Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 25.01.2012, 20:02   #1
karken1994
 
Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner - Standard

Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner



Hayho
Bin neu hier und hoffe mache alles richtig
Also ich hab diesen Virus zu dem viele momentan was schreiben. Ich habe auch schon das OTL-Programm runtergeladen und ein Protokoll gemacht jetzt hab ich aber 2 und weiß nicht welches ich posten soll und ob ich nicht vor dem Protokoll machen noch was eingeben soll.

Danke schon mal

Alt 25.01.2012, 20:05   #2
markusg
/// Malware-holic
 
Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner - Standard

Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner



hi, beide bitte :-)
__________________

__________________

Alt 25.01.2012, 20:11   #3
karken1994
 
Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner - Standard

Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner



Otl
[spoiler ]OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 25.01.2012 18:22:46 - Run 1
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,53 Gb Available Physical Memory | 76,28% Memory free
3,85 Gb Paging File | 3,57 Gb Available in Paging File | 92,62% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.0 | %ProgramFiles% = C:\Programme
Drive C: | 117,19 Gb Total Space | 17,80 Gb Free Space | 15,19% Space Free | Partition Type: NTFS
Drive D: | 87,89 Gb Total Space | 11,29 Gb Free Space | 12,84% Space Free | Partition Type: NTFS
Drive E: | 27,80 Gb Total Space | 1,50 Gb Free Space | 5,40% Space Free | Partition Type: NTFS
 
