Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Unerwünschte Weiterleitung bei Google Suche (Ask.com) (https://www.trojaner-board.de/91899-unerwuenschte-weiterleitung-google-suche-ask-com.html)

AskHans 16.10.2010 14:18

Unerwünschte Weiterleitung bei Google Suche (Ask.com)
 
Hallo zusammen,

auch bei mir ergibt sich das Problem, dass ich bei der Google Suche auf unerwünschte Seite wie ask.com oder kdirectory.com weitergeleitet werde. Ich habe mich schon etwas in den Foren ungesehen und herausgefunden, dass es hierzu wohl nur individuelle Lösungen gibt. Ich habe bereits OTL laufen lassen und Malwarebytes installiert. Für die weiteren Schritte würde ich jedoch Eure Hilfe benötigen und würde mich über Eure Unterstützung sehr freuen.

Viele Grüße,
Johannes

Hier noch der OTL Code:

Code:

OTL logfile created on: 10/16/2010 2:10:28 PM - Run 1
OTL by OldTimer - Version 3.2.15.2    Folder = C:\Users\Johannes\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: Vereinigte Staaten von Amerika | Language: ENU | Date Format: M/d/yyyy
 
3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 49.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144.04 Gb Total Space | 79.70 Gb Free Space | 55.33% Space Free | Partition Type: NTFS
Drive D: | 140.50 Gb Total Space | 44.39 Gb Free Space | 31.59% Space Free | Partition Type: NTFS
Drive E: | 6.67 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 7.47 Gb Total Space | 0.14 Gb Free Space | 1.84% Space Free | Partition Type: FAT32
 
Computer Name: LIEGSALZ | User Name: Johannes | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Johannes\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Programme\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Users\Johannes\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
PRC - C:\Programme\Avira\AntiVir Desktop\avcenter.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\avscan.exe (Avira GmbH)
PRC - C:\Programme\Skype\Toolbars\Shared\SkypeNames2.exe (Skype Technologies S.A.)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
PRC - C:\Programme\FRITZ!DSL\StCenter.exe (AVM Berlin)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Users\Johannes\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Windows\System32\audiodg.exe (Microsoft Corporation)
PRC - C:\Programme\FRITZ!DSL\FwebProt.exe (AVM Berlin)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Programme\Acer\Acer Bio Protection\CompPtcVUI.exe (Arachnoid Biometrics Identification Group Corp.)
PRC - C:\Programme\Acer\Acer Bio Protection\BASVC.exe ()
PRC - C:\Programme\Acer\Acer Bio Protection\PdtWzd.exe (Arachnoid Biometrics Identification Group Corp.)
PRC - C:\Programme\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)
PRC - C:\Programme\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Programme\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
PRC - C:\Programme\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\Programme\Acer\Empowering Technology\Service\ETService.exe ()
PRC - C:\Programme\Acer\Empowering Technology\eAudio\eAudio.exe (Acer Incorporated)
PRC - C:\Programme\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
PRC - C:\Programme\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
PRC - C:\Programme\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe ()
PRC - C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe ()
PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Programme\Common Files\SPBA\upeksvr.exe (UPEK Inc.)
PRC - C:\Programme\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Programme\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Programme\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
PRC - C:\Programme\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\ACER\Mobility Center\MobilityService.exe ()
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Programme\Acer\Acer VCM\acp2HID.exe (Acer Inc.)
PRC - C:\Programme\OpenVPN\bin\openvpn-gui.exe ()
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Johannes\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\SysHook.dll ()
MOD - C:\Windows\System32\BtMmHook.dll (Broadcom Corporation.)
MOD - C:\Programme\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (GoogleDesktopManager-051210-111108) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (IGDCTRL) -- C:\Program Files\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (IGBASVC) -- C:\Programme\Acer\Acer Bio Protection\BASVC.exe ()
SRV - (WinVNC4) -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)
SRV - (IAANTMON) Intel(R) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (ETService) -- C:\Programme\Acer\Empowering Technology\Service\ETService.exe ()
SRV - (eDataSecurity Service) -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
SRV - (NTIBackupSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
SRV - (NTISchedulerSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe ()
SRV - (BUNAgentSvc) -- C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe (NewTech Infosystems, Inc.)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (CLHNService) -- C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
SRV - (RS_Service) -- C:\Programme\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (MobilityService) -- C:\Acer\Mobility Center\MobilityService.exe ()
SRV - (OpenVPNService) -- C:\Programme\OpenVPN\bin\openvpnserv.exe ()
 
 
========== Driver Services (SafeList) ==========
 
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (NETw5v32) Intel(R) -- C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (AlfaFF) -- C:\Windows\system32\Drivers\AlfaFF.sys (Alfa Corporation)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) -- C:\Programme\Acer Arcade Deluxe\PlayMovie\000.fcl (Cyberlink Corp.)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (L1E) -- C:\Windows\System32\drivers\L1E60x86.sys (Atheros Communications, Inc.)
DRV - (psdvdisk) -- C:\Windows\System32\drivers\PSDVdisk.sys (Egis Incorporated)
DRV - (PSDFilter) -- C:\Windows\system32\DRIVERS\psdfilter.sys (Egis Incorporated)
DRV - (PSDNServ) -- C:\Windows\System32\drivers\PSDNServ.sys (Egis Incorporated)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (TcUsb) -- C:\Windows\System32\drivers\tcusb.sys (UPEK Inc.)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (RTSTOR) -- C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (HSF_DPV) -- C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) -- C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (btwaudio) -- C:\Windows\System32\drivers\btwaudio.sys (Broadcom Corporation.)
DRV - (NTIDrvr) -- C:\Windows\System32\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (UBHelper) -- C:\Windows\System32\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) -- C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (NTIPPKernel) -- C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys (Cyberlink Corp.)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (btwrchid) -- C:\Windows\System32\drivers\btwrchid.sys (Broadcom Corporation.)
DRV - (btwavdt) -- C:\Windows\System32\drivers\btwavdt.sys (Broadcom Corporation.)
DRV - (winbondcir) -- C:\Windows\System32\drivers\winbondcir.sys (Winbond Electronics Corporation)
DRV - (int15) -- C:\Windows\System32\drivers\int15.sys ()
DRV - (DKbFltr) -- C:\Windows\System32\drivers\DKbFltr.sys (Dritek System Inc.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (tap0801) -- C:\Windows\System32\drivers\tap0801.sys (The OpenVPN Project)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKLM\..\URLSearchHook: {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - C:\Programme\Softonic_Deutsch\tbSoft.dll (Conduit Ltd.)
 
 
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com [binary data]
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com [binary data]
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
IE - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gmx.de/
IE - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\..\URLSearchHook: {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - C:\Programme\Softonic_Deutsch\tbSoft.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
 
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/16 13:21:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/16 13:21:28 | 000,000,000 | ---D | M]
 
[2010/10/16 13:22:04 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\mozilla\Extensions
[2010/10/16 13:22:12 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\mozilla\Firefox\Profiles\j9g7c9nr.default\extensions
[2010/10/16 13:22:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Johannes\AppData\Roaming\mozilla\Firefox\Profiles\j9g7c9nr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/16 13:22:12 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\mozilla\Firefox\Profiles\j9g7c9nr.default\extensions\staged-xpis
[2010/10/16 13:21:28 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010/09/14 23:32:39 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010/09/14 23:32:39 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010/09/14 23:32:39 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010/09/14 23:32:39 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010/09/14 23:32:39 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006/09/18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Programme\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis)
O2 - BHO: (Softonic Deutsch Toolbar) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - C:\Programme\Softonic_Deutsch\tbSoft.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Programme\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (Softonic Deutsch Toolbar) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - C:\Programme\Softonic_Deutsch\tbSoft.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Programme\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\..\Toolbar\WebBrowser: (Softonic Deutsch Toolbar) - {8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} - C:\Programme\Softonic_Deutsch\tbSoft.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ArcadeDeluxeAgent] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BkupTray] C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe ()
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [eAudio] C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe (Acer Incorporated)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Programme\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
O4 - HKLM..\Run: [ePower_DMC] C:\Programme\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Programme\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [openvpn-gui] C:\Programme\OpenVPN\bin\openvpn-gui.exe ()
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [WarReg_PopUp] C:\Programme\Acer\WR_PopUp\WarReg_PopUp.exe (Acer Incorporated)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZPdtWzdVitaKey MC3000] C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe (Arachnoid Biometrics Identification Group Corp.)
O4 - HKU\.DEFAULT..\Run: [FRITZ!protect]  File not found
O4 - HKU\S-1-5-18..\Run: [FRITZ!protect]  File not found
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-4069621161-912532974-1855927034-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Johannes\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Protect.lnk = C:\Programme\FRITZ!DSL\FwebProt.exe (AVM Berlin)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Programme\Acer\Acer Bio Protection\PwdBank.exe ()
O9 - Extra 'Tools' menuitem : Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Programme\Acer\Acer Bio Protection\PwdBank.exe ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\FRITZ!DSL\\sarah.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000039 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Ranges: GD ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: GD ([http] in Local intranet)
O15 - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\..Trusted Domains: localhost ([]http in Lokales Intranet)
O15 - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\..Trusted Ranges: GD ([http] in Lokales Intranet)
O15 - HKU\S-1-5-21-4069621161-912532974-1855927034-1000\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.84,93.188.161.224
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Programme\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AWinNotifyVitaKey MC3000: DllName - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll - C:\Programme\Acer\Acer Bio Protection\WinNotify.dll (Arachnoid Biometrics Identification Group Corp.)
O20 - Winlogon\Notify\spba: DllName - C:\Program Files\Common Files\SPBA\homefus2.dll - C:\Programme\Common Files\SPBA\homefus2.dll (UPEK Inc.)
O24 - Desktop WallPaper: D:\liegsalz\archiv\Berlin-Calling_Sunset_Paul-Kalkbrenner.jpg
O24 - Desktop BackupWallPaper: D:\liegsalz\archiv\Berlin-Calling_Sunset_Paul-Kalkbrenner.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008/05/06 14:26:23 | 000,000,309 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2009/05/16 08:55:20 | 000,000,000 | ---D | M] - G:\Autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{c9707c94-3c72-11de-82ec-00238b1ed1ba}\Shell - "" = AutoRun
O33 - MountPoints2\{c9707c94-3c72-11de-82ec-00238b1ed1ba}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- [2007/10/23 09:45:40 | 001,336,632 | R--- | M] ()
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- [2007/10/23 09:45:39 | 001,336,632 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5C9A6D70-ADB5-3123-4CFB-BB4EF9CB8F0F} - Internet Explorer
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {BECAB8C3-FA13-32A9-06E4-D3B85B60D00D} - Browser Customizations
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Error creating restore point.
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010/10/16 14:05:44 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Users\Johannes\Desktop\OTL.exe
[2010/10/16 14:02:20 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/10/16 14:02:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/10/16 14:02:15 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/10/16 14:02:15 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2010/10/16 13:21:42 | 000,000,000 | ---D | C] -- C:\Users\Johannes\AppData\Roaming\Mozilla
[2010/10/16 13:21:42 | 000,000,000 | ---D | C] -- C:\Users\Johannes\AppData\Local\Mozilla
[2010/10/16 13:21:25 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2010/10/16 13:20:40 | 008,368,928 | ---- | C] (Mozilla) -- C:\Users\Johannes\Desktop\Firefox Setup 3.6.10.exe
[2010/10/16 12:23:15 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2010/09/29 19:39:49 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010/09/26 10:07:00 | 000,000,000 | ---D | C] -- C:\Programme\iPod
[2010/09/26 10:06:50 | 000,000,000 | ---D | C] -- C:\Programme\iTunes
[2010/09/26 09:59:08 | 000,000,000 | ---D | C] -- C:\Programme\QuickTime
[2008/07/22 10:01:25 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll
 
========== Files - Modified Within 30 Days ==========
 
[2010/10/16 14:02:24 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/16 13:45:50 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\Johannes\Desktop\OTL.exe
[2010/10/16 13:37:48 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/16 13:24:51 | 001,441,160 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/10/16 13:24:51 | 000,911,276 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/10/16 13:24:50 | 003,332,350 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010/10/16 13:24:46 | 001,014,778 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010/10/16 13:21:33 | 000,001,728 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/10/16 13:19:28 | 008,368,928 | ---- | M] (Mozilla) -- C:\Users\Johannes\Desktop\Firefox Setup 3.6.10.exe
[2010/10/16 12:32:40 | 000,001,035 | ---- | M] () -- C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Protect.lnk
[2010/10/16 12:28:14 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/16 12:26:34 | 000,002,337 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Startcenter.lnk
[2010/10/16 12:25:55 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/16 12:25:55 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/16 12:25:54 | 000,028,124 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/10/16 12:25:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/10/16 12:25:29 | 3215,839,232 | -HS- | M] () -- C:\hiberfil.sys
[2010/10/16 12:24:22 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/10/16 12:17:59 | 000,028,124 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/10/15 22:00:54 | 000,281,557 | ---- | M] () -- C:\Users\Johannes\Desktop\Wortschatz.xlsx
[2010/10/08 23:55:36 | 266,550,957 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/10/01 21:41:33 | 000,000,000 | ---- | M] () -- C:\Windows\System32\LogConfigTemp.xml
[2010/09/19 23:35:27 | 000,050,688 | ---- | M] () -- C:\Users\Johannes\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
========== Files Created - No Company Name ==========
 
