~ ZHPDiag v2016.5.25.99 Von Nicolas Coolman (2016/05/25) ~ gestartet von Mus (Administrator) (2016/05/27 18:59:10) ~ Site: http://www.nicolascoolman.com ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Version des Status: Version OK ~ Modus: Scanner ~ Bericht: C:\Dokumente und Einstellungen\Mus\Desktop\ZHPDiag.txt ~ Bericht: C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\ZHP\ZHPDiag.txt ~ UAC: Deactivate ~ Systemstart: Normal (Normal boot) Windows XP, 32-bit Service Pack 3 (Build 2600) ---\\ Internet-browser (2) - 0s MFIE: Mozilla Firefox 46.0.1 (x86 de) MSIE: Internet Explorer v8.0.6001.18702 ---\\ Windows-Produkt-Informationen (3) - 0s Windows Automatic Updates : OK Windows Activation Technologies : KO Windows Genuine Advantage : KO ---\\ System-Datenschutz-software (2) - 1s Avira Launcher v1.1.58.35540 Malwarebytes Anti-Malware Version 2.2.0.1024 ---\\ Monitoring Software (1) - 1s Adobe Flash Player 21 NPAPI ---\\ Informationen über das system (6) - 0s ~ Operating System: x86 Family 6 Model 14 Stepping 8, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 1046.904 MB (22% free) System Restore: Activé (Enable) System drive C: has 77 GB () free of 85 GB ---\\ Verbindung zu den Systemmodus (3) - 0s ~ Computer Name: MUT-E3D7FB2CF21 ~ User Name: Mus ~ Logged in as Administrator ---\\ Aufzählung von Disk-Einheiten (2) - 1s ~ Drive C: has 77 GB free of 85 GB (System) ~ Drive E: has 25 GB free of 28 GB ---\\ Status der Windows-Sicherheitscenter (8) - 0s [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Suche generische Systemdateien (23) - 2s [MD5.418045A93CD87A352098AB7DABE1B53E] - 14/04/2008 - (.Microsoft Corporation - Windows Explorer.) -- C:\WINXP\Explorer.exe [1036800] =>.Microsoft Corporation [MD5.F6B34CD47CAF6D68106B9F8055F35C50] - 14/04/2008 - (.Microsoft Corporation - Eine DLL-Datei als Anwendung ausführen.) -- C:\WINXP\System32\rundll32.exe [33792] =>.Microsoft Corporation [MD5.628696B409200762C12C5140C434CBFA] - 14/12/2010 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\WINXP\System32\wininet.dll [919552] =>.Microsoft Corporation [MD5.F09A527B422E25C478E38CAA0E44417A] - 14/04/2008 - (.Microsoft Corporation - Windows NT-Anmeldung.) -- C:\WINXP\System32\Winlogon.exe [513024] =>.Microsoft Corporation [MD5.411F4DE4AEA652298B03886A9AAB63CD] - 03/08/2009 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINXP\System32\dnsapi.dll [147968] =>.Microsoft Corporation [MD5.4D43E74F2A1239D53929B82600F1971C] - 03/08/2009 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINXP\System32\drivers\AFD.sys [138496] =>.Microsoft Corporation [MD5.9F3A2F5AA6875C72BF062C712CFA2674] - 13/04/2008 - (.Microsoft Corporation - IDE/ATAPI Port Driver.) -- C:\WINXP\System32\drivers\atapi.sys [96512] =>.Microsoft Corporation [MD5.C885B02847F5D2FD45A24E219ED93B32] - 14/04/2008 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINXP\System32\drivers\Cdfs.sys [63744] =>.Microsoft Corporation [MD5.1F4260CC5B42272D71F79E570A27A4FE] - 14/04/2008 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINXP\System32\drivers\Cdrom.sys [62976] =>.Microsoft Corporation [MD5.B0678A548587C5F1967B0D70BACAD6C1] - 14/04/2008 - (.Microsoft Corporation - FIPS-Verschlüsselungstreiber.) -- C:\WINXP\System32\drivers\Fips.sys [44672] =>.Microsoft Corporation [MD5.573C7D0A32852B48F3058CFD8026F511] - 14/04/2008 - (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) -- C:\WINXP\System32\drivers\HDAudBus.sys [144384] [MD5.E283B97CFBEB86C1D86BAED5F7846A92] - 14/04/2008 - (.Microsoft Corporation - i8042-Anschlusstreiber.) -- C:\WINXP\System32\drivers\i8042prt.sys [52992] =>.Microsoft Corporation [MD5.083A052659F5310DD8B6A6CB05EDCF8E] - 14/04/2008 - (.Microsoft Corporation - IMAPI Kernel Driver.) -- C:\WINXP\System32\drivers\Imapi.sys [42112] =>.Microsoft Corporation [MD5.CC748EA12C6EFFDE940EE98098BF96BB] - 14/04/2008 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINXP\System32\drivers\IpNat.sys [152832] =>.Microsoft Corporation [MD5.23C74D75E36E7158768DD63D92789A91] - 14/04/2008 - (.Microsoft Corporation - IPSec Driver.) -- C:\WINXP\System32\drivers\IPSec.sys [75264] =>.Microsoft Corporation [MD5.D09B9F0B9960DD41E73127B7814C115F] - 13/04/2010 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\WINXP\System32\drivers\MRxSmb.sys [457216] =>.Microsoft Corporation [MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - 14/04/2008 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINXP\System32\drivers\netBT.sys [162816] =>.Microsoft Corporation [MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - 14/04/2008 - (.Microsoft Corporation - NT File System Driver.) -- C:\WINXP\System32\drivers\ntfs.sys [574976] =>.Microsoft Corporation [MD5.F84785660305B9B903FB3BCA8BA29837] - 08/03/2011 - (.Microsoft Corporation - Treiber für parallelen Anschluss.) -- C:\WINXP\System32\drivers\Parport.sys [80384] =>.Microsoft Corporation [MD5.11B4A627BC9614B885C4969BFA5FF8A6] - 14/04/2008 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINXP\System32\drivers\Rasl2tp.sys [51328] =>.Microsoft Corporation [MD5.15CABD0F7C00C47C70124907916AF3F1] - 13/04/2008 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\WINXP\System32\drivers\rdpdr.sys [196224] =>.Microsoft Corporation [MD5.ED761D453856F795A7FE056E42C36365] - 14/04/2008 - (.Microsoft Corporation - Redbook-Audiofiltertreiber.) -- C:\WINXP\System32\drivers\redbook.sys [57728] =>.Microsoft Corporation [MD5.A5A712F4E880874A477AF790B5186E1D] - 14/04/2008 - (.Microsoft Corporation - Volumeschattenkopie-Treiber.) -- C:\WINXP\System32\drivers\volsnap.sys [53760] =>.Microsoft Corporation ---\\ Nicht von Microsoft nicht deaktiviert Windows XP/NT/2000-Dienste (9) - 5s O23 - Service: Avira FireWall (AntiVirFirewallService) . (.Avira Operations GmbH & Co. KG - Firewall NT service process.) - C:\Programme\Avira\AntiVir Desktop\avfwsvc.exe =>.Avira Operations GmbH & Co. KG® O23 - Service: Avira Mail Protection (AntiVirMailService) . (.Avira Operations GmbH & Co. KG - Antivirus MailScanner LSP Service.) - C:\Programme\Avira\AntiVir Desktop\avmailc.exe =>.Avira Operations GmbH & Co. KG® O23 - Service: Avira Scheduler (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Programme\Avira\AntiVir Desktop\sched.exe =>.Avira Operations GmbH & Co. KG® O23 - Service: Avira Real-Time Protection (AntiVirService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Programme\Avira\AntiVir Desktop\avguard.exe =>.Avira Operations GmbH & Co. KG® O23 - Service: Avira Web Protection (AntiVirWebService) . (.Avira Operations GmbH & Co. KG - AntiVir WebGuard Service.) - C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe =>.Avira Operations GmbH & Co. KG® O23 - Service: (Ati HotKey Poller) . (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) - C:\WINXP\system32\ati2evxx.exe =>.ATI Technologies Inc. O23 - Service: Avira Service Host (Avira.ServiceHost) . (.Avira Operations GmbH & Co. KG - Avira Service Host.) - C:\Programme\Avira\Launcher\Avira.ServiceHost.exe =>.Avira Operations GmbH & Co. KG® O23 - Service: (MBAMScheduler) . (.Malwarebytes - Malwarebytes Anti-Malware.) - C:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe =>.Malwarebytes Corporation® O23 - Service: (MBAMService) . (.Malwarebytes - Malwarebytes Anti-Malware.) - C:\Programme\Malwarebytes Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation® ---\\ Allgemeinzustand der Dienste nicht Microsoft (SR=Running, SS=Stopped) (12) - 32s SS - Demand [26/05/2016] [ 269504] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINXP\system32\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated® SR - Auto [04/04/2016] [ 1056024] Avira FireWall (AntiVirFirewallService) . (.Avira Operations GmbH & Co. KG.) - C:\Programme\Avira\AntiVir Desktop\avfwsvc.exe =>.Avira Operations GmbH & Co. KG® SR - Auto [04/04/2016] [ 866992] Avira Mail Protection (AntiVirMailService) . (.Avira Operations GmbH & Co. KG.) - C:\Programme\Avira\AntiVir Desktop\avmailc.exe =>.Avira Operations GmbH & Co. KG® SR - Auto [04/04/2016] [ 464232] Avira Scheduler (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Programme\Avira\AntiVir Desktop\sched.exe =>.Avira Operations GmbH & Co. KG® SR - Auto [04/04/2016] [ 464232] Avira Real-Time Protection (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Programme\Avira\AntiVir Desktop\avguard.exe =>.Avira Operations GmbH & Co. KG® SR - Auto [04/04/2016] [ 1044744] Avira Web Protection (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe =>.Avira Operations GmbH & Co. KG® SR - Auto [25/02/2009] [ 602112] (Ati HotKey Poller) . (.ATI Technologies Inc..) - C:\WINXP\system32\ati2evxx.exe =>.ATI Technologies Inc. SS - Auto [30/03/2016] [ 272304] Avira Service Host (Avira.ServiceHost) . (.Avira Operations GmbH & Co. KG.) - C:\Programme\Avira\Launcher\Avira.ServiceHost.exe =>.Avira Operations GmbH & Co. KG® SR - Auto [05/10/2015] [ 1513784] (MBAMScheduler) . (.Malwarebytes.) - C:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe =>.Malwarebytes Corporation® SR - Auto [05/10/2015] [ 1135416] (MBAMService) . (.Malwarebytes.) - C:\Programme\Malwarebytes Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation® SS - Demand [03/05/2016] [ 146888] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation® ---\\ Im Automatikbetrieb geplanten Tasks (10) - 4s [MD5.00000000000000000000000000000000] [APT] [Adobe Flash Player Updater] (...) -- Adobe Systems Incorporated (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.00000000000000000000000000000000] [APT] [Driver Booster Scan] (...) -- Bei Anmeldung des Benutzers starten (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.00000000000000000000000000000000] [APT] [Driver Booster Update] (...) -- Bei Anmeldung des Benutzers starten (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.00000000000000000000000000000000] [APT] [DriverMaxAgent] (...) -- C:\Programme\Innovative Solutions\DriverMax\drivermax.exe (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.00000000000000000000000000000000] [APT] [UninstallMonitor] (...) -- Bei Anmeldung des Benutzers starten (.not file.) [0] (.Activate.) =>.Superfluous.Empty O39 - APT: Adobe Flash Player Updater - (...) -- C:\WINXP\Tasks\Adobe Flash Player Updater.job [880] (.Orphean.) =>.Superfluous.Orphean O39 - APT: Driver Booster Scan - (...) -- C:\WINXP\Tasks\Driver Booster Scan.job [258] (.Orphean.) =>.Superfluous.Orphean O39 - APT: Driver Booster Update - (...) -- C:\WINXP\Tasks\Driver Booster Update.job [260] (.Orphean.) =>.Superfluous.Orphean O39 - APT: DriverMaxAgent - (...) -- C:\WINXP\Tasks\DriverMaxAgent.job [280] (.Orphean.) =>.Superfluous.Orphean O39 - APT: UninstallMonitor - (...) -- C:\WINXP\Tasks\UninstallMonitor.job [316] (.Orphean.) =>.Superfluous.Orphean ---\\ Prozess läuft (16) - 3s [MD5.2A27A3A8634FB9E29F539D6D3ED3646A] - (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) -- C:\WINXP\system32\ati2evxx.exe [602112] [PID.1200] =>.ATI Technologies Inc. [MD5.2A27A3A8634FB9E29F539D6D3ED3646A] - (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) -- C:\WINXP\system32\ati2evxx.exe [602112] [PID.1636] =>.ATI Technologies Inc. [MD5.154A39E54E5216F64360FD8D21431184] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Programme\Avira\AntiVir Desktop\sched.exe [464232] [PID.1736] =>.Avira Operations GmbH & Co. KG® [MD5.618833D3E131505CEDDCE1E21EDC4CD2] - (.Avira Operations GmbH & Co. KG - Firewall NT service process.) -- C:\Programme\Avira\AntiVir Desktop\avfwsvc.exe [1056024] [PID.436] =>.Avira Operations GmbH & Co. KG® [MD5.245B4DC101845BE6E4DE5880C448CBC9] - (.Avira Operations GmbH & Co. KG - Avira Launcher.) -- C:\Programme\Avira\Launcher\Avira.Systray.exe [148168] [PID.484] =>.Avira Operations GmbH & Co. KG® [MD5.7C41C286C691B9EB3B756609F0F385A6] - (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe [773848] [PID.496] =>.Avira Operations GmbH & Co. KG® [MD5.AB176B9E59C0435499D83047D84EDD59] - (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784] [PID.768] =>.Malwarebytes Corporation® [MD5.40C126CB15FAB7D6C66490DCA9C1AED2] - (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Programme\Malwarebytes Anti-Malware\mbamservice.exe [1135416] [PID.1244] =>.Malwarebytes Corporation® [MD5.BABBBDEF9DBB5E012EE5210FCB47C33B] - (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Programme\Malwarebytes Anti-Malware\mbam.exe [9832760] [PID.2144] =>.Malwarebytes Corporation® [MD5.154A39E54E5216F64360FD8D21431184] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe [464232] [PID.3192] =>.Avira Operations GmbH & Co. KG® [MD5.23965FC5E3FE643A78BAC1F4F7419A1A] - (.Avira Operations GmbH & Co. KG - AntiVir shadow copy service.) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe [457096] [PID.3516] =>.Avira Operations GmbH & Co. KG® [MD5.B621B0CE40612E005648FA8584209BA4] - (.Avira Operations GmbH & Co. KG - AntiVir WebGuard Service.) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe [1044744] [PID.1316] =>.Avira Operations GmbH & Co. KG® [MD5.3962EFC7AB7882238344CA8F6B86BDCC] - (.Avira Operations GmbH & Co. KG - Antivirus MailScanner LSP Service.) -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe [866992] [PID.552] =>.Avira Operations GmbH & Co. KG® [MD5.7DF8845A1CF92C227E81DBBC6F6434DF] - (.Mozilla Corporation - Firefox.) -- C:\Programme\Mozilla Firefox\firefox.exe [392136] [PID.2636] =>.Mozilla Corporation® [MD5.2F7F595945B6F2E23D1B1423AF8C5186] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Programme\Mozilla Firefox\plugin-container.exe [276936] [PID.252] =>.Mozilla Corporation® [MD5.95DAE48CF9EB22F0A1C6FD196C75654B] - (.Nicolas Coolman - ZHPDiag.) -- C:\Dokumente und Einstellungen\Mus\Eigene Dateien\Downloads\ZHPDiag3.exe [2210304] [PID.1660] =>.Nicolas Coolman ---\\ Mozilla Firefox, Plugins,Startseite,Seiten of search,Ausdehnung (3) - 1s M0 - MFSP: prefs.js [Mus - msg7cs86.default] http://www.google.de/ P2 - EXT: (...) -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\Mozilla\Extensions\home2@tomtom.com => P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\WINXP\system32\Macromed\Flash\NPSWF32_21_0_0_242.dll =>.Adobe Systems Incorporated ---\\ Internet Explorer, Startseite,Seiten of search,Ausdehnung (10) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer ---\\ Internet Explorer, Proxy Management (5) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 ---\\ Line Analysis - IniFiles, Auto Laden von Programmen (3) - 1s F2 - REG:system.ini: UserInit=C:\WINXP\System32\Userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\WINXP\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl" ---\\ Hosts Datei-Umleitung (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (22) ---\\ Browser Helper-Objekte (1) - 0s O2 - BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} . (.IObit - Uninstall for explorer.) -- C:\Programme\IObit\IObit Uninstaller\UninstallExplorer.dll =>.IObit Information Technology® ---\\ Auto Laden von Programmen vom Register und Ordner (9) - 0s O4 - HKLM\..\Run: [Avira SystrayStartTrigger] . (.Avira Operations GmbH & Co. KG - Avira Launcher.) -- C:\Programme\Avira\Launcher\Avira.SystrayStartTrigger.exe =>.Avira Operations GmbH & Co. KG® O4 - HKLM\..\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe =>.Avira Operations GmbH & Co. KG® O4 - HKLM\..\Run: [DWQueuedReporting] . (.Microsoft Corporation - Watson Subscriber for SENS Network Notifica.) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\DW\DWTRIG20.EXE =>.Microsoft Corporation® O4 - HKCU\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINXP\system32\ctfmon.exe =>.Microsoft Corporation O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINXP\system32\ctfmon.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINXP\system32\ctfmon.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINXP\system32\ctfmon.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINXP\system32\ctfmon.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-329068152-515967899-1606980848-1003\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINXP\system32\ctfmon.exe =>.Microsoft Corporation ---\\ Globale Tastenkombinationen Start (29) - 8s O4 - GS\Desktop [Administrator]: Paltalk Messenger.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Administrator]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Programme\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\Quicklaunch [Administrator]: Paltalk Messenger.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Startup [Administrator]: PalTalk.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Desktop [Gast]: Paltalk Messenger.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Desktop [Gast]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Gast]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Programme\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\Quicklaunch [Gast]: Paltalk Messenger.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Startup [Gast]: PalTalk.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Desktop [Hilfeassistent]: Paltalk Messenger.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Desktop [Hilfeassistent]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Hilfeassistent]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Programme\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\Quicklaunch [Hilfeassistent]: Paltalk Messenger.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Startup [Hilfeassistent]: PalTalk.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Desktop [Mus]: Paltalk Messenger.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Desktop [Mus]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Mus]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Programme\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\Quicklaunch [Mus]: Paltalk Messenger.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Startup [Mus]: PalTalk.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Desktop [SUPPORT_388945a0]: Paltalk Messenger.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Desktop [SUPPORT_388945a0]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [SUPPORT_388945a0]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Programme\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\Quicklaunch [SUPPORT_388945a0]: Paltalk Messenger.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\Startup [SUPPORT_388945a0]: PalTalk.lnk . (.AVM Software Inc. - Paltalk Messenger.) C:\Programme\Paltalk Messenger\paltalk.exe {17B0C425187E4534E12B02B218563F46} =>.AVM Software Inc. O4 - GS\CommonDesktop [Public]: Avira Control Center.lnk . (.Avira Operations GmbH & Co. KG - Control Center.) C:\Programme\Avira\AntiVir Desktop\avcenter.exe =>.Avira Operations GmbH & Co. KG® O4 - GS\CommonDesktop [Public]: Avira Launcher.lnk . (.Avira Operations GmbH & Co. KG - Avira Launcher.) C:\Programme\Avira\Launcher\Avira.Systray.exe =>.Avira Operations GmbH & Co. KG® O4 - GS\CommonDesktop [Public]: Malwarebytes Anti-Malware.lnk . (.Malwarebytes - Malwarebytes Anti-Malware.) C:\Programme\Malwarebytes Anti-Malware\mbam.exe =>.Malwarebytes Corporation® O4 - GS\CommonDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Programme\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® ---\\ Lop.com/Domain Entführer (4) - 1s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = fritz.box O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{B086BC80-BC11-4727-B3C7-DBC9A6A32CAD}: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{B086BC80-BC11-4727-B3C7-DBC9A6A32CAD}: DhcpDomain = fritz.box ---\\ Zusätzliche Protokolle (27) - 3s O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINXP\system32\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINXP\system32\urlmon.dll =>.Microsoft Corporation O18 - Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} . (.Microsoft Corporation - Microsoft SharePoint Portal Server Object M.) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\PKMCDO.DLL =>.Microsoft Corporation O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX-Steuerung für Streamingvideo.) -- C:\WINXP\system32\msvidctl.dll =>.Microsoft Corporation O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINXP\system32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINXP\system32\urlmon.dll =>.Microsoft Corporation O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINXP\system32\urlmon.dll =>.Microsoft Corporation O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINXP\system32\urlmon.dll =>.Microsoft Corporation O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINXP\system32\urlmon.dll =>.Microsoft Corporation O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINXP\system32\itss.dll =>.Microsoft Corporation O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINXP\system32\mshtml.dll =>.Microsoft Corporation O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINXP\system32\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINXP\system32\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API.) -- C:\WINXP\system32\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINXP\system32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINXP\system32\itss.dll =>.Microsoft Corporation O18 - Handler: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} . (.Microsoft Corporation - Microsoft Office XP Web Components.) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL =>.Microsoft Corporation® O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINXP\system32\mshtml.dll =>.Microsoft Corporation O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX-Steuerung für Streamingvideo.) -- C:\WINXP\system32\msvidctl.dll =>.Microsoft Corporation O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINXP\system32\mshtml.dll =>.Microsoft Corporation O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINXP\system32\wiascr.dll =>.Microsoft Corporation O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINXP\system32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINXP\system32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINXP\system32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINXP\system32\urlmon.dll =>.Microsoft Corporation O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINXP\system32\urlmon.dll =>.Microsoft Corporation O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - Allgemeine Windows-Shell-DLL.) -- C:\WINXP\system32\shell32.dll =>.Microsoft Corporation ---\\ Installierte Software (35) - 17s O42 - Logiciel: 7-Zip 16.01 - (.Igor Pavlov.) [HKLM] -- 7-Zip =>.Igor Pavlov O42 - Logiciel: Adobe Flash Player 21 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Flash Player 21 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated® O42 - Logiciel: ATI Display Driver - (...) [HKLM] -- ATI Display Driver O42 - Logiciel: Avira Internet Security v14.0.17.192 - (.Avira Operations GmbH & Co. KG.) [HKLM] -- Avira AntiVir Desktop =>.Avira Operations GmbH & Co. KG® O42 - Logiciel: Avira Launcher v1.1.58.35540 - (.Avira Operations GmbH & Co. KG.) [HKLM] -- {34CE35A5-BC22-4045-9F05-6C411D3A74DB} =>.Avira Operations GmbH & Co. KG O42 - Logiciel: Avira Launcher v1.1.58.35540 - (.Avira Operations GmbH & Co. KG.) [HKLM] -- {74d1ef14-dd39-4749-b051-e183a1e27f5e} =>.Avira Operations GmbH & Co. KG® O42 - Logiciel: Broadcom 440x 10/100 Integrated Controller - (.Broadcom Corporation.) [HKLM] -- {612B9183-67A9-4B44-9877-2F059E35B86A} =>.Broadcom Corporation O42 - Logiciel: Conexant HDA D110 MDC V.92 Modem - (...) [HKLM] -- CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3 O42 - Logiciel: Dell System Detect - (.Dell.) [HKCU] -- 58d94f3ce2c27db0 =>.Dell O42 - Logiciel: Driver Booster 2.4 - (.IObit.) [HKLM] -- Driver Booster_is1 =>.IObit Information Technology® O42 - Logiciel: High Definition Audio Driver Package - KB835221 - (.Microsoft Corporation.) [HKLM] -- KB835221WXP =>.Microsoft Corporation O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5 =>.Microsoft Corporation O42 - Logiciel: IObit Uninstaller - (.IObit.) [HKLM] -- IObitUninstall =>.IObit Information Technology® O42 - Logiciel: Malwarebytes Anti-Malware Version 2.2.0.1024 - (.Malwarebytes.) [HKLM] -- Malwarebytes Anti-Malware_is1 =>.Malwarebytes O42 - Logiciel: Mozilla Firefox 46.0.1 (x86 de) - (.Mozilla.) [HKLM] -- Mozilla Firefox 46.0.1 (x86 de) =>.Mozilla Corporation® O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService =>.Mozilla O42 - Logiciel: Paltalk Messenger 11.7 - (.AVM Software Inc..) [HKLM] -- Paltalk Messenger =>.AVM Software Inc. O42 - Logiciel: REALTEK GbE & FE Ethernet PCI NIC Driver - (.Realtek.) [HKLM] -- {ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730} =>.Macrovision Corporation® O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp. O42 - Logiciel: Sicherheitsupdate für Windows Media Player 11 (KB954154) - (.Microsoft Corporation.) [HKLM] -- KB954154_WM11 =>.Microsoft Corporation O42 - Logiciel: Sicherheitsupdate für Windows XP (KB923561) - (.Microsoft Corporation.) [HKLM] -- KB923561 =>.Microsoft Corporation O42 - Logiciel: Sicherheitsupdate für Windows XP (KB923789) - (.Microsoft Corporation.) [HKLM] -- KB923789 =>.Microsoft Corporation O42 - Logiciel: Sicherheitsupdate für Windows XP (KB941569) - (.Microsoft Corporation.) [HKLM] -- KB941569 =>.Microsoft Corporation O42 - Logiciel: Sicherheitsupdate für Windows XP (KB973346) - (.Microsoft Corporation.) [HKLM] -- KB973346 =>.Microsoft Corporation O42 - Logiciel: Sicherheitsupdate für Windows XP (KB973525) - (.Microsoft Corporation.) [HKLM] -- KB973525 =>.Microsoft Corporation O42 - Logiciel: Sicherheitsupdate für Windows XP (KB978262) - (.Microsoft Corporation.) [HKLM] -- KB978262 =>.Microsoft Corporation O42 - Logiciel: Sicherheitsupdate für Windows XP (KB980195) - (.Microsoft Corporation.) [HKLM] -- KB980195 =>.Microsoft Corporation O42 - Logiciel: Update für Microsoft Windows (KB971513) - (.Microsoft Corporation.) [HKLM] -- KB971513 =>.Microsoft Corporation O42 - Logiciel: Update für Windows XP (KB2467659) - (.Microsoft Corporation.) [HKLM] -- KB2467659 =>.Microsoft Corporation O42 - Logiciel: Update für Windows XP (KB898461) - (.Microsoft Corporation.) [HKLM] -- KB898461 =>.Microsoft Corporation O42 - Logiciel: Update für Windows XP (KB943729) - (.Microsoft Corporation.) [HKLM] -- KB943729 =>.Microsoft Corporation O42 - Logiciel: WebFldrs XP - (.Microsoft Corporation.) [HKLM] -- {350C97B3-3D7C-4EE8-BAA9-00BCB3D54227} =>.Microsoft Corporation O42 - Logiciel: Windows-Treiberpaket - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04 - (.Ricoh Company.) [HKLM] -- 4569969E1360D2854474C661EF9B4D54F143EB16 =>.Microsoft Windows Component Publisher® O42 - Logiciel: WinRAR 5.30 beta 4 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver =>.win.rar GmbH® ---\\ HKCU & HKLM Software Keys (59) - 17s HKLM\SOFTWARE\7-Zip HKLM\SOFTWARE\ATI Technologies HKLM\SOFTWARE\Avira HKLM\SOFTWARE\C07ft5Y HKLM\SOFTWARE\Conexant HKLM\SOFTWARE\CXT HKLM\SOFTWARE\drpsu HKLM\SOFTWARE\Gemplus HKLM\SOFTWARE\Google HKLM\SOFTWARE\IDT HKLM\SOFTWARE\Innovative Solutions HKLM\SOFTWARE\InstalledOptions HKLM\SOFTWARE\Intel HKLM\SOFTWARE\IObit HKLM\SOFTWARE\Licenses HKLM\SOFTWARE\Macromedia HKLM\SOFTWARE\Malwarebytes' Anti-Malware HKLM\SOFTWARE\Mozilla HKLM\SOFTWARE\mozilla.org HKLM\SOFTWARE\MozillaPlugins HKLM\SOFTWARE\Nico Mak Computing HKLM\SOFTWARE\ODBC HKLM\SOFTWARE\PC-Doctor HKLM\SOFTWARE\PowerArchiverInt HKLM\SOFTWARE\Program Groups HKLM\SOFTWARE\Realtek HKLM\SOFTWARE\Realtek Semiconductor Corp. HKLM\SOFTWARE\RegisteredApplications HKLM\SOFTWARE\RTLSetup HKLM\SOFTWARE\Schlumberger HKLM\SOFTWARE\Secure HKLM\SOFTWARE\Sigmatel HKLM\SOFTWARE\Windows 3.1 Migration Status HKLM\SOFTWARE\WinRAR HKLM\SOFTWARE\X-AVCSD HKCU\SOFTWARE\7-Zip HKCU\SOFTWARE\ATI Technologies Inc. HKCU\SOFTWARE\Avance HKCU\SOFTWARE\Avira HKCU\SOFTWARE\ConeXware HKCU\SOFTWARE\Dell HKCU\SOFTWARE\drpsu HKCU\SOFTWARE\Embarcadero HKCU\SOFTWARE\eSupport.com =>PUP.Optional.eSupport HKCU\SOFTWARE\Fighters HKCU\SOFTWARE\Innovative Solutions HKCU\SOFTWARE\Intel HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\OCS HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\Paltalk HKCU\SOFTWARE\pth264 HKCU\SOFTWARE\Realtek HKCU\SOFTWARE\Smart PC Solutions =>PUP.Optional.SmartPCSolutions HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\ZebHelpProcess Helper ---\\ Inhalt der Ordner Programme (113) - 24s O43 - CFD: 25/05/2016 - [] D -- C:\Program Files\Common Files O43 - CFD: 24/05/2016 - [] D -- C:\Programme\7-Zip O43 - CFD: 27/05/2016 - [] D -- C:\Programme\Avira =>.Avira Operations GmbH & Co. KG® O43 - CFD: 25/05/2016 - [] D -- C:\Programme\Broadcom O43 - CFD: 07/04/2016 - [0] D -- C:\Programme\ComPlus Applications O43 - CFD: 25/05/2016 - [] D -- C:\Programme\CONEXANT O43 - CFD: 04/05/2016 - [] D -- C:\Programme\DIFX =>.Microsoft Windows Component Publisher® O43 - CFD: 25/05/2016 - [] D -- C:\Programme\DriverPack Notifier O43 - CFD: 15/04/2016 - [] D -- C:\Programme\DriverUpdaterPro =>.Superfluous.DriverUpdaterPro O43 - CFD: 27/05/2016 - [] D -- C:\Programme\Gemeinsame Dateien {37A799906FD13740B61497ADBB88F792} O43 - CFD: 25/05/2016 - [] D -- C:\Programme\IDT O43 - CFD: 27/05/2016 - [0] D -- C:\Programme\Innovative Solutions O43 - CFD: 25/05/2016 - [] HD -- C:\Programme\InstallShield Installation Information =>.Macrovision Corporation® O43 - CFD: 04/05/2016 - [] D -- C:\Programme\Intel O43 - CFD: 23/05/2016 - [] D -- C:\Programme\Internet Explorer O43 - CFD: 27/05/2016 - [] D -- C:\Programme\IObit =>.IObit Information Technology® O43 - CFD: 24/05/2016 - [] D -- C:\Programme\iolo O43 - CFD: 27/05/2016 - [] D -- C:\Programme\Malwarebytes Anti-Malware =>.Malwarebytes Corporation® O43 - CFD: 07/04/2016 - [] D -- C:\Programme\Messenger O43 - CFD: 07/04/2016 - [] D -- C:\Programme\microsoft frontpage O43 - CFD: 22/05/2016 - [] D -- C:\Programme\Microsoft Office =>.Microsoft Corporation® O43 - CFD: 04/05/2016 - [] D -- C:\Programme\Microsoft.NET O43 - CFD: 07/04/2016 - [] D -- C:\Programme\Movie Maker O43 - CFD: 03/05/2016 - [] D -- C:\Programme\Mozilla Firefox =>.Mozilla Corporation® O43 - CFD: 03/05/2016 - [] D -- C:\Programme\Mozilla Maintenance Service =>.Mozilla Corporation® O43 - CFD: 23/05/2016 - [] D -- C:\Programme\MSBuild O43 - CFD: 07/04/2016 - [] D -- C:\Programme\MSN O43 - CFD: 07/04/2016 - [] D -- C:\Programme\MSN Gaming Zone O43 - CFD: 07/04/2016 - [] D -- C:\Programme\NetMeeting O43 - CFD: 07/04/2016 - [] D -- C:\Programme\Online Services O43 - CFD: 10/04/2016 - [0] D -- C:\Programme\Online-Dienste O43 - CFD: 07/04/2016 - [] D -- C:\Programme\Outlook Express O43 - CFD: 22/05/2016 - [] D -- C:\Programme\Paltalk Messenger {17B0C425187E4534E12B02B218563F46} O43 - CFD: 24/05/2016 - [] D -- C:\Programme\Realtek =>.Realtek Semiconductor Corp® O43 - CFD: 23/05/2016 - [] D -- C:\Programme\Reference Assemblies O43 - CFD: 26/05/2016 - [] D -- C:\Programme\Sigmatel O43 - CFD: 22/05/2016 - [0] D -- C:\Programme\Simple Driver Updater O43 - CFD: 15/04/2016 - [] D -- C:\Programme\Support Tools O43 - CFD: 07/04/2016 - [0] HD -- C:\Programme\Uninstall Information O43 - CFD: 15/04/2016 - [] D -- C:\Programme\USB Disk Security O43 - CFD: 07/04/2016 - [] D -- C:\Programme\Windows Media Connect 2 O43 - CFD: 07/04/2016 - [] D -- C:\Programme\Windows Media Player O43 - CFD: 07/04/2016 - [] D -- C:\Programme\Windows NT O43 - CFD: 07/04/2016 - [0] HD -- C:\Programme\WindowsUpdate O43 - CFD: 25/05/2016 - [] D -- C:\Programme\WinRAR =>.win.rar GmbH® O43 - CFD: 07/04/2016 - [] D -- C:\Programme\xerox O43 - CFD: 24/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\7-Zip O43 - CFD: 22/05/2016 - [] RD -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart O43 - CFD: 27/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Avira O43 - CFD: 27/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes Anti-Malware O43 - CFD: 22/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Outils Microsoft Office O43 - CFD: 04/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Realtek O43 - CFD: 07/04/2016 - [] RD -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Spiele O43 - CFD: 15/04/2016 - [] RD -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Verwaltung O43 - CFD: 25/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\WinRAR O43 - CFD: 07/04/2016 - [] RD -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Zubehör O43 - CFD: 27/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira O43 - CFD: 22/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Caphyon O43 - CFD: 25/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Fighters O43 - CFD: 26/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Innovative Solutions O43 - CFD: 25/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\IObit O43 - CFD: 24/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\iolo O43 - CFD: 07/04/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes O43 - CFD: 22/05/2016 - [] SD -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft O43 - CFD: 26/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Package Cache O43 - CFD: 26/05/2016 - [] D -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ProductData O43 - CFD: 03/05/2016 - [0] AD -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP O43 - CFD: 25/05/2016 - [0] D -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98} O43 - CFD: 27/05/2016 - [] D -- C:\Programme\Gemeinsame Dateien\AV O43 - CFD: 22/05/2016 - [] D -- C:\Programme\Gemeinsame Dateien\Designer O43 - CFD: 07/04/2016 - [] D -- C:\Programme\Gemeinsame Dateien\Dienste O43 - CFD: 26/05/2016 - [] D -- C:\Programme\Gemeinsame Dateien\Innovative Solutions O43 - CFD: 24/05/2016 - [] D -- C:\Programme\Gemeinsame Dateien\InstallShield O43 - CFD: 26/05/2016 - [] D -- C:\Programme\Gemeinsame Dateien\IObit O43 - CFD: 26/05/2016 - [] D -- C:\Programme\Gemeinsame Dateien\Microsoft Shared O43 - CFD: 07/04/2016 - [] D -- C:\Programme\Gemeinsame Dateien\MSSoap O43 - CFD: 07/04/2016 - [] D -- C:\Programme\Gemeinsame Dateien\ODBC O43 - CFD: 07/04/2016 - [] D -- C:\Programme\Gemeinsame Dateien\SpeechEngines O43 - CFD: 22/05/2016 - [] D -- C:\Programme\Gemeinsame Dateien\System O43 - CFD: 24/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\Adobe O43 - CFD: 27/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\Avira O43 - CFD: 25/05/2016 - [] AD -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\DriverPack Notifier O43 - CFD: 25/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\DRPNano O43 - CFD: 25/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\DRPSu O43 - CFD: 26/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\Easeware O43 - CFD: 25/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\Fighters O43 - CFD: 07/04/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\Identities O43 - CFD: 26/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\Innovative Solutions O43 - CFD: 04/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\InstallShield O43 - CFD: 27/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\IObit O43 - CFD: 24/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\Macromedia O43 - CFD: 27/05/2016 - [] SD -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\Microsoft O43 - CFD: 03/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\Mozilla O43 - CFD: 22/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\Paltalk O43 - CFD: 24/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\PCDr O43 - CFD: 25/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\ProductData O43 - CFD: 23/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\TomTom O43 - CFD: 24/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\WinRAR O43 - CFD: 27/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Anwendungsdaten\ZHP O43 - CFD: 24/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Anwendungsdaten\Adobe O43 - CFD: 25/05/2016 - [0] D -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Anwendungsdaten\Deployment O43 - CFD: 23/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Anwendungsdaten\Downloaded Installations O43 - CFD: 24/05/2016 - [0] D -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Anwendungsdaten\eSupport.com =>PUP.Optional.eSupport O43 - CFD: 26/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Anwendungsdaten\Innovative Solutions O43 - CFD: 07/04/2016 - [] SD -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Anwendungsdaten\Microsoft O43 - CFD: 03/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Anwendungsdaten\Mozilla O43 - CFD: 24/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Anwendungsdaten\PCHealth O43 - CFD: 23/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Anwendungsdaten\TomTom O43 - CFD: 22/05/2016 - [] RD -- C:\Dokumente und Einstellungen\Mus\Startmenü\Programme\Autostart O43 - CFD: 24/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Startmenü\Programme\Dell O43 - CFD: 22/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Startmenü\Programme\Paltalk Messenger O43 - CFD: 25/05/2016 - [] D -- C:\Dokumente und Einstellungen\Mus\Startmenü\Programme\WinRAR O43 - CFD: 07/04/2016 - [] RD -- C:\Dokumente und Einstellungen\Mus\Startmenü\Programme\Zubehör ---\\ ShellIconOverlayIdentifiers (SIOI) (1) - 0s O106 - SIOI: Offline Files Menu [Offline Files] - {750fdf0e-2a26-11d1-a3ea-080036587f03}. (.Microsoft Corporation - Clientseitige Cachebenutzeroberfläche.) -- C:\WINXP\system32\cscui.dll =>.Microsoft Corporation ---\\ Liste der Treiber des Systems (57) - 22s O58 - SDL:2009/02/25 22:58:57 A . (.ATI Technologies Inc. - ATI Radeon WindowsNT Miniport Driver.) -- C:\WINXP\System32\drivers\ati2mtag.sys [3565568] =>.ATI Technologies Inc. O58 - SDL:2016/04/04 16:40:35 A . (.Avira GmbH - Packet filtering kernel driver ( NDIS IM ).) -- C:\WINXP\System32\drivers\avfwim.sys [92448] =>.Avira Operations GmbH & Co. KG® O58 - SDL:2016/04/04 16:40:35 A . (.Avira GmbH - TDI filtering kernel driver.) -- C:\WINXP\System32\drivers\avfwot.sys [113024] =>.Avira Operations GmbH & Co. KG® O58 - SDL:2016/04/04 16:40:35 A . (.Avira Operations GmbH & Co. KG - Avira Minifilter Driver.) -- C:\WINXP\System32\drivers\avgntflt.sys [109016] =>.Avira Operations GmbH & Co. KG® O58 - SDL:2016/04/04 16:40:35 A . (.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) -- C:\WINXP\System32\drivers\avipbb.sys [137240] =>.Avira Operations GmbH & Co. KG® O58 - SDL:2016/04/04 16:40:35 A . (.Avira Operations GmbH & Co. KG - Avira Manager Driver.) -- C:\WINXP\System32\drivers\avkmgr.sys [37352] =>.Avira Operations GmbH & Co. KG® O58 - SDL:2006/11/21 04:25:44 RA . (.Broadcom Corporation - Broadcom Corporation NDIS 5.1 ethernet driv.) -- C:\WINXP\System32\drivers\bcm4sbxp.sys [45568] =>.Broadcom Corporation O58 - SDL:2016/05/26 21:38:42 A . (.Broadcom Corporation - Broadcom 802.11 Network Adapter wireless dr.) -- C:\WINXP\System32\drivers\BCMWL5.SYS [3369984] =>.Broadcom Corporation O58 - SDL:2016/05/26 21:38:25 A . (.Broadcom Corporation. - Broadcom Bluetooth IT Manager Filter.) -- C:\WINXP\System32\drivers\btwsecfl.sys [92792] =>.Broadcom Corporation® O58 - SDL:2016/05/26 21:38:25 A . (.Broadcom Corporation. - Driver for Bluetooth USB Devices.) -- C:\WINXP\System32\drivers\btwusb.sys [52984] =>.Broadcom Corporation® O58 - SDL:2011/03/08 21:52:47 A . (.RAVISENT Technologies Inc. - CineMaster C 1.2 WDM-Haupttreiber.) -- C:\WINXP\System32\drivers\cinemst2.sys [262528] =>.RAVISENT Technologies Inc. O58 - SDL:2011/03/08 21:52:47 A . (.Compaq Computer Corporation - Compaq PA-1 Player Driver.) -- C:\WINXP\System32\drivers\cpqdap01.sys [11776] =>.Compaq Computer Corporation O58 - SDL:2008/04/14 08:00:00 A . (.Microsoft Corp., Veritas Software - Treiber für NT Datenträgerverwaltung.) -- C:\WINXP\System32\drivers\dmboot.sys [800384] =>.Microsoft Corp., Veritas Software O58 - SDL:2008/04/14 08:00:00 A . (.Microsoft Corp., Veritas Software - E/A-Treiber für NT Datenträgerverwaltung.) -- C:\WINXP\System32\drivers\dmio.sys [154112] =>.Microsoft Corp., Veritas Software O58 - SDL:2008/04/14 08:00:00 A . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINXP\System32\drivers\dmload.sys [5888] =>.Microsoft Corp., Veritas Software. O58 - SDL:2016/05/24 15:07:52 A . (.Phoenix Technologies - DriverAgent Direct I/O for 32-bit Windows.) -- C:\WINXP\System32\drivers\DrvAgent32.sys [31832] =>PUP.Optional.eSupport O58 - SDL:2016/05/25 22:08:07 A . (...) -- C:\WINXP\System32\drivers\EsgScanner.sys [19984] =>.Enigma Software Group USA, LLC® O58 - SDL:2008/04/14 08:00:00 A . (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) -- C:\WINXP\System32\drivers\hdaudbus.sys [144384] O58 - SDL:2004/08/12 17:45:52 N . (.Windows (R) Server 2003 DDK provider - High Definition Audio Function Driver v1.0.) -- C:\WINXP\System32\drivers\Hdaudio.sys [113664] O58 - SDL:2005/12/01 01:40:12 A . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- C:\WINXP\System32\drivers\HSXHWAZL.sys [192512] =>.Conexant Systems, Inc. O58 - SDL:2005/12/01 01:40:08 A . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\WINXP\System32\drivers\HSX_CNXT.sys [669696] =>.Conexant Systems, Inc. O58 - SDL:2005/12/01 01:40:56 A . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\WINXP\System32\drivers\HSX_DPV.sys [936960] =>.Conexant Systems, Inc. O58 - SDL:2016/05/25 23:05:14 A . (.REALiX(tm) - HWiNFO x86 Kernel Driver.) -- C:\WINXP\System32\drivers\HWiNFO32.SYS [23840] =>.Martin Malik - REALiX® O58 - SDL:2015/10/05 09:50:04 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\WINXP\System32\drivers\mbam.sys [23256] =>.Malwarebytes Corporation® O58 - SDL:2015/10/05 09:50:10 A . (.Malwarebytes - Malwarebytes Chameleon Protection Driver.) -- C:\WINXP\System32\drivers\mbamchameleon.sys [121560] =>.Malwarebytes Corporation® O58 - SDL:2016/05/27 18:42:53 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\WINXP\System32\drivers\MBAMSwissArmy.sys [170200] =>.Malwarebytes Corporation® O58 - SDL:2005/10/04 23:57:08 A . (.Conexant - Diagnostic Interface DRIVER.) -- C:\WINXP\System32\drivers\mdmxsdk.sys [12544] =>.Conexant O58 - SDL:2011/03/08 21:52:47 A . (.S3/Diamond Multimedia Systems - NikeDrv Usb Driver.) -- C:\WINXP\System32\drivers\nikedrv.sys [12032] =>.S3/Diamond Multimedia Systems O58 - SDL:2008/04/14 08:00:00 A . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Lib.) -- C:\WINXP\System32\drivers\ptilink.sys [17792] =>.Parallel Technologies, Inc. O58 - SDL:2016/05/26 21:39:08 A . (.REDC - RICOH SD/MMC Driver.) -- C:\WINXP\System32\drivers\rimmptsk.sys [48128] =>.REDC O58 - SDL:2016/05/26 21:39:08 A . (.REDC - RICOH MS Driver.) -- C:\WINXP\System32\drivers\rimsptsk.sys [44544] =>.REDC O58 - SDL:2011/03/08 21:52:47 A . (.S3/Diamond Multimedia Systems - Rio8Drv.sys Usb Driver.) -- C:\WINXP\System32\drivers\rio8drv.sys [12032] =>.S3/Diamond Multimedia Systems O58 - SDL:2011/03/08 21:52:47 A . (.S3/Diamond Multimedia Systems - RioDrv Usb Driver.) -- C:\WINXP\System32\drivers\riodrv.sys [12032] =>.S3/Diamond Multimedia Systems O58 - SDL:2016/05/26 21:39:38 A . (.REDC - RICOH SD/MMC Driver.) -- C:\WINXP\System32\drivers\risdptsk.sys [46592] =>.REDC O58 - SDL:2016/05/26 21:39:08 A . (.REDC - RICOH XD SM Driver.) -- C:\WINXP\System32\drivers\rixdptsk.sys [38400] =>.REDC O58 - SDL:2012/10/25 08:47:54 RA . (.Realtek Semiconductor Corporation - Realtek RTL8192C USB NDIS Driver.) -- C:\WINXP\System32\drivers\RTL8192cu.sys [1076968] =>.Realtek Semiconductor Corp® O58 - SDL:2015/02/16 16:19:16 A . (.Realtek Semiconductor Corporation - Realtek WLAN USB NDIS Driver 34616.) -- C:\WINXP\System32\drivers\rtwlanu_XP.sys [2664024] =>.Realtek Semiconductor Corp® O58 - SDL:2008/04/14 08:00:00 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\WINXP\System32\drivers\secdrv.sys [20480] =>.Macrovision Corporation, Macrovision Europe Limited, O58 - SDL:2016/04/04 16:40:40 A . (.Avira Operations GmbH & Co. KG - AVIRA SnapShot Driver.) -- C:\WINXP\System32\drivers\ssmdrv.sys [27696] =>.Avira Operations GmbH & Co. KG® O58 - SDL:2009/01/05 15:59:10 A . (.IDT, Inc. - IDT PC Audio.) -- C:\WINXP\System32\drivers\sthda.sys [1229949] =>.IDT, Inc. O58 - SDL:2011/03/08 21:52:47 A . (.Toshiba Corporation - WDM Toshiba Tecra Video Capture Driver.) -- C:\WINXP\System32\drivers\tsbvcap.sys [21376] =>.Toshiba Corporation O58 - SDL:2011/03/08 21:52:47 A . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINXP\System32\drivers\vdmindvd.sys [58112] =>.RAVISENT Technologies Inc. O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\ansi.sys [9032] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\country.sys [27097] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\himem.sys [4992] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\key01.sys [42809] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\keyboard.sys [42537] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\ntdos.sys [27914] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\ntdos404.sys [29146] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\ntdos411.sys [29370] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\ntdos412.sys [29274] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\ntdos804.sys [29146] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\ntio.sys [34032] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\ntio404.sys [34560] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\ntio411.sys [35648] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\ntio412.sys [35424] O58 - SDL:2008/04/14 08:00:00 A . (...) -- C:\WINXP\System32\ntio804.sys [34560] ---\\ Neueste Dateien geändert oder erstellt (Benutzer) (14) - 75s O61 - LFC: 2016/05/24 17:27:57 A . (.Outercurve Foundation.) -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Apps\2.0\YOLCBG2Y.Z5B\YJ6HTKA3.96R\micr..sion_ce35f76fcda82bad_0003.0000_none_5e665c5026c29c9e\Microsoft.Deployment.Compression.dll [36864] O61 - LFC: 2016/05/24 17:27:55 A . (.Outercurve Foundation.) -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Apps\2.0\YOLCBG2Y.Z5B\YJ6HTKA3.96R\micr...cab_ce35f76fcda82bad_0003.0000_none_049f87db51ab7cfa\Microsoft.Deployment.Compression.Cab.dll [49152] O61 - LFC: 2016/05/24 17:27:55 A . (.Outercurve Foundation.) -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Apps\2.0\YOLCBG2Y.Z5B\YJ6HTKA3.96R\dell..tion_6d0a76327dca4869_0007.0004_041659e87a6c2b4d\Microsoft.Deployment.Compression.Cab.dll [49152] O61 - LFC: 2016/05/24 17:27:57 A . (.Outercurve Foundation.) -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Apps\2.0\YOLCBG2Y.Z5B\YJ6HTKA3.96R\dell..tion_6d0a76327dca4869_0007.0004_041659e87a6c2b4d\Microsoft.Deployment.Compression.dll [36864] O61 - LFC: 2016/05/24 17:28:17 A . (..) -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Apps\2.0\YOLCBG2Y.Z5B\YJ6HTKA3.96R\dell..tion_6d0a76327dca4869_0007.0004_041659e87a6c2b4d\uninstaller.bat [144] O61 - LFC: 2016/05/24 21:25:44 A . (..) -- C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Anwendungsdaten\Adobe\259F0F70-8792-4A42-9A4D-03B080CBD41C\gtcheck.exe [77312] O61 - LFC: 2016/05/22 19:52:14 A . (.PC Drivers HeadQuarters.) -- C:\Dokumente und Einstellungen\Mus\Eigene Dateien\Downloads\DriverDetective.exe [2002144] {4BB5B8756BAFFB81CF8C6C8EF4E61006} =>.Superfluous.PCDriversHeadQuarters O61 - LFC: 2016/05/24 18:44:55 A . (..) -- C:\Dokumente und Einstellungen\Mus\Eigene Dateien\Downloads\DriverUpdaterPro.exe [3952504] {112105E7CB168696411506CB28E984788008} =>.Superfluous.DriverUpdaterPro O61 - LFC: 2016/05/26 19:24:45 A . (.Kerish Products.) -- C:\Dokumente und Einstellungen\Mus\Eigene Dateien\Downloads\Kerish_Doctor_4.60.exe [34713800] {1D0F76AAF04C714C925B79F338122EE7} O61 - LFC: 2016/05/24 17:48:32 A . (..) -- C:\Dokumente und Einstellungen\Mus\Eigene Dateien\Downloads\motherboard_driver_audio_realtek_azalia.exe [71014966] O61 - LFC: 2016/05/22 17:36:26 A . (..) -- C:\Dokumente und Einstellungen\Mus\Eigene Dateien\Downloads\powarc160301.exe [32989312] {40DDA0C2CDBC1CAFCA0C80875CBBB9DB} O61 - LFC: 2016/05/25 20:59:52 A . (..) -- C:\Dokumente und Einstellungen\Mus\Eigene Dateien\Downloads\R114200.EXE [2428008] {7846C597000000000009} O61 - LFC: 2016/05/24 15:42:52 A . (..) -- C:\Dokumente und Einstellungen\Mus\Eigene Dateien\Downloads\R154493.EXE [4758792] {7846C597000000000009} O61 - LFC: 2016/05/24 18:19:27 A . (..) -- C:\Dokumente und Einstellungen\Mus\Eigene Dateien\Downloads\SCUDownloader.exe [18131880] ---\\ Verbände Shell Laichen (10) - 1s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Allgemeine Windows-Shell-DLL.) -- C:\WINXP\system32\shell32.dll =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Programme\Internet Explorer\IEXPLORE.EXE =>.Microsoft Corporation® O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINXP\system32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registrierungs-Editor.) -- C:\WINXP\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Programme\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® ---\\ Startmenü Internet (8) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Programme\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Programme\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Programme\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\WINXP\system32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Programme\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\WINXP\system32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Programme\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\WINXP\system32\ie4uinit.exe =>.Microsoft Corporation ---\\ Suche 'Ansteckung in Internet-Browsern (6) - 10s O69 - SBI: prefs.js [Mus - msg7cs86.default] user_pref("extensions.caa1-aDOiCAxFFMOVIX@jetpack.sdk.baseURI", "resource://caa1-adoicaxffmovix-at-jetpack/"); =>PUP.Optional.GoMovix O69 - SBI: prefs.js [Mus - msg7cs86.default] user_pref("extensions.caa1-aDOiCAxFFMOVIX@jetpack.sdk.domain", "caa1-adoicaxffmovix-at-jetpack"); =>PUP.Optional.GoMovix O69 - SBI: prefs.js [Mus - msg7cs86.default] user_pref("extensions.caa1-aDOiCAxFFMOVIX@jetpack.sdk.load.reason", "downgrade"); =>PUP.Optional.GoMovix O69 - SBI: prefs.js [Mus - msg7cs86.default] user_pref("extensions.caa1-aDOiCAxFFMOVIX@jetpack.sdk.rootURI", "jar:file:///C:/Dokumente%20und%20Einstellungen/Mus/Anwendungsdate[...] =>PUP.Optional.GoMovix O69 - SBI: prefs.js [Mus - msg7cs86.default] user_pref("extensions.caa1-aDOiCAxFFMOVIX@jetpack.sdk.version", "0.1.6"); =>PUP.Optional.GoMovix O69 - SBI: prefs.js [Mus - msg7cs86.default] user_pref("extensions.caa1-aDOiCAxFFMOVIX@jetpack.url", "resource://caa1-adoicaxffmovix-at-jetpack/data/index.html"); =>PUP.Optional.GoMovix ---\\ Liste den Dienststart von Svchost (40) - 5s O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Softwareinstallationsdienst.) -- C:\WINXP\system32\appmgmts.dll [175616] =>.Microsoft Corporation O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINXP\system32\audiosrv.dll [42496] =>.Microsoft Corporation O83 - Search Svchost Services: Browser (Browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINXP\system32\browser.dll [77824] =>.Microsoft Corporation O83 - Search Svchost Services: CryptSvc (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) -- C:\WINXP\system32\cryptsvc.dll [62464] =>.Microsoft Corporation O83 - Search Svchost Services: DMServer (DMServer) . (.Microsoft Corp. - LDM-Dienst-DLL (Logical Disk Manager).) -- C:\WINXP\system32\dmserver.dll [24064] =>.Microsoft Corp. O83 - Search Svchost Services: DHCP (DHCP) . (.Microsoft Corporation - DHCP Clientdienst.) -- C:\WINXP\system32\dhcpcsvc.dll [127488] =>.Microsoft Corporation O83 - Search Svchost Services: ERSvc (ERSvc) . (.Microsoft Corporation - Windows Error Reporting Service.) -- C:\WINXP\system32\ersvc.dll [23040] =>.Microsoft Corporation O83 - Search Svchost Services: EventSystem (EventSystem) . (.Microsoft Corporation - .) -- C:\WINXP\system32\es.dll [253952] =>.Microsoft Corporation O83 - Search Svchost Services: FastUserSwitchingCompatibility (FastUserSwitchingCompatibility) . (.Microsoft Corporation - Windows-Shelldienste-DLL.) -- C:\WINXP\system32\shsvcs.dll [135680] =>.Microsoft Corporation O83 - Search Svchost Services: HidServ (HidServ) . (...) -- C:\WINXP\System32\hidserv.dll [0] O83 - Search Svchost Services: LanmanServer (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINXP\system32\srvsvc.dll [99840] =>.Microsoft Corporation O83 - Search Svchost Services: LanmanWorkstation (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) -- C:\WINXP\system32\wkssvc.dll [134144] =>.Microsoft Corporation O83 - Search Svchost Services: Messenger (Messenger) . (.Microsoft Corporation - NT Messenger Service.) -- C:\WINXP\system32\msgsvc.dll [33792] =>.Microsoft Corporation O83 - Search Svchost Services: Netman (Netman) . (.Microsoft Corporation - Netzwerkverbindungs-Manager.) -- C:\WINXP\system32\netman.dll [198144] =>.Microsoft Corporation O83 - Search Svchost Services: Nla (Nla) . (.Microsoft Corporation - Microsoft Windows Sockets 2.0-Dienstanbiete.) -- C:\WINXP\system32\mswsock.dll [247296] =>.Microsoft Corporation O83 - Search Svchost Services: Ntmssvc (Ntmssvc) . (.Microsoft Corporation - Wechselmedien-Manager.) -- C:\WINXP\system32\ntmssvc.dll [438272] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINXP\system32\rasauto.dll [88576] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINXP\system32\rasmans.dll [186368] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINXP\system32\mprdim.dll [53248] =>.Microsoft Corporation O83 - Search Svchost Services: Schedule (Schedule) . (.Microsoft Corporation - Taskplaner-Engine.) -- C:\WINXP\system32\schedsvc.dll [193536] =>.Microsoft Corporation O83 - Search Svchost Services: Seclogon (Seclogon) . (.Microsoft Corporation - DLL für sekundären Anmeldedienst.) -- C:\WINXP\system32\seclogon.dll [18944] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINXP\system32\sens.dll [39424] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT-Hilfskomponenten.) -- C:\WINXP\system32\ipnathlp.dll [334336] =>.Microsoft Corporation O83 - Search Svchost Services: SRService (SRService) . (.Microsoft Corporation - Systemwiederherstellungsdienst.) -- C:\WINXP\system32\srsvc.dll [171520] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft(R) Windows(R) Telefonieserver.) -- C:\WINXP\system32\tapisrv.dll [249856] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows-Shelldienste-DLL.) -- C:\WINXP\system32\shsvcs.dll [135680] =>.Microsoft Corporation O83 - Search Svchost Services: TrkWks (TrkWks) . (.Microsoft Corporation - Distributed Link Tracking Client.) -- C:\WINXP\system32\trkwks.dll [90112] =>.Microsoft Corporation O83 - Search Svchost Services: W32Time (W32Time) . (.Microsoft Corporation - Windows-Zeitdienst.) -- C:\WINXP\system32\w32time.dll [177152] =>.Microsoft Corporation O83 - Search Svchost Services: WZCSVC (WZCSVC) . (.Microsoft Corporation - Konfigurationsfreier Dienst für drahtlose V.) -- C:\WINXP\system32\wzcsvc.dll [483840] =>.Microsoft Corporation O83 - Search Svchost Services: Wmi (Wmi) . (.Microsoft Corporation - Erweitertes Windows 32 Base-API.) -- C:\WINXP\system32\advapi32.dll [678400] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINXP\system32\wbem\wmisvc.dll [145408] =>.Microsoft Corporation O83 - Search Svchost Services: wscsvc (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) -- C:\WINXP\system32\wscsvc.dll [80896] =>.Microsoft Corporation O83 - Search Svchost Services: xmlprov (xmlprov) . (.Microsoft Corporation - Network Provisioning Service.) -- C:\WINXP\system32\xmlprov.dll [129024] =>.Microsoft Corporation O83 - Search Svchost Services: napagent (napagent) . (.Microsoft Corporation - Quarantäne-Agent-Dienstlaufzeit.) -- C:\WINXP\system32\qagentrt.dll [294400] =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Schlüsselverwaltungsdienst.) -- C:\WINXP\system32\kmsvc.dll [61440] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Intelligenter Hintergrundübertragungsdienst.) -- C:\WINXP\system32\qmgr.dll [409088] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update AutoUpdate Service.) -- C:\WINXP\system32\wuauserv.dll [6656] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows-Shelldienste-DLL.) -- C:\WINXP\system32\shsvcs.dll [135680] =>.Microsoft Corporation O83 - Search Svchost Services: helpsvc (helpsvc) . (.Microsoft Corporation - Microsoft PCHealth Service Holder.) -- C:\WINXP\pchealth\helpctr\binaries\pchsvc.dll [38400] =>.Microsoft Corporation O83 - Search Svchost Services: WmdmPmSN (WmdmPmSN) . (.Microsoft Corporation - Microsoft Media Device Service Provider.) -- C:\WINXP\system32\mspmsnsv.dll [27136] =>.Microsoft Corporation ---\\ Zusätzliche Scan (O88) (6) - 0s HKCU\SOFTWARE\eSupport.com =>PUP.Optional.eSupport HKCU\SOFTWARE\Smart PC Solutions =>PUP.Optional.SmartPCSolutions C:\Programme\DriverUpdaterPro =>.Superfluous.DriverUpdaterPro C:\Dokumente und Einstellungen\Mus\Lokale Einstellungen\Anwendungsdaten\eSupport.com =>PUP.Optional.eSupport C:\Dokumente und Einstellungen\Mus\Eigene Dateien\Downloads\DriverDetective.exe =>.Superfluous.PCDriversHeadQuarters C:\Dokumente und Einstellungen\Mus\Eigene Dateien\Downloads\DriverUpdaterPro.exe =>.Superfluous.DriverUpdaterPro ---\\ Zusammenfassung der Elemente gefunden auf Ihrer workstation (8) - 1s http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.eSupport http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.SmartPCSolutions http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.DriverUpdaterPro http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.PCDriversHeadQuarters http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.ReviverSoft http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.DeskToolsSoft http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.KuzyakovArtur http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.GoMovix ~ End of the scan, 10197 items in 00h08mn55s (581)(0)