![]() |
Plagegeister aller Art und deren Bekämpfung: "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :(Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #1 |
![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( Schönen Nachmittag alle zusammen, auch ich habe mir gerade den 50 € bezahlen und runterladen Virus. Betriebssystem: Windows 7 Ich habe meinen PC jetzt mit F8 in den abgesicherten Modus mit Netzwerk gebracht und mich mit dem infizierten Konto angemeldet.stehe jetzt vor dem Problem. Was mache ich jetzt? Ich bin vollkommen überfordert und bitte um Laien gerechte Anweisungen.Da ich momentan sehr auf meinen Laptop angewiesen bin, bitte ich um schnelle Hilfe. Ich bedanke mich jetzt schon mal im Vorraus bei allen, die mir helfen!!! Vielen Dank!! ![]() Mfg Jenny |
![]() | #2 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( hi,
__________________Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %USERPROFILE%\*.* %USERPROFILE%\Local Settings\Temp\*.exe %USERPROFILE%\Local Settings\Temp\*.dll %USERPROFILE%\Application Data\*.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs CREATERESTOREPOINT
__________________ |
![]() | #3 |
![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( Das ist der Texteditor Inhalt von OTL.Txt :OTL Logfile:
ATTFilter OTL logfile created on: 14.02.2012 16:20:47 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Jennifer\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,87 Gb Total Physical Memory | 3,13 Gb Available Physical Memory | 80,99% Memory free 7,73 Gb Paging File | 7,09 Gb Available in Paging File | 91,75% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 421,81 Gb Total Space | 268,77 Gb Free Space | 63,72% Space Free | Partition Type: NTFS Drive D: | 29,00 Gb Total Space | 28,18 Gb Free Space | 97,19% Space Free | Partition Type: NTFS Drive F: | 0,67 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: JENNIFER-PC | User Name: Jennifer | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Jennifer\Downloads\OTL.exe (OldTimer Tools) ========== Modules (No Company Name) ========== ========== Win32 Services (SafeList) ========== SRV:64bit: - (Lenovo ReadyComm ConnSvc) -- C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe (Lenovo Group Limited) SRV:64bit: - (Lenovo ReadyComm AppSvc) -- C:\Program Files\Lenovo\ReadyComm\AppSvc.exe (Lenovo Group Limited) SRV - (SearchAnonymizer) -- C:\Users\Jennifer\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe () SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.) SRV - (BBUpdate) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (ICQ Service) -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe () SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (BrYNSvc) -- C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.) SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.) SRV - (IAStorDataMgrSvc) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) SRV - (IGRS) -- C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe (Lenovo Group Limited) SRV - (ReadyComm.DirectRouter) -- C:\windows\SysWow64\IgrsSvcs.exe (Microsoft Corporation) SRV - (PS_MDP) -- C:\windows\SysWow64\IgrsSvcs.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.) SRV - (NMSAccessU) -- C:\Program Files (x86)\Common Files\NMSAccessU.exe () SRV - (UPnPService) -- C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe (Magix AG) SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®) ========== Driver Services (SafeList) ========== DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated) DRV:64bit: - (vm331avs) -- C:\Windows\SysNative\drivers\vm331avs.sys (Vimicro Corporation) DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.) DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation) DRV:64bit: - (CnxtHdAudService) -- C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation) DRV:64bit: - (ACPIVPC) -- C:\Windows\SysNative\drivers\AcpiVpc.sys (Lenovo Corporation) DRV:64bit: - (HECIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation) DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek ) DRV:64bit: - (wsvd) -- C:\Windows\SysNative\drivers\wsvd.sys (CyberLink) DRV:64bit: - (wdmirror) -- C:\Windows\SysNative\drivers\WDMirror.sys (Lenovo) DRV:64bit: - (Bridge0) -- C:\Windows\SysNative\drivers\WDBridge.sys (Lenovo) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation) DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation) DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) DRV:64bit: - (netw5v64) Intel(R) -- C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation) DRV:64bit: - (k57nd60a) Broadcom NetLink (TM) -- C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) DRV - (StarOpen) -- C:\windows\SysWow64\drivers\StarOpen.sys () ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.yahoo.com/?fr=fp-yie9 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.searchqu.com/413 IE - HKCU\..\URLSearchHook: - No CLSID value found IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.3&q=" FF - prefs.js..browser.search.order.1: "Searchqu Web Search" FF - prefs.js..browser.search.selectedEngine: "ICQ Search" FF - prefs.js..browser.startup.homepage: "hxxp://www.searchqu.com/413" FF - prefs.js..keyword.URL: "hxxp://www.searchqu.com/web?src=ffb&appid=0&systemid=413&sr=0&q=" FF - prefs.js..network.proxy.no_proxies_on: "*.local" FF - prefs.js..network.proxy.type: 0 FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Jennifer\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.02.11 19:27:19 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\mail@gutscheinrausch.de: C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\extensions\mail@gutscheinrausch.de [2011.11.07 11:37:08 | 000,000,000 | ---D | M] [2011.12.12 21:56:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jennifer\AppData\Roaming\mozilla\Extensions [2012.02.12 22:44:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jennifer\AppData\Roaming\mozilla\Firefox\Profiles\lrydn7vs.default\extensions [2012.01.04 20:17:21 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Jennifer\AppData\Roaming\mozilla\Firefox\Profiles\lrydn7vs.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2011.12.12 21:56:11 | 000,000,000 | ---D | M] (Searchqu Toolbar) -- C:\Users\Jennifer\AppData\Roaming\mozilla\Firefox\Profiles\lrydn7vs.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} [2011.09.21 13:17:20 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Jennifer\AppData\Roaming\mozilla\Firefox\Profiles\lrydn7vs.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2011.12.24 22:02:54 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Jennifer\AppData\Roaming\mozilla\Firefox\Profiles\lrydn7vs.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2012.02.12 22:44:36 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Jennifer\AppData\Roaming\mozilla\Firefox\Profiles\lrydn7vs.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2011.11.20 17:36:18 | 000,000,000 | ---D | M] (20-20 3D Viewer - IKEA) -- C:\Users\Jennifer\AppData\Roaming\mozilla\Firefox\Profiles\lrydn7vs.default\extensions\2020Player_IKEA@2020Technologies.com [2011.11.07 11:37:08 | 000,000,000 | ---D | M] (Gutscheinrausch.de) -- C:\Users\Jennifer\AppData\Roaming\mozilla\Firefox\Profiles\lrydn7vs.default\extensions\mail@gutscheinrausch.de [2011.11.07 11:37:12 | 000,001,105 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\icqplugin-1.xml [2011.11.07 11:37:12 | 000,001,105 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\icqplugin-2.xml [2011.11.07 13:05:16 | 000,000,950 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\icqplugin-3.xml [2011.12.13 11:25:02 | 000,000,950 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\icqplugin-4.xml [2012.01.09 21:57:48 | 000,000,950 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\icqplugin-5.xml [2012.02.02 21:49:20 | 000,000,950 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\icqplugin-6.xml [2012.02.11 19:27:43 | 000,000,950 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\icqplugin-7.xml [2012.01.04 14:54:58 | 000,000,168 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\icqplugin.gif [2012.01.04 14:54:58 | 000,000,618 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\icqplugin.src [2011.11.07 11:37:12 | 000,001,122 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\icqplugin.xml [2011.12.12 21:56:05 | 000,002,520 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\SearchResults.xml [2011.11.07 11:37:12 | 000,001,872 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\{42707E69-AD42-4C9B-933B-840B76C63B81}.xml [2011.11.07 11:37:12 | 000,002,190 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\{570FA1DA-73C7-425E-84B7-54DE06E3DE47}.xml [2011.11.07 11:37:12 | 000,002,079 | ---- | M] () -- C:\Users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\searchplugins\{D57A4533-79D6-49ED-ACAA-1E7937161DB0}.xml [2011.12.12 21:56:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions () (No name found) -- C:\USERS\JENNIFER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LRYDN7VS.DEFAULT\EXTENSIONS\{D47A9F51-8281-43FA-F450-F28EF8735E9A}.XPI [2012.02.11 19:27:19 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2011.11.20 11:37:49 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.11.20 11:37:49 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2011.11.20 11:37:49 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2011.11.20 11:37:49 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2011.12.12 21:56:05 | 000,002,520 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml [2011.11.20 11:37:49 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2011.11.20 11:37:49 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - Extension: No name found = C:\Users\Jennifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\\ O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2:64bit: - BHO: (SearchCore for Browsers) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\BROWSE~1.DLL (Bandoo Media, inc) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll () O2 - BHO: (SearchCore for Browsers) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\SEARCH~1\SEARCH~1\BROWSE~1.DLL (Bandoo Media, inc) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc) O2 - BHO: (ICQ Sparberater) - {FE163F11-1919-4257-A280-FF5AF8DAEECB} - C:\Program Files (x86)\icq\Internet Explorer\icq.dll (solute gmbh) O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll () O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Programme\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.) O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited) O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited) O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\windows\SysNative\NvCpl.dll (NVIDIA Corporation) O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\Jennifer\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS) O4:64bit: - HKLM..\Run: [OnekeyStudio] C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo) O4 - HKLM..\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331_STI.EXE (Vimicro) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [DATAMNGR] C:\PROGRA~2\SEARCH~1\SEARCH~1\DATAMN~1.EXE (Bandoo Media, inc) O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [TrayServer] C:\Program Files (x86)\MAGIX\Video_deluxe_15_Premium\TrayServer.exe (MAGIX AG) O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo) O4 - HKLM..\Run: [YouCam Mirror Tray icon] C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (CyberLink Corp.) O4 - HKCU..\Run: [ffdwnd] C:\Users\Jennifer\AppData\Local\Mozilla\Firefox\firefox.exe (Tomasz Pawlak) O4 - HKCU..\Run: [ICQ] C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0 O8:64bit: - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Jennifer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Jennifer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} hxxp://www.o2c.de/download/o2cplayer.cab (o2c Player (ELECO Software GmbH)) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AE20A778-D4C3-4E9A-A6FC-484AA1BE2464}: DhcpNameServer = O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help - No CLSID value found O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\datamngr.dll) - C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\datamngr.dll (Bandoo Media, inc) O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll) - C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll (Bandoo Media, inc) O20 - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\SEARCH~1\datamngr.dll) -C:\PROGRA~2\SEARCH~1\SEARCH~1\datamngr.dll (Bandoo Media, inc) O20 - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\SEARCH~1\IEBHO.dll) -C:\PROGRA~2\SEARCH~1\SEARCH~1\IEBHO.dll (Bandoo Media, inc) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{ea83dd94-090e-11e1-9760-d2b9cd05f4ef}\Shell - "" = AutoRun O33 - MountPoints2\{ea83dd94-090e-11e1-9760-d2b9cd05f4ef}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012.02.06 12:53:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2012.02.06 12:52:36 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2012.02.06 12:52:35 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2012.02.06 12:52:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes [2012.02.06 12:49:38 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2012.02.04 21:00:51 | 000,000,000 | ---D | C] -- C:\Users\Jennifer\AppData\Roaming\gtk-2.0 [2012.02.04 21:00:51 | 000,000,000 | ---D | C] -- C:\Users\Jennifer\.thumbnails [2012.01.30 18:19:57 | 000,000,000 | ---D | C] -- C:\Users\Jennifer\AppData\Roaming\Canneverbe Limited [2012.01.30 18:19:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited [2012.01.30 18:19:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDBurnerXP [2012.01.30 14:37:09 | 000,000,000 | ---D | C] -- C:\Users\Jennifer\.gimp-2.6 [2012.01.30 14:37:08 | 000,000,000 | ---D | C] -- C:\Users\Jennifer\Documents\gegl-0.0 [2012.01.30 14:36:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP [2012.01.30 14:35:53 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0 [1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ] [1 C:\Users\Jennifer\Documents\*.tmp files -> C:\Users\Jennifer\Documents\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.02.14 16:08:21 | 000,000,000 | ---- | M] () -- C:\Users\Jennifer\defogger_reenable [2012.02.14 15:31:15 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2012.02.14 