|
Plagegeister aller Art und deren Bekämpfung: Virenproblem HTML/Drop.Agent.ABWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
07.07.2011, 18:47 | #1 |
| Virenproblem HTML/Drop.Agent.AB Hallo! Ich habe seit heute ein problem mit meinem Antivir. Mein Antivir Guard zeigt mir immer wieder an, dass da ein sog. HTML/Drop.Agent.AB gefunden wurde. Ich verschiebe es immer wieder in Quarantäne, aber es will nicht aufhören. Ich habe OTL schon runtergeladen und scannen lassen, dies sind die texte die rausgekommen sind: OTL Text:OTL Logfile: Code:
ATTFilter OTL logfile created on: 07.07.2011 19:06:12 - Run 1 OTL by OldTimer - Version 3.2.26.1 Folder = C:\Dokumente und Einstellungen\Administrator.HOME-PC\Eigene Dateien\Downloads Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,22 Gb Available Physical Memory | 60,89% Memory free 3,85 Gb Paging File | 3,06 Gb Available in Paging File | 79,59% Paging File free Paging file location(s): d:\pagefile.sys 2048 2048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.0 | %ProgramFiles% = C:\Programme Drive C: | 100,00 Gb Total Space | 1,64 Gb Free Space | 1,64% Space Free | Partition Type: NTFS Drive D: | 132,82 Gb Total Space | 12,94 Gb Free Space | 9,74% Space Free | Partition Type: NTFS Computer Name: HOME-PC | User Name: Administrator | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Dokumente und Einstellungen\Administrator.HOME-PC\Eigene Dateien\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Programme\PDF24\pdf24-Updater.exe (Geek Software GmbH) PRC - C:\Programme\PDF24\pdf24.exe (Geek Software GmbH) PRC - C:\Programme\ICQ6Toolbar\ICQ Service.exe () PRC - C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) PRC - C:\WINDOWS.0\tsnpstd3.exe () PRC - C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe (Avira GmbH) PRC - C:\WINDOWS.0\SoundMan.exe (Realtek Semiconductor Corp.) PRC - C:\Programme\MSI\US54EX\Installer\WINXP\MSI US54EX Wireless Client Utility.exe (MSI Technology GmbH ) PRC - C:\WINDOWS.0\explorer.exe (Microsoft Corporation) PRC - C:\WINDOWS.0\FixCamera.exe () PRC - C:\WINDOWS.0\vsnpstd3.exe () PRC - C:\Programme\Labtec\WebCam10\WebCam10.exe () PRC - C:\Programme\Gemeinsame Dateien\logishrd\LComMgr\Communications_Helper.exe (Labtec Inc,) PRC - C:\Programme\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe (PowerQuest Corporation) PRC - C:\WINDOWS.0\system32\gearsec.exe (GEAR Software) ========== Modules (SafeList) ========== MOD - C:\Dokumente und Einstellungen\Administrator.HOME-PC\Eigene Dateien\Downloads\OTL.exe (OldTimer Tools) MOD - C:\Programme\SweetIM\Messenger\mgAdaptersProxy.dll (SweetIM Technologies Ltd.) MOD - C:\WINDOWS.0\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation) MOD - C:\Programme\SweetIM\Messenger\msvcr71.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device) -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) SRV - (ICQ Service) -- C:\Programme\ICQ6Toolbar\ICQ Service.exe () SRV - (AntiVirScheduler) -- C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe (Avira GmbH) SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe (Avira GmbH) SRV - (Adobe LM Service) -- C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems) SRV - (Macromedia Licensing Service) -- C:\Programme\Gemeinsame Dateien\Macromedia Shared\Service\Macromedia Licensing.exe () SRV - (LVSrvLauncher) -- C:\Programme\Gemeinsame Dateien\logishrd\SrvLnch\SrvLnch.exe (Labtec Inc.) SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) SRV - (TUWinStylerThemeSvc) -- C:\Programme\TuneUpUtilities2006\WinStylerThemeSvc.exe (TuneUp Software GmbH) SRV - (V2i Protector) -- C:\Programme\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe (PowerQuest Corporation) SRV - (GEARSecurity) -- C:\WINDOWS.0\system32\gearsec.exe (GEAR Software) ========== Driver Services (SafeList) ========== DRV - (Micorsoft Windows Service) -- File not found DRV - (sptd) -- C:\WINDOWS.0\System32\Drivers\sptd.sys () DRV - (ati2mtag) -- C:\WINDOWS.0\system32\drivers\ati2mtag.sys (ATI Technologies Inc.) DRV - (SNPSTD3) USB PC Camera (SNPSTD3) -- C:\WINDOWS.0\system32\drivers\snpstd3.sys (Sonix Co. Ltd.) DRV - (avipbb) -- C:\WINDOWS.0\system32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Programme\Avira\AntiVir PersonalEdition Classic\avgntflt.sys (Avira GmbH) DRV - (avgio) -- C:\Programme\Avira\AntiVir PersonalEdition Classic\avgio.sys (Avira GmbH) DRV - (WDC_SAM) -- C:\WINDOWS.0\system32\drivers\wdcsam.sys (Western Digital Technologies) DRV - (gdrv) -- C:\WINDOWS.0\gdrv.sys (Windows (R) 2000 DDK provider) DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS.0\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.) DRV - (JRAID) -- C:\WINDOWS.0\system32\DRIVERS\jraid.sys (JMicron Technology Corp.) DRV - (RTLE8023xp) -- C:\WINDOWS.0\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation ) DRV - (ssmdrv) -- C:\WINDOWS.0\system32\drivers\ssmdrv.sys (AVIRA GmbH) DRV - (RT73) -- C:\WINDOWS.0\system32\drivers\rt73.sys (Ralink Technology, Corp.) DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) -- C:\WINDOWS.0\system32\drivers\LV302V32.SYS (Logitech Inc.) DRV - (UsbDiag) -- C:\WINDOWS.0\system32\drivers\lgusbdiag.sys (LG Electronics Inc.) DRV - (USBModem) -- C:\WINDOWS.0\system32\drivers\lgusbmodem.sys (LG Electronics Inc.) DRV - (usbbus) -- C:\WINDOWS.0\system32\drivers\lgusbbus.sys (LG Electronics Inc.) DRV - (LVUSBSta) -- C:\WINDOWS.0\system32\drivers\LVUSBSta.sys (Labtec Inc.) DRV - (LVMVDrv) -- C:\WINDOWS.0\system32\drivers\LVMVdrv.sys (Labtec Inc.) DRV - (LVcKap) -- C:\WINDOWS.0\system32\drivers\Lvckap.sys () DRV - (PID_0928) Logitech QuickCam Express(PID_0928) -- C:\WINDOWS.0\system32\drivers\LV561AV.SYS (Labtec Inc.) DRV - (RivaTuner32) -- C:\Programme\RivaTuner v2.0 Final Release\RivaTuner32.sys () DRV - (AnyDVD) -- C:\WINDOWS.0\system32\drivers\AnyDVD.sys (SlySoft, Inc.) DRV - (ElbyCDFL) -- C:\WINDOWS.0\system32\drivers\ElbyCDFL.sys (SlySoft, Inc.) DRV - (ElbyDelay) -- C:\WINDOWS.0\system32\drivers\ElbyDelay.sys (Elaborate Bytes AG) DRV - (pfc) -- C:\WINDOWS.0\system32\drivers\pfc.sys (Padus, Inc.) DRV - (PQV2i) -- C:\WINDOWS.0\System32\drivers\PQV2i.sys (StorageCraft) DRV - (PQIMount) -- C:\WINDOWS.0\System32\drivers\PQIMount.sys (PowerQuest Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.0\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://search.qip.ru IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.qip.ru IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.0\system32\blank.htm IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.qip.ru/ie IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.qip.ru IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://search.qip.ru/ie IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\1111241238\ICQToolBar.dll (ICQ) IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru) IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.) IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1801674531-2000478354-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - prefs.js..browser.search.selectedEngine: "ICQ Search" FF - prefs.js..browser.startup.homepage: "hxxp://start.icq.com/" FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9 FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004 FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.8 FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.2.0185 FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q=" FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS.0\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Programme\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Programme\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\Mozilla Firefox\components [2011.07.07 18:41:28 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\Mozilla Firefox\plugins [2011.07.07 18:41:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2011.11.24 13:56:46 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins [2011.11.24 13:56:45 | 000,000,000 | ---D | M] [2008.07.25 17:07:57 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Extensions [2011.12.06 15:08:56 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\extensions [2011.11.24 13:38:17 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2009.09.30 21:42:47 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} [2010.06.15 18:25:47 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\extensions\DTToolbar@toolbarnet.com [2009.09.01 19:27:57 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\extensions\moveplayer@movenetworks.com [2010.06.15 18:24:04 | 000,002,055 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\daemon-search.xml [2011.11.30 14:28:07 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-1.xml [2009.06.16 16:58:46 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-10.xml [2009.07.07 18:51:25 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-11.xml [2009.08.10 15:12:18 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-12.xml [2009.08.11 13:40:12 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-13.xml [2009.09.11 22:15:44 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-14.xml [2009.12.05 13:08:09 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-15.xml [2010.01.08 18:49:26 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-16.xml [2010.02.19 21:42:22 | 000,000,961 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-17.xml [2010.03.25 18:50:58 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-18.xml [2010.03.26 15:47:00 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-19.xml [2008.10.12 14:17:21 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-2.xml [2010.04.03 00:12:34 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-20.xml [2010.06.17 18:47:59 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-21.xml [2010.06.28 22:36:49 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-22.xml [2010.07.17 15:05:03 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-23.xml [2010.09.11 23:20:05 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-24.xml [2010.09.19 18:26:13 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-25.xml [2010.10.23 13:46:24 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-26.xml [2010.11.01 12:56:56 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-27.xml [2010.12.15 18:57:29 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-28.xml [2011.03.02 23:57:39 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-29.xml [2008.11.15 22:59:46 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-3.xml [2011.03.12 20:23:53 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-30.xml [2011.03.26 21:26:18 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-31.xml [2011.05.13 10:48:15 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-32.xml [2011.11.23 04:30:06 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-33.xml [2011.11.24 13:38:32 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-34.xml [2008.12.19 18:57:56 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-4.xml [2009.02.05 20:56:08 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-5.xml [2009.03.05 21:01:11 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-6.xml [2009.03.29 20:53:02 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-7.xml [2009.04.27 20:35:20 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-8.xml [2009.05.01 19:55:02 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin-9.xml [2011.03.30 16:14:34 | 000,001,042 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\icqplugin.xml [2009.06.02 21:19:52 | 000,002,061 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\qipsearch.xml [2009.09.30 21:42:44 | 000,003,915 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\tij31j4b.default\searchplugins\sweetim.xml [2009.08.28 17:05:41 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2009.08.26 16:26:52 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Programme\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2009.03.16 22:01:57 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} File not found (No name found) -- [2009.08.29 13:46:11 | 000,000,000 | ---D | M] (Java Console) -- C:\DOKUMENTE UND EINSTELLUNGEN\ADMINISTRATOR.HOME-PC\DESKTOP\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} [2007.08.10 15:03:04 | 006,275,816 | ---- | M] () -- C:\Programme\mozilla firefox\plugins\ScorchPDFWrapper.dll O1 HOSTS File: ([2005.10.10 14:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS.0\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Yahoo! Companion BHO) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Programme\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_1.dll (Yahoo! Inc.) O2 - BHO: (XTTBPos00 Class) - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Programme\ICQToolbar\toolbaru.dll (ICQ Inc.) O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (QIPBHO Class) - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru) O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programme\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\1111241238\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (no name) - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - No CLSID value found. O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKLM\..\Toolbar: (&Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_1.dll (Yahoo! Inc.) O3 - HKU\S-1-5-21-1801674531-2000478354-839522115-500\..\Toolbar\ShellBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\1111241238\ICQToolBar.dll (ICQ) O3 - HKU\S-1-5-21-1801674531-2000478354-839522115-500\..\Toolbar\WebBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\1111241238\ICQToolBar.dll (ICQ) O3 - HKU\S-1-5-21-1801674531-2000478354-839522115-500\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKU\S-1-5-21-1801674531-2000478354-839522115-500\..\Toolbar\WebBrowser: (&Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_1.dll (Yahoo! Inc.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [36X Raid Configurer] C:\WINDOWS.0\System32\xRaidSetup.exe (JMicron Technology Corp.) O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS.0\Alcmtr.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS.0\alcwzrd.exe (RealTek Semicoductor Corp.) O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [FixCamera] C:\WINDOWS.0\FixCamera.exe () O4 - HKLM..\Run: [JMB36X IDE Setup] C:\WINDOWS.0\RaidTool\xInsIDE.exe () O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe (Labtec Inc,) O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Programme\Labtec\WebCam10\WebCam10.exe () O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS.0\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS.0\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS.0\System32\nwiz.exe () O4 - HKLM..\Run: [PDFPrint] C:\Programme\PDF24\pdf24.exe (Geek Software GmbH) O4 - HKLM..\Run: [snpstd3] C:\WINDOWS.0\vsnpstd3.exe () O4 - HKLM..\Run: [SoundMan] C:\WINDOWS.0\SoundMan.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [SweetIM] C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS.0\tsnpstd3.exe () O4 - HKU\S-1-5-21-1801674531-2000478354-839522115-500..\Run: [DAEMON Tools Lite] D:\malle-festplatte\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKU\S-1-5-21-1801674531-2000478354-839522115-500..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS.0\System32\Macromed\Flash\FlashUtil10m_Plugin.exe (Adobe Systems, Inc.) O4 - Startup: C:\Dokumente und Einstellungen\Administrator.HOME-PC\Startmenü\Programme\Autostart\eedevqib.exe (Macromedia, Inc.) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Adobe Reader Synchronizer.lnk = C:\Programme\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe (Adobe Systems Incorporated) O4 - Startup: C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Startmenü\Programme\Autostart\MSI US54EX Wireless Client Utility.lnk = C:\Programme\MSI\US54EX\Installer\WINXP\MSI US54EX Wireless Client Utility.exe (MSI Technology GmbH ) O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1 O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.) O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programme\PartyGaming.Net\PartyPokerNet\RunPF.exe () O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programme\PartyGaming.Net\PartyPokerNet\RunPF.exe () O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Programme\PokerStars.NET\PokerStarsUpdate.exe (PokerStars) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKU\S-1-5-21-1801674531-2000478354-839522115-500\..Trusted Domains: localhost ([]http in Local intranet) O15 - HKU\S-1-5-21-1801674531-2000478354-839522115-500\..Trusted Domains: prosieben.de ([icqapps] https in Trusted sites) O15 - HKU\S-1-5-21-1801674531-2000478354-839522115-500\..Trusted Ranges: GD ([http] in Local intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Java Plug-in 1.4.2_05) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} hxxp://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab (Oberon Flash Game Host) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Programme\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS.0\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Programme\vxlolnck\eedevqib.exe) - C:\Programme\vxlolnck\eedevqib.exe () O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS.0\System32\ati2evxx.dll (ATI Technologies Inc.) O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - File not found O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2007.08.18 19:42:57 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2010.06.18 16:40:34 | 000,000,100 | ---- | M] () - D:\AUTORUN.INF -- [ NTFS ] O33 - MountPoints2\{1a073372-1618-11e1-b170-001fcf112289}\Shell - "" = AutoRun O33 - MountPoints2\{1a073372-1618-11e1-b170-001fcf112289}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{1a073372-1618-11e1-b170-001fcf112289}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true O33 - MountPoints2\{1efe104a-e199-11de-ae8a-001fcf112289}\Shell\AutoRun\command - "" = G:\Menu.exe O33 - MountPoints2\{e20c320b-61c6-11de-ad43-001fcf112289}\Shell - "" = AutoRun O33 - MountPoints2\{e20c320b-61c6-11de-ad43-001fcf112289}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{e20c320b-61c6-11de-ad43-001fcf112289}\Shell\AutoRun\command - "" = G:\LaunchU3.