This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

RUN:DLL-Error loading rvbw.nxo

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello everybody,
everytime i start my notebook i get the message
"error with loading rvbw.nxo".
i know there is a closed topic about it but that didn´t help me.

Hijack result:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:31:13, on 24.06.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\AVG\AVG9\avgchsvx.exe
C:\Programme\AVG\AVG9\avgrsx.exe
C:\Programme\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programme\idt\wdm\STacSV.exe
C:\WINDOWS\Explorer.exe
C:\Programme\LSI SoftModem\agrsmsvc.exe
C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programme\AVG\AVG9\avgwdsvc.exe
C:\Programme\Bonjour\mDNSResponder.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Programme\Java\jre6\bin\jqs.exe
C:\Programme\AVG\AVG9\avgnsx.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programme\PDF Complete\pdfsvc.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\Programme\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Programme\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe
C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe
C:\Programme\dvd43\dvd43_tray.exe
C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
C:\Programme\Brother\ControlCenter3\brccMCtl.exe
C:\Programme\Microsoft Application Virtualization Client\sftvsa.exe
C:\Programme\SweetIM\Messenger\SweetIM.exe
C:\Programme\Gemeinsame Dateien\Nokia\MPlatform\NokiaMServer.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Programme\Brother\Brmfcmon\BrMfimon.exe
C:\Programme\Microsoft Application Virtualization Client\sftlist.exe
C:\Programme\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Programme\Ares\Ares.exe
C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Programme\W3i\InstallIQUpdater\InstallIQUpdater.exe
C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programme\Windows Desktop Search\WindowsSearch.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Virtualization Handler\CVH.EXE
C:\Programme\Safari\Safari.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Programme\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programme\iPod\bin\iPodService.exe
C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Programme\Hewlett-Packard\Shared\hpqToaster.exe
Q:\140062.deu\Office14\ONENOTEM.EXE
C:\Programme\RelevantKnowledge\rlvknlg.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Dokumente und Einstellungen\Robert\Eigene Dateien\Downloads\HiJackThis204.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Programme\Family Toolbar\tbhelper.dll
F2 - REG:system.ini: Shell=Explorer.exe rundll32.exe rvbw.nxo lekymn
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Programme\Family Toolbar\tbcore3.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programme\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programme\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programme\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Loader Class - {F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} - C:\WINDOWS\BricoPacks\LeopardXP\FindeXer.dll (file missing)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programme\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Programme\Styler\TB\StylerTB.dll
O3 - Toolbar: Family Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Programme\Family Toolbar\tbcore3.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
O4 - HKLM\..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Programme\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Programme\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Software Update] c:\Programme\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [zCpqset] C:\Programme\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPCam_Menu] "c:\Programme\Hewlett-Packard\HP Webcam\MUITransfer\MUIStartMenu.exe" "c:\Programme\Hewlett-Packard\HP Webcam" UpdateWithCreateOnce "Software\CyberLink\HP Webcam\1.0"
O4 - HKLM\..\Run: [WatchDog] C:\Programme\InterVideo\DVD8SESD\DVDCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Programme\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Programme\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [dvd43] C:\Programme\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [DrvIcon] C:\Programme\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [SweetIM] C:\Programme\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [NokiaMServer] C:\Programme\Gemeinsame Dateien\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [DivXUpdate] "C:\Programme\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Programme\MyHeritage\Bin\FTBCheckUpdates.exe
O4 - HKLM\..\Run: [TrayServer] C:\Programme\MAGIX\Filme_auf_DVD_7_TerraTec_Edition\TrayServer.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RelevantKnowledge] C:\Programme\RelevantKnowledge\rlvknlg.exe -boot
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Programme\Gemeinsame Dateien\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ares] "C:\Programme\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Startup] C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\Microsoft\updaters.exe
O4 - HKCU\..\Run: [CursorXP] "C:\Program Files\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [EA Core] "C:\Programme\Electronic Arts\EA Link\Core.exe" -silent
O4 - HKCU\..\Run: [InstallIQUpdater] "C:\Programme\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Gemeinsame Dateien\Microsoft Shared\Virtualization Handler\CVH.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Gemeinsame Dateien\Microsoft Shared\Virtualization Handler\CVH.EXE (User 'Default user')
O4 - Startup: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Gemeinsame Dateien\Microsoft Shared\Virtualization Handler\CVH.EXE
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Windows Search.lnk = C:\Programme\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZRxdm784YYDE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Senden an &Bluetooth-Gerät… - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Senden an Bluetooth - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=92&bd=all&pf=cmnb
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programme\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: McAfee Application Installer Cleanup (0056061265194115) (0056061265194115mcinstcleanup) - Unknown owner - C:\DOKUME~1\Robert\LOKALE~1\Temp\005606~1.EXE (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Programme\LSI SoftModem\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Programme\AVG\AVG9\avgwdsvc.exe
O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Programme\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Programme\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Google Desktop Manager 5.9.909.30391 (GoogleDesktopManager-093009-130223) - Google - C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Programme\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programme\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Programme\PDF Complete\pdfsvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Programme\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\programme\idt\wdm\STacSV.exe

–
End of file - 17333 bytes


Please can you help me!?

RAs936
Hi,

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop. Post them back to your topic.
DDs.txt

DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 20:53:34,35 on 26.06.2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.2039.905 [GMT 2:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Programme\AVG\AVG9\avgchsvx.exe
C:\Programme\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programme\idt\wdm\STacSV.exe
C:\Programme\AVG\AVG9\avgcsrvx.exe
svchost.exe
C:\Programme\LSI SoftModem\agrsmsvc.exe
C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programme\AVG\AVG9\avgwdsvc.exe
C:\Programme\Bonjour\mDNSResponder.exe
C:\Programme\Java\jre6\bin\jqs.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programme\AVG\AVG9\avgnsx.exe
C:\Programme\PDF Complete\pdfsvc.exe
C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Programme\Microsoft Application Virtualization Client\sftvsa.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\mqsvc.exe
C:\Programme\Microsoft Application Virtualization Client\sftlist.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programme\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Programme\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\Programme\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Programme\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe
C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
C:\Programme\dvd43\dvd43_tray.exe
C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
C:\Programme\SweetIM\Messenger\SweetIM.exe
C:\Programme\Gemeinsame Dateien\Nokia\MPlatform\NokiaMServer.exe
C:\Programme\DivX\DivX Update\DivXUpdate.exe
C:\Programme\Brother\ControlCenter3\brccMCtl.exe
C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe
C:\Programme\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\W3i\InstallIQUpdater\InstallIQUpdater.exe
C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Virtualization Handler\CVH.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Programme\Hewlett-Packard\Shared\hpqToaster.exe
Q:\140062.deu\OFFICE14\OUTLOOK.EXE
C:\Programme\RelevantKnowledge\rlvknlg.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Programme\Brother\Brmfcmon\BrMfimon.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Programme\Safari\Safari.exe
C:\WINDOWS\system32\rundll32.exe
C:\Dokumente und Einstellungen\Robert\Eigene Dateien\Downloads\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://search.myheritage.com
uSearch Page =
uSearch Bar =
mStart Page = hxxp://search.myheritage.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
mSearchAssistant =
uURLSearchHooks: H - No File
uURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\programme\family toolbar\tbhelper.dll
mWinlogon: Shell=Explorer.exe rundll32.exe rvbw.nxo lekymn
BHO: MHTBPos00 Class: {0c37b053-fd68-456a-82e1-d788ee342e6f} - c:\programme\family toolbar\tbcore3.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programme\gemeinsame dateien\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\programme\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\programme\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Anmelde-Hilfsprogramm: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programme\gemeinsame dateien\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programme\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\programme\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programme\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Loader Class: {f880a4a8-c436-4ac4-afd1-aa0bdc9552dd} - c:\windows\bricopacks\leopardxp\FindeXer.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\programme\windows live\toolbar\wltcore.dll
TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\programme\styler\tb\StylerTB.dll
TB: Family Toolbar: {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - c:\programme\family toolbar\tbcore3.dll
TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
uRun: [LightScribe Control Panel] c:\programme\gemeinsame dateien\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [ares] "c:\programme\ares\Ares.exe" -h
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Startup] c:\dokumente und einstellungen\robert\anwendungsdaten\microsoft\updaters.exe
uRun: [CursorXP] "c:\program files\cursorxp\CursorXP.exe" -s
uRun: []
uRun: [EA Core] "c:\programme\electronic arts\ea link\Core.exe" -silent
uRun: [InstallIQUpdater] "c:\programme\w3i\installiqupdater\InstallIQUpdater.exe" /silent /autorun
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [IAAnotif] c:\programme\intel\intel matrix storage manager\iaanotif.exe
mRun: [PDF Complete] c:\programme\pdf complete\pdfsty.exe
mRun: [SynTPEnh] c:\programme\synaptics\syntp\SynTPEnh.exe
mRun: [WirelessAssistant] c:\programme\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [QlbCtrl.exe] c:\programme\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [HP Software Update] c:\programme\hp\hp software update\HPWuSchd2.exe
mRun: [zCpqset] c:\programme\hewlett-packard\default settings\cpqset.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [HPCam_Menu] "c:\programme\hewlett-packard\hp webcam\muitransfer\muistartmenu.exe" "c:\programme\hewlett-packard\hp webcam" updatewithcreateonce "software\cyberlink\hp webcam\1.0"
mRun: [WatchDog] c:\programme\intervideo\dvd8sesd\DVDCheck.exe
mRun: [Adobe Reader Speed Launcher] "c:\programme\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\programme\gemeinsame dateien\adobe\arm\1.0\AdobeARM.exe"
mRun: [Google Desktop Search] "c:\programme\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [SSBkgdUpdate] "c:\programme\gemeinsame dateien\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\programme\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\programme\scansoft\paperport\IndexSearch.exe
mRun: [BrMfcWnd] c:\programme\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\programme\brother\controlcenter3\brctrcen.exe /autorun
mRun: [SunJavaUpdateSched] "c:\programme\gemeinsame dateien\java\java update\jusched.exe"
mRun: [dvd43] c:\programme\dvd43\dvd43_tray.exe
mRun: [DrvIcon] c:\programme\vista drive icon\DrvIcon.exe
mRun: [RemoteControl] c:\programme\cyberlink\powerdvd\PDVDServ.exe
mRun: [SweetIM] c:\programme\sweetim\messenger\SweetIM.exe
mRun: [NokiaMServer] c:\programme\gemeinsame dateien\nokia\mplatform\NokiaMServer /watchfiles startup
mRun: [DivXUpdate] "c:\programme\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [Family Tree Builder Update] c:\programme\myheritage\bin\FTBCheckUpdates.exe
mRun: [TrayServer] c:\programme\magix\filme_auf_dvd_7_terratec_edition\TrayServer.exe
mRun: [QuickTime Task] "c:\programme\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\programme\itunes\iTunesHelper.exe"
mRun: [RelevantKnowledge] c:\programme\relevantknowledge\rlvknlg.exe -boot
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\dokume~1\robert\startm~1\progra~1\autost~1\onenot~1.lnk - c:\programme\gemeinsame dateien\microsoft shared\virtualization handler\CVH.EXE
StartupFolder: c:\dokume~1\alluse~1\startm~1\progra~1\autost~1\bttray.lnk - c:\programme\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\dokume~1\alluse~1\startm~1\progra~1\autost~1\window~1.lnk - c:\programme\windows desktop search\WindowsSearch.exe
IE: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZRxdm784YYDE
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Nach Microsoft &Excel exportieren - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: Senden an &Bluetooth-Gerät… - c:\programme\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Senden an Bluetooth - c:\programme\widcomm\bluetooth software\btsendto_ie.htm
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB}
IE: {88EB38EF-4D2C-436D-ABD3-56B232674062} - c:\programme\icq7.0\ICQ.exe
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\programme\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programme\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\programme\windows live\writer\WriterBrowserExtension.dll
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/PopularScreenSaversInitialSetup1.0.1.1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\programme\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\programme\windows desktop search\MSNLNamespaceMgr.dll

