Ok, I completed Step 1 successfully. On Step 2, I still have the same problem that MBAM won't start., so I ran a system scan with Avira Antivir which found 1 Virus and quarantined it. After that the basic problems are still there. MBAM not starting, Opera opening in IE and the occasional "Google Installer" error popping up.
The RootRepeal.exe didn't work for me though. I've tried it several times, I gave it plenty of time, but every time I started it, it would only show this "Initializing" window with nothing happening even if I gave 15 minutes. On top of that it also froze the computer so I had to reset every time.
OTL logfile created on: 9/29/2009 3:38:38 AM - Run 1
OTL by OldTimer - Version 3.0.16.0 Folder = C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: Vereinigte Staaten von Amerika | Language: ENU | Date Format: M/d/yyyy
511.36 Mb Total Physical Memory | 157.62 Mb Available Physical Memory | 30.82% Memory free
1.22 Gb Paging File | 0.82 Gb Available in Paging File | 66.90% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 27.95 Gb Total Space | 2.33 Gb Free Space | 8.32% Space Free | Partition Type: NTFS
Drive D: | 121.10 Gb Total Space | 8.43 Gb Free Space | 6.96% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SPEC
Current User Name: Thomas Kirschner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2002/04/12 01:00:00 | 00,057,344 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\System32\brsvc01a.exe
PRC - [2001/12/13 01:01:00 | 00,045,056 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\System32\brss01a.exe
PRC - [2009/06/24 19:27:23 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2008/04/14 04:22:45 | 01,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2009/08/06 09:25:10 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2006/10/23 14:50:35 | 00,046,640 | ---- | M] (AOL LLC) -- C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe
PRC - [2008/11/07 15:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/04/02 12:47:02 | 00,464,264 | ---- | M] () -- C:\Programme\AskBarDis\bar\bin\AskService.exe
PRC - [2009/04/02 12:47:04 | 00,234,888 | ---- | M] () -- C:\Programme\AskBarDis\bar\bin\ASKUpgrade.exe
PRC - [2008/07/09 00:29:18 | 00,231,192 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG8\avgwdsvc.exe
PRC - [2008/08/29 11:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Programme\Bonjour\mDNSResponder.exe
PRC - [2002/11/27 14:38:32 | 00,061,440 | ---- | M] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\Brmfrmps.exe
PRC - [1999/12/12 19:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\CTsvcCDA.exe
PRC - [2005/10/10 21:49:00 | 00,131,139 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe
PRC - [2005/03/26 20:56:01 | 00,126,976 | ---- | M] () -- C:\WINDOWS\System32\UAService7.exe
PRC - [2003/02/14 11:59:00 | 00,088,107 | ---- | M] (Agere Systems) -- C:\WINDOWS\AGRSMMSG.exe
PRC - [2000/06/02 20:07:58 | 00,024,650 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Hardware\Game Controllers\Common\SWTrayV4.EXE
PRC - [2002/08/08 11:38:16 | 00,045,108 | ---- | M] (ScanSoft, Inc.) -- C:\Programme\Scansoft\PaperPort\pptd40nt.exe
PRC - [2008/06/05 01:09:56 | 04,994,288 | ---- | M] (Itiva Digital Media) -- C:\Programme\Itiva\Itiva Media Accelerator\ItivaMediaAccelerator.exe
PRC - [2006/06/09 01:11:00 | 00,024,576 | ---- | M] (Creative Technology Ltd.) -- C:\Programme\Creative\Creative Live! Cam\VideoFX\StartFX.exe
PRC - [2006/07/19 19:00:00 | 00,036,961 | R--- | M] (Creative Technology Ltd.) -- C:\WINDOWS\System32\V0230Mon.exe
PRC - [2002/08/20 10:29:26 | 00,040,960 | ---- | M] (Easy Systems Japan Ltd.) -- C:\WINDOWS\System32\ezSP_Px.exe
PRC - [2006/10/27 00:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2009/01/05 17:18:48 | 00,413,696 | ---- | M] (Apple Inc.) -- C:\Programme\QuickTime\QTTask.exe
PRC - [2009/01/06 14:06:36 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Programme\iTunes\iTunesHelper.exe
PRC - [2009/02/27 18:10:28 | 00,035,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe
PRC - [2009/03/02 13:08:47 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2006/06/12 14:32:26 | 00,700,416 | ---- | M] () -- C:\Programme\Creative\Sync Manager Unicode\CTSyncU.exe
PRC - [2006/05/31 16:00:54 | 00,143,360 | ---- | M] (Creative Technology Ltd.) -- C:\Programme\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