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: winmgmt - C:\WINDOWS.0\system32\wbem\winmgmt.exe (Microsoft Corporation) MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^Administrator.HOME-PC^Startmenü^Programme^Autostart^OpenOffice.org 2.3.lnk - C:\Programme\OpenOffice.org 2.3\program\quickstart.exe - () MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users.WINDOWS.0^Startmenü^Programme^Autostart^HP Digital Imaging Monitor.lnk - C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe - (Hewlett-Packard Co.) MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: ctfmon.exe - hkey= - key= - File not found MsConfig - StartUpReg: HP Software Update - hkey= - key= - C:\Programme\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.) MsConfig - StartUpReg: KernelFaultCheck - hkey= - key= - File not found MsConfig - StartUpReg: LogitechCommunicationsManager - hkey= - key= - C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe (Labtec Inc,) MsConfig - StartUpReg: LogitechQuickCamRibbon - hkey= - key= - File not found MsConfig - StartUpReg: NeroFilterCheck - hkey= - key= - File not found MsConfig - StartUpReg: NvCplDaemon - hkey= - key= - File not found MsConfig - StartUpReg: nwiz - hkey= - key= - File not found MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Programme\QuickTime\qttask.exe (Apple Inc.) MsConfig - StartUpReg: RemoteControl - hkey= - key= - C:\Programme\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.) MsConfig - StartUpReg: Skype - hkey= - key= - C:\Programme\Skype\Phone\Skype.exe (Skype Technologies S.A.) MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Programme\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.) MsConfig - StartUpReg: WinampAgent - hkey= - key= - C:\Programme\Winamp\winampa.exe () MsConfig - State: "system.ini" - 0 MsConfig - State: "win.ini" - 0 MsConfig - State: "bootini" - 0 MsConfig - State: "services" - 0 MsConfig - State: "startup" - 2 ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS.0\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7 ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {65289DE3-4C1A-11D6-B6E1-00B0D049139F} - Microsoft .NET Framework Service Pack 2 (German) ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {78705f0d-e8db-4b2d-8193-982bdda15ecd} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS.0\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS.0\system32\Rundll32.exe C:\WINDOWS.0\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {9BFBE94F-2FAF-11D6-8712-0002B3281F8B} - Microsoft .NET Framework Service Pack 1 (DEU) ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} - ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C314CE45-3392-3B73-B4E1-139CD41CA933} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F279058C-50B2-4BE4-60C9-369CACF06821} - .NET Framework ActiveX: {F4A339FC-078C-FF2F-D20C-2C4C5BEB3455} - Themes Setup ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS.0\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS.0\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS.0\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS.0\system32\rundll32.exe" "C:\WINDOWS.0\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE Drivers32: msacm.iac2 - C:\WINDOWS.0\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS.0\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.lhacm - C:\WINDOWS.0\System32\lhacm.acm (Microsoft Corporation) Drivers32: msacm.sl_anet - C:\WINDOWS.0\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS.0\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: MSVideo - C:\WINDOWS.0\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: MSVideo8 - C:\WINDOWS.0\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\WINDOWS.0\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.DIVX - C:\WINDOWS.0\System32\DivX.dll (DivX, Inc.) Drivers32: vidc.iv31 - C:\WINDOWS.0\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS.0\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS.0\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS.0\System32\ir50_32.dll (Intel Corporation) Drivers32: vidc.yv12 - C:\WINDOWS.0\System32\DivX.dll (DivX, Inc.) CREATERESTOREPOINT Error creating restore point. ========== Files/Folders - Created Within 30 Days ========== [2011.12.07 14:24:39 | 000,083,331 | --S- | C] (Macromedia, Inc.) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Startmenü\Programme\Autostart\eedevqib.exe [2011.12.07 14:24:39 | 000,000,000 | ---D | C] -- C:\Programme\vxlolnck [2011.11.28 15:30:47 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Startmenü\Programme\Skype [2011.11.24 23:09:00 | 000,011,520 | R--- | C] (Western Digital Technologies) -- C:\WINDOWS.0\System32\drivers\wdcsam.sys [2011.11.24 13:59:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Startmenü\Programme\iTunes [2011.11.24 13:58:18 | 000,000,000 | ---D | C] -- C:\Programme\iPod [2011.11.24 13:58:15 | 000,000,000 | ---D | C] -- C:\Programme\iTunes [2011.11.24 13:58:15 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2011.11.24 13:57:53 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Apple Computer [2011.11.24 13:56:07 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\Apple Computer [2011.11.24 13:55:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Apple [2011.11.24 13:55:30 | 004,517,664 | ---- | C] (Apple, Inc.) -- C:\WINDOWS.0\System32\usbaaplrc.dll [2011.11.24 13:54:36 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Apple [2011.11.24 13:54:36 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\Apple [2011.11.24 13:54:14 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Apple Computer [2011.11.24 13:38:26 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Startmenü\Programme\ICQ7.5 [2011.11.24 13:36:48 | 000,000,000 | ---D | C] -- C:\Programme\ICQ7.5 [2011.11.23 23:14:26 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Western Digital [2011.11.07 18:24:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Startmenü\Programme\Google Earth [2011.07.07 19:00:44 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\Common Files [2011.07.07 18:56:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\MFAData [2011.07.07 18:50:38 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Facebook [2011.07.07 18:40:01 | 013,523,912 | ---- | C] (Mozilla) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\Firefox_Setup_5.0.exe [2011.02.11 23:07:51 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS.0\System32\rsnpstd3.dll [2011.02.11 23:07:51 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS.0\System32\vsnpstd3.dll [2011.02.11 23:07:51 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS.0\System32\csnpstd3.dll [2011.02.11 23:07:51 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS.0\csnpstd3.dll [6 C:\WINDOWS.0\Fonts\*.tmp files -> C:\WINDOWS.0\Fonts\*.tmp -> ] [53 C:\WINDOWS.0\*.tmp files -> C:\WINDOWS.0\*.tmp -> ] [45 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.12.07 19:22:34 | 000,001,100 | ---- | M] () -- C:\WINDOWS.0\tasks\GoogleUpdateTaskMachineCore.job [2011.12.07 19:22:31 | 000,002,048 | --S- | M] () -- C:\WINDOWS.0\bootstat.dat [2011.12.07 18:29:03 | 000,001,104 | ---- | M] () -- C:\WINDOWS.0\tasks\GoogleUpdateTaskMachineUA.job [2011.12.07 15:22:41 | 000,000,116 | ---- | M] () -- C:\WINDOWS.0\NeroDigital.ini [2011.12.07 14:29:15 | 000,083,331 | --S- | M] (Macromedia, Inc.) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Startmenü\Programme\Autostart\eedevqib.exe [2011.12.06 14:53:19 | 000,002,206 | ---- | M] () -- C:\WINDOWS.0\System32\wpa.dbl [2011.12.04 03:41:29 | 000,002,245 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Desktop\Skype.lnk [2011.12.02 18:16:30 | 000,000,408 | ---- | M] () -- C:\WINDOWS.0\tasks\1-Klick-Wartung.job [2011.11.27 23:31:26 | 000,887,770 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\P1050007.JPG [2011.11.24 13:59:57 | 000,001,532 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Desktop\iTunes.lnk [2011.11.24 13:56:32 | 000,001,594 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Desktop\QuickTime Player.lnk [2011.11.24 13:55:43 | 000,000,276 | ---- | M] () -- C:\WINDOWS.0\tasks\AppleSoftwareUpdate.job [2011.11.24 13:38:26 | 000,001,457 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Desktop\ICQ7.5.lnk [2011.11.23 16:09:50 | 000,054,156 | -H-- | M] () -- C:\WINDOWS.0\QTFont.qfn [2011.07.07 18:46:18 | 013,523,912 | ---- | M] (Mozilla) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\Firefox_Setup_5.0.exe [2011.07.07 18:41:34 | 000,000,753 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Desktop\Mozilla Firefox.lnk [53 C:\WINDOWS.0\*.tmp files -> C:\WINDOWS.0\*.tmp -> ] [45 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.11.27 23:31:25 | 000,887,770 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\P1050007.JPG [2011.11.24 13:59:57 | 000,001,532 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Desktop\iTunes.lnk [2011.11.24 13:56:32 | 000,001,594 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Desktop\QuickTime Player.lnk [2011.11.24 13:55:43 | 000,000,276 | ---- | C] () -- C:\WINDOWS.0\tasks\AppleSoftwareUpdate.job [2011.11.24 13:55:42 | 000,001,834 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Startmenü\Programme\Apple Software Update.lnk [2011.11.24 13:38:26 | 000,001,457 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Desktop\ICQ7.5.lnk [2011.07.07 18:41:34 | 000,000,753 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Desktop\Mozilla Firefox.lnk [2011.07.07 18:41:33 | 000,000,759 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Startmenü\Programme\Mozilla Firefox.lnk [2011.02.12 11:35:40 | 000,020,480 | ---- | C] () -- C:\WINDOWS.0\FixCamera.exe [2011.02.11 23:08:01 | 000,835,584 | ---- | C] () -- C:\WINDOWS.0\vsnpstd3.exe [2011.02.11 23:08:01 | 000,360,448 | ---- | C] () -- C:\WINDOWS.0\tsnpstd3.exe [2011.02.11 23:08:00 | 000,015,498 | ---- | C] () -- C:\WINDOWS.0\snpstd3.ini [2011.02.11 23:07:51 | 000,003,968 | ---- | C] () -- C:\WINDOWS.0\System32\drivers\DeNoise.sys [2010.12.29 18:50:48 | 000,000,072 | ---- | C] () -- C:\WINDOWS.0\wiso.ini [2010.08.12 14:55:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS.0\ativpsrm.bin [2010.08.12 14:55:05 | 000,887,724 | R--- | C] () -- C:\WINDOWS.0\System32\ativva6x.dat [2010.08.12 14:55:05 | 000,196,565 | R--- | C] () -- C:\WINDOWS.0\System32\atiicdxx.dat [2010.08.12 14:55:05 | 000,000,003 | R--- | C] () -- C:\WINDOWS.0\System32\ativva5x.dat [2010.08.12 14:55:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS.0\System32\ATIODCLI.exe [2010.08.12 14:54:53 | 000,294,912 | ---- | C] () -- C:\WINDOWS.0\System32\ATIODE.exe [2010.08.12 10:07:47 | 000,000,552 | ---- | C] () -- C:\WINDOWS.0\System32\d3d8caps.dat [2010.07.29 17:25:26 | 000,000,056 | -H-- | C] () -- C:\WINDOWS.0\System32\ezsidmv.dat [2009.11.06 10:58:04 | 000,178,975 | ---- | C] () -- C:\WINDOWS.0\System32\xlive.dll.cat [2008.12.02 22:10:29 | 000,000,072 | ---- | C] () -- C:\WINDOWS.0\CmdPrint.INI [2008.11.01 21:44:18 | 000,138,576 | ---- | C] () -- C:\WINDOWS.0\System32\drivers\PnkBstrK.sys [2008.11.01 21:44:18 | 000,022,328 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\PnkBstrK.sys [2008.11.01 21:44:13 | 000,215,104 | ---- | C] () -- C:\WINDOWS.0\System32\PnkBstrB.exe [2008.11.01 21:43:28 | 000,075,064 | ---- | C] () -- C:\WINDOWS.0\System32\PnkBstrA.exe [2008.11.01 21:39:13 | 000,000,311 | ---- | C] () -- C:\WINDOWS.0\game.ini [2008.10.08 10:45:27 | 000,311,296 | ---- | C] () -- C:\WINDOWS.0\System32\AegisI5.exe [2008.10.08 10:45:27 | 000,290,918 | ---- | C] () -- C:\WINDOWS.0\System32\Install7x.dll [2008.10.08 10:45:27 | 000,002,048 | ---- | C] () -- C:\WINDOWS.0\System32\drivers\rt73.bin [2008.07.25 20:38:15 | 000,003,972 | ---- | C] () -- C:\WINDOWS.0\System32\drivers\PciBus.sys [2008.07.25 18:08:09 | 000,001,788 | ---- | C] () -- C:\WINDOWS.0\System32\dcache.bin [2008.03.07 23:34:57 | 000,000,032 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\ezsid.dat [2008.01.26 14:56:19 | 000,147,285 | ---- | C] () -- C:\WINDOWS.0\hpoins13.dat [2008.01.26 14:56:19 | 000,000,811 | ---- | C] () -- C:\WINDOWS.0\hpomdl13.dat [2007.12.11 16:28:33 | 000,000,900 | -HS- | C] () -- C:\WINDOWS.0\System32\KGyGaAvL.sys [2007.12.07 17:48:13 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\addr_file.html [2007.11.26 16:19:17 | 000,000,116 | ---- | C] () -- C:\WINDOWS.0\NeroDigital.ini [2007.11.26 16:14:36 | 000,049,152 | ---- | C] () -- C:\WINDOWS.0\System32\ChCfg.exe [2007.11.26 15:29:23 | 000,100,864 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2007.11.26 12:29:32 | 000,000,154 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat [2007.11.25 21:01:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS.0\nsreg.dat [2007.11.25 20:20:06 | 000,002,608 | ---- | C] () -- C:\WINDOWS.0\mozver.dat [2007.11.25 20:19:35 | 000,000,406 | ---- | C] () -- C:\WINDOWS.0\ODBC.INI [2007.11.25 20:05:11 | 000,002,048 | --S- | C] () -- C:\WINDOWS.0\bootstat.dat [2007.11.25 19:57:14 | 000,021,740 | ---- | C] () -- C:\WINDOWS.0\System32\emptyregdb.dat [2007.11.25 19:50:40 | 000,004,249 | ---- | C] () -- C:\WINDOWS.0\ODBCINST.INI [2007.11.25 19:49:28 | 001,507,080 | ---- | C] () -- C:\WINDOWS.0\System32\FNTCACHE.DAT [2007.10.12 02:11:58 | 000,051,370 | ---- | C] () -- C:\WINDOWS.0\System32\lvcoinst.ini [2007.09.06 20:04:52 | 003,596,288 | ---- | C] () -- C:\WINDOWS.0\System32\qt-dx331.dll [2007.09.06 20:01:52 | 000,012,288 | ---- | C] () -- C:\WINDOWS.0\System32\DivXWMPExtType.dll [2007.03.06 17:50:30 | 001,669,664 | ---- | C] () -- C:\WINDOWS.0\System32\drivers\Lvckap.sys [2007.02.23 05:25:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS.0\System32\nvwdmcpl.dll [2007.02.23 05:25:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS.0\System32\nwiz.exe [2007.02.23 05:25:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS.0\System32\nview.dll [2007.02.23 05:25:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS.0\System32\nvdspsch.exe [2007.02.23 05:25:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS.0\System32\nvwimg.dll [2007.02.23 05:25:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS.0\System32\nvhwvid.dll [2007.02.23 05:25:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS.0\System32\nvshell.dll [2007.02.23 05:25:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS.0\System32\nvappbar.exe [2007.02.23 05:25:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS.0\System32\keystone.exe [2007.02.23 05:25:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS.0\System32\nvnt4cpl.dll [2005.10.10 14:00:00 | 000,452,646 | ---- | C] () -- C:\WINDOWS.0\System32\perfh007.dat [2005.10.10 14:00:00 | 000,435,836 | ---- | C] () -- C:\WINDOWS.0\System32\perfh009.dat [2005.10.10 14:00:00 | 000,081,134 | ---- | C] () -- C:\WINDOWS.0\System32\perfc007.dat [2005.10.10 14:00:00 | 000,068,350 | ---- | C] () -- C:\WINDOWS.0\System32\perfc009.dat [2005.10.10 14:00:00 | 000,031,232 | ---- | C] () -- C:\WINDOWS.0\System32\cmdow.exe [2005.10.10 14:00:00 | 000,005,702 | ---- | C] () -- C:\WINDOWS.0\System32\OUTLPERF.INI [2005.10.10 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS.0\System32\noise.dat [2005.04.28 06:22:34 | 000,831,488 | ---- | C] () -- C:\WINDOWS.0\System32\libeay32.dll [2005.04.28 06:22:34 | 000,159,744 | ---- | C] () -- C:\WINDOWS.0\System32\ssleay32.dll [2004.08.02 13:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS.0\System32\secupd.dat [2001.08.23 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS.0\System32\oembios.bin [2001.08.23 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS.0\System32\mlang.dat [2001.08.23 13:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS.0\System32\perfi009.dat [2001.08.23 13:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS.0\System32\perfi007.dat [2001.08.23 13:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS.0\System32\dssec.dat [2001.08.23 