15:31:06 | 3113,365,504 | -HS- | M] () -- C:\hiberfil.sys [2012.02.14 15:11:42 | 000,013,424 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.02.14 15:11:42 | 000,013,424 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.02.14 15:09:02 | 000,001,110 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job [2012.02.14 14:46:01 | 000,001,114 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job [2012.02.14 10:39:37 | 000,003,395 | ---- | M] () -- C:\Users\Jennifer\.recently-used.xbel [2012.02.13 09:11:16 | 000,657,910 | ---- | M] () -- C:\windows\SysNative\perfh007.dat [2012.02.13 09:11:16 | 000,619,146 | ---- | M] () -- C:\windows\SysNative\perfh009.dat [2012.02.13 09:11:16 | 000,131,250 | ---- | M] () -- C:\windows\SysNative\perfc007.dat [2012.02.13 09:11:16 | 000,107,466 | ---- | M] () -- C:\windows\SysNative\perfc009.dat [2012.02.13 09:11:15 | 001,507,342 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI [2012.02.09 12:10:02 | 000,002,344 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2012.02.06 12:53:49 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2012.02.03 12:58:34 | 000,001,402 | ---- | M] () -- C:\Users\Jennifer\Desktop\Free YouTube to MP3 Converter.lnk [2012.01.30 18:19:44 | 000,001,953 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk [2012.01.30 14:36:44 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\GIMP 2.lnk [1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ] [1 C:\Users\Jennifer\Documents\*.tmp files -> C:\Users\Jennifer\Documents\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.02.14 16:08:21 | 000,000,000 | ---- | C] () -- C:\Users\Jennifer\defogger_reenable [2012.02.14 10:39:37 | 000,003,395 | ---- | C] () -- C:\Users\Jennifer\.recently-used.xbel [2012.02.06 12:53:49 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2012.01.30 18:19:44 | 000,001,953 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk [2012.01.30 18:19:44 | 000,001,903 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk [2012.01.30 14:36:44 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\GIMP 2.lnk [2011.11.07 11:42:12 | 000,000,052 | ---- | C] () -- C:\windows\Relax.ini [2011.04.30 20:49:04 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt [2011.04.30 20:44:57 | 000,005,632 | ---- | C] () -- C:\windows\SysWow64\drivers\StarOpen.sys [2011.01.15 12:59:58 | 000,000,425 | ---- | C] () -- C:\windows\BRWMARK.INI [2010.12.18 12:54:24 | 000,120,200 | ---- | C] () -- C:\windows\SysWow64\DLLDEV32i.dll [2010.12.18 12:51:12 | 000,007,103 | ---- | C] () -- C:\windows\mgxoschk.ini [2010.06.25 11:35:05 | 000,000,512 | ---- | C] () -- C:\windows\previous.bin [2010.06.25 11:35:05 | 000,000,512 | ---- | C] () -- C:\windows\current.bin [2010.06.25 11:27:52 | 000,016,648 | R--- | C] () -- C:\windows\SysWow64\LogAPI.dll [2010.06.25 11:18:49 | 002,110,816 | ---- | C] () -- C:\windows\SysWow64\Apblend.dll [2010.06.25 11:18:49 | 001,171,456 | ---- | C] () -- C:\windows\SysWow64\PicNotify.dll [2010.06.25 11:18:37 | 001,044,480 | ---- | C] () -- C:\windows\SysWow64\3DImageRenderer.dll [2010.06.25 10:57:20 | 000,001,341 | ---- | C] () -- C:\windows\vm331Rmv.ini [2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat [2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\windows\SysWow64\NOISE.DAT [2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\windows\SysWow64\dssec.dat [2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll [2009.07.13 22:59:36 | 000,982,196 | ---- | C] () -- C:\windows\SysWow64\igkrng500.bin [2009.07.13 22:59:36 | 000,139,824 | ---- | C] () -- C:\windows\SysWow64\igfcg500.bin [2009.07.13 22:59:36 | 000,097,448 | ---- | C] () -- C:\windows\SysWow64\igfcg500m.bin [2009.07.13 22:59:35 | 000,417,344 | ---- | C] () -- C:\windows\SysWow64\igcompkrng500.bin [2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\windows\SysWow64\mlang.dat [2007.01.25 03:52:26 | 000,065,536 | ---- | C] () -- C:\Program Files (x86)\Common Files\NMSAccessU.exe ========== LOP Check ========== [2012.01.30 18:19:57 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\Canneverbe Limited [2011.11.07 11:37:08 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\DesktopIconForAmazon [2012.02.03 12:59:26 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\DVDVideoSoft [2011.09.21 13:17:19 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\DVDVideoSoftIEHelpers [2011.12.21 18:06:54 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\FreeFLVConverter [2012.02.14 10:38:40 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\gtk-2.0 [2011.09.16 16:28:07 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\Guitar Pro 6 [2012.02.14 15:30:13 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\ICQ [2010.12.18 13:29:08 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\MAGIX [2011.11.07 11:37:07 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\OCS [2011.11.07 11:37:12 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\Opera [2011.08.11 17:21:47 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\PhotoScape [2011.04.30 20:49:34 | 000,000,000 | ---D | M] -- C:\Users\Jennifer\AppData\Roaming\Samsung [2012.01.27 09:33:00 | 000,032,640 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > das ist eine Kopie des extra Texteditors:OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 14.02.2012 16:20:47 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Jennifer\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,87 Gb Total Physical Memory | 3,13 Gb Available Physical Memory | 80,99% Memory free 7,73 Gb Paging File | 7,09 Gb Available in Paging File | 91,75% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 421,81 Gb Total Space | 268,77 Gb Free Space | 63,72% Space Free | Partition Type: NTFS Drive D: | 29,00 Gb Total Space | 28,18 Gb Free Space | 97,19% Space Free | Partition Type: NTFS Drive F: | 0,67 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: JENNIFER-PC | User Name: Jennifer | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) .url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery "{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10 "{5E11C972-1E76-45FE-8F92-14E0D1140B1B}" = iTunes "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support "{90140000-0015-0407-1000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0015-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0407-1000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0016-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0407-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0018-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0407-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-0019-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0407-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001A-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0407-1000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001B-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{70A3169E-288F-454F-A08D-20DF66639B50}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUSR_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-001F-0410-1000-0000000FF1CE}_Office14.PROPLUSR_{3013A793-10A7-4D1F-B8B4-2FAA82F4D259}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-002C-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{98782D5D-A9EE-43C6-88AD-B50AD8530E78}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010 "{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0043-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2010 "{90140000-0043-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{8DFD91C7-66AE-4E54-9901-5D5F401AD329}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0407-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010 "{90140000-0044-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-006E-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{8299B64F-1537-4081-974C-033EAB8F098E}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0407-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00A1-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0407-1000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010 "{90140000-00BA-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "0A4175B489A1B4A6E07E11B063A6263480C51D71" = Windows-Treiberpaket - Lenovo (ACPIVPC) System (10/19/2009 "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit "Adobe Flash Player Plugin 64" = Adobe Flash Player 10 Plugin 64-bit "CNXT_AUDIO_HDA" = Conexant HD Audio "DesktopIconAmazon" = Desktop Icon für Amazon "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "NVIDIA Drivers" = NVIDIA Drivers "Office14.PROPLUSR" = Microsoft Office Professional Plus 2010 "SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software "SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set "Samsung Mobile phone USB driver Drive" = Samsung Mobile phone USB driver Drive Software "SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software "SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software "SearchAnonymizer" = SearchAnonymizer "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinGimp-2.0_is1" = GIMP 2.6.8 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{03534DA5-2F88-4B8E-A978-849B979E1B8F}" = TuxGuitar "{0CE226F3-EB27-4ECD-BBF5-F088716779FD}" = Energy Management "{14A487F2-1259-4E6C-AE3C-3C888DDBCB60}_is1" = Guitar Pro 6 Demo "{17542DBF-E17C-4562-BC4D-FA3EF3076C45}" = Lenovo ReadyComm 5 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 24 "{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in "{2B11BA9C-7F97-4C16-970F-1491FD77969B}_is1" = GutscheinRausch.de - AddOn für Firefox "{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie "{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7644E42D-B096-457F-8B5B-901238FC81AE}" = ICQ7.6 "{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync "{76C66170-C538-4E77-B54D-48E136B5B533}" = Lenovo ReadyComm 5.0 Service "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{7FB6B1B7-075B-4B7F-BEB6-97584F73C7B5}" = Brother MFL-Pro Suite DCP-J515W "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later "{8991E763-21F5-4DEA-A938-5D9D77DCB488}" = Broadcom 802.11 Wireless Driver "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{94056AE8-EF0F-45E4-A1B4-D754115F8A28}" = Numedia CD-DVD writing as non-admin user "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{9600B88C-BE14-4BEA-A529-F5F312900BA3}" = Samsung PC Studio 3 "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 "{AC76BA86-7AD7-1031-7B44-A90100000001}" = Adobe Reader 9.0.1 - Deutsch "{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}" = Lenovo EasyCamera "{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare "{B4089055-D468-45A4-A6BA-5A138DD715FC}" = Bing Bar "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3 "{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail "{DEB7295A-D00E-4D45-846C-2947E8C3F080}_is1" = Picture Collage Maker Free 2.1.2 "{DFB19121-0609-49C1-92B1-546E5A940FE8}" = Onekey Theater "{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update "{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "{FE163F11-1919-4257-A280-FF5AF8DAEECB}" = ICQ Sparberater "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition "Free FLV Converter_is1" = Free FLV Converter V 7.3.0 "Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version "Google Chrome" = Google Chrome "Guitar Explorer 1.0" = Guitar Explorer 1.0 "ICQToolbar" = ICQ Toolbar "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery "InstallShield_{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare "MAGIX 3D Maker D" = MAGIX 3D Maker (embeded) "MAGIX Foto Manager 8 D" = MAGIX Foto Manager 8 (D) "MAGIX Fotobuch" = MAGIX Fotobuch 3.6 "MAGIX Online Druck Service D" = MAGIX Online Druck Service (D) "MAGIX Screenshare D" = MAGIX Screenshare (D) "MAGIX Video deluxe 15 Premium D" = MAGIX Video deluxe 15 Premium (D) "MAGIX Xtreme Foto Designer 6 D" = MAGIX Xtreme Foto Designer 6 (D) "McAfee Security Scan" = McAfee Security Scan Plus "Mozilla Firefox 10.0.1 (x86 de)" = Mozilla Firefox 10.0.1 (x86 de) "Mufin MusicFinder Base D" = Mufin MusicFinder Base (D) "PhotoScape" = PhotoScape "SearchCore for Browsers" = SearchCore for Browsers "Searchqu 413 MediaBar" = Windows Searchqu Toolbar "ShapeCollage" = Shape Collage "StudioLine Photo Classic" = StudioLine Photo Classic "VeriFace" = VeriFace "VLC media player" = VLC media player 1.1.11 "WinLiveSuite_Wave3" = Windows Live Essentials "XP-Games JRE" = XP-Games JRE "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Software Update" = Yahoo! Software Update ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 28.12.2011 07:46:21 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 6770 Error - 28.12.2011 07:46:22 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 28.12.2011 07:46:22 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 7815 Error - 28.12.2011 07:46:22 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 7815 Error - 29.12.2011 14:35:50 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 29.12.2011 14:35:50 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 1279 Error - 29.12.2011 14:35:50 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 1279 Error - 29.12.2011 14:35:51 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 29.12.2011 14:35:51 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 2309 Error - 29.12.2011 14:35:51 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 2309 [ System Events ] Error - 14.02.2012 11:15:25 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 14.02.2012 11:15:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 14.02.2012 11:15:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 14.02.2012 11:15:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 14.02.2012 11:20:13 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 14.02.2012 11:20:13 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 14.02.2012 11:20:13 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 14.02.2012 11:20:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 14.02.2012 11:20:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 14.02.2012 11:20:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 < End of report > |
![]() | #4 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( hi dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user. wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts. • Starte bitte die OTL.exe • Kopiere nun das Folgende in die Textbox. Code:
ATTFilter :OTL O4 - HKCU..\Run: [ffdwnd] C:\Users\Jennifer\AppData\Local\Mozilla\Firefox\firefox.exe (Tomasz Pawlak) :Files C:\Users\Jennifer\AppData\Local\Mozilla\Firefox\firefox.exe :Commands [purity] [EMPTYFLASH] [emptytemp] [Reboot] • Schliesse bitte nun alle Programme. • Klicke nun bitte auf den Fix Button. • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen. • Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren. starte in den normalen modus. falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden Drücke bitte die ![]()
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
![]() | #5 |
![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( Error: Unable to interpret <OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 14.02.2012 16:20:47 - Run 1> in the current context! Error: Unable to interpret <OTL by OldTimer - Version Folder = C:\Users\Jennifer\Downloads> in the current context! Error: Unable to interpret <64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation> in the current context! Error: Unable to interpret <Internet Explorer (Version = 9.0.8112.16421)> in the current context! Error: Unable to interpret <Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <3,87 Gb Total Physical Memory | 3,13 Gb Available Physical Memory | 80,99% Memory free> in the current context! Error: Unable to interpret <7,73 Gb Paging File | 7,09 Gb Available in Paging File | 91,75% Paging File free> in the current context! Error: Unable to interpret <Paging file location(s): ?:\pagefile.sys [binary data]> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)> in the current context! Error: Unable to interpret <Drive C: | 421,81 Gb Total Space | 268,77 Gb Free Space | 63,72% Space Free | Partition Type: NTFS> in the current context! Error: Unable to interpret <Drive D: | 29,00 Gb Total Space | 28,18 Gb Free Space | 97,19% Space Free | Partition Type: NTFS> in the current context! Error: Unable to interpret <Drive F: | 0,67 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Computer Name: JENNIFER-PC | User Name: Jennifer | Logged in as Administrator.> in the current context! Error: Unable to interpret <Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan | Include 64bit Scans> in the current context! Error: Unable to interpret <Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <========== Extra Registry (SafeList) ==========> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <========== File Associations ==========> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]> in the current context! Error: Unable to interpret <.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)> in the current context! Error: Unable to interpret <.url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation)> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]> in the current context! Error: Unable to interpret <.cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation)> in the current context! Error: Unable to interpret <.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]> in the current context! Error: Unable to interpret <.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <========== Shell Spawning ==========> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]> in the current context! Error: Unable to interpret <batfile [open] -- "%1" %*> in the current context! Error: Unable to interpret <cmdfile [open] -- "%1" %*> in the current context! Error: Unable to interpret <comfile [open] -- "%1" %*> in the current context! Error: Unable to interpret <exefile [open] -- "%1" %*> in the current context! Error: Unable to interpret <helpfile [open] -- Reg Error: Key error.> in the current context! Error: Unable to interpret <http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)> in the current context! Error: Unable to interpret <https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)> in the current context! Error: Unable to interpret <inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)> in the current context! Error: Unable to interpret <InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)> in the current context! Error: Unable to interpret <InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)> in the current context! Error: Unable to interpret <piffile [open] -- "%1" %*> in the current context! Error: Unable to interpret <regfile [merge] -- Reg Error: Key error.> in the current context! Error: Unable to interpret <scrfile [config] -- "%1"> in the current context! Error: Unable to interpret <scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l> in the current context! Error: Unable to interpret <scrfile [open] -- "%1" /S> in the current context! Error: Unable to interpret <txtfile [edit] -- Reg Error: Key error.> in the current context! Error: Unable to interpret <Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1> in the current context! Error: Unable to interpret <Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()> in the current context! Error: Unable to interpret <Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)> in the current context! Error: Unable to interpret <Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context! Error: Unable to interpret <Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()> in the current context! Error: Unable to interpret <Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context! Error: Unable to interpret <Folder [explore] -- Reg Error: Value error.> in the current context! Error: Unable to interpret <Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]> in the current context! Error: Unable to interpret <batfile [open] -- "%1" %*> in the current context! Error: Unable to interpret <cmdfile [open] -- "%1" %*> in the current context! Error: Unable to interpret <comfile [open] -- "%1" %*> in the current context! Error: Unable to interpret <cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)> in the current context! Error: Unable to interpret <exefile [open] -- "%1" %*> in the current context! Error: Unable to interpret <helpfile [open] -- Reg Error: Key error.> in the current context! Error: Unable to interpret <http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)> in the current context! Error: Unable to interpret <https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)> in the current context! Error: Unable to interpret <inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)> in the current context! Error: Unable to interpret <piffile [open] -- "%1" %*> in the current context! Error: Unable to interpret <regfile [merge] -- Reg Error: Key error.> in the current context! Error: Unable to interpret <scrfile [config] -- "%1"> in the current context! Error: Unable to interpret <scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l> in the current context! Error: Unable to interpret <scrfile [open] -- "%1" /S> in the current context! Error: Unable to interpret <txtfile [edit] -- Reg Error: Key error.> in the current context! Error: Unable to interpret <Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1> in the current context! Error: Unable to interpret <Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()> in the current context! Error: Unable to interpret <Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)> in the current context! Error: Unable to interpret <Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context! Error: Unable to interpret <Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()> in the current context! Error: Unable to interpret <Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context! Error: Unable to interpret <Folder [explore] -- Reg Error: Value error.> in the current context! Error: Unable to interpret <Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <========== Security Center Settings ==========> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]> in the current context! Error: Unable to interpret <"cval" = 0> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]> in the current context! Error: Unable to interpret <"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]> in the current context! Error: Unable to interpret <"AntiVirusOverride" = 0> in the current context! Error: Unable to interpret <"AntiSpywareOverride" = 0> in the current context! Error: Unable to interpret <"FirewallOverride" = 0> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <========== Firewall Settings ==========> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]> in the current context! Error: Unable to interpret <"DisableNotifications" = 0> in the current context! Error: Unable to interpret <"EnableFirewall" = 1> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]> in the current context! Error: Unable to interpret <"DisableNotifications" = 0> in the current context! Error: Unable to interpret <"EnableFirewall" = 1> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]> in the current context! Error: Unable to interpret <"DisableNotifications" = 0> in the current context! Error: Unable to interpret <"EnableFirewall" = 1> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <========== Authorized Applications List ==========> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <========== HKEY_LOCAL_MACHINE Uninstall List ==========> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]> in the current context! Error: Unable to interpret <"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)> in the current context! Error: Unable to interpret <"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack> in the current context! Error: Unable to interpret <"{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery> in the current context! Error: Unable to interpret <"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10> in the current context! Error: Unable to interpret <"{5E11C972-1E76-45FE-8F92-14E0D1140B1B}" = iTunes> in the current context! Error: Unable to interpret <"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour> in the current context! Error: Unable to interpret <"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support> in the current context! Error: Unable to interpret <"{90140000-0015-0407-1000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010> in the current context! Error: Unable to interpret <"{90140000-0015-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-0016-0407-1000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010> in the current context! Error: Unable to interpret <"{90140000-0016-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-0018-0407-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010> in the current context! Error: Unable to interpret <"{90140000-0018-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-0019-0407-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010> in the current context! Error: Unable to interpret <"{90140000-0019-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-001A-0407-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010> in the current context! Error: Unable to interpret <"{90140000-001A-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-001B-0407-1000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010> in the current context! Error: Unable to interpret <"{90140000-001B-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010> in the current context! Error: Unable to interpret <"{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{70A3169E-288F-454F-A08D-20DF66639B50}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010> in the current context! Error: Unable to interpret <"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010> in the current context! Error: Unable to interpret <"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUSR_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010> in the current context! Error: Unable to interpret <"{90140000-001F-0410-1000-0000000FF1CE}_Office14.PROPLUSR_{3013A793-10A7-4D1F-B8B4-2FAA82F4D259}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010> in the current context! Error: Unable to interpret <"{90140000-002C-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{98782D5D-A9EE-43C6-88AD-B50AD8530E78}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010> in the current context! Error: Unable to interpret <"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-0043-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2010> in the current context! Error: Unable to interpret <"{90140000-0043-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{8DFD91C7-66AE-4E54-9901-5D5F401AD329}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-0044-0407-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010> in the current context! Error: Unable to interpret <"{90140000-0044-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010> in the current context! Error: Unable to interpret <"{90140000-006E-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{8299B64F-1537-4081-974C-033EAB8F098E}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-00A1-0407-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010> in the current context! Error: Unable to interpret <"{90140000-00A1-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{90140000-00BA-0407-1000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010> in the current context! Error: Unable to interpret <"{90140000-00BA-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010> in the current context! Error: Unable to interpret <"{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context! Error: Unable to interpret <"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting> in the current context! Error: Unable to interpret <"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)> in the current context! Error: Unable to interpret <"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053> in the current context! Error: Unable to interpret <"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile> in the current context! Error: Unable to interpret <"0A4175B489A1B4A6E07E11B063A6263480C51D71" = Windows-Treiberpaket - Lenovo (ACPIVPC) System (10/19/2009> in the current context! Error: Unable to interpret <"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit> in the current context! Error: Unable to interpret <"Adobe Flash Player Plugin 64" = Adobe Flash Player 10 Plugin 