PRC - [2008/05/27 12:27:24 | 00,547,840 | ---- | M] (MagicISO, Inc.) -- C:\Programme\MagicDisc\MagicDisc.exe
PRC - [2009/01/06 14:06:24 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Programme\iPod\bin\iPodService.exe
PRC - [2009/02/20 15:22:34 | 00,079,088 | ---- | M] (Yahoo! Inc.) -- C:\Programme\Yahoo!\Messenger\ymsgr_tray.exe
PRC - [2009/09/29 02:45:30 | 00,518,144 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\OTL.exe
========== Win32 Services (SafeList) ========== SRV - [2009/06/24 19:27:23 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService [Auto | Running])
SRV - [2009/08/06 09:25:10 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService [Auto | Running])
SRV - [2006/10/23 14:50:35 | 00,046,640 | ---- | M] (AOL LLC) -- C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe -- (AOL ACS [Auto | Running])
SRV - [2008/11/07 15:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2009/04/02 12:47:02 | 00,464,264 | ---- | M] () -- C:\Programme\AskBarDis\bar\bin\AskService.exe -- (ASKService [Auto | Running])
SRV - [2009/04/02 12:47:04 | 00,234,888 | ---- | M] () -- C:\Programme\AskBarDis\bar\bin\ASKUpgrade.exe -- (ASKUpgrade [Auto | Running])
SRV - [2005/09/23 08:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/07/09 00:29:20 | 00,873,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG8\avgemc.exe -- (avg8emc [Auto | Stopped])
SRV - [2008/07/09 00:29:18 | 00,231,192 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
SRV - [2008/08/29 11:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Programme\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2002/11/27 14:38:32 | 00,061,440 | ---- | M] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\Brmfrmps.exe -- (brmfrmps [Auto | Running])
SRV - [2002/04/12 01:00:00 | 00,057,344 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\System32\brsvc01a.exe -- (Brother XP spl Service [Auto | Running])
SRV - [2005/09/23 08:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [1999/12/12 19:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\CTsvcCDA.exe -- (Creative Service for CDROM Access [Auto | Running])
SRV - [2009/03/04 06:29:33 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Programme\Google\Update\GoogleUpdate.exe -- (gupdate1c99c81d5dfa3cc [Auto | Stopped])
SRV - [2007/10/06 17:06:33 | 00,138,680 | ---- | M] (Google) -- C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [Auto | Stopped])
SRV - [2008/04/14 04:22:23 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2009/01/06 14:06:24 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Programme\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2006/10/27 00:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2005/10/10 21:49:00 | 00,131,139 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2006/10/26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2007/06/29 02:01:48 | 00,092,792 | ---- | M] (CACE Technologies) -- C:\Programme\WinPcap\rpcapd.exe -- (rpcapd [On_Demand | Stopped])
SRV - [2002/12/24 11:01:22 | 00,065,536 | ---- | M] (Sony Corporation) -- C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV [On_Demand | Stopped])
SRV - [2005/03/26 20:56:01 | 00,126,976 | ---- | M] () -- C:\WINDOWS\System32\UAService7.exe -- (UserAccess7 [Auto | Running])
SRV - [2006/11/03 10:56:28 | 00,920,576 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm...tf8&oe=utf8IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5
FF - prefs.js..extensions.enabledItems: batchdownload@waxb.blog.com.cn:1.2.2
FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.11.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Programme\AVG\AVG8\Firefox
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\Programme\Mozilla Firefox\components [2009/07/02 11:33:47 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2009/06/12 14:43:35 | 00,000,000 | ---D | M]
[2008/07/31 23:55:10 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\mozilla\Extensions
[2008/07/31 23:55:10 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/09/28 12:00:06 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\mozilla\Firefox\Profiles\zdjou8ce.default\extensions
