![]() |
|
Log-Analyse und Auswertung: Windows XP extrem langsamWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Windows XP extrem langsam Seit einiger Zeit ist mein System extrem langsam. ![]() Code:
ATTFilter ult of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-09-2014 Ran by Thomas (administrator) on BUERO on 28-09-2014 10:54:42 Running from C:\Dokumente und Einstellungen\Thomas\Eigene Dateien\Downloads Loaded Profile: Thomas (Available profiles: Thomas & Administrator) Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 6 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Programme\WISO Internet Security\sched.exe (Avira Operations GmbH & Co. KG) C:\Programme\WISO Internet Security\avfwsvc.exe (Avira Operations GmbH & Co. KG) C:\Programme\WISO Internet Security\avguard.exe (REINER SCT) C:\WINDOWS\system32\cjpcsc.exe (Oracle Corporation) C:\Programme\Java\jre7\bin\jqs.exe (Google Inc.) C:\Programme\Google\Update\GoogleUpdate.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (Nuance Communications, Inc.) C:\Programme\Nuance\PaperPort\PDFProFiltSrvPP.exe (Avira Operations GmbH & Co. KG) C:\Programme\WISO Internet Security\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Programme\WISO Internet Security\avmailc.exe (Avira Operations GmbH & Co. KG) C:\Programme\WISO Internet Security\avwebgrd.exe (Avira Operations GmbH & Co. KG) C:\Programme\WISO Internet Security\avgnt.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe (Oracle Corporation) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Google Inc.) C:\Programme\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Programme\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Programme\Google\Chrome\Application\chrome.exe () C:\Dokumente und Einstellungen\Thomas\Eigene Dateien\Downloads\Defogger.exe (Farbar) C:\Dokumente und Einstellungen\Thomas\Eigene Dateien\Downloads\FRST (1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [avgnt] => C:\Programme\WISO Internet Security\avgnt.exe [751184 2014-08-15] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [20145368 2013-10-04] (Realtek Semiconductor Corp.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [SunJavaUpdateSched] => C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) Winlogon\Notify\ComPlusSetup: C:\WINDOWS\system32\catsrvut.dll (Microsoft Corporation) HKU\S-1-5-21-329068152-1614895754-839522115-1004\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-329068152-1614895754-839522115-1004\...\MountPoints2: G - G:\run_cdviewer.exe HKU\S-1-5-21-329068152-1614895754-839522115-1004\...\MountPoints2: {f4b66a04-a60f-11e3-88a1-001966d63440} - D:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-329068152-1614895754-839522115-1004\...\MountPoints2: {f4b66a09-a60f-11e3-88a1-001966d63440} - D:\.\Setup.exe AUTORUN=1 ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home SearchScopes: HKCU - {8910DCFA-4A26-4E9D-9711-AF8F6A7BEB1C} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=8E24CBBA-7E56-43F4-AB9F-B98C7486F4F9&apn_sauid=31F5FBC5-E101-4C0A-90B5-8B6092D66114 SearchScopes: HKCU - {95449E35-ABB7-4966-B9DA-48D6805CA61A} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=644aa6b8000000000000001966d63440&r=453 BHO: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Programme\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - &Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1391712990718 Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Winsock: Catalog9 01 C:\Programme\WISO Internet Security\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Programme\WISO Internet Security\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 20 C:\Programme\WISO Internet Security\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Tcpip\..\Interfaces\{0247EB4E-153B-4E13-9FEE-977B6AE7AE6B}: [NameServer] 212.6.108.142,212.6.64.15 FireFox: ======== FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Programme\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Programme\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Programme\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader -> C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-07-04] Chrome: ======= CHR CustomProfile: C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-27] CHR Extension: (YouTube) - C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-07-03] CHR Extension: (Google Search) - C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-07-03] CHR Extension: (Google Wallet) - C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Amazon) - C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj [2014-08-21] CHR Extension: (Fade to White Aero Skin (by Skarv)) - C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\oekemfmehiakocmomemagciajlikigkl [2013-11-27] CHR Extension: (Gmail) - C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-07-03] CHR HKLM\...\Chrome\Extension: [ocbnpbkmjpgbdcgiflkgkpnkinifpgpj] - C:\Dokumente und Einstellungen\Thomas\ChromeExtensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj\amazon-icon-2.crx [2014-08-21] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirFirewallService; C:\Programme\WISO Internet Security\avfwsvc.exe [1043024 2014-08-15] (Avira Operations GmbH & Co. KG) R2 AntiVirMailService; C:\Programme\WISO Internet Security\avmailc.exe [802384 2014-08-15] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Programme\WISO Internet Security\sched.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Programme\WISO Internet Security\avguard.