================= FIREFOX ===================

FF - ProfilePath - c:\dokume~1\robert\anwend~1\mozilla\firefox\profiles\7kjm7c80.default\
FF - prefs.js: browser.search.selectedEngine - Suchen
FF - prefs.js: browser.startup.homepage - hxxp://search.myheritage.com/
FF - prefs.js: keyword.URL - hxxp://search.myheritage.com/?orig=ds&q=
FF - component: c:\programme\nokia\nokia ovi suite\connectors\bookmarks connector\firefoxextension\components\FirefoxExtension.dll
FF - plugin: c:\programme\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\programme\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\programme\google\picasa3\npPicasa3.dll
FF - plugin: c:\programme\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\programme\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\programme\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\programme\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\programme\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programme\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\programme\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\programme\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\programme\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\programme\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\programme\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-3 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-2-3 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-3 242896]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-5-11 213768]
R2 avg9wd;AVG Free WatchDog;c:\programme\avg\avg9\avgwdsvc.exe [2010-3-15 308064]
R2 cvhsvc;Client Virtualization Handler;c:\programme\gemeinsame dateien\microsoft shared\virtualization handler\CVHSVC.EXE [2009-9-26 819600]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-2-22 54752]
R2 pdfcDispatcher;PDF Document Manager;c:\programme\pdf complete\pdfsvc.exe [2009-5-11 777240]
R2 sftlist;Application Virtualization Client;c:\programme\microsoft application virtualization client\sftlist.exe [2009-9-23 447832]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2009-2-18 113536]
R3 Com4QLBEx;Com4QLBEx;c:\programme\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-5-11 209464]
R3 osppsvc;Office Software Protection Platform;c:\programme\gemeinsame dateien\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2009-9-26 4639136]
R3 sftfs;sftfs;c:\programme\microsoft application virtualization client\drivers\SftFSXP.sys [2009-9-23 543064]
R3 sftplay;sftplay;c:\programme\microsoft application virtualization client\drivers\sftplayxp.sys [2009-9-23 190312]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [2009-9-23 21864]
R3 sftvol;sftvol;c:\programme\microsoft application virtualization client\drivers\SftVolXP.sys [2009-9-23 14680]
R3 sftvsa;Application Virtualization Service Agent;c:\programme\microsoft application virtualization client\sftvsa.exe [2009-9-23 203608]
S2 0056061265194115mcinstcleanup;McAfee Application Installer Cleanup (0056061265194115);c:\dokume~1\robert\lokale~1\temp\005606~1.exe c:\progra~1\gemein~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service –> c:\dokume~1\robert\lokale~1\temp\005606~1.exe c:\progra~1\gemein~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]
S2 gupdate;Google Update Service (gupdate);c:\programme\google\update\GoogleUpdate.exe [2010-2-13 135664]
S3 cpudrv;cpudrv;c:\programme\systemrequirementslab\cpudrv.sys [2009-12-18 11336]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\programme\magix\common\database\bin\fbserver.exe [2010-6-17 1527900]
S3 fsssvc;Windows Live Family Safety-Dienst;c:\programme\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\programme\google\google desktop search\GoogleDesktop.exe [2010-2-3 30192]
S3 MfeAVFK;McAfee Inc. MfeAVFK;c:\windows\system32\drivers\mfeavfk.sys [2009-5-11 79880]
S3 MfeBOPK;McAfee Inc. MfeBOPK;c:\windows\system32\drivers\mfebopk.sys [2009-5-11 35272]
S3 MfeRKDK;McAfee Inc. MfeRKDK;c:\windows\system32\drivers\mferkdk.sys [2009-5-11 34216]

=============== Created Last 30 ================

2010-06-25 09:37:04 0 d—–w- c:\programme\Microsoft CAPICOM 2.1.0.2
2010-06-24 10:06:39 0 d—–w- C:\Desktop
2010-06-24 10:06:03 0 d—–w- c:\programme\Trend Micro
2010-06-24 09:40:45 263270 —-a-w- C:\lma_log.html
2010-06-24 09:35:17 0 d—–w- c:\programme\W3i, LLC
2010-06-24 09:34:20 0 d—–w- c:\programme\W3i
2010-06-24 09:34:20 0 d—–w- c:\dokume~1\alluse~1\anwend~1\W3i
2010-06-24 09:32:34 0 d—–w- c:\programme\RelevantKnowledge
2010-06-24 08:38:30 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-06-24 08:38:30 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-06-24 08:37:47 0 d—–w- c:\programme\iPod
2010-06-24 08:37:41 0 d—–w- c:\programme\iTunes
2010-06-24 08:37:41 0 d—–w- c:\dokume~1\alluse~1\anwend~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-24 08:35:21 0 d—–w- c:\programme\Bonjour
2010-06-24 08:30:22 0 d—–w- c:\dokume~1\alluse~1\anwend~1\Electronic Arts
2010-06-17 07:08:59 33280 —-a-w- c:\windows\system32\PsisRndr.ax
2010-06-17 07:08:59 33280 —-a-w- c:\windows\system32\dllcache\psisrndr.ax
2010-06-17 07:08:54 18432 —-a-w- c:\windows\system32\dllcache\bdaplgin.ax
2010-06-17 07:08:54 18432 —-a-w- c:\windows\system32\BdaPlgIn.ax
2010-06-17 06:22:12 0 d—–w- c:\dokume~1\robert\anwend~1\MAGIX
2010-06-17 06:21:56 245760 —-a-w- c:\windows\system32\mp4sds32.ax
2010-06-17 06:21:55 420240 —-a-w- c:\windows\system32\mpg4c32.dll
2010-06-17 06:21:43 309616 —-a-w- c:\windows\system32\wmv8dmod.dll
2010-06-17 06:20:49 0 d—–w- c:\programme\gemeinsame dateien\MAGIX Shared
2010-06-17 06:19:24 0 d—–w- c:\dokume~1\alluse~1\anwend~1\MAGIX
2010-06-17 06:18:50 120200 —-a-w- c:\windows\system32\DLLDEV32i.dll
2010-06-17 06:18:50 0 d—–w- c:\programme\MAGIX
2010-06-17 06:16:31 7119 —-a-w- c:\windows\mgxoschk.ini
2010-06-17 06:16:31 700416 —-a-w- c:\windows\system32\mgxoschk.dll
2010-06-17 06:16:31 0 d—–w- c:\windows\system32\MAGIX
2010-06-17 06:12:56 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-06-17 06:12:56 60032 —-a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-06-15 18:06:40 0 d—–w- c:\programme\Ares
2010-06-11 18:54:14 330 —-a-w- c:\windows\MyHeritage.INI
2010-06-11 18:52:25 0 d—–w- c:\dokume~1\robert\anwend~1\MyHeritage
2010-06-11 18:52:25 0 d—–w- c:\dokume~1\alluse~1\anwend~1\MyHeritage
2010-06-11 18:42:29 0 d—–w- c:\programme\Family Toolbar
2010-06-11 18:42:23 454656 —-a-w- c:\windows\system32\PaintX.dll
2010-06-11 18:42:23 372736 —-a-w- c:\windows\system32\ijl15.dll
2010-06-11 18:42:23 137000 —-a-w- c:\windows\system32\msmapi32.ocx
2010-06-11 18:42:23 0 d—–w- c:\dokume~1\robert\anwend~1\The Complete Genealogy Reporter - FTB
2010-06-11 18:36:39 0 d—–w- c:\programme\MyHeritage
2010-06-11 16:35:15 0 d—–w- c:\dokumente und einstellungen\robert\.freemind
2010-06-11 16:35:03 0 d—–w- c:\programme\FreeMind
2010-06-11 11:57:30 0 d—–w- C:\ProgramData
2010-06-11 10:29:24 0 d—–w- c:\programme\gemeinsame dateien\Adobe AIR
2010-06-11 05:28:32 65536 ——w- c:\windows\system32\dllcache\asycfilt.dll
2010-06-10 04:29:14 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-09 17:00:43 0 d—–w- c:\programme\ConvertHelper
2010-06-04 15:51:57 0 d—–w- c:\programme\Guitar Pro 5

==================== Find3M ====================

2010-06-24 09:08:06 96900 —-a-w- c:\windows\system32\perfc007.dat
2010-06-24 09:08:06 497718 —-a-w- c:\windows\system32\perfh007.dat
2010-06-20 10:24:56 5848 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-17 19:41:32 53368 —ha-w- c:\windows\system32\mlfcache.dat
2010-06-02 14:54:48 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-18 14:35:16 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-05-18 14:35:16 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-05-05 13:30:57 173056 ——w- c:\windows\system32\dllcache\ie4uinit.exe
2010-05-02 08:05:54 1851392 ——w- c:\windows\system32\win32k.sys
2010-05-02 08:05:54 1851392 ——w- c:\windows\system32\dllcache\win32k.sys
2010-04-20 05:29:56 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-20 05:29:56 285696 ——w- c:\windows\system32\dllcache\atmfd.dll
2010-04-12 15:29:19 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-04-06 02:52:46 2462720 ——w- c:\windows\system32\dllcache\WMVCore.dll
2010-03-31 01:58:04 133616 ——w- c:\windows\system32\pxafs.dll
2010-03-31 01:58:04 125424 ——w- c:\windows\system32\pxinsi64.exe
2010-03-31 01:58:04 123888 ——w- c:\windows\system32\pxcpyi64.exe
2010-03-30 22:16:34 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-03-30 22:10:40 295264 —-a-w- c:\windows\system32\PresentationHost.exe

============= FINISH: 20:54:36,75 ===============


Attach.txt

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 02.02.2010 13:58:39
System Uptime: 26.06.2010 10:55:01 (10 hours ago)

Motherboard: Hewlett-Packard | | 308A
Processor: Intel® Core™2 Duo CPU T5870 @ 2.00GHz | U10 | 777/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 20,052 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable

==== Disabled Device Manager Items =============

Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia 3110c
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 3110c
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd

==== System Restore Points ===================

RP122: 06.03.2010 19:58:09 - Systemprüfpunkt
RP123: 11.03.2010 17:12:19 - Styler wird installiert
RP124: 11.03.2010 17:22:00 - Styler wird entfernt
RP125: 11.03.2010 20:36:12 - Software Distribution Service 3.0
RP126: 11.03.2010 21:47:56 - Safari wird installiert
RP127: 12.03.2010 06:15:02 - Installed Opera 10.50.
RP128: 13.03.2010 15:41:41 - Systemprüfpunkt
RP129: 14.03.2010 17:18:47 - Installed Windows XP – Software Updates KB952011.
RP130: 15.03.2010 16:39:01 - Avg8 Update
RP131: 15.03.2010 17:32:24 - Avg Update
RP132: 15.03.2010 20:11:00 - Entfernt WinDVD
RP133: 17.03.2010 16:56:25 - Avg Update
RP134: 18.03.2010 16:44:49 - BricoPack Automatic Restore Point
RP135: 18.03.2010 17:23:17 - iTunes wird installiert
RP136: 19.03.2010 16:33:06 - Removed Opera 10.50.
RP137: 20.03.2010 19:25:24 - Systemprüfpunkt
RP138: 21.03.2010 19:33:01 - Systemprüfpunkt
RP139: 22.03.2010 12:13:58 - Installed Windows XP KB915800-v4.
RP140: 22.03.2010 12:14:33 - Installed Virtual Desktop Manager Powertoy for Windows XP
RP141: 22.03.2010 12:14:50 - Installed Windows XP Windows Search 4.0.
RP142: 22.03.2010 12:15:15 - Installed Magnifier Powertoy for Windows XP
RP143: 22.03.2010 12:18:11 - Installed ClearType Tuning Control Panel Applet
RP144: 22.03.2010 12:18:42 - Installed Alt-Tab Task Switcher Powertoy for Windows XP
RP145: 22.03.2010 12:20:28 - DirectX wurde installiert
RP146: 22.03.2010 12:24:47 - Windows XP KB938759 wurde installiert.
RP147: 23.03.2010 10:26:46 - Software Distribution Service 3.0
RP148: 24.03.2010 12:11:37 - Systemprüfpunkt
RP149: 25.03.2010 19:46:33 - Systemprüfpunkt
RP150: 25.03.2010 21:14:11 - Installed SweetIM for Messenger 3.0
RP151: 26.03.2010 22:59:54 - Systemprüfpunkt
RP152: 28.03.2010 13:36:05 - Systemprüfpunkt
RP153: 29.03.2010 16:51:17 - Systemprüfpunkt
RP154: 30.03.2010 18:58:34 - Installed Java™ 6 Update 19
RP155: 31.03.2010 10:57:15 - Software Distribution Service 3.0
RP156: 01.04.2010 16:42:54 - Avg Update
RP157: 01.04.2010 16:44:06 - Avg Update
RP158: 02.04.2010 21:32:09 - Systemprüfpunkt
RP159: 05.04.2010 14:51:24 - Systemprüfpunkt
RP160: 08.04.2010 17:42:18 - Avg Update
RP161: 09.04.2010 20:08:42 - Installation eines unsignierten Treibers
RP162: 14.04.2010 17:52:47 - Software Distribution Service 3.0
RP163: 15.04.2010 16:19:04 - Software Distribution Service 3.0
RP164: 16.04.2010 20:52:40 - Systemprüfpunkt
RP165: 17.04.2010 09:40:31 - TubeBox! wird installiert
RP166: 17.04.2010 15:28:52 - TubeBox! wird entfernt
RP167: 20.04.2010 16:57:37 - Avg Update
RP168: 20.04.2010 16:59:58 - Avg Update
RP169: 02.05.2010 14:49:11 - Systemprüfpunkt
RP170: 02.05.2010 20:26:11 - TubeBox! wird installiert
RP171: 03.05.2010 19:35:49 - Entfernt DIE SIEDLER - Das Erbe der Könige
RP172: 03.05.2010 19:38:24 - Removed Microsoft Games for Windows - LIVE
RP173: 03.05.2010 19:40:08 - Removed Microsoft Games for Windows - LIVE Redistributable
RP174: 03.05.2010 19:43:37 - Nokia Connectivity Cable Driver wird entfernt
RP175: 03.05.2010 19:44:57 - Removed Nokia Ovi Suite Software Updater.
RP176: 03.05.2010 19:45:32 - Removed Nokia Software Updater.
RP177: 03.05.2010 19:51:05 - TubeBox! wird entfernt
RP178: 05.05.2010 16:31:44 - Avg Update
RP179: 06.05.2010 19:36:31 - Systemprüfpunkt
RP180: 08.05.2010 19:13:22 - Installiert SPORE™
RP181: 08.05.2010 19:33:52 - Installiert EA Download Manager
RP182: 09.05.2010 11:13:02 - Gothic 3 wird installiert
RP183: 09.05.2010 11:13:30 - Gothic 3 wird installiert
RP184: 10.05.2010 16:56:44 - Systemprüfpunkt
RP185: 11.05.2010 16:22:49 - Installed Java™ 6 Update 20
RP186: 12.05.2010 17:28:11 - Software Distribution Service 3.0
RP187: 14.05.2010 12:13:16 - Systemprüfpunkt
RP188: 15.05.2010 18:12:06 - Systemprüfpunkt
RP189: 16.05.2010 19:47:37 - Systemprüfpunkt
RP190: 18.05.2010 19:34:52 - Systemprüfpunkt
RP191: 20.05.2010 09:27:37 - Systemprüfpunkt
RP192: 21.05.2010 15:15:41 - Systemprüfpunkt
RP193: 22.05.2010 15:24:36 - Systemprüfpunkt
RP194: 26.05.2010 16:02:43 - Software Distribution Service 3.0
RP195: 30.05.2010 14:41:56 - Systemprüfpunkt
RP196: 01.06.2010 17:43:35 - Systemprüfpunkt
RP197: 02.06.2010 16:55:15 - Avg Update
RP198: 03.06.2010 18:51:38 - Systemprüfpunkt
RP199: 04.06.2010 17:36:55 - Software Distribution Service 3.0
RP200: 06.06.2010 19:58:14 - Systemprüfpunkt
RP201: 08.06.2010 18:35:48 - Systemprüfpunkt
RP202: 11.06.2010 07:28:29 - Software Distribution Service 3.0
RP203: 11.06.2010 13:07:00 - Software Distribution Service 3.0
RP204: 11.06.2010 13:57:18 - Installiert EA Link
RP205: 17.06.2010 09:08:52 - Installation eines unsignierten Treibers
RP206: 19.06.2010 18:47:17 - Systemprüfpunkt
RP207: 23.06.2010 14:13:50 - Software Distribution Service 3.0
RP208: 23.06.2010 19:19:55 - Removed Alt-Tab Task Switcher Powertoy for Windows XP
RP209: 23.06.2010 19:38:42 - Removed ClearType Tuning Control Panel Applet
RP210: 23.06.2010 19:40:08 - Removed LightScribe System Software.
RP211: 23.06.2010 19:40:26 - Removed Magnifier Powertoy for Windows XP
RP212: 23.06.2010 19:41:47 - QuickTime wird entfernt
RP213: 23.06.2010 19:45:11 - Seven Remix XP 2.31: Uninstallation
RP214: 24.06.2010 08:53:07 - iTunes wird entfernt
RP215: 24.06.2010 08:57:30 - Seven Remix XP 2.31: Uninstallation
RP216: 24.06.2010 09:21:00 - Removed SweetIM Toolbar for Internet Explorer 3.6
RP217: 24.06.2010 09:34:05 - Removed Virtual Desktop Manager Powertoy for Windows XP
RP218: 24.06.2010 10:37:33 - iTunes wird installiert
RP219: 24.06.2010 10:45:34 - Safari wird installiert
RP220: 24.06.2010 11:03:26 - Software Distribution Service 3.0
RP221: 24.06.2010 12:27:35 - Installed HiJackThis
RP222: 24.06.2010 12:28:56 - Removed HiJackThis
RP223: 24.06.2010 12:29:37 - Installed HiJackThis
RP224: 25.06.2010 11:24:48 - Avg Update
RP225: 25.06.2010 11:36:43 - Software Distribution Service 3.0