64-bit> in the current context! Error: Unable to interpret <"CNXT_AUDIO_HDA" = Conexant HD Audio> in the current context! Error: Unable to interpret <"DesktopIconAmazon" = Desktop Icon für Amazon> in the current context! Error: Unable to interpret <"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile> in the current context! Error: Unable to interpret <"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack> in the current context! Error: Unable to interpret <"NVIDIA Drivers" = NVIDIA Drivers> in the current context! Error: Unable to interpret <"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010> in the current context! Error: Unable to interpret <"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software> in the current context! Error: Unable to interpret <"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set> in the current context! Error: Unable to interpret <"Samsung Mobile phone USB driver Drive" = Samsung Mobile phone USB driver Drive Software> in the current context! Error: Unable to interpret <"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software> in the current context! Error: Unable to interpret <"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software> in the current context! Error: Unable to interpret <"SearchAnonymizer" = SearchAnonymizer> in the current context! Error: Unable to interpret <"SynTPDeinstKey" = Synaptics Pointing Device Driver> in the current context! Error: Unable to interpret <"WinGimp-2.0_is1" = GIMP 2.6.8> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]> in the current context! Error: Unable to interpret <"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam> in the current context! Error: Unable to interpret <"{03534DA5-2F88-4B8E-A978-849B979E1B8F}" = TuxGuitar> in the current context! Error: Unable to interpret <"{0CE226F3-EB27-4ECD-BBF5-F088716779FD}" = Energy Management> in the current context! Error: Unable to interpret <"{14A487F2-1259-4E6C-AE3C-3C888DDBCB60}_is1" = Guitar Pro 6 Demo> in the current context! Error: Unable to interpret <"{17542DBF-E17C-4562-BC4D-FA3EF3076C45}" = Lenovo ReadyComm 5> in the current context! Error: Unable to interpret <"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148> in the current context! Error: Unable to interpret <"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool> in the current context! Error: Unable to interpret <"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT> in the current context! Error: Unable to interpret <"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 24> in the current context! Error: Unable to interpret <"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in> in the current context! Error: Unable to interpret <"{2B11BA9C-7F97-4C16-970F-1491FD77969B}_is1" = GutscheinRausch.de - AddOn für Firefox> in the current context! Error: Unable to interpret <"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie> in the current context! Error: Unable to interpret <"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support> in the current context! Error: Unable to interpret <"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform> in the current context! Error: Unable to interpret <"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology> in the current context! Error: Unable to interpret <"{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker> in the current context! Error: Unable to interpret <"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go> in the current context! Error: Unable to interpret <"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger> in the current context! Error: Unable to interpret <"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater> in the current context! Error: Unable to interpret <"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent> in the current context! Error: Unable to interpret <"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call> in the current context! Error: Unable to interpret <"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components> in the current context! Error: Unable to interpret <"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable> in the current context! Error: Unable to interpret <"{7644E42D-B096-457F-8B5B-901238FC81AE}" = ICQ7.6> in the current context! Error: Unable to interpret <"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync> in the current context! Error: Unable to interpret <"{76C66170-C538-4E77-B54D-48E136B5B533}" = Lenovo ReadyComm 5.0 Service> in the current context! Error: Unable to interpret <"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053> in the current context! Error: Unable to interpret <"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update> in the current context! Error: Unable to interpret <"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime> in the current context! Error: Unable to interpret <"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP> in the current context! Error: Unable to interpret <"{7FB6B1B7-075B-4B7F-BEB6-97584F73C7B5}" = Brother MFL-Pro Suite DCP-J515W> in the current context! Error: Unable to interpret <"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570> in the current context! Error: Unable to interpret <"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later> in the current context! Error: Unable to interpret <"{8991E763-21F5-4DEA-A938-5D9D77DCB488}" = Broadcom 802.11 Wireless Driver> in the current context! Error: Unable to interpret <"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight> in the current context! Error: Unable to interpret <"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)> in the current context! Error: Unable to interpret <"{94056AE8-EF0F-45E4-A1B4-D754115F8A28}" = Numedia CD-DVD writing as non-admin user> in the current context! Error: Unable to interpret <"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010> in the current context! Error: Unable to interpret <"{9600B88C-BE14-4BEA-A529-F5F312900BA3}" = Samsung PC Studio 3> in the current context! Error: Unable to interpret <"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader> in the current context! Error: Unable to interpret <"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161> in the current context! Error: Unable to interpret <"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper> in the current context! Error: Unable to interpret <"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5> in the current context! Error: Unable to interpret <"{AC76BA86-7AD7-1031-7B44-A90100000001}" = Adobe Reader 9.0.1 - Deutsch> in the current context! Error: Unable to interpret <"{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}" = Lenovo EasyCamera> in the current context! Error: Unable to interpret <"{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare> in the current context! Error: Unable to interpret <"{B4089055-D468-45A4-A6BA-5A138DD715FC}" = Bing Bar> in the current context! Error: Unable to interpret <"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)> in the current context! Error: Unable to interpret <"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3> in the current context! Error: Unable to interpret <"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail> in the current context! Error: Unable to interpret <"{DEB7295A-D00E-4D45-846C-2947E8C3F080}_is1" = Picture Collage Maker Free 2.1.2> in the current context! Error: Unable to interpret <"{DFB19121-0609-49C1-92B1-546E5A940FE8}" = Onekey Theater> in the current context! Error: Unable to interpret <"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer> in the current context! Error: Unable to interpret <"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update> in the current context! Error: Unable to interpret <"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer> in the current context! Error: Unable to interpret <"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]> in the current context! Error: Unable to interpret <"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard> in the current context! Error: Unable to interpret <"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center> in the current context! Error: Unable to interpret <"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials> in the current context! Error: Unable to interpret <"{FE163F11-1919-4257-A280-FF5AF8DAEECB}" = ICQ Sparberater> in the current context! Error: Unable to interpret <"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX> in the current context! Error: Unable to interpret <"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus> in the current context! Error: Unable to interpret <"Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition> in the current context! Error: Unable to interpret <"Free FLV Converter_is1" = Free FLV Converter V 7.3.0> in the current context! Error: Unable to interpret <"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version> in the current context! Error: Unable to interpret <"Google Chrome" = Google Chrome> in the current context! Error: Unable to interpret <"Guitar Explorer 1.0" = Guitar Explorer 1.0> in the current context! Error: Unable to interpret <"ICQToolbar" = ICQ Toolbar> in the current context! Error: Unable to interpret <"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam> in the current context! Error: Unable to interpret <"InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery> in the current context! Error: Unable to interpret <"InstallShield_{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare> in the current context! Error: Unable to interpret <"MAGIX 3D Maker D" = MAGIX 3D Maker (embeded)> in the current context! Error: Unable to interpret <"MAGIX Foto Manager 8 D" = MAGIX Foto Manager 8 (D)> in the current context! Error: Unable to interpret <"MAGIX Fotobuch" = MAGIX Fotobuch 3.6> in the current context! Error: Unable to interpret <"MAGIX Online Druck Service D" = MAGIX Online Druck Service (D)> in the current context! Error: Unable to interpret <"MAGIX Screenshare D" = MAGIX Screenshare (D)> in the current context! Error: Unable to interpret <"MAGIX Video deluxe 15 Premium D" = MAGIX Video deluxe 15 Premium (D)> in the current context! Error: Unable to interpret <"MAGIX Xtreme Foto Designer 6 D" = MAGIX Xtreme Foto Designer 6 (D)> in the current context! Error: Unable to interpret <"McAfee Security Scan" = McAfee Security Scan Plus> in the current context! Error: Unable to interpret <"Mozilla Firefox 10.0.1 (x86 de)" = Mozilla Firefox 10.0.1 (x86 de)> in the current context! Error: Unable to interpret <"Mufin MusicFinder Base D" = Mufin MusicFinder Base (D)> in the current context! Error: Unable to interpret <"PhotoScape" = PhotoScape> in the current context! Error: Unable to interpret <"SearchCore for Browsers" = SearchCore for Browsers> in the current context! Error: Unable to interpret <"Searchqu 413 MediaBar" = Windows Searchqu Toolbar> in the current context! Error: Unable to interpret <"ShapeCollage" = Shape Collage> in the current context! Error: Unable to interpret <"StudioLine Photo Classic" = StudioLine Photo Classic> in the current context! Error: Unable to interpret <"VeriFace" = VeriFace> in the current context! Error: Unable to interpret <"VLC media player" = VLC media player 1.1.11> in the current context! Error: Unable to interpret <"WinLiveSuite_Wave3" = Windows Live Essentials> in the current context! Error: Unable to interpret <"XP-Games JRE" = XP-Games JRE> in the current context! Error: Unable to interpret <"Yahoo! Companion" = Yahoo! Toolbar> in the current context! Error: Unable to interpret <"Yahoo! Software Update" = Yahoo! Software Update> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <========== HKEY_CURRENT_USER Uninstall List ==========> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]> in the current context! Error: Unable to interpret <"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <========== Last 10 Event Log Errors ==========> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[ Application Events ]> in the current context! Error: Unable to interpret <Error - 28.12.2011 07:46:21 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context! Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledSPRetry 6770> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 28.12.2011 07:46:22 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context! Error: Unable to interpret <Description = Task Scheduling Error: Continuously busy for more than a second> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 28.12.2011 07:46:22 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context! Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledEvent 7815> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 28.12.2011 07:46:22 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context! Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledSPRetry 7815> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 29.12.2011 14:35:50 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context! Error: Unable to interpret <Description = Task Scheduling Error: Continuously busy for more than a second> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 29.12.2011 14:35:50 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context! Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledEvent 1279> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 29.12.2011 14:35:50 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context! Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledSPRetry 1279> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 29.12.2011 14:35:51 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context! Error: Unable to interpret <Description = Task Scheduling Error: Continuously busy for more than a second> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 29.12.2011 14:35:51 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context! Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledEvent 2309> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 29.12.2011 14:35:51 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context! Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledSPRetry 2309> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <[ System Events ]> in the current context! Error: Unable to interpret <Error - 14.02.2012 11:15:25 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context! Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context! Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 14.02.2012 11:15:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context! Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context! Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 14.02.2012 11:15:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context! Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context! Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 14.02.2012 11:15:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context! Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context! Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 14.02.2012 11:20:13 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context! Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context! Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 14.02.2012 11:20:13 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context! Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context! Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 14.02.2012 11:20:13 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context! Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context! Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 14.02.2012 11:20:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context! Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context! Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 14.02.2012 11:20:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context! Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context! Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <Error - 14.02.2012 11:20:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context! Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context! Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret << End of report > > in the current context! OTL by OldTimer - Version log created on 02142012_163813 das hat das Textdokument gesagt. soll ich jetzt Neustarten? OTL hat keinen automatischen Neustart verlangt? und dann ohne F8? einfach ganz normal, tschuldigung ![]() ![]() |
![]() | #6 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( das ist aber nicht mein script, lies noch mal bitte :-)
__________________ --> "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( |
![]() | #7 |
![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( ich habe den Code von deinem letzen Post kopiert und in otl eingefügt , alle programme geschlossen und auf fix gedrückt, das ist das was er mir "ausgespuckt" hat. Ich habe das ganze wiederholt aber ich befürchte ich habe wieder irgendetwas falsch gemacht, error hört sich nicht gut an. Error: Unable to interpret <Error: Unable to interpret <OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 14.02.2012 16:20:47 - Run 1> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <OTL by OldTimer - Version Folder = C:\Users\Jennifer\Downloads> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Internet Explorer (Version = 9.0.8112.16421)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <3,87 Gb Total Physical Memory | 3,13 Gb Available Physical Memory | 80,99% Memory free> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <7,73 Gb Paging File | 7,09 Gb Available in Paging File | 91,75% Paging File free> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Paging file location(s): ?:\pagefile.sys [binary data]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Drive C: | 421,81 Gb Total Space | 268,77 Gb Free Space | 63,72% Space Free | Partition Type: NTFS> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Drive D: | 29,00 Gb Total Space | 28,18 Gb Free Space | 97,19% Space Free | Partition Type: NTFS> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Drive F: | 0,67 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Computer Name: JENNIFER-PC | User Name: Jennifer | Logged in as Administrator.> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan | Include 64bit Scans> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <========== Extra Registry (SafeList) ==========> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <========== File Associations ==========> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <.url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <.cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <========== Shell Spawning ==========> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <batfile [open] -- "%1" %*> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <cmdfile [open] -- "%1" %*> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <comfile [open] -- "%1" %*> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <exefile [open] -- "%1" %*> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <helpfile [open] -- Reg Error: Key error.> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <piffile [open] -- "%1" %*> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <regfile [merge] -- Reg Error: Key error.> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <scrfile [config] -- "%1"> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <scrfile [open] -- "%1" /S> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <txtfile [edit] -- Reg Error: Key error.> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Folder [explore] -- Reg Error: Value error.> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <batfile [open] -- "%1" %*> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <cmdfile [open] -- "%1" %*> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <comfile [open] -- "%1" %*> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <exefile [open] -- "%1" %*> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <helpfile [open] -- Reg Error: Key error.> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <piffile [open] -- "%1" %*> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <regfile [merge] -- Reg Error: Key error.> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <scrfile [config] -- "%1"> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <scrfile [open] -- "%1" /S> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <txtfile [edit] -- Reg Error: Key error.> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Folder [explore] -- Reg Error: Value error.> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <========== Security Center Settings ==========> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"cval" = 0> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"AntiVirusOverride" = 0> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"AntiSpywareOverride" = 0> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"FirewallOverride" = 0> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <========== Firewall Settings ==========> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"DisableNotifications" = 0> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"EnableFirewall" = 1> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"DisableNotifications" = 0> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"EnableFirewall" = 1> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"DisableNotifications" = 0> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"EnableFirewall" = 1> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <========== Authorized Applications List ==========> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <========== HKEY_LOCAL_MACHINE Uninstall List ==========> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{5E11C972-1E76-45FE-8F92-14E0D1140B1B}" = iTunes> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0015-0407-1000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0015-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0016-0407-1000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0016-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0018-0407-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0018-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0019-0407-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0019-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001A-0407-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001A-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001B-0407-1000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001B-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{70A3169E-288F-454F-A08D-20DF66639B50}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUSR_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-001F-0410-1000-0000000FF1CE}_Office14.PROPLUSR_{3013A793-10A7-4D1F-B8B4-2FAA82F4D259}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-002C-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{98782D5D-A9EE-43C6-88AD-B50AD8530E78}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0043-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0043-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{8DFD91C7-66AE-4E54-9901-5D5F401AD329}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0044-0407-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-0044-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-006E-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{8299B64F-1537-4081-974C-033EAB8F098E}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-00A1-0407-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-00A1-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-00BA-0407-1000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{90140000-00BA-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"0A4175B489A1B4A6E07E11B063A6263480C51D71" = Windows-Treiberpaket - Lenovo (ACPIVPC) System (10/19/2009> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Adobe Flash Player Plugin 64" = Adobe Flash Player 10 Plugin 64-bit> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"CNXT_AUDIO_HDA" = Conexant HD Audio> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"DesktopIconAmazon" = Desktop Icon für Amazon> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"NVIDIA Drivers" = NVIDIA Drivers> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Samsung Mobile phone USB driver Drive" = Samsung Mobile phone USB driver Drive Software> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"SearchAnonymizer" = SearchAnonymizer> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"SynTPDeinstKey" = Synaptics Pointing Device Driver> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"WinGimp-2.0_is1" = GIMP 2.6.8> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{03534DA5-2F88-4B8E-A978-849B979E1B8F}" = TuxGuitar> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{0CE226F3-EB27-4ECD-BBF5-F088716779FD}" = Energy Management> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{14A487F2-1259-4E6C-AE3C-3C888DDBCB60}_is1" = Guitar Pro 6 Demo> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{17542DBF-E17C-4562-BC4D-FA3EF3076C45}" = Lenovo ReadyComm 5> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 24> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{2B11BA9C-7F97-4C16-970F-1491FD77969B}_is1" = GutscheinRausch.de - AddOn für Firefox> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{7644E42D-B096-457F-8B5B-901238FC81AE}" = ICQ7.6> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{76C66170-C538-4E77-B54D-48E136B5B533}" = Lenovo ReadyComm 5.0 Service> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{7FB6B1B7-075B-4B7F-BEB6-97584F73C7B5}" = Brother MFL-Pro Suite DCP-J515W> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{8991E763-21F5-4DEA-A938-5D9D77DCB488}" = Broadcom 802.11 Wireless Driver> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{94056AE8-EF0F-45E4-A1B4-D754115F8A28}" = Numedia CD-DVD writing as non-admin user> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{9600B88C-BE14-4BEA-A529-F5F312900BA3}" = Samsung PC Studio 3> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{AC76BA86-7AD7-1031-7B44-A90100000001}" = Adobe Reader 9.0.1 - Deutsch> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}" = Lenovo EasyCamera> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{B4089055-D468-45A4-A6BA-5A138DD715FC}" = Bing Bar> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{DEB7295A-D00E-4D45-846C-2947E8C3F080}_is1" = Picture Collage Maker Free 2.1.2> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{DFB19121-0609-49C1-92B1-546E5A940FE8}" = Onekey Theater> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"{FE163F11-1919-4257-A280-FF5AF8DAEECB}" = ICQ Sparberater> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Free FLV Converter_is1" = Free FLV Converter V 7.3.0> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Google Chrome" = Google Chrome> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Guitar Explorer 1.0" = Guitar Explorer 1.0> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"ICQToolbar" = ICQ Toolbar> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"InstallShield_{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"MAGIX 3D Maker D" = MAGIX 3D Maker (embeded)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"MAGIX Foto Manager 8 D" = MAGIX Foto Manager 8 (D)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"MAGIX Fotobuch" = MAGIX Fotobuch 3.6> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"MAGIX Online Druck Service D" = MAGIX Online Druck Service (D)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"MAGIX Screenshare D" = MAGIX Screenshare (D)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"MAGIX Video deluxe 15 Premium D" = MAGIX Video deluxe 15 Premium (D)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"MAGIX Xtreme Foto Designer 6 D" = MAGIX Xtreme Foto Designer 6 (D)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"McAfee Security Scan" = McAfee Security Scan Plus> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Mozilla Firefox 10.0.1 (x86 de)" = Mozilla Firefox 10.0.1 (x86 de)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Mufin MusicFinder Base D" = Mufin MusicFinder Base (D)> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"PhotoScape" = PhotoScape> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"SearchCore for Browsers" = SearchCore for Browsers> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Searchqu 413 MediaBar" = Windows Searchqu Toolbar> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"ShapeCollage" = Shape Collage> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"StudioLine Photo Classic" = StudioLine Photo Classic> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"VeriFace" = VeriFace> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"VLC media player" = VLC media player 1.1.11> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"WinLiveSuite_Wave3" = Windows Live Essentials> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"XP-Games JRE" = XP-Games JRE> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Yahoo! Companion" = Yahoo! Toolbar> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Yahoo! Software Update" = Yahoo! Software Update> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <========== HKEY_CURRENT_USER Uninstall List ==========> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <========== Last 10 Event Log Errors ==========> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[ Application Events ]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 28.12.2011 07:46:21 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledSPRetry 6770> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 28.12.2011 07:46:22 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Task Scheduling Error: Continuously busy for more than a second> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 28.12.2011 07:46:22 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledEvent 7815> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 28.12.2011 07:46:22 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledSPRetry 7815> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 29.12.2011 14:35:50 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Task Scheduling Error: Continuously busy for more than a second> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 29.12.2011 14:35:50 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledEvent 1279> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 29.12.2011 14:35:50 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledSPRetry 1279> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 29.12.2011 14:35:51 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Task Scheduling Error: Continuously busy for more than a second> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 29.12.2011 14:35:51 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledEvent 2309> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 29.12.2011 14:35:51 | Computer Name = Jennifer-PC | Source = Bonjour Service | ID = 100> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Task Scheduling Error: m->NextScheduledSPRetry 2309> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <[ System Events ]> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 14.02.2012 11:15:25 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 14.02.2012 11:15:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 14.02.2012 11:15:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 14.02.2012 11:15:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 14.02.2012 11:20:13 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 14.02.2012 11:20:13 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 14.02.2012 11:20:13 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 14.02.2012 11:20:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 14.02.2012 11:20:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Error - 14.02.2012 11:20:55 | Computer Name = Jennifer-PC | Source = Service Control Manager | ID = 7001> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret <Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < aufgrund folgenden Fehlers nicht gestartet wurde: %%1068> in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret < > in the current context!> in the current context! Error: Unable to interpret <Error: Unable to interpret << End of report > > in the current context!> in the current context! Error: Unable to interpret < > in the current context! Error: Unable to interpret <OTL by OldTimer - Version log created on 02142012_163813> in the current context! OTL by OldTimer - Version log created on 02142012_164856 Ich weiß nicht, was ich falsch gemacht habe. Entschuldigung, für die zusätzliche Arbeit mir mit. |
![]() | #8 |
![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( Ich hab jetzt nochmal die otl.exe neu ausgeführt. und ich glaube jetzt hat es funktioniert. Ich habe jetzt wieder im abgesicherten Modus neustarten lassen, nach aufforderung von OTL. All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ffdwnd deleted successfully. C:\Users\Jennifer\AppData\Local\Mozilla\Firefox\firefox.exe moved successfully. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default User: Default User User: Jennifer ->Flash cache emptied: 71578 bytes User: Public Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Jennifer ->Temp folder emptied: 857099884 bytes ->Temporary Internet Files folder emptied: 900429465 bytes ->Java cache emptied: 1544753 bytes ->FireFox cache emptied: 1115374388 bytes ->Google Chrome cache emptied: 6451742 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 625879840 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67899 bytes RecycleBin emptied: 415536055 bytes Total Files Cleaned = 3.741,00 mb OTL by OldTimer - Version log created on 02142012_171929 Files\Folders moved on Reboot... File move failed. C:\Users\Jennifer\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot. Registry entries deleted on Reboot... |
![]() | #9 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( 1. im normalen modus starten, der sollte gehen. 2. upload machen wie in post4 beschrieben.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
![]() | #10 |
![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( normaler modus hat funktioniert. upload war erfolgreich und problemlos ![]() Geändert von 00Jenny00 (14.02.2012 um 18:04 Uhr) |
![]() | #11 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( das ist doch schon mal was. bitte surfe vorläufig nur auf von mir genannten seiten, um ne reinfektion zu verhindern. Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde! Bitte downloade dir Combofix.exe und speichere es unbedingt auf deinem Desktop.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
![]() | #12 |
![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( Ich hoffe ich hab alles richtig gemacht. Hier mein Log: Combofix Logfile: Code:
ATTFilter ComboFix 12-02-13.01 - Jennifer 14.02.2012 18:40:35.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3959.2654 [GMT 1:00] ausgeführt von:: c:\users\Jennifer\Downloads\ComboFix.exe AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Windows Searchqu Toolbar c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\as_guid.dat c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\bandoocode.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\data\search\engines.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\data\search\search.xsl c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\about.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\bandoocode.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\dtxpanel.xul c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\dtxpaneltransparent.xul c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\dtxpanelwin.xul c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\dtxprefwin.xul c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\dtxtransparentwin.xul c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\dtxwin.xul c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\emailnotifierproviders.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\external.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\imeshcode.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\neterror.xhtml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\vmncode.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib\wmpstreamer.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\modules\datastore.jsm c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\modules\nsDragAndDrop.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\neterror.xhtml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\partner.coupons.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\preferences.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\radiobeta.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\template.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\toolbar.htm c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\toolbar.xul c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\vmncode.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\vmnrsswin.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\tb_icon.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\widget.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\widget.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\widget_version c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\babylon_logo.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\bandoo.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\bluelite.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\bluesky.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\btn-search-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\btn-search.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\btn-settings-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\btn-settings.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\btn-widgets-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\btn-widgets.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\btn_settings.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\ca.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\dictionary.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\divider.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\downloadcom.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\dtxlogo.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\ebay.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\email.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\email_on.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\facebook.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\games.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphred0.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphred0_5.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphred1.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphred1_5.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphred2.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphred2_5.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphred3.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphred3_5.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphred4.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphred4_5.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphred5.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\graphredna.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\grey.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\ico-shield.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\icon_radio_png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\icon_seperator_png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\icon_twitter.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\icon_youtube.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\images.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\imesh.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\add.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\aol.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\arrow-dn.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\arrow-right-disabled.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\arrow-right.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\arrow-up.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\bg-btn-divider.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\bg-btn-end.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\bg-btn-mdl.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\bg-btn-mdl_ff.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\bg-btn-start.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\bg-btnover-divider.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\bg-btnover-end.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\bg-btnover-mdl.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\bg-btnover-mdl_ff.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\bg-btnover-start.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\blank.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\btn-widgets-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\btn-widgets.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\btn_slider.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\btnback-down-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\btnback-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\btnleft-down-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\btnleft-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\btnright-down-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\btnright-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\button-splitter-down-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\button-splitter-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\checkmark.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\chevron.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\collapse.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\comcast.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\dtx.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\edit-back-hot.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\edit-back.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\expand.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\found.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\gmail.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\highlight.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\highlight_blue.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\highlight_cyan.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\highlight_lime.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\highlight_magenta.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\highlight_yellow.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\hotmail.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\ico-check.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\imap.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\lastsearch-thumb-back.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\loadingMid.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\lock.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\logo-separator.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\mailcom.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\menu_bg-basic.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\menu_separator_bar.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\menu_separator_white.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\menuitem-splitter.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\menuitemback-down-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\menuitemback-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\menuitemleft-down-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\menuitemleft-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\menuitemright-down-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\menuitemright-vista.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\modify.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\move.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\movetarget.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\css\panels.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\css\popupAbout.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\css\popupGames.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\css\popupRSS.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\css\popupWidgets.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\css\dialog.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\bg.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\btn-search.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\btn-wide-close-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\btn-wide-close.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\default.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\tab-off-l.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\tab-off-r.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\tab-on-l.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\tab-on-r.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\transparent.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\ttlbar-left.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\ttlbar-mdl.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\ttlbar-right.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\win-btm-left.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\win-btm-mdl.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\win-btm-right-resize.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\win-btm-right.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\win-left.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images\win-right.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\main.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\scripts\defscript.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\footer.htm c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\gamecategory.xsl c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\gameData.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\gameList.xsl c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\games.xsl c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\gametype.xsl c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\arrow-dn.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\arrow-sml-drop.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\arrow-sml.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\arrow-up.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\arrowr-bluew5.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\bg-aboutbox.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\bg-btnover.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\bg-pnl520x390.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-addtoolbar-left-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-addtoolbar-left.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-addtoolbar-right.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-back.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-close-grey.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-close-greyover.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-drag.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-mdl-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-mdl.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-moredetails.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-next-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-next.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-play-left-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-play-left.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-previous-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-previous.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-right-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-search-pnlbtm.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-try-left-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\btn-try-left.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\bullet-orange.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\gamethumb-on.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\gamethumb2-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\ico-calendar.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\ico-dollar.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\ico-download.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\ico-joystick24.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\ico-news24.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\ico-play.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\ico-tags.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\icon-Add.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\icon-download.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\icon-Info.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\icon-play.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\icon-shop.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\menul-bgon.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\menul-bgover.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\panel-botm-noscroll.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\scroll-bg-206.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\scroll-bg.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\scroll-topwin.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\scrollb-disable.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\scrollb-down.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\scrollb-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\scrollb.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\scrollt-disable.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\scrollt-down.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\scrollt-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\scrollt.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\searchbox-pnlbtm.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\star_x_grey.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\star_x_orange.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\TRUSTe_about.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\view-detailed-on.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\view-detailed-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\view-thumb-on.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\view-thumb-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\widgets-square-16px.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\widgets-square-24px.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images\widgets.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\initHTML.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\popupGames.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\popupHTML.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\popupRSS.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\popupWidgets.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\scroll.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\pop.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\css\manager.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\css\slider.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\bg-pnl.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\btn-close-grey.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\btn-close-greyover.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\collapsed_button.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\expanded_button.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\ico-playstation-down.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\ico-playstation-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\ico-playstation.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\ico-radio.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\music-note.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-btn-pause-on.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-btn-pause.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-btn-play-on.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-btn-play.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-eq-bg.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-eq-buffer.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-eq-busy.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-eq-off.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-eq-on.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-eq-warning.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-options-design-on.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-options-design.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-options-on.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-options.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-volume-0.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-volume-1.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-volume-2.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-volume-3.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\radio-volume-mute.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\scrollbar-handle.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\scrollbar-track.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\slider.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\slideron.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images\track.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\managerpanel.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\volumeslider.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radiobeta-buffering.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radiobeta-connecting.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radiobeta-playing.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radiobeta-stopped.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radiobeta.ico c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\reload.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\remove.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\rename.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\resize-box.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\rss.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\rsschannelback.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\RSSLogo.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\rsstabdivider.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\scroll-left.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\scroll-right.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\search-go.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\search.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\text-ellipsis.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\throbber.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\toolbarsplitter.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\transparent_1px.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_02.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_03.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_04.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_06.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_07.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_08.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_09.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_10.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_11.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_12.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_13.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_14.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_15.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_16.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_18.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_19.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_20.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\border_21.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\btn-close-grey.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\btn-close-greyover.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\close-hot.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\close-normal.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\loadingMid.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\proxy.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\template.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\template.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\templateFF.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa\throbber.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\icons\cond999.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\icons\icons.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\icons\na-s.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\icons\na-t.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\icons\na.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\add.