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Programme\WISO Internet Security\AVWEBGRD.EXE [1021008 2014-08-15] (Avira Operations GmbH & Co. KG) S4 BrYNSvc; C:\Programme\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [File not signed] R2 cjpcsc; C:\WINDOWS\system32\cjpcsc.exe [514128 2012-03-19] (REINER SCT) S4 CLCapSvc; C:\Programme\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe [221281 2005-06-20] () [File not signed] S4 CLSched; C:\Programme\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe [110687 2005-06-20] () [File not signed] S4 CyberLink Media Library Service; C:\Programme\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe [61440 2005-06-20] (Cyberlink) [File not signed] S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2012-07-03] (Google Inc.) S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2012-07-03] (Google Inc.) S4 IDriverT; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 JavaQuickStarterService; C:\Programme\Java\jre7\bin\jqs.exe [182696 2014-09-24] (Oracle Corporation) S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [89136 2003-07-28] (Microsoft Corporation) R2 PDFProFiltSrvPP; C:\Programme\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.) S2 spupdsvc; C:\WINDOWS\system32\spupdsvc.exe [26144 2009-01-07] (Microsoft Corporation) S4 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-11-03] (Microsoft Corporation) [File not signed] S4 x10nets; C:\Programme\Common Files\X10\Common\X10nets.exe [20480 2001-11-12] (X10) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 3xHybrid; C:\WINDOWS\System32\DRIVERS\3xHybrid.sys [799744 2005-06-08] (Philips Semiconductors GmbH) S3 61883; C:\WINDOWS\System32\DRIVERS\61883.sys [48128 2008-04-14] (Microsoft Corporation) S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative) R3 avfwim; C:\WINDOWS\System32\DRIVERS\avfwim.sys [92448 2013-04-15] (Avira GmbH) R1 avfwot; C:\WINDOWS\System32\DRIVERS\avfwot.sys [113024 2013-04-15] (Avira GmbH) R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [97648 2014-08-15] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [136216 2014-08-15] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37352 2014-08-15] (Avira Operations GmbH & Co. KG) R3 avmaudio; C:\WINDOWS\System32\DRIVERS\avmaudio.sys [101248 2012-07-04] (AVM Berlin) [File not signed] R1 bizVSerial; C:\WINDOWS\System32\drivers\bizVSerialNT.sys [14949 2007-05-31] (franson.biz) [File not signed] R3 BrScnUsb; C:\WINDOWS\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation) R3 cjcmw2k; C:\WINDOWS\System32\drivers\cjcmw2k.sys [4779 2001-06-12] (REINER SCT powered by SII) [File not signed] R2 cjIfdKb; C:\WINDOWS\System32\drivers\cjIfdKb.sys [29412 2001-05-17] (REINER SCT) [File not signed] R2 cjIfdLpt; C:\WINDOWS\System32\drivers\cjIfdLpt.sys [29412 2001-05-17] (REINER SCT) [File not signed] R2 cjIfdusb01; C:\WINDOWS\System32\drivers\cjIfdu01.sys [29444 2001-05-17] (REINER SCT) [File not signed] R2 cjIfdusb02; C:\WINDOWS\System32\drivers\cjIfdu02.sys [29444 2001-05-17] (REINER SCT) [File not signed] S3 cxbu1wdm; C:\WINDOWS\System32\DRIVERS\cxbu1wdm.sys [93312 2008-08-05] ( ) R2 drhard; C:\WINDOWS\system32\Drivers\drhard.sys [23600 2005-12-01] (Licensed for Gebhard Software) [File not signed] R3 FETND5BV; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [42496 2005-03-18] (VIA Technologies, Inc. ) R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-14] (Microsoft Corporation) R0 giveio; C:\WINDOWS\System32\giveio.sys [5248 1996-04-03] () [File not signed] S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [51024 2003-03-10] (HP) S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16080 2003-03-10] (HP) S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21456 2003-03-10] (HP) S3 IIUSBISP; C:\WINDOWS\System32\Drivers\iiusbisp.sys [15883 2013-05-14] (Windows (R) 2000 DDK provider) [File not signed] R1 ISODrive; C:\Programme\UltraISO\drivers\ISODrive.sys [82320 2010-01-29] (EZB Systems, Inc.) R3 MarvinBus; C:\WINDOWS\System32\DRIVERS\MarvinBus.sys [171520 2005-09-23] (Pinnacle Systems GmbH) [File not signed] S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.) S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2008-04-14] (Microsoft Corporation) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation) R1 PQNTDrv; C:\WINDOWS\system32\Drivers\PQNTDrv.sys [4228 2004-05-05] (PowerQuest Corporation) [File not signed] R3 ps2port; C:\WINDOWS\System32\drivers\ps2port.sys [55144 2001-06-12] (DESKO GmbH) [File not signed] R1 rsct_bus; C:\WINDOWS\System32\DRIVERS\rsct_bus.sys [11776 2007-05-31] (REINER SCT) [File not signed] R3 rsct_dev; C:\WINDOWS\System32\DRIVERS\rsct_dev.sys [11776 2007-05-31] (REINER SCT) [File not signed] R0 speedfan; C:\WINDOWS\System32\speedfan.sys [25240 2011-03-18] (Almico Software) R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2013-04-15] (Avira GmbH) S3 SunkFilt; C:\WINDOWS\System32\Drivers\sunkfilt.sys [40544 2003-11-25] (Alcor Micro Corp.) [File not signed] R0 videX32; C:\WINDOWS\System32\DRIVERS\videX32.sys [9216 2006-10-17] (VIA Technologies, Inc.) R0 vidsflt53; C:\WINDOWS\System32\DRIVERS\vsflt53.sys [83392 2013-04-05] (Acronis) S3 vncmirror; C:\WINDOWS\System32\DRIVERS\vncmirror.sys [4608 2013-03-04] (RealVNC Ltd.) R3 WmBEnum; C:\WINDOWS\System32\drivers\WmBEnum.sys [22856 2010-04-27] (Logitech Inc.) R3 WmFilter; C:\WINDOWS\System32\drivers\WmFilter.sys [37704 2010-04-27] (Logitech Inc.) S3 WmVirHid; C:\WINDOWS\System32\drivers\WmVirHid.sys [15048 2010-04-27] (Logitech Inc.) R3 WmXlCore; C:\WINDOWS\System32\drivers\WmXlCore.sys [66632 2010-04-27] (Logitech Inc.) S3 WpdUsb; C:\WINDOWS\System32\DRIVERS\wpdusb.sys [38528 2006-10-18] (Microsoft Corporation) [File not signed] R3 XUIF; C:\WINDOWS\System32\Drivers\x10ufx2.sys [17792 2005-05-19] (X10 Wireless Technology, Inc.) S3 cpuz137; \??\C:\WINDOWS\TEMP\cpuz137\cpuz137_x32.sys [X] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 FETNDIS; system32\DRIVERS\fetnd5.sys [X] S3 GPUZ; \??\C:\WINDOWS\TEMP\GPUZ.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S3 int15.sys; \??