[2010/10/16 14:02:24 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/16 13:21:33 | 000,001,728 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/10/16 12:32:40 | 000,001,035 | ---- | C] () -- C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Protect.lnk
[2010/10/15 22:00:51 | 000,281,557 | ---- | C] () -- C:\Users\Johannes\Desktop\Wortschatz.xlsx
[2009/10/29 20:56:42 | 000,000,096 | ---- | C] () -- C:\Users\Johannes\AppData\Local\fusioncache.dat
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 11:30:16 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/07/13 23:41:45 | 000,087,552 | ---- | C] () -- C:\Windows\System32\cpwmon2k.dll
[2009/05/12 15:37:55 | 000,050,688 | ---- | C] () -- C:\Users\Johannes\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/11 13:45:53 | 000,007,592 | ---- | C] () -- C:\Users\Johannes\AppData\Local\d3d9caps.dat
[2009/05/09 12:48:37 | 000,028,124 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/05/09 10:32:59 | 000,028,124 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2008/10/27 23:45:53 | 000,006,054 | ---- | C] () -- C:\ProgramData\ArcadeDeluxe2.log
[2008/10/27 23:44:52 | 000,118,784 | ---- | C] () -- C:\Windows\System32\VMC3KAPI.dll
[2008/10/27 23:26:46 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2008/10/27 23:26:46 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini
[2008/07/30 12:19:21 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008/07/30 04:13:17 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIOFM4.dll
[2008/07/30 04:13:17 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN5.dll
[2008/07/30 03:47:56 | 000,204,800 | ---- | C] () -- C:\Windows\System32\SysHook.dll
[2008/07/30 03:42:04 | 000,487,424 | ---- | C] () -- C:\Windows\System32\INT15.dll
[2008/07/30 03:25:14 | 000,001,694 | ---- | C] () -- C:\Windows\RtDefLvl.ini
[2008/02/20 23:44:36 | 000,065,536 | ---- | C] () -- C:\Windows\System32\HPPLVS.dll
[2008/02/07 10:05:18 | 000,163,840 | ---- | C] () -- C:\Windows\System32\hppatusg01.dll
[2007/01/26 08:32:18 | 000,069,632 | ---- | C] () -- C:\Windows\System32\drivers\int15.sys
[2006/11/02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005/01/03 11:10:44 | 000,319,488 | ---- | C] () -- C:\Windows\System32\DLXAPI32.DLL
[2001/12/26 16:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001/11/14 14:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
[2001/09/03 23:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001/07/30 16:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001/07/23 22:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll
 
========== LOP Check ==========
 
[2008/07/30 04:10:28 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Acer GameZone Console
[2008/07/30 04:10:28 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Acer GameZone Console
[2008/07/30 04:10:28 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Acer GameZone Console
[2010/10/16 12:28:19 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Dropbox
[2009/11/01 00:39:02 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Eidologic
[2010/06/09 19:27:08 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\elsterformular
[2010/10/16 12:32:40 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\FRITZ!
[2009/05/07 20:33:20 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Stata10
[2010/10/16 12:27:11 | 000,032,530 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2008/07/30 04:10:28 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Acer GameZone Console
[2010/05/02 22:22:49 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Adobe
[2010/08/19 10:46:45 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Apple Computer
[2009/06/09 20:48:33 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\CyberLink
[2010/10/16 12:28:19 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Dropbox
[2009/11/01 00:39:02 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Eidologic
[2010/06/09 19:27:08 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\elsterformular
[2010/10/16 12:32:40 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\FRITZ!
[2009/05/07 20:28:03 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Google
[2009/05/07 20:07:19 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Identities
[2009/05/07 20:07:51 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Macromedia
[2006/11/02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Media Center Programs
[2010/04/11 18:42:08 | 000,000,000 | --SD | M] -- C:\Users\Johannes\AppData\Roaming\Microsoft
[2010/10/16 13:22:04 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Mozilla
[2010/10/16 14:12:34 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Skype
[2010/10/16 12:16:39 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\skypePM
[2009/05/07 20:33:20 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\Stata10
[2010/07/10 11:16:13 | 000,000,000 | ---D | M] -- C:\Users\Johannes\AppData\Roaming\U3
 
< %APPDATA%\*.exe /s >
[2010/02/26 07:10:20 | 021,979,992 | ---- | M] () -- C:\Users\Johannes\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2010/08/25 20:05:06 | 000,089,831 | ---- | M] () -- C:\Users\Johannes\AppData\Roaming\Dropbox\bin\Uninstall.exe
[2007/10/23 09:27:20 | 000,110,592 | ---- | M] () -- C:\Users\Johannes\AppData\Roaming\U3\temp\cleanup.exe
[2008/05/02 10:41:48 | 003,493,888 | -H-- | M] (SanDisk Corporation) -- C:\Users\Johannes\AppData\Roaming\U3\temp\Launchpad Removal.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2008/01/21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008/01/21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009/04/11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\drivers\atapi.sys
[2008/01/21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2007/01/12 23:30:08 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Programme\Cyberlink\PowerDirector\EventLog.dll
 
< MD5 for: EXPLORER.EXE  >
[2008/10/29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009/04/11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/21 04:24:24 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
 
< MD5 for: IASTOR.SYS  >
[2008/07/20 11:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\ACER\Preload\Autorun\DRV\Intel Robson RBSMDL2G\Winall\Driver\IaStor.sys
[2008/07/20 11:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\Programme\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008/07/20 18:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\Windows\System32\drivers\iaStor.sys
[2008/07/20 11:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_7b6e77f6\iaStor.sys
[2008/04/20 18:29:38 | 000,317,464 | ---- | M] (Intel Corporation) MD5=9F1220113A3A7F4F08042C699324D073 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_18bd4575\iaStor.sys
[2008/07/20 11:44:54 | 000,402,456 | ---- | M] (Intel Corporation) MD5=FC28E90F2204D8FD147FA9BFA8A51C01 -- C:\ACER\Preload\Autorun\DRV\Intel Robson RBSMDL2G\Winall\Driver64\IaStor.sys
[2008/07/20 11:44:54 | 000,402,456 | ---- | M] (Intel Corporation) MD5=FC28E90F2204D8FD147FA9BFA8A51C01 -- C:\Programme\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2008/01/21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008/01/21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009/04/11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009/04/11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/21 04:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006/11/02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008/01/21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008/01/21 04:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009/04/11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2008/01/21 04:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2009/04/11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009/04/11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008/01/21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008/01/21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009/04/11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009/04/11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/21 04:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008/01/21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008/01/21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008/01/21 05:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 05:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 05:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2008/01/21 04:24:47 | 000,403,968 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\FirewallAPI.dll
[2009/04/11 08:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll
[2009/04/11 08:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\SLC.dll
 
< End of report >

Und der Extras Code:

Code:

OTL Extras logfile created on: 10/16/2010 2:10:28 PM - Run 1
OTL by OldTimer - Version 3.2.15.2    Folder = C:\Users\Johannes\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: Vereinigte Staaten von Amerika | Language: ENU | Date Format: M/d/yyyy
 
3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 49.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144.04 Gb Total Space | 79.70 Gb Free Space | 55.33% Space Free | Partition Type: NTFS
Drive D: | 140.50 Gb Total Space | 44.39 Gb Free Space | 31.59% Space Free | Partition Type: NTFS
Drive E: | 6.67 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 7.47 Gb Total Space | 0.14 Gb Free Space | 1.84% Space Free | Partition Type: FAT32
 