Computer Name: STEPHAQN | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.01.25 18:14:02 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\24960-OTL.exe
PRC - [2011.11.10 07:04:50 | 000,370,504 | ---- | M] (Splashtop Inc.) -- C:\Programme\Splashtop\Splashtop Software Updater\SSUService.exe
PRC - [2011.09.09 10:13:20 | 000,518,472 | ---- | M] (Splashtop Inc.) -- C:\Programme\Splashtop\Splashtop Remote\Server\SRService.exe
PRC - [2011.08.15 16:18:14 | 001,955,208 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2011.08.15 16:18:10 | 001,361,288 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe
PRC - [2011.02.18 16:37:16 | 000,037,664 | ---- | M] (Apple Inc.) -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010.11.21 10:49:24 | 000,247,608 | ---- | M] () -- C:\Programme\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.10.29 14:49:28 | 000,249,064 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
PRC - [2010.04.30 12:56:04 | 000,160,424 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\WINDOWS.0\starter4g.exe
PRC - [2010.04.30 12:55:54 | 000,145,064 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\WINDOWS.0\service4g.exe
PRC - [2010.04.12 18:03:44 | 000,329,168 | ---- | M] () -- C:\Programme\XSManager\WTGService.exe
PRC - [2009.10.11 20:22:14 | 000,207,360 | ---- | M] (AVM Berlin) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Apps\2.0\6TQBAN4L.25E\2VP395VW.0D2\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe
PRC - [2008.04.23 02:08:13 | 000,483,328 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\Adobe\Acrobat 7.0\Distillr\acrotray.exe
PRC - [2008.04.15 02:40:39 | 000,032,256 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
PRC - [2008.04.14 06:52:46 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS.0\explorer.exe
PRC - [2008.04.14 06:52:46 | 000,059,904 | ---- | M] (Корпорация Майкрософт) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\firefox.exe
PRC - [2007.11.05 14:28:10 | 000,204,915 | ---- | M] (Option) -- C:\Programme\T-Mobile\web'n'walk Manager\GtDetectSc.exe
PRC - [2007.03.02 16:55:30 | 000,278,608 | ---- | M] () -- C:\Programme\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
PRC - [2005.08.24 01:29:52 | 000,118,272 | ---- | M] (TuneUp Software GmbH) -- C:\Programme\TuneUpUtilities2006\WinStylerThemeSvc.exe
PRC - [2003.03.20 07:21:00 | 001,855,488 | ---- | M] (C-Media Electronic Inc. (www.cmedia.com.tw)) -- C:\WINDOWS.0\mixer.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.02.24 01:57:18 | 000,555,112 | ---- | M] () -- C:\Programme\NVIDIA Corporation\nView\nvShell.dll
MOD - [2010.11.21 10:49:24 | 000,247,608 | ---- | M] () -- C:\Programme\ICQ6Toolbar\ICQ Service.exe
MOD - [2010.09.16 16:18:47 | 000,539,648 | ---- | M] () -- C:\WINDOWS.0\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\b4dc4bd8534d90fbb7430926ad990cd9\PresentationFramework.Luna.ni.dll
MOD - [2010.09.16 16:18:05 | 014,320,128 | ---- | M] () -- C:\WINDOWS.0\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9519494798a88867406b5755e1dbded6\PresentationFramework.ni.dll
MOD - [2010.09.16 16:17:47 | 012,428,800 | ---- | M] () -- C:\WINDOWS.0\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\9a254c455892c02355ab0ab0f0727c5b\System.Windows.Forms.ni.dll
MOD - [2010.09.16 16:17:39 | 001,587,200 | ---- | M] () -- C:\WINDOWS.0\assembly\NativeImages_v2.0.50727_32\System.Drawing\6978f2e90f13bc720d57fa6895c911e2\System.Drawing.ni.dll
MOD - [2010.09.16 16:17:38 | 001,800,704 | ---- | M] () -- C:\WINDOWS.0\assembly\NativeImages_v2.0.50727_32\System.Deployment\df1efcbac5973454c608890f72eb994d\System.Deployment.ni.dll
MOD - [2010.09.16 16:17:34 | 012,213,248 | ---- | M] () -- C:\WINDOWS.0\assembly\NativeImages_v2.0.50727_32\PresentationCore\12dcb10b76012416357bdbb010fdaa97\PresentationCore.ni.dll
MOD - [2010.09.16 16:17:23 | 003,311,104 | ---- | M] () -- C:\WINDOWS.0\assembly\NativeImages_v2.0.50727_32\WindowsBase\df20e56b59b1b1a595af305ddc0777ba\WindowsBase.ni.dll
MOD - [2010.09.16 16:17:15 | 005,449,728 | ---- | M] () -- C:\WINDOWS.0\assembly\NativeImages_v2.0.50727_32\System.Xml\36f3953f24d4f0b767bf172331ad6f3e\System.Xml.ni.dll
MOD - [2010.09.16 16:17:11 | 000,970,752 | ---- | M] () -- C:\WINDOWS.0\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb4cb21d14767292e079366a5d3d76cd\System.Configuration.ni.dll
MOD - [2010.09.16 16:17:08 | 007,867,392 | ---- | M] () -- C:\WINDOWS.0\assembly\NativeImages_v2.0.50727_32\System\aa7926460a336408c8041330ad90929d\System.ni.dll
MOD - [2010.09.16 16:17:01 | 011,485,184 | ---- | M] () -- C:\WINDOWS.0\assembly\NativeImages_v2.0.50727_32\mscorlib\9adb89fa22fd5b4ce433b5aca7fb1b07\mscorlib.ni.dll
MOD - [2010.09.16 16:04:55 | 000,249,856 | ---- | M] () -- C:\WINDOWS.0\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_de_31bf3856ad364e35\PresentationFramework.resources.dll
MOD - [2010.09.16 16:04:26 | 000,413,696 | ---- | M] () -- C:\WINDOWS.0\assembly\GAC_MSIL\System.Deployment.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Deployment.resources.dll
MOD - [2010.04.12 18:03:44 | 000,329,168 | ---- | M] () -- C:\Programme\XSManager\WTGService.exe
MOD - [2009.10.11 20:22:03 | 000,368,640 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Apps\2.0\6TQBAN4L.25E\2VP395VW.0D2\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\managedupnp.dll
MOD - [2008.04.14 06:53:08 | 000,056,832 | ---- | M] () -- C:\WINDOWS.0\system32\MSDvbNP.ax
MOD - [2008.04.14 06:53:08 | 000,033,280 | ---- | M] () -- C:\WINDOWS.0\system32\PsisRndr.ax
MOD - [2008.04.14 06:52:24 | 000,363,520 | ---- | M] () -- C:\WINDOWS.0\system32\PsisDecd.dll
MOD - [2008.04.14 06:52:18 | 000,014,336 | ---- | M] () -- C:\WINDOWS.0\system32\msdmo.dll
MOD - [2007.03.02 16:55:30 | 000,278,608 | ---- | M] () -- C:\Programme\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
MOD - [2007.03.02 16:55:16 | 000,241,750 | ---- | M] () -- C:\Programme\CyberLink\PowerCinema\Kernel\TV\CLCapEngine.dll
MOD - [2006.01.12 21:20:48 | 001,265,664 | ---- | M] () -- C:\Programme\Adobe\Acrobat 7.0\Distillr\adistres.DEU
MOD - [2006.01.12 21:20:26 | 000,019,968 | ---- | M] () -- C:\Programme\Adobe\Acrobat 7.0\Distillr\acrotray.DEU
MOD - [2006.01.12 21:13:46 | 000,019,968 | ---- | M] () -- C:\Programme\Adobe\Acrobat 7.0\Distillr\acrotray.FRA
MOD - [2005.10.19 10:56:28 | 000,125,952 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2005.08.24 01:29:52 | 000,076,288 | ---- | M] () -- C:\Programme\TuneUpUtilities2006\WinStylerThemeHelper.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] --  -- (ServiceLayer)
SRV - File not found [On_Demand | Stopped] --  -- (McComponentHostService)
SRV - [2011.11.10 07:04:50 | 000,370,504 | ---- | M] (Splashtop Inc.) [Auto | Running] -- C:\Programme\Splashtop\Splashtop Software Updater\SSUService.exe -- (SSUService)
SRV - [2011.09.09 10:13:20 | 000,518,472 | ---- | M] (Splashtop Inc.) [Auto | Running] -- C:\Programme\Splashtop\Splashtop Remote\Server\SRService.exe -- (SplashtopRemoteService)
SRV - [2011.08.15 16:18:10 | 001,361,288 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2011.02.18 16:37:16 | 000,037,664 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010.11.21 10:49:24 | 000,247,608 | ---- | M] () [Auto | Running] -- C:\Programme\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.04.30 12:55:54 | 000,145,064 | R--- | M] (4G Systems GmbH & Co. KG) [Auto | Running] -- C:\WINDOWS.0\service4g.exe -- (XS Stick Service)
SRV - [2010.04.12 18:03:44 | 000,329,168 | ---- | M] () [Auto | Running] -- C:\Programme\XSManager\WTGService.exe -- (WTGService)
SRV - [2009.04.22 22:45:34 | 000,098,488 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2009.04.08 19:54:12 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009.04.05 12:28:54 | 000,072,704 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2007.11.05 14:28:10 | 000,204,915 | ---- | M] (Option) [Auto | Running] -- C:\Programme\T-Mobile\web'n'walk Manager\GtDetectSc.exe -- (GtDetectSc)