\O:\3 FAT32\int15.sys [X] S4 IntelIde; No ImagePath S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X] S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X] S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X] U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) S2 StarOpen; No ImagePath S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-28 10:52 - 2014-09-28 10:52 - 00000000 _____ () C:\Dokumente und Einstellungen\Thomas\defogger_reenable 2014-09-24 12:19 - 2014-09-24 12:19 - 00000000 ____D () C:\Dokumente und Einstellungen\Thomas\Eigene Dateien\Buhl 2014-09-24 12:17 - 2014-09-24 12:17 - 00000000 ____D () C:\Dokumente und Einstellungen\Thomas\Anwendungsdaten\Buhl Data Service 2014-09-24 11:51 - 2014-09-24 11:51 - 00000000 ____D () C:\Dokumente und Einstellungen\Thomas\Anwendungsdaten\Oracle 2014-09-24 11:46 - 2014-09-24 11:46 - 00000000 ____D () C:\Programme\Gemeinsame Dateien\Java 2014-09-24 11:45 - 2014-09-24 11:44 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2014-09-24 11:45 - 2014-09-24 11:44 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2014-09-24 11:45 - 2014-09-24 11:44 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2014-09-24 11:45 - 2014-09-24 11:44 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2014-09-24 11:45 - 2014-09-24 11:44 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2014-09-24 11:40 - 2014-09-24 11:40 - 00000000 ____D () C:\Dokumente und Einstellungen\Thomas\Anwendungsdaten\Zeon 2014-09-22 11:56 - 2014-09-22 11:56 - 00002354 _____ () C:\Accountnummer ändern.eml 2014-09-16 10:24 - 2014-09-16 10:24 - 00001669 _____ () C:\WINDOWS\setupapi.log 2014-09-07 13:30 - 2014-09-28 10:20 - 00007978 _____ () C:\WINDOWS\SchedLgU.Txt 2014-09-07 10:44 - 2014-09-07 10:44 - 00044158 _____ () C:\Dokumente und Einstellungen\Thomas\Eigene Dateien\cc_20140907_104433.reg 2014-09-04 11:02 - 2014-09-04 11:04 - 00000190 ___SH () C:\Dokumente und Einstellungen\Administrator\ntuser.ini 2014-09-04 11:02 - 2014-09-04 11:02 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator 2014-09-04 11:02 - 2014-07-27 19:28 - 00001599 _____ () C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Remoteunterstützung.lnk 2014-09-04 11:02 - 2014-07-27 19:28 - 00000772 _____ () C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Windows Media Player.lnk 2014-09-04 11:02 - 2014-07-27 19:28 - 00000000 ___RD () C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme 2014-09-04 11:02 - 2014-07-27 19:26 - 00000000 ___RD () C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Zubehör 2014-09-04 11:02 - 2013-10-16 17:33 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google 2014-09-04 11:02 - 2012-07-02 19:57 - 00000000 ___SD () C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Verlauf 2014-09-04 11:02 - 2012-07-02 19:57 - 00000000 ___RD () C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Autostart 2014-09-04 11:02 - 2012-07-02 19:57 - 00000000 ___RD () C:\Dokumente und Einstellungen\Administrator\Startmenü 2014-09-04 11:02 - 2012-07-02 19:57 - 00000000 ___HD () C:\Dokumente und Einstellungen\Administrator\Netzwerkumgebung 2014-09-04 11:02 - 2012-07-02 19:57 - 00000000 ___HD () C:\Dokumente und Einstellungen\Administrator\Druckumgebung 2014-09-04 11:02 - 2012-07-02 19:57 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp 2014-09-04 09:44 - 2014-09-04 10:24 - 00000000 ____D () C:\Dokumente und Einstellungen\Thomas\Anwendungsdaten\Nico Mak Computing ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-28 10:55 - 2012-07-02 21:16 - 00000000 ____D () C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Temp 2014-09-28 10:54 - 2014-03-24 15:36 - 00000000 ____D () C:\FRST 2014-09-28 10:52 - 2012-07-02 21:16 - 00000000 ____D () C:\Dokumente und Einstellungen\Thomas 2014-09-28 10:33 - 2014-08-07 11:33 - 00004838 _____ () C:\WINDOWS\system32\nvAppTimestamps 2014-09-28 10:27 - 2013-08-10 14:48 - 00000000 ____D () C:\Programme\WISO Internet Security 2014-09-28 10:27 - 2013-08-10 14:48 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WISO Internet Security 2014-09-28 10:25 - 2012-07-02 19:58 - 01224754 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-09-28 10:23 - 2012-07-02 21:09 - 01172329 _____ () C:\WINDOWS\WindowsUpdate.log 2014-09-28 10:21 - 2012-07-02 22:04 - 00000157 _____ () C:\WINDOWS\wiadebug.log 2014-09-28 10:21 - 2012-07-02 22:04 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-09-28 10:20 - 2012-07-02 21:13 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-09-28 10:20 - 2004-08-04 14:00 - 00011936 _____ () C:\WINDOWS\system32\wpa.dbl 2014-09-26 12:09 - 2012-07-02 21:16 - 00000300 ___SH () C:\Dokumente und Einstellungen\Thomas\ntuser.ini 2014-09-26 12:04 - 2012-07-03 21:50 - 00001016 ____C () C:\WINDOWS\wiso.ini 2014-09-26 11:10 - 2012-07-03 17:10 - 00000000 ____D () C:\Dokumente und Einstellungen\Thomas\Eigene Dateien\WISO Mein Geld 2014-09-24 12:07 - 2014-05-30 14:27 - 00000000 ____D () C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Anwendungsdaten\Genymobile 2014-09-24 12:00 - 2012-07-02 19:57 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme 2014-09-24 11:57 - 2013-06-27 11:29 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\boost_interprocess 2014-09-24 11:54 - 2013-06-11 10:26 - 00000033 _____ () C:\Dokumente und Einstellungen\Thomas\.STICK_TYP_VOREINSTELLUNG 2014-09-24 11:44 - 2012-07-04 11:54 - 00000000 ____D () C:\Programme\Java 2014-09-24 11:38 - 2012-07-05 15:37 - 00000116 _____ () C:\WINDOWS\NeroDigital.ini 2014-09-24 11:24 - 2014-05-30 14:27 - 00000000 ____D () C:\Dokumente und Einstellungen\Thomas\.VirtualBox 2014-09-13 17:21 - 2012-07-02 21:13 - 00000190 __SHC () C:\Dokumente und Einstellungen\LocalService\ntuser.ini 2014-09-13 17:21 - 2012-07-02 21:13 - 00000000 __SHD () C:\Dokumente und Einstellungen\LocalService 2014-09-13 11:06 - 2012-09-03 11:39 - 00079872 _____ () C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-09-11 14:08 - 2013-08-10 15:05 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-09-11 13:59 - 2012-07-03 15:02 - 98758480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-09-09 18:00 - 2012-08-21 09:50 - 00000151 _____ () C:\WINDOWS\PhotoSnapViewer.INI 2014-09-09 17:43 - 2012-07-16 14:26 - 00000020 ____H () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLet.DAT 2014-09-09 17:39 - 2013-05-11 13:54 - 00159744 ___SH () C:\Dokumente und Einstellungen\Thomas\Eigene Dateien\Thumbs.db 2014-09-07 19:26 - 2012-07-03 17:15 - 00000000 ____D () C:\Dokumente und Einstellungen\Thomas.MEDION\Eigene Dateien\Mein Geld 2014-09-07 10:33 - 2012-07-03 13:59 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Geräte 2014-09-06 10:43 - 2012-07-02 20:54 - 00000335 ___SH () C:\boot.ini 2014-09-05 23:30 - 2012-07-02 19:58 - 00000000 ___RD () C:\Programme 2014-09-04 09:04 - 2012-07-03 12:32 - 00000000 ___HD () C:\Programme\InstallShield Installation Information Some content of TEMP: ==================== C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Temp\avgnt.exe C:\Dokumente und Einstellungen\Thomas\Lokale Einstellungen\Temp\ltmnbs6x.