Computer Name: LIEGSALZ | User Name: Johannes | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_USERS\S-1-5-21-4069621161-912532974-1855927034-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-4069621161-912532974-1855927034-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E947F4A-88A0-4083-B4B2-DCD64EC7B03D}" = rport=139 | protocol=6 | dir=out | app=system |
"{100F3840-5B83-490D-A7EF-C3781F86DFE8}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{23754781-6A0F-45CB-AA57-72D164ED65E4}" = rport=137 | protocol=17 | dir=out | app=system |
"{82093AF4-8A7D-4D36-B89E-C72C04722B3E}" = lport=138 | protocol=17 | dir=in | app=system |
"{951B2BEF-6DDB-4483-9136-F505E67F35C0}" = lport=137 | protocol=17 | dir=in | app=system |
"{9B2BE31F-21E3-4E14-9D5F-CEEFBF826629}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9F48705E-99EB-440D-8366-9CFDF7DD4D45}" = rport=138 | protocol=17 | dir=out | app=system |
"{BFB048BD-3E30-440B-B85B-E901586C3077}" = lport=445 | protocol=6 | dir=in | app=system |
"{F3AB156C-621E-4435-9F63-E435077A616C}" = lport=139 | protocol=6 | dir=in | app=system |
"{FA956595-D851-4219-9C4F-B2EABC8F3B39}" = rport=445 | protocol=6 | dir=out | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00956BE9-0AA5-45D8-BC3A-907B2CE94566}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0099897C-2885-4671-89FD-B2FD95012F88}" = protocol=17 | dir=in | app=c:\users\johannes\appdata\roaming\dropbox\bin\dropbox.exe |
"{00B94FEE-D78C-4641-BF4B-18A2EB2B479A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0142C4C0-E89C-4C69-B62C-F1DA82F02DAB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{01A78E9F-B1EA-41AB-A292-D8684C9C8A7A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{021CA627-BE8D-4AE7-9CDB-E0789ED8A6CA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{02274A6B-80DA-4AAA-8125-CC0657C40FF6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{02C978DF-2631-4A90-AE78-669D7F3D5AA4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{03195E77-55B3-4FBC-94F4-51B4D727DFC5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{039A9C26-3F9D-41D6-84F2-58F712E3C121}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{04C6958F-B546-4F8A-B73A-C5FCAB063537}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{06D00463-3682-4399-BC65-7979E6D8E6C6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0833824D-9750-48C3-A5BC-3C3EAC8641A1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{089B8109-2978-4DF1-BA6D-5A7065417C4D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{09315F9D-5FC8-4879-851B-4E5A763FEC5B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{09E4D144-9408-4435-92F8-715B919D661B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0A902F12-A59A-4226-9C3F-E28B27F01A8D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0AF12BBE-CB74-4F07-A0C0-41001C091905}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0B33490A-D239-4B59-BD19-A17436EB7FC7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0BD28678-DD0F-45E8-9764-4A856EC753E4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0BE7BF9E-018E-496F-A295-17BAC673630E}" = protocol=17 | dir=in | app=c:\windows\system32\spoolsv.exe |
"{0CCC7B00-BBC8-433B-85A1-F68EAA6F748C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0CD4B801-CC22-41BB-BDF2-813730C4E80E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0D5FEF81-BC1B-46FB-80E0-34A4059F71B5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0EC6B9CA-1931-4FC1-925B-FFCB84035772}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0EF0AE3F-CF5D-4625-A64A-DD8F8D775124}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0F5D8A88-83E1-4DA9-812C-A195BDF3560F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0F7B50C9-5221-4E5B-A68C-0F11B6A73EF9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0F8C498E-027F-42D8-AD21-0F3034835179}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{117DA5AF-A4A1-43E9-8C12-20CD04CED15F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{11C9AA44-F11A-4B2E-9D50-A1E431A0542C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{120E67AB-840A-4809-8F21-7EC1EE30BD0F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1212A629-5CA7-4A5C-AB97-C54E6C28E2D8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{123902C3-3DFA-4F07-82EF-790194DEA37F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{12824B6B-92DB-415C-A0A8-C3716C1AE599}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{12EF3EA0-5014-4B84-ABF8-1D2AEE66D8C4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{12FBB15D-739F-4AB7-9740-60FEF3B1E782}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{13D15A9E-F514-4EF9-BA7C-51A351E94A2F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{14538770-927C-4FBD-88AB-4236E8B73CF3}" = protocol=6 | dir=in | app=c:\program files\sonos\sonos.exe |
"{14873C1C-8B59-46C0-BC2E-5D03EDDF60A3}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe |
"{14AC87AD-C54F-4708-A471-18940D342DA3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{14E9C117-2098-49F2-BFB8-314F2FBE3747}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{16867654-02D9-49EC-A1EB-C6DEB78B4D6C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{16C674DE-D156-499E-B50D-1EEF3FFB82D7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{176D5BE5-3143-4CEC-A576-A3E8D5DB52B4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{18D019F4-FB2C-4D95-AAB3-4E0B1828212E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{195C3C6B-2540-478A-848F-C2E9965FD965}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{19806395-A7B5-400C-9A54-F8AFE74E91DA}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\playmovie.exe |
"{1B8D821E-7795-4199-AC7A-9EC12D8888A0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1BF0BA1A-CA9C-4D79-9A09-BD67088189B9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1CC289F5-A147-425D-9438-E8BE6889911B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1DDDE9BE-F928-4B13-B31B-E33C018B6C2B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1ECB7470-9F42-4F8A-A9FC-A6D4AC1DB1A2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1EDC5FBA-EA02-456E-ACC1-11E3B227591C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1EEEE847-2A7A-44D2-A7F6-84F3A323DD19}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1F3AE81B-2434-44CD-B9EA-B967EA366321}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1F8012B1-8881-4D76-9386-8DCC2C400876}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1FF8AEE3-8028-4BE2-B40A-2E7F0105124F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2041EFBA-3375-47DC-989E-387672C61CBF}" = protocol=6 | dir=in | app=c:\windows\system32\spoolsv.exe |
"{22845442-399E-4E96-8987-701C09775CCF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{23091494-6864-4EE6-A33C-476FE8686C49}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{238D75D9-06DC-4DFD-A415-55800A8894FC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{241B0188-521C-42F9-BE45-53B59F85D1E2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2474E903-4B39-4278-893D-BE66E58311B1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{24B64FD4-6A4A-49D1-A952-425DEF3DCCA7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2581E171-97AB-49A4-9A62-F56843A80E8B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{260E6776-F628-42DA-B9F8-0CCC81D5F269}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{26E77F96-2F51-4C56-BB00-0EC60626EDDC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{27491E29-0A45-41C0-B325-F7C61AAA5FFE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2765FD1C-FAC0-44F0-988C-AE0A5580734A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{28355984-748A-470A-BB4F-C3E7229095F1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2841E1B1-B3E7-4E9E-B03E-39AAEE332845}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2AD026A8-4232-44E7-972E-5C22C40EC551}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2AED3AB6-690B-4C85-A371-B2828EB398BB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2B1872F1-EDC1-4DB4-8A5C-8B5B1441A90A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2B3E9C70-CD1B-4D9E-A26D-50E047DAB82B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2B932962-D0C1-4175-BBF3-35BE9FB52CF7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2BB09CF6-9005-4785-AE4A-790DEE1E5A6E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2BBC3EB7-EE27-4F0E-8566-4A5F16A65A66}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{2C10872C-73D4-4A82-908C-C5BF67FEA7CA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2CDA604F-E160-441D-A259-D860DA8BF2BA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2D6EB2C6-5682-4068-B53D-9FADF6C4C5C4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2DF98EEC-9424-42E4-B222-50BAD22A3827}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{2DFE031F-B86B-4970-BC75-7A00C95C5CAC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2E384D7F-C387-4361-AA0A-A4B5740FDA11}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2EDE151E-9436-4F8C-8FE3-B4E755F0D41E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2FFC2C64-6222-45D5-8773-DAAB09096242}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3003121D-3E51-460E-BB16-816C9DD2603F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3263116E-47A7-4CF0-AA01-F7CEFC66AFA8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3277F3D5-6D35-4045-B3E5-F09CE6F29832}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{32BA2FBC-59A7-46F1-B8DA-C944F1E5A7AE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{32F33A07-C223-453D-9F35-7CC99E1EE929}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{335F8810-C87B-4397-AE5C-F98F4AF58601}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{351DAD91-8739-4014-9819-8A4AD6D76221}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3534FB83-84DB-4DE8-9945-59894F4449DE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{35384DF6-4A69-4783-A344-F4DECBFBEC0A}" = protocol=17 | dir=in | app=c:\program files\sonos\sonos.exe |
"{38BBFF3B-1112-4379-8597-5BE663D39168}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{39170697-7FA8-42E0-9478-F7056506EE7B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{39C5B63D-9E7E-4F1E-954F-D6A9B1AE94A7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3ACA310B-A0F0-4321-B23B-D922D5E672BF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3AE79C0A-1F3F-4A43-92D7-EC77800B250C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3B97B49A-7DF8-446F-A397-34B086C16B21}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3BB20730-CD55-4EC6-A6C5-3FAC492254DE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3CBEAE3C-33E0-4100-BBA6-F99A54CB498A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3D68A0C7-6CDE-4A66-A1D7-128F40B5C702}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3E1DA78D-AAB7-44AD-A127-81A1AEF35EC9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3E42D94B-C24F-44BF-802F-750B6150EC5E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3E7B66C0-97E9-47B2-9593-BFED7463D7A2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{405A3A48-6587-482A-9E75-02D3B1E79785}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{413AAE5A-CB9B-4B0C-9263-9777E6D2080B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{417B13D0-1852-41BD-82BC-9066ACF2BD0D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4185E83E-3E6C-40FC-A42C-C08B43ED07A1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{41A0AC90-A617-44C8-AC41-41528BDC32AC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4236854A-DB40-438C-8745-BED82E1C9FCF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4355D0A4-EF0B-476D-8528-7BCD3D8EB25A}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4500FD3B-90E3-4F6B-8ED6-4469CFE3BE2B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{45641157-C0AD-4793-9710-447881CE1E70}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{45F3C2A3-2818-43B8-AFC0-F318FECEC943}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{47ADC146-A443-4126-BF25-84D943275FF9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{47EB541D-6161-4536-9CA9-E89E85FF0AE7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{47F8348D-F544-4C66-AE46-3E7E2AB98ADF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{481D442C-F37F-460A-9F0C-206A5D4955ED}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{482760BF-897A-44A0-A829-709D39DA9DBB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{498A27F4-5688-4EB1-9754-1D31C0FA4ADE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{49EC9784-5706-421D-9E27-59E0F146706D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4A1DA44B-323A-475D-9790-A104E9BF18A5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4B0413C6-FBC4-4EC0-8E82-B613790CC078}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4B48B25B-2501-4621-939E-DFCC95AF0176}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4B6BD803-BEB3-46D8-A395-2C8672C518F8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4C096D42-5134-49C8-8E59-465F51C07236}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4C4DA137-5517-4F25-B581-10BF60782D43}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{4CCE9736-AF52-43FC-A949-8F8613A9408D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4D2FBC7F-69F8-40CA-A1B5-8C78BF5A992F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4E03CBD7-0CDA-4C8D-94EC-40D7D7D111AB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4E3A4306-C905-4EB0-AE8E-D5D63AC74F17}" = protocol=17 | dir=in | app=c:\program files\fritz!dsl\fboxupd.exe |
"{4E520F43-F711-4F73-A59E-A65BB7BA9D2D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4E5D92A2-36C2-47D0-9000-5B23BC69FD19}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4EC75B4D-B7A5-4023-AB25-6D0570EA1CB8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{51155A9B-8297-47B0-997E-0959364A1388}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{51C2B59B-8D93-4552-8A4B-684CCE73F10B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{521B8DC3-1125-45AF-9034-969AD8A822D9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{52897FE2-9528-4B1C-9DB4-A5B31F7FDBCB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{529ACC6D-CEEA-49EC-A0F3-38C6CEC52B60}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{549920B0-DB01-49E9-9934-3271A763F75E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{54D5238F-D180-4702-8D76-3F5C5B875724}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5502442E-3BDD-4498-BAAD-EF734379219C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{557C37F8-7566-4758-AB68-B5EC9165D8B0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{55BC8675-DBEE-49CC-B733-F130C7614890}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{566649BC-7F38-4B0E-8678-2F54E9958DFE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{56B44DBA-1A0F-4979-8ECE-9019FFA2E341}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{572BF3BC-3240-4038-BAC9-63A12019382E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5730DC48-77F1-4199-9E57-1E8C8A5BFE1D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{573743C1-188F-46CA-B3B3-7504A9A8E2B6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{57759614-5291-4068-9185-F1C38767E041}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{57DA9F9C-62C2-4B64-A1B2-223C0E401453}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{58005BD7-1435-4B5B-83C7-CE30F5D15B9A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{580EC7B2-679E-4BD8-BF9C-8FEE27434B3C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{587CB553-A767-41C7-B481-36E0C2CAB2EB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5A6CDFE9-D553-48F6-BFCC-385D1D7F8F33}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5B43A3FC-A139-4869-A009-3CC4E88273B8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5CDCD959-A952-4BAA-8D3F-0733A1CA9AEC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5D14F57C-515A-4BD4-8591-D25075645487}" = protocol=6 | dir=in | app=c:\program files\fritz!dsl\webwaigd.exe |
"{5DD161ED-D0F0-4FC1-8E92-E95D45115645}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5DDA1596-5F1A-4FAC-A3AD-E85CD3E101A2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{601414A7-FAD5-44DF-993C-D96D8887A96A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6166F5F7-342D-41A6-9034-FA31C405C4F6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{616F102E-3BD2-464E-82BA-7B2663D447AB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{630B2E31-9D61-4C04-BAF3-3999DECE446C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{63182D00-9179-48E1-A2F9-80B813462766}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{63AEAFBB-FAFF-4853-BDBE-5D5CB1ACCE8D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6623C51E-E401-4132-8D33-21682A2A2A96}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6682A241-6AFA-4E6A-A094-23177C75D411}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{66A9EB5F-EF4A-4D4E-B15F-F5831C4524AC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{677CFE80-3104-4EBF-BDEE-09C9269BB0E8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{67F63488-7ECE-4562-B2FC-93B5915706B9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{68D6DB6A-3CE8-45C5-99F9-E6954B225470}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{69477792-9838-46D6-B2E0-52D1F4A72F3B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{69E0DBFA-A7F0-463F-8E52-953C82B2E300}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6A4E3113-1B6B-470A-A854-140496EEE517}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6AF38723-C40C-44FD-8311-91A147B1E422}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6B0902B4-EDF7-4431-A3EE-C5371C61AE07}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6B27F55E-C435-4E03-B275-D970E1052A72}" = protocol=6 | dir=in | app=c:\program files\fritz!dsl\igdctrl.exe |
"{6D01FA02-9F6E-4A20-85A5-0C30B7490780}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6EA8791F-352C-48FB-AB45-AD706144D595}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6EB71356-19CF-48B7-A1AB-9E8BB938C175}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{70DE87E4-8E3F-48FB-9566-12E5C70C750F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{71072B48-8251-4F4C-8830-D1577D168926}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{710B6B17-86CD-4B83-ADA5-5A587F546938}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\pmvservice.exe |
"{71160F5D-38E5-4DE6-9B04-8FBC8AC4BEAC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{71B4CF44-B4C0-4A3C-986F-8BDE20A28567}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{72733298-110B-41F0-9E46-F72627BA4D55}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{72D328A8-1FC6-493C-A5A0-6D11863DB38E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{74249831-98AF-4310-8FAF-34CC2EBB1CE3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{74954A46-82D8-4406-A87D-AB802843BCFC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7499DD14-C84B-4817-8BA5-4DC4E59BB93F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{752E1F2E-EF83-4017-8732-A4FFB091CE9D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{756C3400-01DF-4842-BB0E-BAEE29EAAFCB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{758B8339-361D-441E-BE15-291E3F91B072}" = protocol=6 | dir=in | app=c:\windows\system32\spoolsv.exe |
"{76000322-A4B7-43A3-9E5A-6A115B4F6E9A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7664AAFA-D097-42E6-8F63-9BE50CD8A1AC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7681F4E3-C374-499F-9C92-59D55D7318A4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{76AC1C17-0FC2-4DF3-8CCF-DA93685CB5B7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{788A4363-6D20-4BC0-A606-170420875E26}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{79837F8F-CAAF-4ECD-BD89-E063A31C2837}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7993B8C0-FDD2-4814-ABBE-8EE3B4D2DDB8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7B05C56F-418C-4CBE-920C-A0DBB651EA93}" = protocol=17 | dir=in | app=c:\windows\system32\spoolsv.exe |