SRV - [2007.03.02 16:55:30 | 000,278,608 | ---- | M] () [Auto | Running] -- C:\Programme\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe -- (CLCapSvc) CyberLink Background Capture Service (CBCS)
SRV - [2007.03.02 16:55:30 | 000,110,677 | ---- | M] () [Auto | Stopped] -- C:\Programme\CyberLink\PowerCinema\Kernel\TV\CLSched.exe -- (CLSched) CyberLink Task Scheduler (CTS)
SRV - [2006.06.01 20:06:00 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2005.08.24 01:29:52 | 000,118,272 | ---- | M] (TuneUp Software GmbH) [Auto | Running] -- C:\Programme\TuneUpUtilities2006\WinStylerThemeSvc.exe -- (TUWinStylerThemeSvc)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.11.08 18:43:59 | 000,103,424 | ---- | M] (Mobile Connector) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\cmnsusbser.sys -- (cmnsusbser)
DRV - [2011.10.09 19:31:48 | 000,101,248 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\WINDOWS.0\system32\drivers\avmaudio.sys -- (avmaudio)
DRV - [2011.09.16 07:24:26 | 000,070,400 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\lgandnetndis.sys -- (andnetndis)
DRV - [2011.02.14 02:42:36 | 000,020,864 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2011.02.14 02:42:34 | 000,025,216 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2011.02.14 02:42:32 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2010.12.07 14:23:00 | 000,025,088 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\lgandmodem.sys -- (ANDModem)
DRV - [2010.12.07 14:23:00 | 000,020,736 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\lganddiag.sys -- (AndDiag)
DRV - [2010.12.07 14:23:00 | 000,020,096 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\lgandgps.sys -- (AndGps)
DRV - [2010.12.07 14:22:58 | 000,014,336 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\lgandbus.sys -- (Andbus)
DRV - [2010.08.02 16:19:22 | 000,025,728 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\lgandadb.sys -- (androidusb)
DRV - [2010.07.05 21:50:42 | 000,029,000 | ---- | M] (Senstic) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\camsource.sys -- (avshws)
DRV - [2010.03.02 21:57:06 | 000,031,304 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\senaudio.sys -- (PocketAudio) Senstic PocketAudio (WDM)
DRV - [2010.02.03 15:56:56 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.0\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009.10.11 20:22:05 | 000,101,248 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\WINDOWS.0\system32\drivers\avmaura.sys -- (avmaura)
DRV - [2009.06.19 15:59:34 | 000,019,712 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\motccgp.sys -- (motccgp)
DRV - [2009.05.08 10:56:12 | 000,042,752 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\motodrv.sys -- (MotDev)
DRV - [2009.04.12 22:51:26 | 000,026,216 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3\WNt500x86\sandra.sys -- (SANDRA)
DRV - [2009.04.07 13:36:34 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS.0\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009.01.29 16:18:00 | 000,008,320 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\motccgpfl.sys -- (motccgpfl)
DRV - [2009.01.29 16:15:54 | 000,023,680 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\motmodem.sys -- (motmodem)
DRV - [2008.04.14 00:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS.0\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008.04.13 23:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\MPE.sys -- (MPE)
DRV - [2008.01.03 15:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\WINDOWS.0\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007.07.09 14:17:36 | 000,095,744 | ---- | M] (Option NV) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\Gt51Ip.sys -- (GT72NDISIPXP)
DRV - [2007.06.26 13:38:46 | 000,051,968 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\gt72ubus.sys -- (GT72UBUS)
DRV - [2007.05.23 04:20:58 | 000,036,496 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2007.04.26 10:33:52 | 001,482,048 | R--- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\cmuda3.sys -- (cmuda3)
DRV - [2007.03.30 13:38:14 | 000,008,064 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\gtptser.sys -- (GTPTSER)
DRV - [2007.02.22 11:15:56 | 000,137,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\nmwcd.sys -- (nmwcd)
DRV - [2007.02.22 11:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\nmwcdcm.sys -- (nmwcdcm)
DRV - [2007.02.22 11:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\nmwcdcj.sys -- (nmwcdcj)
DRV - [2007.02.22 11:15:14 | 000,008,320 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\nmwcdc.sys -- (nmwcdc)
DRV - [2007.01.26 00:00:00 | 000,265,088 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\fwlanusb.sys -- (FWLANUSB)
DRV - [2007.01.26 00:00:00 | 000,004,352 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\avmeject.sys -- (avmeject)
DRV - [2007.01.23 14:44:00 | 000,020,496 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.0\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2006.11.02 07:00:08 | 000,039,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\winusb.sys -- (WinUSB)
DRV - [2006.09.24 14:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS.0\system32\speedfan.sys -- (speedfan)
DRV - [2006.03.27 16:53:28 | 000,167,808 | ---- | M] (NETGEAR Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\wg111v2.sys -- (RTLWUSB)
DRV - [2005.11.03 15:40:07 | 000,063,488 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS.0\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2005.09.02 15:43:54 | 000,827,008 | R--- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS.0\system32\drivers\3xHybrid.sys -- (3xHybrid)
DRV - [2005.08.10 13:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS.0\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.07.20 14:35:00 | 000,036,480 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\P2k.sys -- (P2k)
DRV - [2005.05.23 19:29:00 | 000,392,448 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\snpstd2.sys -- (snpstd2)
DRV - [2005.05.16 14:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS.0\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2004.05.17 11:21:54 | 000,017,280 | ---- | M] (Intellon, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS.0\system32\plcndis5.sys -- (PLCNDIS5)
DRV - [2002.11.18 08:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS.0\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [2002.10.02 07:57:12 | 000,013,532 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.0\system32\drivers\SjyPkt.sys -- (SjyPkt)
DRV - [1996.04.03 20:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS.0\system32\giveio.sys -- (giveio)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.haokan123.com/
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.0\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.haokan123.com/
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/ig"
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: orbit_ffext@orbitdownloader:2.02
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.7
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q="
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS.0\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS.0\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0:  File not found
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Programme\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Programme\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.01.09 16:42:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2011.10.12 19:59:05 | 000,000,000 | ---D | M]
 