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 27-09-2014 Ran by Thomas at 2014-09-28 11:22:25 Running from C:\Dokumente und Einstellungen\Thomas\Eigene Dateien\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: WISO Internet Security (Disabled - Up to date) {A4322069-7AB8-4BAE-8341-EA08CA339921} FW: FireWall (Disabled) {A4322069-7AB8-4BAE-8341-EA08CA339921} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 123 Free Solitaire 2011 v8.0 (HKLM\...\123 Free Solitaire_is1) (Version: - TreeCardGames) 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) Adobe Reader X (10.1.11) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated) Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Audacity 2.0 (HKLM\...\Audacity_is1) (Version: - Audacity Team) Biet-O-Matic v2.14.8 (HKLM\...\Biet-O-Matic v2.14.8) (Version: 2.14.8 - BOM Development Team) Brother MFL-Pro Suite MFC-J5910DW (HKLM\...\{830F55B6-4398-4B72-A0D8-66397B902C0E}) (Version: 1.0.5.0 - Brother Industries, Ltd.) CCleaner (HKLM\...\CCleaner) (Version: 4.16 - Piriform) cyberJack Base Components (HKLM\...\{FC338210-F594-11D3-BA24-00001C3AB4DF}) (Version: 6.10.0 - REINER SCT) Dr. Hardware 2013 13.6d (HKLM\...\Dr. Hardware 2013_is1) (Version: - Peter A. Gebhard) DriverTuner 3.1.0.1 (HKLM\...\{520C1D80-935C-42B9-9340-E883849D804F}_is1) (Version: 3.1.0.1 - LionSea SoftWare) EaseUS Data Recovery Wizard 5.8.5 (HKLM\...\EaseUS Data Recovery Wizard 5.8.5_is1) (Version: - EaseUS) G&D StarSign USB Token für ELSTER (HKLM\...\InstallShield_{636BAD38-26BC-4BD8-802B-F18ED2D48D65}) (Version: 1.1.3 - Secunet Security Networks AG) G&D StarSign USB Token für ELSTER (Version: 1.1.3 - Secunet Security Networks AG) Hidden Genymotion version 2.2.2 (HKLM\...\{6D180286-D4DF-40EF-9227-923B9C07C08A}_is1) (Version: 2.2.2 - Genymobile) Google Chrome (HKLM\...\Google Chrome) (Version: 37.0.2062.124 - Google Inc.) Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden Hotfix für Windows XP (KB952287) (HKLM\...\KB952287) (Version: 1 - Microsoft Corporation) Hotfix für Windows XP (KB961118) (HKLM\...\KB961118) (Version: 1 - Microsoft Corporation) Inkscape 0.48.3.1 (HKLM\...\Inkscape) (Version: 0.48.3.1 - ) Java 7 Update 67 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle) Java Auto Updater (Version: 2.1.67.1 - Oracle, Inc.) Hidden JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) Knoll Light Factory EZ Studio (HKLM\...\Knoll Light Factory EZ Studio) (Version: - ) Landwirtschafts Simulator 2011 (HKLM\...\FarmingSimulator2011DE_is1) (Version: 1.0 - GIANTS Software) LetsTrade Komponenten (HKLM\...\LetsTrade) (Version: - ) Mein Verein (HKLM\...\{9ACE3A18-EE13-4012-989C-2BCDC95BA6B9}_is1) (Version: 14.0 - Buhl Data Service GmbH) Microsoft .NET Framework 2.0 Language Pack - DEU (HKLM\...\Microsoft .NET Framework 2.0 Language Pack - DEU) (Version: - Microsoft Corporation) Microsoft .NET Framework 2.0 Language Pack - DEU (Version: 1.1.50727.42 - Microsoft Corporation) Hidden Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation) Microsoft .NET Framework 3.0 German Language Pack (HKLM\...\Microsoft .NET Framework 3.0 German Language Pack) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.0 German Language Pack (Version: 3.0.04506.30 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (HKLM\...\{90110407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Picture It! Foto 2001 (HKLM\...\{D28FDA7D-15C6-48A2-9868-6BCB28BE6254}) (Version: 5.0.0.0000 - Microsoft) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works 2001-Setup-Start (HKLM\...\Works2001Setup) (Version: - ) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MSXML 6.0 Parser (HKLM\...\{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}) (Version: 6.10.1129.0 - Microsoft Corporation) Multimedia Card Reader (HKLM\...\InstallShield_{57E0A4F0-A81A-4D69-82FF-3ECC068DD60E}) (Version: 1.00 - ) Multimedia Card Reader (Version: 1.00 - ) Hidden Nero Suite (HKLM\...\NeroMultiInstaller!UninstallKey) (Version: - ) Nikon File Uploader 2 (HKLM\...\{D1E7142C-6BC3-49EB-A71A-E5D7ADAC7599}) (Version: 2.0.2 - Nikon) Nikon Message Center 2 (HKLM\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon) Nikon Movie Editor (HKLM\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.8.0 - Nikon) Norton PartitionMagic (Version: 8.05.000 - Symantec) Hidden Norton PartitionMagic 8.0 (HKLM\...\InstallShield_{21DBBDD6-93A5-4326-9A04-C9A5C9148502}) (Version: 8.05.000 - Symantec) Nuance PaperPort 12 (HKLM\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.) Nuance PDF Viewer Plus (HKLM\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc) NVIDIA Grafiktreiber 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.157.1165 - NVIDIA Corporation) Hidden NVIDIA PhysX (Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA Systemsteuerung 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden OpenAL (HKLM\...\OpenAL) (Version: - ) Oracle VM VirtualBox 4.2.12 (HKLM\...\{5FA29565-1B72-488F-B975-E3C76F179F36}) (Version: 4.2.12 - Oracle Corporation) PaperPort Image Printer (HKLM\...\{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}) (Version: 1.00.0001 - Nuance Communications, Inc.) PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.9.2 - pdfforge) PhotoScape (HKLM\...\PhotoScape) (Version: - ) Picture Control Utility (HKLM\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.4.13 - Nikon) Pinnacle Studio 14 (HKLM\...\{AADD1C8F-D59F-4D55-A726-768C71A205A8}) (Version: 14.0.0.7255 - Pinnacle Systems) Pinnacle Studio Ultimate Plugins (HKLM\...\{65173BC2-60E7-4DE8-A61D-A81FCB96EE93}) (Version: 14.0.0.7255 - Pinnacle Systems) Pinnacle Video Treiber (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.030 - Pinnacle Systems) Platform (Version: 1.22 - VIA Technologies, Inc.) Hidden PowerCinema 4.0 (HKLM\...