==== Installed Programs ======================

Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.2 - Deutsch
Agere Systems HDA Modem
Any DVD Converter Professional 4.0.5
Any Video Converter 3.0.1
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ares 2.1.5
Atlantica Online
AVG Free 9.0
AVS Media Player 3.1
Bonjour
Brother MFL-Pro Suite
ConvertHelper 2.2
CursorXP
Die Siedler II - Die nächste Generation
DivX-Setup
DivX Plus DirectShow Filters
DVD43 v4.6.0
DynaGeo 2.6e
EA Download Manager
EA Download Manager UI
EA Link
Firebird SQL Server - MAGIX Edition
FreeMind
Gigaflat
Google Desktop
Google Earth
Google Update Helper
Gothic 3
Guitar Pro 5.2
Hotfix für Windows Media Player 11 (KB939683)
Hotfix für Windows XP (KB938759)
Hotfix für Windows XP (KB942288-v3)
Hotfix für Windows XP (KB949764)
Hotfix für Windows XP (KB952287)
Hotfix für Windows XP (KB953955)
Hotfix für Windows XP (KB961118)
Hotfix für Windows XP (KB976098-v2)
Hotfix für Windows XP (KB979306)
Hotfix für Windows XP (KB981793)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
HP Common Access Service Library
HP Help and Support
HP Integrated Module with Bluetooth wireless technology
HP Quick Launch Buttons 6.50 A1
HP Software Setup
HP Update
HP User Guides 0140
HP Webcam
HP Wireless Assistant
ICQ7
IDT Audio
InstallIQ Updater
Intel® Graphics Media Accelerator Driver
Intel® Matrix Storage Manager
iTunes
Java Auto Updater
Java™ 6 Update 20
Java™ 6 Update 7
Junk Mail filter update
Living Marine Aquarium 2
MAGIX Filme auf DVD TerraTec Edition [removed] (D)
MAGIX Online Druck Service [removed] (D)
MAGIX Screenshare 4.3.6.1987 (D)
MFC RunTime files
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 German Language Pack
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office Click-to-Run 2010 (Beta)
Microsoft Office Home and Business 2010 (Beta) - Deutsch
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.7
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.6.3)
Mp3tag v2.46a
MSN
MSVC80_x86_v2
MSVC90_x86
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
MyHeritage Family Tree Builder
Nero OEM
Nero Suite
Nokia Ovi Suite
Ovi Desktop Sync Engine
OviMPlatform
PaperPort
PC Connectivity Solution
PDF Complete
Picasa 3
PowerDVD
QuickTime
RelevantKnowledge
Roxio Activation Module
Roxio Creator Business
Safari
Security Update for CAPICOM (KB931906)
Security Update for Windows Search 4 - KB963093
Segoe UI
Seven Remix XP 2.31
Sicherheitsupdate für Step by Step Interactive Training (KB923723)
Sicherheitsupdate für Windows Internet Explorer 8 (KB971961)
Sicherheitsupdate für Windows Internet Explorer 8 (KB978207)
Sicherheitsupdate für Windows Internet Explorer 8 (KB981332)
Sicherheitsupdate für Windows Internet Explorer 8 (KB982381)
Sicherheitsupdate für Windows Media Player (KB952069)
Sicherheitsupdate für Windows Media Player (KB954155)
Sicherheitsupdate für Windows Media Player (KB968816)
Sicherheitsupdate für Windows Media Player (KB973540)
Sicherheitsupdate für Windows Media Player (KB978695)
Sicherheitsupdate für Windows Media Player 11 (KB954154)
Sicherheitsupdate für Windows XP (KB923561)
Sicherheitsupdate für Windows XP (KB923689)
Sicherheitsupdate für Windows XP (KB941569)
Sicherheitsupdate für Windows XP (KB946648)
Sicherheitsupdate für Windows XP (KB950762)
Sicherheitsupdate für Windows XP (KB950974)
Sicherheitsupdate für Windows XP (KB951066)
Sicherheitsupdate für Windows XP (KB951376-v2)
Sicherheitsupdate für Windows XP (KB951748)
Sicherheitsupdate für Windows XP (KB952004)
Sicherheitsupdate für Windows XP (KB952954)
Sicherheitsupdate für Windows XP (KB956572)
Sicherheitsupdate für Windows XP (KB956744)
Sicherheitsupdate für Windows XP (KB956802)
Sicherheitsupdate für Windows XP (KB956803)
Sicherheitsupdate für Windows XP (KB956844)
Sicherheitsupdate für Windows XP (KB957097)
Sicherheitsupdate für Windows XP (KB958644)
Sicherheitsupdate für Windows XP (KB958687)
Sicherheitsupdate für Windows XP (KB958869)
Sicherheitsupdate für Windows XP (KB959426)
Sicherheitsupdate für Windows XP (KB960225)
Sicherheitsupdate für Windows XP (KB960803)
Sicherheitsupdate für Windows XP (KB960859)
Sicherheitsupdate für Windows XP (KB961501)
Sicherheitsupdate für Windows XP (KB969059)
Sicherheitsupdate für Windows XP (KB969947)
Sicherheitsupdate für Windows XP (KB970238)
Sicherheitsupdate für Windows XP (KB970430)
Sicherheitsupdate für Windows XP (KB971468)
Sicherheitsupdate für Windows XP (KB971486)
Sicherheitsupdate für Windows XP (KB971557)
Sicherheitsupdate für Windows XP (KB971633)
Sicherheitsupdate für Windows XP (KB971657)
Sicherheitsupdate für Windows XP (KB972270)
Sicherheitsupdate für Windows XP (KB973354)
Sicherheitsupdate für Windows XP (KB973507)
Sicherheitsupdate für Windows XP (KB973525)
Sicherheitsupdate für Windows XP (KB973869)
Sicherheitsupdate für Windows XP (KB973904)
Sicherheitsupdate für Windows XP (KB974112)
Sicherheitsupdate für Windows XP (KB974318)
Sicherheitsupdate für Windows XP (KB974392)
Sicherheitsupdate für Windows XP (KB974571)
Sicherheitsupdate für Windows XP (KB975025)
Sicherheitsupdate für Windows XP (KB975467)
Sicherheitsupdate für Windows XP (KB975560)
Sicherheitsupdate für Windows XP (KB975561)
Sicherheitsupdate für Windows XP (KB975562)
Sicherheitsupdate für Windows XP (KB975713)
Sicherheitsupdate für Windows XP (KB977165-v2)
Sicherheitsupdate für Windows XP (KB977165)
Sicherheitsupdate für Windows XP (KB977816)
Sicherheitsupdate für Windows XP (KB977914)
Sicherheitsupdate für Windows XP (KB978037)
Sicherheitsupdate für Windows XP (KB978251)
Sicherheitsupdate für Windows XP (KB978262)
Sicherheitsupdate für Windows XP (KB978338)
Sicherheitsupdate für Windows XP (KB978542)
Sicherheitsupdate für Windows XP (KB978601)
Sicherheitsupdate für Windows XP (KB978706)
Sicherheitsupdate für Windows XP (KB979309)
Sicherheitsupdate für Windows XP (KB979482)
Sicherheitsupdate für Windows XP (KB979559)
Sicherheitsupdate für Windows XP (KB979683)
Sicherheitsupdate für Windows XP (KB980195)
Sicherheitsupdate für Windows XP (KB980218)
Sicherheitsupdate für Windows XP (KB980232)
SMAC 2.0
Sonic CinePlayer Decoder Pack
SPORE™
SweetIM for Messenger 3.0
Synaptics Pointing Device Driver
System Requirements Lab for Intel
Update für Windows Internet Explorer 8 (KB976662)
Update für Windows Internet Explorer 8 (KB980182)
Update für Windows XP (KB942763)
Update für Windows XP (KB951978)
Update für Windows XP (KB955759)
Update für Windows XP (KB961503)
Update für Windows XP (KB967715)
Update für Windows XP (KB968389)
Update für Windows XP (KB971737)
Update für Windows XP (KB973687)
Update für Windows XP (KB973815)
Update für Windows XP (KB978207)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.0.5
WebFldrs XP
Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live-Uploadtool
Windows Live Anmelde-Assistent
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Fotogalerie
Windows Live Mail
Windows Live Messenger
Windows Live Sync
Windows Live Toolbar
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
WinRAR
Xvid 1.2.1 final uninstall

==== End Of File ===========================
Hi,

Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.

Please continue as follows:

  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  • Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log.


A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
Hi, If it was after my instructions then I'd like to see those reports to make sure nothing bad (not necessary visible) is remaining there.
okay you´ll get it

combofix.txt

ComboFix 10-06-28.01 - Robert 29.06.2010 12:28:43.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.2039.1147 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\Robert\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Vorheriger Suchlauf ——-
.
c:\programme\RelevantKnowledge\MSVCP71.DLL
c:\programme\RelevantKnowledge\MSVCR71.DLL
c:\programme\RelevantKnowledge\rlls.dll
c:\programme\RelevantKnowledge\rlls64.dll
c:\programme\RelevantKnowledge\rloci.bin
c:\programme\RelevantKnowledge\rlservice.exe
c:\programme\RelevantKnowledge\rlvknlg.exe
c:\programme\RelevantKnowledge\rlvknlg64.exe
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\xpsp1hfm.log

c:\windows\system32\kernel32.dll . . . ist infiziert!!

.
((((((((((((((((((((((( Dateien erstellt von 2010-05-28 bis 2010-06-29 ))))))))))))))))))))))))))))))
.