"{7B805385-5C73-43DC-BE3A-72D744765629}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7B9FBC05-A880-467B-8413-E06B68F3470A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7BD65B90-A3F1-4D8C-9E90-4999B8EBA804}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{7C372FFB-C0EC-450F-8583-B29DEE8AE356}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7CD57EC8-916D-41A1-A2C5-B5D4C9F52F27}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7EF1E812-7F50-4432-B7B2-E631D565D9CA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7F794A77-FE95-4E62-8480-284AB6387C2F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8032B017-8C02-44E2-801F-8A8FAFD1B621}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{80EA5587-8923-4486-958B-2D9528C01BF3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{80F2F3E3-0677-4635-9502-BD1CFB1F01D7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{80FB5189-8353-4538-8C32-34C0D2B1DC3B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{815AF9BC-DC0A-4C66-97CA-E6B1DE6222C2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8168D247-D8AA-4821-A75E-209EB3CACF81}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{82831AD2-4CC6-4D48-9C81-B87139DF3E26}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{8350BC07-4498-46E6-B7BB-46C0F7DAF8F0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{83D65D57-6575-49AD-8D90-0AD5A4A3B421}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{85B99C08-3BC1-43DC-96F7-207BC89E8173}" = protocol=17 | dir=in | app=c:\program files\fritz!dsl\igdctrl.exe |
"{869733EA-67B4-410F-81FB-64F2243E7569}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{876EFDEE-709D-4699-B158-443FE622087B}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{87B84038-FAAD-47E3-A146-492F98609577}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8886CEF1-F797-4FCD-9CAC-2781BAA247F8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{893AB7C4-7E07-4BD0-806D-9F18B215CF75}" = protocol=17 | dir=in | app=c:\program files\fritz!dsl\webwaigd.exe |
"{897EABCA-2D10-46BD-810E-6850BCCB0398}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8B677C9C-7053-48AA-BEDD-39775BE36440}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8C181C18-6632-450B-A528-97E2EB8FD823}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8C483D7C-A78E-4280-8568-8C815D99BD23}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8C76565A-8B57-4B05-BACF-8D25B6F52E4A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8D0FC374-D096-4F62-B619-226931691287}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8DE20B14-C53D-425E-A11C-1CB3F738E10E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{90319220-F302-4D66-9E98-8ABA8C8B8D2C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{90F85D7F-7088-4013-8CAB-D4872092911B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{90FA3513-BC37-490E-8139-489BEC66EA48}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{91E3BD93-B0A3-4B83-894A-B50B7C662164}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{92998744-4C2E-43CD-BCE6-83457EA33C02}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{935CAD44-19A2-495D-97C4-074A8453FDD6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{93FE8C10-0154-4D44-9D94-9E66D5A08530}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{940DAB68-BF58-47A4-A7E6-5816EF78CEDD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9518B806-DC59-45A9-AB3E-749A5E2066D2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{953D7395-1C15-43F5-856D-EB321B04C5E4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9662C563-9C91-44C5-99F9-4E4D9CD30E9B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{96D28C38-5222-480B-9B88-F2B55CDDEDC0}" = protocol=6 | dir=in | app=c:\users\johannes\appdata\roaming\dropbox\bin\dropbox.exe |
"{96D9938D-4996-4975-9614-2931282F2CD3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{970E2153-184F-482B-9B86-B46EAE130CBB}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{98CCA0CD-93B6-4FD9-9478-E1DB7938F3ED}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{98DDD205-2849-43CC-9669-F89172848F30}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9C80CA82-9D92-4E52-9138-C3F373B10681}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9D9CEC62-696D-4B8A-BC1F-2F317633F607}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9DBD68C1-29A0-45B6-A3DB-534E7C42EB8E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9DCDBF7C-9ABC-4FE2-84D6-64B88C0A2A9E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9E24F5F5-6B74-48AB-8E68-EF0D718FF0D5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9E2D791E-9915-4C58-AEBC-08F81265FEBC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9F795BBD-36BA-4002-9CC3-B765630606DA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A0113961-14D2-4990-AEED-774FA2F57D27}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A01E2F10-3ADF-4094-9C35-9EFE76287E52}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A2DEBD58-CC7E-4925-9ADF-C9E804F33AFA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A3D5EE3E-7915-4E7E-BBF2-3CB83FF8FFF5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A62E0D80-ECDA-4BF3-9CAA-AB2DA84C7EBD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A6440A80-5839-44D7-A274-A8BB2F8B19AC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A6502534-C604-4550-B945-6FA89A10572D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{AA99C0D8-5208-4083-8E1B-CDE134F81C21}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\hp1006mc.exe |
"{AAFC7ACE-8A29-4324-9ADF-71208DA18CD9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{ADC89E6B-0254-4880-B33E-36C9A19E6B2C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{AF93B471-036C-4D37-ABC8-ADC98805C84D}" = dir=in | app=c:\program files\acer\acer vcm\vc.exe |
"{B0AC5D68-FF1D-4FB4-8C91-142DE8960B18}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B0BDF727-DCF3-4FC5-9799-FAB46D6C03FC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B157DF00-BC4D-40E0-BAC8-E964D2AA1381}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B331154D-F137-41C4-95FE-D040DE133411}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{B36220C5-38DC-4814-96A2-C22F3CCA8134}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B3D45A7D-8AD2-4E2C-8D15-B27610520A8F}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{B48F2DB3-F101-497D-941F-F3997D98EDB5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B4962334-8DE9-4FD1-A46B-C6C34331DDA5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B6C093BC-1E03-4E7D-999E-609A6B9B03BB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B7018956-0178-4A2F-9267-C28DCFC4D0CD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B7F8FDD0-EC59-44E9-8DB1-56A6D66ECCE0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B87F52E5-8B48-4EB6-9BA7-BE91C739EEFC}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{B90CD7E6-A2C1-4DD6-A433-DCC83AC552AF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B95A29CF-C9FA-4421-BF74-00AC3BC9FF9B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B9CE16EA-99E4-4BB3-B2F7-184D13C6D935}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B9E4CDB5-504C-4DF0-A4D5-64004C7210BF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BA878669-4669-40FB-8764-97BD9665E6C0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BADA5A60-B1A7-44EC-9DF9-2C33A23E5BAF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BB1AC080-D61F-45FB-A203-EF488AFBABF9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BB42E5E5-EE1B-44AE-B4A6-13A6FB8E3BC5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BC452016-9E16-4132-9AA3-34BD59B12D6D}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe |
"{BC9D9398-8739-4B45-8976-860E6277C40A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BCAE1AF3-397F-4078-952A-F579256E75E1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BE8EC1C2-7DEC-4F17-BE76-E1B85078739E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BEEEEE1F-50B1-48DF-B05F-7ACE0E6D17B3}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{BF22287D-EB6A-4FA7-8BAA-583C596A9F8A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BF702EFC-B559-45F7-8600-0C9D839FAFED}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C0362D18-7296-4A3B-8421-3FFD11323561}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C0E9A36F-5F3B-44F6-80D8-B5D2C7E17153}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C17C4EA4-4A9A-43C2-B6C6-E27B045E43B2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C1BCFBA0-31DC-4E8B-996B-8013E39704CF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C40C8D8D-7BB2-408A-ADE3-CEEA6BCCD1B4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C4BB62C1-7EB8-426D-B73B-D75131B98E9A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C5A44ADF-6592-49D6-96A4-AE18BEE87E0B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C5C19C8E-B863-455B-99E7-03719D324D63}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C661594C-6577-4784-B471-1EB18C287F04}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C688884A-862C-4EB6-B84F-6D761FE97B7F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C7318A9E-8B9F-4B3F-B980-4ED6C69EAB8A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C7B2F9D7-DDC4-46F7-B0A6-0E38DC51C502}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C83CCC83-6E37-44C9-9055-D2FEBFE747D9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C9BF3E48-3057-4C6C-A180-8A1156ED6A6F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CA0BA514-BAB0-4633-970B-F3025C3AC5D3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CA0CFE7A-E094-4CA1-8A4C-C11581776697}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CAFCFBC1-1B64-4117-B522-C6B3095CE569}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CB11D3B4-E420-42A3-A762-07DCCCAB0888}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CBCF8E9A-2E89-43AD-8AEB-0C0C8A62E7E4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CC5B8FDD-675D-4FAE-9871-EB5A27C46DC3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CCD9228C-3712-46E2-8132-0373BD7775C1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CDB1FF85-241F-43F0-867A-D01E9714C416}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CF1E8C29-0997-459A-9AE5-03162C6EFD3A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CF359ECF-0B40-48F8-8A4B-6CFB4D89584E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CFE6EBF3-6204-48AF-8AD2-98E7A66D853B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CFF72C9E-4EB3-4FD4-A77F-94C746F62EC4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D084363A-64E0-400C-9E51-D7133D5C89B5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D0F50243-C88E-420C-89DB-436D0E397E7D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D174DBD2-A0A0-43A5-A75B-E4272DD47F4E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D21512CF-1D55-46B1-AA81-3CB11AC69C43}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D2919B45-C0DD-46E0-9F47-93809BEA3C16}" = protocol=6 | dir=in | app=c:\program files\fritz!dsl\fboxupd.exe |
"{D2B68234-DFC8-44A8-9FEA-86C07112C498}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D3C352F4-F5D9-45B9-A510-FB92EA29A69A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D4CCB30C-9728-4700-9790-0334477CD4BF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D4FE3C6D-D763-406D-AF53-95FD54F21C6B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D5DF75D1-EEA6-459E-8591-6356410D57BB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D5E1EE37-B319-48BB-A793-39B45264C0F4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D6BC0049-27C7-4762-B974-0788031D37FC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D6E7DF08-A03B-4E85-8C9D-C0CE9E450AAC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D804CD33-4989-4A32-825C-71F752F7B720}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{D8A14323-5A9D-4F15-9E66-5B7B34FEF40F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D92A6963-C9AF-4913-8466-69318525E6DC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D991739E-4DDD-420C-8AF0-A280C39BD908}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D9A614B4-8416-4E83-B788-140D5D8C1C69}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D9E86520-0DEC-4293-9B25-CAC688967BCA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DA5EC040-A9A7-494F-AD8A-8802A1085803}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DAD0131F-0698-4917-8D2F-B8A4D3CA3890}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DB1CF8E3-278F-4C58-BE03-8A5CAB55A0E9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DB339D84-F5F7-47EB-8D9D-19B0DBD64006}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\hp1006mc.exe |
"{DBDC3941-509C-420C-86C3-081FB1A70B35}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DC08BB7C-0907-4720-A16A-C6945709CE5E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DC365E67-16A3-42B2-9CBB-DFEDB1C212C8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DC3D37E7-9D95-45E6-B4C4-8B3071FBAF73}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DCE0C462-B3FB-49B9-919B-BE36C9A8CFD9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DD2D6DA9-C57E-49CC-9B52-37CB6E5F2333}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DDD7992D-630D-4D59-A56A-CFFE3B5A67EF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DDEB9D2D-DE97-4F7B-8C8C-606C5FC7385C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DEAEE373-BBF0-4F2E-AB54-6561C76294EF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DECB5B5A-864E-4396-8627-09884A5A09F3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DECDC1D3-F3C7-4963-8035-AE7F2CF2F4DD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DFEC3AA5-D81D-4D76-A64C-31441CC60B31}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E00FC11D-632B-46F6-BA55-6C5285BB3F20}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E1796BA1-BC4C-4A41-8FAB-5E1CB1453B99}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E1BEBEBA-0CC2-40B6-B2B5-A55F9171DC86}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E207B34B-4D14-4E87-95AF-B5C721137C57}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E2CBFCE1-30C7-4560-BAD4-60C17482F3F2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E2FD04AF-28E4-4D8A-B714-1210C8036C23}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E325A4B8-E474-4EAC-BA0D-7660A4139EB6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E4C5EA14-8CE9-4EDF-B2EC-21646CF0DB8C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E663AF8F-02A3-4FF1-BEE6-ADFE58A01E54}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E7381880-0E5B-486A-87E0-84E4064D9C1B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E8ACD9DD-5DCB-46F5-BD9A-24A28428962B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E8CCA47B-2AF0-4E17-8BF2-3FD17260AD60}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E92AFA55-CB5B-4AF4-85D3-7087A5A46398}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E94BF204-ACC1-4FED-819F-851855EB726C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E9B7F232-6487-4F68-8DE0-32B49FB4349C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{EA9D1165-2529-4EE4-8D80-1904AF6731C2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{ECF1617E-506E-4C85-8EC6-9EE84EE25B8F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{ED72F608-95B5-432B-BBEF-6088C92FFE29}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{EDCA9E7F-4B22-4F5A-93A6-525DEC11C2FD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{EDEDC86A-6E8D-412E-9815-35DB603E67BD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{EFC4C349-740A-4F18-8579-3AFA4F90BD9C}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{F0A05BDB-2921-4133-B81A-E01CA919EEB5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F105A71B-8A07-49CA-9D28-976AAAC2D9D0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F15E6081-6A00-40D1-B26E-970F6999F9BE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F22F0F87-A07E-47D9-A790-09A676B686D7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F2E7E768-5F71-43FC-90BA-B7E638943D84}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F30B339F-7948-4F33-B6A6-615D87F90757}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F379E883-67C7-49F2-8958-99E77B830FD4}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{F4D2FA0A-E675-45F8-9AAA-65B52E5DD75D}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{F51D35EC-0430-48BA-97FD-8C5405E7230B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F5680D70-617D-4596-B9F0-A4E80F76B684}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F6C3CFBB-D972-4C04-8EA5-A00CA2104230}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F6DCAA93-0641-49BB-80AE-351E5CCAFFCD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F799AF35-11EE-4ACE-856C-6412C25906CD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F7D2FBFD-A24F-470E-BE96-F2C9230CE9E8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FA5D62B1-995B-4EEC-A24F-8EAB6A02CEF7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FA9C3ACF-DBF3-47B7-9FA8-D379825912DF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FB4D3722-1136-4401-9F59-40253F30E122}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FB76A3B5-DF53-4650-8DCB-F7E41AE499A4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FC0F0C2C-2A76-4793-B857-50FB166CDCE4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FCB8644B-8C9C-4C5B-A859-0CB4892B64D1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FF69F595-C73D-430B-8EC7-94D1773FD0E7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FF9F0CFE-8E05-45F6-B729-0B7553F6A8E9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.6400
"{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM
"{04830D0F-F980-4EC0-89F1-594F2FD2A1B5}" = ElsterFormular 2008/2009
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{10F498FF-5392-4DF3-8F73-FE172A9F3800}" = Winbond CIR Device Drivers
"{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{13D85C14-2B85-419F-AC41-C7F21E68B25D}" = Acer eSettings Management
"{1401311D-3960-4CEB-AC0B-4214F069E5B9}" = Sonos Desktop Controller
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java(TM) 6 Update 15
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}" = Microsoft Works
"{57265292-228A-41FA-9AEC-4620CBCC2739}" = Acer eAudio Management
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
"{5B63A470-9334-44D1-AF61-6CE2DB565AE9}" = Orion
"{6395D480-9F3B-4930-8204-B91C8882F967}" = Stata 10
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74A929E2-FBD8-4736-A84E-2ABBB2ABADF2}" = AVM FRITZ!DSL
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7902E313-FF0F-4493-ACB1-A8147B78DCD0}" = HPSSupply
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111118433}" = Mystery Case Files - Huntsville
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111543617}" = Backspin Billiards
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112615863}" = Agatha Christie Death on the Nile
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
"{8F1B6239-FEA0-450A-A950-B05276CE177C}" = Acer Empowering Technology
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
"{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}" = Acer Crystal Eye Webcam 2.0.8
"{A82D052A-0806-42DF-80CD-1730A1AC0ED3}" = MrvlUsgTracking
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4
"{AC76BA86-7AD7-5670-0000-800000000003}" = Korean Fonts Support For Adobe Reader 8
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe  1.4.142.1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{ECCD28B2-8798-4D16-8126-625D728294A1}" = SPBA 5.8
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Acer Acer Bio Protection 6.0.00.17" = Acer Bio Protection
 