[2009/01/29 14:58:38 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\mozilla\Firefox\Profiles\zdjou8ce.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/08/02 11:06:09 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\mozilla\Firefox\Profiles\zdjou8ce.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2009/09/08 00:54:44 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\mozilla\Firefox\Profiles\zdjou8ce.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/08/01 04:27:50 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\mozilla\Firefox\Profiles\zdjou8ce.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2008/11/12 17:28:11 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\mozilla\Firefox\Profiles\zdjou8ce.default\extensions\batchdownload@waxb.blog.com.cn
[2009/08/02 11:06:08 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\mozilla\Firefox\Profiles\zdjou8ce.default\extensions\piclens@cooliris.com
[2009/09/28 12:00:06 | 00,000,000 | ---D | M] -- C:\Programme\mozilla firefox\extensions
[2009/06/12 14:43:35 | 00,000,000 | ---D | M] -- C:\Programme\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/08/24 19:37:41 | 00,000,000 | ---D | M] -- C:\Programme\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2008/04/20 14:46:48 | 00,000,000 | ---D | M] -- C:\Programme\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/20 14:40:26 | 00,000,000 | ---D | M] -- C:\Programme\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/06/12 14:43:24 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browserdirprovider.dll
[2009/06/12 14:43:24 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\brwsrcmp.dll
[2004/09/09 01:03:50 | 00,049,152 | ---- | M] (Macromedia, Inc.) -- C:\Programme\mozilla firefox\plugins\np32dsw.dll
[2008/02/21 04:04:00 | 01,335,600 | ---- | M] (DivX,Inc.) -- C:\Programme\mozilla firefox\plugins\npdivx32.dll
[2009/06/12 14:43:25 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Programme\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Programme\mozilla firefox\plugins\NPOFF12.DLL
[2009/02/27 13:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\mozilla firefox\plugins\nppdf32.dll
[2009/03/04 21:28:09 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin.dll
[2009/03/04 21:28:09 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin2.dll
[2009/03/04 21:28:09 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin3.dll
[2009/03/04 21:28:09 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin4.dll
[2009/03/04 21:28:09 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin5.dll
[2009/03/04 21:28:09 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin6.dll
[2009/03/04 21:28:09 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin7.dll
[2004/02/20 22:14:09 | 00,176,177 | ---- | M] () -- C:\Programme\mozilla firefox\plugins\npViewpoint.dll
[2008/09/30 02:08:18 | 00,001,394 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom.xml
[2008/09/30 02:08:18 | 00,002,193 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\answers.xml
[2008/09/30 02:08:18 | 00,001,534 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/13 23:56:01 | 00,002,343 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay.xml
[2008/09/30 02:08:18 | 00,001,706 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\google.xml
[2008/09/30 02:08:18 | 00,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia.xml
[2008/09/30 02:08:18 | 00,000,792 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Programme\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Programme\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Programme\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVFX Engine] C:\Programme\Creative\Creative Live! Cam\VideoFX\StartFX.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Programme\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe (Easy Systems Japan Ltd.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IndexSearch] C:\Programme\Scansoft\PaperPort\IndexSearch.exe ()
O4 - HKLM..\Run: [Itiva Media Accelerator] C:\Programme\Itiva\Itiva Media Accelerator\ItivaMediaAccelerator.exe (Itiva Digital Media)
O4 - HKLM..\Run: [iTunesHelper] C:\Programme\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PaperPort PTD] C:\Programme\Scansoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Programme\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SetDefPrt] C:\Programme\Brother\BRMFLPRO\BrDefPrt.exe ()
O4 - HKLM..\Run: [SideWinderTrayV4] C:\Programme\Microsoft Hardware\Game Controllers\Common\SWTrayV4.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [StorageGuard] C:\Programme\VERITAS Software\Update Manager\sgtray.exe (VERITAS Software, Inc.)