2010-06-28 11:44 . 2010-06-28 11:44 ——– d—–w- c:\programme\CCleaner
2010-06-28 11:29 . 2010-06-28 11:29 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\GlarySoft
2010-06-28 11:23 . 2010-06-28 11:23 ——– d—–w- c:\programme\Glary Utilities
2010-06-28 10:45 . 2010-06-28 10:45 ——– d—–w- c:\programme\T3Desk
2010-06-25 09:37 . 2010-06-25 09:37 ——– d—–w- c:\programme\Microsoft CAPICOM 2.1.0.2
2010-06-24 10:06 . 2010-06-28 07:46 ——– d—–w- C:\Desktop
2010-06-24 10:06 . 2010-06-24 10:06 ——– d—–w- c:\programme\Trend Micro
2010-06-24 09:38 . 2010-06-24 09:38 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Winferno
2010-06-24 09:35 . 2010-06-24 09:35 ——– d—–w- c:\programme\W3i, LLC
2010-06-24 09:34 . 2010-06-24 09:34 ——– d—–w- c:\programme\W3i
2010-06-24 09:34 . 2010-06-24 09:34 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\W3i
2010-06-24 08:38 . 2009-05-18 11:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-06-24 08:38 . 2008-04-17 10:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-06-24 08:37 . 2010-06-24 08:37 ——– d—–w- c:\programme\iPod
2010-06-24 08:37 . 2010-06-24 08:38 ——– d—–w- c:\programme\iTunes
2010-06-24 08:37 . 2010-06-24 08:38 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-24 08:36 . 2010-06-24 08:36 ——– d—–w- c:\programme\Apple Software Update
2010-06-24 08:35 . 2010-06-24 08:35 ——– d—–w- c:\programme\Bonjour
2010-06-24 08:30 . 2010-06-24 08:30 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Electronic Arts
2010-06-17 07:09 . 2008-04-13 22:16 15232 —-a-w- c:\windows\system32\drivers\MPE.sys
2010-06-17 07:09 . 2008-04-13 22:16 15232 —-a-w- c:\windows\system32\dllcache\mpe.sys
2010-06-17 07:09 . 2008-11-11 12:23 45344 —-a-r- c:\windows\system32\drivers\emOEM.sys
2010-06-17 07:09 . 2008-11-11 12:23 485920 —-a-r- c:\windows\system32\drivers\emBDA.sys
2010-06-17 07:09 . 2006-12-15 15:54 61440 —-a-r- c:\windows\emMON.exe
2010-06-17 07:09 . 2008-04-14 05:52 363520 —-a-w- c:\windows\system32\PsisDecd.dll
2010-06-17 07:09 . 2008-04-14 05:52 363520 —-a-w- c:\windows\system32\dllcache\psisdecd.dll
2010-06-17 07:09 . 2008-04-13 22:16 11776 —-a-w- c:\windows\system32\drivers\BdaSup.sys
2010-06-17 07:09 . 2008-04-13 22:16 11776 —-a-w- c:\windows\system32\dllcache\bdasup.sys
2010-06-17 06:22 . 2010-06-17 06:22 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\MAGIX
2010-06-17 06:21 . 2001-05-11 11:18 420240 —-a-w- c:\windows\system32\mpg4c32.dll
2010-06-17 06:21 . 2001-05-16 15:54 309616 —-a-w- c:\windows\system32\wmv8dmod.dll
2010-06-17 06:19 . 2010-06-17 06:21 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\MAGIX
2010-06-17 06:18 . 2010-06-17 06:21 ——– d—–w- c:\programme\MAGIX
2010-06-17 06:18 . 2007-04-27 07:43 120200 —-a-w- c:\windows\system32\DLLDEV32i.dll
2010-06-17 06:16 . 2010-06-17 06:21 ——– d—–w- c:\windows\system32\MAGIX
2010-06-17 06:16 . 2008-04-15 13:14 700416 —-a-w- c:\windows\system32\mgxoschk.dll
2010-06-17 06:12 . 2008-04-13 22:15 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-06-17 06:12 . 2008-04-13 22:15 60032 —-a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-06-15 18:06 . 2010-06-15 18:06 ——– d—–w- c:\programme\Ares
2010-06-11 18:52 . 2010-06-11 18:57 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\MyHeritage
2010-06-11 18:52 . 2010-06-11 18:52 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\MyHeritage
2010-06-11 18:42 . 2010-06-11 18:42 ——– d—–w- c:\programme\Family Toolbar
2010-06-11 18:42 . 2010-06-11 18:42 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\The Complete Genealogy Reporter - FTB
2010-06-11 18:42 . 2003-07-06 11:07 372736 —-a-w- c:\windows\system32\ijl15.dll
2010-06-11 18:42 . 2002-03-06 22:19 454656 —-a-w- c:\windows\system32\PaintX.dll
2010-06-11 18:36 . 2010-06-11 18:54 ——– d—–w- c:\programme\MyHeritage
2010-06-11 16:35 . 2010-06-11 16:58 ——– d—–w- c:\dokumente und einstellungen\Robert\.freemind
2010-06-11 16:35 . 2010-06-11 16:35 ——– d—–w- c:\programme\FreeMind
2010-06-11 11:57 . 2010-06-11 11:57 ——– d—–w- C:\ProgramData
2010-06-11 10:29 . 2010-06-24 09:55 ——– d—–w- c:\programme\Gemeinsame Dateien\Adobe AIR
2010-06-11 05:28 . 2010-03-05 14:37 65536 ——w- c:\windows\system32\dllcache\asycfilt.dll
2010-06-10 04:29 . 2010-05-06 10:31 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-09 17:00 . 2010-06-09 17:00 ——– d—–w- c:\programme\ConvertHelper
2010-06-04 15:51 . 2010-06-06 18:52 ——– d—–w- c:\programme\Guitar Pro 5

.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-29 10:37 . 2010-03-02 17:47 ——– d—–w- c:\windows\system32\config\systemprofile\Anwendungsdaten\SoftGrid Client
2010-06-29 10:37 . 2010-03-02 18:22 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\SoftGrid Client
2010-06-28 13:39 . 2010-02-07 03:35 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2010-06-28 11:50 . 2010-03-17 15:58 ——– d—–w- c:\programme\Paraplot
2010-06-24 11:02 . 2010-02-06 13:47 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\ICQ
2010-06-24 09:08 . 2004-08-07 06:04 96900 —-a-w- c:\windows\system32\perfc007.dat
2010-06-24 09:08 . 2004-08-07 06:04 497718 —-a-w- c:\windows\system32\perfh007.dat
2010-06-24 08:45 . 2010-03-11 20:48 ——– d—–w- c:\programme\Safari
2010-06-24 08:37 . 2010-02-07 02:41 ——– d—–w- c:\programme\Gemeinsame Dateien\Apple
2010-06-24 08:37 . 2010-02-07 02:42 ——– d—–w- c:\programme\QuickTime
2010-06-24 07:21 . 2010-03-25 20:14 ——– d—–w- c:\programme\SweetIM
2010-06-24 07:20 . 2010-03-25 20:14 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\SweetIM
2010-06-24 06:48 . 2009-05-11 21:17 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\PDFC
2010-06-23 17:39 . 2010-02-03 19:43 ——– d—–w- c:\programme\Google
2010-06-23 17:38 . 2010-02-10 19:04 ——– d—–w- c:\programme\AVS4YOU
2010-06-21 15:42 . 2010-02-06 13:46 ——– d—–w- c:\programme\ICQ7.0
2010-06-20 10:24 . 2010-03-22 18:21 5848 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-17 19:41 . 2010-03-11 20:48 53368 —ha-w- c:\windows\system32\mlfcache.dat
2010-06-17 06:22 . 2010-06-17 06:20 ——– d—–w- c:\programme\Gemeinsame Dateien\MAGIX Shared
2010-06-11 11:57 . 2009-05-11 20:54 ——– d–h–w- c:\programme\InstallShield Installation Information
2010-06-11 11:57 . 2010-05-08 17:13 ——– d—–w- c:\programme\Electronic Arts
2010-06-06 15:48 . 2010-05-04 17:22 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\DivX
2010-06-06 15:45 . 2010-02-16 20:53 ——– d—–w- c:\programme\DivX
2010-06-04 18:03 . 2010-02-22 17:00 ——– d—–w- c:\programme\Microsoft Silverlight
2010-06-02 14:54 . 2010-02-03 19:52 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-02 14:54 . 2010-02-03 19:52 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-28 14:38 . 2010-03-16 19:39 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\DynaGeo
2010-05-25 11:21 . 2010-03-15 17:56 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\dvdcss
2010-05-22 16:24 . 2010-02-10 19:04 ——– d—–w- c:\programme\Gemeinsame Dateien\AVSMedia
2010-05-22 15:07 . 2010-03-09 17:10 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\AVS4YOU
2010-05-22 14:59 . 2010-04-17 10:13 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\AnvSoft
2010-05-22 14:59 . 2010-04-17 10:13 ——– d—–w- c:\programme\AnvSoft
2010-05-22 14:58 . 2010-05-22 14:29 ——– d—–w- c:\programme\Handbrake
2010-05-22 14:43 . 2010-05-22 14:29 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\HandBrake
2010-05-18 14:35 . 2010-05-18 14:35 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-05-18 14:35 . 2010-05-18 14:35 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-05-11 14:24 . 2010-02-03 19:39 ——– d—–w- c:\programme\Java
2010-05-09 09:13 . 2010-05-09 09:13 ——– d—–w- c:\programme\JoWood
2010-05-08 22:38 . 2010-05-08 22:37 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\SPORE
2010-05-06 10:31 . 2004-08-04 08:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 18:15 . 2010-02-16 21:10 ——– d—–w- c:\dokumente und einstellungen\Robert\Anwendungsdaten\DivX
2010-05-04 17:46 . 2010-02-16 20:53 ——– d—–w- c:\programme\Gemeinsame Dateien\DivX Shared
2010-05-04 15:11 . 2010-05-04 15:11 0 —-a-w- c:\windows\nsreg.dat
2010-05-03 19:18 . 2010-03-20 14:39 ——– d—–w- c:\programme\Free Video Converter
2010-05-03 17:49 . 2010-02-03 19:06 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Roxio
2010-05-03 17:49 . 2010-02-03 19:05 ——– d—–w- c:\programme\Roxio
2010-05-03 17:49 . 2010-02-03 19:05 ——– d—–w- c:\programme\Gemeinsame Dateien\Roxio Shared
2010-05-03 17:49 . 2010-02-03 19:05 ——– d—–w- c:\programme\Gemeinsame Dateien\Sonic Shared
2010-05-03 17:45 . 2010-04-07 19:41 ——– d—–w- c:\programme\Gemeinsame Dateien\Nokia
2010-05-03 17:45 . 2010-04-07 19:38 ——– d—–w- c:\programme\Nokia
2010-05-03 17:35 . 2010-02-07 20:48 ——– d—–w- c:\programme\Ubisoft
2010-05-02 19:20 . 2010-05-02 19:20 ——– d—–w- c:\programme\Xvid
2010-05-02 18:26 . 2010-05-02 18:26 ——– d—–w- c:\programme\Jens Lorek
2010-05-02 08:05 . 2004-08-04 08:00 1851392 ——w- c:\windows\system32\win32k.sys
2010-04-20 05:29 . 2004-08-04 08:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-12 15:29 . 2010-05-11 14:24 411368 —-a-w- c:\windows\system32\deployJava1.dll
.

(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48}"= "c:\programme\Family Toolbar\tbhelper.dll" [2009-05-07 355840]

[HKEY_CLASSES_ROOT\clsid\{1c4ab6a5-595f-4e86-b15f-f93cce2bbd48}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{1EA6B471-CAD2-419a-9539-0586EEFE2D09}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 —-a-w- c:\programme\Family Toolbar\tbcore3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\programme\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]

[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\programme\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]