AAU 6.0.00.17
"Acer GameZone Console_is1" = Acer GameZone Console 2.0.1.1
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"AVMFBox" = AVM FRITZ!Box Dokumentation
"AVMFBoxPrinter" = AVM FRITZ!Box Druckeranschluss
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"CutePDF Writer Installation" = CutePDF Writer 2.7
"ElsterFormular 11.4.1.4323" = ElsterFormular
"ElsterFormular 11.5.0.4546" = ElsterFormular
"FLV Player" = FLV Player 2.0 (build 25)
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"GridVista" = Acer GridVista
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP LaserJet P1000 series" = HP LaserJet P1000 series
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"NVIDIA Drivers" = NVIDIA Drivers
"OpenVPN" = OpenVPN 2.0.9-gui-1.0.3
"PATmonitor PRO Trial" = PATmonitor PRO Trial
"RealVNC_is1" = VNC Free Edition 4.1.3
"Softonic_Deutsch Toolbar" = Softonic_Deutsch Toolbar
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TightVNC_is1" = TightVNC 1.3.10
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-4069621161-912532974-1855927034-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 9/29/2010 1:32:56 PM | Computer Name = Liegsalz | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 69563342
 
Error - 9/29/2010 1:33:06 PM | Computer Name = Liegsalz | Source = Google Update | ID = 20
Description =
 
Error - 9/29/2010 3:44:56 PM | Computer Name = Liegsalz | Source = Bonjour Service | ID = 100
Description = 392: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde
 vom Remotehost geschlossen.)
 
Error - 9/29/2010 3:59:26 PM | Computer Name = Liegsalz | Source = Application Hang | ID = 1002
Description = Programm iexplore.exe, Version 8.0.6001.18943 arbeitet nicht mehr
mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet
 "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen
über das Problem zu suchen.  Prozess-ID: 834  Anfangszeit: 01cb600ecdbd6060  Zeitpunkt
 der Beendigung: 0
 
Error - 9/29/2010 4:15:19 PM | Computer Name = Liegsalz | Source = SPP | ID = 16387
Description =
 
Error - 9/29/2010 4:15:19 PM | Computer Name = Liegsalz | Source = System Restore | ID = 8193
Description =
 
Error - 9/29/2010 4:15:32 PM | Computer Name = Liegsalz | Source = SPP | ID = 16387
Description =
 
Error - 9/29/2010 4:15:32 PM | Computer Name = Liegsalz | Source = System Restore | ID = 8193
Description =
 
Error - 9/29/2010 4:16:05 PM | Computer Name = Liegsalz | Source = SPP | ID = 16387
Description =
 
Error - 9/29/2010 4:16:05 PM | Computer Name = Liegsalz | Source = System Restore | ID = 8193
Description =
 
[ Media Center Events ]
Error - 5/12/2009 9:36:36 AM | Computer Name = Liegsalz | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed;
 Win32 GetLastError returned 0D  Prozess: DefaultDomain Objektname: Media Center Guide
 
 
Error - 5/15/2009 10:55:01 AM | Computer Name = Liegsalz | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide
 
 
[ OSession Events ]
Error - 5/12/2009 10:20:35 PM | Computer Name = Liegsalz | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.6214.1000, Microsoft Office Version: 12.0.6215.1000. This session lasted 535
 seconds with 120 seconds of active time.  This session ended with a crash.
 
Error - 5/13/2009 2:09:40 AM | Computer Name = Liegsalz | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6211.1000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 4407 seconds with 2220 seconds of active time.  This session ended with a
 crash.
 
Error - 9/6/2009 6:51:44 PM | Computer Name = Liegsalz | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3
 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error - 7/18/2010 1:07:43 PM | Computer Name = Liegsalz | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.6535.5002, Microsoft Office Version: 12.0.6425.1000. This session lasted 25
 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error - 8/23/2010 3:36:45 AM | Computer Name = Liegsalz | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.6535.5002, Microsoft Office Version: 12.0.6425.1000. This session lasted 166
 seconds with 60 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 10/16/2010 6:23:36 AM | Computer Name = Liegsalz | Source = Service Control Manager | ID = 7032
Description =
 
Error - 10/16/2010 6:27:46 AM | Computer Name = Liegsalz | Source = Service Control Manager | ID = 7031
Description =
 
Error - 10/16/2010 6:28:12 AM | Computer Name = Liegsalz | Source = Service Control Manager | ID = 7032
Description =
 
Error - 10/16/2010 6:29:12 AM | Computer Name = Liegsalz | Source = Service Control Manager | ID = 7032
Description =
 
Error - 10/16/2010 6:29:12 AM | Computer Name = Liegsalz | Source = Service Control Manager | ID = 7032
Description =
 
Error - 10/16/2010 6:29:12 AM | Computer Name = Liegsalz | Source = Service Control Manager | ID = 7032
Description =
 
Error - 10/16/2010 6:32:19 AM | Computer Name = Liegsalz | Source = Service Control Manager | ID = 7032
Description =
 
Error - 10/16/2010 6:56:23 AM | Computer Name = Liegsalz | Source = Service Control Manager | ID = 7011
Description =
 
Error - 10/16/2010 7:48:15 AM | Computer Name = Liegsalz | Source = Service Control Manager | ID = 7011
Description =
 
Error - 10/16/2010 8:27:23 AM | Computer Name = Liegsalz | Source = DCOM | ID = 10010
Description =
 
 
< End of report >


cosinus 18.10.2010 09:38

Zitat:

Ich habe bereits OTL laufen lassen und Malwarebytes installiert.
Wo sind die Logs von malwarebytes?

AskHans 18.10.2010 20:08

Hallo Arne,

vielen Dank für Deine Antwort.

Hier das Malwarebytes Log File:

Code:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4052

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943

10/17/2010 5:07:18 PM
mbam-log-2010-10-17 (17-07-18).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 128977
Laufzeit: 14 Minute(n), 9 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 6
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Not selected for removal.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{182102b0-376f-4dcc-b86c-4cc758b63865}\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{182102b0-376f-4dcc-b86c-4cc758b63865}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{463fb10b-4fc8-44cd-824a-096c81aa3247}\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{463fb10b-4fc8-44cd-824a-096c81aa3247}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9165c51f-fda4-4b4d-a800-802af1849a54}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


cosinus 18.10.2010 20:24

Zitat:

Datenbank Version: 4052
Art des Suchlaufs: Quick-Scan
Du hast Malwarebytes vorher nicht aktualisiert. Bitte updaten und einen Vollscan machen.

AskHans 21.10.2010 21:40

Hallo Arne,

Beitrag bitte noch nicht schließen. Hab bereits zweimal den Full Scan laufen lassen, konnte dann aber das Log File nicht speichern. Ich hoffe, dass es beim nächsten mal klappt..

Viele Grüße,
Johannes

cosinus 21.10.2010 22:14

Speichern??
Das macht Malwarebytes doch für Dich! Schau nach im Reiter Logdateien!

AskHans 22.10.2010 16:12

Hallo zusammenn,

anbei das Malwarebytes Full Scan Log File:

Malwarebytes' Anti-Malware 1.46
Malwarebytes

Datenbank Version: 4910

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

10/22/2010 5:07:03 PM
mbam-log-2010-10-22 (17-07-03).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|)
Durchsuchte Objekte: 323763
Laufzeit: 2 Stunde(n), 4 Minute(n), 35 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

---

Viele Grüße,
Johannes

cosinus 23.10.2010 18:40

Poste bitte alle Logs vom Fullscan.

AskHans 24.10.2010 13:44

Das ist leider das einzige Full Scan Log File das im Mawarebytes-Ordner-Logs zu finden ist. Die einzige ander Datei hierzu ist das oben gepostete Quick Scan Log File.

Wo müsste ich denn nachsehen um weitere Log Files zu finden?

cosinus 24.10.2010 14:16

Hast Du nicht mehrere Vollscan-Durchgänge gemacht oder nur einen? Pro Durchgang gibt es jedesmal ein Log! Schau nach im Riter Logdateien.

AskHans 24.10.2010 14:26

Ich hatte mehrer Scans durchgeführt - manche Log Files konnte ich wie oben beschrieben leider nicht abspeichern da Malwarebytes sich aufgehangen hatte (lag daran, dass man zum abspeichern wohl online sein muss). Alle Log-Files, die sich abgespeichert im Ordner befinden sind folgende - ich hoffe man kann damit noch was anfangen:

(1)
Malwarebytes' Anti-Malware 1.46
Malwarebytes

Datenbank Version: 4052

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943

10/17/2010 5:07:18 PM
mbam-log-2010-10-17 (17-07-18).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 128977
Laufzeit: 14 Minute(n), 9 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 6
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Not selected for removal.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{182102b0-376f-4dcc-b86c-4cc758b63865}\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{182102b0-376f-4dcc-b86c-4cc758b63865}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{463fb10b-4fc8-44cd-824a-096c81aa3247}\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{463fb10b-4fc8-44cd-824a-096c81aa3247}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9165c51f-fda4-4b4d-a800-802af1849a54}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

(2)
Malwarebytes' Anti-Malware 1.46
Malwarebytes

Datenbank Version: 4894

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

10/20/2010 7:25:06 PM
mbam-log-2010-10-20 (19-25-06).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 14979
Laufzeit: 2 Minute(n), 1 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

(3)
Malwarebytes' Anti-Malware 1.46
Malwarebytes

Datenbank Version: 4894

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

10/20/2010 7:28:51 PM
mbam-log-2010-10-20 (19-28-51).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 15208
Laufzeit: 3 Minute(n), 12 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

(4)
Malwarebytes' Anti-Malware 1.46
Malwarebytes

Datenbank Version: 4910

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

10/22/2010 5:07:03 PM
mbam-log-2010-10-22 (17-07-03).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|)
Durchsuchte Objekte: 323763
Laufzeit: 2 Stunde(n), 4 Minute(n), 35 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

cosinus 24.10.2010 14:32

Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.84,93.188.161.224
O32 - AutoRun File - [2008/05/06 14:26:23 | 000,000,309 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2009/05/16 08:55:20 | 000,000,000 | ---D | M] - G:\Autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{c9707c94-3c72-11de-82ec-00238b1ed1ba}\Shell - "" = AutoRun
O33 - MountPoints2\{c9707c94-3c72-11de-82ec-00238b1ed1ba}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- [2007/10/23 09:45:40 | 001,336,632 | R--- | M] ()
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- [2007/10/23 09:45:39 | 001,336,632 | R--- | M] ()
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

AskHans 24.10.2010 14:40

Ich hab mehrere Scans durchegführt, manche Log Files wurden jedoch nicht gespeichert, da Malwarebytes sich manchmal aufgehangen hatte. Follgende Dateien liegen noch im Reiter Logdateien (inkl. dem letzten Full Scan):

(1)
Malwarebytes' Anti-Malware 1.46
Malwarebytes

Datenbank Version: 4052

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943

10/17/2010 5:07:18 PM
mbam-log-2010-10-17 (17-07-18).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 128977
Laufzeit: 14 Minute(n), 9 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 6
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Not selected for removal.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{182102b0-376f-4dcc-b86c-4cc758b63865}\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{182102b0-376f-4dcc-b86c-4cc758b63865}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{463fb10b-4fc8-44cd-824a-096c81aa3247}\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{463fb10b-4fc8-44cd-824a-096c81aa3247}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9165c51f-fda4-4b4d-a800-802af1849a54}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

(2)
Malwarebytes' Anti-Malware 1.46
Malwarebytes

Datenbank Version: 4894

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

10/20/2010 7:25:06 PM
mbam-log-2010-10-20 (19-25-06).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 14979
Laufzeit: 2 Minute(n), 1 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

(3)
Malwarebytes' Anti-Malware 1.46
Malwarebytes

Datenbank Version: 4894

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

10/20/2010 7:28:51 PM
mbam-log-2010-10-20 (19-28-51).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 15208
Laufzeit: 3 Minute(n), 12 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

(4)
Malwarebytes' Anti-Malware 1.46
Malwarebytes

Datenbank Version: 4910

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

10/22/2010 5:07:03 PM
mbam-log-2010-10-22 (17-07-03).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|)
Durchsuchte Objekte: 323763
Laufzeit: 2 Stunde(n), 4 Minute(n), 35 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.84,93.188.161.224 -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

cosinus 24.10.2010 14:49

Ja die Logs hab ich jetzt ja. Du solltest den o.g. OTL-Fix erstmal machen.

AskHans 24.10.2010 14:55

Muss ich dafür einen individuellen Code in die Codebox bei OTL kopieren?

cosinus 24.10.2010 14:59

Den hab ich doch genannt!