\{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: - ) PowerDVD (HKLM\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: - ) Pro Evolution Soccer 2010 (HKLM\...\{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}) (Version: 1.00.0000 - KONAMI) QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.7111 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30101 - Realtek Semiconductor Corp.) Red Giant ToonIt Studio (HKLM\...\Red Giant ToonIt Studio) (Version: - ) Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Scansoft PDF Professional (Version: - ) Hidden Security Task Manager 1.8g (HKLM\...\Security Task Manager) (Version: 1.8g - Neuber Software) Sicherheitsupdate für Microsoft Windows (KB2564958) (HKLM\...\KB2564958) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2115168) (HKLM\...\KB2115168) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2229593) (HKLM\...\KB2229593) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2296011) (HKLM\...\KB2296011) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2347290) (HKLM\...\KB2347290) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2387149) (HKLM\...\KB2387149) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2393802) (HKLM\...\KB2393802) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2419632) (HKLM\...\KB2419632) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2423089) (HKLM\...\KB2423089) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2443105) (HKLM\...\KB2443105) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2478960) (HKLM\...\KB2478960) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2478971) (HKLM\...\KB2478971) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2479943) (HKLM\...\KB2479943) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2481109) (HKLM\...\KB2481109) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2483185) (HKLM\...\KB2483185) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2485663) (HKLM\...\KB2485663) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2506212) (HKLM\...\KB2506212) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2507938) (HKLM\...\KB2507938) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2508429) (HKLM\...\KB2508429) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2509553) (HKLM\...\KB2509553) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2510581) (HKLM\...\KB2510581) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2535512) (HKLM\...\KB2535512) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2536276-v2) (HKLM\...\KB2536276-v2) (Version: 2 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2544893-v2) (HKLM\...\KB2544893-v2) (Version: 2 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2566454) (HKLM\...\KB2566454) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2570947) (HKLM\...\KB2570947) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2584146) (HKLM\...\KB2584146) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2585542) (HKLM\...\KB2585542) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2592799) (HKLM\...\KB2592799) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2598479) (HKLM\...\KB2598479) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2603381) (HKLM\...\KB2603381) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2619339) (HKLM\...\KB2619339) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2620712) (HKLM\...\KB2620712) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2631813) (HKLM\...\KB2631813) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2653956) (HKLM\...\KB2653956) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2655992) (HKLM\...\KB2655992) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2659262) (HKLM\...\KB2659262) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2676562) (HKLM\...\KB2676562) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2686509) (HKLM\...\KB2686509) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2691442) (HKLM\...\KB2691442) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2698365) (HKLM\...\KB2698365) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2705219-v2) (HKLM\...\KB2705219-v2) (Version: 2 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2712808) (HKLM\...\KB2712808) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2719985) (HKLM\...\KB2719985) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2723135-v2) (HKLM\...\KB2723135-v2) (Version: 2 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2727528) (HKLM\...\KB2727528) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2757638) (HKLM\...\KB2757638) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2770660) (HKLM\...\KB2770660) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2780091) (HKLM\...\KB2780091) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2802968) (HKLM\...\KB2802968) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2807986) (HKLM\...\KB2807986) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2813345) (HKLM\...\KB2813345) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2820917) (HKLM\...\KB2820917) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2834886) (HKLM\...\KB2834886) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2847311) (HKLM\...\KB2847311) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2850869) (HKLM\...\KB2850869) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2859537) (HKLM\...\KB2859537) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2862152) (HKLM\...\KB2862152) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2862330) (HKLM\...\KB2862330) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2862335) (HKLM\...\KB2862335) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2864063) (HKLM\...\KB2864063) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2868038) (HKLM\...\KB2868038) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2868626) (HKLM\...\KB2868626) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2876217) (HKLM\...\KB2876217) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2876331) (HKLM\...\KB2876331) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2892075) (HKLM\...\KB2892075) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2893294) (HKLM\...\KB2893294) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2898715) (HKLM\...\KB2898715) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2909212) (HKLM\...\KB2909212) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2914368) (HKLM\...\KB2914368) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2916036) (HKLM\...\KB2916036) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2922229) (HKLM\...\KB2922229) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2929961) (HKLM\...\KB2929961) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2930275) (HKLM\...\KB2930275) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2936068) (HKLM\...\KB2936068) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2964358) (HKLM\...\KB2964358) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB923561) (HKLM\...\KB923561) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB923789) (HKLM\...\KB923789) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB946648) (HKLM\...\KB946648) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB950762) (HKLM\...\KB950762) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB950974) (HKLM\...\KB950974) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB951376-v2) (HKLM\...\KB951376-v2) (Version: 2 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB952004) (HKLM\...\KB952004) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB952954) (HKLM\...\KB952954) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB953155) (HKLM\...\KB953155) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB956572) (HKLM\...\KB956572) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB956844) (HKLM\...\KB956844) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB959426) (HKLM\...\KB959426) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB960803) (HKLM\...\KB960803) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB960859) (HKLM\...\KB960859) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB969059) (HKLM\...\KB969059) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB970430) (HKLM\...\KB970430) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB971657) (HKLM\...\KB971657) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB972270) (HKLM\...\KB972270) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB973507) (HKLM\...\KB973507) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB973869) (HKLM\...\KB973869) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB973904) (HKLM\...\KB973904) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB974112) (HKLM\...\KB974112) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB974318) (HKLM\...\KB974318) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB974392) (HKLM\...\KB974392) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB974571) (HKLM\...\KB974571) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB975025) (HKLM\...\KB975025) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB975467) (HKLM\...\KB975467) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB975560) (HKLM\...\KB975560) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB975713) (HKLM\...\KB975713) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB977816) (HKLM\...\KB977816) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB977914) (HKLM\...\KB977914) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB978338) (HKLM\...\KB978338) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB978542) (HKLM\...\KB978542) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB978706) (HKLM\...\KB978706) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB979309) (HKLM\...\KB979309) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB979482) (HKLM\...\KB979482) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB979687) (HKLM\...\KB979687) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB981997) (HKLM\...\KB981997) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB982132) (HKLM\...\KB982132) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB982665) (HKLM\...\KB982665) (Version: 1 - Microsoft Corporation) smartMate (HKLM\...\{34BAB9B0-3259-11D4-BB64-0050BAE025B7}) (Version: - ) SpeedFan (remove only) (HKLM\...\SpeedFan) (Version: - ) Texas Instruments PCIxx21/x515 drivers. (HKLM\...\InstallShield_{406A5ABF-CA65-4E11-95C7-52228FE48F58}) (Version: 1.11.0000 - Texas Instruments Inc.) Texas Instruments PCIxx21/x515/xx12 drivers. (HKLM\...\InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}) (Version: 2.00.0001 - Ihr Firmenname) TIPCI (Version: 2.00.0001 - Ihr Firmenname) Hidden TIxx21 (Version: 1.11.0000 - Texas Instruments Inc.) Hidden TuneUp Utilities Language Pack (de-DE) (Version: 10.0.4500.49 - TuneUp Software) Hidden UltraISO Premium V9.53 (HKLM\...\UltraISO_is1) (Version: - ) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2345886) (HKLM\...\KB2345886) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2749655) (HKLM\...\KB2749655) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB951978) (HKLM\...\KB951978) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB955759) (HKLM\...\KB955759) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB968389) (HKLM\...\KB968389) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB971029) (HKLM\...\KB971029) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB973815) (HKLM\...\KB973815) (Version: 1 - Microsoft Corporation) USB CCID Smartcard Reader - Version 1.2.0.5 (HKLM\...\{939913F9-F134-4E9E-B879-BE6755B69952}) (Version: 3.0.0.0 - USB CCID) VIA Plattform-Geräte-Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.22 - VIA Technologies, Inc.) VIA Rhine-Family Fast Ethernet Adapter (HKLM\...\VN_VUIns_Rhine_VIA) (Version: - ) ViewNX 2 (HKLM\...\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.8.0 - Nikon) WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden Windows Communication Foundation Language Pack - DEU (Version: 3.0.04506.30 - Microsoft Corporation) Hidden Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - ) Windows Media Format 11 runtime (Version: - Microsoft Corporation) Hidden Windows Media Player 11 (HKLM\...\Windows Media Player) (Version: - ) Windows Media Player 11 (Version: - Microsoft Corporation) Hidden Windows Presentation Foundation (Version: 3.0.6920.0 - Microsoft Corporation) Hidden Windows Presentation Foundation Language Pack (DEU) (Version: 3.0.6920.0 - Microsoft Corporation) Hidden Windows Workflow Foundation DE Language Pack (Version: 3.0.4203.2 - Microsoft Corporation) Hidden Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031514 - Microsoft Corporation) Windows-Treiberpaket - Brother MFC-J5910CDW, MFC-J5910DW (09/03/2012 01.01.06.05) (HKLM\...\7CCEF175049717F93AD31E9B68BE46AA3CFD50FF) (Version: 09/03/2012 01.01.06.05 - Brother) Windows-Treiberpaket - Brother MFC-J5910CDW,MFC-J5910DW (07/25/2012 01.00.01.01) (HKLM\...\11EA9492AC04044EB9ED984B852557E87C16B1B9) (Version: 07/25/2012 01.00.01.01 - Brother) Windows-Treiberpaket - Realtek Semiconductor Corp. HD Audio Driver (10/07/2013 5.10.0.7058) (HKLM\...\D6F1C56649462607C880F3095EA8D4CF49D32E33) (Version: 10/07/2013 5.10.0.7058 - Realtek Semiconductor Corp.) Windows-Treiberpaket - VIA Technologies, Inc. System (08/12/2009 6.0.00.0320) (HKLM\...\0E1B7BB02168CD19134B5D83F75C79968F207142) (Version: 08/12/2009 6.0.00.0320 - VIA Technologies, Inc.) Windows-Treiberpaket - VIA Technologies, Inc. System (10/02/2002 5.1.00.0260) (HKLM\...\D2368183C1AA3129073E1008D0C1E48250CE86EE) (Version: 10/02/2002 5.1.00.0260 - VIA Technologies, Inc.) WinRAR 4.01 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) WISO Bewerbung 2008 (HKLM\...\{FD065B02-AE17-4496-8C0F-FFD3A9FD9460}) (Version: 6.1.0.56 - Buhl Data Service GmbH) WISO Internet Security (HKLM\...\WISO Internet Security) (Version: 14.0.6.570 - Buhl Data Service GmbH) WISO Mein Geld 2014 Professional (HKLM\...\WISO Mein Geld 2014 Professional) (Version: - Buhl Data Service GmbH) WISO Mein Geld 2014 Professional (Version: 16.0.1.0 - Buhl Data Service GmbH) Hidden WISO Steuer-Sparbuch 2014 (HKLM\...\{8978065E-FE0C-4BCD-9EC6-860A3AD8FE84}) (Version: 21.00.8480 - Buhl Data Service GmbH) Works Suite-Betriebssystem-Pack (Version: 1.0.0.0000 - Microsoft Corporation) Hidden Works-Synchronisierung (Version: 1.0.0.0000 - Firmenname) Hidden X10 Hardware(TM) (HKLM\...\X10Hardware) (Version: - ) Zoo Tycoon: Complete Collection (HKLM\...\Zoo Tycoon 1.0) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-329068152-1614895754-839522115-1004_Classes\CLSID\{5B004CDE-0211-469C-B9B5-0552E7E63917}\InprocServer32 -> C:\Programme\Pinnacle\Shared Files\Filter\MarvinAVRenderer.ax (Pinnacle Systems GmbH) CustomCLSID: HKU\S-1-5-21-329068152-1614895754-839522115-1004_Classes\CLSID\{77D8C8C7-6B46-4429-B876-DBC006C96EB1}\InprocServer32 -> C:\Programme\Pinnacle\Shared Files\Filter\MarvinAVRenderer.ax (Pinnacle Systems GmbH) CustomCLSID: HKU\S-1-5-21-329068152-1614895754-839522115-1004_Classes\CLSID\{CD37ED08-860C-4B86-AD25-5587D8386587}\InprocServer32 -> C:\Programme\Pinnacle\Shared Files\Filter\MarvinAVRenderer.ax (Pinnacle Systems GmbH) ==================== Restore Points ========================= 27-07-2014 17:41:37 Systemprüfpunkt 27-07-2014 18:36:37 TuneUp Utilities 2014 wird entfernt 27-07-2014 18:37:31 TuneUp Utilities 2014 (de-DE) wird entfernt 27-07-2014 21:05:03 Der unsignierte Treiber kann nicht aktualisiert werden 27-07-2014 22:02:17 Installiert Realtek High Definition Audio Driver 31-07-2014 06:23:51 Software Distribution Service 3.0 01-08-2014 08:20:49 Software Distribution Service 3.0 01-08-2014 08:54:49 Software Distribution Service 3.0 07-08-2014 08:33:35 Java 7 Update 65 wird installiert 07-08-2014 08:34:36 Configured Platform 07-08-2014 09:18:36 Der unsignierte Treiber kann nicht aktualisiert werden 07-08-2014 09:40:02 Configured Platform 07-08-2014 10:27:09 3DMark 07-08-2014 10:29:48 DirectX wurde installiert 07-08-2014 10:34:46 3DMark 07-08-2014 10:35:41 DirectX wurde installiert 07-08-2014 11:45:45 Installed 3DMark06 07-08-2014 11:47:27 Installed 3DMark06 13-08-2014 08:31:22 Software Distribution Service 3.0 14-08-2014 08:27:07 Datei in Quarantäne Ordner verschieben: SaveSense for IE 14-08-2014 08:29:03 "Url Helper" deinstallieren 16-08-2014 09:42:35 Installiert cyberJack Base Components 16-08-2014 09:47:48 Installiert cyberJack Base Components 16-08-2014 09:51:00 Installation eines unsignierten Treibers 20-08-2014 09:40:46 Entfernt cyberJack Base Components 20-08-2014 11:41:22 Installiert cyberJack Base Components 20-08-2014 11:53:39 Installiert cyberJack Base Components 29-08-2014 08:44:18 Java 7 Update 45 wird entfernt 29-08-2014 08:46:50 Java 7 Update 67 wird installiert 04-09-2014 07:02:05 Revo Uninstaller's restore point - 3DMark06 04-09-2014 07:04:01 Removed 3DMark06 04-09-2014 07:06:09 Revo Uninstaller's restore point - Free YouTube to MP3 Converter version 3.12.17.1125 04-09-2014 07:09:22 Revo Uninstaller's restore point - Express Burn 04-09-2014 08:46:12 Revo Uninstaller's restore point - Compatibility Pack für 2007 Office System 04-09-2014 08:54:39 Compatibility Pack für 2007 Office System wird entfernt 04-09-2014 09:14:09 Revo Uninstaller's restore point - Compatibility Pack für 2007 Office System 04-09-2014 09:26:52 Compatibility Pack für 2007 Office System wird entfernt 04-09-2014 09:42:29 Compatibility Pack für 2007 Office System wird entfernt 05-09-2014 07:05:13 Revo Uninstaller's restore point - Compatibility Pack für 2007 Office System 05-09-2014 08:49:09 Compatibility Pack für 2007 Office System wird entfernt 05-09-2014 08:46:06 Revo Uninstaller's restore point - Futuremark SystemInfo 05-09-2014 08:57:18 Removed Futuremark SystemInfo 05-09-2014 09:04:02 Revo Uninstaller's restore point - Compatibility Pack für 2007 Office System 05-09-2014 09:05:21 Compatibility Pack für 2007 Office System wird entfernt 05-09-2014 21:27:08 Revo Uninstaller's restore point - Futuremark SystemInfo 05-09-2014 21:27:35 Removed Futuremark SystemInfo 05-09-2014 21:38:39 Revo Uninstaller's restore point - Java 7 Update 67 07-09-2014 08:34:39 Java 7 Update 67 wird entfernt 07-09-2014 08:32:04 Revo Uninstaller's restore point - Express Rip 07-09-2014 08:33:49 Revo Uninstaller's restore point - Java 7 Update 67 07-09-2014 08:34:47 Java 7 Update 67 wird entfernt 09-09-2014 15:01:36 Java 7 Update 67 wird installiert 11-09-2014 11:58:08 Software Distribution Service 3.0 13-09-2014 09:02:49 Revo Uninstaller's restore point - Java 7 Update 67 13-09-2014 09:03:28 Java 7 Update 67 wird entfernt 24-09-2014 09:10:28 Java 7 Update 67 wird installiert 24-09-2014 09:43:10 Java 7 Update 67 wird entfernt 24-09-2014 09:44:44 Java 7 Update 67 wird installiert ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2004-08-04 14:00 - 2004-08-04 14:00 - 00000820 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Benachrichtigung – Anmeldung.job => C:\WINDOWS\system32\xp_eos.exe Task: C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Monatliche Benachrichtigung.job => C:\WINDOWS\system32\xp_eos.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Programme\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Programme\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-07-03 16:47 - 2007-05-31 07:38 - 00167936 ____N () C:\WINDOWS\system32\SerialXP.dll 2013-03-18 13:08 - 2009-02-27 17:38 - 00139264 ____R () C:\Programme\Brother\BrUtilities\BrLogAPI.dll 2004-08-04 14:00 - 2008-04-14 07:52 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll 2014-09-26 10:47 - 2014-09-23 06:07 - 08577864 _____ () C:\Programme\Google\Chrome\Application\37.0.2062.124\pdf.dll 2014-09-26 10:47 - 2014-09-23 06:07 - 00331592 _____ () C:\Programme\Google\Chrome\Application\37.0.2062.124\ppGoogleNaClPluginChrome.dll 2014-09-26 10:47 - 2014-09-23 06:06 - 01660232 _____ () C:\Programme\Google\Chrome\Application\37.0.2062.124\ffmpegsumo.dll 2014-09-26 10:47 - 2014-09-23 06:07 - 14891848 _____ () C:\Programme\Google\Chrome\Application\37.0.2062.124\PepperFlash\pepflashplayer.dll 2014-09-28 10:51 - 2014-09-28 10:51 - 00050477 _____ () C:\Dokumente und Einstellungen\Thomas\Eigene Dateien\Downloads\Defogger.exe ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:373E1720 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Reader - Schnellstart.lnk => C:\WINDOWS\pss\Adobe Reader - Schnellstart.lnkCommon Startup MSCONFIG\startupfolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^WISO Mein Steuer-Sparbuch heute.lnk => C:\WINDOWS\pss\WISO Mein Steuer-Sparbuch heute.lnkCommon Startup MSCONFIG\startupfolder: C:^Dokumente und Einstellungen^Thomas^Startmenü^Programme^Autostart^WISO Bewerbung-Reminder.lnk => C:\WINDOWS\pss\WISO Bewerbung-Reminder.lnkStartup MSCONFIG\startupreg: Adobe ARM => "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: BrStsMon00 => C:\Programme\Browny02\Brother\BrStMonW.exe /AUTORUN MSCONFIG\startupreg: ControlCenter4 => C:\Programme\ControlCenter4\BrCcBoot.exe /autorun MSCONFIG\startupreg: IndexSearch => "C:\Programme\Nuance\PaperPort\IndexSearch.exe" MSCONFIG\startupreg: ISUSPM => C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\FLEXnet\Connect\11\ISUSPM.exe -scheduler MSCONFIG\startupreg: MSMSGS => "C:\Programme\Messenger\msmsgs.exe" /background MSCONFIG\startupreg: NBJ => "C:\Programme\Ahead\Nero BackItUp\NBJ.exe" MSCONFIG\startupreg: NvBackend => "C:\Programme\NVIDIA Corporation\Update Core\NvBackend.exe" MSCONFIG\startupreg: NvCplDaemon => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup MSCONFIG\startupreg: nwiz => C:\Programme\NVIDIA Corporation\nview\nwiz.exe /installquiet MSCONFIG\startupreg: PaperPort PTD => "C:\Programme\Nuance\PaperPort\pptd40nt.exe" MSCONFIG\startupreg: PDF5 Registry Controller => C:\Programme\Nuance\PDF Viewer Plus\RegistryController.exe MSCONFIG\startupreg: PDFHook => C:\Programme\Nuance\PDF Viewer Plus\pdfpro5hook.exe MSCONFIG\startupreg: Start WingMan Profiler => C:\Programme\Logitech\Gaming Software\LWEMon.exe /noui MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" MSCONFIG\startupreg: Sunkist2k => C:\Programme\Multimedia Card Reader\shwicon2k.exe MSCONFIG\startupreg: USBToolTip => C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe ========================= Accounts: ========================== Administrator (S-1-5-21-329068152-1614895754-839522115-500 - Administrator - Enabled) => %SystemDrive%\Dokumente und Einstellungen\Administrator ASPNET (S-1-5-21-329068152-1614895754-839522115-1006 - Limited - Enabled) Gast (S-1-5-21-329068152-1614895754-839522115-501 - Limited - Enabled) Hilfeassistent (S-1-5-21-329068152-1614895754-839522115-1000 - Limited - Disabled) SUPPORT_388945a0 (S-1-5-21-329068152-1614895754-839522115-1002 - Limited - Disabled) Thomas (S-1-5-21-329068152-1614895754-839522115-1004 - Administrator - Enabled) => %SystemDrive%\Dokumente und Einstellungen\Thomas ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Pentium(R) D CPU 2.80GHz Percentage of memory in use: 43% Total physical RAM: 2047.23 MB Available physical RAM: 1161.78 MB Total Pagefile: 4897.68 MB Available Pagefile: 3876.55 MB Total Virtual: 2047.88 MB Available Virtual: 1962.37 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:143.2 GB) (Free:49.51 GB) NTFS ==>[Drive with boot components (Windows XP)] Drive e: (RECOVER) (Fixed) (Total:5.84 GB) (Free:0.7 GB) FAT32 Drive f: (Daten) (Fixed) (Total:1713.97 GB) (Free:1530.9 GB) NTFS Drive g: (ST2014) (CDROM) (Total:0.56 GB) (Free:0 GB) CDFS Drive q: (Musik) (Fixed) (Total:244.14 GB) (Free:64.69 GB) NTFS Drive r: (Video) (Fixed) (Total:195.31 GB) (Free:85.5 GB) NTFS Drive s: (Datenablage) (Fixed) (Total:9.77 GB) (Free:4.18 GB) NTFS Drive t: (BACKUP) (Fixed) (Total:16.54 GB) (Free:5.81 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 1863 GB) (Disk ID: DC48A5F6) Partition 1: (Active) - (Size=143.2 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=1719.8 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 465.8 GB) (Disk ID: F8B99265) Partition 1: (Not Active) - (Size=244.1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=221.6 GB) - (Type=OF Extended) ==================== End Of Log ============================ Geändert von tommy taste (28.09.2014 um 10:25 Uhr) |