[2009.04.07 13:40:31 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Extensions
[2012.01.23 16:13:10 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\extensions
[2012.01.08 15:36:41 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010.10.25 19:36:35 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.01.23 16:13:10 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011.05.08 11:22:45 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\extensions\engine@conduit.com
[2009.09.16 18:52:55 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\extensions\moveplayer@movenetworks.com
[2011.11.29 18:02:22 | 000,000,933 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\11-suche.xml
[2011.11.29 18:02:22 | 000,002,419 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\englische-ergebnisse.xml
[2011.11.29 18:02:22 | 000,010,525 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\gmx-suche.xml
[2012.01.23 20:15:55 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\icqplugin-1.xml
[2011.03.06 17:13:32 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\icqplugin-2.xml
[2011.03.27 10:39:20 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\icqplugin-3.xml
[2011.04.30 11:59:58 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\icqplugin-4.xml
[2011.05.06 19:48:35 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\icqplugin-5.xml
[2011.05.14 16:39:44 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\icqplugin-6.xml
[2011.06.25 13:06:10 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\icqplugin-7.xml
[2011.08.18 19:50:22 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\icqplugin-8.xml
[2011.08.31 20:26:45 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\icqplugin-9.xml
[2011.03.30 14:14:34 | 000,001,042 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\icqplugin.xml
[2011.11.29 18:02:22 | 000,002,457 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\lastminute.xml
[2011.11.29 18:02:22 | 000,005,508 | ---- | M] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\Mozilla\Firefox\Profiles\00gtti0s.default\searchplugins\webde-suche.xml
[2011.11.13 21:27:06 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.08.29 23:46:24 | 000,000,000 | ---D | M] (Click to call with Skype) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
() (No name found) -- C:\DOKUMENTE UND EINSTELLUNGEN\ADMINISTRATOR.HOME-PC\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\00GTTI0S.DEFAULT\EXTENSIONS\{DC572301-7619-498C-A57D-39143191B318}.XPI
() (No name found) -- C:\DOKUMENTE UND EINSTELLUNGEN\ADMINISTRATOR.HOME-PC\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\00GTTI0S.DEFAULT\EXTENSIONS\TOOLBAR@WEB.DE.XPI
[2009.07.17 10:55:13 | 000,000,000 | ---D | M] (Orbit Downloader Firefox Integration) -- C:\PROGRAMME\ORBITDOWNLOADER\ADDONS\ORBITFF
[2012.01.09 16:42:53 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2011.02.02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll
[2010.07.28 10:20:04 | 000,124,200 | ---- | M] (DeLorme) -- C:\Programme\mozilla firefox\plugins\nppnplugin.dll
[2011.07.11 22:48:12 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\mozilla firefox\plugins\npwachk.dll
[2011.10.07 16:25:25 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.07 16:25:25 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2011.10.07 16:25:25 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.07 16:25:25 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.07 16:25:25 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.07 16:25:25 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.09.22 16:40:58 | 000,000,853 | ---- | M]) - C:\WINDOWS.0\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: 127.0.0.1				activate.adobe.com
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Programme\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Programme\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Programme\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Programme\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Programme\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [C-Media Mixer] C:\WINDOWS.0\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
O4 - HKLM..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Programme\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS.0\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS.0\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [starter4g] C:\WINDOWS.0\starter4g.exe (4G Systems GmbH & Co. KG)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [AVMUSBFernanschluss] C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Apps\2.0\6TQBAN4L.25E\2VP395VW.0D2\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\AVMAutoStart.exe (AVM Berlin)
O4 - HKCU..\Run: [Firefox helper] C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\firefox.exe (Корпорация Майкрософт)
O4 - Startup: C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Startmenü\Programme\Autostart\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS.0\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_Acrobat.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O8 - Extra context menu item: &Download by Orbit - C:\Programme\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Programme\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Programme\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Programme\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Free YouTube Download - C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{36C4384D-8D9A-4433-BA7A-38AD5C0F5CDC}: NameServer = 192.168.178.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS.0\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS.0\system32\userinit.exe) -C:\WINDOWS.0\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.04.05 11:19:45 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{31a87768-0a31-11e1-9db3-0019668e3bbe}\Shell - "" = AutoRun
O33 - MountPoints2\{31a87768-0a31-11e1-9db3-0019668e3bbe}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{31a87768-0a31-11e1-9db3-0019668e3bbe}\Shell\AutoRun\command - "" = J:\autorun.exe
O33 - MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\Shell - "" = Autorun
O33 - MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\Shell\AutoRun\command - "" = C:\WINDOWS.0\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-1-9-90-100002473-100002232-100019806-1353.com f:\
O33 - MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\Shell\Open\command - "" = RECYCLER\S-1-9-90-100002473-100002232-100019806-1353.com f:\
O33 - MountPoints2\{654942e4-2dbd-11de-abc0-0019668e3bbe}\Shell\verb1\command - "" = desktop.exe
O33 - MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\Shell\autoPlay\commaND - "" = raue.cmd
O33 - MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\Shell\AutoRun\command - "" = raue.cmd
O33 - MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\Shell\ExploRE\CoMmANd - "" = raue.cmd
O33 - MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\Shell\open\COmmAnd - "" = raue.cmd
O33 - MountPoints2\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\Shell - "" = AutoRun
O33 - MountPoints2\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\Shell\AutoRun\command - "" = J:\setup.exe AUTORUN=1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.25 18:16:17 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\24960-OTL.exe
[2012.01.04 00:32:30 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Startmenü\Programme\°²»úÍø
[2012.01.03 22:45:25 | 000,581,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS.0\System32\WinUSBCoInstaller.dll
[2010.07.09 18:10:09 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS.0\System32\csnpstd2.dll
[2010.07.09 18:10:09 | 000,036,864 | ---- | C] ( ) -- C:\WINDOWS.0\System32\vsnpstd2.dll
[2010.03.29 20:34:52 | 000,098,304 | ---- | C] ( ) -- C:\WINDOWS.0\System32\rsnpstd2.dll
[58 C:\WINDOWS.0\*.tmp files -> C:\WINDOWS.0\*.tmp -> ]
[3 C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\*.tmp files -> C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\*.tmp -> ]
[2 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.25 18:17:49 | 000,002,323 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Startmenü\Programme\Autostart\Adobe Acrobat Speed Launcher.lnk
[2012.01.25 18:17:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS.0\bootstat.dat
[2012.01.25 18:17:28 | 2146,750,464 | -HS- | M] () -- C:\hiberfil.sys
[2012.01.25 18:14:02 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\24960-OTL.exe
[2012.01.24 18:10:10 | 000,520,090 | ---- | M] () -- C:\WINDOWS.0\System32\perfh007.dat
[2012.01.24 18:10:10 | 000,496,094 | ---- | M] () -- C:\WINDOWS.0\System32\perfh009.dat
[2012.01.24 18:10:10 | 000,101,506 | ---- | M] () -- C:\WINDOWS.0\System32\perfc007.dat
[2012.01.24 18:10:10 | 000,084,578 | ---- | M] () -- C:\WINDOWS.0\System32\perfc009.dat
[2012.01.24 17:03:06 | 000,000,151 | ---- | M] () -- C:\WINDOWS.0\PhotoSnapViewer.INI
[2012.01.23 15:41:01 | 000,002,206 | ---- | M] () -- C:\WINDOWS.0\System32\wpa.dbl
[2012.01.20 17:16:32 | 000,000,408 | ---- | M] () -- C:\WINDOWS.0\tasks\1-Klick-Wartung.job
[2012.01.03 22:58:52 | 000,000,000 | -H-- | M] () -- C:\WINDOWS.0\System32\drivers\Msft_Kernel_WinUSB_01007.Wdf
[2012.01.03 21:56:55 | 000,000,423 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Dokumente\Verknüpfung mit Gemeinsame Dokumente.lnk
[2012.01.03 19:16:02 | 000,000,000 | -H-- | M] () -- C:\WINDOWS.0\System32\drivers\Msft_Kernel_lgandadb_01005.Wdf
[2012.01.03 17:31:44 | 000,002,413 | ---- | M] () -- C:\WINDOWS.0\System32\lgAxconfig.ini
[58 C:\WINDOWS.0\*.tmp files -> C:\WINDOWS.0\*.tmp -> ]
[3 C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\*.tmp files -> C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\*.tmp -> ]
[2 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.01.25 18:17:28 | 2146,750,464 | -HS- | C] () -- C:\hiberfil.sys
[2012.01.03 22:58:52 | 000,000,000 | -H-- | C] () -- C:\WINDOWS.0\System32\drivers\Msft_Kernel_WinUSB_01007.Wdf
[2012.01.03 21:56:55 | 000,000,423 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Dokumente\Verknüpfung mit Gemeinsame Dokumente.lnk
[2012.01.03 19:24:20 | 000,002,323 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Startmenü\Programme\Autostart\Adobe Acrobat Speed Launcher.lnk
[2012.01.03 19:16:02 | 000,000,000 | -H-- | C] () -- C:\WINDOWS.0\System32\drivers\Msft_Kernel_lgandadb_01005.Wdf
[2011.11.06 20:10:08 | 000,000,600 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\PUTTY.RND
[2011.10.22 08:39:02 | 000,053,248 | ---- | C] () -- C:\WINDOWS.0\System32\CommonDL.dll
[2011.10.22 08:39:02 | 000,002,413 | ---- | C] () -- C:\WINDOWS.0\System32\lgAxconfig.ini
[2011.10.10 19:39:35 | 000,103,509 | ---- | C] () -- C:\WINDOWS.0\hpoins04.dat.temp
[2011.10.10 19:39:35 | 000,017,176 | ---- | C] () -- C:\WINDOWS.0\hpomdl04.dat.temp
[2011.04.28 10:46:17 | 000,000,114 | ---- | C] () -- C:\WINDOWS.0\System32\nvUnsupRes.dat
[2011.04.28 01:22:14 | 000,097,360 | ---- | C] () -- C:\WINDOWS.0\System32\drivers\Fwusb1b.bin
[2011.03.04 10:45:35 | 000,000,026 | ---- | C] () -- C:\WINDOWS.0\CMCDPLAY.INI
[2010.11.21 14:26:26 | 000,259,604 | ---- | C] () -- C:\WINDOWS.0\System32\nvdrsdb0.bin
[2010.11.21 14:26:24 | 000,259,604 | ---- | C] () -- C:\WINDOWS.0\System32\nvdrsdb1.bin
[2010.11.21 14:26:24 | 000,000,001 | ---- | C] () -- C:\WINDOWS.0\System32\nvdrssel.bin
[2010.11.21 14:26:02 | 002,116,894 | ---- | C] () -- C:\WINDOWS.0\System32\nvdata.bin
[2010.10.12 21:10:55 | 000,040,508 | -H-- | C] () -- C:\WINDOWS.0\System32\mlfcache.dat
[2010.09.06 17:04:09 | 000,000,010 | ---- | C] () -- C:\WINDOWS.0\WININIT.INI
[2010.07.09 18:10:09 | 000,392,448 | ---- | C] () -- C:\WINDOWS.0\System32\drivers\snpstd2.sys
[2010.07.09 18:10:09 | 000,286,720 | ---- | C] () -- C:\WINDOWS.0\vsnpstd2.exe
[2010.07.09 18:10:09 | 000,053,248 | ---- | C] () -- C:\WINDOWS.0\System32\dsnpstd2.dll
[2010.07.09 18:10:09 | 000,015,541 | ---- | C] () -- C:\WINDOWS.0\snpstd2.ini
[2010.06.29 16:16:38 | 000,000,530 | ---- | C] () -- C:\WINDOWS.0\eReg.dat
[2010.06.28 14:31:28 | 000,000,263 | ---- | C] () -- C:\WINDOWS.0\game.ini
[2009.12.14 19:36:09 | 000,000,111 | ---- | C] () -- C:\WINDOWS.0\telephon.ini
[2009.12.08 18:26:56 | 000,010,240 | ---- | C] () -- C:\WINDOWS.0\System32\vidx16.dll
[2009.12.08 18:26:52 | 000,004,333 | ---- | C] () -- C:\WINDOWS.0\mixerdef.ini
[2009.12.08 18:26:18 | 000,039,279 | ---- | C] () -- C:\WINDOWS.0\cmijack.dat
[2009.12.08 18:26:18 | 000,028,165 | ---- | C] () -- C:\WINDOWS.0\cmijack.ini
[2009.12.08 18:26:17 | 000,023,041 | ---- | C] () -- C:\WINDOWS.0\cmaudio.dat
[2009.12.08 18:26:17 | 000,018,240 | ---- | C] () -- C:\WINDOWS.0\cmaudio.ini
[2009.12.08 18:26:12 | 000,000,411 | ---- | C] () -- C:\WINDOWS.0\CMISETUP.INI
[2009.12.06 12:17:50 | 000,000,056 | -H-- | C] () -- C:\WINDOWS.0\System32\ezsidmv.dat
[2009.12.01 17:51:52 | 000,005,259 | ---- | C] () -- C:\WINDOWS.0\Cmicnfgp.ini.cfg
[2009.12.01 17:51:50 | 000,000,582 | ---- | C] () -- C:\WINDOWS.0\cmudaxp.ini
[2009.11.28 13:38:55 | 000,000,038 | ---- | C] () -- C:\WINDOWS.0\popcinfot.dat
[2009.11.15 15:07:28 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\$_hpcst$.hpc
[2009.11.08 05:09:40 | 000,000,151 | ---- | C] () -- C:\WINDOWS.0\PhotoSnapViewer.INI
[2009.10.12 10:27:12 | 000,000,116 | ---- | C] () -- C:\WINDOWS.0\NeroDigital.ini
[2009.10.11 20:27:30 | 000,103,509 | ---- | C] () -- C:\WINDOWS.0\hpoins04.dat
[2009.10.11 20:27:30 | 000,017,176 | ---- | C] () -- C:\WINDOWS.0\hpomdl04.dat
[2009.09.18 12:20:58 | 000,033,533 | ---- | C] () -- C:\WINDOWS.0\System32\CoreVorbis-uninstall.exe
[2009.09.18 12:20:54 | 000,036,734 | ---- | C] () -- C:\WINDOWS.0\System32\OggDSuninst.exe
[2009.09.18 12:20:22 | 000,077,824 | ---- | C] () -- C:\WINDOWS.0\System32\MMSwitch.dll
[2009.09.18 12:20:22 | 000,040,960 | ---- | C] () -- C:\WINDOWS.0\System32\MMAVILNG.exe
[2009.08.23 16:20:19 | 000,004,981 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\mtbjfghn.xbe
[2009.07.09 13:25:23 | 000,000,065 | ---- | C] () -- C:\WINDOWS.0\FISHUI.INI
[2009.04.28 16:52:30 | 010,059,776 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\sandra.mda
[2009.04.20 09:57:33 | 000,036,864 | ---- | C] () -- C:\WINDOWS.0\System32\cmll10sx.dll
[2009.04.20 09:57:32 | 000,000,530 | ---- | C] () -- C:\WINDOWS.0\System32\tx13_ic.ini
[2009.04.19 16:20:46 | 000,000,406 | ---- | C] () -- C:\WINDOWS.0\ODBC.INI
[2009.04.18 16:49:53 | 000,022,328 | ---- | C] () -- C:\WINDOWS.0\System32\drivers\PnkBstrK.sys
[2009.04.18 16:49:53 | 000,022,328 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Anwendungsdaten\PnkBstrK.sys
[2009.04.18 16:49:08 | 000,103,736 | ---- | C] () -- C:\WINDOWS.0\System32\PnkBstrB.exe
[2009.04.18 16:49:07 | 000,669,184 | ---- | C] () -- C:\WINDOWS.0\System32\pbsvc.exe
[2009.04.18 16:49:07 | 000,066,872 | ---- | C] () -- C:\WINDOWS.0\System32\PnkBstrA.exe
[2009.04.16 12:24:14 | 000,921,600 | ---- | C] () -- C:\WINDOWS.0\System32\vorbisenc.dll
[2009.04.16 12:24:14 | 000,237,568 | ---- | C] () -- C:\WINDOWS.0\System32\OggDS.dll
[2009.04.16 12:24:14 | 000,188,416 | ---- | C] () -- C:\WINDOWS.0\System32\vorbis.dll
[2009.04.16 12:24:14 | 000,045,056 | ---- | C] () -- C:\WINDOWS.0\System32\Ogg.dll
[2009.04.16 10:12:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS.0\ativpsrm.bin
[2009.04.08 14:47:54 | 000,098,816 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.04.07 20:25:27 | 000,003,072 | R--- | C] () -- C:\WINDOWS.0\System32\34CoInstaller.dll
[2009.04.07 20:25:23 | 000,363,520 | ---- | C] () -- C:\WINDOWS.0\System32\PsisDecd.dll
[2009.04.07 14:09:06 | 000,458,752 | R--- | C] () -- C:\WINDOWS.0\System32\Cmeaupci.exe
[2009.04.07 14:09:00 | 000,106,496 | R--- | C] () -- C:\WINDOWS.0\Vmix.dll
[2009.04.07 14:09:00 | 000,000,140 | ---- | C] () -- C:\WINDOWS.0\Cmicnfg3.ini.cfl
[2009.04.07 14:08:37 | 000,065,536 | R--- | C] () -- C:\WINDOWS.0\System32\CmiInstallResAll.dll
[2009.04.07 14:08:37 | 000,003,189 | R--- | C] () -- C:\WINDOWS.0\Cmicnfg3.ini.cfg
[2009.04.07 14:08:37 | 000,000,725 | R--- | C] () -- C:\WINDOWS.0\cmudax3.ini
[2009.04.07 14:08:37 | 000,000,168 | ---- | C] () -- C:\WINDOWS.0\Cmicnfg3.ini.imi
[2009.04.07 14:08:26 | 005,802,528 | -HS- | C] () -- C:\WINDOWS.0\System32\drivers\fidbox.dat
[2009.04.07 14:08:26 | 000,761,888 | -HS- | C] () -- C:\WINDOWS.0\System32\drivers\fidbox2.dat
[2009.04.07 13:40:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS.0\nsreg.dat
[2009.04.07 13:27:46 | 000,000,664 | ---- | C] () -- C:\WINDOWS.0\System32\d3d9caps.dat
[2009.04.07 12:52:20 | 000,004,500 | ---- | C] () -- C:\WINDOWS.0\Ascd_tmp.ini
[2009.04.07 12:52:17 | 000,010,288 | ---- | C] () -- C:\WINDOWS.0\System32\drivers\ASUSHWIO.SYS
[2009.04.06 19:11:11 | 000,004,249 | ---- | C] () -- C:\WINDOWS.0\ODBCINST.INI
[2009.04.06 19:08:21 | 002,083,856 | ---- | C] () -- C:\WINDOWS.0\System32\FNTCACHE.DAT
[2009.04.06 18:23:29 | 000,002,048 | --S- | C] () -- C:\WINDOWS.0\bootstat.dat
[2009.04.06 18:15:13 | 000,021,740 | ---- | C] () -- C:\WINDOWS.0\System32\emptyregdb.dat
[2009.04.05 16:25:57 | 000,228,736 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2008.10.28 16:40:48 | 000,173,552 | ---- | C] () -- C:\WINDOWS.0\System32\xlive.dll.cat
[2007.03.29 23:00:40 | 000,203,264 | R--- | C] () -- C:\WINDOWS.0\System32\CddbCdda.dll
[2006.06.01 20:06:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS.0\System32\oembios.bin
[2006.06.01 20:06:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS.0\System32\mlang.dat
[2006.06.01 20:06:00 | 000,520,090 | ---- | C] () -- C:\WINDOWS.0\System32\perfh007.dat
[2006.06.01 20:06:00 | 000,496,094 | ---- | C] () -- C:\WINDOWS.0\System32\perfh009.dat
[2006.06.01 20:06:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS.0\System32\perfi009.dat
[2006.06.01 20:06:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS.0\System32\perfi007.dat
[2006.06.01 20:06:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS.0\System32\dssec.dat
[2006.06.01 20:06:00 | 000,101,506 | ---- | C] () -- C:\WINDOWS.0\System32\perfc007.dat
[2006.06.01 20:06:00 | 000,084,578 | ---- | C] () -- C:\WINDOWS.0\System32\perfc009.dat
[2006.06.01 20:06:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS.0\System32\mib.bin
[2006.06.01 20:06:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS.0\System32\perfd007.dat
[2006.06.01 20:06:00 | 000,031,232 | R--- | C] () -- C:\WINDOWS.0\System32\cmdow.exe
[2006.06.01 20:06:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS.0\System32\perfd009.dat
[2006.06.01 20:06:00 | 000,005,702 | ---- | C] () -- C:\WINDOWS.0\System32\OUTLPERF.INI
[2006.06.01 20:06:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS.0\System32\secupd.dat
[2006.06.01 20:06:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS.0\System32\oembios.dat
[2006.06.01 20:06:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS.0\System32\dcache.bin
[2006.06.01 20:06:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS.0\System32\noise.dat
[1996.04.03 20:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS.0\System32\giveio.sys
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 122 bytes -> C:\Dokumente und Einstellungen\All Users.WINDOWS.0\Anwendungsdaten\TEMP:5F64C164

< End of report >
         
--- --- ---

[/spoiler ]

Extras
[/spoiler]OTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 25.01.2012 18:22:46 - Run 1
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,53 Gb Available Physical Memory | 76,28% Memory free
3,85 Gb Paging File | 3,57 Gb Available in Paging File | 92,62% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.0 | %ProgramFiles% = C:\Programme
Drive C: | 117,19 Gb Total Space | 17,80 Gb Free Space | 15,19% Space Free | Partition Type: NTFS
Drive D: | 87,89 Gb Total Space | 11,29 Gb Free Space | 12,84% Space Free | Partition Type: NTFS
Drive E: | 27,80 Gb Total Space | 1,50 Gb Free Space | 5,40% Space Free | Partition Type: NTFS
 
Computer Name: STEPHAQN | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /k "cd %L" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"1782:TCP" = 1782:TCP:*:Enabled:SensticPocketServiceWin.exe Operation Port (1782)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5353:TCP" = 5353:TCP:*:Disabled:Adobe CSI CS4
"1782:TCP" = 1782:TCP:*:Enabled:SensticPocketServiceWin.exe Operation Port (1782)
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Programme\ICQ7.5\ICQ.exe" = C:\Programme\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5 -- (ICQ, LLC.)
"C:\Programme\Ipod Software\PocketControl\SensticPocketServiceWin.exe" = C:\Programme\Ipod Software\PocketControl\SensticPocketServiceWin.exe:*:Enabled:SensticPocketServiceWin.exe
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\GTA4\Grand Theft Auto IV\LaunchGTAIV.exe" = D:\GTA4\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV -- ()
"\\HURENSOHN\BlueSoleil\BlueSoleil.exe" = \\HURENSOHN\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil
"C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3\RpcAgentSrv.exe" = C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service -- (SiSoftware)
"D:\Crysis\Bin32\Crysis.exe" = D:\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis_32 -- (Crytek GmbH)
"D:\Crysis\Bin32\CrysisDedicatedServer.exe" = D:\Crysis\Bin32\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32 -- (Crytek GmbH)
"C:\WINDOWS.0\system32\muzapp.exe" = C:\WINDOWS.0\system32\muzapp.exe:*:Enabled:MUZ AOD APP player -- (Musiccity Co.Ltd.)
"C:\Programme\Orbitdownloader\orbitdm.exe" = C:\Programme\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Programme\Orbitdownloader\orbitnet.exe" = C:\Programme\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Programme\Gemeinsame Dateien\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Programme\Gemeinsame Dateien\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Disabled:Adobe CSI CS4 -- (Adobe Systems Incorporated)
"D:\TmNationsForever\TmNationsForever\TmForever.exe" = D:\TmNationsForever\TmNationsForever\TmForever.exe:*:Enabled:TmForever -- ()
"C:\Programme\ICQ6.5\ICQ.exe" = C:\Programme\ICQ6.5\ICQ.exe:*:Enabled:ICQ
"D:\GTA4\Grand Theft Auto IV\GTAIV.exe" = D:\GTA4\Grand Theft Auto IV\GTAIV.exe:*:Enabled:Grand Theft Auto IV -- (Take-Two Interactive Software, Inc.)
"D:\World of Warcraft (3.0.9)\WoW-3.2.0.10192-to-3.2.0.10314-deDE-downloader.exe" = D:\World of Warcraft (3.0.9)\WoW-3.2.0.10192-to-3.2.0.10314-deDE-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"D:\World of Warcraft (3.0.9)\Launcher.exe" = D:\World of Warcraft (3.0.9)\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"D:\World of Warcraft (3.0.9)\WoW-3.2.0.10314-to-3.2.2.10482-deDE-downloader.exe" = D:\World of Warcraft (3.0.9)\WoW-3.2.0.10314-to-3.2.2.10482-deDE-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"D:\World of Warcraft (3.0.9)\WoW-3.2.2.10482-to-3.2.2.10505-deDE-downloader.exe" = D:\World of Warcraft (3.0.9)\WoW-3.2.2.10482-to-3.2.2.10505-deDE-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Apps\2.0\6TQBAN4L.25E\2VP395VW.0D2\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Apps\2.0\6TQBAN4L.25E\2VP395VW.0D2\frit..tion_f8d772dfbb3f7453_0002.0001_0db5bf169ed5c0c1\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss -- (AVM Berlin)
"C:\Programme\devolo\informer\devinf.exe" = C:\Programme\devolo\informer\devinf.exe:*:Enabled:devolo Informer -- (devolo AG)
"C:\Programme\devolo\easyshare\easyshare.exe" = C:\Programme\devolo\easyshare\easyshare.exe:*:Enabled:devolo EasyShare -- (devolo AG)
"D:\steamup\steamapps\common\peggle nights\PeggleNights.exe" = D:\steamup\steamapps\common\peggle nights\PeggleNights.exe:*:Enabled:Peggle Nights Demo
"C:\Programme\Skype\Plugin Manager\skypePM.exe" = C:\Programme\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"D:\steamup\steamapps\common\peggle deluxe\Peggle.exe" = D:\steamup\steamapps\common\peggle deluxe\Peggle.exe:*:Enabled:Peggle Deluxe Demo
"C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3\WNt500x86\RpcSandraSrv.exe" = C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service -- (SiSoftware)
"C:\Programme\Alice Software\AliceSetup.exe" = C:\Programme\Alice Software\AliceSetup.exe:LocalSubNet:Enabled:AliceSetup.exe -- (Hansenet)
"D:\Cod4\iw3mp.exe" = D:\Cod4\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) -- ()
"D:\Steam\Steam.exe" = D:\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"D:\Steam\steamapps\common\peggle nights\PeggleNights.exe" = D:\Steam\steamapps\common\peggle nights\PeggleNights.exe:*:Enabled:Peggle Nights -- ()
"C:\Programme\ICQ7.5\ICQ.exe" = C:\Programme\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5 -- (ICQ, LLC.)
"C:\Programme\Ipod Software\PocketControl\SensticPocketServiceWin.exe" = C:\Programme\Ipod Software\PocketControl\SensticPocketServiceWin.exe:*:Enabled:SensticPocketServiceWin.exe
"C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Apps\2.0\6TQBAN4L.25E\2VP395VW.0D2\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe" = C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Apps\2.0\6TQBAN4L.25E\2VP395VW.0D2\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe:*:Enabled:FRITZ!Box USB-Fernanschluss
"C:\Programme\Unified Remote\RemoteServer.exe" = C:\Programme\Unified Remote\RemoteServer.exe:*:Enabled:Unified Remote -- (Unified Remote)
"C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\Zeugs\Webcam\iWebcameraApp.exe" = C:\Dokumente und Einstellungen\Administrator.HOME-PC\Desktop\Zeugs\Webcam\iWebcameraApp.exe:*:Enabled:iWebcameraApp -- (drahtwerk)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis(R)
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{08B3869E-D282-424C-9AFC-870E04A4BA14}" = Rockstar Games Social Club
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
"{0F60FD8E-3E58-4F8E-BF2C-DFA4C9987AE2}_is1" = DeLorme Send To GPS 1.2
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{11964613-805F-432D-A12B-169554B793E7}" = Nokia Connectivity Cable Driver
"{13B792AA-C078-43A4-8A3A-8B12D629940D}" = Counter-Strike 1.6
"{13E92303-C1AC-4012-9E22-54EACBF54888}" = MCCI(r)Firmware Update Driver for MTK
"{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1B343C8C-F170-4829-8481-E163317C5830}" = iTunes
"{1C6B69CB-7BB1-4281-9DC2-A23BF0642F2A}" = Motorola Software Update
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{25DEC9F7-08C7-4511-9B4A-40A61E40658E}" = web'n'walk Manager
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = PowerCinema
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 24
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{2A3A4BD6-6CE0-4E2A-80D2-1D0FF6ACBFBA}" = LG United Mobile Driver
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{2EFEAD58-3311-4B2B-9D8A-8D663581D109}" = Splashtop Streamer
"{31492759-0E89-46B5-9770-F6E5808E3017}" = xImage
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{414A373B-59DF-4102-94CA-9FE9A74CBDDA}" = Garmin Trip and Waypoint Manager v5
"{42347B75-9660-2DA4-63FD-D35E344E1031}" = Nero 7 Premium
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}" = Microsoft Games for Windows - LIVE 
"{4E6D3F7E-6419-41F7-B7A3-689807348764}" = RSDLite
"{566BB41D-F006-4956-A5D3-94D8DFFA7F51}" = Adobe Setup
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{5AB36A6C-27A8-4CB1-89A1-9D05F3F16625}" = Mobile Mouse Server
"{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4
"{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5
"{75F509C3-5F01-48C1-ACB9-B9B38A952E6C}" = Unified Remote
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7AC09F4A-6AA6-4848-8959-A109BA079C5C}" = Trek 310
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{868D7896-99D4-4513-BC62-2B3AD3E24926}" = TuneUp Utilities 2006
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BBB5E4C-3F5E-4C07-BFBE-33B34600783A}" = LogMeIn Hamachi
"{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}" = CDDRV_Installer
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90170407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{92DF2F1B-F63C-4D9A-B3E1-B2D11AE29790}" = Windows Presentation Foundation Language Pack (DEU)
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{99A40651-0BC2-4095-8F9A-A40FAB224FEF}" = PC Connectivity Solution
"{99E862CC-6F69-4D39-99AA-DBF71BF3B585}" = OpenOffice.org 3.1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}" = Counter-Strike 1.6
"{9D210D79-AEC5-453B-960C-4DD2C73931E1}" = Bonjour-Druckdienste
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}" = Nokia PC Suite
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{ABBC8011-1E42-4ADA-9794-574349612CEF}" = iWebcamera
"{AC76BA86-1033-F400-7760-000000000002}" = Adobe Acrobat 7.0 Professional - English, Français, Deutsch
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 270.61
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 270.61
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.70
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C20CE592-B0F8-4D20-BF31-0151CA6331A6}" = EmoDio
"{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2196}_is1" = SiSoftware Sandra Lite 2009.SP3
"{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C89C8D86-4423-4A58-AA40-DD259ACE07C1}" = KhalSetup
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{D4E3C357-E294-4593-BF33-811822CC26FD}" = IMG2MS
"{DD1BD6BA-21C0-42C2-910B-11AE19FAD760}" = VideoCAM Eye
"{DE3BB35E-C0CE-4CA1-9CB4-CD9E69364BD9}" = Adobe Premiere Pro CS4
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E0F252A6-DE85-4E93-A93B-DFC3537B3965}" = WG111v2 Configuration Utility
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{EA6EB7D0-C920-4434-B43D-0DDD0AF8F497}" = Garmin MapSource
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F2A7F421-1679-48D5-B918-96999014ED53}" = Microsoft .NET Framework 3.0 German Language Pack
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB068BA4-C6EA-4D47-A491-C40E23E77F89}" = Motorola Driver Installation 3.9.0
"{FC6B78BE-922F-45D4-9D47-D10C494658F6}" = TSConverter
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT-Erweiterung für den Microsoft Windows XP-Assistenten zum Schreiben von CDs
"{FD052FB9-FE90-4438-B355-15EDC89D8FB1}" = Microsoft Games for Windows - LIVE Redistributable
"°²»úÍøÒ»¼üRoot¹¤¾ß" = °²»úÍøÒ»¼üRoot¹¤¾ß 2.2
"7-Zip" = 7-Zip 4.65
"Adobe Acrobat 7.0 Professional - EFG" = Adobe Acrobat 7.1.0 Professional
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Adobe_26b63376f4efc354dae41af6b5e3343" = Adobe Premiere Pro CS4
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"Alice Software" = Alice Software 4.10.0
"Audacity_is1" = Audacity 1.2.6
"C-Media Oxygen HD Sound" = ASUS Xonar DX Audio
"C-Media PCI Sound" = C-Media PCI Audio
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"CoreVorbis Audio Decoder" = CoreVorbis Audio Decoder (remove only)
"DIVXCodec" = DivX Codec 3.1alpha release
"dlanconf" = devolo dLAN-Konfigurationsassistent
"dslmon" = devolo Informer
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"DXTXTRA" = Microsoft DirectX Transform optional components
"easyclean" = devolo EasyClean
"easyshare" = devolo EasyShare
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free Studio_is1" = Free Studio version 5.0.4
"Free Video to iPod Converter_is1" = Free Video to iPod Converter version 3.1
"Free YouTube to iPod Converter_is1" = Free YouTube to iPod Converter version 3.1
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.35.324
"Frequenzweiche_is1" = Frequenzweiche 4.x
"Guitar Pro 5_is1" = Guitar Pro 5.2
"ICQToolbar" = ICQ Toolbar
"InstallShield_{2EFEAD58-3311-4B2B-9D8A-8D663581D109}" = Splashtop Streamer
"InstallShield_{C20CE592-B0F8-4D20-BF31-0151CA6331A6}" = EmoDio
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"LogMeIn Hamachi" = LogMeIn Hamachi
"Microsoft .NET Framework 3.0 German Language Pack" = Microsoft .NET Framework 3.0 German Language Pack
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Minecraft Beta Cracked" = Minecraft Beta Cracked
"Mozilla Firefox 9.0.1 (x86 de)" = Mozilla Firefox 9.0.1 (x86 de)
"Mp3tag" = Mp3tag v2.46a
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OggDS" = Direct Show Ogg Vorbis Filter (remove only)
"OpenAL" = OpenAL
"Orbit_is1" = Orbit Downloader
"PCI Audio Applications" = PCI Audio Applications
"PCI Audio Driver" = PCI Audio Driver
"Pontifex II" = Pontifex II
"PunkBusterSvc" = PunkBuster Services
"screensaver_shell" = screensaver_shell
"Steam App 3540" = Peggle Nights
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TmNationsForever_is1" = TmNationsForever
"Uninstall_is1" = Uninstall 1.0.0.1
"uniquemagicmp3taggerappid_is1" = Magic MP3 Tagger 2.2.6
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR Archivierer
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World of Warcraft" = World of Warcraft
"Wudf01005" = Microsoft User-Mode Driver Framework Feature Pack 1.5
"XMedia Recode" = XMedia Recode 3.0.0.2
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"XSManager" = XSManager
"Yawle_0.3b" = YAWLE 0.5b
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CreepSmash" = CreepSmash
"f6791b188d8f3ff8" = AVM FRITZ!Box USB-Fernanschluss
"Smart Shutdown Manager" = Smart Shutdown Manager
"Winamp Detect" = Winamp Erkennungs-Plug-in
"World Wind Java Application Template" = World Wind Java Application Template
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 15.10.2011 06:56:48 | Computer Name = STEPHAQN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung winamp.exe, Version 5.6.2.3173, fehlgeschlagenes
 Modul msvcr90.dll, Version 9.0.30729.4148, Fehleradresse 0x00056b6a.
 
Error - 15.10.2011 06:57:07 | Computer Name = STEPHAQN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung winamp.exe, Version 5.6.2.3173, fehlgeschlagenes
 Modul msvcr90.dll, Version 9.0.30729.4148, Fehleradresse 0x00056b6a.
 
Error - 15.10.2011 07:02:24 | Computer Name = STEPHAQN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung winamp.exe, Version 5.6.2.3173, fehlgeschlagenes
 Modul msvcr90.dll, Version 9.0.30729.4148, Fehleradresse 0x00056b6a.
 
Error - 15.10.2011 07:02:35 | Computer Name = STEPHAQN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung winamp.exe, Version 5.6.2.3173, fehlgeschlagenes
 Modul msvcr90.dll, Version 9.0.30729.4148, Fehleradresse 0x00056b6a.
 
Error - 15.10.2011 08:36:14 | Computer Name = STEPHAQN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung winamp.exe, Version 5.6.2.3173, fehlgeschlagenes
 Modul msvcr90.dll, Version 9.0.30729.4148, Fehleradresse 0x00056b6a.
 
Error - 15.10.2011 08:37:10 | Computer Name = STEPHAQN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung winamp.exe, Version 5.6.2.3173, fehlgeschlagenes
 Modul msvcr90.dll, Version 9.0.30729.4148, Fehleradresse 0x00056b6a.
 
Error - 18.10.2011 14:51:56 | Computer Name = STEPHAQN | Source = crypt32 | ID = 131080
Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer
 von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
 ist fehlgeschlagen mit dem Fehler: Dieser Vorgang wurde wegen Zeitüberschreitung
 zurückgegeben.  .
 
Error - 30.10.2011 08:29:37 | Computer Name = STEPHAQN | Source = MsiInstaller | ID = 10005
Description = Product: Unified Remote -- This application requires .NET Framework
 4.0 Client Profile or Full. Please install the .NET Framework then run this installer
 again.
 
Error - 30.10.2011 08:29:57 | Computer Name = STEPHAQN | Source = MsiInstaller | ID = 10005
Description = Product: Unified Remote -- This application requires .NET Framework
 4.0 Client Profile or Full. Please install the .NET Framework then run this installer
 again.
 
Error - 28.11.2011 13:21:47 | Computer Name = STEPHAQN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung javaw.exe, Version 6.0.240.7, fehlgeschlagenes
 Modul nvoglnt.dll, Version 6.14.12.7061, Fehleradresse 0x0072df7f.
 
[ System Events ]
Error - 25.01.2012 12:25:20 | Computer Name = STEPHAQN | Source = Service Control Manager | ID = 7022
Description = Der Dienst "CyberLink Background Capture Service (CBCS)" wurde nicht
 ordnungsgemäß gestartet.
 
Error - 25.01.2012 12:25:20 | Computer Name = STEPHAQN | Source = Service Control Manager | ID = 7001
Description = Der Dienst "CyberLink Task Scheduler (CTS)" ist vom Dienst "CyberLink
 Background Capture Service (CBCS)" abhängig, der aufgrund folgenden Fehlers nicht
 gestartet wurde:   %%1070
 
Error - 25.01.2012 12:34:31 | Computer Name = STEPHAQN | Source = Service Control Manager | ID = 7022
Description = Der Dienst "CyberLink Background Capture Service (CBCS)" wurde nicht
 ordnungsgemäß gestartet.
 
Error - 25.01.2012 12:34:31 | Computer Name = STEPHAQN | Source = Service Control Manager | ID = 7001
Description = Der Dienst "CyberLink Task Scheduler (CTS)" ist vom Dienst "CyberLink
 Background Capture Service (CBCS)" abhängig, der aufgrund folgenden Fehlers nicht
 gestartet wurde:   %%1070
 
Error - 25.01.2012 13:12:50 | Computer Name = STEPHAQN | Source = DCOM | ID = 10005
Description = Bei DCOM ist der Fehler "%1084" aufgetreten, als der Dienst "EventSystem"
 mit den Argumenten ""  gestartet wurde, um den folgenden Server zu verwenden:  {1BE1F766-5536-11D1-B726-00C04FB926AF}
 
Error - 25.01.2012 13:13:43 | Computer Name = STEPHAQN | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   Fips  intelppm
 
Error - 25.01.2012 13:15:51 | Computer Name = STEPHAQN | Source = DCOM | ID = 10005
Description = Bei DCOM ist der Fehler "%1084" aufgetreten, als der Dienst "StiSvc"
 mit den Argumenten ""  gestartet wurde, um den folgenden Server zu verwenden:  {A1F4E726-8CF1-11D1-BF92-0060081ED811}
 
Error - 25.01.2012 13:16:33 | Computer Name = STEPHAQN | Source = DCOM | ID = 10005
Description = Bei DCOM ist der Fehler "%1084" aufgetreten, als der Dienst "EventSystem"
 mit den Argumenten ""  gestartet wurde, um den folgenden Server zu verwenden:  {1BE1F766-5536-11D1-B726-00C04FB926AF}
 
Error - 25.01.2012 13:19:06 | Computer Name = STEPHAQN | Source = Service Control Manager | ID = 7022
Description = Der Dienst "CyberLink Background Capture Service (CBCS)" wurde nicht
 ordnungsgemäß gestartet.
 
Error - 25.01.2012 13:19:06 | Computer Name = STEPHAQN | Source = Service Control Manager | ID = 7001
Description = Der Dienst "CyberLink Task Scheduler (CTS)" ist vom Dienst "CyberLink
 Background Capture Service (CBCS)" abhängig, der aufgrund folgenden Fehlers nicht
 gestartet wurde:   %%1070
 
 
< End of report >
         
--- --- ---
[spoiler]
__________________

Alt 25.01.2012, 20:14   #4
markusg
/// Malware-holic
 
Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner - Standard

Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner



hi


dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:
ATTFilter
:OTL
O4 - HKCU..\Run: [Firefox helper] C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\firefox.exe
(Корпорация Майкрософт)
O33 - MountPoints2\{31a87768-0a31-11e1-9db3-0019668e3bbe}\Shell - "" = AutoRun
O33 - MountPoints2\{31a87768-0a31-11e1-9db3-0019668e3bbe}\Shell\AutoRun - "" = AutoPlay
O33 - MountPoints2\{31a87768-0a31-11e1-9db3-0019668e3bbe}\Shell\AutoRun\command - "" = J:\autorun.exe
O33 - MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\Shell - "" = Autorun
O33 - MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\Shell\AutoRun - "" = AutoPlay
O33 - MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\Shell\AutoRun\command - "" = C:\WINDOWS.0\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL
RECYCLER\S-1-9-90-100002473-100002232-100019806-1353.com f:\
O33 - MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\Shell\Open\command - "" = RECYCLER\S-1-9-90-100002473-100002232-100019806-1353.com f:\
O33 - MountPoints2\{654942e4-2dbd-11de-abc0-0019668e3bbe}\Shell\verb1\command - "" = desktop.exe
O33 - MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\Shell\autoPlay\commaND - "" = raue.cmd
O33 - MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\Shell\AutoRun\command - "" = raue.cmd
O33 - MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\Shell\ExploRE\CoMmANd - "" = raue.cmd
O33 - MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\Shell\open\COmmAnd - "" = raue.cmd
O33 - MountPoints2\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\Shell - "" = AutoRun
O33 - MountPoints2\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\Shell\AutoRun - "" = AutoPlay
O33 - MountPoints2\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\Shell\AutoRun\command - "" = J:\setup.exe AUTORUN=1
 :Files
C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\firefox.exe
:Commands
[purity]
[EMPTYFLASH] 
[emptytemp]
[Reboot]
         


• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.
starte in den normalen modus.

falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden

Drücke bitte die + E Taste.
  • Öffne dein Systemlaufwerk ( meistens C: )
  • Suche nun
    folgenden Ordner: _OTL und öffne diesen.
  • Mache einen Rechtsklick auf den Ordner Movedfiles --> Senden an --> Zip-Komprimierter Ordner

  • Dies wird eine Movedfiles.zip Datei in _OTL erstellen
  • Lade diese bitte in unseren Uploadchannel
    hoch. ( Durchsuchen --> C:\_OTL\Movedfiles.zip )
Teile mir mit ob der Upload problemlos geklappt hat. Danke im voraus
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 25.01.2012, 20:32   #5
karken1994
 
Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner - Standard

Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner



Sauber?

All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Firefox helper deleted successfully.
C:\Dokumente und Einstellungen\Administrator.HOME-PC\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\firefox.exe moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{31a87768-0a31-11e1-9db3-0019668e3bbe}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31a87768-0a31-11e1-9db3-0019668e3bbe}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{31a87768-0a31-11e1-9db3-0019668e3bbe}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31a87768-0a31-11e1-9db3-0019668e3bbe}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{31a87768-0a31-11e1-9db3-0019668e3bbe}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31a87768-0a31-11e1-9db3-0019668e3bbe}\ not found.
File J:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54a546fc-2e82-11de-abf0-0019668e3bbe}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54a546fc-2e82-11de-abf0-0019668e3bbe}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54a546fc-2e82-11de-abf0-0019668e3bbe}\ not found.
File C:\WINDOWS.0\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54a546fc-2e82-11de-abf0-0019668e3bbe}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54a546fc-2e82-11de-abf0-0019668e3bbe}\ not found.
File C:\RECYCLER\S-1-9-90-100002473-100002232-100019806-1353.com f:\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{654942e4-2dbd-11de-abc0-0019668e3bbe}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{654942e4-2dbd-11de-abc0-0019668e3bbe}\ not found.
File desktop.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70f81c39-a9ee-11de-9853-0019668e3bbe}\ not found.
File raue.cmd not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70f81c39-a9ee-11de-9853-0019668e3bbe}\ not found.
File raue.cmd not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70f81c39-a9ee-11de-9853-0019668e3bbe}\ not found.
File raue.cmd not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{70f81c39-a9ee-11de-9853-0019668e3bbe}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70f81c39-a9ee-11de-9853-0019668e3bbe}\ not found.
File raue.cmd not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b5bb660c-e7f4-11de-98e7-0019668e3bbe}\ not found.
File J:\setup.exe AUTORUN=1 not found.
========== COMMANDS ==========

[EMPTYFLASH]

User: Administrator.HOME-PC
->Flash cache emptied: 2057056 bytes

User: All Users.WINDOWS.0

User: LocalService

User: LocalService.NT-AUTORITÄT

User: NetworkService

User: NetworkService.NT-AUTORITÄT

Total Flash Files Cleaned = 2,00 mb


[EMPTYTEMP]

User: Administrator.HOME-PC
->Temp folder emptied: 62577534 bytes
->Temporary Internet Files folder emptied: 33717311 bytes
->Java cache emptied: 104970301 bytes
->FireFox cache emptied: 108062865 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users.WINDOWS.0

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService.NT-AUTORITÄT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 68031 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService.NT-AUTORITÄT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1239280 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1959104 bytes
%systemroot%\System32 .tmp files removed: 2951 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 379451256 bytes
RecycleBin emptied: 6898972653 bytes

Total Files Cleaned = 7.239,00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 01252012_202337

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


Alt 25.01.2012, 21:06   #6
markusg
/// Malware-holic
 
Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner - Standard

Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner



hi,
Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich
ziehen und eine Bereinigung der Infektion noch erschweren.

Bitte downloade dir Combofix.exe und speichere es unbedingt auf deinem Desktop.
  • Besuche folgende Seite für Downloadlinks und Anweisungen für dieses
    Tool

    Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Hinweis:
    Gehe sicher das all deine Anti Virus und Anti Malware Programme abgeschalten sind, damit diese Combofix nicht bei der Arbeit stören.
  • Poste bitte die C:\Combofix.txt in deiner nächsten Antwort.
__________________
--> Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner

Antwort

Themen zu Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner
achtung, achtung!, aus sicherheitsgründen, eingebe, hoffe, momentan, neu, otl-programm, poste, posten, protokoll, richtig, runtergeladen, sicherheitsgründe, sicherheitsgründen, tan, troja, trojane, trojaner, virus, windowssystem, wurde ihr




Ähnliche Themen: Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner


  1. Achtung! Aus Sicherheitsgründen wurde ihr windowssystem blockiert
    Log-Analyse und Auswertung - 16.05.2012 (10)
  2. Trojaner Achtung aus Sicherheitsgründen wurde Ihr Windowssystem blockiert
    Plagegeister aller Art und deren Bekämpfung - 07.05.2012 (27)
  3. Trojaner Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert.
    Log-Analyse und Auswertung - 21.03.2012 (6)
  4. Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. (die 100.)
    Log-Analyse und Auswertung - 11.03.2012 (5)
  5. ACHTUNG! Aus Sicherheitsgründen wurde Ihr Windowssystem blockiert
    Plagegeister aller Art und deren Bekämpfung - 18.02.2012 (19)
  6. Achtung! Aus Sicherheitsgründen wurde Ihr Windowssystem blockiert...
    Log-Analyse und Auswertung - 12.02.2012 (31)
  7. Achtung: Aus Sicherheitsgründen wurde ihr Windowssystem blockiert
    Log-Analyse und Auswertung - 10.02.2012 (6)
  8. Trojaner: Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert
    Plagegeister aller Art und deren Bekämpfung - 26.01.2012 (12)
  9. Achtung aus sicherheitsgründen wurde ihr windowssystem blockiert!
    Log-Analyse und Auswertung - 21.01.2012 (3)
  10. Achtung! Aus sicherheitsgründen wurde ihr windowssystem blockiert...
    Log-Analyse und Auswertung - 18.01.2012 (1)
  11. 50€ Trojaner - Achtung aus Sicherheitsgründen wurde ihr Windowssystem blockiert
    Plagegeister aller Art und deren Bekämpfung - 12.01.2012 (30)
  12. Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert
    Plagegeister aller Art und deren Bekämpfung - 23.12.2011 (3)
  13. ACHTUNG! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert.
    Plagegeister aller Art und deren Bekämpfung - 23.12.2011 (32)
  14. ACHTUNG! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert.
    Log-Analyse und Auswertung - 22.12.2011 (10)
  15. Achtung aus sicherheitsgründen wurde ihr windowssystem blockiert
    Log-Analyse und Auswertung - 12.12.2011 (8)
  16. Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert.
    Plagegeister aller Art und deren Bekämpfung - 09.12.2011 (1)
  17. Achtung aus sicherheitsgründen wurde ihr windowssystem blockiert
    Log-Analyse und Auswertung - 04.12.2011 (24)

Zum Thema Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner - Hayho Bin neu hier und hoffe mache alles richtig Also ich hab diesen Virus zu dem viele momentan was schreiben. Ich habe auch schon das OTL-Programm runtergeladen und ein Protokoll - Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner...
Archiv
Du betrachtest: Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert. Trojaner auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.