AskHans 24.10.2010 14:59

Muss ich dafür einen individuellen Code in die Codebox von OTL eingeben?

AskHans 24.10.2010 18:03

Hier das OTL Fix Log File:

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\NameServer| /E : value set successfully!
File E:\autorun.inf not found.
File not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c9707c94-3c72-11de-82ec-00238b1ed1ba}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c9707c94-3c72-11de-82ec-00238b1ed1ba}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c9707c94-3c72-11de-82ec-00238b1ed1ba}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c9707c94-3c72-11de-82ec-00238b1ed1ba}\ not found.
File G:\LaunchU3.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found.
File E:\LaunchU3.exe not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Johannes
->Temp folder emptied: 223914561 bytes
->Temporary Internet Files folder emptied: 221228147 bytes
->Java cache emptied: 67796859 bytes
->FireFox cache emptied: 91786874 bytes
->Google Chrome cache emptied: 10251805 bytes
->Flash cache emptied: 68964 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 50430543 bytes
RecycleBin emptied: 6613259999 bytes

Total Files Cleaned = 6,942.00 mb


OTL by OldTimer - Version 3.2.15.2 log created on 10242010_184415

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

cosinus 24.10.2010 19:48

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

AskHans 25.10.2010 23:08

Habe CombiFix ausgeführt. Der Laptop hat zwischenzeitlich neu gestartet wegen "Rootaktivitäten" und hat sich danach einmal aufgehangen. Danach lief CombiFix ohne Probleme durch. Beim Neustart hat Antivir (das ich davor eigentlich abgestellt hatte) einen Trojaner gefunden "RootKit.Gen3". Zu guter letzt hab ich die CC Cleaner Systembereinigung durchgführt. Hier das Log File zum CombiFix, zum CC Cleaner gibt es wohl keins:
Combofix Logfile:
Code:

ComboFix 10-10-24.06 - Johannes 10/25/2010  23:14:48.1.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3066.1825 [GMT 2:00]
ausgeführt von:: c:\users\Johannes\Desktop\cofi.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\userinit.exe . . . ist infiziert!!

.
(((((((((((((((((((((((  Dateien erstellt von 2010-09-25 bis 2010-10-25  ))))))))))))))))))))))))))))))
.

2010-10-25 21:28 . 2010-10-25 21:28        --------        d-----w-        c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-10-25 21:28 . 2010-10-25 21:28        --------        d-----w-        c:\users\Default\AppData\Local\temp
2010-10-24 16:44 . 2010-10-24 16:44        --------        d-----w-        C:\_OTL
2010-10-22 08:05 . 2010-10-07 23:21        6146896        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{B309F0EB-AC7E-41C7-BB3D-B5ACA66EDEEB}\mpengine.dll
2010-10-21 20:22 . 2010-10-21 20:22        --------        d-----w-        c:\windows\system32\config\systemprofile\AppData\Local\Mozilla
2010-10-21 19:22 . 2010-10-21 19:22        --------        d-----w-        c:\windows\system32\config\systemprofile\AppData\Roaming\Malwarebytes
2010-10-17 15:32 . 2010-09-13 13:56        168960        ----a-w-        c:\program files\Windows Media Player\wmplayer.exe
2010-10-17 15:32 . 2010-09-13 13:56        8147456        ----a-w-        c:\windows\system32\wmploc.DLL
2010-10-17 15:30 . 2010-05-04 19:13        231424        ----a-w-        c:\windows\system32\msshsq.dll
2010-10-17 15:30 . 2010-08-20 16:05        867328        ----a-w-        c:\windows\system32\wmpmde.dll
2010-10-17 15:30 . 2010-08-31 15:44        531968        ----a-w-        c:\windows\system32\comctl32.dll
2010-10-16 12:39 . 2010-10-16 12:39        --------        d-----w-        c:\users\Johannes\AppData\Roaming\Malwarebytes
2010-10-16 12:02 . 2010-04-29 13:39        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-16 12:02 . 2010-10-16 12:02        --------        d-----w-        c:\programdata\Malwarebytes
2010-10-16 12:02 . 2010-10-22 15:06        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2010-10-16 12:02 . 2010-04-29 13:39        20952        ----a-w-        c:\windows\system32\drivers\mbam.sys
2010-10-16 11:21 . 2010-10-16 11:21        --------        d-----w-        c:\users\Johannes\AppData\Local\Mozilla
2010-10-16 10:23 . 2010-10-16 10:23        --------        d-----w-        c:\windows\system32\config\systemprofile\AppData\Roaming\Apple Computer
2010-10-16 10:23 . 2010-10-16 10:23        --------        d-sh--w-        c:\windows\system32\%APPDATA%
2010-10-16 10:23 . 2010-10-16 10:23        --------        d-----w-        c:\windows\system32\config\systemprofile\AppData\Local\PowerCinema
2010-09-29 17:39 . 2010-06-22 13:30        2048        ----a-w-        c:\windows\system32\tzres.dll
2010-09-29 17:39 . 2010-08-26 04:23        13312        ----a-w-        c:\program files\Internet Explorer\iecompat.dll
2010-09-26 08:07 . 2010-09-26 08:07        --------        d-----w-        c:\program files\iPod
2010-09-26 08:06 . 2010-09-26 08:08        --------        d-----w-        c:\program files\iTunes
2010-09-26 08:00 . 2010-09-26 08:00        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2010-09-26 08:00 . 2010-09-26 08:00        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2010-09-26 08:00 . 2010-09-26 08:00        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2010-09-26 08:00 . 2010-09-26 08:00        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2010-09-26 08:00 . 2010-09-26 08:00        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2010-09-26 08:00 . 2010-09-26 08:00        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2010-09-26 08:00 . 2010-09-26 08:00        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2010-09-26 07:59 . 2010-09-26 08:00        --------        d-----w-        c:\program files\QuickTime

.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 09:41 . 2009-10-04 16:59        222080        ------w-        c:\windows\system32\MpSigStub.exe
2010-09-08 09:17 . 2010-09-08 09:17        94208        ----a-w-        c:\windows\system32\QuickTimeVR.qtx
2010-09-08 09:17 . 2010-09-08 09:17        69632        ----a-w-        c:\windows\system32\QuickTime.qts
2010-08-17 14:11 . 2010-09-14 19:59        128000        ----a-w-        c:\windows\system32\spoolsv.exe
.

((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}"= "c:\program files\Softonic_Deutsch\tbSoft.dll" [2008-09-15 1784856]

[HKEY_CLASSES_ROOT\clsid\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}]
2008-09-15 04:47        1784856        ----a-w-        c:\program files\Softonic_Deutsch\tbSoft.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}"= "c:\program files\Softonic_Deutsch\tbSoft.dll" [2008-09-15 1784856]

[HKEY_CLASSES_ROOT\clsid\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}"= "c:\program files\Softonic_Deutsch\tbSoft.dll" [2008-09-15 1784856]

[HKEY_CLASSES_ROOT\clsid\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19        94208        ----a-w-        c:\users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19        94208        ----a-w-        c:\users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19        94208        ----a-w-        c:\users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-05-14 15:05        121392        ----a-w-        c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-07 68856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-07 6139904]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1049896]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-05-14 526896]
"eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-05-30 544768]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-18 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-18 92704]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-06-04 817672]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2008-10-27 3676160]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-07-24 147456]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-07-24 167936]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-07-18 167936]
"WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-09-14 30192]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"openvpn-gui"="c:\program files\OpenVPN\bin\openvpn-gui.exe" [2005-08-18 99328]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-06 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]

c:\users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Johannes\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
FRITZ!DSL Protect.lnk - c:\program files\FRITZ!DSL\FwebProt.exe [2009-4-9 1061688]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2008-10-28 1216512]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-23 727592]
FRITZ!DSL Startcenter.lnk - c:\windows\Installer\{74A929E2-FBD8-4736-A84E-2ABBB2ABADF2}\Icon2457326B4.exe [2010-4-29 29184]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2010-4-5 494920]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2008-10-27 21:44        3197952        ----a-w-        c:\program files\Acer\Acer Bio Protection\WinNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\spba]
2008-03-25 14:24        567560        ----a-w-        c:\program files\Common Files\SPBA\homefus2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4069621161-912532974-1855927034-1000]
"EnableNotificationsRef"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 135664]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-09-14 30192]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\Drivers\AlfaFF.sys [2008-10-27 42608]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-07-18 61424]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
S2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-06-02 24576]
S2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [2008-10-27 3602432]
S2 IGDCTRL;AVM IGD CTRL Service;c:\program files\FRITZ!DSL\IGDCTRL.EXE [2009-07-28 73528]
S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
S2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2008-01-10 233472]
S3 NETw5v32;Intel(R) Wireless WiFi Link Adaptertreiber für Windows Vista 32-Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2010-01-13 6628352]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-06-25 44064]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
S3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [2007-03-28 43008]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs        REG_MULTI_SZ          BthServ
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners

2010-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 18:49]

2010-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 18:49]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.gmx.de/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
uInternet Settings,ProxyOverride = *.local
IE: An vorhandene PDF-Datei anfügen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\program files\FRITZ!DSL\\sarah.dll
FF - ProfilePath - c:\users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\j9g7c9nr.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX Richtlinien ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true);  // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true);  // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -

HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
HKU-Default-Run-FRITZ!protect - FwebProt.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2010-10-25 23:31
Windows 6.0.6002 Service Pack 2 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostarteinträge...

Scanne versteckte Dateien...


c:\windows\TEMP\TMP00000004B42A08A191B4A8EF 524288 bytes executable

Scan erfolgreich abgeschlossen
versteckte Dateien: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------

- - - - - - - > 'Explorer.exe'(6028)
c:\users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\system32\btmmhook.dll
c:\windows\System32\SysHook.dll
c:\windows\system32\btncopy.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\SPBA\upeksvr.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Acer\Acer Bio Protection\CompPtcVUI.exe
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\windows\system32\spool\DRIVERS\W32X86\3\HP1006MC.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Cyberlink\Shared files\RichVideo.exe
c:\program files\RealVNC\VNC4\WinVNC4.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\System32\rundll32.exe
c:\program files\Launch Manager\QtZgAcer.EXE
c:\windows\ehome\ehmsas.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Acer\Acer VCM\acp2HID.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2010-10-25  23:41:29 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2010-10-25 21:41

Vor Suchlauf: 14 Verzeichnis(se), 91,416,784,896 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 91,075,751,936 Bytes frei

- - End Of File - - 3D69ACBC29770DBF4E7FCE450E45C69A

--- --- ---

cosinus 27.10.2010 08:46

Bitte diese Datei laden => File-Upload.net - userinit.exe
Und direkt auf C: ohne Unterordner speichern also als c:\userinit.exe. Sie ist aus meiner WinXP-SP3-Installation und sauber. Die benötigt Dein Rechner ;)

Dann gehts so weiter:

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:

FCopy::
c:\userinit.exe | c:\windows\system32\userinit.exe

Filelook::
c:\windows\system32\dllcache\userinit.exe

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

AskHans 29.10.2010 09:26

Hier die Log Datei zum Combofix Script:
Combofix Logfile:
Code:

ComboFix 10-10-27.A3 - Johannes 10/29/2010  9:53.2.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3066.1861 [GMT 2:00]
ausgeführt von:: c:\users\Johannes\Desktop\cofi.exe
Benutzte Befehlsschalter :: c:\users\Johannes\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((  Dateien erstellt von 2010-09-28 bis 2010-10-29  ))))))))))))))))))))))))))))))
.