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS.0\System32\mib.bin [2001.08.23 13:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS.0\System32\perfd007.dat [2001.08.23 13:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS.0\System32\perfd009.dat [2001.08.23 13:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS.0\System32\oembios.dat ========== LOP Check ========== [2007.11.27 17:30:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Babylon [2010.06.15 18:33:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\DAEMON Tools Lite [2010.01.06 21:45:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\gtk-2.0 [2011.12.02 14:28:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\ICQ [2007.11.27 17:21:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\ICQ Toolbar [2011.04.26 19:43:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Image Zone Express [2009.08.26 16:53:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\LG Electronics [2007.12.09 21:52:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\LimeWire [2008.11.01 23:04:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Meine Der Herr der Ringe™, Aufstieg des Hexenkönigs™-Dateien [2008.04.11 16:04:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Notepad++ [2008.10.09 21:36:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\PACE Anti-Piracy [2011.04.26 19:43:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Printer Info Cache [2007.12.19 13:49:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\QIP [2011.03.19 09:36:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\TeamViewer [2008.10.09 12:55:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\temp [2009.01.03 17:02:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Thunderbird [2010.03.17 17:12:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\TS3Client [2007.11.25 20:09:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\TuneUp Software [2008.11.02 02:07:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Ubisoft [2007.08.20 22:20:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AntiVir PersonalEdition Classic [2007.08.19 18:57:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PowerQuest [2007.08.18 19:51:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software [2007.11.26 15:27:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\AntiVir PersonalEdition Classic [2008.01.03 18:47:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\Babylon [2010.12.29 18:46:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\Buhl Data Service GmbH [2011.07.07 19:00:44 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\Common Files [2010.06.15 18:23:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\DAEMON Tools Lite [2011.02.07 00:19:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\Driver Whiz [2011.11.24 13:38:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\ICQ [2011.07.07 19:00:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\MFAData [2008.10.09 21:36:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\PACE Anti-Piracy [2007.11.26 12:29:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\PowerQuest [2010.03.23 22:15:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\Solidshield [2009.09.30 21:42:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\SweetIM [2007.11.25 20:09:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\TuneUp Software [2011.02.07 00:19:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\UAB [2008.11.02 01:28:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\Ubisoft [2011.11.24 13:59:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2009.12.14 21:58:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\ICQ [2007.11.26 11:37:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marvin\Anwendungsdaten\ICQ [2007.11.25 21:19:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marvin\Anwendungsdaten\ICQ Toolbar [2007.11.26 12:59:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Marvin\Anwendungsdaten\TuneUp Software [2011.12.02 18:16:30 | 000,000,408 | ---- | M] () -- C:\WINDOWS.0\Tasks\1-Klick-Wartung.job ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2008.08.13 19:16:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Adobe [2010.02.18 14:33:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Ahead [2011.11.24 14:00:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Apple Computer [2010.08.12 15:02:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\ATI [2007.11.27 17:30:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Babylon [2007.11.25 20:23:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Corel [2007.11.26 19:11:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\CyberLink [2010.06.15 18:33:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\DAEMON Tools Lite [2009.08.26 16:31:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\DivX [2010.04.29 19:08:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Google [2010.01.06 21:45:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\gtk-2.0 [2008.01.26 15:05:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\HP [2011.12.02 14:28:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\ICQ [2007.11.27 17:21:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\ICQ Toolbar [2007.11.25 20:11:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Identities [2011.04.26 19:43:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Image Zone Express [2007.11.26 15:21:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\InstallShield [2009.08.26 16:53:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\LG Electronics [2007.12.09 21:52:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\LimeWire [2007.12.04 15:57:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Macromedia [2008.11.01 23:04:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Meine Der Herr der Ringe™, Aufstieg des Hexenkönigs™-Dateien [2010.08.12 14:54:43 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Microsoft [2009.09.11 23:28:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Move Networks [2008.07.25 17:07:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla [2010.04.02 23:25:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla-Cache [2008.04.11 16:04:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Notepad++ [2011.11.15 22:08:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\OpenOffice.org2 [2008.10.09 21:36:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\PACE Anti-Piracy [2011.04.26 19:43:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Printer Info Cache [2007.12.19 13:49:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\QIP [2011.12.04 04:11:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Skype [2011.11.28 15:30:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\skypePM [2007.11.25 20:19:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Sun [2008.06.03 19:16:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\teamspeak2 [2011.03.19 09:36:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\TeamViewer [2008.10.09 12:55:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\temp [2009.01.03 17:02:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Thunderbird [2010.03.17 17:12:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\TS3Client [2007.11.25 20:09:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\TuneUp Software [2011.07.07 18:40:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\U3 [2008.11.02 02:07:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Ubisoft [2008.09.11 17:23:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\vlc [2008.07.25 14:59:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\WinRAR [2009.01.20 21:10:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Xfire < %APPDATA%\*.exe /s > [2007.12.09 21:42:46 | 003,381,280 | ---- | M] (Lime Wire LLC) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\LimeWire\.NetworkShare\LimeWireWin4.14.12.exe [2010.08.16 10:19:11 | 000,010,134 | R--- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Microsoft\Installer\{35725FBC-A136-4A46-9F29-091759D9BB93}\ARPPRODUCTICON.exe [2010.08.12 14:54:44 | 000,010,134 | R--- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Microsoft\Installer\{639205FC-A8C3-A655-ACF8-8B13A753242F}\ARPPRODUCTICON.exe [2010.08.16 10:19:26 | 000,010,134 | R--- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Microsoft\Installer\{BEF726DD-4037-4214-8C6A-E625C02D2870}\ARPPRODUCTICON.exe [2010.08.16 10:19:02 | 000,010,134 | R--- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Microsoft\Installer\{EA516024-D84D-41F1-814F-83175A6188F2}\ARPPRODUCTICON.exe [2005.06.06 11:29:14 | 000,110,592 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\U3\temp\cleanup.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2007.10.09 19:15:40 | 016,734,399 | ---- | M] () .cab file -- C:\WINDOWS.0\Driver Cache\i386\sp2.cab:AGP440.sys [2007.10.09 19:15:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS.0\$NtServicePackUninstall$\agp440.sys [2007.10.09 19:15:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS.0\system32\drivers\agp440.sys < MD5 for: ATAPI.SYS > [2007.10.09 19:15:40 | 016,734,399 | ---- | M] () .cab file -- C:\WINDOWS.0\Driver Cache\i386\sp2.cab:atapi.sys [2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\kann_geloescht_werden_WINDOWS\system32\dllcache\atapi.sys [2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\kann_geloescht_werden_WINDOWS\system32\drivers\atapi.sys [2005.10.10 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\kann_geloescht_werden_WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys [2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\kann_geloescht_werden_WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys [2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS.0\$NtServicePackUninstall$\atapi.sys [2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS.0\system32\drivers\atapi.sys < MD5 for: EVENTLOG.DLL > [2005.10.10 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\kann_geloescht_werden_WINDOWS\system32\dllcache\eventlog.dll [2005.10.10 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\kann_geloescht_werden_WINDOWS\system32\eventlog.dll [2004.08.03 23:57:20 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS.0\$NtServicePackUninstall$\eventlog.dll [2004.08.03 23:57:20 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS.0\system32\eventlog.dll < MD5 for: EXPLORER.EXE > [2005.10.10 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=22FE1BE02EADDE1632E478E4125639E0 -- C:\kann_geloescht_werden_WINDOWS\explorer.exe [2005.10.10 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=22FE1BE02EADDE1632E478E4125639E0 -- C:\kann_geloescht_werden_WINDOWS\system32\dllcache\explorer.exe [2007.06.13 15:10:08 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=331ED93570BAF3CFE30340298762CD56 -- C:\WINDOWS.0\$hf_mig$\KB938828\SP2QFE\explorer.exe [2007.10.09 19:05:16 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=331ED93570BAF3CFE30340298762CD56 -- C:\WINDOWS.0\$NtServicePackUninstall$\explorer.exe [2007.10.09 19:05:16 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=331ED93570BAF3CFE30340298762CD56 -- C:\WINDOWS.0\explorer.exe < MD5 for: NETLOGON.DLL > [2005.10.10 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\kann_geloescht_werden_WINDOWS\system32\dllcache\netlogon.dll [2005.10.10 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\kann_geloescht_werden_WINDOWS\system32\netlogon.dll [2004.08.03 23:57:32 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS.0\$NtServicePackUninstall$\netlogon.dll [2004.08.03 23:57:32 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS.0\system32\netlogon.dll < MD5 for: SCECLI.DLL > [2005.10.10 14:00:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\kann_geloescht_werden_WINDOWS\system32\dllcache\scecli.dll [2005.10.10 14:00:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\kann_geloescht_werden_WINDOWS\system32\scecli.dll [2004.08.03 23:57:34 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS.0\$NtServicePackUninstall$\scecli.dll [2004.08.03 23:57:34 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS.0\system32\scecli.dll < MD5 for: USER32.DLL > [2005.10.10 14:00:00 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A -- C:\kann_geloescht_werden_WINDOWS\system32\dllcache\user32.dll [2005.10.10 14:00:00 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A -- C:\kann_geloescht_werden_WINDOWS\system32\user32.dll [2005.03.02 20:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS.0\$hf_mig$\KB890859\SP2QFE\user32.dll [2007.03.08 17:48:39 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=78785EFF8CB90CEC1862A4CCFD9A3C3A -- C:\WINDOWS.0\$hf_mig$\KB925902\SP2QFE\user32.dll [2007.10.09 19:06:46 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=78785EFF8CB90CEC1862A4CCFD9A3C3A -- C:\WINDOWS.0\$NtServicePackUninstall$\user32.dll [2007.10.09 19:06:46 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=78785EFF8CB90CEC1862A4CCFD9A3C3A -- C:\WINDOWS.0\system32\user32.dll < MD5 for: USERINIT.EXE > [2005.10.10 14:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\kann_geloescht_werden_WINDOWS\system32\dllcache\userinit.exe [2005.10.10 14:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\kann_geloescht_werden_WINDOWS\system32\userinit.exe [2004.08.03 23:58:18 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS.0\$NtServicePackUninstall$\userinit.exe [2004.08.03 23:58:18 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS.0\system32\userinit.exe < MD5 for: WINLOGON.EXE > [2005.10.10 14:00:00 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\kann_geloescht_werden_WINDOWS\system32\dllcache\winlogon.exe [2005.10.10 14:00:00 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\kann_geloescht_werden_WINDOWS\system32\winlogon.exe [2004.08.03 23:58:20 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS.0\$NtServicePackUninstall$\winlogon.exe [2004.08.03 23:58:20 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS.0\system32\winlogon.exe < MD5 for: WS2IFSL.SYS > [2005.10.10 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\kann_geloescht_werden_WINDOWS\system32\dllcache\ws2ifsl.sys [2005.10.10 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\kann_geloescht_werden_WINDOWS\system32\drivers\ws2ifsl.sys [2001.08.23 13:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS.0\system32\drivers\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > [2010.06.15 18:23:48 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS.0\system32\drivers\sptd.sys < %systemroot%\System32\config\*.sav > [2008.07.25 17:46:53 | 000,262,144 | ---- | M] () -- C:\WINDOWS.0\System32\config\default.sav [2008.07.25 15:42:11 | 000,262,144 | ---- | M] () -- C:\WINDOWS.0\System32\config\security.sav [2008.07.25 17:46:53 | 025,165,824 | ---- | M] () -- C:\WINDOWS.0\System32\config\software.sav [2008.07.25 17:46:55 | 006,553,600 | ---- | M] () -- C:\WINDOWS.0\System32\config\system.sav < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [45 C:\WINDOWS.0\system32\*.tmp files -> C:\WINDOWS.0\system32\*.tmp -> ] < End of report > Ich hoffe sie können mir weiterhelfen, ich weiß echt nicht was ich machen soll glg zacoleon Geändert von zacoleon (07.07.2011 um 19:07 Uhr) |
07.07.2011, 18:48 | #2 |
| Virenproblem HTML/Drop.Agent.AB Extra Text:OTL EXTRAS Logfile:
__________________Code:
ATTFilter OTL Extras logfile created on: 07.07.2011 19:06:12 - Run 1 OTL by OldTimer - Version 3.2.26.1 Folder = C:\Dokumente und Einstellungen\Administrator.HOME-PC\Eigene Dateien\Downloads Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,22 Gb Available Physical Memory | 60,89% Memory free 3,85 Gb Paging File | 3,06 Gb Available in Paging File | 79,59% Paging File free Paging file location(s): d:\pagefile.sys 2048 2048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.0 | %ProgramFiles% = C:\Programme Drive C: | 100,00 Gb Total Space | 1,64 Gb Free Space | 1,64% Space Free | Partition Type: NTFS Drive D: | 132,82 Gb Total Space | 12,94 Gb Free Space | 9,74% Space Free | Partition Type: NTFS Computer Name: HOME-PC | User Name: Administrator | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* [HKEY_USERS\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /k "cd %L" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Programme\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Programme\Winamp\Winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Programme\Winamp\Winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Programme\ICQ7.5\ICQ.exe" = C:\Programme\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5 -- (ICQ, LLC.) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Programme\ICQ6\ICQ.exe" = C:\Programme\ICQ6\ICQ.exe:*:Enabled:ICQ Library "C:\Programme\LimeWire\LimeWire.exe" = C:\Programme\LimeWire\LimeWire.exe:*:Enabled:LimeWire "C:\Programme\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe" = C:\Programme\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis_32 -- (Crytek GmbH) "C:\Programme\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe" = C:\Programme\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32 -- (Crytek GmbH) "C:\Programme\Valve\hl.exe" = C:\Programme\Valve\hl.exe:*:Disabled:Half-Life Launcher "C:\Programme\Metin2_Germany\metin2.bin" = C:\Programme\Metin2_Germany\metin2.bin:*:Enabled:metin2 "C:\Programme\Far Cry\Bin32\FarCry.exe" = C:\Programme\Far Cry\Bin32\FarCry.exe:*:Disabled:Far Cry "C:\Programme\GIGABYTE\@BIOS\gwflash.exe" = C:\Programme\GIGABYTE\@BIOS\gwflash.exe:*:Enabled:@BIOS Application -- () "C:\Programme\ICQ7.5\ICQ.exe" = C:\Programme\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5 -- (ICQ, LLC.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis(R) "{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable "{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{05D6AEBA-03FA-492E-9B10-412E4FF0E742}" = NeroVision Express Plugins "{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan "{0DABCF4F-75AA-5330-D82A-5BE4642CD6B2}" = CCC Help Italian "{0E592C31-09EF-3CA1-A7DE-05D13DFCF791}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - deu "{13168936-AABD-6EDF-5CBE-8C8FE6D97569}" = ccc-core-preinstall "{13B792AA-C078-43A4-8A3A-8B12D629940D}" = Counter-Strike 1.6 "{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan "{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg "{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20F1FFAF-1BFF-450C-A8C7-03D1BE24B950}" = Microsoft .NET Framework (German) "{23352C40-1797-7C93-432A-ACBB1BEE1F58}" = CCC Help Dutch "{236BB7C4-4419-42FD-0407-1E257A25E34D}" = Adobe Photoshop CS2 "{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2 "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3 "{29F05234-DCBB-4FE0-88DC-5160C9250312}" = Adobe Photoshop CS3 "{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}" = Microsoft Games for Windows - LIVE "{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox "{2F353D44-73BB-4971-B31D-F7642E9E9531}" = Macromedia Flash MX 2004 "{2FDFD600-7338-4738-90D5-FC4ACA08DC36}" = Pro Evolution Soccer 2008 "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5 "{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types "{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision "{38B39865-D988-4945-9A22-6107B8B40953}" = C4200 "{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMB36X Raid Configurer "{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2 "{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch "{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{3FF55F91-4296-46D0-B045-1429CD46AF99}" = Adobe Setup "{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36 "{49B9ADB0-65A6-6F4B-4C79-182565EF5B70}" = CCC Help German "{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc "{4A8B461A-9336-4CF9-98F4-14DD38E673F0}" = BioShock 2 "{4AA5B8A5-BEEF-4AD8-B11D-4443A042EA4F}" = Adobe Dreamweaver CS3 "{50CE21D8-0F44-4f3f-A392-7F9AD3194DEF}" = PS_AIO_Software "{538E852C-1064-46EF-9B24-6EC9B1494792}" = Steuersparer 2011 "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{5CCBE1E4-20C5-B6E5-7537-51E9EA12386A}" = Catalyst Control Center Core Implementation "{6003C4F2-F6CA-7FA7-6463-D45EE6339016}" = CCC Help Japanese "{622E99D8-88A8-0370-C81E-E6F2AB2D0A6F}" = Catalyst Control Center Graphics Light "{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0 "{639205FC-A8C3-A655-ACF8-8B13A753242F}" = Catalyst Control Center InstallProxy "{665DE588-1296-5B7C-4BBB-37C346D53C1E}" = Catalyst Control Center Graphics Previews Common "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder "{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All "{6B2F4031-ECE8-84B2-3582-432C6BFF1E5D}" = Catalyst Control Center Localization All "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder "{7148F0A8-6813-11D6-A77B-00B0D0142050}" = Java 2 Runtime Environment, SE v1.4.2_05 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{738B0934-6676-44F6-AB52-32F4E60DCA7F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools (Deutsch) "{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5 "{760422FB-5441-E547-BC54-BA4CF9A7412B}" = CCC Help Danish "{7A2FD295-38D2-4AAF-BF41-2C95EBB96126}" = Moorhuhn Kart 2 XXL "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{7D386596-0E80-4808-8AAE-C1DDA8212F7F}" = Adobe Setup "{7E19B002-4CA3-4C9F-BA92-91D101B97219}" = James Cameron's AVATAR(tm): DAS SPIEL "{7F3AD00A-1819-4B15-BB7D-08B3586336D7}" = 3DMark06 "{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3 "{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 2.9.9 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{84CD6277-A61C-6A9B-F064-25E84773EE3B}" = CCC Help English "{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Patch "{8641C1CB-03B3-41d4-8DEC-79826A4B5C0E}" = HP Photosmart All-In-One Software 8.0 "{868D7896-99D4-4513-BC62-2B3AD3E24926}" = TuneUp Utilities 2006 "{86EF9FC4-F209-4520-B7E1-C7FF0EEBDFFF}" = Adobe Audition 1.5 "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder "{89AC76C9-40F1-4D45-5C66-E4F4DA3E8C5A}" = CCC Help Swedish "{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8C13BEE4-E7CE-4E46-BD13-8F41DAD00FEF}" = SweetIM Toolbar for Internet Explorer 3.4 "{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update "{8CFA9151-6404-409A-AF22-4632D04582FD}" = Assassin's Creed "{8D538DFC-1E7A-45F0-9C7B-D8B6629CC2DC}" = PowerQuest Drive Image 7.0 "{8E309767-4214-4A04-AB88-FE86155FC151}" = Race Driver "{8F714418-F3C3-3BF0-B548-E4BDA7AD41DE}" = Microsoft Visual Basic 2008 Express Edition with SP1 - DEU "{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{90170407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003 "{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch "{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype(TM) "{95120000-0052-0407-0000-0000000FF1CE}" = Microsoft Office Visio Viewer 2007 "{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch "{95F51757-60D3-0A62-E790-DC7F378298D3}" = Catalyst Control Center Graphics Full Existing "{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status "{97BBECCF-B1FD-4010-8D4B-EFC9E3CCEECF}" = Driver Whiz "{993960EE-CA4D-443F-8F88-E24260DD5FD2}" = LG PC Suite "{995BF1A7-30E5-49E5-A0E4-AD3213D9E330}" = Labtec WebCam "{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations "{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter "{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy "{A625D45F-1DC4-47FB-ABCF-6B27684AA717}" = OpenOffice.org 2.3 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}" = Google Earth Plug-in "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder "{AC76BA86-7AD7-1031-7B44-A81200000003}" = Adobe Reader 8.1.2 - Deutsch "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS Ver.2.01 "{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support "{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup "{B45F8388-9D26-438D-8C68-3F4E2FA0B577}" = Nero 6 VideoPlugins "{B668B2B8-70D4-4754-A890-17C1DDDA9418}" = PS_AIO_Software_min "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3 "{B9C0477C-4DC7-A460-86A5-5CF46FAC9953}" = CCC Help Spanish "{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3 "{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm "{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support "{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU "{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour "{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU "{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver "{C46B9153-9476-03E0-B799-72B9987B51C3}" = ccc-core-static "{C580908C-B3BA-4C19-BD60-16F02F272201}" = BattleForge™ "{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update "{C716522C-3731-4667-8579-40B098294500}" = Toolbox "{C897FCB3-2F8B-4185-8035-79E2AF3A92A4}" = iTunes "{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver "{C9D456FD-C25B-49DE-AA71-6B76D6550B23}" = Adobe Fireworks CS3 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader "{D3996160-705D-DAC7-FADC-4498E7275D58}" = ATI AVIVO Codecs "{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3 "{D9BE48FD-7121-BAE0-8959-6930441C4094}" = CCC Help Chinese Traditional "{DE8E21F2-C478-58B4-2760-15ACB52130A9}" = ccc-utility "{DFE4B4DF-ADD5-47F8-220B-A1739AFD3426}" = CCC Help Norwegian "{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport "{E17BF866-3732-2380-E6D0-CB7CD76380D8}" = CCC Help Finnish "{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM) "{E65CA2A8-1F2A-4400-AE55-FFD43D3B6980}" = c4200_Help "{E65E137D-F81C-4F7E-9C61-DB618D72DD7A}" = Nero 6 AudioPlugins "{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator "{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential "{EB564D17-E76F-7659-1CAB-96C0966A3AEF}" = CCC Help Chinese Standard "{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply "{EC87E256-B0A4-4A41-8682-AB57FF21196D}" = SweetIM for Messenger 2.7 "{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = PC Camera-168 "{F01F79AD-1F47-4685-AE4E-CCFA4EA9FF7C}" = Adobe Setup "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer "{F2AC9D5E-42EC-C77E-B224-ED391CA7FEA8}" = ATI Catalyst Install Manager "{F49B85B8-0D0E-7F2F-CCF3-53EF106CC1D3}" = Skins "{F5622E83-86B5-4C03-BA6B-26028F83D2B6}" = Catalyst Control Center - Branding "{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects "{FA440BE8-EC2F-4478-A01A-077DA0606501}" = Microsoft SQL Server Compact 3.5 SP1 (Deutsch) "{FC63CAEA-1900-0C26-E1DD-AC12CF19A939}" = CCC Help French "{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT-Erweiterung für den Microsoft Windows XP-Assistenten zum Schreiben von CDs "{FE0C305A-37EE-4499-B4CF-0182E37B20C4}" = PS_AIO_ProductContext "{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp "{FFAA01ED-BEEC-4578-87D5-90E1C7A6D230}" = MSI US54EX Wireless Client Utility "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0407-1E257A25E34D}" = Adobe Photoshop CS2 "Adobe_25db75244653b42cb93dc27939d1c0e" = Adobe Dreamweaver CS3 "Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2 "Adobe_5f143314a5d434c8511097393d17397" = Adobe Photoshop CS3 "Adobe_6c7ed6c08f4acf68bf0512885eec384" = Adobe Fireworks CS3 "AntiVir PersonalEdition Classic" = Avira AntiVir Personal - Free Antivirus "AnyDVD" = AnyDVD "AP Tuner 3.08" = AP Tuner 3.08 "ATI Display Driver" = ATI Display Driver "Bagger-Simulator 2008" = Bagger-Simulator 2008 "Bagger-Simulator 2011 (Demo)" = Bagger-Simulator 2011 (Demo) "CloneCD" = CloneCD "CloneDVD2" = CloneDVD2 "COD4MW Screensaver" = COD4MW Screensaver "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "EAX Unified" = EAX Unified "Free Audio CD Burner_is1" = Free Audio CD Burner version 1.2 "Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.2 "GameSpy Arcade" = GameSpy Arcade "Google Desktop" = Google Desktop "HP Imaging Device Functions" = HP Imaging Device Functions 8.0 "HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0 "HPExtendedCapabilities" = HP Customer Participation Program 8.0 "HPOCR" = HP OCR Software 8.0 "ICQToolbar" = ICQ Toolbar "ie8" = Windows Internet Explorer 8 "InstallShield_{2FDFD600-7338-4738-90D5-FC4ACA08DC36}" = Pro Evolution Soccer 2008 "InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch "InstallShield_{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch "InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch "InstallShield_{8E309767-4214-4A04-AB88-FE86155FC151}" = Race Driver "InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch "InstallShield_{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype(TM) "InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM) "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework Full v1.0.3705 (1031)" = Microsoft .NET Framework (German) v1.0.3705 "Microsoft Visual Basic 2008 Express Edition with SP1 - DEU" = Microsoft Visual Basic 2008 Express Edition mit SP1 - DEU "Mozilla Firefox 5.0 (x86 de)" = Mozilla Firefox 5.0 (x86 de) "Mozilla Thunderbird (2.0.0.21)" = Mozilla Thunderbird (2.0.0.21) "Nero - Burning Rom!UninstallKey" = Nero 6 Enterprise Edition "NeroVision!UninstallKey" = Nero Digital "Notepad++" = Notepad++ "NVIDIA Drivers" = NVIDIA Drivers "PartyPokerNet" = PartyPoker.net "PokerStars.net" = PokerStars.net "QcDrv" = Labtec® Camera-Treiber "RivaTuner" = RivaTuner v2.0 Final Release "Scribus 1.3.3.12" = Scribus 1.3.3.12 "SystemRequirementsLab" = System Requirements Lab "TeamSpeak 3 Client" = TeamSpeak 3 Client "Uninstall_is1" = Uninstall 1.0.0.1 "Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions "VLC media player" = VideoLAN VLC media player 0.8.2 "WIC" = Windows Imaging Component "Winamp" = Winamp (remove only) "Windows Media Format Runtime" = Windows Media Format Runtime "Windows Media Player" = Windows Media Player 10 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinGimp-2.0_is1" = GIMP 2.6.8 "WinRAR archiver" = WinRAR "XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0 "Yahoo! Companion" = Yahoo! Companion ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1801674531-2000478354-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "QIP 2005" = QIP 2005 8092 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 07.12.2011 12:56:29 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:31 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:33 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:35 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:36 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:38 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:40 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:41 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:43 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:44 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. [ Application Events ] Error - 07.12.2011 12:56:29 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:31 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:33 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:35 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:36 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:38 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:40 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:41 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:43 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error - 07.12.2011 12:56:44 | Computer Name = HOME-PC | Source = MsiInstaller | ID = 11706 Description = Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. [ System Events ] Error - 04.12.2011 19:24:28 | Computer Name = HOME-PC | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1083" aufgetreten, als der Dienst "BITS" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 04.12.2011 19:24:29 | Computer Name = HOME-PC | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1083" aufgetreten, als der Dienst "BITS" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 05.12.2011 07:23:35 | Computer Name = HOME-PC | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1083" aufgetreten, als der Dienst "BITS" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 05.12.2011 07:23:39 | Computer Name = HOME-PC | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1083" aufgetreten, als der Dienst "BITS" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 07.12.2011 08:13:47 | Computer Name = HOME-PC | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1083" aufgetreten, als der Dienst "BITS" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 07.12.2011 08:13:48 | Computer Name = HOME-PC | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1083" aufgetreten, als der Dienst "BITS" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 07.12.2011 08:30:02 | Computer Name = HOME-PC | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1083" aufgetreten, als der Dienst "BITS" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 07.12.2011 08:30:06 | Computer Name = HOME-PC | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1083" aufgetreten, als der Dienst "BITS" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 07.12.2011 13:23:36 | Computer Name = HOME-PC | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1083" aufgetreten, als der Dienst "BITS" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 07.12.2011 13:23:39 | Computer Name = HOME-PC | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1083" aufgetreten, als der Dienst "BITS" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {4991D34B-80A1-4291-83B6-3328366B9097} < End of report > |
07.07.2011, 19:58 | #3 |
/// Malware-holic | Virenproblem HTML/Drop.Agent.AB bitte erstelle und poste ein combofix log.
__________________Ein Leitfaden und Tutorium zur Nutzung von ComboFix
__________________ |
Themen zu Virenproblem HTML/Drop.Agent.AB |
0x00000001, adobe, antivir guard, avira, bho, bonjour, desktop, einstellungen, error, explorer, firefox, format, google earth, helper.exe, intranet, logfile, mozilla, mozilla thunderbird, nvidia, object, pdf, plug-in, problem, realtek, registry, rundll, scan, sched.exe, software, sptd.sys, sweetim, teamspeak, usb, version=1.0, winlogon.exe |