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\box-check.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-check.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\options-weather.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\over-blue.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\over-orange.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\popupWeather.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\popupWeather.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\yahoo.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lichen.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\logo-about.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\logo-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\logo-separator.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\logo.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\mail.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\maps.bmp c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\menuseparatorback.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\modify-save.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\modify.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\modifyhot.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\music.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\news.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-main.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-search.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-weather.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-weather.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-widgets.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\orange.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\pixsy.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\protect-id.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-buffering.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-connecting.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-playing.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-stopped.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta.ico c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\relatedlinks.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-collapse.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-delete.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-expand.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-feed.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-folder-remove.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-folder-rename.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-folder.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-found.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-reload.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-subscribe.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rssback.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rsstopback.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search-over.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search_button_over_png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search_button_png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\searchbar\searchbar-background-left.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\searchbar\searchbar-background-middle.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\searchbar\searchbar-background-right.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\settings.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\shopping.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\siteinfo.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-bluelite.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-bluesky.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-grey.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-lichen.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-orange.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-yellow.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\technorati.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\throbber.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\toolbarsplitter.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\translate.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\video.bmp c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\vmn.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\vmn.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\weather.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\web.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\widgets-square-16px.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\wikipedia.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\yahoosearch.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\yellow.gif c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\youtube.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\zoom.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\components\windowmediator.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\dtUser.exe c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\manifest.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\searchquband.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\uninstall.exe c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\uninstallTB.exe c:\users\Jennifer\Documents\~WRL0003.tmp c:\windows\s.bat . . ((((((((((((((((((((((( Dateien erstellt von 2012-01-14 bis 2012-02-14 )))))))))))))))))))))))))))))) . . 2012-02-14 17:51 . 2012-02-14 17:51 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-02-14 15:37 . 2012-02-14 16:50 -------- d-----w- C:\_OTL 2012-02-14 13:13 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A291D728-BC71-4AEA-A05E-D5EF6929B62C}\mpengine.dll 2012-02-06 11:52 . 2012-02-06 11:52 -------- d-----w- c:\program files\iPod 2012-02-06 11:52 . 2012-02-06 11:53 -------- d-----w- c:\program files\iTunes 2012-02-06 11:52 . 2012-02-06 11:53 -------- d-----w- c:\program files (x86)\iTunes 2012-02-04 20:00 . 2012-02-14 09:38 -------- d-----w- c:\users\Jennifer\AppData\Roaming\gtk-2.0 2012-02-04 20:00 . 2012-02-04 20:00 -------- d-----w- c:\users\Jennifer\.thumbnails 2012-01-30 17:19 . 2012-01-30 17:19 -------- d-----w- c:\users\Jennifer\AppData\Roaming\Canneverbe Limited 2012-01-30 17:19 . 2012-01-30 17:19 -------- d-----w- c:\programdata\Canneverbe Limited 2012-01-30 17:19 . 2012-01-30 17:19 -------- d-----w- c:\program files (x86)\CDBurnerXP 2012-01-30 13:37 . 2012-02-14 10:13 -------- d-----w- c:\users\Jennifer\.gimp-2.6 2012-01-30 13:35 . 2012-01-30 13:35 -------- d-----w- c:\program files\GIMP-2.0 . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-01-26 23:52 . 2010-09-29 13:32 279656 ------w- c:\windows\system32\MpSigStub.exe 2011-12-08 12:28 . 2011-12-12 20:56 311296 ----a-w- c:\windows\SysWow64\TubeFinder.exe 2011-11-24 04:52 . 2011-12-15 22:11 3145216 ----a-w- c:\windows\system32\win32k.sys 2011-11-23 13:27 . 2011-06-06 19:28 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-19 14:58 . 2012-01-11 13:11 77312 ----a-w- c:\windows\system32\packager.dll 2011-11-19 14:01 . 2012-01-11 13:11 67072 ----a-w- c:\windows\SysWow64\packager.dll 2011-11-17 06:41 . 2012-01-11 13:11 1731920 ----a-w- c:\windows\system32\ntdll.dll 2011-11-17 05:38 . 2012-01-11 13:11 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll 2007-01-25 02:52 . 2007-01-25 02:52 65536 ----a-w- c:\program files (x86)\Common Files\NMSAccessU.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FE163F11-1919-4257-A280-FF5AF8DAEECB}] 2011-08-24 13:26 50240 ----a-w- c:\program files (x86)\icq\Internet Explorer\icq.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304] "ICQ"="c:\program files (x86)\ICQ7.6\ICQ.exe" [2011-10-10 127040] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-23 284696] "331BigDog"="c:\program files (x86)\USB Camera\VM331_STI.EXE" [2010-01-15 536576] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-12-03 35184] "VeriFaceManager"="c:\program files (x86)\Lenovo\VeriFace\PManage.exe" [2010-06-25 3122528] "UCam_Menu"="c:\program files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "YouCam Mirror Tray icon"="c:\program files (x86)\Lenovo\YouCam\YouCamTray.exe" [2009-12-22 167008] "UpdateP2GShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-11-12 281768] "TrayServer"="c:\program files (x86)\MAGIX\Video_deluxe_15_Premium\TrayServer.exe" [2008-08-07 90112] "ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688] "BrStsMon00"="c:\program files (x86)\Browny02\Brother\BrStMonW.exe" [2010-02-09 2621440] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "WLStart"="c:\program files (x86)\Windows Live\Installer\wlstart.exe" [2009-07-26 786760] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~2\SEARCH~1\SEARCH~1\datamngr.dll c:\progra~2\SEARCH~1\SEARCH~1\IEBHO.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-29 136176] R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [x] R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1527900] R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-29 136176] R3 IGRS;IGRS;c:\program files (x86)\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152] R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192] R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536] R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 UPnPService;UPnPService;c:\program files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2006-12-14 544768] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WSDPrintDevice;WSD-Druckunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x] R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-30 136360] S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-23 13336] S2 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608] S2 SearchAnonymizer;SearchAnonymizer;c:\users\Jennifer\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [2011-11-07 40960] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-09 2320920] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [x] S3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 vm331avs;Digital Camera 1;c:\windows\system32\Drivers\vm331avs.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP . Inhalt des "geplante Tasks" Ordners . 2012-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-29 14:07] . 2012-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-29 14:07] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc] @="{771C7324-DA80-49D3-8017-753B0AF60951}" [HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}] 2010-06-25 10:18 1502720 ----a-w- c:\windows\System32\IcnOvrly.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-11 16414312] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272] "OnekeyStudio"="c:\program files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe" [2009-12-19 776608] "EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\utility.exe" [2009-12-17 4367808] "Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2009-12-17 6988736] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512] "Ocs_SM"="c:\users\Jennifer\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2011-11-07 106496] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 "AppInit_DLLs"=c:\progra~2\SEARCH~1\SEARCH~1\x64\datamngr.dll c:\progra~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.searchqu.com/413 uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: Free YouTube to MP3 Converter - c:\users\Jennifer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe TCP: DhcpNameServer = DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} - hxxp://www.o2c.de/download/o2cplayer.cab FF - ProfilePath - c:\users\Jennifer\AppData\Roaming\Mozilla\Firefox\Profiles\lrydn7vs.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.3&q= FF - prefs.js: browser.search.selectedEngine - ICQ Search FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/413 FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&appid=0&systemid=413&sr=0&q= FF - prefs.js: network.proxy.type - 0 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Toolbar-10 - (no file) Toolbar-Locked - (no file) Toolbar-10 - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-Searchqu 413 MediaBar - c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\uninstallTB.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10s_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10s_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2012-02-14 18:56:33 ComboFix-quarantined-files.txt 2012-02-14 17:56 . Vor Suchlauf: 12 Verzeichnis(se), 291.807.346.688 Bytes frei Nach Suchlauf: 17 Verzeichnis(se), 291.433.205.760 Bytes frei . - - End Of File - - E273A712884AD46B872E97E3E43A9827 |
![]() | #13 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( malwarebytes: Downloade Dir bitte Malwarebytes
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
![]() | #14 |
![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( Malware hat gesagt 0 infizierte Objekte von daher konnte ich auch keine Funde löschen. Hier die Logfile: Malwarebytes Anti-Malware Malwarebytes : Free anti-malware, anti-virus and spyware removal download Datenbank Version: v2012.02.14.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Jennifer :: JENNIFER-PC [Administrator] 14.02.2012 19:40:34 mbam-log-2012-02-14 (19-40-34).txt Art des Suchlaufs: Vollständiger Suchlauf Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 361330 Laufzeit: 48 Minute(n), 21 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
![]() | #15 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( sehr schön. lade den CCleaner standard: CCleaner Download - CCleaner 3.15.1643 falls der CCleaner bereits instaliert, überspringen. instalieren, öffnen, extras, liste der instalierten programme, als txt speichern. öffnen. hinter, jedes von dir benötigte programm, schreibe notwendig. hinter, jedes, von dir nicht benötigte, unnötig. hinter, dir unbekannte, unbekannt. liste posten.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
![]() |
Themen zu "Ihr Windowssystem wurde aus Sicherheitsgründen blockiert" :( |
abgesicherte, abgesicherten, abgesicherten modus, aus sicherheitsgründen, bezahlen, bezahlen und runterladen, blockiert, infizierte, infizierten, konto, laien, laptop, modus, momentan, netzwerk, runterladen, schnelle, schöne, schönen, sicherheitsgründe, sicherheitsgründen, tan, windows, windowssystem, zusammen |