2010-10-29 08:05 . 2010-10-29 08:05        --------        d-----w-        c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-10-29 08:05 . 2010-10-29 08:05        --------        d-----w-        c:\users\Default\AppData\Local\temp
2010-10-26 20:54 . 2010-10-07 23:21        6146896        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{2789C837-4A00-4649-A7B1-30DE2252A82F}\mpengine.dll
2010-10-26 20:54 . 2010-08-26 16:34        1696256        ----a-w-        c:\windows\system32\gameux.dll
2010-10-26 20:54 . 2010-08-26 16:33        28672        ----a-w-        c:\windows\system32\Apphlpdm.dll
2010-10-26 20:54 . 2010-08-26 14:23        4240384        ----a-w-        c:\windows\system32\GameUXLegacyGDFs.dll
2010-10-25 21:57 . 2010-10-25 21:57        --------        d-----w-        c:\program files\CCleaner
2010-10-24 16:44 . 2010-10-24 16:44        --------        d-----w-        C:\_OTL
2010-10-21 20:22 . 2010-10-21 20:22        --------        d-----w-        c:\windows\system32\config\systemprofile\AppData\Local\Mozilla
2010-10-21 19:22 . 2010-10-21 19:22        --------        d-----w-        c:\windows\system32\config\systemprofile\AppData\Roaming\Malwarebytes
2010-10-17 15:32 . 2010-09-13 13:56        168960        ----a-w-        c:\program files\Windows Media Player\wmplayer.exe
2010-10-17 15:32 . 2010-09-13 13:56        8147456        ----a-w-        c:\windows\system32\wmploc.DLL
2010-10-17 15:30 . 2010-05-04 19:13        231424        ----a-w-        c:\windows\system32\msshsq.dll
2010-10-17 15:30 . 2010-08-20 16:05        867328        ----a-w-        c:\windows\system32\wmpmde.dll
2010-10-17 15:30 . 2010-08-31 15:44        531968        ----a-w-        c:\windows\system32\comctl32.dll
2010-10-16 12:39 . 2010-10-16 12:39        --------        d-----w-        c:\users\Johannes\AppData\Roaming\Malwarebytes
2010-10-16 12:02 . 2010-04-29 13:39        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-16 12:02 . 2010-10-16 12:02        --------        d-----w-        c:\programdata\Malwarebytes
2010-10-16 12:02 . 2010-10-22 15:06        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2010-10-16 12:02 . 2010-04-29 13:39        20952        ----a-w-        c:\windows\system32\drivers\mbam.sys
2010-10-16 11:21 . 2010-10-16 11:21        --------        d-----w-        c:\users\Johannes\AppData\Local\Mozilla
2010-10-16 10:23 . 2010-10-16 10:23        --------        d-----w-        c:\windows\system32\config\systemprofile\AppData\Roaming\Apple Computer
2010-10-16 10:23 . 2010-10-16 10:23        --------        d-sh--w-        c:\windows\system32\%APPDATA%
2010-10-16 10:23 . 2010-10-16 10:23        --------        d-----w-        c:\windows\system32\config\systemprofile\AppData\Local\PowerCinema
2010-09-29 17:39 . 2010-06-22 13:30        2048        ----a-w-        c:\windows\system32\tzres.dll
2010-09-29 17:39 . 2010-08-26 04:23        13312        ----a-w-        c:\program files\Internet Explorer\iecompat.dll

.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 09:41 . 2009-10-04 16:59        222080        ------w-        c:\windows\system32\MpSigStub.exe
2010-09-08 09:17 . 2010-09-08 09:17        94208        ----a-w-        c:\windows\system32\QuickTimeVR.qtx
2010-09-08 09:17 . 2010-09-08 09:17        69632        ----a-w-        c:\windows\system32\QuickTime.qts
2010-08-26 16:33 . 2010-10-26 20:54        173056        ----a-w-        c:\windows\apppatch\AcXtrnal.dll
2010-08-26 16:33 . 2010-10-26 20:54        542720        ----a-w-        c:\windows\apppatch\AcLayers.dll
2010-08-26 16:33 . 2010-10-26 20:54        458752        ----a-w-        c:\windows\apppatch\AcSpecfc.dll
2010-08-26 16:33 . 2010-10-26 20:54        2159616        ----a-w-        c:\windows\apppatch\AcGenral.dll
2010-08-17 14:11 . 2010-09-14 19:59        128000        ----a-w-        c:\windows\system32\spoolsv.exe
.

((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}"= "c:\program files\Softonic_Deutsch\tbSoft.dll" [2008-09-15 1784856]

[HKEY_CLASSES_ROOT\clsid\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}]
2008-09-15 04:47        1784856        ----a-w-        c:\program files\Softonic_Deutsch\tbSoft.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}"= "c:\program files\Softonic_Deutsch\tbSoft.dll" [2008-09-15 1784856]

[HKEY_CLASSES_ROOT\clsid\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}"= "c:\program files\Softonic_Deutsch\tbSoft.dll" [2008-09-15 1784856]

[HKEY_CLASSES_ROOT\clsid\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19        94208        ----a-w-        c:\users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19        94208        ----a-w-        c:\users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19        94208        ----a-w-        c:\users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-05-14 15:05        121392        ----a-w-        c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-07 68856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-07 6139904]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1049896]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-05-14 526896]
"eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-05-30 544768]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-18 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-18 92704]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-06-04 817672]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2008-10-27 3676160]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-07-24 147456]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-07-24 167936]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-07-18 167936]
"WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-09-14 30192]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"openvpn-gui"="c:\program files\OpenVPN\bin\openvpn-gui.exe" [2005-08-18 99328]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-06 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]

c:\users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Johannes\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
FRITZ!DSL Protect.lnk - c:\program files\FRITZ!DSL\FwebProt.exe [2009-4-9 1061688]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2008-10-28 1216512]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-23 727592]
FRITZ!DSL Startcenter.lnk - c:\windows\Installer\{74A929E2-FBD8-4736-A84E-2ABBB2ABADF2}\Icon2457326B4.exe [2010-4-29 29184]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2010-4-5 494920]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2008-10-27 21:44        3197952        ----a-w-        c:\program files\Acer\Acer Bio Protection\WinNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\spba]
2008-03-25 14:24        567560        ----a-w-        c:\program files\Common Files\SPBA\homefus2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4069621161-912532974-1855927034-1000]
"EnableNotificationsRef"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 135664]
R2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [2008-10-27 3602432]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-09-14 30192]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\Drivers\AlfaFF.sys [2008-10-27 42608]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-07-18 61424]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
S2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-06-02 24576]
S2 IGDCTRL;AVM IGD CTRL Service;c:\program files\FRITZ!DSL\IGDCTRL.EXE [2009-07-28 73528]
S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
S2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2008-01-10 233472]
S3 NETw5v32;Intel(R) Wireless WiFi Link Adaptertreiber für Windows Vista 32-Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2010-01-13 6628352]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-06-25 44064]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
S3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [2007-03-28 43008]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs        REG_MULTI_SZ          BthServ
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners

2010-10-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 18:49]

2010-10-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 18:49]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.gmx.de/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g
uInternet Settings,ProxyOverride = *.local
IE: An vorhandene PDF-Datei anfügen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\j9g7c9nr.default\
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX Richtlinien ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true);  // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true);  // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2010-10-29 10:05
Windows 6.0.6002 Service Pack 2 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostarteinträge...

Scanne versteckte Dateien...

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------

- - - - - - - > 'Explorer.exe'(3472)
c:\users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\system32\btmmhook.dll
c:\windows\System32\SysHook.dll
.
Zeit der Fertigstellung: 2010-10-29  10:10:40
ComboFix-quarantined-files.txt  2010-10-29 08:10
ComboFix2.txt  2010-10-25 21:41

Vor Suchlauf: 19 Verzeichnis(se), 93,544,345,600 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 93,525,942,272 Bytes frei

- - End Of File - - 86EF34F41F3EF416CB596243A6193CE2

--- --- ---

cosinus 29.10.2010 12:47

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus

Downloade Dir anschließend bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur eine Sekunde.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

AskHans 30.10.2010 18:56

GMER ist leider immer wieder abgestürzt (immer bei der Datei: \Device\Harddisk\ShadowCopy1). OSAM lief hingegen innerhalb einer Minute ohne Probleme durch und auch MBRCheck ging ohne Probleme.

Hier das OSAM Log File:
OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
Online Solutions. Complex Protection for Information Systems
Saved at 19:48:37 on 30.10.2010

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 3.6.12

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[AppInit DLLs]
-----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )-----
"AppInit_DLLs" - "Google" - C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
"AppInit_DLLs" - "Google" - C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AlfaFF File System mini-filter" (AlfaFF) - "Alfa Corporation" - C:\Windows\System32\Drivers\AlfaFF.sys
"Apple Mobile USB Driver" (USBAAPL) - "Apple, Inc." - C:\Windows\System32\Drivers\usbaapl.sys
"avgio" (avgio) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\Users\Johannes\AppData\Local\Temp\catchme.sys  (File not found)
"int15" (int15) - ? - C:\Windows\system32\drivers\int15.sys  (File found, but it contains no detailed information)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"NTIPPKernel" (NTIPPKernel) - "Cyberlink Corp." - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys
"PSDFilter" (PSDFilter) - "Egis Incorporated" - C:\Windows\System32\DRIVERS\psdfilter.sys
"PSDNServ" (PSDNServ) - "Egis Incorporated" - C:\Windows\System32\DRIVERS\PSDNServ.sys
"PSDVdisk" (psdvdisk) - "Egis Incorporated" - C:\Windows\System32\DRIVERS\PSDVdisk.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"TAP-Win32 Adapter V8" (tap0801) - "The OpenVPN Project" - C:\Windows\System32\DRIVERS\tap0801.sys
"UBHelper" (UBHelper) - "NewTech Infosystems Corporation" - C:\Windows\system32\drivers\UBHelper.sys
"Upper Class Filter Driver" (NTIDrvr) - "NewTech Infosystems, Inc." - C:\Windows\System32\DRIVERS\NTIDrvr.sys
"{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}" ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) - "Cyberlink Corp." - C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} "DragDropProtect Class" - "Egis Inc." - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
{2b45bd21-71f8-4c8c-a87a-7eeb25a1a3e0} "EPM-PO Shell Extensions" - ? - epm-po.dll  (File not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{8F9D8FBE-C5C1-4B65-986E-51235C9283E8} "FPLaunchCache" - "Arachnoid Biometrics Identification Group Corp." - C:\Program Files\Acer\Acer Bio Protection\FPLaunchCache.dll
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -  (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -  (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{E0D79304-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll
{E0D79305-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll
{E0D79306-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll
{E0D79307-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
<binary data> "Softonic Deutsch Toolbar" - "Conduit Ltd." - C:\Program Files\Softonic_Deutsch\tbSoft.dll
<binary data> "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" - ? -  (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )-----
{8dbb6d8e-e4a6-4e3b-9753-af78b226441c} "Softonic Deutsch Toolbar" - "Conduit Ltd." - C:\Program Files\Softonic_Deutsch\tbSoft.dll
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_15" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} "Java Plug-in 1.6.0_15" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_15" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_15.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? -  (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
"Quick-Launching Area" - ? - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype add-on for Internet Explorer" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "Acer eDataSecurity Management" - "Egis Incorporated." - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
{8dbb6d8e-e4a6-4e3b-9753-af78b226441c} "Softonic Deutsch Toolbar" - "Conduit Ltd." - C:\Program Files\Softonic_Deutsch\tbSoft.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} "ShowBarObj Class" - "Egis" - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype add-on for Internet Explorer" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{8dbb6d8e-e4a6-4e3b-9753-af78b226441c} "Softonic Deutsch Toolbar" - "Conduit Ltd." - C:\Program Files\Softonic_Deutsch\tbSoft.dll
{02478D38-C3F9-4efb-9B51-7695ECA05670} "{02478D38-C3F9-4efb-9B51-7695ECA05670}" - ? -  (File not found | COM-object registry key not found)

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"FRITZ!DSL Protect.lnk" - "AVM Berlin" - C:\Program Files\FRITZ!DSL\FwebProt.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"Acer VCM.lnk" - "Acer Incorporated" - C:\Program Files\Acer\Acer VCM\AcerVCM.exe  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"FRITZ!DSL Startcenter.lnk" - "AVM Berlin" - C:\Program Files\FRITZ!DSL\StCenter.exe  (Shortcut exists | File exists)
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
"WinZip Quick Pick.lnk" - "WinZip Computing, S.L." - C:\Program Files\WinZip\WZQKPICK.EXE  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"swg" - "Google Inc." - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"ArcadeDeluxeAgent" - "CyberLink Corp." - "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"BkupTray" - ? - "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
"CLMLServer" - "CyberLink" - "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
"eAudio" - "Acer Incorporated" - "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
"eDataSecurity Loader" - "Egis Incorporated" - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
"ePower_DMC" - "Acer Inc." - C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
"Google Desktop Search" - "Google" - "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"IAAnotif" - "Intel Corporation" - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"LManager" - "Dritek System Inc." - C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
"openvpn-gui" - ? - C:\Program Files\OpenVPN\bin\openvpn-gui.exe  (File found, but it contains no detailed information)
"PlayMovie" - "Acer Corp." - "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
"PLFSetI" - ? - C:\Windows\PLFSetI.exe
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Java\jre6\bin\jusched.exe"
"WarReg_PopUp" - "Acer Incorporated" - C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
"ZPdtWzdVitaKey MC3000" - "Arachnoid Biometrics Identification Group Corp." - "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"avm:" - "AVM Berlin GmbH" - C:\Windows\system32\avmprmon.dll
"CutePDF Writer Monitor" - ? - C:\Windows\system32\cpwmon2k.dll  (File found, but it contains no detailed information)
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"AVM IGD CTRL Service" (IGDCTRL) - "AVM Berlin" - C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
"Bonjour Service" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"CLHNService" (CLHNService) - ? - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
"eDataSecurity Service" (eDataSecurity Service) - "Egis Incorporated" - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
"Empowering Technology Service" (ETService) - ? - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
"Google Desktop Manager 5.9.1005.12335" (GoogleDesktopManager-051210-111108) - "Google" - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"iGroupTec Service" (IGBASVC) - ? - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe  (File found, but it contains no detailed information)
"Intel(R) Matrix Storage Event Monitor" (IAANTMON) - "Intel Corporation" - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
"iPod Service" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"MobilityService" (MobilityService) - ? - C:\Acer\Mobility Center\MobilityService.exe
"NTI Backup Now 5 Agent Service" (BUNAgentSvc) - "NewTech Infosystems, Inc." - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
"NTI Backup Now 5 Backup Service" (NTIBackupSvc) - "NewTech InfoSystems, Inc." - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
"NTI Backup Now 5 Scheduler Service" (NTISchedulerSvc) - ? - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe  (File found, but it contains no detailed information)
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"OpenVPN Service" (OpenVPNService) - ? - C:\Program Files\OpenVPN\bin\openvpnserv.exe  (File found, but it contains no detailed information)
"Raw Socket Service" (RS_Service) - "Acer Incorporated" - C:\Program Files\Acer\Acer VCM\RS_Service.exe
"VNC Server Version 4" (WinVNC4) - "RealVNC Ltd." - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