[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorXP"="c:\program files\CursorXP\CursorXP.exe" [2005-01-19 128000]
"T3Desk"="c:\programme\T3Desk\T3Desk.exe" [2010-06-09 1111040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\programme\Gemeinsame Dateien\Nokia\MPlatform\NokiaMServer" [X]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2009-02-18 737280]
"IAAnotif"="c:\programme\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-12-16 186904]
"PDF Complete"="c:\programme\PDF Complete\pdfsty.exe" [2008-08-08 319000]
"SynTPEnh"="c:\programme\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1430824]
"WirelessAssistant"="c:\programme\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-02-18 506424]
"HP Software Update"="c:\programme\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"zCpqset"="c:\programme\Hewlett-Packard\Default Settings\cpqset.exe" [2008-12-11 81920]
"HPCam_Menu"="c:\programme\Hewlett-Packard\HP Webcam\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]
"Adobe Reader Speed Launcher"="c:\programme\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"Google Desktop Search"="c:\programme\Google\Google Desktop Search\GoogleDesktop.exe" [2010-02-03 30192]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-02 2065248]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SSBkgdUpdate"="c:\programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\programme\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
"IndexSearch"="c:\programme\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
"BrMfcWnd"="c:\programme\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-28 622592]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2010-02-18 248040]
"dvd43"="c:\programme\dvd43\dvd43_tray.exe" [2009-10-23 827904]
"SweetIM"="c:\programme\SweetIM\Messenger\SweetIM.exe" [2010-02-24 111928]
"TrayServer"="c:\programme\MAGIX\Filme_auf_DVD_7_TerraTec_Edition\TrayServer.exe" [2008-01-17 90112]
"ControlCenter3"="c:\programme\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 77824]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-01-21 134656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-01-21 166912]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-01-21 134656]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\dokumente und einstellungen\All Users\Startmen\Programme\Autostart\
BTTray.lnk - c:\programme\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programme\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-15 15:47 12464 ——w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"iTunesHelper"="c:\programme\iTunes\iTunesHelper.exe"
"Family Tree Builder Update"=c:\programme\MyHeritage\Bin\FTBCheckUpdates.exe
"DivXUpdate"="c:\programme\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"RemoteControl"=c:\programme\CyberLink\PowerDVD\PDVDServ.exe
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" -atboottime
"QlbCtrl.exe"=c:\programme\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programme\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programme\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programme\\ICQ7.0\\ICQ.exe"=
"c:\\Programme\\ICQ7.0\\aolload.exe"=
"c:\\Programme\\Messenger\\msmsgs.exe"=
"c:\\Nexon\\NEXON_EU_Downloader\\NEXON_EU_Downloader_Engine.exe"=
"c:\\Programme\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programme\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programme\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Dokumente und Einstellungen\\All Users\\Anwendungsdaten\\NexonEU\\NGM\\NGM.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\iTunes\\iTunes.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [03.02.2010 21:52 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [03.02.2010 21:52 242896]
R2 avg9wd;AVG Free WatchDog;c:\programme\AVG\AVG9\avgwdsvc.exe [15.03.2010 17:46 308064]
R2 cvhsvc;Client Virtualization Handler;c:\programme\Gemeinsame Dateien\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [26.09.2009 08:35 819600]
R2 pdfcDispatcher;PDF Document Manager;c:\programme\PDF Complete\pdfsvc.exe [11.05.2009 23:17 777240]
R2 sftlist;Application Virtualization Client;c:\programme\Microsoft Application Virtualization Client\sftlist.exe [23.09.2009 16:04 447832]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [18.02.2009 15:41 113536]
R3 sftfs;sftfs;c:\programme\Microsoft Application Virtualization Client\drivers\SftFSXP.sys [23.09.2009 16:04 543064]
R3 sftplay;sftplay;c:\programme\Microsoft Application Virtualization Client\drivers\sftplayxp.sys [23.09.2009 16:04 190312]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [23.09.2009 16:05 21864]
R3 sftvol;sftvol;c:\programme\Microsoft Application Virtualization Client\drivers\SftVolXP.sys [23.09.2009 16:04 14680]
R3 sftvsa;Application Virtualization Service Agent;c:\programme\Microsoft Application Virtualization Client\sftvsa.exe [23.09.2009 16:04 203608]
S2 0056061265194115mcinstcleanup;McAfee Application Installer Cleanup (0056061265194115);c:\dokume~1\Robert\LOKALE~1\Temp\005606~1.EXE c:\progra~1\GEMEIN~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service –> c:\dokume~1\Robert\LOKALE~1\Temp\005606~1.EXE c:\progra~1\GEMEIN~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 gupdate;Google Update Service (gupdate);c:\programme\Google\Update\GoogleUpdate.exe [13.02.2010 15:02 135664]
S3 Com4QLBEx;Com4QLBEx;c:\programme\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [11.05.2009 23:47 209464]
S3 cpudrv;cpudrv;c:\programme\SystemRequirementsLab\cpudrv.sys [18.12.2009 11:58 11336]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\programme\MAGIX\Common\Database\bin\fbserver.exe [17.06.2010 08:20 1527900]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\programme\Google\Google Desktop Search\GoogleDesktop.exe [03.02.2010 21:46 30192]
S3 osppsvc;Office Software Protection Platform;c:\programme\Gemeinsame Dateien\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [26.09.2009 05:28 4639136]
.
Inhalt des "geplante Tasks" Ordners

2010-06-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]

2010-06-29 c:\windows\Tasks\GlaryInitialize.job
- c:\programme\Glary Utilities\initialize.exe [2010-06-28 08:01]

2010-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2010-02-13 13:01]

2010-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2010-02-13 13:01]

2010-06-29 c:\windows\Tasks\User_Feed_Synchronization-{BF0CEA61-B9A9-4910-A112-901D690ECD4E}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
——- Zusätzlicher Suchlauf ——-
.
uStart Page = hxxp://search.myheritage.com
mStart Page = hxxp://search.myheritage.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Senden an &Bluetooth-Gerät… - c:\programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Senden an Bluetooth - c:\programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
FF - ProfilePath - c:\dokumente und einstellungen\Robert\Anwendungsdaten\Mozilla\Firefox\Profiles\7kjm7c80.default\
FF - prefs.js: browser.search.selectedEngine - Suchen
FF - prefs.js: browser.startup.homepage - hxxp://search.myheritage.com/
FF - prefs.js: keyword.URL - hxxp://search.myheritage.com/?orig=ds&q=
FF - component: c:\programme\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\components\FirefoxExtension.dll
FF - plugin: c:\programme\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\programme\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programme\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\programme\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\programme\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\programme\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX Richtlinien —-
c:\programme\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -

WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-29 12:50
Windows 5.1.2600 Service Pack 3 NTFS

Scanne versteckte Prozesse…

Scanne versteckte Autostarteinträge…

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
zCpqset = c:\programme\Hewlett-Packard\Default Settings\cpqset.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

Scanne versteckte Dateien…

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\programme\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
——————— Gesperrte Registrierungsschluessel ———————

[HKEY_USERS\S-1-5-21-2597394465-2889974788-3793429437-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:15,cf,7b,19,34,18,b9,b7,b0,68,a7,10,ce,de,b8,4f,91,a2,92,2c,f0,fa,2b,
0f,45,27,1f,fd,59,5f,5a,79,af,00,68,4d,6c,09,cd,a1,da,63,01,ef,7e,14,50,61,\
"??"=hex:ea,7a,23,8e,c9,8f,07,b3,23,66,15,15,9c,63,2c,e3

[HKEY_USERS\S-1-5-21-2597394465-2889974788-3793429437-1006\Software\SecuROM\License information*]
"datasecu"=hex:67,a0,e4,95,67,bb,bc,94,39,5c,6c,45,e5,08,a0,49,5c,eb,22,92,e0,
6b,44,59,21,3a,e9,6b,dd,53,f6,4f,2b,74,48,02,40,98,46,d6,d2,05,ca,2a,45,03,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]
"7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"7040710900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
——————— Durch laufende Prozesse gestartete DLLs ———————

- - - - - - - > 'explorer.exe'(5964)
c:\windows\system32\btmmhook.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Weitere laufende Prozesse ————————
.
c:\programme\idt\wdm\STacSV.exe
c:\windows\system32\msdtc.exe
c:\programme\LSI SoftModem\agrsmsvc.exe
c:\programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programme\Bonjour\mDNSResponder.exe
c:\programme\Java\jre6\bin\jqs.exe
c:\programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\SearchIndexer.exe
c:\programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\SearchProtocolHost.exe
c:\programme\Brother\Brmfcmon\BrMfimon.exe
c:\programme\Gemeinsame Dateien\Nokia\MPlatform\NokiaMServer.exe
c:\programme\Brother\ControlCenter3\brccMCtl.exe
c:\windows\system32\igfxsrvc.exe
c:\programme\Hewlett-Packard\Shared\hpqwmiex.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\programme\AVG\AVG9\avgscanx.exe
c:\programme\AVG\AVG9\avgcsrvx.exe
c:\programme\AVG\AVG9\avgchsvx.exe
c:\programme\Hewlett-Packard\Shared\hpqToaster.exe
c:\programme\AVG\AVG9\avgnsx.exe
c:\programme\AVG\AVG9\avgrsx.exe
c:\programme\AVG\AVG9\avgcsrvx.exe
c:\programme\AVG\AVG9\avgscanx.exe
c:\programme\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2010-06-29 12:56:30 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2010-06-29 10:56

Vor Suchlauf: 25 Verzeichnis(se), 28.102.094.848 Bytes frei
Nach Suchlauf: 27 Verzeichnis(se), 28.066.549.760 Bytes frei

- - End Of File - - D6C9B4227EA3C65425C85AB71DADFA1A

DDS-log


DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 13:12:59,89 on 29.06.2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.2039.850 [GMT 2:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programme\idt\wdm\STacSV.exe
svchost.exe
C:\Programme\LSI SoftModem\agrsmsvc.exe
C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programme\Bonjour\mDNSResponder.exe
C:\Programme\Java\jre6\bin\jqs.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programme\PDF Complete\pdfsvc.exe
C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Programme\Microsoft Application Virtualization Client\sftvsa.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\mqsvc.exe
C:\Programme\Microsoft Application Virtualization Client\sftlist.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\Programme\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Programme\Hp\HP Software Update\HPWuSchd2.exe
C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe
C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
C:\Programme\dvd43\dvd43_tray.exe
C:\Programme\Brother\Brmfcmon\BrMfimon.exe
C:\Programme\Gemeinsame Dateien\Nokia\MPlatform\NokiaMServer.exe
C:\Programme\Brother\ControlCenter3\brccMCtl.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programme\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Programme\AVG\AVG9\avgscanx.exe
C:\Programme\AVG\AVG9\avgcsrvx.exe
C:\Programme\AVG\AVG9\avgchsvx.exe
C:\Programme\Hewlett-Packard\Shared\hpqToaster.exe
C:\Programme\AVG\AVG9\avgwdsvc.exe
C:\Programme\AVG\AVG9\avgnsx.exe
C:\Programme\AVG\AVG9\avgrsx.exe
C:\Programme\AVG\AVG9\avgcsrvx.exe
C:\Programme\AVG\AVG9\avgscanx.exe
C:\Programme\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\explorer.exe
C:\Programme\Safari\Safari.exe
C:\Dokumente und Einstellungen\Robert\Desktop\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://search.myheritage.com
mStart Page = hxxp://search.myheritage.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
uURLSearchHooks: H - No File
uURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\programme\family toolbar\tbhelper.dll
BHO: MHTBPos00 Class: {0c37b053-fd68-456a-82e1-d788ee342e6f} - c:\programme\family toolbar\tbcore3.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programme\gemeinsame dateien\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\programme\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\programme\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Anmelde-Hilfsprogramm: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programme\gemeinsame dateien\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programme\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\programme\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programme\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} - No File
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\programme\windows live\toolbar\wltcore.dll
TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\programme\styler\tb\StylerTB.dll
TB: Family Toolbar: {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - c:\programme\family toolbar\tbcore3.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
uRun: [CursorXP] "c:\program files\cursorxp\CursorXP.exe" -s
uRun: [T3Desk] c:\programme\t3desk\T3Desk.exe
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [IAAnotif] c:\programme\intel\intel matrix storage manager\iaanotif.exe
mRun: [PDF Complete] c:\programme\pdf complete\pdfsty.exe
mRun: [SynTPEnh] c:\programme\synaptics\syntp\SynTPEnh.exe
mRun: [WirelessAssistant] c:\programme\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [HP Software Update] c:\programme\hp\hp software update\HPWuSchd2.exe
mRun: [zCpqset] c:\programme\hewlett-packard\default settings\cpqset.exe
mRun: [HPCam_Menu] "c:\programme\hewlett-packard\hp webcam\muitransfer\muistartmenu.exe" "c:\programme\hewlett-packard\hp webcam" updatewithcreateonce "software\cyberlink\hp webcam\1.0"
mRun: [Adobe Reader Speed Launcher] "c:\programme\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\programme\gemeinsame dateien\adobe\arm\1.0\AdobeARM.exe"
mRun: [Google Desktop Search] "c:\programme\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [SSBkgdUpdate] "c:\programme\gemeinsame dateien\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\programme\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\programme\scansoft\paperport\IndexSearch.exe
mRun: [BrMfcWnd] c:\programme\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [SunJavaUpdateSched] "c:\programme\gemeinsame dateien\java\java update\jusched.exe"
mRun: [dvd43] c:\programme\dvd43\dvd43_tray.exe
mRun: [SweetIM] c:\programme\sweetim\messenger\SweetIM.exe
mRun: [NokiaMServer] c:\programme\gemeinsame dateien\nokia\mplatform\NokiaMServer /watchfiles startup
mRun: [TrayServer] c:\programme\magix\filme_auf_dvd_7_terratec_edition\TrayServer.exe
mRun: [ControlCenter3] c:\programme\brother\controlcenter3\brctrcen.exe /autorun
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\dokume~1\alluse~1\startm~1\progra~1\autost~1\bttray.lnk - c:\programme\widcomm\bluetooth software\BTTray.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Nach Microsoft &Excel exportieren - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: Senden an &Bluetooth-Gerät… - c:\programme\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Senden an Bluetooth - c:\programme\widcomm\bluetooth software\btsendto_ie.htm
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB}
IE: {88EB38EF-4D2C-436D-ABD3-56B232674062} - c:\programme\icq7.0\ICQ.exe
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\programme\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programme\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\programme\windows live\writer\WriterBrowserExtension.dll
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\programme\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\programme\windows desktop search\MSNLNamespaceMgr.dll