O4 - HKLM..\Run: [V0230Mon.exe] C:\WINDOWS\System32\V0230Mon.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [Creative Live! Cam Manager] C:\Programme\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [CTSyncU.exe] C:\Programme\Creative\Sync Manager Unicode\CTSyncU.exe ()
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Programme\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Google Updater.lnk = C:\Programme\Google\Google Updater\GoogleUpdater.exe (Google)
O4 - Startup: C:\Dokumente und Einstellungen\Thomas Kirschner\Startmenü\Programme\Autostart\ERUNT AutoBackup.lnk = C:\Programme\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Dokumente und Einstellungen\Thomas Kirschner\Startmenü\Programme\Autostart\MagicDisc.lnk = C:\Programme\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 227
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskmgr = 0
O8 - Extra context menu item: &AOL Toolbar-Suche - c:\programme\aol\aol toolbar 4.0\resources\de-DE\local\search.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: SirSearch - C:\Programme\GRIPBTSS\Cache\SelectedContextSearch.htm File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71}
http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C}
http://messenger.zone.msn.com/binary/msgrchkr.cab (Checkers Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Programme\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {430DDE24-C051-11CF-95BE-0020AFF75E4F}
http://chat2.playboy.com:4080/chat/data/ht...sie/msichat.ocx (ichat xchat Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://by21fd.bay21.hotmail.msn.com/resources/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2}
http://simcity.ea.com/update/EARTPX.cab (EARTPatchX Class)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
http://download.bitdefender.com/resources/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {64697663-0000-0010-8000-00AA00389B71}
http://codecs.microsoft.com/codecs/i386/cinepak.cab (Reg Error: Key error.)
O16 - DPF: {6F1AF9D5-68BB-4A81-93F1-481CB8AB0D0B}
http://web1.photocolor.net/webupload/Activ...lorUploader.cab (PhotocolorUploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
http://messenger.zone.msn.com/binary/Messe...StatsClient.cab (MessengerStatsClient Class)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
http://messenger.msn.com/download/MsnMesse...pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592}
http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}
http://game04.zylom.com/activex/zylomgamesplayer.cab (Zylom Games Player)
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD}
http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab (MaxisSimCity4PatcherX Control)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {C8D533D0-31AA-4EBA-BD20-D5126963E0AC}
http://www.webchat-solutions.de/chats/jfc/ActiveChat.CAB (WollnyITService.ActiveChat)
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/1.4/ji...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2_05)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2_06)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_08)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB}
http://ax.phobos.apple.com.edgesuite.net/d.../ITDetector.cab (iTunesDetector Class)
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3}
http://messenger.zone.msn.com/binary/WoF.cab57176.cab (WheelofFortune Object)
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88}
http://us.dl1.yimg.com/download.companion....ebio5_1_6_0.cab (Reg Error: Key error.)
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D}
http://by21fd.bay21.hotmail.msn.com/activex/HMAtchmt.ocx (Hotmail Attachments Control)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6}
http://chat.msn.com/bin/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ic32pp {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - C:\WINDOWS\wc98pp.dll ()
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - file:///C:/DOKUME~1/THOMAS~1/LOKALE~1/Temp/msohtmlclip1/01/clip_image002.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O27 - HKLM IFEO\chrome.exe: Debugger - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation)
O27 - HKLM IFEO\navigator.exe: Debugger - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation)
O27 - HKLM IFEO\opera.exe: Debugger - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation)
O27 - HKLM IFEO\safari.exe: Debugger - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation)
O27 - HKLM IFEO\userinit.exe: Debugger - File not found
O28 - HKLM ShellExecuteHooks: {93994DE8-8239-4655-B1D1-5F4E91300429} - C:\Programme\DVD Region+CSS Free\DVDShell.dll (Fengtao Software Inc.)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/01 07:03:39 | 00,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{0a7e5c97-0e2f-11dd-854f-00038a000015}\Shell\AutoRun\command - "" = H:\Launch.exe -- File not found
O33 - MountPoints2\{4a7c77df-ce91-11db-82cd-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{4a7c77df-ce91-11db-82cd-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{75996356-4e00-11dc-8308-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{75996356-4e00-11dc-8308-00038a000015}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 14 Days ========== [2009/09/29 02:45:44 | 00,472,064 | ---- | C] ( ) -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\RootRepeal.exe
[2009/09/29 02:45:30 | 00,518,144 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\OTL.exe
[2009/09/29 02:44:44 | 00,464,491 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\RootRepeal.zip
[2009/09/29 02:40:10 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/09/29 02:30:16 | 00,440,832 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\CKScanner.exe
[2009/09/29 02:29:56 | 00,173,119 | ---- | C] (Eric_71) -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\Rooter.exe
[2009/09/28 23:05:10 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/09/28 23:04:51 | 00,000,751 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Startmenü\Programme\Autostart\ERUNT AutoBackup.lnk
[2009/09/28 23:04:48 | 00,000,595 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\NTREGOPT.lnk
[2009/09/28 23:04:48 | 00,000,576 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\ERUNT.lnk
[2009/09/28 23:04:48 | 00,000,000 | ---D | C] -- C:\Programme\ERUNT
[2009/09/28 23:02:57 | 00,271,872 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\TFC.exe
[2009/09/28 23:02:46 | 00,794,112 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\The_Comedian.exe
[2009/09/28 12:58:14 | 00,000,254 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Eigene Dateien\cc_20090928_125812.reg
[2009/09/28 12:57:52 | 00,005,368 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Eigene Dateien\cc_20090928_125751.reg
[2009/09/28 12:57:09 | 00,049,494 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Eigene Dateien\cc_20090928_125706.reg
[2009/09/25 16:32:32 | 00,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AOL
[2009/09/25 05:58:04 | 00,091,289 | ---- | C] () -- C:\WINDOWS\System32\ousivhfztup
[2009/09/24 05:32:40 | 02,202,796 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\31572135.jpg
[2009/09/23 09:46:51 | 02,757,814 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\mcd_coupons_zum_ausdrucken_sept_09.pdf
[2009/09/23 00:14:42 | 00,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\lovvekylie
[2009/09/22 16:10:35 | 00,604,242 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\barber2.jpg
[2009/09/22 16:01:55 | 01,677,408 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\CIMG1041.JPG
[2009/09/21 03:13:54 | 00,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\vlc
[2009/09/21 01:03:10 | 00,000,695 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
[2009/09/20 20:19:13 | 00,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\Sara
[2009/09/19 23:51:52 | 02,562,247 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\019_bathroom_strip.wmv
[2009/09/18 19:55:14 | 00,020,578 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\eyebrow-kitty.jpg
[2009/09/17 19:45:03 | 00,027,105 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Eigene Dateien\Nocat1.jpg
[2009/09/17 17:57:49 | 00,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\ebay
[2009/09/16 06:59:05 | 01,438,639 | ---- | C] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\haystacklanding.jpg
========== Files - Modified Within 14 Days ========== [2009/09/29 03:35:37 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/09/29 03:34:55 | 00,039,369 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/09/29 03:34:23 | 00,001,084 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/09/29 03:34:18 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/09/29 03:34:06 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/09/29 02:45:30 | 00,518,144 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\OTL.exe
[2009/09/29 02:44:45 | 00,464,491 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\RootRepeal.zip
[2009/09/29 02:43:11 | 00,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/09/29 02:30:16 | 00,440,832 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\CKScanner.exe
[2009/09/29 02:29:57 | 00,173,119 | ---- | M] (Eric_71) -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\Rooter.exe
[2009/09/28 23:04:51 | 00,000,751 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Startmenü\Programme\Autostart\ERUNT AutoBackup.lnk
[2009/09/28 23:04:48 | 00,000,595 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\NTREGOPT.lnk
[2009/09/28 23:04:48 | 00,000,576 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\ERUNT.lnk
[2009/09/28 23:02:57 | 00,271,872 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\TFC.exe
[2009/09/28 23:02:47 | 00,794,112 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\The_Comedian.exe
[2009/09/28 12:58:16 | 00,000,254 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Eigene Dateien\cc_20090928_125812.reg
[2009/09/28 12:57:56 | 00,005,368 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Eigene Dateien\cc_20090928_125751.reg
[2009/09/28 12:57:17 | 00,049,494 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Eigene Dateien\cc_20090928_125706.reg
[2009/09/28 12:49:48 | 00,000,035 | ---- | M] () -- C:\WINDOWS\entpack.ini
[2009/09/28 11:30:38 | 00,041,472 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/25 17:03:13 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/09/25 11:34:07 | 00,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/09/25 05:58:04 | 00,091,289 | ---- | M] () -- C:\WINDOWS\System32\ousivhfztup
[2009/09/24 05:32:41 | 02,202,796 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\31572135.jpg
[2009/09/23 09:46:52 | 02,757,814 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\mcd_coupons_zum_ausdrucken_sept_09.pdf
[2009/09/22 16:11:32 | 00,604,242 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\barber2.jpg
[2009/09/22 16:02:32 | 01,677,408 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\CIMG1041.JPG
[2009/09/22 03:03:01 | 00,000,067 | ---- | M] () -- C:\WINDOWS\DVDRegionFree.INI
[2009/09/21 01:03:10 | 00,000,695 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
[2009/09/19 23:51:53 | 02,562,247 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\019_bathroom_strip.wmv
[2009/09/18 19:55:15 | 00,020,578 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\eyebrow-kitty.jpg
[2009/09/17 19:45:04 | 00,027,105 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Eigene Dateien\Nocat1.jpg
[2009/09/16 06:59:05 | 01,438,639 | ---- | M] () -- C:\Dokumente und Einstellungen\Thomas Kirschner\Desktop\haystacklanding.jpg
========== LOP Check ========== [2009/09/25 16:32:32 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten
[2009/02/06 12:49:25 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2007/03/24 06:33:56 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Azureus
[2003/04/15 10:37:15 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CyberLink
[2008/02/28 08:28:49 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Itiva
[2004/06/27 16:07:24 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Macrovision
[2009/05/30 01:20:43 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Messenger Plus!
[2006/02/26 05:18:18 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MSN6
[2008/06/01 07:01:32 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\muvee Technologies
[2004/03/16 10:02:15 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NFS Underground
[2003/06/07 09:47:09 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SBSI
[2004/01/15 22:47:06 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft
[2005/03/31 14:46:12 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SUIIMAGE
[2009/08/20 11:24:52 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
[2005/10/09 03:24:29 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Trymedia
[2007/10/06 17:02:46 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Viewpoint
[2006/03/12 00:30:42 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Zylom
[2009/09/21 03:13:54 | 00,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten
[2005/07/11 16:08:51 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\.bittorrent
[2004/11/13 22:17:37 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\Acclaim Entertainment
[2009/09/24 15:42:22 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\Azureus
[2004/01/20 13:01:20 | 00,000,000 | R--D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\Brother
[2005/06/22 21:01:15 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\Canon
[2006/02/25 19:39:48 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\CDZilla
[2008/10/26 23:12:24 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2006/06/23 23:46:48 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\CoreCodec
[2003/10/19 22:45:25 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\CyberLink
[2009/09/01 20:05:09 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\dvdcss
[2008/11/05 23:30:19 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\GetRightToGo
[2009/04/18 11:56:00 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\gtk-2.0
[2003/06/08 14:02:38 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\InterTrust
[2004/08/20 11:22:48 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\InterVideo
[2004/03/12 20:21:09 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\Leadertech
[2008/12/07 22:12:43 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\LEGO Company
[2007/10/14 22:39:16 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\mIRC
[2006/06/04 18:16:42 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\MonkeyJam
[2006/03/04 15:52:46 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\MSN6
[2008/06/01 07:17:35 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\muvee Technologies
[2005/07/27 04:49:23 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\Offline Explorer
[2007/10/07 18:51:55 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\Opera
[2008/03/24 23:04:02 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\Orbit
[2005/08/07 03:46:21 | 00,000,000 | RH-D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\SecuROM
[2003/10/09 15:35:30 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\Template
[2003/10/08 22:31:18 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\VERITAS
[2008/04/26 03:16:19 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\Viewpoint
[2006/02/25 19:44:14 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\visviva
[2007/08/17 03:45:54 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\WebCam Recorder
[2006/02/11 15:30:12 | 00,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Thomas Kirschner\Anwendungsdaten\You've Got Pictures Screensaver
[2009/09/25 11:34:07 | 00,000,276 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 14:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2006/04/06 05:55:35 | 00,000,372 | ---- | M] () -- C:\WINDOWS\Tasks\family.guy.404.pdtv-lol.[VTV].job
[2009/09/29 03:34:23 | 00,001,084 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009/09/29 02:43:11 | 00,001,088 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2009/09/29 03:34:18 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe >[2005/10/31 17:56:00 | 00,700,416 | ---- | M] (LimeWire) -- C:\StubInstaller.exe
========== Alternate Data Streams ========== @Alternate Data Stream - 487 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:05EE1EEF
@Alternate Data Stream - 144 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:DFC5A2B2
< End of report >