[Winlogon]
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
"AWinNotifyVitaKey MC3000" - "Arachnoid Biometrics Identification Group Corp." - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
"spba" - "UPEK Inc." - C:\Program Files\Common Files\SPBA\homefus2.dll

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"Sarah NSP" - "AVM Berlin" - C:\Program Files\FRITZ!DSL\sarah.dll
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"SARAH LSP" - "AVM Berlin" - C:\Program Files\FRITZ!DSL\sarah.dll

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---
If You have questions or want to get some help, You can visit Online Solutions :: Index


Das MBRCheck Log File:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: Acer
BIOS Manufacturer: Acer
System Manufacturer: Acer
System Product Name: Aspire 6930G
Logical Drives Mask: 0x0000002c

Kernel Drivers (total 163):
0x8201F000 \SystemRoot\system32\ntkrnlpa.exe
0x823D8000 \SystemRoot\system32\hal.dll
0x8040A000 \SystemRoot\system32\kdcom.dll
0x80411000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x80481000 \SystemRoot\system32\PSHED.dll
0x80492000 \SystemRoot\system32\BOOTVID.dll
0x8049A000 \SystemRoot\system32\CLFS.SYS
0x804DB000 \SystemRoot\system32\CI.dll
0x8060D000 \SystemRoot\system32\drivers\Wdf01000.sys
0x80689000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80696000 \SystemRoot\system32\drivers\acpi.sys
0x806DC000 \SystemRoot\system32\drivers\WMILIB.SYS
0x806E5000 \SystemRoot\system32\drivers\msisadrv.sys
0x806ED000 \SystemRoot\system32\drivers\pci.sys
0x80714000 \SystemRoot\System32\drivers\partmgr.sys
0x80723000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x80726000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x80730000 \SystemRoot\system32\drivers\volmgr.sys
0x8073F000 \SystemRoot\System32\drivers\volmgrx.sys
0x80789000 \SystemRoot\System32\drivers\mountmgr.sys
0x80799000 \SystemRoot\System32\Drivers\UBHelper.sys
0x82609000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x826E2000 \SystemRoot\system32\drivers\atapi.sys
0x826EA000 \SystemRoot\system32\drivers\ataport.SYS
0x82708000 \SystemRoot\system32\drivers\fltmgr.sys
0x8273A000 \SystemRoot\system32\drivers\fileinfo.sys
0x8274A000 \SystemRoot\system32\DRIVERS\psdfilter.sys
0x82753000 \SystemRoot\system32\Drivers\AlfaFF.sys
0x8275C000 \SystemRoot\system32\Drivers\ksecdd.sys
0x8A00A000 \SystemRoot\system32\drivers\ndis.sys
0x8A115000 \SystemRoot\system32\drivers\msrpc.sys
0x8A140000 \SystemRoot\system32\drivers\NETIO.SYS
0x8A20A000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8A31A000 \SystemRoot\system32\drivers\volsnap.sys
0x8A353000 \SystemRoot\System32\Drivers\spldr.sys
0x8A35B000 \SystemRoot\System32\Drivers\mup.sys
0x8A36A000 \SystemRoot\System32\drivers\ecache.sys
0x8A391000 \SystemRoot\system32\drivers\disk.sys
0x8A3A2000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8A3C3000 \SystemRoot\system32\drivers\crcdisk.sys
0x8DADE000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8DAE9000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8DAF2000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8DAF6000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8DE0E000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8E541000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8E5E2000 \SystemRoot\System32\drivers\watchdog.sys
0x8E5EE000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8DAFF000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8DB3D000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8DB4C000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8E604000 \SystemRoot\system32\DRIVERS\NETw5v32.sys
0x8EC60000 \SystemRoot\system32\DRIVERS\L1E60x86.sys
0x8EC70000 \SystemRoot\system32\DRIVERS\winbondcir.sys
0x8EC85000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8EC98000 \SystemRoot\system32\DRIVERS\DKbFltr.sys
0x8ECA2000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8ECAD000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8ECDD000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8ECDF000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8ECEA000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8ED02000 \SystemRoot\system32\DRIVERS\NTIDrvr.sys
0x8ED0A000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8ED10000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8ED1F000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8ED4E000 \SystemRoot\system32\DRIVERS\storport.sys
0x8ED8F000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8ED9A000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8EDB1000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8EDBC000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8EDDF000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8DBD9000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8A3D9000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8EDEE000 \SystemRoot\system32\DRIVERS\tap0801.sys
0x8DBED000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8EDF9000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8A17B000 \SystemRoot\system32\DRIVERS\ks.sys
0x8DE00000 \SystemRoot\system32\DRIVERS\circlass.sys
0x8A3EE000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8A1A5000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8A1B2000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8A1E7000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8EE04000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8F00C000 \SystemRoot\system32\drivers\portcls.sys
0x8F039000 \SystemRoot\system32\drivers\drmk.sys
0x8F05E000 \SystemRoot\system32\DRIVERS\HSXHWAZL.sys
0x8F09B000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys
0x8F207000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0x8F2BC000 \SystemRoot\system32\drivers\modem.sys
0x8F2C9000 \SystemRoot\system32\drivers\nvhda32v.sys
0x8F2D7000 \SystemRoot\system32\DRIVERS\hidir.sys
0x8F2E2000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8F2F2000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8F2F9000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x8F302000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8F30A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8F313000 \SystemRoot\System32\Drivers\Null.SYS
0x8F31A000 \SystemRoot\System32\Drivers\Beep.SYS
0x8F321000 \SystemRoot\System32\drivers\vga.sys
0x8F32D000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8F34E000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8F356000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8F35E000 \SystemRoot\system32\drivers\RTSTOR.SYS
0x8F371000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8F37C000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8F38A000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8FE08000 \SystemRoot\System32\drivers\tcpip.sys
0x8FEF2000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8FF0D000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8FF23000 \SystemRoot\system32\DRIVERS\smb.sys
0x8FF37000 \SystemRoot\system32\drivers\afd.sys
0x8FF7F000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8FFB1000 \SystemRoot\system32\drivers\ws2ifsl.sys
0x8FFBA000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8FFD0000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8FFDE000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8FFF1000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x8F393000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8F3CF000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8F3D9000 \SystemRoot\System32\Drivers\dfsc.sys
0x8F19D000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x8FFF7000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0x8F1B9000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8F1D0000 \SystemRoot\System32\Drivers\usbvideo.sys
0x8F3F0000 \SystemRoot\System32\Drivers\tcusb.sys
0x8F1F1000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8DA00000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x95CB0000 \SystemRoot\System32\win32k.sys
0x8A200000 \SystemRoot\System32\drivers\Dxapi.sys
0x827CD000 \SystemRoot\system32\DRIVERS\monitor.sys
0x95ED0000 \SystemRoot\System32\TSDDD.dll
0x827DC000 \SystemRoot\system32\drivers\luafv.sys
0x807A1000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x95EF0000 \SystemRoot\System32\cdd.dll
0x9CA08000 \SystemRoot\system32\drivers\spsys.sys
0x9CAB8000 \SystemRoot\system32\DRIVERS\ipfltdrv.sys
0x9CACA000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9CADA000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9CB04000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9CB0E000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9CB21000 \SystemRoot\system32\drivers\HTTP.sys
0x9CB8E000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9CBAB000 \SystemRoot\system32\DRIVERS\bowser.sys
0x9CBC4000 \SystemRoot\System32\drivers\mpsdrv.sys
0x9CBD9000 \SystemRoot\system32\drivers\mrxdav.sys
0x807B5000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x805BB000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x807D4000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9E402000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9E42A000 \SystemRoot\System32\DRIVERS\srv.sys
0x9E478000 \??\C:\Windows\system32\drivers\int15.sys
0x9E489000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0x9E48D000 \??\C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys
0x9E4AB000 \SystemRoot\system32\drivers\peauth.sys
0x9E589000 \SystemRoot\system32\DRIVERS\PSDNServ.sys
0x9E592000 \SystemRoot\system32\DRIVERS\PSDVdisk.sys
0x9E5A4000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9E5AE000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9E5BA000 \SystemRoot\system32\DRIVERS\xaudio.sys
0x9E5C2000 \??\C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl
0x9E5E3000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x8A3CC000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0x774E0000 \Windows\System32\ntdll.dll

Processes (total 102):
0 System Idle Process
4 System
484 C:\Windows\System32\smss.exe
608 csrss.exe
660 C:\Windows\System32\wininit.exe
672 csrss.exe
704 C:\Windows\System32\services.exe
716 C:\Windows\System32\lsass.exe
724 C:\Windows\System32\lsm.exe
888 C:\Windows\System32\svchost.exe
956 C:\Windows\System32\nvvsvc.exe
984 C:\Windows\System32\svchost.exe
1020 C:\Windows\System32\svchost.exe
1080 C:\Windows\System32\svchost.exe
1112 C:\Windows\System32\svchost.exe
1124 C:\Windows\System32\svchost.exe
1208 C:\Windows\System32\audiodg.exe
1232 C:\Windows\System32\svchost.exe
1256 C:\Windows\System32\winlogon.exe
1280 C:\Windows\System32\SLsvc.exe
1324 C:\Windows\System32\svchost.exe
1460 C:\Windows\System32\svchost.exe
1692 C:\Windows\System32\spoolsv.exe
1748 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1780 C:\Windows\System32\rundll32.exe
1792 C:\Windows\System32\svchost.exe
1832 C:\Program Files\Common Files\SPBA\upeksvr.exe
412 C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
968 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
1152 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1416 C:\Program Files\Bonjour\mDNSResponder.exe
1456 C:\Windows\System32\svchost.exe
1636 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
1928 C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
1912 C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
316 C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
2136 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
2160 C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
2240 C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
2304 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2336 C:\ACER\Mobility Center\MobilityService.exe
2468 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
2516 HP1006MC.EXE
2584 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
2612 C:\Windows\System32\svchost.exe
2664 C:\Program Files\Cyberlink\Shared files\RichVideo.exe
2684 C:\Program Files\Acer\Acer VCM\RS_Service.exe
2728 C:\Windows\System32\svchost.exe
2768 C:\Windows\System32\svchost.exe
2824 C:\Program Files\RealVNC\VNC4\winvnc4.exe
2856 C:\Windows\System32\SearchIndexer.exe
2880 C:\Windows\System32\drivers\XAudio.exe
3344 C:\Windows\System32\taskeng.exe
3412 C:\Windows\System32\dwm.exe
3468 C:\Windows\explorer.exe
3608 C:\Windows\System32\taskeng.exe
3720 C:\Program Files\Windows Defender\MSASCui.exe
3732 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
3740 C:\Windows\RtHDVCpl.exe
3752 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3812 C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
3928 C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
3948 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
3964 C:\Windows\System32\rundll32.exe
3980 C:\Windows\PLFSetI.exe
4000 C:\Program Files\Launch Manager\QtZgAcer.EXE
4020 C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
4028 C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
4040 C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
4052 C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
4064 C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
4080 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
1364 C:\Program Files\OpenVPN\bin\openvpn-gui.exe
428 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
2032 C:\Program Files\Java\jre6\bin\jusched.exe
1408 C:\Program Files\iTunes\iTunesHelper.exe
2524 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
2292 C:\Windows\ehome\ehtray.exe
1996 C:\Program Files\Skype\Phone\Skype.exe
2604 C:\Program Files\Acer\Acer VCM\AcerVCM.exe
2464 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
700 C:\Program Files\FRITZ!DSL\StCenter.exe
600 C:\Program Files\FRITZ!DSL\FwebProt.exe
3880 C:\Windows\System32\wbem\unsecapp.exe
3924 WmiPrvSE.exe
1216 C:\Windows\ehome\ehmsas.exe
4500 C:\Users\Johannes\AppData\Local\Temp\RtkBtMnt.exe
4744 WmiPrvSE.exe
4900 C:\Program Files\iPod\bin\iPodService.exe
5016 C:\Program Files\Acer\Acer VCM\acp2HID.exe
5700 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
5712 C:\Program Files\Skype\Plugin Manager\skypePM.exe
4124 C:\Windows\System32\msiexec.exe
4388 C:\Program Files\Mozilla Firefox\firefox.exe
3160 C:\Program Files\Mozilla Firefox\plugin-container.exe
816 C:\Program Files\WinZip\WZQKPICK.EXE
5892 C:\Users\Johannes\Desktop\osam.exe
4740 C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
3540 C:\Windows\System32\SearchProtocolHost.exe
4392 C:\Windows\System32\SearchFilterHost.exe
4640 C:\Users\Johannes\Desktop\MBRCheck.exe
5664 C:\Windows\System32\conime.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`80100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000026`82e00000 (NTFS)

PhysicalDrive0 Model Number: ST9320320AS, Rev: 0303

Size Device Name MBR Status
--------------------------------------------
298 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 1BD01CAC429595C1D0CBBF8C10C0B8BA957B5116


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

cosinus 30.10.2010 20:17

Schau mal hier => Vista Notfall/Recovery-CD 32-Bit - Dr. Windows

Lad das iso runter, brenn es zB mit ImgBurn per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten).
Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:53 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131