|
Alles rund um Windows: Keine Startleiste mehr nach Virus Vista-HomeWindows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
01.09.2010, 18:09 | #1 |
| Problem: Keine Startleiste mehr nach Virus Vista-Home Guten Abend, ich hatte erst ein wie in diesem Thread : http://www.trojaner-board.de/56939-v...askleiste.html beschriebenes Problem. Was ich mit dem Einsatz von HijackThis und Malware erstmal lösen konnte. Kann nun wieder auf Internetseiten gehen und jegliche Art von .exe Dateien starten. Allerdings wird mir keine Startleiste mehr mehr angezeigt und beim hochfahren dauert es nach der PW Eingabe ungewöhnlich lange vorher vllt 2 sec. jetzt 10-20. Betriebssystem ist Vista und der Pc von Packard. Habe schon gegooglet konnte allerdings nichts nützliches finden.Achja das Problem mit der Taskleiste bestand schon als der Virus noch drauf war und ich noch nix geändert hatte. Mfg xajiin Geändert von xajiin (01.09.2010 um 18:30 Uhr) |
01.09.2010, 18:52 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Keine Startleiste mehr nach Virus Vista-Home Anleitung / HilfeZitat:
__________________ |
01.09.2010, 22:05 | #3 |
| Keine Startleiste mehr nach Virus Vista-Home Details Malwarebytes' Anti-Malware 1.46
__________________www.malwarebytes.org Datenbank Version: 4521 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 01.09.2010 23:04:30 mbam-log-2010-09-01 (23-04-30).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 135326 Laufzeit: 5 Minute(n), 10 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> No action taken. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
02.09.2010, 10:12 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Lösung: Keine Startleiste mehr nach Virus Vista-Home Bitte routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ Logfiles bitte immer in CODE-Tags posten |
02.09.2010, 12:30 | #5 |
| Wie Keine Startleiste mehr nach Virus Vista-Home OTL Logfile: Code:
ATTFilter OTL logfile created on: 02.09.2010 13:23:25 - Run 1 OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\matze\Desktop 64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 66,00% Memory free 8,00 Gb Paging File | 7,00 Gb Available in Paging File | 82,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 581,52 Gb Total Space | 382,46 Gb Free Space | 65,77% Space Free | Partition Type: NTFS Drive D: | 5,90 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Drive K: | 465,20 Mb Total Space | 346,68 Mb Free Space | 74,52% Space Free | Partition Type: FAT32 Computer Name: MARTIN Current User Name: matze Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\matze\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe () PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) PRC - C:\Windows\SysWOW64\PnkBstrA.exe () PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\ACER\Preload\Autorun\DRV\FUJI Keyboard\AOSD.exe (Packard Bell BV) PRC - C:\ACER\Preload\Autorun\DRV\FUJI Keyboard\ABoard.exe (Packard Bell BV) PRC - C:\Programme\PACKARD BELL\SetUpMyPC\SmpSys.exe (Packard Bell BV) PRC - C:\Windows\SysWOW64\HidService.exe (Packard Bell Services) PRC - C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe () PRC - C:\Windows\SysWOW64\IoctlSvc.exe (Prolific Technology Inc.) ========== Modules (SafeList) ========== MOD - C:\Users\matze\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (PnkBstrA) -- C:\Windows\SysNative\PnkBstrA.exe File not found SRV:64bit: - (ezSharedSvc) -- C:\Windows\SysNative\ezsvc7.dll File not found SRV:64bit: - (GenericHidService) -- C:\Windows\SysNative\HidService.exe () SRV - (Akamai) -- c:\program files (x86)\common files\akamai\rswin_3745.dll () SRV - (ICQ Service) -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe () SRV - (Hamachi2Svc) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.) SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe () SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.) SRV - (ETService) -- C:\Programme\PACKARD BELL\Packard Bell Recovery Management\Service\ETService.exe () SRV - (GenericHidService) -- C:\Windows\SysWow64\HidService.exe (Packard Bell Services) SRV - (ezSharedSvc) -- C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS) SRV - (AdobeActiveFileMonitor6.0) -- C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe () SRV - (PLFlash DeviceIoControl Service) -- C:\Windows\SysWOW64\IoctlSvc.exe (Prolific Technology Inc.) ========== Driver Services (SafeList) ========== DRV:64bit: - (SRTSPX) -- C:\Windows\SysNative\drivers\NISx64\1000000.07D\SRTSPX64.SYS File not found DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\NISx64\1000000.07D\SRTSP64.SYS File not found DRV:64bit: - (NwlnkFwd) -- C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found DRV:64bit: - (NwlnkFlt) -- C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found DRV:64bit: - (IpInIp) -- C:\Windows\SysNative\DRIVERS\ipinip.sys File not found DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys () DRV:64bit: - (ESLvnic1) -- C:\Windows\SysNative\DRIVERS\ESLvnic.sys () DRV:64bit: - (hamachi) -- C:\Windows\SysNative\DRIVERS\hamachi.sys () DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys () DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys () DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\Wbem\ntfs.mof () DRV - (int15) -- C:\Windows\SysWOW64\drivers\int15_64.sys (Acer, Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=0409&m=imedia_x4614_ge IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=0409&m=imedia_x4614_ge IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=0409&m=imedia_x4614_ge IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=0409&m=imedia_x4614_ge IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=0409&m=imedia_x4614_ge IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.esl.eu/de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - prefs.js..browser.search.selectedEngine: "ICQ Search" FF - prefs.js..browser.startup.homepage: "hxxp://start.icq.com/" FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.6 FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.6&q=" FF - prefs.js..network.proxy.type: 4 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.08.26 23:54:29 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.07.25 01:41:28 | 000,000,000 | ---D | M] [2010.02.14 23:32:38 | 000,000,000 | ---D | M] -- C:\Users\matze\AppData\Roaming\mozilla\Extensions [2010.09.01 14:21:15 | 000,000,000 | ---D | M] -- C:\Users\matze\AppData\Roaming\mozilla\Firefox\Profiles\bimcp4lw.default\extensions [2010.07.27 10:58:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\matze\AppData\Roaming\mozilla\Firefox\Profiles\bimcp4lw.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2010.08.28 02:03:45 | 000,001,056 | ---- | M] () -- C:\Users\matze\AppData\Roaming\Mozilla\FireFox\Profiles\bimcp4lw.default\searchplugins\icqplugin.xml [2010.09.01 14:21:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2010.07.23 17:48:46 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.07.23 17:48:46 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.07.23 17:48:46 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.07.23 17:48:46 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.07.23 17:48:46 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.08.31 18:34:23 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.) O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O4:64bit: - HKLM..\Run: [FujiKeyboard] c:\ACER\Preload\Autorun\DRV\FUJI Keyboard\ABoard.exe (Packard Bell BV) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.) O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [eRecoveryService] File not found O4 - HKLM..\Run: [SmpcSys] C:\Programme\PACKARD BELL\SetUpMyPC\SmpSys.exe (Packard Bell BV) O4 - HKCU..\Run: [ICQ] C:\Program Files (x86)\ICQ6.5\ICQ.exe File not found O4 - HKCU..\Run: [SmpcSys] C:\Programme\PACKARD BELL\SetUpMyPC\SmpSys.exe (Packard Bell BV) O4 - HKCU..\Run: [Steam] c:\program files (x86)\steam\steam.exe (Valve Corporation) O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 2nvtu0 = C:\Users\matze\AppData\Local\Temp\ui15cr.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1 O8:64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.) O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.) O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16) O16 - DPF: {C212D449-8B3C-41F2-BD9A-047BD770550F} hxxp://www.fiaa.eu/OPLauncher.cab (Perparer Class) O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16) O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\matze\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\matze\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.) O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{c264a41a-15a3-11df-affd-0022684c2afe}\Shell - "" = AutoRun O33 - MountPoints2\{c264a41a-15a3-11df-affd-0022684c2afe}\Shell\AutoRun\command - "" = J:\setup.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.09.02 13:22:08 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\matze\Desktop\OTL.exe [2010.09.01 14:21:05 | 000,000,000 | ---D | C] -- C:\Users\matze\Desktop\backups [2010.09.01 13:51:53 | 000,000,000 | ---D | C] -- C:\Users\matze\AppData\Roaming\Malwarebytes [2010.09.01 13:51:19 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.09.01 13:51:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.09.01 13:51:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.09.01 13:33:50 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\matze\Desktop\HiJackThis204.exe [2010.08.31 19:34:13 | 000,000,000 | ---D | C] -- C:\Users\matze\AppData\Local\MigWiz [2010.08.31 18:23:34 | 000,188,928 | ---- | C] (OpenSC Project) -- C:\Windows\Atapoa.exe [2010.08.31 18:23:20 | 000,000,000 | ---D | C] -- C:\Users\matze\AppData\Local\tjhgwfrsy [2010.08.31 18:23:09 | 000,000,000 | ---D | C] -- C:\Users\matze\AppData\Local\Windows Server [2010.08.29 20:47:34 | 000,000,000 | ---D | C] -- C:\Windows\Minidump [2010.08.14 19:36:49 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll [2010.08.14 19:36:49 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_7.dll [2010.08.14 19:36:49 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_7.dll [2010.08.14 19:36:49 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_5.dll [2010.08.14 19:36:48 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_43.dll [2010.08.14 19:36:48 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_43.dll [2010.08.14 19:36:48 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_43.dll [2010.08.14 19:36:47 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_43.dll [2010.08.14 19:36:47 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_6.dll [2010.08.14 19:36:47 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_6.dll [2010.08.14 19:36:47 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_4.dll [2010.08.14 19:36:46 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_5.dll [2010.08.14 19:36:46 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_5.dll [2010.08.14 19:36:46 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_7.dll [2010.08.14 19:36:45 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_42.dll [2010.08.14 19:36:45 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_42.dll [2010.08.14 19:36:44 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_41.dll [2010.08.14 19:36:44 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_42.dll [2010.08.14 19:36:44 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_41.dll [2010.08.14 19:36:43 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_4.dll [2010.08.14 19:36:43 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_4.dll [2010.08.14 19:36:43 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_3.dll [2010.08.14 19:36:42 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_40.dll [2010.08.14 19:36:42 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_40.dll [2010.08.14 19:36:42 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_6.dll [2010.08.14 19:36:41 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_40.dll [2010.08.14 19:36:41 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_3.dll [2010.08.14 19:36:41 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_3.dll [2010.08.14 19:36:41 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_2.dll [2010.08.14 19:36:41 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_5.dll [2010.08.14 19:36:40 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_39.dll [2010.08.14 19:36:40 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_2.dll [2010.08.14 19:36:40 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_39.dll [2010.08.14 19:36:40 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_2.dll [2010.08.14 19:36:40 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_1.dll [2010.08.14 19:36:39 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_39.dll [2010.08.14 19:36:39 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_1.dll [2010.08.14 19:36:39 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_1.dll [2010.08.14 19:36:39 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_0.dll [2010.08.14 19:36:39 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_4.dll [2010.08.14 19:36:38 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_38.dll [2010.08.14 19:36:38 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_38.dll [2010.08.14 19:36:38 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_38.dll [2010.08.14 19:36:37 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_37.dll [2010.08.14 19:36:37 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_0.dll [2010.08.14 19:36:37 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_37.dll [2010.08.14 19:36:37 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_0.dll [2010.08.14 19:36:37 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_3.dll [2010.08.14 19:36:36 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_37.dll [2010.08.14 19:36:36 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_10.dll [2010.08.14 19:36:35 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_36.dll [2010.08.14 19:36:35 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_36.dll [2010.08.14 19:36:35 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_36.dll [2010.08.14 19:36:34 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_35.dll [2010.08.14 19:36:34 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_35.dll [2010.08.14 19:36:34 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_35.dll [2010.08.14 19:36:34 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_9.dll [2010.08.14 19:36:34 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_2.dll [2010.08.14 19:35:37 | 000,000,000 | -H-D | C] -- C:\Windows\msdownld.tmp [2010.08.14 05:12:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Doom 3 [2010.08.14 03:25:52 | 000,000,000 | ---D | C] -- C:\Users\matze\AppData\Roaming\LolClient [2010.08.14 02:54:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx [2010.08.14 02:51:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\League of Legends [2010.08.14 02:38:57 | 000,000,000 | ---D | C] -- C:\Users\matze\AppData\Local\PMB Files [2010.08.14 02:38:56 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files [2010.08.14 02:38:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks [2010.08.14 01:19:55 | 000,000,000 | ---D | C] -- C:\Users\matze\AppData\Roaming\Nero [2010.08.14 00:57:46 | 000,305,152 | ---- | C] (InstallShield Software Corporation) -- C:\Windows\IsUninst.exe [2010.08.13 23:31:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bullfrog [2010.08.09 15:14:43 | 000,000,000 | ---D | C] -- C:\Users\matze\AppData\Roaming\dvdcss [2010.04.07 00:25:42 | 000,036,069 | ---- | C] (Beepa Pty Ltd) -- C:\Programme\uninstall.exe [2010.03.31 08:02:44 | 000,074,672 | ---- | C] (Beepa P/L) -- C:\Programme\fraps64.dat [2010.03.31 08:02:36 | 002,181,040 | ---- | C] (Beepa P/L) -- C:\Programme\fraps.exe [2010.03.31 08:00:06 | 000,159,744 | ---- | C] (Beepa P/L) -- C:\Programme\frapslcd.dll [2010.03.31 07:20:48 | 000,156,592 | ---- | C] (Beepa P/L) -- C:\Programme\fraps64.dll [2010.03.31 07:20:46 | 000,206,768 | ---- | C] (Beepa P/L) -- C:\Programme\fraps32.dll [4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.09.02 13:26:14 | 004,456,448 | -HS- | M] () -- C:\Users\matze\NTUSER.DAT [2010.09.02 13:25:59 | 001,418,806 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010.09.02 13:25:59 | 000,618,204 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2010.09.02 13:25:59 | 000,586,980 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010.09.02 13:25:59 | 000,122,636 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2010.09.02 13:25:59 | 000,101,052 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010.09.02 13:22:06 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\matze\Desktop\OTL.exe [2010.09.02 13:19:04 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\LogConfigTemp.xml [2010.09.02 13:19:03 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2010.09.02 13:18:52 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010.09.02 13:18:52 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010.09.02 13:18:51 | 000,070,575 | ---- | M] () -- C:\ProgramData\nvModes.001 [2010.09.02 13:18:46 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.09.02 13:18:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.09.02 13:18:40 | 4293,054,464 | -HS- | M] () -- C:\hiberfil.sys [2010.09.02 02:54:24 | 000,524,288 | -HS- | M] () -- C:\Users\matze\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms [2010.09.02 02:54:24 | 000,065,536 | -HS- | M] () -- C:\Users\matze\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf [2010.09.02 02:36:00 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2010.09.01 14:58:33 | 003,188,983 | -H-- | M] () -- C:\Users\matze\AppData\Local\IconCache.db [2010.09.01 13:51:22 | 000,000,882 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.09.01 12:55:40 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\matze\Desktop\HiJackThis204.exe [2010.08.31 18:34:23 | 000,000,761 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2010.08.31 18:23:30 | 000,188,928 | ---- | M] (OpenSC Project) -- C:\Windows\Atapoa.exe [2010.08.31 18:23:15 | 000,000,005 | ---- | M] () -- C:\zrpt.xml [2010.08.31 17:19:26 | 000,070,575 | ---- | M] () -- C:\ProgramData\nvModes.dat [2010.08.29 22:04:42 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini [2010.08.29 20:47:34 | 376,154,432 | ---- | M] () -- C:\Windows\MEMORY.DMP [2010.08.20 22:54:58 | 000,002,015 | ---- | M] () -- C:\Users\matze\Desktop\Cstrike.lnk [2010.08.20 14:02:28 | 000,000,374 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.ics [2010.08.18 22:48:27 | 000,103,736 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe [2010.08.18 03:31:24 | 000,008,704 | ---- | M] () -- C:\Users\matze\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.08.14 05:13:11 | 000,000,350 | ---- | M] () -- C:\Windows\doom3.ini [4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.09.01 13:51:22 | 000,000,882 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.09.01 13:51:17 | 000,024,664 | ---- | C] () -- C:\Windows\SysNative\drivers\mbam.sys [2010.08.31 18:23:15 | 000,000,005 | ---- | C] () -- C:\zrpt.xml [2010.08.29 20:47:14 | 376,154,432 | ---- | C] () -- C:\Windows\MEMORY.DMP [2010.08.23 22:07:48 | 000,333,470 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistMSI1AA0.txt [2010.08.23 22:07:47 | 000,011,142 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistUI1AA0.txt [2010.08.14 19:36:49 | 002,526,056 | ---- | C] () -- C:\Windows\SysNative\D3DCompiler_43.dll [2010.08.14 19:36:49 | 000,518,488 | ---- | C] () -- C:\Windows\SysNative\XAudio2_7.dll [2010.08.14 19:36:49 | 000,176,984 | ---- | C] () -- C:\Windows\SysNative\xactengine3_7.dll [2010.08.14 19:36:49 | 000,077,656 | ---- | C] () -- C:\Windows\SysNative\XAPOFX1_5.dll [2010.08.14 19:36:48 | 001,907,552 | ---- | C] () -- C:\Windows\SysNative\d3dcsx_43.dll [2010.08.14 19:36:48 | 000,511,328 | ---- | C] () -- C:\Windows\SysNative\d3dx10_43.dll [2010.08.14 19:36:48 | 000,276,832 | ---- | C] () -- C:\Windows\SysNative\d3dx11_43.dll [2010.08.14 19:36:47 | 002,401,112 | ---- | C] () -- C:\Windows\SysNative\D3DX9_43.dll [2010.08.14 19:36:47 | 000,530,776 | ---- | C] () -- C:\Windows\SysNative\XAudio2_6.dll [2010.08.14 19:36:47 | 000,176,984 | ---- | C] () -- C:\Windows\SysNative\xactengine3_6.dll [2010.08.14 19:36:47 | 000,078,680 | ---- | C] () -- C:\Windows\SysNative\XAPOFX1_4.dll [2010.08.14 19:36:46 | 002,582,888 | ---- | C] () -- C:\Windows\SysNative\D3DCompiler_42.dll [2010.08.14 19:36:46 | 000,517,960 | ---- | C] () -- C:\Windows\SysNative\XAudio2_5.dll [2010.08.14 19:36:46 | 000,176,968 | ---- | C] () -- C:\Windows\SysNative\xactengine3_5.dll [2010.08.14 19:36:46 | 000,024,920 | ---- | C] () -- C:\Windows\SysNative\X3DAudio1_7.dll [2010.08.14 19:36:45 | 005,554,512 | ---- | C] () -- C:\Windows\SysNative\d3dcsx_42.dll [2010.08.14 19:36:45 | 000,285,024 | ---- | C] () -- C:\Windows\SysNative\d3dx11_42.dll [2010.08.14 19:36:44 | 002,475,352 | ---- | C] () -- C:\Windows\SysNative\D3DX9_42.dll [2010.08.14 19:36:44 | 002,430,312 | ---- | C] () -- C:\Windows\SysNative\D3DCompiler_41.dll [2010.08.14 19:36:44 | 000,523,088 | ---- | C] () -- C:\Windows\SysNative\d3dx10_42.dll [2010.08.14 19:36:44 | 000,520,544 | ---- | C] () -- C:\Windows\SysNative\d3dx10_41.dll [2010.08.14 19:36:43 | 005,425,496 | ---- | C] () -- C:\Windows\SysNative\D3DX9_41.dll [2010.08.14 19:36:43 | 000,521,560 | ---- | C] () -- C:\Windows\SysNative\XAudio2_4.dll [2010.08.14 19:36:43 | 000,174,936 | ---- | C] () -- C:\Windows\SysNative\xactengine3_4.dll [2010.08.14 19:36:43 | 000,073,544 | ---- | C] () -- C:\Windows\SysNative\XAPOFX1_3.dll [2010.08.14 19:36:42 | 002,605,920 | ---- | C] () -- C:\Windows\SysNative\D3DCompiler_40.dll [2010.08.14 19:36:42 | 000,519,000 | ---- | C] () -- C:\Windows\SysNative\d3dx10_40.dll [2010.08.14 19:36:42 | 000,024,920 | ---- | C] () -- C:\Windows\SysNative\X3DAudio1_6.dll [2010.08.14 19:36:41 | 005,631,312 | ---- | C] () -- C:\Windows\SysNative\D3DX9_40.dll [2010.08.14 19:36:41 | 000,518,480 | ---- | C] () -- C:\Windows\SysNative\XAudio2_3.dll [2010.08.14 19:36:41 | 000,175,440 | ---- | C] () -- C:\Windows\SysNative\xactengine3_3.dll [2010.08.14 19:36:41 | 000,074,576 | ---- | C] () -- C:\Windows\SysNative\XAPOFX1_2.dll [2010.08.14 19:36:41 | 000,025,936 | ---- | C] () -- C:\Windows\SysNative\X3DAudio1_5.dll [2010.08.14 19:36:40 | 001,942,552 | ---- | C] () -- C:\Windows\SysNative\D3DCompiler_39.dll [2010.08.14 19:36:40 | 000,540,688 | ---- | C] () -- C:\Windows\SysNative\d3dx10_39.dll [2010.08.14 19:36:40 | 000,513,544 | ---- | C] () -- C:\Windows\SysNative\XAudio2_2.dll [2010.08.14 19:36:40 | 000,177,672 | ---- | C] () -- C:\Windows\SysNative\xactengine3_2.dll [2010.08.14 19:36:40 | 000,072,200 | ---- | C] () -- C:\Windows\SysNative\XAPOFX1_1.dll [2010.08.14 19:36:39 | 004,992,520 | ---- | C] () -- C:\Windows\SysNative\D3DX9_39.dll [2010.08.14 19:36:39 | 000,511,496 | ---- | C] () -- C:\Windows\SysNative\XAudio2_1.dll [2010.08.14 19:36:39 | 000,177,672 | ---- | C] () -- C:\Windows\SysNative\xactengine3_1.dll [2010.08.14 19:36:39 | 000,068,104 | ---- | C] () -- C:\Windows\SysNative\XAPOFX1_0.dll [2010.08.14 19:36:39 | 000,028,168 | ---- | C] () -- C:\Windows\SysNative\X3DAudio1_4.dll [2010.08.14 19:36:38 | 004,991,496 | ---- | C] () -- C:\Windows\SysNative\D3DX9_38.dll [2010.08.14 19:36:38 | 001,941,528 | ---- | C] () -- C:\Windows\SysNative\D3DCompiler_38.dll [2010.08.14 19:36:38 | 000,540,688 | ---- | C] () -- C:\Windows\SysNative\d3dx10_38.dll [2010.08.14 19:36:37 | 001,860,120 | ---- | C] () -- C:\Windows\SysNative\D3DCompiler_37.dll [2010.08.14 19:36:37 | 000,529,424 | ---- | C] () -- C:\Windows\SysNative\d3dx10_37.dll [2010.08.14 19:36:37 | 000,489,480 | ---- | C] () -- C:\Windows\SysNative\XAudio2_0.dll [2010.08.14 19:36:37 | 000,177,672 | ---- | C] () -- C:\Windows\SysNative\xactengine3_0.dll [2010.08.14 19:36:37 | 000,028,168 | ---- | C] () -- C:\Windows\SysNative\X3DAudio1_3.dll [2010.08.14 19:36:36 | 004,910,088 | ---- | C] () -- C:\Windows\SysNative\D3DX9_37.dll [2010.08.14 19:36:36 | 000,411,656 | ---- | C] () -- C:\Windows\SysNative\xactengine2_10.dll [2010.08.14 19:36:35 | 005,081,608 | ---- | C] () -- C:\Windows\SysNative\d3dx9_36.dll [2010.08.14 19:36:35 | 002,006,552 | ---- | C] () -- C:\Windows\SysNative\D3DCompiler_36.dll [2010.08.14 19:36:35 | 000,508,264 | ---- | C] () -- C:\Windows\SysNative\d3dx10_36.dll [2010.08.14 19:36:34 | 005,073,256 | ---- | C] () -- C:\Windows\SysNative\d3dx9_35.dll [2010.08.14 19:36:34 | 001,985,904 | ---- | C] () -- C:\Windows\SysNative\D3DCompiler_35.dll [2010.08.14 19:36:34 | 000,508,264 | ---- | C] () -- C:\Windows\SysNative\d3dx10_35.dll [2010.08.14 19:36:34 | 000,411,496 | ---- | C] () -- C:\Windows\SysNative\xactengine2_9.dll [2010.08.14 19:36:34 | 000,021,000 | ---- | C] () -- C:\Windows\SysNative\X3DAudio1_2.dll [2010.08.14 05:13:10 | 000,000,350 | ---- | C] () -- C:\Windows\doom3.ini [2010.06.26 17:47:37 | 000,335,372 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistMSI1FC6.txt [2010.06.26 17:47:36 | 000,011,222 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistUI1FC6.txt [2010.06.20 17:02:52 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll [2010.06.20 17:02:52 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll [2010.06.20 17:02:52 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll [2010.06.08 18:57:38 | 000,334,612 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistMSI56F8.txt [2010.06.08 18:57:37 | 000,011,190 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistUI56F8.txt [2010.04.07 00:28:09 | 000,000,093 | ---- | C] () -- C:\Programme\FRAPSLOG.TXT [2010.04.05 23:19:56 | 000,323,472 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistMSI173A.txt [2010.04.05 23:19:56 | 000,011,174 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistUI173A.txt [2010.04.04 01:35:10 | 000,333,852 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistMSI6277.txt [2010.04.04 01:35:10 | 000,011,158 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistUI6277.txt [2010.04.04 00:33:35 | 000,335,752 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistMSI3355.txt [2010.04.04 00:33:35 | 000,011,238 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistUI3355.txt [2010.04.03 19:40:05 | 000,000,262 | ---- | C] () -- C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini [2010.03.31 07:10:20 | 000,019,716 | ---- | C] () -- C:\Programme\changes.txt [2010.03.31 06:56:10 | 000,001,872 | ---- | C] () -- C:\Programme\README.HTM [2010.03.07 12:06:57 | 000,333,852 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistMSI3A47.txt [2010.03.07 12:06:56 | 000,011,158 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistUI3A47.txt [2010.02.14 19:31:19 | 000,333,370 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistMSI259A.txt [2010.02.14 19:31:19 | 000,011,126 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistUI259A.txt [2010.02.07 14:54:58 | 000,070,575 | ---- | C] () -- C:\ProgramData\nvModes.001 [2010.02.07 14:54:49 | 000,070,575 | ---- | C] () -- C:\ProgramData\nvModes.dat [2010.02.05 03:38:30 | 000,424,944 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistMSI0D26.txt [2010.02.05 03:38:30 | 000,011,414 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistUI0D26.txt [2009.12.21 00:50:29 | 000,421,836 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistMSI026F.txt [2009.12.21 00:50:29 | 000,011,414 | ---- | C] () -- C:\Users\matze\AppData\Local\dd_vcredistUI026F.txt [2009.12.09 03:06:16 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini [2009.11.24 19:58:32 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini [2009.11.24 19:58:22 | 000,008,704 | ---- | C] () -- C:\Users\matze\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.04.08 04:52:52 | 000,000,026 | ---- | C] () -- C:\Windows\Irremote.ini [2009.01.20 23:23:15 | 000,000,566 | ---- | C] () -- C:\Windows\SysWow64\hidservice.ini [2008.01.21 04:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini [2008.01.21 04:49:49 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll < End of report > |
02.09.2010, 12:31 | #6 |
| Wo Keine Startleiste mehr nach Virus Vista-Home Lösung! OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 02.09.2010 13:23:25 - Run 1 OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\matze\Desktop 64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 66,00% Memory free 8,00 Gb Paging File | 7,00 Gb Available in Paging File | 82,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 581,52 Gb Total Space | 382,46 Gb Free Space | 65,77% Space Free | Partition Type: NTFS Drive D: | 5,90 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Drive K: | 465,20 Mb Total Space | 346,68 Mb Free Space | 74,52% Space Free | Partition Type: FAT32 Computer Name: MARTIN Current User Name: matze Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" () piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l () scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" File not found Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" File not found Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "oobe_av" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{05CE412F-55F9-4969-8A0F-113BA3F640D8}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{07E0E4E9-7F6C-4C6E-BC2B-3C3194014C83}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{0C3099AF-04D6-46FF-AFEC-73A51739622C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{109F89BA-E812-481D-81BC-9880224F330B}" = lport=8394 | protocol=6 | dir=in | name=league of legends launcher | "{16E5F55D-F87A-4A28-A743-BD5946DBD85C}" = lport=49165 | protocol=6 | dir=in | name=akamai netsession interface | "{2A079D27-4A97-4FD4-AFE0-BB132B02D21C}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{30F8C7F6-7484-4FBA-BE80-52FEB4E67918}" = lport=139 | protocol=6 | dir=in | app=system | "{5A278FCE-20BE-4D5F-86B6-CD83425A4249}" = lport=138 | protocol=17 | dir=in | app=system | "{628B97E2-CA1D-4889-AC59-2A62FDAFC2A1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{68CBA288-29D4-4523-B42C-EA8FFEFE5449}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{7AF3F427-53A1-454F-B095-2A66DAD4F441}" = lport=2869 | protocol=6 | dir=in | app=system | "{7DFEBC95-A6B3-4364-A8E0-2B1220E3D394}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{809C63E1-68A0-4A72-BDB3-A415FD37E69C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{880A0B65-A189-4093-93DE-BB5945A4399C}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface | "{8DBAEA03-38E8-4A92-BC16-9F2678FF2291}" = lport=445 | protocol=6 | dir=in | app=system | "{927CCC1F-A371-466B-8333-7372500220AE}" = rport=2869 | protocol=6 | dir=out | app=system | "{9288CEDA-652C-40D2-859B-6DD72165DBC0}" = lport=8394 | protocol=6 | dir=in | name=league of legends launcher | "{99560F33-08DF-4DCD-9791-9BF312DAC5CA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{99FF03A1-C266-43EE-B7F8-E10CDF33A689}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{9DD447DA-8F2E-4D04-9A0E-0789CA267791}" = lport=8394 | protocol=17 | dir=in | name=league of legends launcher | "{9EA57804-A9C1-461B-93EF-976499EEF4F1}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{A33B628A-2A5E-458D-9BC5-7B9B68415035}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{B0A0C74E-8AF1-4D09-84B3-D8DF4633D204}" = lport=8394 | protocol=17 | dir=in | name=league of legends launcher | "{B3D2BB47-40C5-4F82-861E-3BB12DB8A1CC}" = rport=139 | protocol=6 | dir=out | app=system | "{B795F2AA-FC43-4C08-A495-03F0DADA01FC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B99E41E0-0139-4208-AA01-7D1C234177A1}" = lport=6887 | protocol=6 | dir=in | name=league of legends launcher | "{D20ADDC9-3DAF-4430-B331-78303F340B54}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{D326829A-6123-448B-BA24-FB3B319C9046}" = lport=137 | protocol=17 | dir=in | app=system | "{D70386A9-3784-4565-9E76-CD1241E4AFEA}" = rport=137 | protocol=17 | dir=out | app=system | "{E4A20DCC-471A-4B6A-AC16-AC1485D54391}" = rport=445 | protocol=6 | dir=out | app=system | "{EF0AE1D2-3F2B-4357-9C1F-0C9F005FF728}" = lport=49167 | protocol=6 | dir=in | name=akamai netsession interface | "{F24ECB49-06C3-4FE9-8528-5F3AA3A998B0}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{F4061086-B387-4FC9-A9F9-B0A342BC0B0A}" = lport=6887 | protocol=17 | dir=in | name=league of legends launcher | "{F5B713AA-AFCF-4BAF-8A9C-556726F83C36}" = rport=138 | protocol=17 | dir=out | app=system | "{F85C2C47-984A-4BBB-9EEF-C1991E547EED}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F95A954D-3491-4336-BF47-57FE14E3ABBB}" = lport=2869 | protocol=6 | dir=in | app=system | "{FE00093B-1B3C-46F2-BFF0-10114D18907F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{FE51ED51-434D-4FF7-9C5C-E636A6CE9CC8}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02DE1EA5-901F-4CF0-AA20-28C307639EB4}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{05FAA1CC-F0C7-465C-BE13-1CA03BF47CBB}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\wow-3.2.0-dede-downloader.exe | "{0AB45EB4-BEF9-486A-BE8D-D198F548222B}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{0C063101-DFC2-450B-91F7-104A3F854F79}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{1DD36ABF-6519-4E43-BB4E-1B37D056D0C1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\betti88\condition zero\hl.exe | "{2AD460B0-8D70-4302-985B-8306CC043BED}" = protocol=17 | dir=in | app=c:\program files (x86)\league of legends\game\league of legends.exe | "{2B4D8A14-CE67-427D-9CC5-C8E8FEC8C4E9}" = protocol=17 | dir=in | app=c:\program files\eslwire\wire.exe | "{2E7AC3D0-DD14-498C-B159-34AAA385783A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\betti88\condition zero\hl.exe | "{324F5E67-4A87-44E2-AE05-07F1C0924D2E}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{365A501A-EF84-44F4-9CE6-1386CEC7ADD7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{3C033763-65B7-4F38-9417-EECAA988C220}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{3CA9FE9A-E2E2-465A-A587-98FF0370467F}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.2\icq.exe | "{3F43CA1D-E512-4F0B-9F56-B42D2C2AD336}" = protocol=6 | dir=in | app=c:\program files (x86)\league of legends\air\lolclient.exe | "{408DD8E1-D6B9-4ABA-8380-B984E90D7D10}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe | "{41D01237-851E-4992-A9CD-13E47C6BD295}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{42334AF6-67E8-4822-9E62-3EE3D0DC38E2}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{471794A6-1FD8-4AB3-9B64-AE30AB74B7D9}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.2\icq.exe | "{49EA9684-3675-43FD-8EB2-98E060D1709E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{59539230-003E-4D86-8EC6-CEBF22F07DB6}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{61800DBB-19A4-47B8-BBFF-9AE770B8569E}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.2\icq.exe | "{6ABCB392-A85A-4F53-9AF7-7EBDBD343B44}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.2\aolload.exe | "{6B875B65-2814-407F-8564-53CA405E9A49}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\betti88\condition zero\hl.exe | "{7AF6ADA6-7D90-49E6-8A63-52E29551BBDE}" = protocol=6 | dir=in | app=c:\program files\eslwire\wire.exe | "{7C196F90-4D48-45E3-9316-D439A94CC036}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.2\aolload.exe | "{7CE4870A-F7C8-4CC8-999F-DA862F1BC63A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\betti88\condition zero\hl.exe | "{820C489C-3D37-4C7D-BA6C-9757C2FE3E12}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{84CBCECD-2FB9-4765-8BEC-A305218702EF}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{8516E331-59F5-422E-811B-4CB2ED898A12}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{8A1C35AE-EFBB-410D-AB9A-F74E0923CEE7}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.2\aolload.exe | "{90629F55-C4C2-45F7-9822-72B69FD760AB}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{9349E24C-4484-430E-9A6C-5925852DF7FC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\betti88\counter-strike\hl.exe | "{94CB466E-6CAB-44F3-8620-FFE342956715}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{9D90DB14-566A-4331-8B4D-AD631A94DDB9}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{B09030A5-010D-4265-88D0-1E298E2E10AF}" = protocol=6 | dir=in | app=c:\program files (x86)\league of legends\game\league of legends.exe | "{B2EDFFCB-939C-40C5-B740-B9172A959FFC}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe | "{B35E75E2-D54E-4708-865D-6E19552FEBC9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{B5406382-97DC-4FDE-9280-BC00989BD98A}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{B6DA95AD-C582-48AF-A72F-EEC2CEC59BEF}" = protocol=6 | dir=in | app=c:\program files (x86)\league of legends\game\league of legends.exe | "{BD8D9C68-8050-460B-B9C6-EC9355CEBD91}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\betti88\counter-strike\hl.exe | "{C03CFF27-3324-4BF8-AA8D-D5E303ED5A40}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\betti88\counter-strike\hl.exe | "{C0F87BC0-9DF7-4B4B-9DAA-B00BA2E9A231}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.2\icq.exe | "{C444EFE0-231A-4500-9D5C-87940A753506}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | "{C95266DB-02E9-4C59-9D3F-5D51DA6FEA15}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{CEA20500-2F59-4B07-8C15-E1FE8B4437B6}" = protocol=17 | dir=in | app=c:\program files (x86)\league of legends\air\lolclient.exe | "{D2DB4977-FFB9-4539-91DE-C71936BEB53B}" = protocol=17 | dir=in | app=c:\program files (x86)\league of legends\air\lolclient.exe | "{D42B4E49-670E-4871-9A9E-5D03C968922D}" = protocol=17 | dir=in | app=c:\program files (x86)\league of legends\game\league of legends.exe | "{D7AC05CB-3573-4C40-9AC5-5FB679B8E4CE}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe | "{D96818CF-A56C-40CB-898C-B59735BB84B7}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe | "{DBE74A5B-FFDE-4B13-B0A3-7E92543FCED0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{DDC225E2-6C47-4D29-871A-390C8858971C}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\wow-3.2.0-dede-downloader.exe | "{EB31804E-74E2-4BF2-829D-7A5AA7155644}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{EE382749-B5EE-46EC-B08B-2D361C8EFF01}" = protocol=6 | dir=in | app=c:\program files (x86)\league of legends\air\lolclient.exe | "{EE63954B-82A7-4FD6-8D0E-F805C7A01D9A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\betti88\counter-strike\hl.exe | "{F02B40C6-25D2-49B6-881E-4AF808784ED7}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.2\aolload.exe | "{F1FBC703-2CD1-443D-9F72-E2EE02E76D4C}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{F6766F9E-61CF-40D2-B7FE-38B2E6B14C3F}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe | "TCP Query User{12A784FC-0645-455E-A81D-B203C747A7A1}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | "TCP Query User{1749D2FF-6EED-4EA4-B992-5100551CDB7F}C:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe | "TCP Query User{19547F8C-C03D-423F-B4B2-A38BBA1744E7}C:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe | "TCP Query User{24B7A15F-AF87-408F-B412-AD1C516BE5A6}C:\h§\heroes of might and magic iii complete\heroes of might and magic iii complete\heroes3.exe" = protocol=6 | dir=in | app=c:\h§\heroes of might and magic iii complete\heroes of might and magic iii complete\heroes3.exe | "TCP Query User{321A1DCA-37D1-49CF-90E4-977452A3B832}C:\unrealtournament\system\unrealtournament.exe" = protocol=6 | dir=in | app=c:\unrealtournament\system\unrealtournament.exe | "TCP Query User{385A9E07-3D16-4C0F-9EE6-9A87ABBAE999}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "TCP Query User{58A76E3D-83E5-42CC-B002-F3645FF3AC3D}C:\program files (x86)\hlsw\hlsw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hlsw\hlsw.exe | "TCP Query User{97C0A95C-3DCE-4AD1-B9EF-C03D05EA200D}C:\windows\syswow64\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe | "TCP Query User{AA1E3F06-132C-4565-A426-35E81E1F7E10}C:\program files (x86)\gamers.irc\mirc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gamers.irc\mirc.exe | "TCP Query User{BAD93A4E-B5BC-4140-9790-D0CB2D101D89}C:\program files\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.exe | "TCP Query User{CA421361-5F5B-4AC4-AAB6-E3D7C854B63C}C:\program files (x86)\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files (x86)\icq6.5\icq.exe | "TCP Query User{CBA9C91F-229A-4244-829D-C20EE23880D8}C:\program files (x86)\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files (x86)\icq6.5\icq.exe | "TCP Query User{E343CF12-7BB5-45A3-B6AB-A52CE9DD4DD0}C:\program files (x86)\gamers.irc\mirc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gamers.irc\mirc.exe | "UDP Query User{08C116AF-9E41-45D2-B980-3CC8827581E8}C:\program files (x86)\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files (x86)\icq6.5\icq.exe | "UDP Query User{1F66F55D-0C8D-4B24-B9F4-6C9DC047DB71}C:\program files (x86)\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files (x86)\icq6.5\icq.exe | "UDP Query User{2B7BF27C-827C-4259-80B9-79D22DA54CFA}C:\program files (x86)\gamers.irc\mirc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gamers.irc\mirc.exe | "UDP Query User{53D47467-A05A-487D-86CC-A5BB4D5AE01A}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "UDP Query User{561B0766-5894-4C0C-9352-4343391D3412}C:\program files (x86)\gamers.irc\mirc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gamers.irc\mirc.exe | "UDP Query User{5818F903-9784-4032-B8DA-B2617616BFDD}C:\h§\heroes of might and magic iii complete\heroes of might and magic iii complete\heroes3.exe" = protocol=17 | dir=in | app=c:\h§\heroes of might and magic iii complete\heroes of might and magic iii complete\heroes3.exe | "UDP Query User{5EE1C9D4-F7B2-487E-9D59-336CAA5AC2F8}C:\unrealtournament\system\unrealtournament.exe" = protocol=17 | dir=in | app=c:\unrealtournament\system\unrealtournament.exe | "UDP Query User{74F7E014-8C50-4599-8496-6893AD83EB5F}C:\program files\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.exe | "UDP Query User{A3D4EA67-39CA-4CE4-A27A-C6FF825A4F54}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | "UDP Query User{A921F9DD-BE76-4743-977B-0764C75AC0A5}C:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe | "UDP Query User{C32B7835-DB70-4264-A985-30B7A8002B0C}C:\windows\syswow64\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe | "UDP Query User{C99DDB43-0483-4E0D-9D55-35940B4A92DC}C:\program files (x86)\hlsw\hlsw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hlsw\hlsw.exe | "UDP Query User{EC64A95D-7A98-4CF6-ABAE-D8DA0EC3854B}C:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64 "ESL Wire_is1" = ESL Wire 1.4 "NVIDIA Display Control Panel" = NVIDIA Display Control Panel "NVIDIA Drivers" = NVIDIA Drivers "Office2007" = Microsoft Office Home and Student "TeamSpeak 3 Client" = TeamSpeak 3 Client "WinRAR archiver" = WinRAR "Works9se" = Microsoft Works 9.0 SE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{20071984-5EB1-4881-8EDB-082532ACEC6D}" = Heroes of Might and Magic V "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java(TM) 6 Update 16 "{28518520-F25C-48C3-A224-861F331602F4}" = Setup My PC "{3559CDE0-11FC-4D7B-A65C-D646035B1031}" = Nero 8 Essentials "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{5A166C0B-9557-4364-A057-F946D674E6AC}" = Windows Live Mail "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{62F7DA7E-CCCB-439C-A760-00C3926E761F}" = Microsoft Works "{6B96DADA-1A27-4A04-8CB2-CC45168D05FA}" = Windows Live Fotogalerie "{709817E4-5439-4206-8738-796B34B623BD}" = MetaBoli "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2 "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Packard Bell Recovery Management "{81821BF8-DA20-4F8C-AA87-F70A274828D4}" = Windows Live Writer "{835686C5-8650-49EB-8CA0-4528B4035495}" = Windows Live Call "{837B6259-6FF5-4E66-87C1-A5A15ED36FF4}" = Windows Live Messenger "{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8C1E2925-14F8-45AA-B999-1E2A74BF5607}" = Windows Live Sync "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{58FC5E37-DD28-4D4A-A549-125744C6763C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{00C5525B-3CB3-467D-8100-2E6FB306CD86}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-002A-0407-1000-0000000FF1CE}_HOMESTUDENTR_{888B9AC7-8F5C-456B-A27A-157A6C310E52}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{888B9AC7-8F5C-456B-A27A-157A6C310E52}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German) "{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6 "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A8C2A0AE-FBF8-4B0D-A541-F434D80E55B2}" = Windows Vista Demo Screen Saver "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder "{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter "{AC76BA86-7AD7-1031-7B44-A90000000001}" = Adobe Reader 9 - Deutsch "{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B5BCBD49-202F-4238-8398-D83D423A48B4}" = Windows Live Anmelde-Assistent "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player "{CA786CFF-1D31-4804-B436-F3405B14357F}" = Packard Bell Updator "{DF5F687F-8018-4542-9F98-7084E9022917}" = Windows Live Essentials "{E285F3B1-A840-414F-9A95-47627A16E633}" = AvalonHeroesEU "{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM) "{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant "{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F4EA67C9-6748-4C1E-9AFF-04149AC75D95}" = Packard Bell ImageWriter "{F54AC413-D2C6-4A24-B324-370C223C6250}" = Adobe Photoshop Elements 6.0 "{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Photoshop Elements 6" = Adobe Photoshop Elements 6.0 "Akamai" = Akamai NetSession Interface "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "CPLGUI" = CPL CS GUI "Diablo II" = Diablo II "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "Dungeon Keeper II" = Dungeon Keeper 2 "EasyBits Magic Desktop" = EasyBits Magic Desktop "Fraps" = Fraps "Free Audio CD Burner_is1" = Free Audio CD Burner version 1.2 "Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.2 "Gamers.IRC" = Gamers.IRC 5.30 "Heroes of Might and Magic® III" = Heroes of Might and Magic® III "HLSW_is1" = HLSW v1.3.2.1 "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "ICQToolbar" = ICQ Toolbar "InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM) "InstallShield_{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3 "League of Legends_is1" = League of Legends "LogMeIn Hamachi" = LogMeIn Hamachi "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Mantronic´s Kaiser II_is1" = KaiserII (Version 1.9.0) "Mount&Blade Warband" = Mount&Blade Warband "Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8) "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "OPERATION7" = OPERATION7 "Picasa 3" = Picasa 3 "Steam App 80" = Condition Zero "SystemRequirementsLab" = System Requirements Lab "Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2 "Uninstall_is1" = Uninstall 1.0.0.1 "UnrealTournament" = Unreal Tournament "VentriloMIX" = VentriloMIX "VLC media player" = VLC media player 1.0.3 "WinLiveSuite_Wave3" = Windows Live Essentials "World of Warcraft" = World of Warcraft ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 27.08.2010 08:05:22 | Computer Name = Martin | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 27.08.2010 12:52:22 | Computer Name = Martin | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 27.08.2010 12:52:22 | Computer Name = Martin | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 27.08.2010 20:12:17 | Computer Name = Martin | Source = VSS | ID = 39 Description = Error - 27.08.2010 20:12:17 | Computer Name = Martin | Source = VSS | ID = 8193 Description = Error - 27.08.2010 20:12:17 | Computer Name = Martin | Source = System Restore | ID = 8193 Description = Error - 28.08.2010 08:43:06 | Computer Name = Martin | Source = SideBySide | ID = 16842830 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Nero\Nero8\Nero Toolkit\DiscSpeed.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion. Die widersprüchlichen Komponenten sind: Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_152e7382f3bd50c6.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc.manifest. Error - 28.08.2010 08:43:06 | Computer Name = Martin | Source = SideBySide | ID = 16842830 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Nero\Nero8\Nero Toolkit\DiscSpeed.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion. Die widersprüchlichen Komponenten sind: Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_152e7382f3bd50c6.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc.manifest. Error - 28.08.2010 08:43:16 | Computer Name = Martin | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 28.08.2010 08:43:16 | Computer Name = Martin | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = [ System Events ] Error - 14.07.2010 07:14:49 | Computer Name = Martin | Source = Service Control Manager | ID = 7000 Description = Error - 14.07.2010 07:14:49 | Computer Name = Martin | Source = Service Control Manager | ID = 7000 Description = Error - 14.07.2010 07:14:49 | Computer Name = Martin | Source = Service Control Manager | ID = 7001 Description = Error - 14.07.2010 07:14:49 | Computer Name = Martin | Source = Service Control Manager | ID = 7026 Description = Error - 14.07.2010 12:36:09 | Computer Name = Martin | Source = HTTP | ID = 15016 Description = Error - 14.07.2010 12:37:49 | Computer Name = Martin | Source = Service Control Manager | ID = 7000 Description = Error - 14.07.2010 12:37:49 | Computer Name = Martin | Source = Service Control Manager | ID = 7000 Description = Error - 14.07.2010 12:37:49 | Computer Name = Martin | Source = Service Control Manager | ID = 7001 Description = Error - 14.07.2010 12:37:49 | Computer Name = Martin | Source = Service Control Manager | ID = 7026 Description = Error - 15.07.2010 03:39:47 | Computer Name = Martin | Source = HTTP | ID = 15016 Description = < End of report > |
02.09.2010, 12:38 | #7 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Keine Startleiste mehr nach Virus Vista-Home Was ist mit dem Vollscan von Malwarebytes?
__________________ Logfiles bitte immer in CODE-Tags posten |
02.09.2010, 12:48 | #8 |
| Keine Startleiste mehr nach Virus Vista-Home Hier der Malwarelog Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4529 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 02.09.2010 14:19:11 mbam-log-2010-09-02 (14-19-11).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 274056 Laufzeit: 51 Minute(n), 48 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> No action taken. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Geändert von xajiin (02.09.2010 um 13:19 Uhr) |
02.09.2010, 18:25 | #9 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Keine Startleiste mehr nach Virus Vista-Home Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1 [2010.08.31 19:34:13 | 000,000,000 | ---D | C] -- C:\Users\matze\AppData\Local\MigWiz [2010.08.31 18:23:34 | 000,188,928 | ---- | C] (OpenSC Project) -- C:\Windows\Atapoa.exe [2010.08.31 18:23:20 | 000,000,000 | ---D | C] -- C:\Users\matze\AppData\Local\tjhgwfrsy [2010.08.31 18:23:09 | 000,000,000 | ---D | C] -- C:\Users\matze\AppData\Local\Windows Server [2010.08.31 18:23:15 | 000,000,005 | ---- | M] () -- C:\zrpt.xml :Commands [purity] [resethosts] [emptytemp] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.
__________________ Logfiles bitte immer in CODE-Tags posten |
02.09.2010, 20:21 | #10 |
| Keine Startleiste mehr nach Virus Vista-Home [gelöst] All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully. C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll moved successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! C:\Users\matze\AppData\Local\MigWiz folder moved successfully. File C:\Windows\Atapoa.exe not found. C:\Users\matze\AppData\Local\tjhgwfrsy folder moved successfully. C:\Users\matze\AppData\Local\Windows Server folder moved successfully. C:\zrpt.xml moved successfully. ========== COMMANDS ========== File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: matze ->Temp folder emptied: 1031117407 bytes ->Temporary Internet Files folder emptied: 752894099 bytes ->Java cache emptied: 24294992 bytes ->FireFox cache emptied: 76128829 bytes ->Flash cache emptied: 30996 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 31590243 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 9438236197 bytes Total Files Cleaned = 10.828,00 mb OTL by OldTimer - Version 3.2.11.0 log created on 09022010_211630 Files\Folders moved on Reboot... File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DW6QMRW5\desktop.ini scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6MOWL0UY\desktop.ini scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\21X6GUBR\desktop.ini scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1CQDYT00\desktop.ini scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot. Registry entries deleted on Reboot... |
02.09.2010, 20:24 | #11 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Keine Startleiste mehr nach Virus Vista-Home [gelöst] CustomScan mit OTL Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Keine Startleiste mehr nach Virus Vista-Home |
abend, angezeigt, betriebssystem, dateien, dauert, eingabe, einsatz, guten, hijack, hijackthis, hochfahren, interne, internetseite, internetseiten, lange, leiste, malware, nichts, seite, seiten, starte, starten., startleiste, thread, ungewöhnlich, virus |