================= FIREFOX ===================

FF - ProfilePath - c:\dokume~1\robert\anwend~1\mozilla\firefox\profiles\7kjm7c80.default\
FF - prefs.js: browser.search.selectedEngine - Suchen
FF - prefs.js: browser.startup.homepage - hxxp://search.myheritage.com/
FF - prefs.js: keyword.URL - hxxp://search.myheritage.com/?orig=ds&q=
FF - component: c:\programme\nokia\nokia ovi suite\connectors\bookmarks connector\firefoxextension\components\FirefoxExtension.dll
FF - plugin: c:\programme\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\programme\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\programme\google\picasa3\npPicasa3.dll
FF - plugin: c:\programme\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\programme\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\programme\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\programme\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\programme\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programme\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\programme\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\programme\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\programme\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\programme\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\programme\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-3 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-2-3 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-3 242896]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-5-11 213768]
R2 avg9wd;AVG Free WatchDog;c:\programme\avg\avg9\avgwdsvc.exe [2010-3-15 308064]
R2 cvhsvc;Client Virtualization Handler;c:\programme\gemeinsame dateien\microsoft shared\virtualization handler\CVHSVC.EXE [2009-9-26 819600]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-2-22 54752]
R2 pdfcDispatcher;PDF Document Manager;c:\programme\pdf complete\pdfsvc.exe [2009-5-11 777240]
R2 sftlist;Application Virtualization Client;c:\programme\microsoft application virtualization client\sftlist.exe [2009-9-23 447832]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2009-2-18 113536]
R3 sftfs;sftfs;c:\programme\microsoft application virtualization client\drivers\SftFSXP.sys [2009-9-23 543064]
R3 sftplay;sftplay;c:\programme\microsoft application virtualization client\drivers\sftplayxp.sys [2009-9-23 190312]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [2009-9-23 21864]
R3 sftvol;sftvol;c:\programme\microsoft application virtualization client\drivers\SftVolXP.sys [2009-9-23 14680]
R3 sftvsa;Application Virtualization Service Agent;c:\programme\microsoft application virtualization client\sftvsa.exe [2009-9-23 203608]
S2 0056061265194115mcinstcleanup;McAfee Application Installer Cleanup (0056061265194115);c:\dokume~1\robert\lokale~1\temp\005606~1.exe c:\progra~1\gemein~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service –> c:\dokume~1\robert\lokale~1\temp\005606~1.exe c:\progra~1\gemein~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]
S2 gupdate;Google Update Service (gupdate);c:\programme\google\update\GoogleUpdate.exe [2010-2-13 135664]
S3 Com4QLBEx;Com4QLBEx;c:\programme\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-5-11 209464]
S3 cpudrv;cpudrv;c:\programme\systemrequirementslab\cpudrv.sys [2009-12-18 11336]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\programme\magix\common\database\bin\fbserver.exe [2010-6-17 1527900]
S3 fsssvc;Windows Live Family Safety-Dienst;c:\programme\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\programme\google\google desktop search\GoogleDesktop.exe [2010-2-3 30192]
S3 MfeAVFK;McAfee Inc. MfeAVFK;c:\windows\system32\drivers\mfeavfk.sys [2009-5-11 79880]
S3 MfeBOPK;McAfee Inc. MfeBOPK;c:\windows\system32\drivers\mfebopk.sys [2009-5-11 35272]
S3 MfeRKDK;McAfee Inc. MfeRKDK;c:\windows\system32\drivers\mferkdk.sys [2009-5-11 34216]
S3 osppsvc;Office Software Protection Platform;c:\programme\gemeinsame dateien\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2009-9-26 4639136]

=============== Created Last 30 ================

2010-06-28 11:44:10 0 d—–w- c:\programme\CCleaner
2010-06-28 11:29:27 0 d—–w- c:\dokume~1\robert\anwend~1\GlarySoft
2010-06-28 11:23:14 0 d—–w- c:\programme\Glary Utilities
2010-06-28 10:45:05 0 d—–w- c:\programme\T3Desk
2010-06-28 07:55:49 0 d-sha-r- C:\cmdcons
2010-06-28 07:50:56 98816 —-a-w- c:\windows\sed.exe
2010-06-28 07:50:56 77312 —-a-w- c:\windows\MBR.exe
2010-06-28 07:50:56 256512 —-a-w- c:\windows\PEV.exe
2010-06-28 07:50:56 161792 —-a-w- c:\windows\SWREG.exe
2010-06-25 09:37:04 0 d—–w- c:\programme\Microsoft CAPICOM 2.1.0.2
2010-06-24 10:06:39 0 d—–w- C:\Desktop
2010-06-24 10:06:03 0 d—–w- c:\programme\Trend Micro
2010-06-24 09:40:45 367447 —-a-w- C:\lma_log.html
2010-06-24 09:35:17 0 d—–w- c:\programme\W3i, LLC
2010-06-24 09:34:20 0 d—–w- c:\programme\W3i
2010-06-24 09:34:20 0 d—–w- c:\dokume~1\alluse~1\anwend~1\W3i
2010-06-24 08:38:30 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-06-24 08:38:30 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-06-24 08:37:47 0 d—–w- c:\programme\iPod
2010-06-24 08:37:41 0 d—–w- c:\programme\iTunes
2010-06-24 08:37:41 0 d—–w- c:\dokume~1\alluse~1\anwend~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-24 08:35:21 0 d—–w- c:\programme\Bonjour
2010-06-24 08:30:22 0 d—–w- c:\dokume~1\alluse~1\anwend~1\Electronic Arts
2010-06-17 07:08:59 33280 —-a-w- c:\windows\system32\PsisRndr.ax
2010-06-17 07:08:59 33280 —-a-w- c:\windows\system32\dllcache\psisrndr.ax
2010-06-17 07:08:54 18432 —-a-w- c:\windows\system32\dllcache\bdaplgin.ax
2010-06-17 07:08:54 18432 —-a-w- c:\windows\system32\BdaPlgIn.ax
2010-06-17 06:22:12 0 d—–w- c:\dokume~1\robert\anwend~1\MAGIX
2010-06-17 06:21:56 245760 —-a-w- c:\windows\system32\mp4sds32.ax
2010-06-17 06:21:55 420240 —-a-w- c:\windows\system32\mpg4c32.dll
2010-06-17 06:21:43 309616 —-a-w- c:\windows\system32\wmv8dmod.dll
2010-06-17 06:20:49 0 d—–w- c:\programme\gemeinsame dateien\MAGIX Shared
2010-06-17 06:19:24 0 d—–w- c:\dokume~1\alluse~1\anwend~1\MAGIX
2010-06-17 06:18:50 120200 —-a-w- c:\windows\system32\DLLDEV32i.dll
2010-06-17 06:18:50 0 d—–w- c:\programme\MAGIX
2010-06-17 06:16:31 7119 —-a-w- c:\windows\mgxoschk.ini
2010-06-17 06:16:31 700416 —-a-w- c:\windows\system32\mgxoschk.dll
2010-06-17 06:16:31 0 d—–w- c:\windows\system32\MAGIX
2010-06-17 06:12:56 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-06-17 06:12:56 60032 —-a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-06-15 18:06:40 0 d—–w- c:\programme\Ares
2010-06-11 18:54:14 330 —-a-w- c:\windows\MyHeritage.INI
2010-06-11 18:52:25 0 d—–w- c:\dokume~1\robert\anwend~1\MyHeritage
2010-06-11 18:52:25 0 d—–w- c:\dokume~1\alluse~1\anwend~1\MyHeritage
2010-06-11 18:42:29 0 d—–w- c:\programme\Family Toolbar
2010-06-11 18:42:23 454656 —-a-w- c:\windows\system32\PaintX.dll
2010-06-11 18:42:23 372736 —-a-w- c:\windows\system32\ijl15.dll
2010-06-11 18:42:23 137000 —-a-w- c:\windows\system32\msmapi32.ocx
2010-06-11 18:42:23 0 d—–w- c:\dokume~1\robert\anwend~1\The Complete Genealogy Reporter - FTB
2010-06-11 18:36:39 0 d—–w- c:\programme\MyHeritage
2010-06-11 16:35:15 0 d—–w- c:\dokumente und einstellungen\robert\.freemind
2010-06-11 16:35:03 0 d—–w- c:\programme\FreeMind
2010-06-11 11:57:30 0 d—–w- C:\ProgramData
2010-06-11 10:29:24 0 d—–w- c:\programme\gemeinsame dateien\Adobe AIR
2010-06-11 05:28:32 65536 ——w- c:\windows\system32\dllcache\asycfilt.dll
2010-06-10 04:29:14 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-09 17:00:43 0 d—–w- c:\programme\ConvertHelper
2010-06-04 15:51:57 0 d—–w- c:\programme\Guitar Pro 5

==================== Find3M ====================

2010-06-28 13:39:56 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2010-06-24 09:08:06 96900 —-a-w- c:\windows\system32\perfc007.dat
2010-06-24 09:08:06 497718 —-a-w- c:\windows\system32\perfh007.dat
2010-06-20 10:24:56 5848 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-17 19:41:32 53368 —ha-w- c:\windows\system32\mlfcache.dat
2010-06-02 14:54:48 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-18 14:35:16 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-05-18 14:35:16 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-05-05 13:30:57 173056 ——w- c:\windows\system32\dllcache\ie4uinit.exe
2010-05-02 08:05:54 1851392 ——w- c:\windows\system32\win32k.sys
2010-05-02 08:05:54 1851392 ——w- c:\windows\system32\dllcache\win32k.sys
2010-04-20 05:29:56 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-20 05:29:56 285696 ——w- c:\windows\system32\dllcache\atmfd.dll
2010-04-12 15:29:19 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-04-06 02:52:46 2462720 ——w- c:\windows\system32\dllcache\WMVCore.dll

============= FINISH: 13:14:58,76 ===============
Hi,

Upload c:\windows\system32\kernel32.dll file to http://www.virustotal.com and post back the results/link to the results.
Hi,

Get update 9.3.3 for Adobe Reader here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here.

Uninstall this vulnerable Java:
Java™ 6 Update 7


Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


Post back its report & a fresh dds.txt log.
KAS.txt

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, July 1, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, July 01, 2010 11:43:04
Records in database: 4262214
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
Q:\

Scan statistics:
Objects scanned: 206861
Threats found: 1
Infected objects found: 2
Suspicious objects found: 0
Scan duration: 04:46:07


File name / Threat / Threats count
C:\Installationsdateien\neuer computer\vnc-3.3.7-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c 2

Selected area has been scanned.


dds.txt


DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 22:40:35,40 on 01.07.2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.2039.949 [GMT 2:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programme\idt\wdm\STacSV.exe
svchost.exe
C:\Programme\LSI SoftModem\agrsmsvc.exe
C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programme\Bonjour\mDNSResponder.exe
C:\Programme\Java\jre6\bin\jqs.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programme\PDF Complete\pdfsvc.exe
C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Programme\Microsoft Application Virtualization Client\sftvsa.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\mqsvc.exe
C:\Programme\Microsoft Application Virtualization Client\sftlist.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\AESTFltr.exe
C:\Programme\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Programme\Hp\HP Software Update\HPWuSchd2.exe
C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe
C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe
C:\Programme\dvd43\dvd43_tray.exe
C:\Programme\SweetIM\Messenger\SweetIM.exe
C:\Programme\Gemeinsame Dateien\Nokia\MPlatform\NokiaMServer.exe
C:\Programme\Brother\ControlCenter3\brccMCtl.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programme\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Programme\Hewlett-Packard\Shared\hpqToaster.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Virtualization Handler\CVH.EXE
Q:\140062.deu\OFFICE14\OUTLOOK.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe
C:\Programme\iPod\bin\iPodService.exe
C:\Programme\DivX\DivX Update\DivXUpdate.exe
C:\Programme\Brother\Brmfcmon\BrMfimon.exe
C:\Programme\iTunes\iTunes.exe
C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\distnoted.exe
C:\Programme\AVG\AVG9\avgchsvx.exe
C:\Programme\AVG\AVG9\avgwdsvc.exe
C:\Programme\AVG\AVG9\avgnsx.exe
C:\Programme\AVG\AVG9\avgrsx.exe
C:\Programme\AVG\AVG9\avgcsrvx.exe
C:\Programme\Safari\Safari.exe
C:\Dokumente und Einstellungen\Robert\Desktop\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://search.myheritage.com
mStart Page = hxxp://search.myheritage.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
uURLSearchHooks: H - No File
uURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\programme\family toolbar\tbhelper.dll
BHO: MHTBPos00 Class: {0c37b053-fd68-456a-82e1-d788ee342e6f} - c:\programme\family toolbar\tbcore3.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programme\gemeinsame dateien\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\programme\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\programme\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\programme\java\jre6\bin\ssv.dll
BHO: Windows Live Anmelde-Hilfsprogramm: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programme\gemeinsame dateien\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programme\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\programme\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programme\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} - No File
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\programme\windows live\toolbar\wltcore.dll
TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\programme\styler\tb\StylerTB.dll
TB: Family Toolbar: {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - c:\programme\family toolbar\tbcore3.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
uRun: [CursorXP] "c:\program files\cursorxp\CursorXP.exe" -s
uRun: [T3Desk] c:\programme\t3desk\T3Desk.exe
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [IAAnotif] c:\programme\intel\intel matrix storage manager\iaanotif.exe
mRun: [PDF Complete] c:\programme\pdf complete\pdfsty.exe
mRun: [SynTPEnh] c:\programme\synaptics\syntp\SynTPEnh.exe
mRun: [WirelessAssistant] c:\programme\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [HP Software Update] c:\programme\hp\hp software update\HPWuSchd2.exe
mRun: [zCpqset] c:\programme\hewlett-packard\default settings\cpqset.exe
mRun: [HPCam_Menu] "c:\programme\hewlett-packard\hp webcam\muitransfer\muistartmenu.exe" "c:\programme\hewlett-packard\hp webcam" updatewithcreateonce "software\cyberlink\hp webcam\1.0"
mRun: [Adobe Reader Speed Launcher] "c:\programme\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\programme\gemeinsame dateien\adobe\arm\1.0\AdobeARM.exe"
mRun: [Google Desktop Search] "c:\programme\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [SSBkgdUpdate] "c:\programme\gemeinsame dateien\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\programme\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\programme\scansoft\paperport\IndexSearch.exe
mRun: [BrMfcWnd] c:\programme\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [dvd43] c:\programme\dvd43\dvd43_tray.exe
mRun: [SweetIM] c:\programme\sweetim\messenger\SweetIM.exe
mRun: [NokiaMServer] c:\programme\gemeinsame dateien\nokia\mplatform\NokiaMServer /watchfiles startup
mRun: [TrayServer] c:\programme\magix\filme_auf_dvd_7_terratec_edition\TrayServer.exe
mRun: [ControlCenter3] c:\programme\brother\controlcenter3\brctrcen.exe /autorun
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [QlbCtrl.exe] c:\programme\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [RemoteControl] c:\programme\cyberlink\powerdvd\PDVDServ.exe
mRun: [SunJavaUpdateSched] "c:\programme\java\jre6\bin\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\dokume~1\alluse~1\startm~1\progra~1\autost~1\bttray.lnk - c:\programme\widcomm\bluetooth software\BTTray.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Nach Microsoft &Excel exportieren - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: Senden an &Bluetooth-Gerät… - c:\programme\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Senden an Bluetooth - c:\programme\widcomm\bluetooth software\btsendto_ie.htm
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB}
IE: {88EB38EF-4D2C-436D-ABD3-56B232674062} - c:\programme\icq7.0\ICQ.exe
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\programme\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programme\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC} - c:\programme\java\jre6\bin\jp2iexp.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\programme\windows live\writer\WriterBrowserExtension.dll
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\programme\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\programme\windows desktop search\MSNLNamespaceMgr.dll

