT logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla\Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Programme\Mozilla\Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Programme\Mozilla\Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Durchsuchen mit &IrfanView] -- "C:\Programme\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"6198:TCP" = 6198:TCP:*:Enabled:freenetSPEED
"3126:TCP" = 3126:TCP:*:Enabled:freenetSPEED
"3128:TCP" = 3128:TCP:*:Enabled:freenetSPEED
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Programme\IBM\Updater\jre\bin\java.exe" = C:\Programme\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\jre\bin\javaw.exe" = C:\Programme\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\ucsmb.exe" = C:\Programme\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector -- File not found
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Programme\IBM\Updater\jre\bin\java.exe" = C:\Programme\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\jre\bin\javaw.exe" = C:\Programme\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\ucsmb.exe" = C:\Programme\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector -- File not found
"D:\fsetup.exe" = D:\fsetup.exe:*:Enabled:AVM FSetup Application -- File not found
"C:\Programme\freenet\PxClient.exe" = C:\Programme\freenet\PxClient.exe:*:Enabled:freenetSPEED -- File not found
"C:\Programme\VoipDiscount.com\VoipDiscount\VoipDiscount.exe" = C:\Programme\VoipDiscount.com\VoipDiscount\VoipDiscount.exe:*:Enabled:VoipDiscount -- (VoipDiscount)
"C:\Programme\Mozilla Thunderbird\thunderbird.exe" = C:\Programme\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Mozilla Thunderbird -- (Mozilla Messaging)
"C:\Programme\Intuwave Ltd\Shared\mRouterRunTime\mRouterRuntime.exe" = C:\Programme\Intuwave Ltd\Shared\mRouterRunTime\mRouterRuntime.exe:*:Enabled:mRouterRuntime -- (Intuwave Ltd.)
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft  Fax Console -- (Microsoft Corporation)
"C:\Programme\Java\jdk1.6.0_01\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_01\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe" = C:\Programme\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe:*:Enabled:mysqld-nt -- ()
"C:\Programme\Java\jdk1.6.0_01\bin\java.exe" = C:\Programme\Java\jdk1.6.0_01\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Java\jdk1.6.0\bin\java.exe" = C:\Programme\Java\jdk1.6.0\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\FRITZ!DSL\FBOXUPD.EXE" = C:\Programme\FRITZ!DSL\FBOXUPD.EXE:*:Enabled:AVM FRITZ!Box Firmware-Update -- (AVM Berlin)
"C:\Programme\Java\jdk1.6.0_02\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_02\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Home Cinema\PowerCinema\PowerCinema.exe" = C:\Programme\Home Cinema\PowerCinema\PowerCinema.exe:*:Enabled:PowerCinema -- File not found
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_147a792107b9f781\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_147a792107b9f781\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Programme\WS_FTP\WS_FTP95.exe" = C:\Programme\WS_FTP\WS_FTP95.exe:*:Enabled:WS_FTP 95 -- (Ipswitch, Inc. 81 Hartwell Ave. Lexington, MA)
"C:\Programme\Java\jdk1.6.0_03\bin\java.exe" = C:\Programme\Java\jdk1.6.0_03\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Programme\Java\jdk1.6.0_03\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_03\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Programme\Java\jre1.6.0_03\bin\java.exe" = C:\Programme\Java\jre1.6.0_03\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Java\NetBeans 6.0 RC2\mobility8\WTK2.5.2\bin\emulator.exe" = C:\Programme\Java\NetBeans 6.0 RC2\mobility8\WTK2.5.2\bin\emulator.exe:*:Enabled:emulator -- File not found
"C:\Programme\Java\WTK22\bin\emulator.exe" = C:\Programme\Java\WTK22\bin\emulator.exe:*:Enabled:emulator -- ()
"C:\Programme\Java\NetBeans 6.0\mobility8\WTK2.5.2\bin\emulator.exe" = C:\Programme\Java\NetBeans 6.0\mobility8\WTK2.5.2\bin\emulator.exe:*:Enabled:emulator -- File not found
"C:\Programme\FRITZ!DSL\IGDCTRL.EXE" = C:\Programme\FRITZ!DSL\IGDCTRL.EXE:*:Enabled:AVM FRITZ!DSL - igdctrl.exe -- (AVM Berlin)
"C:\Programme\FRITZ!DSL\WebwaIgd.exe" = C:\Programme\FRITZ!DSL\WebwaIgd.exe:*:Enabled:AVM FRITZ!DSL - webwaigd.exe -- (AVM Berlin)
"C:\Programme\uTorrent\uTorrent.exe" = C:\Programme\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- File not found
"C:\Programme\Sony Ericsson\Update Service\ma3platform.exe" = C:\Programme\Sony Ericsson\Update Service\ma3platform.exe:*:Enabled:ma3platform -- File not found
"C:\Programme\Sony Ericsson\Update Service\Update Service.exe" = C:\Programme\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service -- File not found
"C:\Programme\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe" = C:\Programme\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.0 -- (Sony Creative Software Inc.)
"C:\Programme\Java\jdk1.6.0_04\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_04\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0e9add42c1\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0e9add42c1\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Programme\Java\jre1.6.0_04\bin\javaw.exe" = C:\Programme\Java\jre1.6.0_04\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Program Files\IBM\Java142\jre\bin\javaw.exe" = C:\Program Files\IBM\Java142\jre\bin\javaw.exe:*:Enabled:Java launcher -- (IBM)
"C:\Programme\Mozilla\Firefox\firefox.exe" = C:\Programme\Mozilla\Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Programme\Java\jdk1.6.0_06\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_06\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0f9b5c5281\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0f9b5c5281\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Programme\Java\jdk1.6.0_07\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_07\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Real\RealPlayer\realplay.exe" = C:\Programme\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- File not found
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf139d589181\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf139d589181\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf149dd7a141\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf149dd7a141\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- (AVM Berlin)
"C:\Programme\Java\jre6\bin\java.exe" = C:\Programme\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"C:\Programme\Java\jre6\bin\javaw.exe" = C:\Programme\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- (AVM Berlin)
"C:\WINDOWS\LMI35.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI35.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI60.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI60.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI33D.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI33D.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI3B2.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI3B2.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI3B7.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI3B7.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\Programme\BitTorrent\bittorrent.exe" = C:\Programme\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Programme\FRITZ!Box Monitor\FRITZBoxMonitor.exe" = C:\Programme\FRITZ!Box Monitor\FRITZBoxMonitor.exe:*:Enabled:FRITZ!Box Monitor -- (AVM Berlin)
"C:\Programme\FRITZ!vox\Fritz!vox.exe" = C:\Programme\FRITZ!vox\Fritz!vox.exe:*:Enabled:Fritz!vox -- (AVM Berlin)
"C:\CYGWIN\bin\rsync.exe" = C:\CYGWIN\bin\rsync.exe:*:Enabled:rsync -- ()
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000407-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium
"{00170407-78E1-11D2-B60F-006097C998E7}" = Microsoft Word 2000 SR-1
"{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}" = Java DB 10.5.3.0
"{01008202-823E-46CD-A70E-BEE818F97169}" = Microsoft Encarta Enzyklopädie 2002
"{01DA3FC4-CF94-4AAD-9127-C8F2E09F6E69}" = PowerArchiver 2010
"{024D73F0-1C49-2340-8AC3-5234AAA560C0}" = ccc-core-static
"{03B1BBDC-7FAA-4A03-9988-A85428BAD382}" = Sun ODF Plugin for Microsoft Office 3.0
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{05E9F134-07C9-4249-9B80-EE5D975F201B}" = Sony Ericsson Image Editor
"{0873B1A3-00A9-40D6-BACE-3DB4BC5DA840}" = ThinkPad SATA Power Management Driver
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Systemsteuerung
"{0D05C1D4-BB4C-4545-86DC-F5EA7D04121A}" = Vtpro-e Themes v1.3
"{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}" = HP USB Disk Storage Format Tool
"{1007F41F-7D69-468E-8017-3849A5A973C2}" = IBM ThinkVantage Technologies Welcome Message
"{11783F13-C3A9-44A8-929B-21A476F65272}" = IBM Rescue and Recovery with Rapid Restore
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1297C681-92D7-40EF-93BF-03F66EC5105C}" = ThinkPad-Dienstprogramm 'EasyEject'
"{13EDFFFE-DCF2-448A-A653-3C4CD60D99B4}" = Palm Desktop and Synchronization Software
"{1649C93D-C661-4C53-B8AE-DB3592150B34}" = Buhl finance - tax 2006 Professional
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = ThinkPad UltraNav Utility
"{1E5007FA-DA5E-4EDD-BDE5-14D128D66887}" = PowerQuest PartitionMagic 7.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = Dienstprogramm 'IBM ThinkPad-Tastaturanpassung'
"{23170F69-40C1-2701-0465-000001000000}" = 7-Zip 4.65
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{2457326B-C110-40C3-89B0-889CC913871A}" = AVM FRITZ!DSL
"{24F9E04D-4CD5-3979-76F9-C1C6E78471AB}" = CCC Help Italian
"{25F60491-F5AB-4985-9354-37C146783F35}" = Microsoft Works Suite-Add-Ins für Microsoft Word
"{2604C0F9-BFD3-4BA0-9EB5-22537C648F03}" = MobileMe Control Panel
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 21
"{2D230139-69DA-4CE8-83FB-EE5F522D2FF5}" = Praesideo Logging Server V2.32.1757
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator
"{2FEB25F8-C3CB-49A2-AE79-DE17FFAFB5D9}" = MySQL Server 5.0
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 3.108.00
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{31E1050B-F69F-4A16-8F5A-E44D31901250}" = Ulead DVD DiskRecorder 2.1.1
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{32A3A4F4-B792-11D6-A78A-00B0D0150100}" = J2SE Development Kit 5.0 Update 10
"{32A3A4F4-B792-11D6-A78A-00B0D0160030}" = Java(TM) SE Development Kit 6 Update 3
"{32A3A4F4-B792-11D6-A78A-00B0D0160180}" = Java(TM) SE Development Kit 6 Update 18
"{32A3A4F4-B792-11D6-A78A-00B0D0160200}" = Java(TM) SE Development Kit 6 Update 20
"{32A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java(TM) SE Development Kit 7
"{3305E24F-1192-0424-8A25-39713FD92728}" = Skins
"{34F0D55F-C386-4195-9A5B-961D3F6ACD46}" = InterVideo MediaOne Gallery
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B94A56F-9FDA-46CC-A3B6-07613A84200B}" = Buhl finance - tax 2007 Professional
"{3D289CAC-AD9F-45d9-9D36-524EB7B6C958}" = Lenovo Hard Drive Quick Test
"{3DA7A736-0B03-565C-1139-83FE890F0AF3}" = CCC Help French
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{3F71721C-E73D-481C-B926-C56B68D8F388}" = Praesideo Open Interface Library V2.32.1757
"{437C19B3-7E20-4E39-B868-CA6BAA820E1C}" = Microsoft Rechner-Plus
"{43A1FE83-D39F-3779-8D48-D6D19EE7AC48}" = CCC Help Chinese Traditional
"{443CBE24-0679-4027-9C36-66F129E009C5}" = Crestron Database
"{448AB2CB-C94A-47DE-80B8-9D7824DEFA57}" = Ulead FilmBrennerei 4.0
"{44B32F92-5A96-43D9-BCBE-0AD2CDC409E7}" = TortoiseHg 1.1.3 (x86)
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage System für aktiven Festplattenschutz
"{47CF8B92-4083-4F43-9680-6EDE10F812BD}" = Praesideo Logging Viewer V2.32.1757
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{55C28EF3-2EA3-46AB-B1E7-54B96C5A6921}" = Viewport v3.99.01
"{57FA0525-01F9-4051-8DE9-CBF43CAC68D9}" = Catalyst Control Center - Branding
"{5C72622B-643D-4296-B57D-5D53D0C68509}" = Sony Ericsson Media Manager 1.0
"{5D73F169-DD54-4C74-AEB0-CE72A4ED95E6}" = Algo Vision LuraTech Browser Plug-ins
"{5DE1B7CF-7429-40CA-987F-6BEE09B63787}" = Prime95
"{5F71EB81-C72E-4B28-8D90-FDEECFEBC2DE}" = Drive Image
"{61A17AE1-B4C3-4FC0-8563-684C23CBFA0F}" = SW-Entwicklung\Sun Java (TM) Wireless Toolkit 2.5.2 for CLDC
"{63F817ED-F710-481B-B332-7A356CE04E10}" = TortoiseOverlays
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6686F38D-1A32-4A8C-94D7-A2AA9C5F3C9B}" = Crestron Device Database
"{66CA5E58-0D03-A75D-16EF-68258DE0DFC3}" = CCC Help English
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BC292E6-5C85-4620-C1D0-A2FEAFD5D135}" = CCC Help Japanese
"{6C31E111-96BB-4ADC-9C81-E6D3EEDDD8D3}" = Powertoys For Windows XP
"{6CE96A14-61E2-48CC-837E-22710A953ADE}" = IBM Themes
"{7005C601-B415-4D77-B2ED-FF40E3DACDED}" = DEAL for Windows v4.00
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{735DEB9C-61BD-4D31-994B-92395BBB4E45}" = Microsoft XML Parser
"{75438C0E-9925-412E-AD85-D0E71C6CE2ED}" = USB2.0 PC Camera (SN9C201&202)
"{7579A17B-0E6C-9EF3-D022-30729A24B399}" = CCC Help Chinese Standard
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7BAA2000-5B8D-66DD-DBE7-089671AC118B}" = ccc-utility
"{7C2BD022-2B09-1F6D-D6C1-AD2A591E7537}" = Catalyst Control Center Core Implementation
"{7D2370AC-D8E6-4996-986A-19824F8A167C}" = Logitech QuickCam
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{806DB796-7082-C63F-284E-62245284A417}" = CCC Help Dutch
"{808FAA20-4C3A-11D4-8A57-00201853C903}" = PC-Linq
"{82512BC9-BD5D-4C50-BE4D-B98E7DF78687}" = ThinkPad-UltraNav-Assistent
"{8398B542-3CC4-44D9-83DF-696CCE70124B}" = Windows Support Tools
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{8675339C-128C-44DD-83BF-0A5D6ABD8297}" = System Update
"{8745DEAB-1126-42F5-9585-C66D5497B47B}" = EMEA Wallpaper
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D0E26CF-AA2F-48FF-A533-6207DE50B1C4}_is1" = Agendus for Windows Palm Desktop Edition
"{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2
"{8EAB2384-C794-40ED-A9DD-3270A0D2BB76}" = Ulead VideoStudio 9.0
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{91AF774D-8506-4194-9B77-9D803CBF5AC1}" = SIMPL Windows v2.10
"{925936AC-9C9A-4897-874B-60961AAB6D52}" = Disc2Phone
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{984E0622-29E5-44EA-A075-A0CE91B2CF13}" = TortoiseOverlays
"{A0E64EBA-8BF0-49FB-90C0-BB3D781A2016}" = ThinkPad Energie-Manager
"{A1A903C9-35DE-4770-9264-5F831E0A3A2E}" = SIMPL Windows Library v565
"{A2092B2A-A4FB-4464-A4C0-023D2C9993F8}" =
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3E23D97-145F-29BF-81DE-DAEC1E5AB237}" = Catalyst Control Center Graphics Full New
"{A8FA2AC0-3875-B59F-917F-719982FB1BE8}" = CCC Help Portuguese
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA3983BF-9B72-484E-972A-E47BBAFA9CCA}" = VisionTools Pro-e v3.8
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.4 - Deutsch
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AC849092-6F19-4395-8860-BC3B82CAFE51}" = funScreenScraping Microsoft Systemdateien
"{AE1A0B0E-2EC7-656A-711A-0E7E8D4AB5CF}" = CCC Help Spanish
"{B016DE7B-CA2D-5EFD-9591-A109E67119BD}" = CCC Help Swedish
"{B214C3C8-FC16-42EC-B7BB-703A1BB9C790}" = Lenovo Battery Program
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B5FE8184-DB90-4642-826C-096C6369B3DA}" = J2ME Wireless Toolkit 2.2
"{B6826FA8-04C8-4147-AA3C-5B900AB887A1}" = PowerArchiver 2007
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU
"{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU
"{C4A92EF9-D14C-937F-742E-D272938DC590}" = CCC Help Korean
"{C769A271-7E1C-48F9-B331-474600DD4C06}" = Microsoft Picture It! Foto 2002
"{C7B8E06E-EBBC-4210-93AB-DFC8760E3FC9}" = Works Suite-Betriebssystem-Pack
"{C9A87D86-FDFD-418B-BF96-EF09320973B3}" = PC Inspector smart recovery
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CD6EB005-957A-4191-93ED-6ECD5F7F931E}" = SKTimeStamp
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFEDA22F-435D-4891-913A-75B80D8159B8}" = Crestron Toolbox v1.12
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D121161E-AD64-4438-97A0-66A1AB7FFDE3}" = Works Suite-Betriebssystem-Pack
"{D2FEBD11-E587-4C41-AD33-0CD90D26A964}" = Client für die Windows-Rechteverwaltung mit Service Pack 2
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow! 1.0
"{D5881E4A-0764-11D6-9D93-DECCF2B3F57C}" = Praesideo Core V2.32.1757
"{D5A9B7C0-8751-11D8-9D75-000129760D75}" = MediaShow 3.0
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7 Anniversary Edition
"{D702172D-8D17-D9EC-B661-42FA268575AF}" = Catalyst Control Center Localization All
"{DAA3F236-CEEC-C6CC-12C2-AB1B75C8BC09}" = CCC Help German
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DEC2C123-3CE0-4669-B119-61519130CACD}" = TortoiseSVN 1.6.10.19898 (32 bit)
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E09CEE8B-1DCD-C628-A8EA-2B56D61DDEFA}" = ccc-core-preinstall
"{E258A840-7E9A-443A-B156-67102C48BF17}" = TPP Storage Driver Installation
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9-Reihe
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{E922961C-6DB6-41DE-9FEA-426DF3E9F81C}" = IBM 32-bit Runtime Environment for Java 2, v1.4.2
"{EA664480-3844-11D5-8C25-444553540000}" = Funktion "TrackPoint-Eingabehilfen"
"{EC6AF20D-4376-4070-BEE4-D3A0DFF7E140}" = Access IBM
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Rückwärtskompatibilität des Clients für die Windows-Rechteverwaltung SP2
"{ED5EDCD0-5745-4B13-8061-58C9833FD06D}" = Microsoft Works 6.0
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F18B31E4-E2E3-4F4F-A2C9-BA579D6AF400}" = TortoiseOverlays
"{F2260E94-80F2-4CB1-B6B1-6043D9BFFA47}" = Works-Synchronisierung
"{F22FD942-651D-4EE8-BD6F-7E0AF5E17625}" = Intel(R) PROSet/Wireless WiFi-Software
"{F3439243-1BAC-7250-D346-2642655F95ED}" = Catalyst Control Center Graphics Full Existing
"{F34D9A5F-484A-4E31-A9D3-908CB265B289}" = Sygate Personal Firewall
"{F3FAE3D8-A91D-4D11-90C1-27581C2C23B9}" = Sony Ericsson MMS Home Studio
"{F413B3A4-EE5D-457C-BAE5-6E58D9589ED5}" = Access IBM Message Center
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F63E8666-0F10-11D3-8258-00C04F6843FE}" = Microsoft Visual Keyboard
"{F705E3E1-A471-426B-9A09-73429F3418EE}" = System Migration Assistant
"{F7F2DC0A-C22E-49AD-AD37-797309A54E7B}" = Microsoft AutoRoute 2002
"{FB97A745-D1E6-435D-B942-264E94F89938}" = SIMPL+ Cross Compiler
"{FC081D4D-DF1B-4CF1-B530-027E4118D846}" = ThinkPad-Konfiguration
"{FC18114B-05A0-11D6-8140-000102E745A6}" = PC Suite for P800
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FD331A3B-F7A5-4C31-B8D4-DF413C85AF7A}" = Message Center Plus
"{FD9D4CA5-8F97-44A0-B17E-C2C77C824FA4}" = funScreenScraping Client Version
"{FF2AFF73-099E-0BB5-AE87-B044D3D7DE78}" = Catalyst Control Center Graphics Light
"1&1 Upload-Manager" = 1&1 Upload-Manager
"274c5407c4fa26908310cb5c1c5500001224356439" = NetBeans IDE 5.5
"312f77fc8b5965949add215dd8550000-1163196496" = NetBeans Profiler 5.5
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"All ATI Software" = ATI - Dienstprogramm zur Deinstallation der Software
"Any Video Converter_is1" = Any Video Converter 3.0.3
"ATI Display Driver" = ATI Display Driver
"Attribute Manager_is1" = Attribute Manager 2.35
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.9 (Unicode)
"Audacity_is1" = Audacity 1.2.6
"avast5" = avast! Free Antivirus
"AVIcodec" = AVIcodec (remove only)
"Avira UnErase Personal" = Avira UnErase Personal
"AVMFBox" = AVM FRITZ!Box Dokumentation
"AVMFBoxAnswerMachine" = AVM FRITZ!vox
"AVMFBoxMonitor" = AVM FRITZ!Box Monitor
"BitTorrent" = BitTorrent
"CCleaner" = CCleaner
"CD Audio Reader Filter" = CD Audio Reader Filter (remove only)
"CDCheck" = CDCheck
"CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_05591014" = ThinkPad Integrated 56K Modem
"CollabNet Automatic Update" = CollabNet Automatic Update 1.2
"CollabNet Subversion Client" = CollabNet Subversion Client 1.6.12
"Corel Applications" = Corel Applications
"CvsConflictEditor_is1" = CvsConflictEditor 1.2.0
"CVSNT_is1" = CVSNT
"D2D77DC2-8299-11D1-8949-444553540000_is1" = WinCvs 2.0
"Defraggler" = Defraggler
"DiffUtils-2.8.7_is1" = GnuWin32: DiffUtils version 2.8.7
"Digital Image Recovery_is1" = Digital Image Recovery 1.47
"DirectVobSub" = DirectVobSub (remove only)
"doPDF 7 printer_is1" = doPDF 7.1 printer
"EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 5.5.1 Home Edition
"EPSON SMART PANEL" = EPSON SMART PANEL
"EPSON Stylus Scan" = EPSON Stylus Scan FB TWAIN
"EPSON-Drucker und Utilities" = EPSON-Drucker-Software
"Exact Audio Copy" = Exact Audio Copy 0.99pb5
"Exifer_is1" = Exifer
"fcd569e3a3b8ade0f9366fc6625500001796351737" = NetBeans Mobility Pack 5.5
"Feurio" = Feurio! CD-Writer
"ffdshow_is1" = ffdshow [rev 1868] [2008-02-22]
"FFmpeg for Audacity on Windows_is1" = FFmpeg for Audacity on Windows
"FinePrint 2000" = FinePrint 2000
"FinePrint2000" = FinePrint 2000
"FolderSizes_is1" = FolderSizes 1.0
"frndial" = freenet.de
"FTDICOMM" = SEMC DSS-20 SyncStation Driver
"GMX Upload-Manager" = GMX Upload-Manager
"IE7 Standalone_is1" = Internet Explorer 7 Standalone
"InstallShield für Microsoft Visual C++ 6" = InstallShield für Microsoft Visual C++ 6
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{5D73F169-DD54-4C74-AEB0-CE72A4ED95E6}" = Algo Vision LuraTech Browser Plug-ins
"InstallShield_{E922961C-6DB6-41DE-9FEA-426DF3E9F81C}" = IBM 32-bit Runtime Environment for Java 2, v1.4.2
"IrfanView" = IrfanView (remove only)
"ISO Commander" = ISO Commander 1.6 (remove only)
"IsoBuster_is1" = IsoBuster 2.7
"jclasslib bytecode viewer 3.0" = jclasslib bytecode viewer 3.0
"KompoZer_is1" = KompoZer 0.77
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Lavasoft VX2 Cleaner" = Lavasoft VX2 Cleaner
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaInfo" = MediaInfo 0.7.29
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Developer Network - Visual Studio 6.0a (deu)" = MSDN Library - Visual Studio 6.0a (Deutsch)
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"Mozilla Thunderbird (3.1.4)" = Mozilla Thunderbird (3.1.4)
"Mp3tag" = Mp3tag v2.46a
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyDefrag v4.2.5_is1" = MyDefrag v4.2.5
"MyDefrag v4.2.9_is1" = MyDefrag v4.2.9
"nbi-nb-base-6.0.0.0.200711201000" = NetBeans IDE 6.0 RC2
"nbi-nb-base-6.1.0.0.200804211638" = NetBeans IDE 6.1
"nbi-nb-base-6.5.0.0.200811100001" = NetBeans IDE 6.5
"nbi-nb-base-6.7.1.0.0" = NetBeans IDE 6.7.1
"nbi-nb-base-6.9.0.0.0" = NetBeans IDE 6.9
"nbi-nb-base-6.9.1.0.201006282301" = NetBeans IDE 6.9.1 Build 201006282301
"Nero - Burning Rom!UninstallKey" = Ahead Nero - Burning Rom
"Notepad++" = Notepad++
"NTFSRatio_is1" = NTFSRatio V1.3
"Nvu_is1" = Nvu 1.0
"OnScreenDisplay" = Anzeige am Bildschirm
"PC-Doctor 5 for Windows" = PC-Doctor 5 für Windows
"PFrank_is1" = Peter's Flexible RenAmiNg Kit (PFrank) 2.13
"Power Management Driver" = ThinkPad Power Management Driver
"Praesideo PC Callstation" = Praesideo PC Callstation
"Presentation Director" = ThinkPad-Präsentationsdirektor
"ProInst" = Intel PROSet Wireless
"QcDrv" = Logitech® Camera-Treiber
"RealPlayer 12.0" = RealPlayer
"RealVNC_is1" = VNC Free Edition 4.1.2
"Rename-It!" = Rename-It!
"ReNamer_is1" = ReNamer
"Secunia PSI" = Secunia PSI
"SequoiaView" = SequoiaView
"SpeedFan" = SpeedFan (remove only)
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"ThinkPadSoftwareInstaller" = Installationsprogramm für ThinkPad-Software
"TPKBDLED" = Scroll Lock Indicator Utility
"TPP200" = USB Storage Adapter V2 (TPP)
"TPP300" = USB Storage Adapter V3 (TPP)
"TPP725" = USB Storage Adapter (TPP)
"TreeSize Free_is1" = TreeSize Free V2.2.1
"UltraDefrag" = Ultra Defragmenter
"Unlocker" = Unlocker 1.8.7
"VLC media player" = VLC media player 1.1.4
"VoipDiscount_is1" = VoipDiscount
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WebPost" = Microsoft Web Publishing Wizard 1.53
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9-Reihe
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinHex" = WinHex
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.43
"WinMerge_is1" = WinMerge 2.12.4
"WinRAR archiver" = WinRAR
"winscp3_is1" = WinSCP 4.2.7
"WinZip" = WinZip
"WinZip Self-Extractor" = WinZip Self-Extractor
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2002Setup" = Microsoft Works 2002-Setup-Start
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"X10Hardware" = X10 Hardware(TM)
"xdocdiff" = xdocdiff
"XP Codec Pack" = XP Codec Pack
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"Z-DBackup" = Z-DBackup
"ZoomPlayer" = Zoom Player (remove only)
"ZoomPlayerLang" = Zoom Player deutsche Sprachdateien (entfernen)
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-999901472-3601035388-3065584919-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01D5859C-5207-4183-B88D-3DCD2022BC54}" = t@x 2008 Professional
"{40030378-9EB9-482A-AC10-195097CA624D}" = t@x 2009 Professional
"f6791b188d8f3ff8" = AVM FRITZ!Box USB-Fernanschluss
"InstallShield_{5F71EB81-C72E-4B28-8D90-FDEECFEBC2DE}" = PowerQuest Drive Image 2002
"jIRCii" = jIRCii
"muCommander" = muCommander
"StackTrace" = StackTrace
 
========== Last 10 Event Log Errors ==========
 
Error: Unable to start EventLog service!
 
< End of report >

--- --- ---

cosinus 01.10.2010 14:51

Zitat:

========== Win32 Services (SafeList) ==========


========== Driver Services (SafeList) ==========


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========
Da fehlen schon wieder Passagen!!
Bist Du sicher, dass Du OTL direkt nach der Anleitung ausführst? :wtf:

Herzmann 01.10.2010 14:59

Liste der Anhänge anzeigen (Anzahl: 1)
Zitat:

Zitat von cosinus (Beitrag 574056)
Da fehlen schon wieder Passagen!!
Bist Du sicher, dass Du OTL direkt nach der Anleitung ausführst? :wtf:

Eigentlich schon.
Kann es daran liegen, daß ich unter eingeschränktem Benutzer scanne?

cosinus 01.10.2010 17:24

Zitat:

Kann es daran liegen, daß ich unter eingeschränktem Benutzer scanne?
Ja :D
Deswegen fragte ich auch, ob Du nach Anleitung ausgeführt hast, das bedeutet unter XP mit einem Adminkonto und unter Vista/7 per Rechtsklick als Admin ausführen!

Herzmann 01.10.2010 21:59

Zitat:

Zitat von cosinus (Beitrag 574115)
Ja :D
Deswegen fragte ich auch, ob Du nach Anleitung ausgeführt hast, das bedeutet unter XP mit einem Adminkonto und unter Vista/7 per Rechtsklick als Admin ausführen!

Aus der Anleitung schien mir, daß das spezielle Administrator-Handling nur für Vista/W7 gelte. So nahm ich an, daß OTL sich schon beschweren würde, wenn es unter XP als Administrator laufen will. Vielleicht das noch genauer für XP in der Anleitung erwähnen.
Hast meinen Hinweis "OTL-Log (unter eingeschränktem Benutzer ausgeführt, hoffentlich OK so)" wohl übersehen, und im log stand ja auch:
"NOT logged in as Administrator."

Macht nichts. Ich mach's dann halt nochmal.

Herzmann 01.10.2010 22:21

Code:

OTL logfile created on: 01.10.2010 23:02:41 - Run 3
OTL by OldTimer - Version 3.2.14.1    Folder = E:\Software\Ab 17.04.2009\Download\Sicherheit
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 36,00% Memory free
3,00 Gb Paging File | 1,00 Gb Available in Paging File | 47,00% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1536 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 59,53 Gb Total Space | 5,16 Gb Free Space | 8,66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 46,18 Gb Total Space | 2,20 Gb Free Space | 4,77% Space Free | Partition Type: FAT32
Drive F: | 4,00 Gb Total Space | 0,45 Gb Free Space | 11,32% Space Free | Partition Type: FAT32
Drive G: | 4,01 Gb Total Space | 0,46 Gb Free Space | 11,49% Space Free | Partition Type: FAT32
Drive H: | 25,27 Gb Total Space | 4,47 Gb Free Space | 17,68% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
 
Computer Name: XXX
Current User Name: ***
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - E:\Software\Ab 17.04.2009\Download\Sicherheit\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
PRC - C:\Programme\Mozilla\Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Programme\Mozilla\Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Programme\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Programme\TortoiseHg\TortoiseHgOverlayServer.exe ()
PRC - C:\Programme\TortoiseSVN\bin\TSVNCache.exe (hxxp://tortoisesvn.net)
PRC - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Programme\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
PRC - C:\Programme\ThinkPad\Utilities\PWMDBSVC.exe ()
PRC - C:\WINDOWS\system32\TpShocks.exe (Lenovo.)
PRC - C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe (Lenovo )
PRC - C:\Programme\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Programme\Lenovo\Message Center Plus\MCPLaunch.exe ()
PRC - C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe (AVM Berlin)
PRC - C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
PRC - C:\Programme\Intel\WiFi\bin\S24EvMon.exe (Intel(R) Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
PRC - C:\WINDOWS\system32\NMSAccessU.exe ()
PRC - c:\Programme\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
PRC - C:\Programme\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Programme\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
PRC - C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
PRC - C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
PRC - C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Programme\Gemeinsame Dateien\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
PRC - C:\Programme\FRITZ!DSL\StCenter.exe (AVM Berlin)
PRC - C:\Programme\FRITZ!DSL\FwebProt.exe (AVM Berlin)
PRC - C:\Programme\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
PRC - C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Programme\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Programme\Logitech\QuickCam10\QuickCam10.exe ()
PRC - C:\Programme\Gemeinsame Dateien\logishrd\LComMgr\Communications_Helper.exe (Logitech Inc.)
PRC - C:\Programme\Gemeinsame Dateien\logishrd\LQCVFX\COCIManager.exe (Logitech Inc.)
PRC - c:\Programme\Gemeinsame Dateien\logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Programme\Gemeinsame Dateien\logishrd\LComMgr\LVComSX.exe (Logitech Inc.)
PRC - C:\WINDOWS\tsnp2std.exe (SONIX)
PRC - C:\WINDOWS\vsnp2std.exe (Sonix)
PRC - C:\Programme\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\system32\dla\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\IBMTOOLS\utils\ibmprc.exe (IBM Corp.)
PRC - C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe (Teleca Software Solutions AB)
PRC - C:\Programme\Analog Devices\SoundMAX\SMax4.exe (Analog Devices, Inc.)
PRC - C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
PRC - C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Programme\Sony Ericsson\Mobile\Connectivity Pack\ConnMngMntBox.exe (Symbian Ltd.)
PRC - c:\Programme\Intuwave Ltd\Shared\mRouterRunTime\mRouterRuntime.exe (Intuwave Ltd.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
PRC - C:\Programme\Palm\Handspring\HOTSYNC.EXE (Palm, Inc.)
PRC - C:\WINDOWS\system32\TpKmpSvc.exe ()
PRC - C:\WINDOWS\system32\TpScrLk.exe ()
PRC - C:\Programme\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\2\fpdisp4.exe (FinePrint Software, LLC)
PRC - C:\Programme\Common Files\X10\Common\X10nets.exe (X10)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()
PRC - C:\WINDOWS\tppaldr.exe (In-System Design, Inc.)
PRC - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe (Microsoft® Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
PRC - C:\Programme\EPSON\SMART PANEL\SmaPanel.exe (NewSoft)
 
 
========== Modules (SafeList) ==========
 
MOD - E:\Software\Ab 17.04.2009\Download\Sicherheit\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)
MOD - C:\Programme\Gemeinsame Dateien\logishrd\LVMVFM\LVPrcInj.dll (Logitech Inc.)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (PsaSrv) -- C:\WINDOWS\System32\PsaSrv.exe File not found
SRV - (gupdate) Google Update Service (gupdate) -- C:\Programme\Google\Update\GoogleUpdate.exe File not found
SRV - (de_serv) -- C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe File not found
SRV - (avast! Web Scanner) -- C:\Programme\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) -- C:\Programme\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) -- C:\Programme\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (DozeSvc) -- C:\Programme\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
SRV - (Power Manager DBC Service) -- C:\Programme\ThinkPad\Utilities\PWMDBSVC.exe ()
SRV - (AcSvc) -- C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
SRV - (AcPrfMgrSvc) -- C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
SRV - (TPHDEXLGSVC) -- C:\WINDOWS\system32\TPHDEXLG.exe (Lenovo.)
SRV - (EvtEng) Intel(R) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV - (S24EventMonitor) Intel(R) -- C:\Programme\Intel\WiFi\bin\S24EvMon.exe (Intel(R) Corporation)
SRV - (RegSrvc) Intel(R) -- C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV - (NMSAccessU) -- C:\WINDOWS\system32\NMSAccessU.exe ()
SRV - (SUService) -- c:\Programme\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
SRV - (aawservice) -- C:\Programme\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (IBMPMSVC) -- C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
SRV - (TVT Scheduler) -- C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
SRV - (btwdins) -- C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (ThinkVantage Registry Monitor Service) -- C:\Programme\Gemeinsame Dateien\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (IGDCTRL) -- C:\Programme\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (LVSrvLauncher) -- C:\Programme\Gemeinsame Dateien\logishrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LVPrcSrv) -- c:\Programme\Gemeinsame Dateien\logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (IDriverT) -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (UleadBurningHelper) -- C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (SmcService) -- C:\Programme\Sygate\SPF\Smc.exe (Sygate Technologies, Inc.)
SRV - (TpKmpSVC) -- C:\WINDOWS\system32\TpKmpSvc.exe ()
SRV - (SoundMAX Agent Service (default)) -- C:\Programme\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (x10nets) -- C:\Programme\Common Files\X10\Common\X10nets.exe (X10)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (UIUSys) -- C:\WINDOWS\System32\drivers\UIUSys.sys File not found
DRV - (PORTMON) -- C:\Programme\sysinternals\PortMon\PORTMSYS.SYS File not found
DRV - (PcdrNdisuio) -- C:\WINDOWS\System32\DRIVERS\pcdrndisuio.sys File not found
DRV - (NETFWDSL) -- C:\WINDOWS\System32\DRIVERS\NETFWDSL.SYS File not found
DRV - (Imagedrv) -- C:\WINDOWS\System32\DRIVERS\imagedrv.sys File not found
DRV - (GEARAspiWDM) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys File not found
DRV - (EGATHDRV) -- C:\WINDOWS\System32\EGATHDRV.SYS File not found
DRV - (aswTdi) -- C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) -- C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) -- C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMon2) -- C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) -- C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (epmntdrv) -- C:\WINDOWS\system32\epmntdrv.sys ()
DRV - (EuGdiDrv) -- C:\WINDOWS\system32\EuGdiDrv.sys ()
DRV - (DozeHDD) -- C:\WINDOWS\System32\DRIVERS\DozeHDD.sys (Lenovo.)
DRV - (TPPWRIF) -- C:\WINDOWS\system32\drivers\TPPWRIF.SYS ()
DRV - (SynTP) -- C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (IBMTPCHK) -- C:\WINDOWS\system32\drivers\IBMBLDID.sys ()
DRV - (ANC) -- C:\WINDOWS\system32\drivers\ANC.sys (IBM Corp.)
DRV - (StarOpen) -- C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (Shockprf) -- C:\WINDOWS\System32\DRIVERS\Apsx86.sys (Lenovo.)
DRV - (TPDIGIMN) -- C:\WINDOWS\System32\DRIVERS\ApsHM86.sys (Lenovo.)
DRV - (ultradfg) -- C:\WINDOWS\system32\drivers\ultradfg.sys (UltraDefrag Development Team)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (psadd) -- C:\WINDOWS\system32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (PSI) -- C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (avmaura) -- C:\WINDOWS\system32\drivers\avmaura.sys (AVM Berlin)
DRV - (IBMPMDRV) -- C:\WINDOWS\system32\drivers\ibmpmdrv.sys (Lenovo.)
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (NSCIRDA) -- C:\WINDOWS\system32\drivers\nscirda.sys (National Semiconductor Corporation)
DRV - (MPE) -- C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (uigxrdr) -- C:\WINDOWS\system32\drivers\uigxrdr.SYS (GMX GmbH)
DRV - (ui11rdr) -- C:\WINDOWS\system32\drivers\ui11rdr.SYS (1&1 Internet AG)
DRV - (ggsemc) -- C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) -- C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (w29n51) Intel(R) -- C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (FilterService) -- C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) QuickCam for Notebooks Pro(UVC) -- C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (lvpopflt) -- C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (SNP2STD) USB2.0 PC Camera (SNP2STD) -- C:\WINDOWS\system32\drivers\snp2sxp.sys ()
DRV - (s116unic) Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM) -- C:\WINDOWS\system32\drivers\s116unic.sys (MCCI Corporation)
DRV - (s116obex) -- C:\WINDOWS\system32\drivers\s116obex.sys (MCCI Corporation)
DRV - (s116nd5) Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS) -- C:\WINDOWS\system32\drivers\s116nd5.sys (MCCI Corporation)
DRV - (s116mgmt) Sony Ericsson Device 116  USB WMC Device Management Drivers (WDM) -- C:\WINDOWS\system32\drivers\s116mgmt.sys (MCCI Corporation)
DRV - (s116mdm) -- C:\WINDOWS\system32\drivers\s116mdm.sys (MCCI Corporation)
DRV - (s116mdfl) -- C:\WINDOWS\system32\drivers\s116mdfl.sys (MCCI Corporation)
DRV - (s116bus) Sony Ericsson Device 116 driver (WDM) -- C:\WINDOWS\system32\drivers\s116bus.sys (MCCI Corporation)
DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (LVPr2Mon) -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (lvmvdrv) -- C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (Lvckap) -- C:\WINDOWS\system32\drivers\Lvckap.sys ()
DRV - (TSMAPIP) -- C:\WINDOWS\system32\drivers\TSMAPIP.SYS ()
DRV - (ACEDRV05) -- C:\WINDOWS\system32\drivers\ACEDRV05.sys (Protect Software GmbH)
DRV - (TPHKDRV) -- C:\WINDOWS\system32\drivers\TPHKDRV.sys (IBM Corporation)
DRV - (Smapint) -- C:\WINDOWS\system32\drivers\SMAPINT.SYS (Microsoft Corporation)
DRV - (TDSMAPI) -- C:\WINDOWS\system32\drivers\TDSMAPI.SYS ()
DRV - (TPDiskPM) -- C:\WINDOWS\System32\drivers\TPDiskPM.sys (Lenovo, Ltd. and IBM Corporation)
DRV - (TPInput) -- C:\WINDOWS\system32\drivers\TPInput.sys (Lenovo, Ltd. and IBM Corporation.)
DRV - (speedfan) -- C:\WINDOWS\system32\speedfan.sys (Windows (R) 2000 DDK provider)
DRV - (se27unic) Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM) -- C:\WINDOWS\system32\drivers\se27unic.sys (MCCI)
DRV - (SE27obex) -- C:\WINDOWS\system32\drivers\SE27obex.sys (MCCI)
DRV - (se27nd5) Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS) -- C:\WINDOWS\system32\drivers\se27nd5.sys (MCCI)
DRV - (SE27mgmt) Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM) -- C:\WINDOWS\system32\drivers\SE27mgmt.sys (MCCI)
DRV - (SE27mdm) -- C:\WINDOWS\system32\drivers\SE27mdm.sys (MCCI)
DRV - (SE27mdfl) -- C:\WINDOWS\system32\drivers\SE27mdfl.sys (MCCI)
DRV - (SE27bus) Sony Ericsson Device 039 Driver driver (WDM) -- C:\WINDOWS\system32\drivers\SE27bus.sys (MCCI)
DRV - (FWLANUSB) -- C:\WINDOWS\system32\drivers\fwlanusb.sys (AVM GmbH)
DRV - (HSF_DPV) -- C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWICH) -- C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (TPM) -- C:\WINDOWS\system32\drivers\tpm.sys (Winbond Electronics Corp.)
DRV - (DLAUDFAM) -- C:\WINDOWS\system32\dla\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) -- C:\WINDOWS\system32\dla\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) -- C:\WINDOWS\system32\dla\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) -- C:\WINDOWS\system32\dla\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) -- C:\WINDOWS\system32\dla\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) -- C:\WINDOWS\system32\dla\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) -- C:\WINDOWS\system32\dla\DLADResN.SYS (Sonic Solutions)
DRV - (drvmcdb) -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (LVPrcMon) -- C:\WINDOWS\system32\drivers\LVPrcMon.sys ()
DRV - (DLACDBHM) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (drvnddm) -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (Iviaspi) -- C:\WINDOWS\system32\drivers\iviaspi.sys (InterVideo, Inc.)
DRV - (CXLWIRE) USB Hybrid Video Capture (DVB-T/PAL) -- C:\WINDOWS\system32\drivers\ctxusbtv.sys (Conexant Systems, Inc.)
DRV - (wg6n) -- C:\WINDOWS\SYSTEM32\Drivers\wg6n.sys (Sygate Technologies, Inc.)
DRV - (wg5n) -- C:\WINDOWS\SYSTEM32\Drivers\wg5n.sys (Sygate Technologies, Inc.)
DRV - (wg4n) -- C:\WINDOWS\SYSTEM32\Drivers\wg4n.sys (Sygate Technologies, Inc.)
DRV - (wg3n) -- C:\WINDOWS\SYSTEM32\Drivers\wg3n.sys (Sygate Technologies, Inc.)
DRV - (wpsdrvnt) -- C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Sygate Technologies, Inc.)
DRV - (Teefer) -- C:\WINDOWS\SYSTEM32\Drivers\Teefer.sys (Sygate Technologies, Inc.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (portio) -- C:\WINDOWS\system32\drivers\NscTpmDD.sys (National Semiconductor Corp.)
DRV - (XUIF) -- C:\WINDOWS\system32\drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
DRV - (PalmUSBD) -- C:\WINDOWS\system32\drivers\PalmUSBD.sys (Palm, Inc.)
DRV - (Pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (GWUSB2E) -- C:\WINDOWS\system32\drivers\GWUSB2E.sys (Generic )
DRV - (FTSER2K) -- C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTLUND) -- C:\WINDOWS\system32\drivers\ftlund.sys (FTDI Ltd.)
DRV - (FTDIBUS) -- C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (Ser2pl) -- C:\WINDOWS\system32\drivers\ser2pl.sys (Prolific Technology Inc.)
DRV - (TPP200) USB Storage Adapter V2 (TPP) -- C:\WINDOWS\system32\drivers\tpp200.sys (In-System Design, Inc.)
DRV - (CmdIde) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (Sparrow) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (ENUM1394) -- C:\WINDOWS\system32\drivers\enum1394.sys (Microsoft Corporation)
DRV - (ac97intc) Intel(r) 82801 Audiotreiber-Installationsdienst (WDM) -- C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (PQNTDrv) -- C:\WINDOWS\System32\drivers\PQNTDRV.SYS ()
DRV - (Wdm1) -- C:\WINDOWS\system32\drivers\usbbc.sys ()
DRV - (PMEM) -- C:\WINDOWS\system32\drivers\PMEMNT.SYS (Microsoft Corporation)
DRV - (Aspi32) -- C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-999901472-3601035388-3065584919-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-999901472-3601035388-3065584919-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.09.07 00:35:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Programme\Mozilla\Firefox\components [2010.09.17 12:18:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Programme\Mozilla\Firefox\plugins [2010.09.17 12:24:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2010.09.17 12:18:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
 
 
O1 HOSTS File: ([2004.08.04 05:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - No CLSID value found.
O3 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ACTray] C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
O4 - HKLM..\Run: [ACWLIcon] C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [avast5] C:\Programme\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BLOG] C:\Programme\ThinkPad\Utilities\BATLOGEX.DLL ()
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\dla\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [EZEJMNAP] C:\Programme\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
O4 - HKLM..\Run: [FinePrint Dispatcher v4] C:\WINDOWS\system32\spool\drivers\w32x86\2\fpdisp4.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [ibmmessages] C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKLM..\Run: [IBMPRC] C:\IBMTOOLS\utils\ibmprc.exe (IBM Corp.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [KernelFaultCheck]  File not found
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Programme\Logitech\QuickCam10\QuickCam10.exe ()
O4 - HKLM..\Run: [Message Center Plus] C:\Programme\LENOVO\Message Center Plus\MCPLaunch.exe ()
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Programme\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [Microsoft Works Update Detection] C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [PWRMGRTR] C:\Programme\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [RemoteControl] C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SmcService] C:\Programme\Sygate\SPF\Smc.exe (Sygate Technologies, Inc.)
O4 - HKLM..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe (Sonix)
O4 - HKLM..\Run: [SoundMAX] C:\Programme\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [TkBellExe] C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TortoiseHgOverlayIconServer] C:\Programme\TortoiseHg\TortoiseHgOverlayServer.exe ()
O4 - HKLM..\Run: [TP4EX] C:\WINDOWS\System32\TP4EX.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe ()
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Programme\ThinkPad\Utilities\TpKmapAp.exe (IBM Corp.)
O4 - HKLM..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe (In-System Design, Inc.)
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe (SONIX)
O4 - HKLM..\Run: [TVT Scheduler Proxy] C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
O4 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005..\Run: [AVMUSBFernanschluss] C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\AVMAutoStart.exe (AVM Berlin)
O4 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005..\Run: [IBM RecordNow!] C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005..\Run: [ibmmessages] C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005..\Run: [Microsoft Works Update Detection] C:\Programme\Microsoft Works\WkDetect.exe File not found
O4 - HKU\S-1-5-21-999901472-3601035388-3065584919-1008..\Run: [ibmmessages] C:\Programme\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKU\.DEFAULT..\RunOnce: [IETI] C:\Programme\Skype\Phone\IEPlugin\unins000.exe File not found
O4 - HKU\.DEFAULT..\RunOnce: [WUAppSetup] C:\Programme\Gemeinsame Dateien\logishrd\WUApp32.exe -v 0x046d -p 0x08c3 -f video -m logitech -d 11.0.0.1217 File not found
O4 - HKU\S-1-5-18..\RunOnce: [IETI] C:\Programme\Skype\Phone\IEPlugin\unins000.exe File not found
O4 - HKU\S-1-5-18..\RunOnce: [WUAppSetup] C:\Programme\Gemeinsame Dateien\logishrd\WUApp32.exe -v 0x046d -p 0x08c3 -f video -m logitech -d 11.0.0.1217 File not found
O4 - Startup: C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Autostart\Windows-Explorer.lnk = C:\WINDOWS\explorer.exe (Microsoft Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\BTTray.lnk = C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\EPSON SMART PANEL.lnk = C:\Programme\EPSON\SMART PANEL\SmaPanel.exe (NewSoft)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Erinnerungen in Microsoft Works-Kalender.lnk = C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Fax-Controller.lnk = C:\Programme\EPSON\SMART PANEL\faxicore.exe (NewSoft Technology Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Telefonverbindungsmonitor.lnk = C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe (Teleca Software Solutions AB)
O4 - Startup: C:\Dokumente und Einstellungen\+++\Startmenü\Programme\Autostart\FRITZ!DSL Protect.lnk = C:\Programme\FRITZ!DSL\FwebProt.exe (AVM Berlin)
O4 - Startup: C:\Dokumente und Einstellungen\+++\Startmenü\Programme\Autostart\FRITZ!DSL Startcenter.lnk = C:\Programme\FRITZ!DSL\StCenter.exe (AVM Berlin)
O4 - Startup: C:\Dokumente und Einstellungen\+++\Startmenü\Programme\Autostart\HotSync Manager.lnk = C:\Programme\Palm\Handspring\HOTSYNC.EXE (Palm, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00  [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00  [binary data]
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-999901472-3601035388-3065584919-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\FRITZ!DSL\\sarah.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Programme\FRITZ!DSL\sarah.dll (AVM Berlin)
O15 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} hxxp://www.alternatiff.com/install-ie/alttiff.cab (AlternaTIFF ActiveX)
O16 - DPF: {15A7CF10-CB3E-4265-8779-9FD22619E8ED} hxxp://192.168.1.205/XPanel.cab (XPanel Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} hxxp://www-307.ibm.com/pc/support/acpir.cab (IASRunner Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1164927521531 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} hxxp://java.sun.com/products/plugin/1.4.2/jinstall-142-win.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {F74959B0-1779-472E-BE6E-3023E1DBEC73} hxxp://192.168.1.205/XInit.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ACNotify: DllName - ACNotify.dll - C:\Programme\ThinkPad\ConnectUtilities\ACNotify.dll (Lenovo )
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\tpfnf2: DllName - C:\Programme\Lenovo\HOTKEY\notifyf2.dll - C:\Programme\Lenovo\HOTKEY\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - C:\Programme\Lenovo\HOTKEY\tphklock.dll - C:\Programme\Lenovo\HOTKEY\tphklock.dll ()
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.27 10:02:05 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\autoexec.rod -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\AUTOEXEC.ICR -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\autoexec.rod -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\AUTOEXEC.ICR -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O34 - HKLM BootExecute: (pgdfgsvc c 1) - C:\WINDOWS\System32\pgdfgsvc.exe (Sysinternals - www.sysinternals.com)
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 60 Days ==========
 
[2010.09.28 22:03:35 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Malwarebytes
[2010.09.28 20:24:35 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Adobe
[2010.09.28 20:24:35 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Adobe
[2010.09.23 10:36:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Subversion
[2010.09.23 10:27:10 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Sun
[2010.09.20 19:36:03 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Real
[2010.09.20 19:36:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\ATI
[2010.09.20 19:36:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\ATI
[2010.09.20 19:35:58 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\***\Eigene Dateien\Eigene Videos
[2010.09.20 19:35:58 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Eigene Dateien\FinePrint-Dateien
[2010.09.20 19:35:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Apple Computer
[2010.09.20 19:35:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\TSVNCache
[2010.09.20 19:35:23 | 000,000,000 | --SD | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Microsoft
[2010.09.20 19:35:23 | 000,000,000 | --SD | C] -- C:\Dokumente und Einstellungen\***\Cookies
[2010.09.20 19:35:23 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\***\SendTo
[2010.09.20 19:35:23 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\***\Recent
[2010.09.20 19:35:23 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten
[2010.09.20 19:35:23 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\***\Startmenü
[2010.09.20 19:35:23 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\***\Favoriten
[2010.09.20 19:35:23 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\***\Eigene Dateien\Eigene Musik
[2010.09.20 19:35:23 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\***\Eigene Dateien
[2010.09.20 19:35:23 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\***\Eigene Dateien\Eigene Bilder
[2010.09.20 19:35:23 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\***\Vorlagen
[2010.09.20 19:35:23 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\***\Netzwerkumgebung
[2010.09.20 19:35:23 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen
[2010.09.20 19:35:23 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\***\Druckumgebung
[2010.09.20 19:35:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Sonic
[2010.09.20 19:35:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Microsoft
[2010.09.20 19:35:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Intel
[2010.09.20 19:35:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Identities
[2010.09.20 19:35:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\IBM
[2010.09.20 19:35:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Desktop
[2010.09.20 19:35:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\BVRP Software
[2010.09.20 19:35:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Eigene Dateien\Bluetooth-Exchange-Ordner
[2010.09.20 19:35:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Bluetooth Software
[2010.09.20 19:35:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\ApplicationHistory
[2010.09.16 18:36:33 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.09.16 18:36:31 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.09.16 18:36:31 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2010.09.16 18:36:30 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2010.09.09 01:36:21 | 000,165,584 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010.09.09 01:36:21 | 000,017,744 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010.09.09 01:36:20 | 000,023,376 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010.09.09 01:36:19 | 000,046,672 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010.09.09 01:36:18 | 000,100,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010.09.09 01:36:18 | 000,094,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010.09.09 01:36:17 | 000,028,880 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010.09.09 01:36:05 | 000,167,592 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010.09.09 01:36:05 | 000,038,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010.09.09 01:35:57 | 000,000,000 | ---D | C] -- C:\Programme\Alwil Software
[2010.09.09 01:35:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Alwil Software
[2010.09.08 11:17:46 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2010.09.08 11:17:46 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2010.09.07 00:34:37 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\xing shared
[2010.09.07 00:01:40 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.09.07 00:01:40 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.09.07 00:01:40 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.08.17 15:17:06 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spoolsv.exe
[2007.12.13 22:41:16 | 000,151,552 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnp2std.dll
[2007.12.13 22:41:14 | 000,077,824 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2std.dll
[2006.11.14 01:13:40 | 000,021,866 | ---- | C] (In-System Design, Inc.) -- C:\Programme\Gemeinsame Dateien\tppupd2k.dll
[2004.11.24 21:25:52 | 000,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 60 Days ==========
 
[2010.10.01 23:01:20 | 000,000,296 | ---- | M] () -- C:\WINDOWS\tasks\PMTask.job
[2010.10.01 23:00:40 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.10.01 22:47:01 | 000,001,082 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.10.01 22:47:00 | 000,001,078 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.09.30 22:49:19 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.09.30 22:47:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.09.30 22:47:06 | 2145,832,960 | -HS- | M] () -- C:\hiberfil.sys
[2010.09.30 20:32:30 | 000,000,190 | -HS- | M] () -- C:\Dokumente und Einstellungen\***\ntuser.ini
[2010.09.30 20:32:22 | 001,582,274 | -H-- | M] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\IconCache.db
[2010.09.30 20:09:02 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.09.30 15:23:44 | 001,572,864 | -H-- | M] () -- C:\Dokumente und Einstellungen\***\NTUSER.DAT
[2010.09.29 10:09:09 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.09.28 21:46:38 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-999901472-3601035388-3065584919-1005.job
[2010.09.28 21:46:37 | 000,000,274 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-999901472-3601035388-3065584919-1005.job
[2010.09.20 19:45:17 | 000,001,797 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Logitech QuickCam.lnk
[2010.09.20 19:36:14 | 000,168,088 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
[2010.09.20 19:35:32 | 000,000,770 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Desktop\Windows Media Player.lnk
[2010.09.15 23:05:35 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.09.09 01:36:22 | 000,001,672 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\avast! Free Antivirus.lnk
[2010.09.09 01:36:18 | 000,003,002 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010.09.08 11:17:46 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2010.09.08 11:17:46 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2010.09.07 17:12:17 | 000,038,848 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010.09.07 17:11:54 | 000,167,592 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010.09.07 16:52:25 | 000,046,672 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010.09.07 16:52:03 | 000,165,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010.09.07 16:47:46 | 000,023,376 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010.09.07 16:47:19 | 000,100,176 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010.09.07 16:47:16 | 000,094,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010.09.07 16:47:07 | 000,017,744 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010.09.07 16:46:51 | 000,028,880 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010.09.07 00:35:47 | 000,000,821 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\RealPlayer SP.lnk
[2010.09.07 00:35:17 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2010.09.07 00:34:54 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2010.09.07 00:34:54 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2010.09.07 00:33:10 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2010.09.07 00:10:45 | 000,001,717 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2010.09.02 00:04:08 | 000,505,008 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.09.01 22:37:21 | 000,000,699 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
[2010.08.25 01:14:32 | 000,000,975 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010.08.17 15:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spoolsv.exe
[2010.08.11 20:07:18 | 001,031,240 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.08.11 20:07:18 | 000,461,292 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2010.08.11 20:07:18 | 000,443,184 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.08.11 20:07:18 | 000,085,978 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2010.08.11 20:07:18 | 000,072,450 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.09.20 19:35:32 | 000,000,770 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Desktop\Windows Media Player.lnk
[2010.09.20 19:35:24 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2010.09.20 19:35:23 | 000,028,672 | -H-- | C] () -- C:\Dokumente und Einstellungen\***\ntuser.dat.LOG
[2010.09.20 19:35:23 | 000,000,190 | -HS- | C] () -- C:\Dokumente und Einstellungen\***\ntuser.ini
[2010.09.20 19:35:22 | 001,572,864 | -H-- | C] () -- C:\Dokumente und Einstellungen\***\NTUSER.DAT
[2010.09.09 01:36:22 | 000,001,672 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\avast! Free Antivirus.lnk
[2010.09.07 00:35:47 | 000,000,821 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\RealPlayer SP.lnk
[2010.09.02 00:02:59 | 001,784,720 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2010.09.01 22:37:21 | 000,000,699 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
[2010.08.25 01:14:32 | 000,000,975 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010.04.13 21:40:03 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\EuEpmGdi.dll
[2010.04.13 21:40:03 | 000,013,192 | ---- | C] () -- C:\WINDOWS\System32\epmntdrv.sys
[2010.04.13 21:40:03 | 000,008,456 | ---- | C] () -- C:\WINDOWS\System32\EuGdiDrv.sys
[2009.10.21 03:54:22 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2009.10.17 01:55:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2009.10.06 09:11:50 | 000,091,648 | ---- | C] () -- C:\WINDOWS\System32\lua5.1a.dll
[2009.04.11 21:25:54 | 000,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008.12.19 18:51:56 | 000,000,734 | ---- | C] () -- C:\WINDOWS\wiso.ini
[2008.11.19 17:39:26 | 000,000,011 | ---- | C] () -- C:\WINDOWS\cmvpt32.ini
[2008.11.19 17:38:46 | 000,884,736 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2008.11.19 17:38:46 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\SSLeay32.dll
[2008.11.19 10:53:59 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\GCL52FW.DLL
[2008.11.19 10:48:43 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\Cmpnl32.dll
[2008.11.19 10:48:43 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\GCL52FWZ.DLL
[2008.11.19 10:48:42 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\CMUpdate.dll
[2008.03.20 23:39:08 | 000,000,030 | ---- | C] () -- C:\Programme\Exiferupdate.ini
[2008.03.03 00:55:21 | 000,661,504 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008.03.03 00:55:21 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2008.03.03 00:55:21 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008.03.03 00:55:21 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008.03.03 00:55:21 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\ffavisynth.dll
[2008.03.03 00:55:20 | 000,397,312 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2008.03.03 00:55:20 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2008.03.03 00:55:20 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2008.03.03 00:55:20 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2008.03.03 00:55:20 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\ff_realaac.dll
[2008.03.03 00:55:20 | 000,102,912 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2008.03.03 00:55:20 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2008.03.03 00:55:20 | 000,054,784 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2008.02.14 14:55:42 | 000,000,032 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ezsid.dat
[2008.01.14 20:50:44 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ZSubTimer.dll
[2008.01.10 13:40:29 | 000,015,360 | ---- | C] () -- C:\WINDOWS\System32\evntmsg.dll
[2008.01.04 16:13:58 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\DEVMAN.DLL
[2007.12.24 13:47:52 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007.12.24 13:40:26 | 000,405,504 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z444.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z443.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z442.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z440.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z439.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z438.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z437.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z436.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z435.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z434.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z433.dll
[2007.12.23 14:00:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\Merge7z432.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z444U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z443U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z442U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z440U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z439U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z438U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z437U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z436U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z435U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z434U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z433U.dll
[2007.12.23 14:00:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\Merge7z432U.dll
[2007.12.22 22:02:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2007.12.22 21:27:22 | 003,138,048 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2007.12.13 22:41:22 | 000,015,497 | ---- | C] () -- C:\WINDOWS\snp2std.ini
[2007.12.13 22:41:20 | 000,025,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\sncamd.sys
[2007.12.13 22:41:19 | 012,039,552 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2sxp.sys
[2007.12.13 19:18:03 | 000,000,719 | R--- | C] () -- C:\WINDOWS\System32\InstExec.ini
[2007.12.13 19:17:25 | 000,057,126 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007.12.07 16:15:39 | 000,001,260 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2007.12.03 16:34:32 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2007.12.01 13:43:30 | 000,541,696 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2007.11.29 12:52:36 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007.11.26 16:56:04 | 002,842,624 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2007.11.26 16:43:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2007.09.04 23:56:09 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007.09.04 23:44:27 | 000,198,144 | ---- | C] () -- C:\WINDOWS\System32\_psisdecd.dll
[2007.02.27 18:12:06 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\USBaccess.dll
[2007.02.06 18:45:04 | 000,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007.02.06 18:42:40 | 001,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
[2007.01.29 00:03:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\IROTVIEW.INI
[2007.01.28 21:23:40 | 000,000,275 | ---- | C] () -- C:\WINDOWS\ddespy.ini
[2007.01.10 14:00:41 | 000,001,571 | ---- | C] () -- C:\WINDOWS\Faxcpp1.ini
[2007.01.10 14:00:41 | 000,000,422 | ---- | C] () -- C:\WINDOWS\Faxcpp.ini
[2007.01.10 12:52:58 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2006.12.30 20:09:45 | 000,000,240 | ---- | C] () -- C:\WINDOWS\BUHL.INI
[2006.12.24 23:39:33 | 000,000,040 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2006.12.24 22:11:08 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2006.12.21 02:21:58 | 000,144,656 | ---- | C] () -- C:\WINDOWS\System32\FAMCOM.dll
[2006.12.20 22:10:03 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\Gif89.dll
[2006.12.19 18:39:09 | 000,110,642 | ---- | C] () -- C:\WINDOWS\System32\pdfmona.dll
[2006.12.19 18:39:09 | 000,043,252 | ---- | C] () -- C:\WINDOWS\System32\pdfmon.dll
[2006.12.09 02:04:03 | 000,000,687 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006.11.30 22:27:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\FoneSync.INI
[2006.11.30 18:30:30 | 000,000,126 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2006.11.30 17:45:46 | 000,000,037 | ---- | C] () -- C:\WINDOWS\Viewer.ini
[2006.11.30 17:38:48 | 000,000,151 | ---- | C] () -- C:\WINDOWS\ccard100.ini
[2006.11.30 17:37:13 | 000,007,901 | ---- | C] () -- C:\WINDOWS\MSACC20.INI
[2006.11.30 17:30:38 | 000,001,245 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006.11.30 17:30:38 | 000,000,061 | ---- | C] () -- C:\WINDOWS\odbcisam.ini
[2006.11.30 17:30:37 | 000,000,914 | ---- | C] () -- C:\WINDOWS\MSOFFICE.INI
[2006.11.30 17:30:29 | 000,000,124 | ---- | C] () -- C:\WINDOWS\GRAPH5.INI
[2006.11.30 17:30:21 | 000,002,640 | ---- | C] () -- C:\WINDOWS\WINWORD6.INI
[2006.11.30 17:30:18 | 000,000,329 | ---- | C] () -- C:\WINDOWS\EXCEL5.INI
[2006.11.30 17:30:17 | 000,000,239 | ---- | C] () -- C:\WINDOWS\Winhelp.ini
[2006.11.30 17:30:17 | 000,000,110 | ---- | C] () -- C:\WINDOWS\msquery.ini
[2006.11.30 17:30:08 | 000,000,535 | ---- | C] () -- C:\WINDOWS\MSTXTCNV.INI
[2006.11.30 17:30:06 | 000,002,122 | ---- | C] () -- C:\WINDOWS\MSFNTMAP.INI
[2006.11.30 17:30:06 | 000,000,280 | ---- | C] () -- C:\WINDOWS\TTEMBED.INI
[2006.11.30 15:01:49 | 000,000,266 | ---- | C] () -- C:\WINDOWS\VISITE.INI
[2006.11.30 15:00:13 | 000,005,230 | ---- | C] () -- C:\WINDOWS\TOPDRAW.INI
[2006.11.30 14:26:24 | 000,112,688 | ---- | C] () -- C:\WINDOWS\System32\shw32.dll
[2006.11.29 18:34:56 | 000,000,044 | ---- | C] () -- C:\WINDOWS\SMWizard.INI
[2006.11.16 23:01:57 | 000,003,776 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006.11.14 02:05:27 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2006.11.13 00:24:27 | 000,015,576 | R--- | C] () -- C:\WINDOWS\System32\drivers\usbbc.sys
[2006.11.13 00:24:27 | 000,003,953 | R--- | C] () -- C:\WINDOWS\System32\coinst.dll
[2006.11.10 23:55:40 | 000,096,768 | ---- | C] () -- C:\WINDOWS\SlantAdj.dll
[2006.10.10 09:46:17 | 000,003,252 | ---- | C] () -- C:\WINDOWS\System32\drivers\PQNTDRV.SYS
[2006.10.10 04:14:04 | 000,000,092 | ---- | C] () -- C:\WINDOWS\System32\ftdiun2k.ini
[2006.09.26 01:14:35 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006.09.26 01:13:47 | 000,004,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2006.09.26 01:10:01 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
[2006.09.26 01:09:38 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2006.09.26 01:09:38 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2006.09.26 01:09:10 | 000,004,224 | ---- | C] () -- C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2006.09.26 01:02:33 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006.09.26 01:02:33 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006.09.26 01:02:33 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006.09.26 01:02:33 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006.09.26 01:02:33 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006.09.26 01:02:33 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006.09.26 01:02:00 | 000,000,642 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006.09.26 00:53:24 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\FPCALL.dll
[2006.09.26 00:53:07 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2006.09.26 00:50:44 | 000,009,343 | ---- | C] () -- C:\WINDOWS\System32\drivers\TDSMAPI.SYS
[2006.09.26 00:39:34 | 000,002,458 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006.09.26 00:32:23 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\tphklock.dll
[2006.06.09 11:43:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005.09.01 14:11:52 | 000,016,768 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPrcMon.sys
[2005.07.06 00:45:08 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\notifyf2.dll
[2005.02.17 12:41:32 | 000,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005.02.17 12:41:30 | 000,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2004.12.16 03:41:58 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\pwdmon.dll
[2004.12.16 03:41:58 | 000,019,853 | ---- | C] () -- C:\WINDOWS\ibmprc.ini
[2004.10.15 19:31:56 | 000,218,264 | ---- | C] () -- C:\WINDOWS\System32\SetAid.dll
[2004.10.03 19:50:54 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004.08.10 13:48:32 | 000,000,849 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004.01.09 06:10:32 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\AIBMRUNL.dll
[2001.11.14 13:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1999.04.29 22:00:00 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998.04.24 01:00:00 | 000,000,218 | ---- | C] () -- C:\WINDOWS\FRONTPG.INI
[1996.04.03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
< End of report >


Herzmann 01.10.2010 22:25

LOP- und Purity-Prüfung hatte ich nicht angehakt, dafür aber "Scanne alle Benutzer" und 60 Tage.

Code:

OTL Extras logfile created on: 01.10.2010 23:02:41 - Run 3
OTL by OldTimer - Version 3.2.14.1    Folder = E:\Software\Ab 17.04.2009\Download\Sicherheit
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 36,00% Memory free
3,00 Gb Paging File | 1,00 Gb Available in Paging File | 47,00% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1536 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 59,53 Gb Total Space | 5,16 Gb Free Space | 8,66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 46,18 Gb Total Space | 2,20 Gb Free Space | 4,77% Space Free | Partition Type: FAT32
Drive F: | 4,00 Gb Total Space | 0,45 Gb Free Space | 11,32% Space Free | Partition Type: FAT32
Drive G: | 4,01 Gb Total Space | 0,46 Gb Free Space | 11,49% Space Free | Partition Type: FAT32
Drive H: | 25,27 Gb Total Space | 4,47 Gb Free Space | 17,68% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
 
Computer Name: XXX
Current User Name: ***
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Minimal
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla\Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Programme\Mozilla\Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Programme\Mozilla\Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Durchsuchen mit &IrfanView] -- "C:\Programme\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"6198:TCP" = 6198:TCP:*:Enabled:freenetSPEED
"3126:TCP" = 3126:TCP:*:Enabled:freenetSPEED
"3128:TCP" = 3128:TCP:*:Enabled:freenetSPEED
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player-Netzwerkfreigabedienst
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Programme\IBM\Updater\jre\bin\java.exe" = C:\Programme\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\jre\bin\javaw.exe" = C:\Programme\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\ucsmb.exe" = C:\Programme\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector -- File not found
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Programme\IBM\Updater\jre\bin\java.exe" = C:\Programme\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\jre\bin\javaw.exe" = C:\Programme\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector -- File not found
"C:\Programme\IBM\Updater\ucsmb.exe" = C:\Programme\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector -- File not found
"D:\fsetup.exe" = D:\fsetup.exe:*:Enabled:AVM FSetup Application -- File not found
"C:\Programme\freenet\PxClient.exe" = C:\Programme\freenet\PxClient.exe:*:Enabled:freenetSPEED -- File not found
"C:\Programme\VoipDiscount.com\VoipDiscount\VoipDiscount.exe" = C:\Programme\VoipDiscount.com\VoipDiscount\VoipDiscount.exe:*:Enabled:VoipDiscount -- (VoipDiscount)
"C:\Programme\Mozilla Thunderbird\thunderbird.exe" = C:\Programme\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Mozilla Thunderbird -- (Mozilla Messaging)
"C:\Programme\Intuwave Ltd\Shared\mRouterRunTime\mRouterRuntime.exe" = C:\Programme\Intuwave Ltd\Shared\mRouterRunTime\mRouterRuntime.exe:*:Enabled:mRouterRuntime -- (Intuwave Ltd.)
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft  Fax Console -- (Microsoft Corporation)
"C:\Programme\Java\jdk1.6.0_01\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_01\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe" = C:\Programme\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe:*:Enabled:mysqld-nt -- ()
"C:\Programme\Java\jdk1.6.0_01\bin\java.exe" = C:\Programme\Java\jdk1.6.0_01\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Java\jdk1.6.0\bin\java.exe" = C:\Programme\Java\jdk1.6.0\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\FRITZ!DSL\FBOXUPD.EXE" = C:\Programme\FRITZ!DSL\FBOXUPD.EXE:*:Enabled:AVM FRITZ!Box Firmware-Update -- (AVM Berlin)
"C:\Programme\Java\jdk1.6.0_02\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_02\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Home Cinema\PowerCinema\PowerCinema.exe" = C:\Programme\Home Cinema\PowerCinema\PowerCinema.exe:*:Enabled:PowerCinema -- File not found
"C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_147a792107b9f781\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_147a792107b9f781\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Programme\WS_FTP\WS_FTP95.exe" = C:\Programme\WS_FTP\WS_FTP95.exe:*:Enabled:WS_FTP 95 -- (Ipswitch, Inc. 81 Hartwell Ave. Lexington, MA)
"C:\Programme\Java\jdk1.6.0_03\bin\java.exe" = C:\Programme\Java\jdk1.6.0_03\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Programme\Java\jdk1.6.0_03\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_03\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Programme\Java\jre1.6.0_03\bin\java.exe" = C:\Programme\Java\jre1.6.0_03\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Java\NetBeans 6.0 RC2\mobility8\WTK2.5.2\bin\emulator.exe" = C:\Programme\Java\NetBeans 6.0 RC2\mobility8\WTK2.5.2\bin\emulator.exe:*:Enabled:emulator -- File not found
"C:\Programme\Java\WTK22\bin\emulator.exe" = C:\Programme\Java\WTK22\bin\emulator.exe:*:Enabled:emulator -- ()
"C:\Programme\Java\NetBeans 6.0\mobility8\WTK2.5.2\bin\emulator.exe" = C:\Programme\Java\NetBeans 6.0\mobility8\WTK2.5.2\bin\emulator.exe:*:Enabled:emulator -- File not found
"C:\Programme\FRITZ!DSL\IGDCTRL.EXE" = C:\Programme\FRITZ!DSL\IGDCTRL.EXE:*:Enabled:AVM FRITZ!DSL - igdctrl.exe -- (AVM Berlin)
"C:\Programme\FRITZ!DSL\WebwaIgd.exe" = C:\Programme\FRITZ!DSL\WebwaIgd.exe:*:Enabled:AVM FRITZ!DSL - webwaigd.exe -- (AVM Berlin)
"C:\Programme\uTorrent\uTorrent.exe" = C:\Programme\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- File not found
"C:\Programme\Sony Ericsson\Update Service\ma3platform.exe" = C:\Programme\Sony Ericsson\Update Service\ma3platform.exe:*:Enabled:ma3platform -- File not found
"C:\Programme\Sony Ericsson\Update Service\Update Service.exe" = C:\Programme\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service -- File not found
"C:\Programme\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe" = C:\Programme\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.0 -- (Sony Creative Software Inc.)
"C:\Programme\Java\jdk1.6.0_04\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_04\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0e9add42c1\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0e9add42c1\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Programme\Java\jre1.6.0_04\bin\javaw.exe" = C:\Programme\Java\jre1.6.0_04\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Program Files\IBM\Java142\jre\bin\javaw.exe" = C:\Program Files\IBM\Java142\jre\bin\javaw.exe:*:Enabled:Java launcher -- (IBM)
"C:\Programme\Mozilla\Firefox\firefox.exe" = C:\Programme\Mozilla\Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Programme\Java\jdk1.6.0_06\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_06\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0f9b5c5281\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf0f9b5c5281\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Programme\Java\jdk1.6.0_07\jre\bin\java.exe" = C:\Programme\Java\jdk1.6.0_07\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Programme\Real\RealPlayer\realplay.exe" = C:\Programme\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- File not found
"C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf139d589181\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf139d589181\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- File not found
"C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf149dd7a141\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf149dd7a141\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- (AVM Berlin)
"C:\Programme\Java\jre6\bin\java.exe" = C:\Programme\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"C:\Programme\Java\jre6\bin\javaw.exe" = C:\Programme\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\CDYO31ZO.VG2\OEZVKJ02.55X\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- (AVM Berlin)
"C:\WINDOWS\LMI35.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI35.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI60.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI60.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI33D.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI33D.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI3B2.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI3B2.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI3B7.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI3B7.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\Programme\BitTorrent\bittorrent.exe" = C:\Programme\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Programme\FRITZ!Box Monitor\FRITZBoxMonitor.exe" = C:\Programme\FRITZ!Box Monitor\FRITZBoxMonitor.exe:*:Enabled:FRITZ!Box Monitor -- (AVM Berlin)
"C:\Programme\FRITZ!vox\Fritz!vox.exe" = C:\Programme\FRITZ!vox\Fritz!vox.exe:*:Enabled:Fritz!vox -- (AVM Berlin)
"C:\CYGWIN\bin\rsync.exe" = C:\CYGWIN\bin\rsync.exe:*:Enabled:rsync -- ()
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000407-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium
"{00170407-78E1-11D2-B60F-006097C998E7}" = Microsoft Word 2000 SR-1
"{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}" = Java DB 10.5.3.0
"{01008202-823E-46CD-A70E-BEE818F97169}" = Microsoft Encarta Enzyklopädie 2002
"{01DA3FC4-CF94-4AAD-9127-C8F2E09F6E69}" = PowerArchiver 2010
"{024D73F0-1C49-2340-8AC3-5234AAA560C0}" = ccc-core-static
"{03B1BBDC-7FAA-4A03-9988-A85428BAD382}" = Sun ODF Plugin for Microsoft Office 3.0
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{05E9F134-07C9-4249-9B80-EE5D975F201B}" = Sony Ericsson Image Editor
"{0873B1A3-00A9-40D6-BACE-3DB4BC5DA840}" = ThinkPad SATA Power Management Driver
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Systemsteuerung
"{0D05C1D4-BB4C-4545-86DC-F5EA7D04121A}" = Vtpro-e Themes v1.3
"{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}" = HP USB Disk Storage Format Tool
"{1007F41F-7D69-468E-8017-3849A5A973C2}" = IBM ThinkVantage Technologies Welcome Message
"{11783F13-C3A9-44A8-929B-21A476F65272}" = IBM Rescue and Recovery with Rapid Restore
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1297C681-92D7-40EF-93BF-03F66EC5105C}" = ThinkPad-Dienstprogramm 'EasyEject'
"{13EDFFFE-DCF2-448A-A653-3C4CD60D99B4}" = Palm Desktop and Synchronization Software
"{1649C93D-C661-4C53-B8AE-DB3592150B34}" = Buhl finance - tax 2006 Professional
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = ThinkPad UltraNav Utility
"{1E5007FA-DA5E-4EDD-BDE5-14D128D66887}" = PowerQuest PartitionMagic 7.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = Dienstprogramm 'IBM ThinkPad-Tastaturanpassung'
"{23170F69-40C1-2701-0465-000001000000}" = 7-Zip 4.65
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{2457326B-C110-40C3-89B0-889CC913871A}" = AVM FRITZ!DSL
"{24F9E04D-4CD5-3979-76F9-C1C6E78471AB}" = CCC Help Italian
"{25F60491-F5AB-4985-9354-37C146783F35}" = Microsoft Works Suite-Add-Ins für Microsoft Word
"{2604C0F9-BFD3-4BA0-9EB5-22537C648F03}" = MobileMe Control Panel
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 21
"{2D230139-69DA-4CE8-83FB-EE5F522D2FF5}" = Praesideo Logging Server V2.32.1757
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator
"{2FEB25F8-C3CB-49A2-AE79-DE17FFAFB5D9}" = MySQL Server 5.0
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 3.108.00
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{31E1050B-F69F-4A16-8F5A-E44D31901250}" = Ulead DVD DiskRecorder 2.1.1
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{32A3A4F4-B792-11D6-A78A-00B0D0150100}" = J2SE Development Kit 5.0 Update 10
"{32A3A4F4-B792-11D6-A78A-00B0D0160030}" = Java(TM) SE Development Kit 6 Update 3
"{32A3A4F4-B792-11D6-A78A-00B0D0160180}" = Java(TM) SE Development Kit 6 Update 18
"{32A3A4F4-B792-11D6-A78A-00B0D0160200}" = Java(TM) SE Development Kit 6 Update 20
"{32A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java(TM) SE Development Kit 7
"{3305E24F-1192-0424-8A25-39713FD92728}" = Skins
"{34F0D55F-C386-4195-9A5B-961D3F6ACD46}" = InterVideo MediaOne Gallery
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B94A56F-9FDA-46CC-A3B6-07613A84200B}" = Buhl finance - tax 2007 Professional
"{3D289CAC-AD9F-45d9-9D36-524EB7B6C958}" = Lenovo Hard Drive Quick Test
"{3DA7A736-0B03-565C-1139-83FE890F0AF3}" = CCC Help French
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{3F71721C-E73D-481C-B926-C56B68D8F388}" = Praesideo Open Interface Library V2.32.1757
"{437C19B3-7E20-4E39-B868-CA6BAA820E1C}" = Microsoft Rechner-Plus
"{43A1FE83-D39F-3779-8D48-D6D19EE7AC48}" = CCC Help Chinese Traditional
"{443CBE24-0679-4027-9C36-66F129E009C5}" = Crestron Database
"{448AB2CB-C94A-47DE-80B8-9D7824DEFA57}" = Ulead FilmBrennerei 4.0
"{44B32F92-5A96-43D9-BCBE-0AD2CDC409E7}" = TortoiseHg 1.1.3 (x86)
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage System für aktiven Festplattenschutz
"{47CF8B92-4083-4F43-9680-6EDE10F812BD}" = Praesideo Logging Viewer V2.32.1757
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{55C28EF3-2EA3-46AB-B1E7-54B96C5A6921}" = Viewport v3.99.01
"{57FA0525-01F9-4051-8DE9-CBF43CAC68D9}" = Catalyst Control Center - Branding
"{5C72622B-643D-4296-B57D-5D53D0C68509}" = Sony Ericsson Media Manager 1.0
"{5D73F169-DD54-4C74-AEB0-CE72A4ED95E6}" = Algo Vision LuraTech Browser Plug-ins
"{5DE1B7CF-7429-40CA-987F-6BEE09B63787}" = Prime95
"{5F71EB81-C72E-4B28-8D90-FDEECFEBC2DE}" = Drive Image
"{61A17AE1-B4C3-4FC0-8563-684C23CBFA0F}" = SW-Entwicklung\Sun Java (TM) Wireless Toolkit 2.5.2 for CLDC
"{63F817ED-F710-481B-B332-7A356CE04E10}" = TortoiseOverlays
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6686F38D-1A32-4A8C-94D7-A2AA9C5F3C9B}" = Crestron Device Database
"{66CA5E58-0D03-A75D-16EF-68258DE0DFC3}" = CCC Help English
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BC292E6-5C85-4620-C1D0-A2FEAFD5D135}" = CCC Help Japanese
"{6C31E111-96BB-4ADC-9C81-E6D3EEDDD8D3}" = Powertoys For Windows XP
"{6CE96A14-61E2-48CC-837E-22710A953ADE}" = IBM Themes
"{7005C601-B415-4D77-B2ED-FF40E3DACDED}" = DEAL for Windows v4.00
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{735DEB9C-61BD-4D31-994B-92395BBB4E45}" = Microsoft XML Parser
"{75438C0E-9925-412E-AD85-D0E71C6CE2ED}" = USB2.0 PC Camera (SN9C201&202)
"{7579A17B-0E6C-9EF3-D022-30729A24B399}" = CCC Help Chinese Standard
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7BAA2000-5B8D-66DD-DBE7-089671AC118B}" = ccc-utility
"{7C2BD022-2B09-1F6D-D6C1-AD2A591E7537}" = Catalyst Control Center Core Implementation
"{7D2370AC-D8E6-4996-986A-19824F8A167C}" = Logitech QuickCam
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{806DB796-7082-C63F-284E-62245284A417}" = CCC Help Dutch
"{808FAA20-4C3A-11D4-8A57-00201853C903}" = PC-Linq
"{82512BC9-BD5D-4C50-BE4D-B98E7DF78687}" = ThinkPad-UltraNav-Assistent
"{8398B542-3CC4-44D9-83DF-696CCE70124B}" = Windows Support Tools
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{8675339C-128C-44DD-83BF-0A5D6ABD8297}" = System Update
"{8745DEAB-1126-42F5-9585-C66D5497B47B}" = EMEA Wallpaper
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D0E26CF-AA2F-48FF-A533-6207DE50B1C4}_is1" = Agendus for Windows Palm Desktop Edition
"{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2
"{8EAB2384-C794-40ED-A9DD-3270A0D2BB76}" = Ulead VideoStudio 9.0
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{91AF774D-8506-4194-9B77-9D803CBF5AC1}" = SIMPL Windows v2.10
"{925936AC-9C9A-4897-874B-60961AAB6D52}" = Disc2Phone
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{984E0622-29E5-44EA-A075-A0CE91B2CF13}" = TortoiseOverlays
"{A0E64EBA-8BF0-49FB-90C0-BB3D781A2016}" = ThinkPad Energie-Manager
"{A1A903C9-35DE-4770-9264-5F831E0A3A2E}" = SIMPL Windows Library v565
"{A2092B2A-A4FB-4464-A4C0-023D2C9993F8}" =
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3E23D97-145F-29BF-81DE-DAEC1E5AB237}" = Catalyst Control Center Graphics Full New
"{A8FA2AC0-3875-B59F-917F-719982FB1BE8}" = CCC Help Portuguese
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA3983BF-9B72-484E-972A-E47BBAFA9CCA}" = VisionTools Pro-e v3.8
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.4 - Deutsch
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AC849092-6F19-4395-8860-BC3B82CAFE51}" = funScreenScraping Microsoft Systemdateien
"{AE1A0B0E-2EC7-656A-711A-0E7E8D4AB5CF}" = CCC Help Spanish
"{B016DE7B-CA2D-5EFD-9591-A109E67119BD}" = CCC Help Swedish
"{B214C3C8-FC16-42EC-B7BB-703A1BB9C790}" = Lenovo Battery Program
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B5FE8184-DB90-4642-826C-096C6369B3DA}" = J2ME Wireless Toolkit 2.2
"{B6826FA8-04C8-4147-AA3C-5B900AB887A1}" = PowerArchiver 2007
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU
"{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU
"{C4A92EF9-D14C-937F-742E-D272938DC590}" = CCC Help Korean
"{C769A271-7E1C-48F9-B331-474600DD4C06}" = Microsoft Picture It! Foto 2002
"{C7B8E06E-EBBC-4210-93AB-DFC8760E3FC9}" = Works Suite-Betriebssystem-Pack
"{C9A87D86-FDFD-418B-BF96-EF09320973B3}" = PC Inspector smart recovery
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CD6EB005-957A-4191-93ED-6ECD5F7F931E}" = SKTimeStamp
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFEDA22F-435D-4891-913A-75B80D8159B8}" = Crestron Toolbox v1.12
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D121161E-AD64-4438-97A0-66A1AB7FFDE3}" = Works Suite-Betriebssystem-Pack
"{D2FEBD11-E587-4C41-AD33-0CD90D26A964}" = Client für die Windows-Rechteverwaltung mit Service Pack 2
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow! 1.0
"{D5881E4A-0764-11D6-9D93-DECCF2B3F57C}" = Praesideo Core V2.32.1757
"{D5A9B7C0-8751-11D8-9D75-000129760D75}" = MediaShow 3.0
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7 Anniversary Edition
"{D702172D-8D17-D9EC-B661-42FA268575AF}" = Catalyst Control Center Localization All
"{DAA3F236-CEEC-C6CC-12C2-AB1B75C8BC09}" = CCC Help German
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DEC2C123-3CE0-4669-B119-61519130CACD}" = TortoiseSVN 1.6.10.19898 (32 bit)
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E09CEE8B-1DCD-C628-A8EA-2B56D61DDEFA}" = ccc-core-preinstall
"{E258A840-7E9A-443A-B156-67102C48BF17}" = TPP Storage Driver Installation
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9-Reihe
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{E922961C-6DB6-41DE-9FEA-426DF3E9F81C}" = IBM 32-bit Runtime Environment for Java 2, v1.4.2
"{EA664480-3844-11D5-8C25-444553540000}" = Funktion "TrackPoint-Eingabehilfen"
"{EC6AF20D-4376-4070-BEE4-D3A0DFF7E140}" = Access IBM
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Rückwärtskompatibilität des Clients für die Windows-Rechteverwaltung SP2
"{ED5EDCD0-5745-4B13-8061-58C9833FD06D}" = Microsoft Works 6.0
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F18B31E4-E2E3-4F4F-A2C9-BA579D6AF400}" = TortoiseOverlays
"{F2260E94-80F2-4CB1-B6B1-6043D9BFFA47}" = Works-Synchronisierung
"{F22FD942-651D-4EE8-BD6F-7E0AF5E17625}" = Intel(R) PROSet/Wireless WiFi-Software
"{F3439243-1BAC-7250-D346-2642655F95ED}" = Catalyst Control Center Graphics Full Existing
"{F34D9A5F-484A-4E31-A9D3-908CB265B289}" = Sygate Personal Firewall
"{F3FAE3D8-A91D-4D11-90C1-27581C2C23B9}" = Sony Ericsson MMS Home Studio
"{F413B3A4-EE5D-457C-BAE5-6E58D9589ED5}" = Access IBM Message Center
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F63E8666-0F10-11D3-8258-00C04F6843FE}" = Microsoft Visual Keyboard
"{F705E3E1-A471-426B-9A09-73429F3418EE}" = System Migration Assistant
"{F7F2DC0A-C22E-49AD-AD37-797309A54E7B}" = Microsoft AutoRoute 2002
"{FB97A745-D1E6-435D-B942-264E94F89938}" = SIMPL+ Cross Compiler
"{FC081D4D-DF1B-4CF1-B530-027E4118D846}" = ThinkPad-Konfiguration
"{FC18114B-05A0-11D6-8140-000102E745A6}" = PC Suite for P800
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FD331A3B-F7A5-4C31-B8D4-DF413C85AF7A}" = Message Center Plus
"{FD9D4CA5-8F97-44A0-B17E-C2C77C824FA4}" = funScreenScraping Client Version
"{FF2AFF73-099E-0BB5-AE87-B044D3D7DE78}" = Catalyst Control Center Graphics Light
"1&1 Upload-Manager" = 1&1 Upload-Manager
"274c5407c4fa26908310cb5c1c5500001224356439" = NetBeans IDE 5.5
"312f77fc8b5965949add215dd8550000-1163196496" = NetBeans Profiler 5.5
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"All ATI Software" = ATI - Dienstprogramm zur Deinstallation der Software
"Any Video Converter_is1" = Any Video Converter 3.0.3
"ATI Display Driver" = ATI Display Driver
"Attribute Manager_is1" = Attribute Manager 2.35
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.9 (Unicode)
"Audacity_is1" = Audacity 1.2.6
"avast5" = avast! Free Antivirus
"AVIcodec" = AVIcodec (remove only)
"Avira UnErase Personal" = Avira UnErase Personal
"AVMFBox" = AVM FRITZ!Box Dokumentation
"AVMFBoxAnswerMachine" = AVM FRITZ!vox
"AVMFBoxMonitor" = AVM FRITZ!Box Monitor
"BitTorrent" = BitTorrent
"CCleaner" = CCleaner
"CD Audio Reader Filter" = CD Audio Reader Filter (remove only)
"CDCheck" = CDCheck
"CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_05591014" = ThinkPad Integrated 56K Modem
"CollabNet Automatic Update" = CollabNet Automatic Update 1.2
"CollabNet Subversion Client" = CollabNet Subversion Client 1.6.12
"Corel Applications" = Corel Applications
"CvsConflictEditor_is1" = CvsConflictEditor 1.2.0
"CVSNT_is1" = CVSNT
"D2D77DC2-8299-11D1-8949-444553540000_is1" = WinCvs 2.0
"Defraggler" = Defraggler
"DiffUtils-2.8.7_is1" = GnuWin32: DiffUtils version 2.8.7
"Digital Image Recovery_is1" = Digital Image Recovery 1.47
"DirectVobSub" = DirectVobSub (remove only)
"doPDF 7 printer_is1" = doPDF 7.1 printer
"EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 5.5.1 Home Edition
"EPSON SMART PANEL" = EPSON SMART PANEL
"EPSON Stylus Scan" = EPSON Stylus Scan FB TWAIN
"EPSON-Drucker und Utilities" = EPSON-Drucker-Software
"Exact Audio Copy" = Exact Audio Copy 0.99pb5
"Exifer_is1" = Exifer
"fcd569e3a3b8ade0f9366fc6625500001796351737" = NetBeans Mobility Pack 5.5
"Feurio" = Feurio! CD-Writer
"ffdshow_is1" = ffdshow [rev 1868] [2008-02-22]
"FFmpeg for Audacity on Windows_is1" = FFmpeg for Audacity on Windows
"FinePrint 2000" = FinePrint 2000
"FinePrint2000" = FinePrint 2000
"FolderSizes_is1" = FolderSizes 1.0
"frndial" = freenet.de
"FTDICOMM" = SEMC DSS-20 SyncStation Driver
"GMX Upload-Manager" = GMX Upload-Manager
"IE7 Standalone_is1" = Internet Explorer 7 Standalone
"InstallShield für Microsoft Visual C++ 6" = InstallShield für Microsoft Visual C++ 6
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{5D73F169-DD54-4C74-AEB0-CE72A4ED95E6}" = Algo Vision LuraTech Browser Plug-ins
"InstallShield_{E922961C-6DB6-41DE-9FEA-426DF3E9F81C}" = IBM 32-bit Runtime Environment for Java 2, v1.4.2
"IrfanView" = IrfanView (remove only)
"ISO Commander" = ISO Commander 1.6 (remove only)
"IsoBuster_is1" = IsoBuster 2.7
"jclasslib bytecode viewer 3.0" = jclasslib bytecode viewer 3.0
"KompoZer_is1" = KompoZer 0.77
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Lavasoft VX2 Cleaner" = Lavasoft VX2 Cleaner
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaInfo" = MediaInfo 0.7.29
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Developer Network - Visual Studio 6.0a (deu)" = MSDN Library - Visual Studio 6.0a (Deutsch)
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"Mozilla Thunderbird (3.1.4)" = Mozilla Thunderbird (3.1.4)
"Mp3tag" = Mp3tag v2.46a
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyDefrag v4.2.5_is1" = MyDefrag v4.2.5
"MyDefrag v4.2.9_is1" = MyDefrag v4.2.9
"nbi-nb-base-6.0.0.0.200711201000" = NetBeans IDE 6.0 RC2
"nbi-nb-base-6.1.0.0.200804211638" = NetBeans IDE 6.1
"nbi-nb-base-6.5.0.0.200811100001" = NetBeans IDE 6.5
"nbi-nb-base-6.7.1.0.0" = NetBeans IDE 6.7.1
"nbi-nb-base-6.9.0.0.0" = NetBeans IDE 6.9
"nbi-nb-base-6.9.1.0.201006282301" = NetBeans IDE 6.9.1 Build 201006282301
"Nero - Burning Rom!UninstallKey" = Ahead Nero - Burning Rom
"Notepad++" = Notepad++
"NTFSRatio_is1" = NTFSRatio V1.3
"Nvu_is1" = Nvu 1.0
"OnScreenDisplay" = Anzeige am Bildschirm
"PC-Doctor 5 for Windows" = PC-Doctor 5 für Windows
"PFrank_is1" = Peter's Flexible RenAmiNg Kit (PFrank) 2.13
"Power Management Driver" = ThinkPad Power Management Driver
"Praesideo PC Callstation" = Praesideo PC Callstation
"Presentation Director" = ThinkPad-Präsentationsdirektor
"ProInst" = Intel PROSet Wireless
"QcDrv" = Logitech® Camera-Treiber
"RealPlayer 12.0" = RealPlayer
"RealVNC_is1" = VNC Free Edition 4.1.2
"Rename-It!" = Rename-It!
"ReNamer_is1" = ReNamer
"Secunia PSI" = Secunia PSI
"SequoiaView" = SequoiaView
"SpeedFan" = SpeedFan (remove only)
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"ThinkPadSoftwareInstaller" = Installationsprogramm für ThinkPad-Software
"TPKBDLED" = Scroll Lock Indicator Utility
"TPP200" = USB Storage Adapter V2 (TPP)
"TPP300" = USB Storage Adapter V3 (TPP)
"TPP725" = USB Storage Adapter (TPP)
"TreeSize Free_is1" = TreeSize Free V2.2.1
"UltraDefrag" = Ultra Defragmenter
"Unlocker" = Unlocker 1.8.7
"VLC media player" = VLC media player 1.1.4
"VoipDiscount_is1" = VoipDiscount
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WebPost" = Microsoft Web Publishing Wizard 1.53
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9-Reihe
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinHex" = WinHex
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.43
"WinMerge_is1" = WinMerge 2.12.4
"WinRAR archiver" = WinRAR
"winscp3_is1" = WinSCP 4.2.7
"WinZip" = WinZip
"WinZip Self-Extractor" = WinZip Self-Extractor
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2002Setup" = Microsoft Works 2002-Setup-Start
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"X10Hardware" = X10 Hardware(TM)
"xdocdiff" = xdocdiff
"XP Codec Pack" = XP Codec Pack
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"Z-DBackup" = Z-DBackup
"ZoomPlayer" = Zoom Player (remove only)
"ZoomPlayerLang" = Zoom Player deutsche Sprachdateien (entfernen)
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-999901472-3601035388-3065584919-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01D5859C-5207-4183-B88D-3DCD2022BC54}" = t@x 2008 Professional
"{40030378-9EB9-482A-AC10-195097CA624D}" = t@x 2009 Professional
"f6791b188d8f3ff8" = AVM FRITZ!Box USB-Fernanschluss
"InstallShield_{5F71EB81-C72E-4B28-8D90-FDEECFEBC2DE}" = PowerQuest Drive Image 2002
"jIRCii" = jIRCii
"muCommander" = muCommander
"StackTrace" = StackTrace
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 27.09.2010 11:59:17 | Computer Name = XXX | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung plugin-container.exe, Version 1.9.2.3909,
 fehlgeschlagenes Modul ntdll.dll, Version 5.1.2600.5755, Fehleradresse 0x0000100b.
 
Error - 27.09.2010 12:42:21 | Computer Name = XXX | Source = PerfNet | ID = 2004
Description = Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen
werden
 nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0.
 
Error - 27.09.2010 12:42:32 | Computer Name = XXX | Source = PerfNet | ID = 2004
Description = Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen
werden
 nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0.
 
Error - 27.09.2010 13:15:28 | Computer Name = XXX | Source = PerfNet | ID = 2004
Description = Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen
werden
 nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0.
 
Error - 27.09.2010 16:53:56 | Computer Name = XXX | Source = PerfNet | ID = 2004
Description = Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen
werden
 nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0.
 
Error - 28.09.2010 09:53:31 | Computer Name = XXX | Source = PerfNet | ID = 2004
Description = Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen
werden
 nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0.
 
Error - 28.09.2010 14:27:55 | Computer Name = XXX | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung ccc.exe, Version 2.0.0.0, fehlgeschlagenes
 Modul kernel32.dll, Version 5.1.2600.5781, Fehleradresse 0x00012afb.
 
Error - 28.09.2010 15:57:30 | Computer Name = XXX | Source = PerfNet | ID = 2004
Description = Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen
werden
 nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0.
 
Error - 29.09.2010 08:48:29 | Computer Name = XXX | Source = PerfNet | ID = 2004
Description = Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen
werden
 nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0.
 
Error - 30.09.2010 16:49:59 | Computer Name = XXX | Source = PerfNet | ID = 2004
Description = Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen
werden
 nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0.
 
[ Lenovo-Message Center Plus/*** Events ]
Error - 14.01.2010 09:38:09 | Computer Name = XXX | Source = Lenovo-Message Center Plus/*** | ID = 4
Description = Relevancy program timed out for message 'MCPToLTT_ROW': LTTCheck.exe
 
Error - 01.02.2010 22:52:42 | Computer Name = XXX | Source = Lenovo-Message Center Plus/*** | ID = 4
Description = Relevancy program timed out for message 'MCPToLTT_ROW': LTTCheck.exe
 
Error - 29.09.2010 08:13:50 | Computer Name = XXX | Source = Lenovo-Message Center Plus/*** | ID = 2
Description = IOException -> Exception message: Der Prozess kann nicht auf die Datei
 "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lenovo\MessageCenterPlus\LocalRepository\LocalRepository.bin"
 zugreifen, da sie von einem anderen Prozess verwendet wird.
 
[ System Events ]
Error - 29.09.2010 08:49:44 | Computer Name = XXX | Source = DCOM | ID = 10005
Description = Bei DCOM ist der Fehler "%1058" aufgetreten, als der Dienst "upnphost"
 mit den Argumenten ""  gestartet wurde, um den folgenden Server zu verwenden:  {204810B9-73B2-11D4-BF42-00B0D0118B56}
 
Error - 30.09.2010 09:20:20 | Computer Name = XXX | Source = Service Control Manager | ID = 7000
Description = Der Dienst "IBM Access Support" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%2
 
Error - 30.09.2010 14:01:13 | Computer Name = XXX | Source = Service Control Manager | ID = 7000
Description = Der Dienst "IBM Access Support" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%2
 
Error - 30.09.2010 16:50:41 | Computer Name = XXX | Source = Service Control Manager | ID = 7000
Description = Der Dienst "IBM Access Support" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%2
 
Error - 30.09.2010 16:50:41 | Computer Name = XXX | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Google Update Service (gupdate)" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%3
 
Error - 30.09.2010 16:50:41 | Computer Name = XXX | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Windows Media Player-Netzwerkfreigabedienst" ist vom Dienst
 "Universeller Plug & Play-Gerätehost" abhängig, der aufgrund folgenden Fehlers
nicht gestartet wurde:  %%1058
 
Error - 30.09.2010 16:50:53 | Computer Name = XXX | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Windows Media Player-Netzwerkfreigabedienst" ist vom Dienst
 "Universeller Plug & Play-Gerätehost" abhängig, der aufgrund folgenden Fehlers
nicht gestartet wurde:  %%1058
 
Error - 30.09.2010 16:51:05 | Computer Name = XXX | Source = DCOM | ID = 10005
Description = Bei DCOM ist der Fehler "%1058" aufgetreten, als der Dienst "upnphost"
 mit den Argumenten ""  gestartet wurde, um den folgenden Server zu verwenden:  {204810B9-73B2-11D4-BF42-00B0D0118B56}
 
Error - 01.10.2010 07:01:05 | Computer Name = XXX | Source = Service Control Manager | ID = 7011
Description = Zeitüberschreitung (30000 ms) beim Warten auf eine Transaktionsrückmeldung
 von Dienst WZCSVC.
 
Error - 01.10.2010 17:01:14 | Computer Name = XXX | Source = Service Control Manager | ID = 7000
Description = Der Dienst "IBM Access Support" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%2
 
 
< End of report >


Herzmann 01.10.2010 23:20

Liste der Anhänge anzeigen (Anzahl: 1)
Merkwürdigerweise kriege ich auch immer, wenn ich vom admin-Konto abmelde, und dann wieder zum eingeschränkten Konto zurück gehe folgende Meldung:

Herzmann 01.10.2010 23:30

Ich sollte vielleicht auch erwähnen, daß mein normales Benutzerkonto bis vor kurzem immer Admin-Rechte hatte. Erst seit www.camp-firefox.de/forum/viewtopic.php?p=678884#p678884 habe ich es eingeschränkt, und ein zusätzliches admin-Konto eingerichtet.

cosinus 03.10.2010 12:30

Dass Du nicht als Admin eingeloggt warst hab ich tatsächlich übersehen. Eigentlich solte es aber auch klar sein, dass man nur vernünftig analysieren und bereinigen kann, wenn man alle Rechte hat.

Zitat:

Zitat von Herzmann (Beitrag 574256)
Merkwürdigerweise kriege ich auch immer, wenn ich vom admin-Konto abmelde, und dann wieder zum eingeschränkten Konto zurück gehe folgende Meldung:

Verisign ist eine Zertifizierungststelle. Und rundll32.exe ist ein betriebbsystembestandteil. Dein Rechner will vermutlich wohl nur ein Zertifikat abgleichen. Es gibt da keinen Grund sowas blockieren zu wollen, Du kannst dieses sinnfreie FritzDSL-Protect getrost deinstallieren. Erst recht bringt so ein Programm Dir rein garnichts wenn Du die Meldungen nicht verstehst. Du erlaubst dann alles solange bis irgendwann alles so funktioniert wie Du es willst.


Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
SRV - (PsaSrv) -- C:\WINDOWS\System32\PsaSrv.exe File not found
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - No CLSID value found.
O3 - HKU\S-1-5-21-999901472-3601035388-3065584919-1005\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\autoexec.rod -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - F:\AUTOEXEC.ICR -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\autoexec.rod -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2003.10.20 15:35:04 | 000,000,042 | ---- | M] () - G:\AUTOEXEC.ICR -- [ FAT32 ]
O34 - HKLM BootExecute: (pgdfgsvc c 1) - C:\WINDOWS\System32\pgdfgsvc.exe (Sysinternals - www.sysinternals.com)
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Herzmann 05.10.2010 14:13

Zitat:

Zitat von cosinus (Beitrag 574490)
Dass Du nicht als Admin eingeloggt warst hab ich tatsächlich übersehen. Eigentlich solte es aber auch klar sein, dass man nur vernünftig analysieren und bereinigen kann, wenn man alle Rechte hat.

Auf der einen Seite JA, auf der anderen Seite gibt es Programme, die (1), obwohl vom eingeschränkten Benutzer aus gestartet, durchaus System-Voll-Zugriff haben, z.B. Virenscanner, Update-Installer etc., oder (2) meckern, wenn sie ihn vermissen.
Ich wußte ja nicht, (3) was OTL so alles scannt, (4) ob es in Default/Quick Konfiguration evtl. auch ohne Admin-Rechte auskommt, (5) bei spezieller Konfiguration dann evtl. ein extra Hinweis von Dir käme
und last but not least, (6) daß es sinnfrei klaglos weitermacht, wenn es keine Admin-Rechte hat.

Aber klar, es wäre nicht unlogisch gewesen, Admin-Rechte obligatorisch vorauszusetzen.

Würde es in der Anleitung nicht besser heißen:
Wenn mit Administrator-Rechten eingeloggt: Doppelklick auf die OTL.exe
Sonst: Rechtsklick auf die OTL.exe und "Ausführen als..." Administrator wählen

P.S.: Meine geposteten Malwarebytes scans sind, wenn ich mich recht entsinne, zum Teil auch ohne Admin-Rechte gelaufen. Kannst Du deren Aussagekraft noch mal überfliegen?

Zitat:

Verisign ist eine Zertifizierungststelle. Und rundll32.exe ist ein betriebbsystembestandteil. Dein Rechner will vermutlich wohl nur ein Zertifikat abgleichen. Es gibt da keinen Grund sowas blockieren zu wollen,
Danke! Ich dachte bislang, rundll32.exe kann auch von malware angestoßen und wie auch immer mißbraucht werden. Muß man da nicht vorsichtig sein? Wird doch schon seinen Sinn haben, warum FritzDSL-Protect da skeptisch nachfragt, statt einfach durchzuwinken.
Zitat:

Du kannst dieses sinnfreie FritzDSL-Protect getrost deinstallieren. Erst recht bringt so ein Programm Dir rein garnichts wenn Du die Meldungen nicht verstehst. Du erlaubst dann alles solange bis irgendwann alles so funktioniert wie Du es willst.
Da kennst Du mich aber schlecht. Ich erlaube längst nicht alles, selbst wenn es vertrauenswürdige SW ist. So habe ich eine prima Kontrolle über so manches, was da so heimlich im Hintergrund abgeht, und ich kann resourcen-fressende Aktionen unterbinden, bis ich mit meiner Arbeit fertig bin.

Zitat:

Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)
Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte.
- Es poppte kein log auf, und es wurde auch keins an die übliche Stelle geschrieben.
- Das ganze dauerte so ca. 10 Minuten.
- Unter Extra Registry, wählte ich NICHT Use SafeList
- Vor dem Start hat sich mal eben noch schnell ein Windows-Update dazwischen gemogelt, welches ich abgewartet habe, der Neustart-Anfrage aber zunächst nicht entsprochen habe (erst nach dem OTL-Scan).
Zitat:

Evtl. wird der Rechner neu gestartet.
- Höflicherweise hat OTL erst danach gefragt. :applaus:
- Nach dem Neustart hatte ich mindestens 20 Minuten einen schwarzen Bildschirm und gelegentliche Festplattenaktivität.
- Was dann noch wielange passierte ???, denn ich bin dann zu meiner Freundin. :pfeiff:
- Am nächsten Morgen begrüßte mich aber ein gutgelauntes Windows. :heilig:

Und an dieser Stelle schon mal ein herzliches Dankeschön für all die Bemühungen bisher.

Herzmann 05.10.2010 16:28

So, nun habe ich das Log doch gefunden.:headbang:

Nachdem ich den eingeschränkten Benutzer wieder abgemeldet hatte, um dann das OTL-Script nochmal auszuführen, meldete ich mich nochmal als Administrator an.
Tja, und was sah ich da...
Ohne weiteres Zutun war auf einmal das Log auf dem Schirm. Wieder per Zufall fand ich dann auch noch den Speicherort, als ich per "Speichern unter" in den Datei-Dialog gelangte, welcher mir genau diesen anbot, nämlich einen Ordner _OTL im Wurzelverzeichnis meiner Daten-Partition (ein voriger Hinweis darauf hätte mir einige Zeit und einiges Rätseln erspart).
Hier ist er also:

Code:

All processes killed
========== OTL ==========
Service PsaSrv stopped successfully!
Service PsaSrv deleted successfully!
File  C:\WINDOWS\System32\PsaSrv.exe File not found not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDF3E430-B101-42AD-A544-FADC6B084872}\ not found.
Registry value HKEY_USERS\S-1-5-21-999901472-3601035388-3065584919-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
F:\autoexec.rod moved successfully.
F:\AUTOEXEC.BAT moved successfully.
F:\AUTOEXEC.ICR moved successfully.
G:\autoexec.rod moved successfully.
G:\AUTOEXEC.BAT moved successfully.
G:\AUTOEXEC.ICR moved successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:pgdfgsvc c 1 deleted successfully.
C:\WINDOWS\system32\pgdfgsvc.exe moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
[EMPTYTEMP]
 
User: +++
->Temp folder emptied: 24994087 bytes
->Temporary Internet Files folder emptied: 375760 bytes
->Java cache emptied: 0 bytes
 
User: Administrator
->Temp folder emptied: 120396 bytes
->Temporary Internet Files folder emptied: 45293 bytes
 
User: All Users
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes
 
User: ***
->Temp folder emptied: 169905578 bytes
->Temporary Internet Files folder emptied: 90236586 bytes
->Java cache emptied: 12404600 bytes
->FireFox cache emptied: 58077962 bytes
->Flash cache emptied: 15182 bytes
 
User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 32902 bytes
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 34702 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2224038 bytes
%systemroot%\System32 .tmp files removed: 2951 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 44581426 bytes
RecycleBin emptied: 2856 bytes
 
Total Files Cleaned = 384,00 mb
 
 
OTL by OldTimer - Version 3.2.14.1 log created on 10042010_215157

Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...


cosinus 05.10.2010 19:40

Zitat:

Da kennst Du mich aber schlecht. Ich erlaube längst nicht alles, selbst wenn es vertrauenswürdige SW ist.
So, auch der default Browser? ;)
Wirklich böse Sachen kannst Du nicht (zuverlässig) blockieren, aber behalt es ruhig wenn Du meinst es sei ein tolles Hilfsmittel.

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Herzmann 06.10.2010 23:42

Liste der Anhänge anzeigen (Anzahl: 1)
Zitat:

Zitat von cosinus (Beitrag 575380)
So, auch der default Browser? ;)
  • Dann folgende Anleitung durchlesen und abarbeiten -> CCleaner Systembereinigung

Ich würde ungerne ALLES löschen.
Bei den Cookies z.B. sind ja durchaus einige auch nützlich.

Reichen nicht vielleicht auch folgende Einstellungen?

cosinus 07.10.2010 13:35

Ja das reicht auch aus. Deine Cookies kannste behalten.

Herzmann 08.10.2010 00:43

Neue Ergebnisse:
- Sofort nach Start von CoFi wurde erst mal der Rechner neu gestartet.
- Dieser mündete dann in "kein Zugriff"-Meldungen seitens CoFi, da automatische der eingeschränkte Nutzer gebootet wurde.
- Also nochmal booten, Shift-Taste festhalten und CoFi neu starten.
- Dann wurde die Wiederherstellungskonsole downgeloadet und installiert.
- ungefähr nach Schritt 5..7 kam ein Anwendungfehler wegen Exception.
- Nach einiger Zeit war das Hintergrundbild verschwunden, und ist nach späterem Neustart auch nicht mehr wiedergekommen.
- Ebenfalls wurden die Links des Startmenüs auf default desetzt.

Hier nun das Log-File:
Code:

ComboFix 10-10-07.01 - Admin 08.10.2010  0:39.1.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.49.1031.18.2046.1428 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\+++\Desktop\CoFi.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Sygate Personal Firewall *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.

((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\Temp
c:\windows\winhelp.ini

.
(((((((((((((((((((((((  Dateien erstellt von 2010-09-07 bis 2010-10-07  ))))))))))))))))))))))))))))))
.

2010-10-07 16:43 . 2006-12-14 08:00    110592    ----a-w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\U3\temp\cleanup.exe
2010-10-07 16:40 . 2007-02-12 15:46    3096576    ---ha-w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\U3\temp\Launchpad Removal.exe
2010-10-07 16:40 . 2010-10-07 16:40    --------    d-----w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\U3
2010-10-06 23:51 . 2010-10-06 23:56    --------    d-----w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\Notepad++
2010-10-06 00:46 . 2010-10-06 00:46    --------    d-----w-    c:\dokumente und einstellungen\+++\Lokale Einstellungen\Anwendungsdaten\AVM_Berlin
2010-10-05 22:32 . 2010-10-07 22:55    --------    d-----w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\FRITZ!
2010-10-05 18:07 . 2010-10-05 18:07    --------    d-----w-    c:\dokumente und einstellungen\+++\Lokale Einstellungen\Anwendungsdaten\Mozilla
2010-10-05 18:01 . 2010-10-05 22:50    --------    d-----w-    c:\dokumente und einstellungen\+++\Lokale Einstellungen\Anwendungsdaten\Deployment
2010-09-29 12:14 . 2009-12-17 12:37    14912    ----a-w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Lenovo\MessageCenterPlus\LocalRepository\Messages\MCPToLTT_ROW_1\LTTCheck.exe
2010-09-29 12:14 . 2009-12-17 06:44    560624    ----a-w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Lenovo\MessageCenterPlus\LocalRepository\Messages\MCPToLTT_ROW_1\appupdater.exe
2010-09-28 20:03 . 2010-09-28 20:03    --------    d-----w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\Malwarebytes
2010-09-28 18:24 . 2010-09-28 18:25    --------    d-----w-    c:\dokumente und einstellungen\+++\Lokale Einstellungen\Anwendungsdaten\Adobe
2010-09-23 08:36 . 2010-09-23 08:36    --------    d-----w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\Subversion
2010-09-23 08:27 . 2010-09-23 08:27    503808    ----a-w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-580a09f7-n\msvcp71.dll
2010-09-23 08:27 . 2010-09-23 08:27    12800    ----a-w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5a18f197-n\decora-d3d.dll
2010-09-23 08:27 . 2010-09-23 08:27    499712    ----a-w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-580a09f7-n\jmc.dll
2010-09-23 08:27 . 2010-09-23 08:27    61440    ----a-w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5a18f197-n\decora-sse.dll
2010-09-23 08:27 . 2010-09-23 08:27    348160    ----a-w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-580a09f7-n\msvcr71.dll
2010-09-20 17:49 . 2010-09-20 17:49    --------    d-----w-    c:\dokumente und einstellungen\Administrator\Anwendungsdaten\Subversion
2010-09-20 17:45 . 2010-09-20 17:45    168088    ----a-w-    c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
2010-09-20 17:44 . 2010-09-20 17:44    --------    d-----w-    c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\ATI
2010-09-20 17:44 . 2010-09-20 17:44    --------    d-----w-    c:\dokumente und einstellungen\Administrator\Anwendungsdaten\ATI
2010-09-20 17:44 . 2010-09-20 17:44    --------    d-----w-    c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Apple Computer
2010-09-20 17:44 . 2010-09-20 18:05    --------    d-----w-    c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\TSVNCache
2010-09-20 17:36 . 2010-09-20 17:36    168088    ----a-w-    c:\dokumente und einstellungen\+++\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
2010-09-20 17:36 . 2010-09-20 17:36    --------    d-----w-    c:\dokumente und einstellungen\+++\Lokale Einstellungen\Anwendungsdaten\ATI
2010-09-20 17:35 . 2010-09-20 17:35    --------    d-----r-    c:\dokumente und einstellungen\+++\Eigene Dateien
2010-09-16 16:36 . 2010-04-29 13:39    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-16 16:36 . 2010-09-16 16:36    --------    d-----w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes
2010-09-16 16:36 . 2010-04-29 13:39    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
2010-09-16 16:36 . 2010-09-17 13:04    --------    d-----w-    c:\programme\Malwarebytes' Anti-Malware
2010-09-08 23:36 . 2010-09-07 14:52    165584    ----a-w-    c:\windows\system32\drivers\aswSP.sys
2010-09-08 23:36 . 2010-09-07 14:47    17744    ----a-w-    c:\windows\system32\drivers\aswFsBlk.sys
2010-09-08 23:36 . 2010-09-07 14:47    23376    ----a-w-    c:\windows\system32\drivers\aswRdr.sys
2010-09-08 23:36 . 2010-09-07 14:52    46672    ----a-w-    c:\windows\system32\drivers\aswTdi.sys
2010-09-08 23:36 . 2010-09-07 14:47    100176    ----a-w-    c:\windows\system32\drivers\aswmon2.sys
2010-09-08 23:36 . 2010-09-07 14:47    94544    ----a-w-    c:\windows\system32\drivers\aswmon.sys
2010-09-08 23:36 . 2010-09-07 14:46    28880    ----a-w-    c:\windows\system32\drivers\aavmker4.sys
2010-09-08 23:36 . 2010-09-07 15:12    38848    ----a-w-    c:\windows\avastSS.scr
2010-09-08 23:36 . 2010-09-07 15:11    167592    ----a-w-    c:\windows\system32\aswBoot.exe
2010-09-08 23:35 . 2010-09-08 23:35    --------    d-----w-    c:\programme\Alwil Software
2010-09-08 23:35 . 2010-09-08 23:35    --------    d-----w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Alwil Software

.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-07 22:50 . 2010-09-01 22:02    1784720    ----a-w-    c:\dokumente und einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
2010-10-07 22:18 . 2010-10-07 22:18    0    ----a-w-    c:\dokumente und einstellungen\***\ntuser.tmp
2010-10-07 17:01 . 2006-10-11 12:36    --------    d-----w-    c:\programme\PowerArchiver
2010-10-06 23:05 . 2008-09-22 15:14    --------    d-----w-    c:\programme\CCleaner
2010-10-04 19:50 . 1979-12-31 22:00    86016    ----a-w-    c:\windows\system32\perfc007.dat
2010-10-04 19:50 . 1979-12-31 22:00    461330    ----a-w-    c:\windows\system32\perfh007.dat
2010-09-29 12:45 . 2008-02-14 09:16    --------    d-----w-    c:\programme\Microsoft Silverlight
2010-09-29 08:09 . 2007-12-20 17:26    664    ----a-w-    c:\windows\system32\d3d9caps.dat
2010-09-28 18:07 . 2009-11-23 14:53    --------    d-----w-    c:\programme\BitTorrent
2010-09-20 21:21 . 2010-09-20 17:35    --------    d-----w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\IBM
2010-09-20 17:36 . 2010-09-20 17:36    --------    d-----w-    c:\dokumente und einstellungen\+++\Anwendungsdaten\ATI
2010-09-17 13:07 . 2008-03-05 22:16    --------    d-----w-    c:\programme\Mozilla Thunderbird
2010-09-17 10:17 . 2008-02-14 08:52    --------    d-----w-    c:\programme\QuickTime
2010-09-17 10:17 . 2006-11-17 20:58    --------    d-----w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Apple Computer
2010-09-06 22:35 . 2010-09-06 22:35    45056    ----a-w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-09-06 22:35 . 2010-09-06 22:35    45056    ----a-w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-09-06 22:35 . 2010-09-06 22:35    45056    ----a-w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-09-06 22:35 . 2010-09-06 22:35    49152    ----a-w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-09-06 22:35 . 2010-09-06 22:35    45056    ----a-w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-09-06 22:35 . 2010-09-06 22:35    308808    ----a-w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-09-06 22:35 . 2010-09-06 22:35    14848    ----a-w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-09-06 22:35 . 2010-09-06 22:35    40960    ----a-w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-09-06 22:35 . 2010-05-06 16:42    341600    ----a-w-    c:\dokumente und einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-09-06 22:35 . 2006-11-17 21:10    --------    d-----w-    c:\programme\Gemeinsame Dateien\Real
2010-09-06 22:34 . 2006-11-17 21:10    --------    d-----w-    c:\programme\Real
2010-09-06 22:34 . 2010-09-06 22:34    --------    d-----w-    c:\programme\Gemeinsame Dateien\xing shared
2010-09-06 22:03 . 2006-11-17 22:46    --------    d-----w-    c:\programme\Gemeinsame Dateien\Java
2010-09-06 22:01 . 2006-11-17 22:46    --------    d-----w-    c:\programme\Java
2010-09-06 21:36 . 2006-10-11 11:56    --------    d-----w-    c:\programme\Gemeinsame Dateien\Adobe
2010-09-01 19:20 . 2009-03-22 10:40    --------    d-----w-    c:\programme\TortoiseHg
2010-09-01 19:20 . 2009-03-12 13:05    --------    d-----w-    c:\programme\Gemeinsame Dateien\TortoiseOverlays
2010-08-24 23:02 . 2008-04-17 10:16    --------    d-----w-    c:\programme\OpenOffice
2010-08-19 17:03 . 2006-12-07 23:57    --------    d-----w-    c:\programme\TortoiseSVN
2010-08-17 13:17 . 1979-12-31 22:00    58880    ----a-w-    c:\windows\system32\spoolsv.exe
2010-07-22 15:48 . 1979-12-31 22:00    590848    ----a-w-    c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 05:25    5632    ----a-w-    c:\windows\system32\xpsp4res.dll
2010-07-17 03:00 . 2010-05-09 12:28    423656    ----a-w-    c:\windows\system32\deployJava1.dll
2009-11-11 14:54 . 2008-03-20 21:39    30    ----a-w-    c:\programme\Exiferupdate.ini
2001-10-05 11:53 . 2006-11-13 23:13    21866    ----a-w-    c:\programme\Gemeinsame Dateien\tppupd2k.dll
.

((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50    66312    ----a-w-    c:\programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50    66312    ----a-w-    c:\programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50    66312    ----a-w-    c:\programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50    66312    ----a-w-    c:\programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50    66312    ----a-w-    c:\programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50    66312    ----a-w-    c:\programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50    66312    ----a-w-    c:\programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50    66312    ----a-w-    c:\programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50    66312    ----a-w-    c:\programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVMUSBFernanschluss"="c:\dokumente und einstellungen\+++\Lokale Einstellungen\Apps\2.0\P2PN3W8Y.MX4\860T49LP.4CK\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\AVMAutoStart.exe" [2010-10-05 139264]
"ibmmessages"="c:\programme\IBM\Messages By IBM\ibmmessages.exe" [2004-08-06 442368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tsnp2std"="c:\windows\tsnp2std.exe" [2007-01-05 258048]
"TpShocks"="TpShocks.exe" [2009-12-11 337256]
"TPP Auto Loader"="c:\windows\TPPALDR.EXE" [2001-10-05 118784]
"TPKMAPHELPER"="c:\programme\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-04 897024]
"TPKBDLED"="c:\windows\system32\TpScrLk.exe" [2002-10-08 40960]
"TPHOTKEY"="c:\programme\Lenovo\HOTKEY\TPOSDSVC.exe" [2007-03-09 66176]
"TP4EX"="tp4ex.exe" [2005-10-17 65536]
"SynTPLpr"="c:\programme\Synaptics\SynTP\SynTPLpr.exe" [2009-12-03 128296]
"SynTPEnh"="c:\programme\Synaptics\SynTP\SynTPEnh.exe" [2009-12-03 1594664]
"SoundMAXPnP"="c:\programme\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"snp2std"="c:\windows\vsnp2std.exe" [2006-09-15 675840]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-10-15 2577632]
"RemoteControl"="c:\programme\Home Cinema\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2009-12-16 513384]
"Microsoft Works Update Detection"="c:\programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe" [2001-10-04 28738]
"Microsoft Works Portfolio"="c:\programme\Microsoft Works\WksSb.exe" [2001-10-04 331830]
"ISUSScheduler"="c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ISUSPM Startup"="c:\progra~1\GEMEIN~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"IBMPRC"="c:\ibmtools\UTILS\ibmprc.exe" [2004-12-16 90112]
"ibmmessages"="c:\programme\IBM\Messages By IBM\ibmmessages.exe" [2004-08-06 442368]
"FinePrint Dispatcher v4"="c:\windows\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe" [2002-06-24 352256]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-10-08 256576]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-10-06 122940]
"CoolSwitch"="c:\windows\system32\taskswitch.exe" [2001-10-19 45632]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2009-12-16 208896]
"ATIPTA"="c:\programme\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-01-21 344064]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"AppleSyncNotifier"="c:\programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"TVT Scheduler Proxy"="c:\programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"LogitechCommunicationsManager"="c:\programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 488984]
"LogitechQuickCamRibbon"="c:\programme\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 774168]
"Message Center Plus"="c:\programme\LENOVO\Message Center Plus\MCPLaunch.exe" [2009-05-27 49976]
"StartCCC"="c:\programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-29 61440]
"ACTray"="c:\programme\ThinkPad\ConnectUtilities\ACTray.exe" [2009-12-10 431464]
"ACWLIcon"="c:\programme\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2009-12-10 181608]
"Adobe Reader Speed Launcher"="c:\programme\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"TortoiseHgOverlayIconServer"="c:\programme\TortoiseHg\TortoiseHgOverlayServer.exe" [2010-08-26 44448]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2010-05-14 248552]
"TkBellExe"="c:\programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" [2010-09-06 202256]
"avast5"="c:\programme\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2010-09-08 421888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\programme\Gemeinsame Dateien\logishrd\WUApp32.exe" [2007-05-11 441120]

c:\dokumente und einstellungen\Administrator\Startmen\Programme\Autostart\
Windows-Explorer.lnk - c:\windows\explorer.exe [1980-1-1 1036800]

c:\dokumente und einstellungen\Administrator\Startmen\Programme\Autostart\
Windows-Explorer.lnk - c:\windows\explorer.exe [1980-1-1 1036800]

c:\dokumente und einstellungen\+++\Startmen\Programme\Autostart\
FRITZ!DSL Protect.lnk - c:\programme\FRITZ!DSL\FwebProt.exe [2007-9-7 1070384]

c:\dokumente und einstellungen\All Users\Startmen\Programme\Autostart\
BTTray.lnk - c:\programme\ThinkPad\Bluetooth Software\BTTray.exe [2007-11-26 576104]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-29 24576]
EPSON SMART PANEL.lnk - c:\programme\EPSON\SMART PANEL\SmaPanel.exe [2006-11-10 156160]
EPSON Status Monitor 3 Environment Check.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV03.EXE [1999-10-22 217600]
Erinnerungen in Microsoft Works-Kalender.lnk - c:\programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\wkcalrem.exe [2001-10-4 24633]
Fax-Controller.lnk - c:\programme\EPSON\SMART PANEL\faxicore.exe [2006-11-10 24064]
FRITZ!DSL Startcenter.lnk - c:\windows\Installer\{2457326B-C110-40C3-89B0-889CC913871A}\Icon2457326B4.exe [2007-12-8 29184]
Telefonverbindungsmonitor.lnk - c:\programme\Sony Ericsson\Mobile\audevicemgr.exe [2007-3-29 754176]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 14:37    34344    ----a-w-    c:\programme\Lenovo\HOTKEY\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2006-12-14 09:06    28672    ----a-w-    c:\programme\Lenovo\HOTKEY\tphklock.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\%RunKey%]
2007-07-26 01:00    1515520    ----a-w-    c:\programme\FRITZ!vox\Fritz!vox.exe
2007-07-26 01:00    95    ----a-w-    c:\programme\FRITZ!vox\Fritz!vox.ini

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\VoipDiscount.com\\VoipDiscount\\VoipDiscount.exe"=
"c:\\Programme\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Programme\\Intuwave Ltd\\Shared\\mRouterRunTime\\mRouterRuntime.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Programme\\MySQL\\MySQL Server 5.0\\bin\\mysqld-nt.exe"=
"c:\\Programme\\WS_FTP\\WS_FTP95.exe"=
"c:\\Programme\\Java\\jdk1.6.0_03\\bin\\java.exe"=
"c:\\Programme\\Java\\jdk1.6.0_03\\jre\\bin\\java.exe"=
"c:\\Programme\\Java\\WTK22\\bin\\emulator.exe"=
"c:\\Programme\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"c:\\Program Files\\IBM\\Java142\\jre\\bin\\javaw.exe"=
"c:\\Programme\\Mozilla\\Firefox\\firefox.exe"=
"c:\\Programme\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Programme\\Java\\jre6\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Dokumente und Einstellungen\\***\\Lokale Einstellungen\\Apps\\2.0\\CDYO31ZO.VG2\\OEZVKJ02.55X\\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\\fritzbox-usb-fernanschluss.exe"=
"c:\\Programme\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programme\\BitTorrent\\bittorrent.exe"=
"c:\\Programme\\FRITZ!Box Monitor\\FRITZBoxMonitor.exe"=
"c:\\Programme\\FRITZ!vox\\Fritz!vox.exe"=
"c:\\CYGWIN\\bin\\rsync.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
"c:\\Dokumente und Einstellungen\\+++\\Lokale Einstellungen\\Apps\\2.0\\P2PN3W8Y.MX4\\860T49LP.4CK\\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\\fritzbox-usb-fernanschluss.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6198:TCP"= 6198:TCP:freenetSPEED
"3126:TCP"= 3126:TCP:freenetSPEED
"3128:TCP"= 3128:TCP:freenetSPEED

R0 DozeHDD;DozeHDD;c:\windows\system32\drivers\DOZEHDD.SYS [19.02.2010 15:11 24304]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [09.10.2009 12:10 20520]
R0 TPDiskPM;TPDiskPM;c:\windows\system32\drivers\TPDiskPM.sys [26.09.2006 00:48 14848]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [09.09.2010 01:36 165584]
R1 ui11rdr;ui11rdr;c:\windows\system32\drivers\ui11rdr.SYS [17.04.2008 17:10 148864]
R1 uigxrdr;uigxrdr;c:\windows\system32\drivers\uigxrdr.SYS [17.04.2008 18:17 148864]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [09.09.2010 01:36 17744]
R2 DozeSvc;Lenovo Doze Mode Service;c:\programme\ThinkPad\Utilities\DOZESVC.EXE [19.02.2010 15:11 132456]
R2 IGDCTRL;AVM IGD CTRL Service;c:\programme\FRITZ!DSL\IGDCTRL.EXE [04.09.2007 11:14 87344]
R2 Power Manager DBC Service;Power Manager DBC Service;c:\programme\ThinkPad\Utilities\PWMDBSVC.exe [28.10.2008 13:17 53248]
R3 avmaura;AVM USB-Fernanschluss;c:\windows\system32\drivers\avmaura.sys [07.09.2007 23:25 101248]
R3 GWUSB2E;USB 2.0 10/100Base Ethernet Adapter;c:\windows\system32\drivers\GWUSB2E.sys [13.11.2006 00:23 10496]
R3 TPInput;TPInput;c:\windows\system32\drivers\TPInput.sys [26.09.2006 00:48 6528]
R3 Wdm1;USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc.sys [13.11.2006 00:24 15576]
S2 gupdate;Google Update Service (gupdate);"c:\programme\Google\Update\GoogleUpdate.exe" /svc --> c:\programme\Google\Update\GoogleUpdate.exe [?]
S3 CXLWIRE;USB Hybrid Video Capture (DVB-T/PAL);c:\windows\system32\drivers\ctxusbtv.sys [04.09.2007 23:56 85120]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [13.04.2010 21:40 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [13.04.2010 21:40 8456]
S3 FTLUND;Lundinova Filter Driver;c:\windows\system32\drivers\ftlund.sys [10.10.2006 05:14 6828]
S3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\drivers\fwlanusb.sys [29.12.2007 20:29 264704]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [21.01.2008 20:26 13352]
S3 NETFWDSL;AVM FRITZ!web DSL PPP;c:\windows\system32\DRIVERS\NETFWDSL.SYS --> c:\windows\system32\DRIVERS\NETFWDSL.SYS [?]
S3 PORTMON;PORTMON;\??\c:\programme\sysinternals\PortMon\PORTMSYS.SYS --> c:\programme\sysinternals\PortMon\PORTMSYS.SYS [?]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [17.06.2009 14:20 12648]
S3 TPP200;USB Storage Adapter V2 (TPP);c:\windows\system32\drivers\tpp200.sys [14.11.2006 01:13 35541]
S3 ultradfg;ultradfg;c:\windows\system32\drivers\ultradfg.sys [06.10.2009 09:11 41984]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11.04.2009 21:25 721904]
.
Inhalt des "geplante Tasks" Ordners

2010-09-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

2010-10-07 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2006-09-25 00:12]

2010-10-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-999901472-3601035388-3065584919-1005.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]

2010-10-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-999901472-3601035388-3065584919-1008.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]

2010-10-07 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-999901472-3601035388-3065584919-1005.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]

2010-10-07 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-999901472-3601035388-3065584919-1008.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Connection Wizard,ShellNext = hxxp://clickonce.avm.de/usb-fernanschluss2/deutsch/fritzbox-usb-fernanschluss.application
IE: Senden an &Bluetooth - c:\programme\IBM\Bluetooth Software\btsendto_ie_ctx.htm
LSP: c:\programme\FRITZ!DSL\\sarah.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {15A7CF10-CB3E-4265-8779-9FD22619E8ED} - hxxp://192.168.1.205/XPanel.cab
DPF: {F74959B0-1779-472E-BE6E-3023E1DBEC73} - hxxp://192.168.1.205/XInit.cab
FF - ProfilePath - c:\dokumente und einstellungen\+++\Anwendungsdaten\Mozilla\Firefox\Profiles\tzh7ibcd.default\
FF - component: c:\dokumente und einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realplayer\Netscape6\nprpjplug.dll
FF - plugin: c:\programme\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\programme\Mozilla\Firefox\plugins\npldf32.dll
FF - plugin: c:\programme\Mozilla\Firefox\plugins\nplwf32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX Richtlinien ----
c:\programme\Mozilla\Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\programme\Mozilla\Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\programme\Mozilla\Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -

HKU-Default-RunOnce-IETI - c:\programme\Skype\Phone\IEPlugin\unins000.exe
Notify-ACNotify - ACNotify.dll



[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\vsdatant]
"ImagePath"=""
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------

- - - - - - - > 'winlogon.exe'(1260)
c:\programme\ThinkPad\ConnectUtilities\ACNotify.dll
c:\programme\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\programme\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\programme\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\Ati2evxx.dll
c:\programme\Lenovo\HOTKEY\tphklock.dll

- - - - - - - > 'lsass.exe'(1336)
c:\programme\FRITZ!DSL\sarah.dll
c:\programme\FRITZ!DSL\block.dll

- - - - - - - > 'explorer.exe'(4228)
c:\programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll
c:\programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll
c:\programme\TortoiseSVN\bin\TortoiseStub.dll
c:\programme\TortoiseSVN\bin\TortoiseSVN.dll
c:\programme\TortoiseSVN\bin\intl3_tsvn.dll
c:\programme\TortoiseHg\ThgShellx86.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\programme\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\System32\uigxnp.dll
c:\windows\System32\ui11np.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\Ati2evxx.exe
c:\programme\ThinkPad\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\Ati2evxx.exe
c:\programme\Intel\WiFi\bin\S24EvMon.exe
c:\programme\Lavasoft\Ad-Aware\aawservice.exe
c:\programme\Alwil Software\Avast5\AvastSvc.exe
c:\programme\TortoiseSVN\bin\TSVNCache.exe
c:\programme\gemeinsame dateien\logishrd\lvmvfm\LVPrcSrv.exe
c:\programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\programme\Intel\WiFi\bin\EvtEng.exe
c:\windows\system32\TpShocks.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\programme\Lenovo\HOTKEY\TPONSCR.exe
c:\programme\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\ThinkPad\UltraNav Wizard\UNavTray.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\programme\Java\jre6\bin\jqs.exe
c:\programme\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\NMSAccessU.exe
c:\programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe
c:\programme\Analog Devices\SoundMAX\SMAgent.exe
c:\programme\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\programme\Gemeinsame Dateien\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\system32\TpKmpSVC.exe
c:\programme\Gemeinsame Dateien\Lenovo\Scheduler\tvtsched.exe
c:\programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\fxssvc.exe
c:\programme\Gemeinsame Dateien\LogiShrd\LComMgr\LVComSX.exe
c:\dokumente und einstellungen\+++\Lokale Einstellungen\Apps\2.0\P2PN3W8Y.MX4\860T49LP.4CK\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe
c:\programme\lenovo\system update\suservice.exe
c:\programme\ThinkPad\ConnectUtilities\AcSvc.exe
c:\progra~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE
c:\progra~1\INTUWA~1\Shared\MROUTE~1\mRouterRuntime.exe
c:\windows\system32\wscntfy.exe
c:\programme\Gemeinsame Dateien\Logishrd\LQCVFX\COCIManager.exe
c:\progra~1\COMMON~1\X10\Common\x10nets.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programme\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2010-10-08  01:01:27 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2010-10-07 23:01

Vor Suchlauf: 5.601.693.696 Bytes frei
Nach Suchlauf: 5.868.056.576 Bytes frei

WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - B19B705E9E31850B541B14211643870E


cosinus 08.10.2010 11:32

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus

Downloade Dir anschließend bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur eine Sekunde.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

Herzmann 08.10.2010 11:48

Mal 'ne kurze Zwischenfrage:
War mein Rechner tatsächlich wirklich befallen, und der Trojaner auch schon aktiv,
oder sind wir noch in der Untersuchungs-Phase?

Ein Zwischenergebnis Deiner Einschätzung würde mich sehr interessieren, und woran (grob) Du das erkennen konntest.
Danke!

cosinus 08.10.2010 13:27

Ein paar Sachen waren dabei. Aber wirklich Böses hab ich noch nicht ausgemacht. Wird sich zeigen wie die nächsten Logs aussehen.

Herzmann 10.10.2010 19:53

Zitat:

Zitat von cosinus (Beitrag 576285)
Ein paar Sachen waren dabei. Aber wirklich Böses hab ich noch nicht ausgemacht. Wird sich zeigen wie die nächsten Logs aussehen.

Danke für den kurzen Zwischenbericht. Kannst Du evtl. Stellen in meinen logs aufzeigen, wo ich näheres über die "Ein paar Sachen" erkennen kann?

GMER habe ich ausgeführt.
Als ich am nächsten Morgen den etwas zugeklappten Notebook-Bildschirm öffnete, sah es zunächst für einen kurzen Blick aus dem Augenwinkel ganz gut aus, doch stieß ich dann versehentlich an die Maus (ohne Klick) und sah dann denn berühmten Anwendungsfehler-Dialog. Evtl. irre ich mich, aber ich hatte den Eindruck, daß der erst mit dem Anstoßen an die Maus dazukam. Das soll nur so mitgeteilt werden, vielleicht ist es ja von Wichtigkeit.

OSAM konnte ich leider nicht runterlagen, da der auf der Anleitung angegebene Link mehrmals in "Die Verbindung zum Server wurde zurückgesetzt, während die Seite geladen wurde." endete.
Hier nun das GMER-log:
Code:

GMER 1.0.15.15281 - hxxp://www.gmer.net
Rootkit scan 2010-10-10 07:56:11
Windows 5.1.2600 Service Pack 3
Running: pel7zqu1.exe; Driver: C:\DOKUME~1\+++\LOKALE~1\Temp\pgtdypod.sys


---- System - GMER 1.0.15 ----

SSDT            \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)                                                                      ZwAllocateVirtualMemory [0xB91D8B30]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwClose [0xB4D1ECF0]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwCreateKey [0xB4D1EBAC]
SSDT            \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)                                                                      ZwCreateThread [0xB91D86F0]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwDeleteKey [0xB4D1F160]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwDeleteValueKey [0xB4D1F08A]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwDuplicateObject [0xB4D1E782]
SSDT            \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)                                                                      ZwMapViewOfSection [0xB91D8470]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwOpenKey [0xB4D1EC86]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwOpenProcess [0xB4D1E6C2]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwOpenThread [0xB4D1E726]
SSDT            \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)                                                                      ZwProtectVirtualMemory [0xB91D8C50]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwQueryValueKey [0xB4D1EDA6]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwRenameKey [0xB4D1F22E]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwRestoreKey [0xB4D1ED66]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwSetValueKey [0xB4D1EEE6]
SSDT            \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)                                                                      ZwShutdownSystem [0xB91D8990]
SSDT            \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)                                                                      ZwTerminateProcess [0xB91D88D0]
SSDT            \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)                                                                      ZwWriteVirtualMemory [0xB91D8D60]

Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwCreateProcessEx [0xB4D2BBAE]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwCreateSection [0xB4D2B9D2]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ZwLoadDriver [0xB4D2BB0C]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  NtCreateSection
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ObInsertObject
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                  ObMakeTemporaryObject

---- Kernel code sections - GMER 1.0.15 ----

PAGE            ntkrnlpa.exe!ZwLoadDriver                                                                                                                              805795FA 7 Bytes  JMP B4D2BB10 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            ntkrnlpa.exe!NtCreateSection                                                                                                                          805A075C 7 Bytes  JMP B4D2B9D6 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            ntkrnlpa.exe!ObMakeTemporaryObject                                                                                                                    805B1CE0 5 Bytes  JMP B4D275D4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            ntkrnlpa.exe!ObInsertObject                                                                                                                            805B8B58 5 Bytes  JMP B4D28FFA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            ntkrnlpa.exe!ZwCreateProcessEx                                                                                                                        805C73EA 7 Bytes  JMP B4D2BBB2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text          C:\WINDOWS\system32\DRIVERS\ati2mtag.sys                                                                                                              section is writeable [0xB9946000, 0x1C5D38, 0xE8000020]
.text          tcpip.sys!IPTransmit + 10FC                                                                                                                            B4F55D3A 6 Bytes  CALL B9DBEE50 Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
.text          tcpip.sys!IPTransmit + 2A52                                                                                                                            B4F57690 6 Bytes  CALL B9DBEE50 Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
.text          tcpip.sys!IPRegisterProtocol + 930                                                                                                                    B4F6D454 6 Bytes  CALL B9DBEE50 Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
.text          wanarp.sys                                                                                                                                            B91CB3FD 7 Bytes  CALL B9DBEFA0 Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
.text          C:\WINDOWS\system32\drivers\ACEDRV05.sys                                                                                                              section is writeable [0xB2914000, 0x30A4A, 0xE8000020]
.pklstb        C:\WINDOWS\system32\drivers\ACEDRV05.sys                                                                                                              entry point in ".pklstb" section [0xB2956000]
.relo2          C:\WINDOWS\system32\drivers\ACEDRV05.sys                                                                                                              unknown last section [0xB2971000, 0x8E, 0x42000040]

---- User code sections - GMER 1.0.15 ----

.text          C:\Programme\Alwil Software\Avast5\AvastSvc.exe[684] kernel32.dll!SetUnhandledExceptionFilter                                                          7C84495D 4 Bytes  [C2, 04, 00, 90] {RET 0x4; NOP }

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT            \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter]                                                                                    [B9DBFC70] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter]                                                                                    [B9DBFBD0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol]                                                                              [B9DBFB10] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol]                                                                                [B9DBF8E0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol]                                                                              [B9DBF8E0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter]                                                                                    [B9DBFBD0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter]                                                                                  [B9DBFC70] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol]                                                                            [B9DBFB10] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol]                                                                              [B9DBFB10] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol]                                                                                [B9DBF8E0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter]                                                                                      [B9DBFBD0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter]                                                                                    [B9DBFC70] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol]                                                                                [B9DBF8E0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol]                                                                              [B9DBFB10] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter]                                                                                    [B9DBFC70] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter]                                                                                    [B9DBFBD0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter]                                                                                      [B9DBFC70] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter]                                                                                      [B9DBFBD0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol]                                                                                  [B9DBF8E0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol]                                                                              [B9DBFB10] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol]                                                                                [B9DBF8E0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter]                                                                                      [B9DBFBD0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter]                                                                                    [B9DBFC70] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter]                                                                                    [B9DBFC70] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter]                                                                                    [B9DBFBD0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol]                                                                              [B9DBFB10] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol]                                                                                [B9DBF8E0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\irda.sys[NDIS.SYS!NdisOpenAdapter]                                                                                        [B9DBFBD0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\irda.sys[NDIS.SYS!NdisRegisterProtocol]                                                                                  [B9DBF8E0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\irda.sys[NDIS.SYS!NdisCloseAdapter]                                                                                      [B9DBFC70] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\irda.sys[NDIS.SYS!NdisDeregisterProtocol]                                                                                [B9DBFB10] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol]                                                                                [B9DBF8E0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol]                                                                              [B9DBFB10] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter]                                                                                    [B9DBFC70] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT            \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter]                                                                                    [B9DBFBD0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\WINDOWS\system32\wscntfy.exe[272] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                      [00802EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\wscntfy.exe[272] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                              [00802C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\wscntfy.exe[272] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                            [00802C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\wscntfy.exe[272] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                                  [00802C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe[336] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                  [00C92EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe[336] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                          [00C92C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe[336] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                        [00C92C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe[336] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                              [00C92C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\Explorer.EXE[728] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                              [00AF2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\Explorer.EXE[728] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                                      [00AF2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\Explorer.EXE[728] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                                    [00AF2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\Explorer.EXE[728] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                                          [00AF2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\rundll32.exe[756] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                      [00AC2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\rundll32.exe[756] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                            [00AC2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\rundll32.exe[756] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                          [00AC2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\rundll32.exe[756] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                                [00AC2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE[796] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                    [00A32EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE[796] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                            [00A32C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE[796] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                          [00A32C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE[796] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                [00A32C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\services.exe[1160] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW]                                          00380002
IAT            C:\WINDOWS\system32\services.exe[1160] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW]                                                00380000
IAT            C:\Program Files\Digital Line Detect\DLG.exe[1244] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                        [00A82EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Program Files\Digital Line Detect\DLG.exe[1244] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                [00A82C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Program Files\Digital Line Detect\DLG.exe[1244] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                              [00A82C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Program Files\Digital Line Detect\DLG.exe[1244] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                    [00A82C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\rundll32.exe[1316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                    [00AC2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\rundll32.exe[1316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                            [00AC2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\rundll32.exe[1316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                          [00AC2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\rundll32.exe[1316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                                [00AC2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe[2004] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                      [00882EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe[2004] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                              [00882C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe[2004] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                            [00882C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe[2004] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                  [00882C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\LVComSX.exe[2308] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                        [00A52EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\LVComSX.exe[2308] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                [00A52C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\LVComSX.exe[2308] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                              [00A52C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\LVComSX.exe[2308] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                    [00A52C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2396] @ C:\WINDOWS\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                            [00B82EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2396] @ C:\WINDOWS\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                  [00B82C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2396] @ C:\WINDOWS\system32\KERNEL32.dll [ntdll.dll!NtClose]                                [00B82C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2396] @ C:\WINDOWS\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                      [00B82C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            c:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\mRouterRuntime.exe[2508] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                              [00AC2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            c:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\mRouterRuntime.exe[2508] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                    [00AC2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            c:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\mRouterRuntime.exe[2508] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                  [00AC2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            c:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\mRouterRuntime.exe[2508] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                        [00AC2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Dokumente und Einstellungen\All Users\Desktop\pel7zqu1.exe[2752] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                        [00802EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Dokumente und Einstellungen\All Users\Desktop\pel7zqu1.exe[2752] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]              [00802C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Dokumente und Einstellungen\All Users\Desktop\pel7zqu1.exe[2752] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                            [00802C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Dokumente und Einstellungen\All Users\Desktop\pel7zqu1.exe[2752] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                  [00802C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\TPPALDR.EXE[2756] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                              [009A2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\TPPALDR.EXE[2756] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                                      [009A2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\TPPALDR.EXE[2756] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                                    [009A2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\TPPALDR.EXE[2756] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                                          [009A2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Lenovo\HOTKEY\TPONSCR.exe[2832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                              [00A22EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Lenovo\HOTKEY\TPONSCR.exe[2832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                      [00A22C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Lenovo\HOTKEY\TPONSCR.exe[2832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                    [00A22C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Lenovo\HOTKEY\TPONSCR.exe[2832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                          [00A22C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\wkcalrem.exe[4068] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]          [00382EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\wkcalrem.exe[4068] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]  [00382C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\wkcalrem.exe[4068] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                [00382C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\wkcalrem.exe[4068] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]      [00382C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\TpScrLk.exe[4356] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                      [00992EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\TpScrLk.exe[4356] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                            [00992C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\TpScrLk.exe[4356] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                          [00992C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\TpScrLk.exe[4356] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                                [00992C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe[4724] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                [00FE2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe[4724] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                      [00FE2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe[4724] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                    [00FE2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe[4724] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                          [00FE2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Synaptics\SynTP\SynTPEnh.exe[4948] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                            [00BC2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Synaptics\SynTP\SynTPEnh.exe[4948] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                  [00BC2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Synaptics\SynTP\SynTPEnh.exe[4948] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                [00BC2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Synaptics\SynTP\SynTPEnh.exe[4948] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                      [00BC2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe[4964] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                        [003E2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe[4964] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                [003E2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe[4964] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                              [003E2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe[4964] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                    [003E2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\TortoiseSVN\bin\TSVNCache.exe[5028] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                          [00A72EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\TortoiseSVN\bin\TSVNCache.exe[5028] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                  [00A72C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\TortoiseSVN\bin\TSVNCache.exe[5028] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                [00A72C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\TortoiseSVN\bin\TSVNCache.exe[5028] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                      [00A72C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\Ati2evxx.exe[5040] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                    [00392EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\Ati2evxx.exe[5040] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                            [00392C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\Ati2evxx.exe[5040] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                          [00392C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\Ati2evxx.exe[5040] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                                [00392C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe[5072] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]            [00972EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe[5072] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]  [00972C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe[5072] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                [00972C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe[5072] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]      [00972C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe[5840] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                [00BA2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe[5840] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]        [00BA2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe[5840] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                      [00BA2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe[5840] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]            [00BA2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\IBMTOOLS\UTILS\ibmprc.exe[6328] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                        [00372EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\IBMTOOLS\UTILS\ibmprc.exe[6328] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                                [00372C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\IBMTOOLS\UTILS\ibmprc.exe[6328] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                              [00372C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\IBMTOOLS\UTILS\ibmprc.exe[6328] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                                    [00372C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe[6468] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                    [00C82EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe[6468] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                          [00C82C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe[6468] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                        [00C82C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe[6468] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                              [00C82C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Logishrd\LQCVFX\COCIManager.exe[6508] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                      [003D2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Logishrd\LQCVFX\COCIManager.exe[6508] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]            [003D2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Logishrd\LQCVFX\COCIManager.exe[6508] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                          [003D2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\Logishrd\LQCVFX\COCIManager.exe[6508] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                [003D2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe[6608] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                    [00D72EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe[6608] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                          [00D72C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe[6608] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                        [00D72C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe[6608] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                              [00D72C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\vsnp2std.exe[6640] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                              [00AE2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\vsnp2std.exe[6640] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                                    [00AE2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\vsnp2std.exe[6640] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                                  [00AE2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\vsnp2std.exe[6640] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                                        [00AE2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe[6692] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                              [003C2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe[6692] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                    [003C2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe[6692] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                  [003C2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe[6692] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                        [003C2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\TpShocks.exe[6772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                    [003B2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\TpShocks.exe[6772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                            [003B2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\TpShocks.exe[6772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                          [003B2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\TpShocks.exe[6772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                                [003B2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Synaptics\SynTP\SynTPLpr.exe[6984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                            [003A2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Synaptics\SynTP\SynTPLpr.exe[6984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                  [003A2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Synaptics\SynTP\SynTPLpr.exe[6984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                [003A2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Synaptics\SynTP\SynTPLpr.exe[6984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                      [003A2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[7084] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                    [003C2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[7084] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                          [003C2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[7084] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                        [003C2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[7084] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                              [003C2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\taskswitch.exe[7100] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                  [008D2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\taskswitch.exe[7100] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                          [008D2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\taskswitch.exe[7100] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                        [008D2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\system32\taskswitch.exe[7100] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                              [008D2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe[7144] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                              [009A2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe[7144] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                      [009A2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe[7144] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                    [009A2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe[7144] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                          [009A2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[7192] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                          [009F2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[7192] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                  [009F2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[7192] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                [009F2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[7192] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                      [009F2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe[7236] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                [00982EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe[7236] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]      [00982C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe[7236] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                    [00982C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe[7236] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]          [00982C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\IBM\Messages By IBM\ibmmessages.exe[7332] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                    [00BE2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\IBM\Messages By IBM\ibmmessages.exe[7332] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                            [00BE2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\IBM\Messages By IBM\ibmmessages.exe[7332] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                          [00BE2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\IBM\Messages By IBM\ibmmessages.exe[7332] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                [00BE2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\System32\DLA\DLACTRLW.EXE[7484] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                                [00A72EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\System32\DLA\DLACTRLW.EXE[7484] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                                        [00A72C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\System32\DLA\DLACTRLW.EXE[7484] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                                      [00A72C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\WINDOWS\System32\DLA\DLACTRLW.EXE[7484] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                                            [00A72C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\LENOVO\Message Center Plus\MCPLaunch.exe[7580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                [00962EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\LENOVO\Message Center Plus\MCPLaunch.exe[7580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                      [00962C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\LENOVO\Message Center Plus\MCPLaunch.exe[7580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                    [00962C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\LENOVO\Message Center Plus\MCPLaunch.exe[7580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                          [00962C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe[7624] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                  [003E2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe[7624] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                          [003E2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe[7624] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                        [003E2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe[7624] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                              [003E2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[7632] @ C:\WINDOWS\system32\KERNEL32.dll [ntdll.dll!NtCreateFile]                            [00802EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[7632] @ C:\WINDOWS\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile]                  [00802C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[7632] @ C:\WINDOWS\system32\KERNEL32.dll [ntdll.dll!NtClose]                                [00802C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[7632] @ C:\WINDOWS\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject]                      [00802C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe[7660] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]          [00AA2EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe[7660] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]  [00AA2C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe[7660] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                [00AA2C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe[7660] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]      [00AA2C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe[7816] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                  [00D42EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe[7816] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                        [00D42C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe[7816] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                      [00D42C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe[7816] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                            [00D42C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe[8128] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile]                                    [00A32EC0] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe[8128] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                          [00A32C30] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe[8128] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose]                                        [00A32C90] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT            C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe[8128] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                              [00A32C60] C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                                                                aswSP.SYS (avast! self protection module/AVAST Software)

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                                                                aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

Device          \FileSystem\Fastfat \FatCdrom                                                                                                                          aswSP.SYS (avast! self protection module/AVAST Software)

AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                                                              wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)
AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass0                                                                                                                Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass1                                                                                                                Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)

Device          \Driver\aswTdi \Device\AswUdpFilter                                                                                                                    wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)

AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                                                              wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)

Device          \Driver\aswTdi \Device\ASWTDI                                                                                                                          wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)
Device          \Driver\aswTdi \Device\AswTcpFilter                                                                                                                    wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)

AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                                                              wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                                                            wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)

Device          \FileSystem\Fastfat \Fat                                                                                                                              aswSP.SYS (avast! self protection module/AVAST Software)

AttachedDevice  \FileSystem\Fastfat \Fat                                                                                                                              fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice  \FileSystem\Fastfat \Fat                                                                                                                              aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

Device          \FileSystem\Cdfs \Cdfs                                                                                                                                DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)                                                 
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                                                        C:\Programme\Alcohol Soft\Alcohol 120\
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                                        0
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                                    0xFF 0x36 0xBB 0x94 ...
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)                                         
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                                              0x20 0x01 0x00 0x00 ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000e9bda3b35                                                                           
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                                                     
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                                    0
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                                0xFF 0x36 0xBB 0x94 ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001                                                             
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                                        0xF6 0x70 0xC0 0xA2 ...
Reg            HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\000e9bda3b35 (not active ControlSet)                                                       
Reg            HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)                                                 
Reg            HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                                        0
Reg            HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                                    0xFF 0x36 0xBB 0x94 ...
Reg            HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)                                         
Reg            HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                                            0xF6 0x70 0xC0 0xA2 ...

---- Files - GMER 1.0.15 ----

File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-j2ee-metadata.xml                                                        419 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-j2ee-persistence-kit.xml                                                438 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-j2ee-persistence.xml                                                    428 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-j2ee-persistenceapi.xml                                                  437 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-j2ee-toplinklib.xml                                                      752 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-debug.xml                                                          411 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-editor-lib.xml                                                      426 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-editor.xml                                                          422 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-examples.xml                                                        420 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-freeform.xml                                                        420 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-guards.xml                                                          414 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-helpset.xml                                                        507 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-hints.xml                                                          415 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-j2seplatform.xml                                                    534 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-j2seproject.xml                                                    538 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-kit.xml                                                            402 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-lexer.xml                                                          411 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-apache-tools-ant-module.xml                                                              3830 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-api-debugger-jpda.xml                                                            409 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-api-java.xml                                                                    381 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-libs-javacapi.xml                                                                460 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-libs-javacimpl.xml                                                              468 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-ant-browsetask.xml                                                      510 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-ant-debugger.xml                                                        419 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-platform.xml                                                        517 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-preprocessorbridge.xml                                              447 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-project.xml                                                        516 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-source.xml                                                          416 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-sourceui.xml                                                        424 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-javadoc.xml                                                              405 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-javawebstart-signtask.xml                                                537 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-javawebstart.xml                                                        415 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-junit.xml                                                                593 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-refactoring-java.xml                                                    428 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-swingapp.xml                                                            622 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-websvc-jaxws21.xml                                                      1369 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-websvc-jaxws21api.xml                                                    900 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-websvc-serviceapi.xml                                                    430 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-ant-freeform.xml                                                        418 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-j2ee-metadata-model-support.xml                                          462 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-java-navigation.xml                                                      425 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-ant-grammar.xml                                                          414 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-ant-kit.xml                                                              398 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-dbschema.xml                                                            494 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-debugger-jpda-ant.xml                                                    523 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-debugger-jpda-projects.xml                                              447 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-debugger-jpda-ui.xml                                                    428 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-debugger-jpda.xml                                                        421 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-derby.xml                                                                462 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-form-j2ee.xml                                                            408 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-form-kit.xml                                                            401 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-form.xml                                                                862 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-i18n-form.xml                                                            409 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-i18n.xml                                                                394 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-j2ee-jpa-refactoring.xml                                                438 bytes
File            C:\Programme\Java\NetBeans 6.0 RC2\java1\update_tracking\org-netbeans-modules-j2ee-jpa-verification.xml                                                444 bytes

---- EOF - GMER 1.0.15 ----


cosinus 10.10.2010 21:00

OSAM hatte ich als zip vor ein paar Wochen mal hochgeladen => File-Upload.net - osam.zip

Herzmann 11.10.2010 08:49

Liste der Anhänge anzeigen (Anzahl: 1)
Danke!

Zitat:

Zitat von cosinus (Beitrag 576285)
Ein paar Sachen waren dabei. Aber wirklich Böses hab ich noch nicht ausgemacht. Wird sich zeigen wie die nächsten Logs aussehen.

Danke für den kurzen Zwischenbericht. Kannst Du evtl. Stellen in meinen logs aufzeigen, wo ich näheres über die "Ein paar Sachen" erkennen kann?

Ansonsten scheint die Datenbank für OSAM leider offline zu sein...

cosinus 11.10.2010 10:21

Die DB-Abfrage von OSAM brauchst du nicht. Ich will einfach nur das Log sehen.

Herzmann 11.10.2010 11:57

Als ich vom AdministratorBenutzer wieder hierher zurückgekehrt bin, fragte mich meine FRITZ!Protect-Firewall, ob OSAM der Zugriff zum Internet erlaubt werden soll, und das, obwohl ich OSAM unter dem AdministratorBenutzer komplett geschlossen hatte. Es scheint also einen Unterprozess zu geben, welcher noch im eingeschränkten Benutzermodus aktiv zu sein scheint.
Das zum Thema, warum ich diese Firewall und deren Infomationen für nützlich halte.

Code:

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html lang="en">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Report of OSAM: Autorun Manager v5.0.11926.0</title>
<style type="text/css">
body
{
    margin                    : 10px 10px 10px 20px;
    color                    : #000000;
    background-color          : #fffbf0;
    font                      : 10pt Tahoma, Verdana, Arial, Helvetica, sans-serif;
    scrollbar-3dlight-color  : #fffbf0;
    scrollbar-arrow-color    : #000000;
    scrollbar-darkshadow-color: #000000;
    scrollbar-face-color      : #fffbf0;
    scrollbar-highlight-color : #000000;
    scrollbar-shadow-color    : #fffbf0;
    scrollbar-track-color    : #fffbf0;
}
a:link
{
    color: #e15616;
}
a:visited
{
    color: #e15616;
}
a:hover
{
    color: #e4743f;
}
a:active
{
    color: #e4743f;
}
.header1
{
    font-size  : 115%;
    font-weight: bold;
    margin-left: 0px;
}
table
{
    border-collapse: collapse;
    border        : 1px solid #000000;
    cellpadding    : 0;
    cellspacing    : 0;
    width          : 90%;
}
td,th
{
    font-size    : 12px;
    color        : #000000;
    background    : #fffbf0;
    border        : 1px solid #000000;
    text-align    : left;
    vertical-align: top;
    padding      : 2px 4px 2px 4px;
}
.cap
{
    font-weight: bold;
    font-size  : 10pt;
    padding    : 2px 4px 2px 4px;
    border    : 1px solid #000000;
}
.group
{
    font-weight: bold;
    font-size  : 10pt;
    padding    : 2px 4px 2px 4px;
    text-align : center;
}
.reg
{
    font-weight: bold;
    font-size  : 10pt;
    border    : 0px none;
    padding    : 2px 4px 2px 4px;
}
.notfound
{
    background-color: #B3DDFF;
}
.blocked
{
    background-color: #FF96EB;
}
.nodetails
{
    background-color: #FFFF75;
}
.trusted
{
    background-color: #C8FFC8;
}
.rootkit
{
    background-color: #FF8696;
}
td.rs { text-align: center; vertical-align: center; font-family: courier; }
td.rs.rm { background: #F90424; title: "Malware"; }
td.rs.ri { background: #F90424; title: "Infected"; color: #21F411; }
td.rs.rw { background: #F90424; title: "Unwanted"; }
td.rs.rs { background: #F90424; title: "Suspicious"; }
td.rs.rt { background: #21F411; title: "Trusted"; }
td.rs.rc { background: #21F411; title: "Checked"; }
td.rs.ry { background: #21F411; title: "Up-to-You"; }
td.rs.rr { background: #F6EB13; title: "Riskware"; }
td.rs.ru { background: #D4D0C8; title: "Unknown"; }
td.rs.rn { background: #FFFFFF; title: "Not checked"; }
</style>
</head>
<body>
<p><span class="header1">Report of OSAM: Autorun Manager v5.0.11926.0</span><br>
<a href="hxxp://www.online-solutions.ru/en/" target="_blank">hxxp://www.online-solutions.ru/en/</a><br>
Saved at 12:38:23 on 11.10.2010</p>
<b>OS</b>: Windows XP Professional Service Pack 3 (Build 2600)<br>
<b>Default Browser</b>: Microsoft Corporation Internet Explorer 6.00.2900.5512<br>
<br><b>Scanner Settings</b><br>
<input type="checkbox" disabled checked>Rootkits detection (hidden registry)<br>
<input type="checkbox" disabled checked>Rootkits detection (hidden files)<br>
<input type="checkbox" disabled checked>Retrieve files information<br>
<input type="checkbox" disabled checked>Check Microsoft signatures<br>
<br><b>Filters</b><br>
<input type="checkbox" disabled>Trusted entries<br>
<input type="checkbox" disabled>Empty entries<br>
<input type="checkbox" disabled checked>Hidden registry entries (rootkit activity)<br>
<input type="checkbox" disabled checked>Exclusively opened files<br>
<input type="checkbox" disabled checked>Not found files<br>
<input type="checkbox" disabled checked>Files without detailed information<br>
<input type="checkbox" disabled checked>Existing files<br>
<input type="checkbox" disabled>Non-startable services<br>
<input type="checkbox" disabled>Non-startable drivers<br>
<input type="checkbox" disabled checked>Active entries<br>
<input type="checkbox" disabled checked>Disabled entries<br>
<br>
<table border="1" cellpadding="0" cellspacing="0">
<tr>
<th class="cap" width="20">&nbsp;</th>
<th class="cap">Risk</th>
<th class="cap">Name</th>
<th class="cap">Publisher</th>
<th class="cap">Full Path</th>
<th class="cap">Status</th>
</tr>
<tr>
<td class="group" colspan="6">Boot Execute</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\SYSTEM\CurrentControlSet\Control\Session Manager</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td>
<td class="nodetails">"BootExecute"</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\system32\lsdelete.exe</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td class="group" colspan="6">Common</td>
</tr>
<tr>
<td class="reg" colspan="6">%SystemRoot%\Tasks</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"AppleSoftwareUpdate.job"</td>
<td>"Apple Inc."</td>
<td>C:\Programme\Apple Software Update\SoftwareUpdate.exe</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"GoogleUpdateTaskMachineUA.job"</td>
<td class="notfound"></td>
<td class="notfound">C:\Programme\Google\Update\GoogleUpdate.exe</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"PMTask.job"</td>
<td class="nodetails"></td>
<td class="nodetails">C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"RealUpgradeLogonTaskS-1-5-21-999901472-3601035388-3065584919-1005.job"</td>
<td>"RealNetworks, Inc."</td>
<td>C:\Programme\Real\RealUpgrade\realupgrade.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"RealUpgradeLogonTaskS-1-5-21-999901472-3601035388-3065584919-1008.job"</td>
<td>"RealNetworks, Inc."</td>
<td>C:\Programme\Real\RealUpgrade\realupgrade.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"RealUpgradeScheduledTaskS-1-5-21-999901472-3601035388-3065584919-1005.job"</td>
<td>"RealNetworks, Inc."</td>
<td>C:\Programme\Real\RealUpgrade\realupgrade.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"RealUpgradeScheduledTaskS-1-5-21-999901472-3601035388-3065584919-1008.job"</td>
<td>"RealNetworks, Inc."</td>
<td>C:\Programme\Real\RealUpgrade\realupgrade.exe</td>
<td>File exists</td>
</tr>
<tr>
<td class="group" colspan="6">Control Panel Objects</td>
</tr>
<tr>
<td class="reg" colspan="6">%SystemRoot%\system32</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"btcpl.cpl"</td>
<td>"Broadcom Corporation."</td>
<td>C:\WINDOWS\system32\btcpl.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ecsepm.cpl"</td>
<td>"Teleca Software Solutions AB"</td>
<td>C:\WINDOWS\system32\ecsepm.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"IBMJavaPlugin142.cpl"</td>
<td>"IBM"</td>
<td>C:\WINDOWS\system32\IBMJavaPlugin142.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"infocardcpl.cpl"</td>
<td>"Microsoft Corporation"</td>
<td>C:\WINDOWS\system32\infocardcpl.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ISUSPM.cpl"</td>
<td>"InstallShield Software Corporation"</td>
<td>C:\WINDOWS\system32\ISUSPM.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"javacpl.cpl"</td>
<td>"Sun Microsystems, Inc."</td>
<td>C:\WINDOWS\system32\javacpl.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"PWMCPl.cpl"</td>
<td>"Lenovo Group Limited"</td>
<td>C:\WINDOWS\system32\PWMCPl.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Spcselfb.cpl"</td>
<td>"SEIKO EPSON CORP."</td>
<td>C:\WINDOWS\system32\Spcselfb.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"tp4ex.cpl"</td>
<td>"IBM Corporation"</td>
<td>C:\WINDOWS\system32\tp4ex.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TP98.CPL"</td>
<td>"Lenovo Group Limited"</td>
<td>C:\WINDOWS\system32\TP98.CPL</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TpShCPL.cpl"</td>
<td>"Lenovo."</td>
<td>C:\WINDOWS\system32\TpShCPL.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ECSEPM"</td>
<td>"Sony Ericsson Mobile Communications AB"</td>
<td>C:\Programme\Sony Ericsson\Mobile\Mobile Phone Monitor\ecsepm.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"QuickTime"</td>
<td>"Apple Inc."</td>
<td>C:\Programme\QuickTime\QTSystem\QuickTime.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"SMAX4CP"</td>
<td>"Analog Devices, Inc."</td>
<td>C:\Programme\Analog Devices\SoundMAX\SMax4.cpl</td>
<td>File exists</td>
</tr>
<tr>
<td class="group" colspan="6">Drivers</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\SYSTEM\CurrentControlSet\Services</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ACEDRV05" (ACEDRV05)</td>
<td>"Protect Software GmbH"</td>
<td>C:\WINDOWS\system32\drivers\ACEDRV05.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ANC" (ANC)</td>
<td>"IBM Corp."</td>
<td>C:\WINDOWS\System32\drivers\ANC.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"APS Digitizer Activity Monitor" (TPDIGIMN)</td>
<td>"Lenovo."</td>
<td>C:\WINDOWS\System32\DRIVERS\ApsHM86.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Aspi32" (Aspi32)</td>
<td>"Adaptec"</td>
<td>C:\WINDOWS\system32\drivers\Aspi32.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"aswFsBlk" (aswFsBlk)</td>
<td>"AVAST Software"</td>
<td>C:\WINDOWS\system32\drivers\aswFsBlk.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"aswMon2" (aswMon2)</td>
<td>"AVAST Software"</td>
<td>C:\WINDOWS\system32\drivers\aswMon2.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"aswRdr" (aswRdr)</td>
<td>"AVAST Software"</td>
<td>C:\WINDOWS\system32\drivers\aswRdr.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"aswSP" (aswSP)</td>
<td>"AVAST Software"</td>
<td>C:\WINDOWS\system32\drivers\aswSP.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"avast! Asynchronous Virus Monitor" (Aavmker4)</td>
<td>"AVAST Software"</td>
<td>C:\WINDOWS\system32\drivers\Aavmker4.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"avast! Network Shield Support" (aswTdi)</td>
<td>"AVAST Software"</td>
<td>C:\WINDOWS\system32\drivers\aswTdi.sys</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"AVM FRITZ!web DSL PPP" (NETFWDSL)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\System32\DRIVERS\NETFWDSL.SYS</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"AVM USB-Fernanschluss" (avmaura)</td>
<td>"AVM Berlin"</td>
<td>C:\WINDOWS\System32\DRIVERS\avmaura.sys</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"catchme" (catchme)</td>
<td class="notfound"></td>
<td class="notfound">C:\DOKUME~1\+++\LOKALE~1\Temp\catchme.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"Changer" (Changer)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\system32\drivers\Changer.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"Conexant Setup API" (UIUSys)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\System32\drivers\UIUSys.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"DLABOIOM" (DLABOIOM)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\DLA\DLABOIOM.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"DLACDBHM" (DLACDBHM)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\Drivers\DLACDBHM.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"DLADResN" (DLADResN)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\DLA\DLADResN.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"DLAIFS_M" (DLAIFS_M)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\DLA\DLAIFS_M.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"DLAOPIOM" (DLAOPIOM)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\DLA\DLAOPIOM.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"DLAPoolM" (DLAPoolM)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\DLA\DLAPoolM.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"DLARTL_N" (DLARTL_N)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\Drivers\DLARTL_N.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"DLAUDFAM" (DLAUDFAM)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\DLA\DLAUDFAM.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"DLAUDF_M" (DLAUDF_M)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\DLA\DLAUDF_M.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"DozeHDD" (DozeHDD)</td>
<td>"Lenovo."</td>
<td>C:\WINDOWS\System32\DRIVERS\DozeHDD.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"drvmcdb" (drvmcdb)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\Drivers\DRVMCDB.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"drvnddm" (drvnddm)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\Drivers\DRVNDDM.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"epmntdrv" (epmntdrv)</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\system32\epmntdrv.sys</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"EuGdiDrv" (EuGdiDrv)</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\system32\EuGdiDrv.sys</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"GEAR ASPI Filter Driver" (GEARAspiWDM)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"giveio" (giveio)</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\System32\giveio.sys</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"IBM Access Support" (EGATHDRV)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\SYSTEM32\EGATHDRV.SYS</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"IBMTPCHK" (IBMTPCHK)</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\system32\Drivers\IBMBLDID.sys</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"Imagedrv" (Imagedrv)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\System32\DRIVERS\imagedrv.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"IVI ASPI Shell" (Iviaspi)</td>
<td>"InterVideo, Inc."</td>
<td>C:\WINDOWS\System32\drivers\iviaspi.sys</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"lbrtfdc" (lbrtfdc)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\system32\drivers\lbrtfdc.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Logitech LVPrcMon Driver" (LVPrcMon)</td>
<td>"Logitech Inc."</td>
<td>C:\WINDOWS\system32\drivers\LVPrcMon.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Padus ASPI Shell" (Pfc)</td>
<td>"Padus, Inc."</td>
<td>C:\WINDOWS\System32\drivers\pfc.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"PalmUSBD" (PalmUSBD)</td>
<td>"Palm, Inc."</td>
<td>C:\WINDOWS\System32\drivers\PalmUSBD.sys</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"PCDRNDISUIO Usermode I/O Protocol" (PcdrNdisuio)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\System32\DRIVERS\pcdrndisuio.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"PCIDump" (PCIDump)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\system32\drivers\PCIDump.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"PDCOMP" (PDCOMP)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\system32\drivers\PDCOMP.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"PDFRAME" (PDFRAME)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\system32\drivers\PDFRAME.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"PDRELI" (PDRELI)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\system32\drivers\PDRELI.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"PDRFRAME" (PDRFRAME)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\system32\drivers\PDRFRAME.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"PMEM" (PMEM)</td>
<td>"Microsoft Corporation"</td>
<td>C:\WINDOWS\SYSTEM32\Drivers\PMEMNT.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"PORTMON" (PORTMON)</td>
<td class="notfound"></td>
<td class="notfound">C:\Programme\sysinternals\PortMon\PORTMSYS.SYS</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"PQNTDrv" (PQNTDrv)</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\system32\drivers\PQNTDrv.sys</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"PSI" (PSI)</td>
<td>"Secunia"</td>
<td>C:\WINDOWS\System32\DRIVERS\psi_mf.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"PxHelp20" (PxHelp20)</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\Drivers\PxHelp20.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Shockprf" (Shockprf)</td>
<td>"Lenovo."</td>
<td>C:\WINDOWS\System32\DRIVERS\Apsx86.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Smapint" (Smapint)</td>
<td>"Microsoft Corporation"</td>
<td>C:\WINDOWS\System32\drivers\Smapint.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Sony Ericsson Device 039 Driver driver (WDM)" (SE27bus)</td>
<td>"MCCI"</td>
<td>C:\WINDOWS\System32\DRIVERS\SE27bus.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS)" (se27nd5)</td>
<td>"MCCI"</td>
<td>C:\WINDOWS\System32\DRIVERS\se27nd5.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM)" (se27unic)</td>
<td>"MCCI"</td>
<td>C:\WINDOWS\System32\DRIVERS\se27unic.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM)" (SE27mgmt)</td>
<td>"MCCI"</td>
<td>C:\WINDOWS\System32\DRIVERS\SE27mgmt.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Sony Ericsson Device 039 USB WMC Modem Driver" (SE27mdm)</td>
<td>"MCCI"</td>
<td>C:\WINDOWS\System32\DRIVERS\SE27mdm.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Sony Ericsson Device 039 USB WMC Modem Filter" (SE27mdfl)</td>
<td>"MCCI"</td>
<td>C:\WINDOWS\System32\DRIVERS\SE27mdfl.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Sony Ericsson Device 039 USB WMC OBEX Interface" (SE27obex)</td>
<td>"MCCI"</td>
<td>C:\WINDOWS\System32\DRIVERS\SE27obex.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"speedfan" (speedfan)</td>
<td>"Windows (R) 2000 DDK provider"</td>
<td>C:\WINDOWS\System32\speedfan.sys</td>
<td>File exists</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"StarOpen" (StarOpen)</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\system32\drivers\StarOpen.sys</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"SyGate for NT, wg3n" (wg3n)</td>
<td>"Sygate Technologies, Inc."</td>
<td>C:\WINDOWS\SYSTEM32\Drivers\wg3n.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"SyGate for NT, wg4n" (wg4n)</td>
<td>"Sygate Technologies, Inc."</td>
<td>C:\WINDOWS\SYSTEM32\Drivers\wg4n.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"SyGate for NT, wg5n" (wg5n)</td>
<td>"Sygate Technologies, Inc."</td>
<td>C:\WINDOWS\SYSTEM32\Drivers\wg5n.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"SyGate for NT, wg6n" (wg6n)</td>
<td>"Sygate Technologies, Inc."</td>
<td>C:\WINDOWS\SYSTEM32\Drivers\wg6n.sys</td>
<td>File exists</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"TDSMAPI" (TDSMAPI)</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\System32\drivers\TDSMAPI.SYS</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Teefer for NT" (Teefer)</td>
<td>"Sygate Technologies, Inc."</td>
<td>C:\WINDOWS\System32\Drivers\Teefer.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TPDiskPM" (TPDiskPM)</td>
<td>"Lenovo, Ltd. and IBM Corporation"</td>
<td>C:\WINDOWS\system32\drivers\TPDiskPM.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TPHKDRV" (TPHKDRV)</td>
<td>"IBM Corporation"</td>
<td>C:\WINDOWS\System32\DRIVERS\TPHKDRV.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TPInput" (TPInput)</td>
<td>"Lenovo, Ltd. and IBM Corporation."</td>
<td>C:\WINDOWS\System32\DRIVERS\TPInput.sys</td>
<td>File exists</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"TPPWRIF" (TPPWRIF)</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\System32\drivers\Tppwrif.sys</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"TSMAPIP" (TSMAPIP)</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\System32\drivers\TSMAPIP.SYS</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ui11rdr" (ui11rdr)</td>
<td>"1&1 Internet AG"</td>
<td>C:\WINDOWS\System32\DRIVERS\ui11rdr.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"uigxrdr" (uigxrdr)</td>
<td>"GMX GmbH"</td>
<td>C:\WINDOWS\System32\DRIVERS\uigxrdr.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ultradfg" (ultradfg)</td>
<td>"UltraDefrag Development Team"</td>
<td>C:\WINDOWS\System32\DRIVERS\ultradfg.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"USB 2.0 10/100Base Ethernet Adapter" (GWUSB2E)</td>
<td>"Generic "</td>
<td>C:\WINDOWS\System32\DRIVERS\GWUSB2E.sys</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"USB Storage Adapter V2 (TPP)" (TPP200)</td>
<td>"In-System Design, Inc."</td>
<td>C:\WINDOWS\System32\DRIVERS\TPP200.SYS</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"WDICA" (WDICA)</td>
<td class="notfound"></td>
<td class="notfound">C:\WINDOWS\system32\drivers\WDICA.sys</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"wpsdrvnt" (wpsdrvnt)</td>
<td>"Sygate Technologies, Inc."</td>
<td>C:\WINDOWS\system32\drivers\wpsdrvnt.sys</td>
<td>File exists</td>
</tr>
<tr>
<td class="group" colspan="6">Explorer</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath"</td>
<td>"Microsoft Corporation"</td>
<td>c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install</td>
<td>File exists</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\Software\Classes\Folder\shellex\ColumnHandlers</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension"</td>
<td>"Adobe Systems, Inc."</td>
<td>C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{30351349-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}"</td>
<td></td>
<td>C:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\Software\Classes\Protocols\Filter</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1"</td>
<td>"Microsoft Corporation"</td>
<td>C:\WINDOWS\system32\mscoree.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1"</td>
<td>"Microsoft Corporation"</td>
<td>C:\WINDOWS\system32\mscoree.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1"</td>
<td>"Microsoft Corporation"</td>
<td>C:\WINDOWS\system32\mscoree.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\Software\Classes\Protocols\Handler</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class"</td>
<td>"Skype Technologies"</td>
<td>C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0"</td>
<td>"Microsoft Corporation"</td>
<td>C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension"</td>
<td>"Igor Pavlov"</td>
<td>C:\Programme\7-Zip\7-zip.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{472083B0-C522-11CF-8763-00608CC02F24} "avast"</td>
<td>"AVAST Software"</td>
<td>C:\Programme\Alwil Software\Avast5\ashShell.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{6af09ec9-b429-11d4-a1fb-0090960218cb} "Bluetooth-Umgebung"</td>
<td>"Broadcom Corporation."</td>
<td>C:\WINDOWS\system32\BTNEIG~1.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung"</td>
<td class="notfound"></td>
<td class="notfound">deskpan.dll</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">{FCF608CF-5716-47C3-A1A8-991D873AF72B} "Delphi Context Menu Shell Extension Example"</td>
<td class="nodetails"></td>
<td class="nodetails">C:\Programme\Exifer\exifershellext.dll</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{5CA3D70E-1895-11CF-8E15-001234567890} "DriveLetterAccess"</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\DLA\DLASHX_W.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">{56160A70-D083-4856-9998-F565ABC03F86} "FolderSizes Shell Extension"</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{1D2680C9-0E2A-469d-B787-065558BC7D43} "Fusion Cache"</td>
<td>"Microsoft Corporation"</td>
<td>c:\WINDOWS\system32\mscoree.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung"</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{fc181130-05a0-11d6-8140-000102e745a6} "Mein P910i"</td>
<td>"Teleca Software Solutions AB"</td>
<td>C:\Programme\Sony Ericsson\Mobile\auexpext.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class"</td>
<td>"Broadcom Corporation."</td>
<td>C:\WINDOWS\system32\btncopy.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler"</td>
<td></td>
<td>C:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler"</td>
<td></td>
<td>C:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler"</td>
<td></td>
<td>C:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer"</td>
<td></td>
<td>C:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung"</td>
<td>"Microsoft Corporation"</td>
<td>C:\PROGRA~1\MICROS~3\Office\OLKFSTUB.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class"</td>
<td>"RealNetworks, Inc."</td>
<td>c:\program files\real\realplayer\rpshell.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{E91B2703-013E-4A99-AD33-2B6FB00AA356} "RecordNow! ContextMenuExt"</td>
<td></td>
<td>C:\Programme\Sonic\RecordNow!\RecordNow!\shlext.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{DEE12703-6333-4D4E-8F34-738C4DCC2E04} "RecordNow! SendToExt"</td>
<td></td>
<td>C:\Programme\Sonic\RecordNow!\RecordNow!\shlext.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References"</td>
<td>"Microsoft Corporation"</td>
<td>c:\WINDOWS\system32\dfshim.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{62DF97A2-3635-4412-AE30-80B164BC88AD} "ShellContextMenuHandler Class"</td>
<td>"1&1 Internet AG"</td>
<td>C:\Programme\1&1\1&1 Upload-Manager\SHNDLERS.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{D6613619-EDAA-451e-AA0C-671737CF6022} "ShellContextMenuHandler Class"</td>
<td>"GMX GmbH"</td>
<td>C:\Programme\GMX\GMX Upload-Manager\SHNDLERS.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung"</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References"</td>
<td>"Microsoft Corporation"</td>
<td>c:\WINDOWS\system32\dfshim.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class"</td>
<td>"Advanced Micro Devices, Inc."</td>
<td>C:\Programme\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">{01D8AD1E-46C9-4882-925C-CC29D9A99858} "SKTimeStamp"</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">{738D66C6-0149-4D40-84E4-A7BB2D0CE949} "Sony Ericsson File Manager"</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{46605027-5B8C-4DCE-BFE0-051B7972D64C} "TortoiseHg"</td>
<td>"TortoiseHg Project"</td>
<td>C:\Programme\TortoiseHg\ThgShellx86.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{869C8877-2C3C-438D-844B-31B86BFE5E8A} "TortoiseHg"</td>
<td>"TortoiseHg Project"</td>
<td>C:\Programme\TortoiseHg\ThgShellx86.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{9E3D4EC9-0624-4393-8B48-204C217ED1FF} "TortoiseHg"</td>
<td>"TortoiseHg Project"</td>
<td>C:\Programme\TortoiseHg\ThgShellx86.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{AF42ADAB-8C2E-4285-B746-99B31094708E} "TortoiseHg"</td>
<td>"TortoiseHg Project"</td>
<td>C:\Programme\TortoiseHg\ThgShellx86.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{CDA1C89D-E9B5-4981-A857-82DD932EA2FD} "TortoiseHg"</td>
<td>"TortoiseHg Project"</td>
<td>C:\Programme\TortoiseHg\ThgShellx86.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{30351346-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{30351347-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{30351348-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{30351349-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{3035134A-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{3035134B-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{3035134C-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{3035134D-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{3035134E-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{3035134F-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{30351350-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\TortoiseSVN\bin\TortoiseStub.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{C5994560-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{C5994561-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{C5994562-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{C5994563-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{C5994564-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{C5994565-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{C5994566-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{C5994567-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{C5994568-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN"</td>
<td>"hxxp://tortoisesvn.net"</td>
<td>C:\Programme\Gemeinsame Dateien\TortoiseOverlays\TortoiseOverlays.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} "UnlockerShellExtension"</td>
<td class="nodetails"></td>
<td class="nodetails">C:\Programme\Unlocker\UnlockerCOM.dll</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR"</td>
<td class="nodetails"></td>
<td class="nodetails">C:\Programme\WinRAR\rarext.dll</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{E0D79304-84BE-11CE-9641-444553540000} "WinZip"</td>
<td>"WinZip Computing, Inc."</td>
<td>C:\PROGRA~1\WINZIP\WZSHLSTB.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{E0D79305-84BE-11CE-9641-444553540000} "WinZip"</td>
<td>"WinZip Computing, Inc."</td>
<td>C:\PROGRA~1\WINZIP\WZSHLSTB.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{E0D79306-84BE-11CE-9641-444553540000} "WinZip"</td>
<td>"WinZip Computing, Inc."</td>
<td>C:\PROGRA~1\WINZIP\WZSHLSTB.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{E0D79307-84BE-11CE-9641-444553540000} "WinZip"</td>
<td>"WinZip Computing, Inc."</td>
<td>C:\PROGRA~1\WINZIP\WZSHLSTB.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">Rename-It! extension "{A64BBF5F-1250-4083"</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td class="group" colspan="6">Internet Explorer</td>
</tr>
<tr>
<td class="reg" colspan="6">HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound"><binary data> "ITBarLayout"</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{106E49CF-797A-11D2-81A2-00E02C015623} "AlternaTIFF ActiveX"<br>hxxp://www.alternatiff.com/install-ie/alttiff.cab</td>
<td>"Medical Informatics Engineering, Inc."</td>
<td>C:\WINDOWS\Downloaded Program Files\alttiff.ocx</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{2DAD3559-2923-4935-AD49-B673D2539944} "IASRunner Class"<br>hxxp://www-307.ibm.com/pc/support/acpir.cab</td>
<td></td>
<td>C:\WINDOWS\Downloaded Program Files\acpir2.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_21"<br>hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab</td>
<td>"Sun Microsystems, Inc."</td>
<td>C:\Programme\Java\jre6\bin\npjpi160_21.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} "Java Plug-in 1.6.0_21"<br>hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab</td>
<td>"Sun Microsystems, Inc."</td>
<td>C:\Programme\Java\jre6\bin\npjpi160_21.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_21"<br>hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab</td>
<td>"Sun Microsystems, Inc."</td>
<td>C:\Programme\Java\jre6\bin\npjpi160_21.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">Microsoft XML Parser for Java "Microsoft XML Parser for Java"<br>file://C:\WINDOWS\Java\classes\xmldso.cab</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{17492023-C23A-453E-A040-C7C580BBF700} "Windows Genuine Advantage Validation Tool"<br>hxxp://go.microsoft.com/fwlink/?linkid=39204</td>
<td>"Microsoft Corporation"</td>
<td>C:\WINDOWS\system32\legitcheckcontrol.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{15A7CF10-CB3E-4265-8779-9FD22619E8ED} "XPanel Class"<br>hxxp://192.168.1.205/XPanel.cab</td>
<td>"Crestron Electronics, Inc."</td>
<td>C:\WINDOWS\Downloaded Program Files\cmxpanel.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} "{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}"<br>hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} "{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}"<br>hxxp://java.sun.com/products/plugin/1.4.2/jinstall-142-win.cab</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} "{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}"<br>hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} "{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}"<br>hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">{F74959B0-1779-472E-BE6E-3023E1DBEC73} "{F74959B0-1779-472E-BE6E-3023E1DBEC73}"<br>hxxp://192.168.1.205/XInit.cab</td>
<td class="notfound"></td>
<td class="notfound"></td>
<td class="notfound">File not found | COM-object registry key not found</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"@btrez.dll,-4015"</td>
<td></td>
<td>C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{86529161-034E-4F8A-88D2-3C625E612E04} "Run WinHTTrack"</td>
<td></td>
<td>C:\Programme\WinHTTrack\WinHTTrackIEBar.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper"</td>
<td>"Adobe Systems Incorporated"</td>
<td>C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{5CA3D70E-1895-11CF-8E15-001234567890} "DriveLetterAccess"</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\DLA\DLASHX_W.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper"</td>
<td>"Sun Microsystems, Inc."</td>
<td>C:\Programme\Java\jre6\bin\jp2ssv.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class"</td>
<td>"Sun Microsystems, Inc."</td>
<td>C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>{3049C3E9-B461-4BC5-8870-4C09146192CA} "RealPlayer Download and Record Plugin for Internet Explorer"</td>
<td>"RealPlayer"</td>
<td>C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="group" colspan="6">Logon</td>
</tr>
<tr>
<td class="reg" colspan="6">%AllUsersProfile%\Startmenü\Programme\Autostart</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"desktop.ini"</td>
<td></td>
<td>C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Digital Line Detect.lnk"</td>
<td>"BVRP Software"</td>
<td>C:\Program Files\Digital Line Detect\DLG.exe</td>
<td>Shortcut exists | File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"EPSON SMART PANEL.lnk"</td>
<td>"NewSoft"</td>
<td>C:\Programme\EPSON\SMART PANEL\SmaPanel.exe</td>
<td>Shortcut exists | File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"EPSON Status Monitor 3 Environment Check.lnk"</td>
<td>"SEIKO EPSON CORPORATION"</td>
<td>C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE</td>
<td>Shortcut exists | File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Fax-Controller.lnk"</td>
<td>"NewSoft Technology Corporation"</td>
<td>C:\Programme\EPSON\SMART PANEL\faxicore.exe</td>
<td>Shortcut exists | File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"FRITZ!DSL Startcenter.lnk"</td>
<td>"AVM Berlin"</td>
<td>C:\Programme\FRITZ!DSL\StCenter.exe</td>
<td>Shortcut exists | File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Telefonverbindungsmonitor.lnk"</td>
<td>"Teleca Software Solutions AB"</td>
<td>C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe</td>
<td>Shortcut exists | File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Erinnerungen in Microsoft Works-Kalender.lnk"</td>
<td>"Microsoft® Corporation"</td>
<td>C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkCalRem.exe</td>
<td>Shortcut exists | File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"BTTray.lnk"</td>
<td>"Broadcom Corporation."</td>
<td>C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe</td>
<td>Shortcut exists | File exists</td>
</tr>
<tr>
<td class="reg" colspan="6">%UserProfile%\Startmenü\Programme\Autostart</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"desktop.ini"</td>
<td></td>
<td>C:\Dokumente und Einstellungen\+++\Startmenü\Programme\Autostart\desktop.ini</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"FRITZ!DSL Protect.lnk"</td>
<td>"AVM Berlin"</td>
<td>C:\Programme\FRITZ!DSL\FwebProt.exe</td>
<td>Shortcut exists | File exists</td>
</tr>
<tr>
<td class="reg" colspan="6">HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"AVMUSBFernanschluss"</td>
<td>"AVM Berlin"</td>
<td>C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\P2PN3W8Y.MX4\860T49LP.4CK\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\AVMAutoStart.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ibmmessages"</td>
<td>"IBM"</td>
<td>C:\Programme\IBM\Messages By IBM\ibmmessages.exe</td>
<td>File exists</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\Software\Microsoft\Windows\CurrentVersion\Run</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ACTray"</td>
<td>"Lenovo "</td>
<td>C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ACWLIcon"</td>
<td>"Lenovo "</td>
<td>C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Adobe ARM"</td>
<td>"Adobe Systems Incorporated"</td>
<td>"C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Adobe Reader Speed Launcher"</td>
<td>"Adobe Systems Incorporated"</td>
<td>"C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe"</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"AppleSyncNotifier"</td>
<td>"Apple Inc."</td>
<td>C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ATIPTA"</td>
<td>"ATI Technologies, Inc."</td>
<td>"C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe"</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"avast5"</td>
<td>"AVAST Software"</td>
<td>"C:\Programme\Alwil Software\Avast5\avastUI.exe" /nogui</td>
<td>File exists</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"BLOG"</td>
<td class="nodetails"></td>
<td class="nodetails">rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"CoolSwitch"</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\system32\taskswitch.exe</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"DLA"</td>
<td>"Sonic Solutions"</td>
<td>C:\WINDOWS\System32\DLA\DLACTRLW.EXE</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"EZEJMNAP"</td>
<td>"Lenovo Group Ltd."</td>
<td>C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"FinePrint Dispatcher v4"</td>
<td>"FinePrint Software, LLC"</td>
<td>C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ibmmessages"</td>
<td>"IBM"</td>
<td>C:\Programme\IBM\Messages By IBM\ibmmessages.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"IBMPRC"</td>
<td>"IBM Corp."</td>
<td>C:\IBMTOOLS\UTILS\ibmprc.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ISUSPM Startup"</td>
<td>"InstallShield Software Corporation"</td>
<td>C:\PROGRA~1\GEMEIN~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ISUSScheduler"</td>
<td>"InstallShield Software Corporation"</td>
<td>"C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe" -start</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"LogitechCommunicationsManager"</td>
<td>"Logitech Inc."</td>
<td>"C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe"</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"LogitechQuickCamRibbon"</td>
<td>"Logitech Inc."</td>
<td>"C:\Programme\Logitech\QuickCam10\QuickCam10.exe" /hide</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Message Center Plus"</td>
<td></td>
<td>C:\Programme\LENOVO\Message Center Plus\MCPLaunch.exe /start</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Microsoft Works Portfolio"</td>
<td>"Microsoft® Corporation"</td>
<td>C:\Programme\Microsoft Works\WksSb.exe /AllUsers</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Microsoft Works Update Detection"</td>
<td>"Microsoft® Corporation"</td>
<td>C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"PWRMGRTR"</td>
<td>"Lenovo Group Limited"</td>
<td>rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"QuickTime Task"</td>
<td>"Apple Inc."</td>
<td>"C:\Programme\QuickTime\QTTask.exe" -atboottime</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"RemoteControl"</td>
<td>"Cyberlink Corp."</td>
<td>"C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe"</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"SmcService"</td>
<td>"Sygate Technologies, Inc."</td>
<td>C:\PROGRA~1\Sygate\SPF\smc.exe -startgui</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"SoundMAXPnP"</td>
<td>"Analog Devices, Inc."</td>
<td>C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"StartCCC"</td>
<td>"Advanced Micro Devices, Inc."</td>
<td>"C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"SunJavaUpdateSched"</td>
<td>"Sun Microsystems, Inc."</td>
<td>"C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe"</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TkBellExe"</td>
<td>"RealNetworks, Inc."</td>
<td>"C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe"  -osboot</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TortoiseHgOverlayIconServer"</td>
<td></td>
<td>C:\Programme\TortoiseHg\TortoiseHgOverlayServer.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TP4EX"</td>
<td>"Lenovo Group Limited"</td>
<td>tp4ex.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TPHOTKEY"</td>
<td>"Lenovo Group Limited"</td>
<td>C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe</td>
<td>File exists</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"TPKBDLED"</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\system32\TpScrLk.exe</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TPKMAPHELPER"</td>
<td>"IBM Corp."</td>
<td>C:\Programme\ThinkPad\Utilities\TpKmapAp.exe -helper</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TPP Auto Loader"</td>
<td>"In-System Design, Inc."</td>
<td>C:\WINDOWS\TPPALDR.EXE</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TpShocks"</td>
<td>"Lenovo."</td>
<td>TpShocks.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"tsnp2std"</td>
<td>"SONIX"</td>
<td>C:\WINDOWS\tsnp2std.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TVT Scheduler Proxy"</td>
<td>"Lenovo Group Limited"</td>
<td>C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe</td>
<td>File exists</td>
</tr>
<tr>
<td class="group" colspan="6">Network Providers</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"1&1 SmartDrive"</td>
<td>"1&1 Internet AG"</td>
<td>C:\WINDOWS\System32\ui11np.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"GMX MediaCenter"</td>
<td>"GMX GmbH"</td>
<td>C:\WINDOWS\System32\uigxnp.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="group" colspan="6">Print Monitors</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"avm:"</td>
<td>"AVM Berlin GmbH"</td>
<td>C:\WINDOWS\system32\avmprmon.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Bluetooth-Druckeranschluss"</td>
<td>"Broadcom Corporation."</td>
<td>C:\WINDOWS\system32\bthcrp.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"doPDF 7 Monitor"</td>
<td>"Softland"</td>
<td>C:\WINDOWS\system32\dopdfmn7.dll</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"EPSON STM3 2KMonitor9"</td>
<td>"SEIKO EPSON CORPORATION"</td>
<td>C:\WINDOWS\system32\E_SL2009.DLL</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"FPR4:"</td>
<td>"FinePrint Software, LLC"</td>
<td>C:\WINDOWS\system32\fpmon4.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"PDF995 Monitor"</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\system32\pdfmon.dll</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td class="group" colspan="6">Services</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\SYSTEM\CurrentControlSet\Services</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32)</td>
<td>"Microsoft Corporation"</td>
<td>C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Ac Profile Manager Service" (AcPrfMgrSvc)</td>
<td>"Lenovo "</td>
<td>C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Access Connections Main Service" (AcSvc)</td>
<td>"Lenovo "</td>
<td>C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ASP.NET-Zustandsdienst" (aspnet_state)</td>
<td>"Microsoft Corporation"</td>
<td>C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"avast! Antivirus" (avast! Antivirus)</td>
<td>"AVAST Software"</td>
<td>C:\Programme\Alwil Software\Avast5\AvastSvc.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"avast! Mail Scanner" (avast! Mail Scanner)</td>
<td>"AVAST Software"</td>
<td>C:\Programme\Alwil Software\Avast5\AvastSvc.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"avast! Web Scanner" (avast! Web Scanner)</td>
<td>"AVAST Software"</td>
<td>C:\Programme\Alwil Software\Avast5\AvastSvc.exe</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"AVM FRITZ!web Routing Service" (de_serv)</td>
<td class="notfound"></td>
<td class="notfound">C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"AVM IGD CTRL Service" (IGDCTRL)</td>
<td>"AVM Berlin"</td>
<td>C:\Programme\FRITZ!DSL\IGDCTRL.EXE</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Bluetooth Service" (btwdins)</td>
<td>"Broadcom Corporation."</td>
<td>C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe</td>
<td>File exists</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"Google Update Service (gupdate)" (gupdate)</td>
<td class="notfound"></td>
<td class="notfound">"C:\Programme\Google\Update\GoogleUpdate.exe" /svc</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"HID Input Service" (HidServ)</td>
<td class="notfound"></td>
<td class="notfound"> C:\WINDOWS\System32\hidserv.dll</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"IBM KCU Service" (TpKmpSVC)</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\system32\TpKmpSVC.exe</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"InstallDriver Table Manager" (IDriverT)</td>
<td>"Macrovision Corporation"</td>
<td>C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Intel(R) PROSet/Wireless Event Log" (EvtEng)</td>
<td>"Intel(R) Corporation"</td>
<td>C:\Programme\Intel\WiFi\bin\EvtEng.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Intel(R) PROSet/Wireless Registry Service" (RegSrvc)</td>
<td>"Intel(R) Corporation"</td>
<td>C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Intel(R) PROSet/Wireless WiFi Service" (S24EventMonitor)</td>
<td>"Intel(R) Corporation"</td>
<td>C:\Programme\Intel\WiFi\bin\S24EvMon.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Java Quick Starter" (JavaQuickStarterService)</td>
<td>"Sun Microsystems, Inc."</td>
<td>C:\Programme\Java\jre6\bin\jqs.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Lavasoft Ad-Aware Service" (aawservice)</td>
<td>"Lavasoft"</td>
<td>C:\Programme\Lavasoft\Ad-Aware\aawservice.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Lenovo Doze Mode Service" (DozeSvc)</td>
<td>"Lenovo."</td>
<td>C:\Programme\ThinkPad\Utilities\DOZESVC.EXE</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Logitech Process Monitor" (LVPrcSrv)</td>
<td>"Logitech Inc."</td>
<td>c:\programme\gemeinsame dateien\logishrd\lvmvfm\LVPrcSrv.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"LVSrvLauncher" (LVSrvLauncher)</td>
<td>"Logitech Inc."</td>
<td>C:\Programme\Gemeinsame Dateien\LogiShrd\SrvLnch\SrvLnch.exe</td>
<td>File exists</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"NMSAccessU" (NMSAccessU)</td>
<td class="nodetails"></td>
<td class="nodetails">C:\WINDOWS\system32\NMSAccessU.exe</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Power Manager DBC Service" (Power Manager DBC Service)</td>
<td></td>
<td>C:\Programme\ThinkPad\Utilities\PWMDBSVC.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"SoundMAX Agent Service" (SoundMAX Agent Service (default))</td>
<td>"Analog Devices, Inc."</td>
<td>C:\Programme\Analog Devices\SoundMAX\SMAgent.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Sygate Personal Firewall" (SmcService)</td>
<td>"Sygate Technologies, Inc."</td>
<td>C:\Programme\Sygate\SPF\smc.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"System Update" (SUService)</td>
<td>"Lenovo Group Limited"</td>
<td>c:\programme\lenovo\system update\suservice.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ThinkPad HDD APS Logging Service" (TPHDEXLGSVC)</td>
<td>"Lenovo."</td>
<td>C:\WINDOWS\System32\TPHDEXLG.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"ThinkVantage Registry Monitor Service" (ThinkVantage Registry Monitor Service)</td>
<td>"Lenovo Group Limited"</td>
<td>C:\Programme\Gemeinsame Dateien\Lenovo\tvt_reg_monitor_svc.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"TVT Scheduler" (TVT Scheduler)</td>
<td>"Lenovo Group Limited"</td>
<td>C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\tvtsched.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Ulead Burning Helper" (UleadBurningHelper)</td>
<td>"Ulead Systems, Inc."</td>
<td>C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Windows CardSpace" (idsvc)</td>
<td>"Microsoft Corporation"</td>
<td>C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0)</td>
<td>"Microsoft Corporation"</td>
<td>c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe</td>
<td>File exists</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"X10 Device Network Service" (x10nets)</td>
<td>"X10"</td>
<td>C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe</td>
<td>File exists</td>
</tr>
<tr>
<td class="group" colspan="6">Winlogon</td>
</tr>
<tr>
<td class="reg" colspan="6">HKCU\Control Panel\IOProcs</td>
</tr>
<tr>
<td class="notfound"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="notfound">"MVB"</td>
<td class="notfound"></td>
<td class="notfound">mvfs32.dll</td>
<td class="notfound">File not found</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"tpfnf2"</td>
<td class="nodetails"></td>
<td class="nodetails">C:\Programme\Lenovo\HOTKEY\notifyf2.dll</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td class="nodetails"><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td class="nodetails">"tphotkey"</td>
<td class="nodetails"></td>
<td class="nodetails">C:\Programme\Lenovo\HOTKEY\tphklock.dll</td>
<td class="nodetails">File found, but it contains no detailed information</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"WgaLogon"</td>
<td>"Microsoft Corporation"</td>
<td>C:\WINDOWS\system32\WgaLogon.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="group" colspan="6">Winsock Providers</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"Sarah NSP"</td>
<td>"AVM Berlin"</td>
<td>C:\Programme\FRITZ!DSL\sarah.dll</td>
<td>File exists</td>
</tr>
<tr>
<td class="reg" colspan="6">HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</td>
</tr>
<tr>
<td><input type="checkbox" disabled checked></td>
<td class="rs rn">&nbsp;</td>
<td>"SARAH LSP"</td>
<td>"AVM Berlin"</td>
<td>C:\Programme\FRITZ!DSL\sarah.dll</td>
<td>File exists</td>
</tr>
</table>
<p>If You have questions or want to get some help, You can visit <a href="hxxp://forum.online-solutions.ru" target="_blank">hxxp://forum.online-solutions.ru</a></p>
</body></html>

Code:

für MBRCheck.....txt ist leider der Zugriff von hier nicht erlaubt, obwohl in den All Users Ordner verschoben.
Also wieder zurück zum Administrator, um zu sehen, was da los ist.


Herzmann 11.10.2010 12:07

Code:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:           
Windows Version:        Windows XP Professional
Windows Information:        Service Pack 3 (build 2600)
Logical Drives Mask:        0x000007fc

Kernel Drivers (total 200):
  0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
  0x806D1000 \WINDOWS\system32\hal.dll
  0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
  0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
  0xB9F78000 ACPI.sys
  0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
  0xB9F67000 pci.sys
  0xBA0A8000 isapnp.sys
  0xBA4BC000 compbatt.sys
  0xBA4C0000 \WINDOWS\system32\DRIVERS\BATTC.SYS
  0xBA670000 pciide.sys
  0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
  0xB9F49000 pcmcia.sys
  0xBA0B8000 MountMgr.sys
  0xB9F2A000 ftdisk.sys
  0xBA5AC000 dmload.sys
  0xB9F04000 dmio.sys
  0xBA330000 PartMgr.sys
  0xBA4C4000 ACPIEC.sys
  0xBA671000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
  0xBA4C8000 TPDiskPM.sys
  0xBA0C8000 VolSnap.sys
  0xB9EEC000 atapi.sys
  0xBA0D8000 disk.sys
  0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
  0xB9ECC000 fltmgr.sys
  0xB9EBA000 sr.sys
  0xB9EA4000 DRVMCDB.SYS
  0xBA338000 PxHelp20.sys
  0xB9E8D000 KSecDD.sys
  0xBA340000 DozeHDD.sys
  0xB9E00000 Ntfs.sys
  0xB9DD3000 NDIS.sys
  0xBA0F8000 ApsHM86.sys
  0xB9DB6000 Teefer.sys
  0xBA5AE000 speedfan.sys
  0xB9D96000 Apsx86.sys
  0xBA108000 sbp2port.sys
  0xBA118000 ohci1394.sys
  0xBA128000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
  0xB9D7C000 Mup.sys
  0xBA672000 giveio.sys
  0xBA178000 \SystemRoot\system32\DRIVERS\nic1394.sys
  0xBA188000 \SystemRoot\system32\DRIVERS\intelppm.sys
  0xB9945000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
  0xB9909000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
  0xB98DE000 \SystemRoot\system32\DRIVERS\b57xp32.sys
  0xBA370000 \SystemRoot\system32\DRIVERS\usbuhci.sys
  0xB98BA000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
  0xBA378000 \SystemRoot\system32\DRIVERS\usbehci.sys
  0xB969C000 \SystemRoot\system32\DRIVERS\w29n51.sys
  0xB965C000 \SystemRoot\system32\drivers\smwdm.sys
  0xB9638000 \SystemRoot\system32\drivers\portcls.sys
  0xBA1A8000 \SystemRoot\system32\drivers\drmk.sys
  0xB9615000 \SystemRoot\system32\drivers\ks.sys
  0xB95F5000 \SystemRoot\system32\drivers\aeaudio.sys
  0xB95B9000 \SystemRoot\system32\DRIVERS\HSFHWICH.sys
  0xB94C5000 \SystemRoot\system32\DRIVERS\HSF_DPV.sys
  0xB9414000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
  0xBA3A0000 \SystemRoot\System32\Drivers\Modem.SYS
  0xBA1C8000 \SystemRoot\system32\DRIVERS\i8042prt.sys
  0xBA3B8000 \SystemRoot\system32\DRIVERS\kbdclass.sys
  0xBA5B6000 \SystemRoot\System32\DRIVERS\TPInput.sys
  0xB93DD000 \SystemRoot\system32\DRIVERS\SynTP.sys
  0xBA5BA000 \SystemRoot\system32\DRIVERS\USBD.SYS
  0xBA1D8000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS
  0xB936C000 \SystemRoot\system32\DRIVERS\Wdf01000.sys
  0xBA3C8000 \SystemRoot\system32\DRIVERS\mouclass.sys
  0xBA3D8000 \SystemRoot\system32\DRIVERS\fdc.sys
  0xBA1E8000 \SystemRoot\system32\DRIVERS\serial.sys
  0xBA5A0000 \SystemRoot\system32\DRIVERS\serenum.sys
  0xB9358000 \SystemRoot\system32\DRIVERS\parport.sys
  0xBA3E0000 \SystemRoot\system32\DRIVERS\nscirda.sys
  0xBA5A4000 \SystemRoot\system32\DRIVERS\irenum.sys
  0xBA3F0000 \SystemRoot\system32\DRIVERS\tpm.sys
  0xB9D3F000 \SystemRoot\system32\DRIVERS\CmBatt.sys
  0xBA400000 \SystemRoot\system32\DRIVERS\ibmpmdrv.sys
  0xBA1F8000 \SystemRoot\system32\DRIVERS\imapi.sys
  0xBA208000 \SystemRoot\system32\DRIVERS\cdrom.sys
  0xBA218000 \SystemRoot\system32\DRIVERS\redbook.sys
  0xB933F000 \SystemRoot\system32\DRIVERS\avmaura.sys
  0xBA418000 \SystemRoot\system32\DRIVERS\TDI.SYS
  0xB9246000 \SystemRoot\system32\DRIVERS\btkrnl.sys
  0xBA7B9000 \SystemRoot\system32\DRIVERS\audstub.sys
  0xBA430000 \SystemRoot\system32\DRIVERS\rasirda.sys
  0xBA278000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
  0xB9D0F000 \SystemRoot\system32\DRIVERS\ndistapi.sys
  0xB918F000 \SystemRoot\system32\DRIVERS\ndiswan.sys
  0xBA288000 \SystemRoot\system32\DRIVERS\raspppoe.sys
  0xBA2A8000 \SystemRoot\system32\DRIVERS\raspptp.sys
  0xB917E000 \SystemRoot\system32\DRIVERS\psched.sys
  0xBA2B8000 \SystemRoot\system32\DRIVERS\msgpc.sys
  0xBA450000 \SystemRoot\system32\DRIVERS\ptilink.sys
  0xBA460000 \SystemRoot\system32\DRIVERS\raspti.sys
  0xB914E000 \SystemRoot\system32\DRIVERS\rdpdr.sys
  0xBA2C8000 \SystemRoot\system32\DRIVERS\termdd.sys
  0xBA478000 \SystemRoot\system32\DRIVERS\psadd.sys
  0xBA5C2000 \SystemRoot\system32\DRIVERS\swenum.sys
  0xB90F0000 \SystemRoot\system32\DRIVERS\update.sys
  0xB993D000 \SystemRoot\system32\DRIVERS\mssmbios.sys
  0xBA488000 \SystemRoot\system32\DRIVERS\btport.sys
  0xBA2F8000 \SystemRoot\System32\Drivers\NDProxy.SYS
  0xBA168000 \SystemRoot\system32\DRIVERS\usbhub.sys
  0xB9327000 \SystemRoot\System32\Drivers\i2omgmt.SYS
  0xBA5CC000 \SystemRoot\System32\Drivers\DLACDBHM.SYS
  0xBA5D0000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
  0xBA679000 \SystemRoot\System32\Drivers\Null.SYS
  0xBA5D4000 \SystemRoot\System32\Drivers\Beep.SYS
  0xBA358000 \SystemRoot\System32\Drivers\DLARTL_N.SYS
  0xBA368000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
  0xBA380000 \SystemRoot\System32\drivers\vga.sys
  0xBA5D8000 \SystemRoot\System32\Drivers\mnmdd.SYS
  0xBA5DC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
  0xBA390000 \SystemRoot\System32\Drivers\Msfs.SYS
  0xBA3A8000 \SystemRoot\System32\Drivers\Npfs.SYS
  0xB9317000 \SystemRoot\system32\DRIVERS\rasacd.sys
  0xB4FAB000 \SystemRoot\system32\DRIVERS\ipsec.sys
  0xB4F52000 \SystemRoot\system32\DRIVERS\tcpip.sys
  0xB91F6000 \SystemRoot\System32\Drivers\aswTdi.SYS
  0xB4F2C000 \SystemRoot\system32\DRIVERS\ipnat.sys
  0xB91E6000 \SystemRoot\system32\DRIVERS\wanarp.sys
  0xB91D6000 \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys
  0xB91C6000 \SystemRoot\system32\DRIVERS\arp1394.sys
  0xB4EDC000 \SystemRoot\system32\DRIVERS\netbt.sys
  0xB90DC000 \SystemRoot\System32\drivers\ws2ifsl.sys
  0xB4EBA000 \SystemRoot\System32\drivers\afd.sys
  0xB90D4000 \SystemRoot\system32\DRIVERS\hidusb.sys
  0xB91B6000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
  0xB91A6000 \SystemRoot\system32\DRIVERS\netbios.sys
  0xB4E95000 \SystemRoot\System32\DRIVERS\uigxrdr.sys
  0xB4E70000 \SystemRoot\System32\DRIVERS\ui11rdr.sys
  0xBA408000 \SystemRoot\System32\drivers\TSMAPIP.SYS
  0xBA410000 \SystemRoot\System32\drivers\Tppwrif.sys
  0xBA428000 \SystemRoot\system32\DRIVERS\TPHKDRV.sys
  0xBA438000 \SystemRoot\System32\drivers\TDSMAPI.SYS
  0xBA440000 \SystemRoot\System32\drivers\Smapint.sys
  0xB4DD5000 \SystemRoot\system32\DRIVERS\rdbss.sys
  0xBA6B5000 \SystemRoot\System32\Drivers\PQNTDrv.SYS
  0xB4D3D000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
  0xBA5E6000 \??\C:\WINDOWS\system32\Drivers\IBMBLDID.sys
  0xBA258000 \SystemRoot\System32\Drivers\Fips.SYS
  0xB4D16000 \SystemRoot\System32\Drivers\aswSP.SYS
  0xBA590000 \SystemRoot\System32\drivers\ANC.SYS
  0xBA468000 \SystemRoot\System32\Drivers\Aavmker4.SYS
  0xB932B000 \SystemRoot\system32\DRIVERS\mouhid.sys
  0xB4CCA000 \SystemRoot\System32\Drivers\Fastfat.SYS
  0xB4F1C000 \SystemRoot\system32\DRIVERS\GWUSB2E.sys
  0xBA480000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
  0xBA4A8000 \SystemRoot\system32\DRIVERS\usbprint.sys
  0xBA360000 \SystemRoot\system32\DRIVERS\usbccgp.sys
  0xB504E000 \SystemRoot\system32\DRIVERS\ser2pl.sys
  0xB4F14000 \SystemRoot\System32\Drivers\usbbc.sys
  0xB4F08000 \SystemRoot\system32\DRIVERS\kbdhid.sys
  0xB4CB2000 \SystemRoot\System32\Drivers\dump_atapi.sys
  0xBA5F4000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
  0xBF800000 \SystemRoot\System32\win32k.sys
  0xB90B8000 \SystemRoot\System32\drivers\Dxapi.sys
  0xBA3C0000 \SystemRoot\System32\watchdog.sys
  0xBF000000 \SystemRoot\System32\drivers\dxg.sys
  0xBA6D2000 \SystemRoot\System32\drivers\dxgthk.sys
  0xBF012000 \SystemRoot\System32\ati2dvag.dll
  0xBF065000 \SystemRoot\System32\ati2cqag.dll
  0xBF0FE000 \SystemRoot\System32\atikvmag.dll
  0xBF182000 \SystemRoot\System32\atiok3x2.dll
  0xBF1CD000 \SystemRoot\System32\ati3duag.dll
  0xBF572000 \SystemRoot\System32\ativvaxx.dll
  0xBA588000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
  0xB2913000 \??\C:\WINDOWS\system32\drivers\ACEDRV05.sys
  0xB500E000 \SystemRoot\System32\Drivers\DRVNDDM.SYS
  0xBA753000 \SystemRoot\System32\DLA\DLADResN.SYS
  0xB28FD000 \SystemRoot\System32\DLA\DLAIFS_M.SYS
  0xB29E2000 \SystemRoot\System32\DLA\DLAOPIOM.SYS
  0xBA64C000 \SystemRoot\System32\DLA\DLAPoolM.SYS
  0xB4E20000 \SystemRoot\System32\DLA\DLABOIOM.SYS
  0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
  0xB281D000 \SystemRoot\System32\DLA\DLAUDFAM.SYS
  0xB2807000 \SystemRoot\System32\DLA\DLAUDF_M.SYS
  0xB2639000 \SystemRoot\system32\DRIVERS\irda.sys
  0xB273B000 \SystemRoot\system32\DRIVERS\ndisuio.sys
  0xB272F000 \SystemRoot\system32\DRIVERS\s24trans.sys
  0xB2629000 \SystemRoot\SYSTEM32\Drivers\wg3n.sys
  0xB2621000 \SystemRoot\SYSTEM32\Drivers\wg4n.sys
  0xB2611000 \SystemRoot\SYSTEM32\Drivers\wg5n.sys
  0xB2733000 \SystemRoot\SYSTEM32\Drivers\wg6n.sys
  0xB23F2000 \SystemRoot\System32\Drivers\aswMon2.SYS
  0xB22D2000 \SystemRoot\System32\Drivers\Cdfs.SYS
  0xB1965000 \SystemRoot\system32\drivers\wdmaud.sys
  0xB1938000 \SystemRoot\system32\DRIVERS\mrxdav.sys
  0xB2092000 \SystemRoot\system32\drivers\sysaudio.sys
  0xB1C1A000 \SystemRoot\System32\Drivers\Aspi32.SYS
  0xB1289000 \SystemRoot\System32\Drivers\HTTP.sys
  0xB11E2000 \SystemRoot\system32\DRIVERS\srv.sys
  0xB12EE000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
  0xBA5F0000 \??\C:\WINDOWS\SYSTEM32\Drivers\PMEMNT.SYS
  0xB1B8A000 \SystemRoot\system32\DRIVERS\secdrv.sys
  0xBA388000 \SystemRoot\system32\DRIVERS\LVPr2Mon.sys
  0xBA398000 \SystemRoot\System32\Drivers\aswRdr.SYS
  0xBF9C5000 \SystemRoot\System32\spool\DRIVERS\W32X86\2\fpgraph4.dll
  0xBFF50000 \SystemRoot\System32\TSDDD.dll
  0x7C910000 \WINDOWS\system32\ntdll.dll

Processes (total 151):
      0 System Idle Process
      4 System
    980 C:\WINDOWS\system32\smss.exe
    1216 csrss.exe
    1264 C:\WINDOWS\system32\winlogon.exe
    1340 C:\WINDOWS\system32\services.exe
    1352 C:\WINDOWS\system32\lsass.exe
    1524 C:\WINDOWS\system32\ibmpmsvc.exe
    1568 C:\WINDOWS\system32\ati2evxx.exe
    1588 C:\WINDOWS\system32\svchost.exe
    1680 svchost.exe
    1840 C:\WINDOWS\system32\svchost.exe
    1896 C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe
    340 C:\Programme\Intel\WiFi\bin\S24EvMon.exe
    396 svchost.exe
    708 svchost.exe
    1096 C:\Programme\Lavasoft\Ad-Aware\aawservice.exe
    1276 C:\Programme\Alwil Software\Avast5\AvastSvc.exe
    2056 C:\WINDOWS\system32\spoolsv.exe
    2128 C:\Programme\Gemeinsame Dateien\logishrd\LVMVFM\LVPrcSrv.exe
    2376 svchost.exe
    2100 C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    3808 svchost.exe
    4068 C:\Programme\ThinkPad\Utilities\DOZESVC.EXE
    760 C:\Programme\Intel\WiFi\bin\EvtEng.exe
    3396 PresentationFontCache.exe
    2164 C:\WINDOWS\system32\svchost.exe
    3184 C:\Programme\FRITZ!DSL\IGDCTRL.EXE
    3092 C:\Programme\Java\jre6\bin\jqs.exe
    3948 C:\WINDOWS\system32\NMSAccessU.exe
    3848 C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe
    1404 C:\Programme\Analog Devices\SoundMAX\SMAgent.exe
    4100 C:\WINDOWS\system32\svchost.exe
    4168 C:\Programme\Gemeinsame Dateien\Lenovo\tvt_reg_monitor_svc.exe
    4256 C:\WINDOWS\system32\TpKmpSvc.exe
    4384 C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\tvtsched.exe
    4712 C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe
    4864 C:\WINDOWS\system32\fxssvc.exe
    5012 C:\Programme\ThinkPad\Utilities\PWMDBSVC.exe
    5128 C:\Programme\Lenovo\System Update\SUService.exe
    5340 C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe
    2248 C:\PROGRA~1\COMMON~1\X10\Common\X10nets.exe
    2624 wmiprvse.exe
    3212 C:\WINDOWS\system32\wbem\wmiapsrv.exe
    4972 alg.exe
    5884 C:\Programme\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
    6732 realupgrade.exe
    8168 C:\WINDOWS\system32\ati2evxx.exe
    2440 explorer.exe
    6412 TSVNCache.exe
    8068 tsnp2std.exe
    6348 TpShocks.exe
    3640 tppaldr.exe
    6976 TpScrLk.exe
    6444 TPOSDSVC.exe
    2768 SynTPEnh.exe
    2764 SMax4PNP.exe
    7888 vsnp2std.exe
    2920 PDVDServ.exe
    3572 rundll32.exe
    7816 issch.exe
    6620 ibmprc.exe
    3700 ibmmessages.exe
    7340 fpdisp4.exe
    1200 EZEJMNAP.EXE
    3440 DLACTRLW.EXE
    1020 TaskSwitch.exe
    1192 TPONSCR.exe
    7112 TpScrex.exe
    3160 rundll32.exe
    4908 scheduler_proxy.exe
    3868 Communications_Helper.exe
    3020 QuickCam10.exe
    4768 MCPLaunch.exe
    6056 ACTray.exe
    1432 ACWLIcon.exe
    3792 MOM.exe
    2548 TortoiseHgOverlayServer.exe
    528 jusched.exe
    3244 realsched.exe
    7608 AvastUI.exe
    7204 ctfmon.exe
    2544 Skype.exe
    3744 SynTPLpr.exe
    5384 wmpnscfg.exe
    3384 BTTray.exe
    5168 DLG.exe
    4136 SmaPanel.exe
    7296 WkCalRem.exe
    5632 audevicemgr.exe
    1888 FwebProt.exe
    6316 StCenter.exe
    7924 HOTSYNC.EXE
    8136 fritzbox-usb-fernanschluss.exe
    4144 LVComSX.exe
    3324 CCC.exe
    948 MROUTE~2.EXE
    2616 CONNMN~1.EXE
    2824 COCIManager.exe
    3176 skypePM.exe
    1768 firefox.exe
    9492 plugin-container.exe
    7972 csrss.exe
    4292 C:\WINDOWS\system32\winlogon.exe
    8328 C:\WINDOWS\system32\ati2evxx.exe
    9412 C:\WINDOWS\explorer.exe
    9104 C:\Programme\TortoiseSVN\bin\TSVNCache.exe
    7500 C:\WINDOWS\tsnp2std.exe
    9128 C:\WINDOWS\system32\TpShocks.exe
    8848 C:\WINDOWS\tppaldr.exe
    276 C:\WINDOWS\system32\TpScrLk.exe
    3456 C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe
    8416 C:\Programme\Synaptics\SynTP\SynTPEnh.exe
    5784 C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe
    9160 C:\WINDOWS\vsnp2std.exe
    8108 C:\Programme\Home Cinema\PowerDVD\PDVDServ.exe
    288 C:\Programme\Lenovo\HOTKEY\TPONSCR.exe
    8288 C:\Programme\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
    4140 C:\WINDOWS\system32\rundll32.exe
    9988 C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
    5716 C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe
    7684 C:\IBMTOOLS\utils\ibmprc.exe
    8628 C:\Programme\IBM\Messages By IBM\ibmmessages.exe
    1416 C:\WINDOWS\system32\spool\drivers\w32x86\2\fpdisp4.exe
    8952 C:\PROGRA~1\ThinkPad\UTILIT~1\EZEJMNAP.EXE
  10112 C:\WINDOWS\system32\dla\DLACTRLW.EXE
    9328 C:\WINDOWS\system32\TaskSwitch.exe
    9408 C:\WINDOWS\system32\rundll32.exe
    7024 C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe
    1676 C:\Programme\Gemeinsame Dateien\logishrd\LComMgr\Communications_Helper.exe
  10076 C:\Programme\Logitech\QuickCam10\QuickCam10.exe
    3804 C:\Programme\Lenovo\Message Center Plus\MCPLaunch.exe
    8276 C:\Programme\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    4548 C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.exe
    8584 C:\Programme\TortoiseHg\TortoiseHgOverlayServer.exe
    1456 C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
    7732 C:\Programme\Alwil Software\Avast5\AvastUI.exe
    8236 C:\Programme\Synaptics\SynTP\SynTPLpr.exe
    8528 C:\Dokumente und Einstellungen\+++\Lokale Einstellungen\Apps\2.0\P2PN3W8Y.MX4\860T49LP.4CK\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe
    9708 C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe
    9996 C:\Program Files\Digital Line Detect\DLG.exe
    6600 C:\Programme\EPSON\SMART PANEL\SmaPanel.exe
    8036 C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkCalRem.exe
    8640 C:\Programme\Sony Ericsson\Mobile\audevicemgr.exe
    3468 C:\Programme\FRITZ!DSL\FwebProt.exe
    8020 C:\Programme\Gemeinsame Dateien\logishrd\LComMgr\LVComSX.exe
    9740 C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    8736 C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE
    8924 C:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\MROUTE~2.EXE
    9180 C:\Programme\Gemeinsame Dateien\logishrd\LQCVFX\COCIManager.exe
    6504 C:\Dokumente und Einstellungen\All Users\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00  (NTFS)
\\.\E: --> \\.\PhysicalDrive0 at offset 0x00000018`b5e3cc00  (FAT32)
\\.\F: --> \\.\PhysicalDrive0 at offset 0x00000016`32aa0a00  (FAT32)
\\.\G: --> \\.\PhysicalDrive0 at offset 0x00000017`338fa400  (FAT32)
\\.\H: --> \\.\PhysicalDrive0 at offset 0x0000000f`e146c800  (NTFS)
\\.\I: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00  (NTFS)
\\.\J: --> \\.\PhysicalDrive1 at offset 0x00000024`366bb800  (NTFS)
\\.\K: --> \\.\PhysicalDrive1 at offset 0x0000002e`ff1a3600  (NTFS)

PhysicalDrive0 Model Number: SAMSUNGHM160HC, Rev: LQ100-10
PhysicalDrive1 Model Number: WDC WD2500BB-55GUA0, Rev:

      Size  Device Name          MBR Status
  --------------------------------------------
    149 GB  \\.\PhysicalDrive0  Unknown MBR code
            SHA1: 38CA05E08340C4AE507EF76A4F8EA9A9594E071E
    232 GB  \\.\PhysicalDrive1  Windows XP MBR code detected
            SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
  [1] Dump the MBR of a physical disk to file.
  [2] Restore the MBR of a physical disk with a standard boot code.
  [3] Exit.

Enter your choice: Enter the physical disk number to dump (0-99, -1 to exit): 0Dumping \\.\PhysicalDisk0...
Enter filename to dump to: NonStandard0_from_IBM_R52.mbrDumped successfully!

Enter the physical disk number to dump (0-99, -1 to exit): -1

Done!


cosinus 11.10.2010 13:01

Starte den Rechner neu und wähle im Bootmenü die Wiederherstellungskonsole aus.

Tipp dort den Befehl fixmbr ein (dann Enter, mit j bestätigen) danach den Befehl fixboot (dann Enter, mit j bestätigen)

Mit exit (dann enter drücken) wird der Rechner neu gestartet. Führe im normalen Windowsmodus mbrcheck nochmals aus und poste das neue Log.

Herzmann 11.10.2010 14:12

Sicherheitshalber muß ich da leider noch mal dazwischen fragen:
fixboot erscheint mir nicht so gefährlich, denn das sollte nur die Windows-Partition betreffen
Mit fixmbr befürchte ich, daß dann anschließend die Recovery-Partition meines IBM ThinkPad R52 nicht mehr geht, d.h. per AccessIBM bzw. F11-Taste während dem booten startbar ist. Der MBR besteht hier aus wenigstens 9 Sektoren, und der normale Microsoft MBR ist doch nur 1 Sector groß (?)

Bist Du sicher, daß fixmbr die obige Recovery-Funktionalität mit beinhaltet und aufrecht erhält?

cosinus 11.10.2010 15:24

Zitat:

Bist Du sicher, daß fixmbr die obige Recovery-Funktionalität mit beinhaltet und aufrecht erhält?
Selbst wenn nicht: Recovery-Medien sollte man extern haben! Wenn die Platte kaputt sein sollte hast Du bei einer neuen Platte keine Möglichkeit mehr sonst das System draufzukriegen!
Das erste was man macht ist Recover-Medien zu brennen, wenn man Wert auf die Recover-Geschichte legt!

Herzmann 11.10.2010 15:52

Was man sollte, weiß ich, habe ich aber leider nicht. Das separate Herstellen eines externen Recovery-Mediums habe ich gemäß Removing IBM Rescue & Recovery - ibmfilter.sys problems
Code:

hxxp://forums.lenovo.com/t5/T61-and-prior-T-series-ThinkPad/Removing-IBM-Rescue-amp-Recovery-ibmfilter-sys-problems/m-p/60680
leider zerschossen wegen: Roger K. Wells - Re: [Fwd: Blue screen when running installation *.sh]
Code:

hxxp://sourceware.org/ml/cygwin/2010-01/msg00161.html
Zitat:

Selbst wenn nicht:
Dann müßte ich nachher wieder genau diesen MBR wieder drauf spielen.

Es wäre für mich also von hohem Wert zu wissen, ob mein MBR tatsächlich malware-korrumpiert ist, oder lediglich in korrekter Weise von einem original Microsoft-MBR abweicht.
Also was genau testet MBRCheck hier?

cosinus 11.10.2010 19:32

Tja, falls denn der neue MBR tatsächlich die Recovery-Partition unbootbar macht, müsstest Du den MBR vorher sichern. Ich weiß nicht ob das mit sowas wie Testdisk geht, mit Linux über die Konsole geht das auf jeden Fall.

Herzmann 11.10.2010 20:37

Zitat:

Zitat von cosinus (Beitrag 577674)
Tja, falls denn der neue MBR tatsächlich die Recovery-Partition unbootbar macht, müsstest Du den MBR vorher sichern. Ich weiß nicht ob das mit sowas wie Testdisk geht, mit Linux über die Konsole geht das auf jeden Fall.

Letzteres würde ich schon hinkriegen, doch was würde die ganze Aktion bringen?
Wir wüßten immer noch nicht, ob mein MBR Malware-frei ist.

cosinus 11.10.2010 20:41

Zitat:

Wir wüßten immer noch nicht, ob mein MBR Malware-frei ist.
Deswegen müssen wir den ja neu schreiben, weil mbrcheck einen unbekannten MBR gefunden hat :D

Herzmann 11.10.2010 21:42

Zitat:

Zitat von cosinus (Beitrag 577756)
Deswegen müssen wir den ja neu schreiben, weil mbrcheck einen unbekannten MBR gefunden hat :D

Hm, bin ich jetzt blöd.

Ein per fixmbr erzeugter MBR ist natürlich malware-frei. Den zu prüfen ist nonsens.
Da er zu 99 % meine Recovery-Partition nicht booten kann, müßte ich ihn wieder mit dem zuvor gesicherten MBR überschreiben.
MBRCheck würde dann wieder einen unbekannten MBR finden, von dem wir nicht wissen, ob er malware enthält,
oder exakt in dem Zustand ist, wie von IBM mal draufgespielt.

So wären wir dann keinen einzigen Schritt weiter, oder was hab' ich da übersehen?

cosinus 12.10.2010 09:08

Zitat:

So wären wir dann keinen einzigen Schritt weiter, oder was hab' ich da übersehen?
Gesetzt den Fall, er kann danach von der Recover-Partition nicht mehr booten. Du weißt es auch nicht, oder woher kommen die 99% her? ;)

Edith sagt: Der "unbekannte" MBR kann natürlich auch ein eigener vom Hersteller sein, der natürlich nicht Windowsstandard ist. Du kannst den MBR auch so lassen, wenn Du darauf wettest, der MBR sei ok.
Ist Dir die Recovery-Partition denn so wichtig? Keine normalen Installations-CDs im Haus, wo man Windows für den Fall der Fälle normal neu installieren kann?

Herzmann 12.10.2010 10:35

Zitat:

Zitat von cosinus (Beitrag 577855)
Gesetzt den Fall, er kann danach von der Recover-Partition nicht mehr booten. Du weißt es auch nicht, oder woher kommen die 99% her? ;)

(1.) daraus, daß es scheint (meine Frage danach ist immer noch offen), daß Du nicht weißt nach welchen Kriterien/Parametern MBRCheck die Sicherheit des MBR beurteilt (Hersteller-abhängige Abwandlungen sind ja nicht unüblich, doch MBRCheck scheint sie alle pauschal für malware-verdächtig zu halten ?), und (2.) wegen dieser Erfahrung:
hxxp://www.thinkpad-forum.de/thinkpad-hardware/r-serie/89707-accessibm-geht-nicht-mehr/
Soweit ich mich noch richtig erinnere, hatte ich es damals auch mit der Wiederherstellungskonsole versucht, ohne Erfolg.
Zitat:

Edith sagt: Der "unbekannte" MBR kann natürlich auch ein eigener vom Hersteller sein, der natürlich nicht Windowsstandard ist.
Ja und was macht der MBRCheck denn nun tätsächlich? Vergleicht er nur den MBR mit dem Standard-Original von M$, was ich mit jedem Hexeditor auch von Hand tun könnte, oder wieviel zusätzliche Intelligenz steckt da noch dahinter? :glaskugel:
Die Frage ist ernst gemeint, denn meine IBM-Abwandlung könnte ja dennoch verseucht sein.
Zitat:

Du kannst den MBR auch so lassen, wenn Du darauf wettest, der MBR sei ok.
Ist Dir die Recovery-Partition denn so wichtig? Keine normalen Installations-CDs im Haus, wo man Windows für den Fall der Fälle normal neu installieren kann?
Ja, ist sie. Notebooks sind ja bekanntlich zickig, was Treiber angeht. Warum auf die Originalen von IBM-Lenovo verzichten, zumal die auch ziemlich engagiert in Sachen Bugfixes und Verbesserungen sind? Selbst nach 5 Jahren kommen noch welche.
Des weiteren habe ich mich auch an die ein- oder anderen speziell auf meine Hardware abgestimmten Zusatzfunktionalitäten gewöhnt, z.B. eine ziemlich leistungsfähige Erweiterung der Energieoptionen. Z.B. schlug der Überhitzungsschutz mit den Jahren vermehrt zu (schaltet urplötzlich ab), da die Wärmeleitpaste zwischen CPU und Kühlung altert. In den Energieoptionen konnte ich dann die CPU-Leistungs-Grenze leicht vermindern, und läuft er heute noch.
Und last but not least... Das Windows-Aktivierungs-Thema :headbang:

Herzmann 13.10.2010 12:25

Zitat:

Zitat von cosinus (Beitrag 577855)
Gesetzt den Fall, er kann danach von der Recover-Partition nicht mehr booten. Du weißt es auch nicht, oder woher kommen die 99% her? ;)

Ich erhöhe auf 100 %. :kloppen:

Also ich habe mir die Mühe gemacht. Mit fixmbr wurde der MBR derart zerschossen, daß ich einige Mühe hatte, wieder alles an's Laufen zu bringen.
Dank an die Linux SystemRescueCD :heilig:

Aber wie geht's jetzt weiter?
Gibt's sonst noch was verdächtiges abzuklären?
Ist mein System jetzt evtl. wieder clean?
Sind Trojan.Agent, Worm.Autorun.B, Adware.ADON jemals aktiv geworden?
Falls ja, wie gefährlich sind diese Plagegeister?
Gehören sie zu denen, die Passwörter klauen, oder verbreiten sie "bloß" SPAM?

cosinus 13.10.2010 12:43

Zitat:

doch MBRCheck scheint sie alle pauschal für malware-verdächtig zu halten ?), und (2.) wegen dieser Erfahrung:
Nein so nicht. Die unbekannten werden als unbekannt eingestuft. Das können herstellersüezifische aber auch Malware-MBRs sein. Es gibt auch bekannte schädliche MBRs, da zeigt mbrcheck dann auch tatsächlich known-bad an.

Zitat:

Die Frage ist ernst gemeint, denn meine IBM-Abwandlung könnte ja dennoch verseucht sein.
Ja, aber wie willst Du das prüfen?
Ganz sicher kannst Du Dir nur sein, wenn Du einen neuen MBR schreibst.


Zitat:

Aber wie geht's jetzt weiter?
Lass den MBR jetzt so wie er ist. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

Herzmann 13.10.2010 16:41

Ja danke noch mal.

Nun spinnt mein Druckertreiber, druck nur noch wirre Buchstaben. Kann das die Auswirkung der diversen Fix-Maßnahmen sein?

Die Scans mache ich heute nacht.

cosinus 13.10.2010 16:51

Könnte sein. Druckertreiber mal neu installiert?

Herzmann 14.10.2010 14:54

Code:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4816

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

14.10.2010 04:55:36
mbam-log-2010-10-14 (04-55-36).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|F:\|G:\|H:\|)
Durchsuchte Objekte: 929353
Laufzeit: 3 Stunde(n), 18 Minute(n), 39 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


cosinus 15.10.2010 11:32

Und das andere Log?

Herzmann 15.10.2010 11:37

Zitat:

Zitat von cosinus (Beitrag 579132)
Und das andere Log?

Wurde gestern abend gestartet, und zu ca. 80 % durch. :kaffee:
Danke der Nachfrage !

Herzmann 15.10.2010 14:07

Code:

SUPERAntiSpyware Scann-Protokoll
hxxp://www.superantispyware.com

Generiert 10/15/2010 bei 03:01 PM

Version der Applikation : 4.44.1000

Version der Kern-Datenbank : 5686
Version der Spur-Datenbank : 3498

Scan Art      : kompletter Scann
Totale Scann-Zeit : 14:44:23

Gescannte Speicherelemente  : 1139
Erfasste Speicher-Bedrohungen  : 0
Gescannte Register-Elemente  : 10975
Erfasste Register-Bedrohungen  : 0
Gescannte Datei-Elemente    : 1192758
Erfasste Datei-Elemente  : 0


cosinus 15.10.2010 15:02

Sieht ok aus, keine Funde!
Noch Probleme oder weitere Funde in der Zwischenzeit?

Herzmann 24.11.2010 17:37

Jetzt ist es erstmal schon lange fällig, daß ich mich mal ganz herzlich bedanke für die viele Mühe, und noch etwas Feedback gebe:
- Die beschriebenen Probleme mit dem Drucker rühren eher davon, daß ich seit dem Virenfund meinem Benutzerkonto eingeschränkte Recht verpasst habe, wofür ich ein zusätzliches Konto mit Administratorrechten einrichten mußte. (Das standardmäßig vorhandene Konto "Administrator" reicht dafür unter mir bisher nicht verstehbaren Gründen nicht aus.) Seit dem funktioniert mein Druckertreiber (trotz Neuinstallation) nur noch von dem 2. Administratorkonto aus, vom eingeschränkten Benutzerkonto aus bekomme ich nur Zeichensalat auf's Papier. Der Drucker-Treiber für meinen Epson Stylus SCAN 2500 ist noch eine Win2000-Version, neuere gibts leider nicht.
- Viele andere Probleme, die noch bestehen, kommen vermutlich auch von der 3-Konten-Konfiguration.
- Fritz!Box-Funktionalität hat Macken
- Automatische Software-Updates bleiben hängen
- etc.

Ich muß also wohl mein System doch mal neu installieren. Hoffentlich bekomme ich dann nicht wieder die gleichen Probleme wegen dem eingeschränkten Konto.

Ich überlege auch, die "Daten" auf eine 2. Partition auszulagern. Zumindest "Eigene Dateien" und "Anwendungsdaten" oder gleich den ganzen "Dokumente und Einstellungen"-Ordner, damit ich die Systempartition unabhängig sichern und gegebenenfalls zurückspielen kann. Gibt es da einen Rat zu?
Leider sind ja dann auch die ganzen Systemeinstellungen, welche ja eigentlich der Systempartition zugeordnet gehören, auch auf der Daten-Partition, was ich unlogisch finde.

Da ich einige ältere Anwendungen, die ich nur ganz selten noch brauchen werde, nicht in die neue Installation aufnehmen möchte, müßte ich dann auch noch meine ca. 1,5 Jahre alte Installation (hab' ich noch auf der alten Backup-Platte) von dem gleichen Malware-Problem reinigen. Wenn es soweit ist, melde ich mich dann noch mal.


Alle Zeitangaben in WEZ +1. Es ist jetzt 12:44 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131