================= FIREFOX ===================

FF - ProfilePath - c:\dokume~1\robert\anwend~1\mozilla\firefox\profiles\7kjm7c80.default\
FF - prefs.js: browser.search.selectedEngine - Suchen
FF - prefs.js: browser.startup.homepage - hxxp://search.myheritage.com/
FF - prefs.js: keyword.URL - hxxp://search.myheritage.com/?orig=ds&q=
FF - component: c:\programme\nokia\nokia ovi suite\connectors\bookmarks connector\firefoxextension\components\FirefoxExtension.dll
FF - plugin: c:\programme\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\programme\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\programme\google\picasa3\npPicasa3.dll
FF - plugin: c:\programme\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\programme\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\programme\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\programme\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\programme\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programme\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\programme\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\programme\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\programme\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\programme\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\programme\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-3 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-2-3 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-3 242896]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-5-11 213768]
R2 avg9wd;AVG Free WatchDog;c:\programme\avg\avg9\avgwdsvc.exe [2010-3-15 308064]
R2 cvhsvc;Client Virtualization Handler;c:\programme\gemeinsame dateien\microsoft shared\virtualization handler\CVHSVC.EXE [2009-9-26 819600]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-2-22 54752]
R2 pdfcDispatcher;PDF Document Manager;c:\programme\pdf complete\pdfsvc.exe [2009-5-11 777240]
R2 sftlist;Application Virtualization Client;c:\programme\microsoft application virtualization client\sftlist.exe [2009-9-23 447832]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2009-2-18 113536]
R3 osppsvc;Office Software Protection Platform;c:\programme\gemeinsame dateien\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2009-9-26 4639136]
R3 sftfs;sftfs;c:\programme\microsoft application virtualization client\drivers\SftFSXP.sys [2009-9-23 543064]
R3 sftplay;sftplay;c:\programme\microsoft application virtualization client\drivers\sftplayxp.sys [2009-9-23 190312]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [2009-9-23 21864]
R3 sftvol;sftvol;c:\programme\microsoft application virtualization client\drivers\SftVolXP.sys [2009-9-23 14680]
R3 sftvsa;Application Virtualization Service Agent;c:\programme\microsoft application virtualization client\sftvsa.exe [2009-9-23 203608]
S2 0056061265194115mcinstcleanup;McAfee Application Installer Cleanup (0056061265194115);c:\dokume~1\robert\lokale~1\temp\005606~1.exe c:\progra~1\gemein~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service –> c:\dokume~1\robert\lokale~1\temp\005606~1.exe c:\progra~1\gemein~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]
S2 gupdate;Google Update Service (gupdate);c:\programme\google\update\GoogleUpdate.exe [2010-2-13 135664]
S3 Com4QLBEx;Com4QLBEx;c:\programme\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-5-11 209464]
S3 cpudrv;cpudrv;c:\programme\systemrequirementslab\cpudrv.sys [2009-12-18 11336]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\programme\magix\common\database\bin\fbserver.exe [2010-6-17 1527900]
S3 fsssvc;Windows Live Family Safety-Dienst;c:\programme\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\programme\google\google desktop search\GoogleDesktop.exe [2010-2-3 30192]
S3 MfeAVFK;McAfee Inc. MfeAVFK;c:\windows\system32\drivers\mfeavfk.sys [2009-5-11 79880]
S3 MfeBOPK;McAfee Inc. MfeBOPK;c:\windows\system32\drivers\mfebopk.sys [2009-5-11 35272]
S3 MfeRKDK;McAfee Inc. MfeRKDK;c:\windows\system32\drivers\mferkdk.sys [2009-5-11 34216]

=============== Created Last 30 ================

2010-06-28 11:44:10 0 d—–w- c:\programme\CCleaner
2010-06-28 11:29:27 0 d—–w- c:\dokume~1\robert\anwend~1\GlarySoft
2010-06-28 11:23:14 0 d—–w- c:\programme\Glary Utilities
2010-06-28 10:45:05 0 d—–w- c:\programme\T3Desk
2010-06-28 07:55:49 0 d-sha-r- C:\cmdcons
2010-06-28 07:50:56 98816 —-a-w- c:\windows\sed.exe
2010-06-28 07:50:56 77312 —-a-w- c:\windows\MBR.exe
2010-06-28 07:50:56 256512 —-a-w- c:\windows\PEV.exe
2010-06-28 07:50:56 161792 —-a-w- c:\windows\SWREG.exe
2010-06-25 09:37:04 0 d—–w- c:\programme\Microsoft CAPICOM 2.1.0.2
2010-06-24 10:06:39 0 d—–w- C:\Desktop
2010-06-24 10:06:03 0 d—–w- c:\programme\Trend Micro
2010-06-24 09:40:45 367447 —-a-w- C:\lma_log.html
2010-06-24 09:35:17 0 d—–w- c:\programme\W3i, LLC
2010-06-24 09:34:20 0 d—–w- c:\programme\W3i
2010-06-24 09:34:20 0 d—–w- c:\dokume~1\alluse~1\anwend~1\W3i
2010-06-24 08:38:30 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-06-24 08:38:30 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-06-24 08:37:47 0 d—–w- c:\programme\iPod
2010-06-24 08:37:41 0 d—–w- c:\programme\iTunes
2010-06-24 08:37:41 0 d—–w- c:\dokume~1\alluse~1\anwend~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-24 08:35:21 0 d—–w- c:\programme\Bonjour
2010-06-24 08:30:22 0 d—–w- c:\dokume~1\alluse~1\anwend~1\Electronic Arts
2010-06-17 07:08:59 33280 —-a-w- c:\windows\system32\PsisRndr.ax
2010-06-17 07:08:59 33280 —-a-w- c:\windows\system32\dllcache\psisrndr.ax
2010-06-17 07:08:54 18432 —-a-w- c:\windows\system32\dllcache\bdaplgin.ax
2010-06-17 07:08:54 18432 —-a-w- c:\windows\system32\BdaPlgIn.ax
2010-06-17 06:22:12 0 d—–w- c:\dokume~1\robert\anwend~1\MAGIX
2010-06-17 06:21:56 245760 —-a-w- c:\windows\system32\mp4sds32.ax
2010-06-17 06:21:55 420240 —-a-w- c:\windows\system32\mpg4c32.dll
2010-06-17 06:21:43 309616 —-a-w- c:\windows\system32\wmv8dmod.dll
2010-06-17 06:20:49 0 d—–w- c:\programme\gemeinsame dateien\MAGIX Shared
2010-06-17 06:19:24 0 d—–w- c:\dokume~1\alluse~1\anwend~1\MAGIX
2010-06-17 06:18:50 120200 —-a-w- c:\windows\system32\DLLDEV32i.dll
2010-06-17 06:18:50 0 d—–w- c:\programme\MAGIX
2010-06-17 06:16:31 7119 —-a-w- c:\windows\mgxoschk.ini
2010-06-17 06:16:31 700416 —-a-w- c:\windows\system32\mgxoschk.dll
2010-06-17 06:16:31 0 d—–w- c:\windows\system32\MAGIX
2010-06-17 06:12:56 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-06-17 06:12:56 60032 —-a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-06-15 18:06:40 0 d—–w- c:\programme\Ares
2010-06-11 18:54:14 330 —-a-w- c:\windows\MyHeritage.INI
2010-06-11 18:52:25 0 d—–w- c:\dokume~1\robert\anwend~1\MyHeritage
2010-06-11 18:52:25 0 d—–w- c:\dokume~1\alluse~1\anwend~1\MyHeritage
2010-06-11 18:42:29 0 d—–w- c:\programme\Family Toolbar
2010-06-11 18:42:23 454656 —-a-w- c:\windows\system32\PaintX.dll
2010-06-11 18:42:23 372736 —-a-w- c:\windows\system32\ijl15.dll
2010-06-11 18:42:23 137000 —-a-w- c:\windows\system32\msmapi32.ocx
2010-06-11 18:42:23 0 d—–w- c:\dokume~1\robert\anwend~1\The Complete Genealogy Reporter - FTB
2010-06-11 18:36:39 0 d—–w- c:\programme\MyHeritage
2010-06-11 16:35:15 0 d—–w- c:\dokumente und einstellungen\robert\.freemind
2010-06-11 16:35:03 0 d—–w- c:\programme\FreeMind
2010-06-11 11:57:30 0 d—–w- C:\ProgramData
2010-06-11 10:29:24 0 d—–w- c:\programme\gemeinsame dateien\Adobe AIR
2010-06-11 05:28:32 65536 ——w- c:\windows\system32\dllcache\asycfilt.dll
2010-06-10 04:29:14 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-09 17:00:43 0 d—–w- c:\programme\ConvertHelper
2010-06-04 15:51:57 0 d—–w- c:\programme\Guitar Pro 5

==================== Find3M ====================

2010-06-28 13:39:56 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2010-06-24 09:08:06 96900 —-a-w- c:\windows\system32\perfc007.dat
2010-06-24 09:08:06 497718 —-a-w- c:\windows\system32\perfh007.dat
2010-06-20 10:24:56 5848 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-17 19:41:32 53368 —ha-w- c:\windows\system32\mlfcache.dat
2010-06-02 14:54:48 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-18 14:35:16 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-05-18 14:35:16 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-05-05 13:30:57 173056 ——w- c:\windows\system32\dllcache\ie4uinit.exe
2010-05-02 08:05:54 1851392 ——w- c:\windows\system32\win32k.sys
2010-05-02 08:05:54 1851392 ——w- c:\windows\system32\dllcache\win32k.sys
2010-04-20 05:29:56 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-20 05:29:56 285696 ——w- c:\windows\system32\dllcache\atmfd.dll
2010-04-12 15:29:19 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-04-06 02:52:46 2462720 ——w- c:\windows\system32\dllcache\WMVCore.dll

============= FINISH: 22:41:15,81 ===============


attach.txt


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 02.02.2010 13:58:39
System Uptime: 30.06.2010 23:32:16 (23 hours ago)

Motherboard: Hewlett-Packard | | 308A
Processor: Intel® Core™2 Duo CPU T5870 @ 2.00GHz | U10 | 1575/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 26,034 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia 3110c
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 3110c
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd

==== System Restore Points ===================

RP158: 02.04.2010 21:32:09 - Systemprüfpunkt
RP159: 05.04.2010 14:51:24 - Systemprüfpunkt
RP160: 08.04.2010 17:42:18 - Avg Update
RP161: 09.04.2010 20:08:42 - Installation eines unsignierten Treibers
RP162: 14.04.2010 17:52:47 - Software Distribution Service 3.0
RP163: 15.04.2010 16:19:04 - Software Distribution Service 3.0
RP164: 16.04.2010 20:52:40 - Systemprüfpunkt
RP165: 17.04.2010 09:40:31 - TubeBox! wird installiert
RP166: 17.04.2010 15:28:52 - TubeBox! wird entfernt
RP167: 20.04.2010 16:57:37 - Avg Update
RP168: 20.04.2010 16:59:58 - Avg Update
RP169: 02.05.2010 14:49:11 - Systemprüfpunkt
RP170: 02.05.2010 20:26:11 - TubeBox! wird installiert
RP171: 03.05.2010 19:35:49 - Entfernt DIE SIEDLER - Das Erbe der Könige
RP172: 03.05.2010 19:38:24 - Removed Microsoft Games for Windows - LIVE
RP173: 03.05.2010 19:40:08 - Removed Microsoft Games for Windows - LIVE Redistributable
RP174: 03.05.2010 19:43:37 - Nokia Connectivity Cable Driver wird entfernt
RP175: 03.05.2010 19:44:57 - Removed Nokia Ovi Suite Software Updater.
RP176: 03.05.2010 19:45:32 - Removed Nokia Software Updater.
RP177: 03.05.2010 19:51:05 - TubeBox! wird entfernt
RP178: 05.05.2010 16:31:44 - Avg Update
RP179: 06.05.2010 19:36:31 - Systemprüfpunkt
RP180: 08.05.2010 19:13:22 - Installiert SPORE™
RP181: 08.05.2010 19:33:52 - Installiert EA Download Manager
RP182: 09.05.2010 11:13:02 - Gothic 3 wird installiert
RP183: 09.05.2010 11:13:30 - Gothic 3 wird installiert
RP184: 10.05.2010 16:56:44 - Systemprüfpunkt
RP185: 11.05.2010 16:22:49 - Installed Java™ 6 Update 20
RP186: 12.05.2010 17:28:11 - Software Distribution Service 3.0
RP187: 14.05.2010 12:13:16 - Systemprüfpunkt
RP188: 15.05.2010 18:12:06 - Systemprüfpunkt
RP189: 16.05.2010 19:47:37 - Systemprüfpunkt
RP190: 18.05.2010 19:34:52 - Systemprüfpunkt
RP191: 20.05.2010 09:27:37 - Systemprüfpunkt
RP192: 21.05.2010 15:15:41 - Systemprüfpunkt
RP193: 22.05.2010 15:24:36 - Systemprüfpunkt
RP194: 26.05.2010 16:02:43 - Software Distribution Service 3.0
RP195: 30.05.2010 14:41:56 - Systemprüfpunkt
RP196: 01.06.2010 17:43:35 - Systemprüfpunkt
RP197: 02.06.2010 16:55:15 - Avg Update
RP198: 03.06.2010 18:51:38 - Systemprüfpunkt
RP199: 04.06.2010 17:36:55 - Software Distribution Service 3.0
RP200: 06.06.2010 19:58:14 - Systemprüfpunkt
RP201: 08.06.2010 18:35:48 - Systemprüfpunkt
RP202: 11.06.2010 07:28:29 - Software Distribution Service 3.0
RP203: 11.06.2010 13:07:00 - Software Distribution Service 3.0
RP204: 11.06.2010 13:57:18 - Installiert EA Link
RP205: 17.06.2010 09:08:52 - Installation eines unsignierten Treibers
RP206: 19.06.2010 18:47:17 - Systemprüfpunkt
RP207: 23.06.2010 14:13:50 - Software Distribution Service 3.0
RP208: 23.06.2010 19:19:55 - Removed Alt-Tab Task Switcher Powertoy for Windows XP
RP209: 23.06.2010 19:38:42 - Removed ClearType Tuning Control Panel Applet
RP210: 23.06.2010 19:40:08 - Removed LightScribe System Software.
RP211: 23.06.2010 19:40:26 - Removed Magnifier Powertoy for Windows XP
RP212: 23.06.2010 19:41:47 - QuickTime wird entfernt
RP213: 23.06.2010 19:45:11 - Seven Remix XP 2.31: Uninstallation
RP214: 24.06.2010 08:53:07 - iTunes wird entfernt
RP215: 24.06.2010 08:57:30 - Seven Remix XP 2.31: Uninstallation
RP216: 24.06.2010 09:21:00 - Removed SweetIM Toolbar for Internet Explorer 3.6
RP217: 24.06.2010 09:34:05 - Removed Virtual Desktop Manager Powertoy for Windows XP
RP218: 24.06.2010 10:37:33 - iTunes wird installiert
RP219: 24.06.2010 10:45:34 - Safari wird installiert
RP220: 24.06.2010 11:03:26 - Software Distribution Service 3.0
RP221: 24.06.2010 12:27:35 - Installed HiJackThis
RP222: 24.06.2010 12:28:56 - Removed HiJackThis
RP223: 24.06.2010 12:29:37 - Installed HiJackThis
RP224: 25.06.2010 11:24:48 - Avg Update
RP225: 25.06.2010 11:36:43 - Software Distribution Service 3.0
RP226: 28.06.2010 09:51:09 - ComboFix created restore point
RP227: 28.06.2010 15:25:15 - Software Distribution Service 3.0
RP228: 30.06.2010 20:16:12 - Systemprüfpunkt
RP229: 01.07.2010 16:27:21 - Removed Java™ 6 Update 7
RP230: 01.07.2010 16:29:29 - Removed Living Marine Aquarium 2

==== Installed Programs ======================

Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.3 - Deutsch
Any DVD Converter Professional 4.0.5
Any Video Converter 3.0.1
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ares 2.1.5
Atlantica Online
AVG Free 9.0
AVS Media Player 3.1
Bonjour
Brother MFL-Pro Suite
CCleaner
ConvertHelper 2.2
CursorXP
Die Siedler II - Die nächste Generation
DivX-Setup
DivX Plus DirectShow Filters
DVD43 v4.6.0
DynaGeo 2.6e
EA Download Manager
EA Download Manager UI
EA Link
Firebird SQL Server - MAGIX Edition
FreeMind
Gigaflat
Glary Utilities 2.23.0.923
Google Desktop
Google Earth
Google Update Helper
Gothic 3
Guitar Pro 5.2
Hotfix für Windows Media Player 11 (KB939683)
Hotfix für Windows XP (KB938759)
Hotfix für Windows XP (KB942288-v3)
Hotfix für Windows XP (KB949764)
Hotfix für Windows XP (KB952287)
Hotfix für Windows XP (KB953955)
Hotfix für Windows XP (KB961118)
Hotfix für Windows XP (KB976098-v2)
Hotfix für Windows XP (KB979306)
Hotfix für Windows XP (KB981793)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
HP Common Access Service Library
HP Help and Support
HP Integrated Module with Bluetooth wireless technology
HP Quick Launch Buttons 6.50 A1
HP Software Setup
HP Update
HP User Guides 0140
HP Webcam
HP Wireless Assistant
ICQ7
IDT Audio
InstallIQ Updater
Intel® Graphics Media Accelerator Driver
Intel® Matrix Storage Manager
iTunes
Java Auto Updater
Java™ 6 Update 20
Junk Mail filter update
MAGIX Filme auf DVD TerraTec Edition [removed] (D)
MAGIX Online Druck Service [removed] (D)
MAGIX Screenshare 4.3.6.1987 (D)
MFC RunTime files
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 German Language Pack
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Language Pack - DEU
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office Click-to-Run 2010 (Beta)
Microsoft Office Home and Business 2010 (Beta) - Deutsch
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.7
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.6.3)
Mp3tag v2.46a
MSN
MSVC80_x86_v2
MSVC90_x86
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
MyHeritage Family Tree Builder
Nero OEM
Nero Suite
Nokia Ovi Suite
Ovi Desktop Sync Engine
OviMPlatform
PaperPort
PC Connectivity Solution
PDF Complete
Picasa 3
PowerDVD
QuickTime
Roxio Activation Module
Roxio Creator Business
Safari
Security Update for CAPICOM (KB931906)
Security Update for Windows Search 4 - KB963093
Segoe UI
Seven Remix XP 2.31
Sicherheitsupdate für Step by Step Interactive Training (KB923723)
Sicherheitsupdate für Windows Internet Explorer 8 (KB971961)
Sicherheitsupdate für Windows Internet Explorer 8 (KB978207)
Sicherheitsupdate für Windows Internet Explorer 8 (KB981332)
Sicherheitsupdate für Windows Internet Explorer 8 (KB982381)
Sicherheitsupdate für Windows Media Player (KB952069)
Sicherheitsupdate für Windows Media Player (KB954155)
Sicherheitsupdate für Windows Media Player (KB968816)
Sicherheitsupdate für Windows Media Player (KB973540)
Sicherheitsupdate für Windows Media Player (KB978695)
Sicherheitsupdate für Windows Media Player 11 (KB954154)
Sicherheitsupdate für Windows XP (KB923561)
Sicherheitsupdate für Windows XP (KB941569)
Sicherheitsupdate für Windows XP (KB946648)
Sicherheitsupdate für Windows XP (KB950762)
Sicherheitsupdate für Windows XP (KB950974)
Sicherheitsupdate für Windows XP (KB951066)
Sicherheitsupdate für Windows XP (KB951376-v2)
Sicherheitsupdate für Windows XP (KB951748)
Sicherheitsupdate für Windows XP (KB952004)
Sicherheitsupdate für Windows XP (KB952954)
Sicherheitsupdate für Windows XP (KB956572)
Sicherheitsupdate für Windows XP (KB956744)
Sicherheitsupdate für Windows XP (KB956802)
Sicherheitsupdate für Windows XP (KB956803)
Sicherheitsupdate für Windows XP (KB956844)
Sicherheitsupdate für Windows XP (KB957097)
Sicherheitsupdate für Windows XP (KB958644)
Sicherheitsupdate für Windows XP (KB958687)
Sicherheitsupdate für Windows XP (KB958869)
Sicherheitsupdate für Windows XP (KB959426)
Sicherheitsupdate für Windows XP (KB960225)
Sicherheitsupdate für Windows XP (KB960803)
Sicherheitsupdate für Windows XP (KB960859)
Sicherheitsupdate für Windows XP (KB961501)
Sicherheitsupdate für Windows XP (KB969059)
Sicherheitsupdate für Windows XP (KB969947)
Sicherheitsupdate für Windows XP (KB970238)
Sicherheitsupdate für Windows XP (KB970430)
Sicherheitsupdate für Windows XP (KB971468)
Sicherheitsupdate für Windows XP (KB971486)
Sicherheitsupdate für Windows XP (KB971557)
Sicherheitsupdate für Windows XP (KB971633)
Sicherheitsupdate für Windows XP (KB971657)
Sicherheitsupdate für Windows XP (KB972270)
Sicherheitsupdate für Windows XP (KB973354)
Sicherheitsupdate für Windows XP (KB973507)
Sicherheitsupdate für Windows XP (KB973525)
Sicherheitsupdate für Windows XP (KB973869)
Sicherheitsupdate für Windows XP (KB973904)
Sicherheitsupdate für Windows XP (KB974112)
Sicherheitsupdate für Windows XP (KB974318)
Sicherheitsupdate für Windows XP (KB974392)
Sicherheitsupdate für Windows XP (KB974571)
Sicherheitsupdate für Windows XP (KB975025)
Sicherheitsupdate für Windows XP (KB975467)
Sicherheitsupdate für Windows XP (KB975560)
Sicherheitsupdate für Windows XP (KB975561)
Sicherheitsupdate für Windows XP (KB975562)
Sicherheitsupdate für Windows XP (KB975713)
Sicherheitsupdate für Windows XP (KB977165-v2)
Sicherheitsupdate für Windows XP (KB977165)
Sicherheitsupdate für Windows XP (KB977816)
Sicherheitsupdate für Windows XP (KB977914)
Sicherheitsupdate für Windows XP (KB978037)
Sicherheitsupdate für Windows XP (KB978251)
Sicherheitsupdate für Windows XP (KB978262)
Sicherheitsupdate für Windows XP (KB978338)
Sicherheitsupdate für Windows XP (KB978542)
Sicherheitsupdate für Windows XP (KB978601)
Sicherheitsupdate für Windows XP (KB978706)
Sicherheitsupdate für Windows XP (KB979309)
Sicherheitsupdate für Windows XP (KB979482)
Sicherheitsupdate für Windows XP (KB979559)
Sicherheitsupdate für Windows XP (KB979683)
Sicherheitsupdate für Windows XP (KB980195)
Sicherheitsupdate für Windows XP (KB980218)
Sicherheitsupdate für Windows XP (KB980232)
SMAC 2.0
Sonic CinePlayer Decoder Pack
SPORE™
SweetIM for Messenger 3.0
Synaptics Pointing Device Driver
System Requirements Lab for Intel
T3Desk 2010 Build Version 10.06
Update für Windows Internet Explorer 8 (KB976662)
Update für Windows Internet Explorer 8 (KB980182)
Update für Windows XP (KB942763)
Update für Windows XP (KB951978)
Update für Windows XP (KB955759)
Update für Windows XP (KB961503)
Update für Windows XP (KB967715)
Update für Windows XP (KB968389)
Update für Windows XP (KB971737)
Update für Windows XP (KB973687)
Update für Windows XP (KB973815)
Update für Windows XP (KB978207)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.0.5
WebFldrs XP
Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live-Uploadtool
Windows Live Anmelde-Assistent
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Fotogalerie
Windows Live Mail
Windows Live Messenger
Windows Live Sync
Windows Live Toolbar
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
WinRAR
Xvid 1.2.1 final uninstall

==== End Of File ===========================
Good. You may ignore that scanner finding.

Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions.


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE,NOT on a regular basis



Now lets uninstall ComboFix:
  • Click START then RUN
  • Now copy-paste Combofix /uninstall in the runbox and click OK


Please download OTC and save it to desktop.
  • Double-click OTC.exe.
  • Click the CleanUp! button.
  • Select Yes when the
    Begin cleanup Process?
    prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.

Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.


UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.

  • hosts file:
    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
    • This is why using a hosts file is optional!!
    Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here
    If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    • Click the start button (at the lower left hand corner of your screen)
    • Click run
    • In the dialog box, type services.msc
    • hit enter, then locate dns client
    • Highlight it, then double-click it.
    • On the dropdown box, change the setting from automatic to manual.
    • Click ok
  • Run Secunia vulnerability check here and fix its findings.
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
    If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free or Comodo Firewall Pro (If you choose Comodo: Uncheck during installation Install Comodo HopSurf.., Make Comodo my default search provider and Make Comodo Search my homepage and install firewall ONLY!). Both providers have support forums that help with configuration related questions.


Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Once again, please post and tell me how things are going with your system… problems etc.

Have a great day,
Blade B)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI