Problem u.a. mit File preinstt.exe |
||
---|---|---|
#0
| ||
29.08.2004, 15:32
...neu hier
Beiträge: 4 |
||
|
||
29.08.2004, 16:05
Member
Beiträge: 441 |
#2
Hallo,
Das eScan AV Toolkit (mwav.exe) herunterladen, die Datei in den Ordner "c:\Bases" (wichtig !) entpacken und danach die "kavupd.exe" (Update) ausführen. http://www.mwti.net/antivirus/free_utilities.asp Fixe diese Einträge: O2 - BHO: (no name) - {8403CB53-12B3-4537-9DEC-4F12F70A883D} - C:\WINDOWS\SYSTEM\ANTI-PP.DLL O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} - (no file) O9 - Extra button: Microsoft® JavaScript® Console - {7BE6152A-8437-436E-A999-8AE34E6E1838} - (no file) O9 - Extra 'Tools' menuitem: JavaScript Console - {7BE6152A-8437-436E-A999-8AE34E6E1838} - (no file) O9 - Extra button: (no name) - {237AA178-C3BC-4f67-A8BB-D8BC14BA0B89} - (no file) O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} - (no file) (HKCU) O9 - Extra button: Microsoft® JavaScript® Console - {7BE6152A-8437-436E-A999-8AE34E6E1838} - (no file) (HKCU) O9 - Extra 'Tools' menuitem: JavaScript Console - {7BE6152A-8437-436E-A999-8AE34E6E1838} - (no file) (HKCU) O9 - Extra button: (no name) - {237AA178-C3BC-4f67-A8BB-D8BC14BA0B89} - (no file) (HKCU) Wechsle in den abgesicherten Modus und lösche diese Dateien: preinstt.exe => http://www.pestpatrol.com/PestInfo/t/twain-tech.asp C:\WINDOWS\SYSTEM\ANTI-PP.DLL - mit eScan scannen (den Scanner mit der "mwavscan.com" starten. Alle Häkchen setzen und "Scan clean" klicken.) - Neustart - neues Log-File von HiJackThis und die Virus Log Information von eScan posten __________ Das Wertvollste im Leben ist die Zeit. Leben heißt, mit der Zeit richtig umzugehen. Neuaufsetzen des Systems/Absicherung! HJT Anleitung |
|
|
||
29.08.2004, 17:34
...neu hier
Themenstarter Beiträge: 4 |
#3
Danke für Deine Hilfe
[0xfffd1cf3] 29/08/2004 16:24:37:800 :[msvLclnt.dll]ModuleName = C:\BASES\MWAVSCAN.COM [0xfffd1cf3] 29/08/2004 16:24:37:800 :[msvLclnt.dll]Registry Key Deleted Properly!!! [0xfffd1cf3] 29/08/2004 16:24:40:050 :[msvLclnt.dll]Options Set by External applications MWAVSCAN.COM are 9896960 (0x970400): [0xfffd1cf3] 29/08/2004 16:24:40:050 :[msvLclnt.dll]Mode ACKED,ARCHIVED,CA,WARNINGS,MAILPLAIN [0xfffd1cf3] 29/08/2004 16:24:40:050 :[msvLclnt.dll]TimeOut : ffffffff [0xfffd1cf3] 29/08/2004 16:24:40:050 :[msvLclnt.dll]Priority : NORMAL [0xfffd1cf3] 29/08/2004 16:24:40:880 :[msvLclnt.dll]VirusCount = 102371 Latest Date = 2004/08/29 [0xfffc2b23] 29/08/2004 16:36:59:460 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\lfdj.dat infected by Trojan.Win32.Dialer.ce [0xfffc2b23] 29/08/2004 16:36:59:790 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\lfdj.dat infected by Trojan.Win32.Dialer.ce [0xfffc2b23] 29/08/2004 16:37:46:970 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\FLEOK\msbb.exe infected by not-a-virus:AdvWare.180Solutions [0xfffc2b23] 29/08/2004 16:37:47:020 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\FLEOK\msbb.exe infected by not-a-virus:AdvWare.180Solutions [0xfffc2b23] 29/08/2004 16:37:51:470 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\msbb.exe infected by not-a-virus:AdvWare.180Solutions [0xfffc2b23] 29/08/2004 16:37:51:530 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\msbb.exe infected by not-a-virus:AdvWare.180Solutions [0xfffc2b23] 29/08/2004 16:37:51:750 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\msbbhook.dll infected by not-a-virus:AdvWare.180Solutions [0xfffc2b23] 29/08/2004 16:37:51:750 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\msbbhook.dll infected by not-a-virus:AdvWare.180Solutions [0xfffc2b23] 29/08/2004 16:37:52:130 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\cdt_bbi8016.exe infected by not-a-virus:AdvWare.BargainBuddy.a [0xfffc2b23] 29/08/2004 16:37:52:350 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\cdt_bbi8016.exe infected by not-a-virus:AdvWare.BargainBuddy.a [0xfffc2b23] 29/08/2004 16:37:54:600 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\Del81D0.TMP infected by not-a-virus:AdvWare.180Solutions [0xfffc2b23] 29/08/2004 16:37:54:660 :[msvLclnt.dll][00000001] File C:\WINDOWS\TEMP\Del81D0.TMP infected by not-a-virus:AdvWare.180Solutions [0xfffc2b23] 29/08/2004 17:19:45:300 :[msvLclnt.dll][00000001] File D:\des\Rec1\iMusik_Video\Mp3\Meine\WinRAR 2.80.exe infected by not-a-virus:RiskWare.Monitor.Perflogger.k [0xfffc2b23] 29/08/2004 17:19:57:390 :[msvLclnt.dll][00000001] File D:\des\Rec1\Internet\netants110.zip infected by not-a-virus:Tool.Win32.Reboot [0xfffc2b23] 29/08/2004 17:19:58:490 :[msvLclnt.dll][00000001] File D:\des\Rec1\Internet\zonealarm.zip infected by not-a-virus:Tool.Win32.Reboot [0xfffc2b23] 29/08/2004 17:20:28:970 :[msvLclnt.dll][00000001] File D:\des\Rec1\ZIP\wrar280d.exe infected by not-a-virus:RiskWare.Monitor.Perflogger.k [0xfffc2b23] 29/08/2004 17:26:36:370 :[msvLclnt.dll][00000001] File D:\Aktuellste\eig\Installationsdateien\s2k.Ser*hier nicht!*2k7.1.zip infected by not-a-virus:RiskWare.Dialer.gen [0xfffc2b23] 29/08/2004 17:28:07:600 :[msvLclnt.dll][00000001] File D:\Aktuellste\eig\CoffeeView25.exe infected by not-a-virus:Tool.Win32.Reboot [0xfffc2b23] 29/08/2004 17:29:02:520 :[msvLclnt.dll]VirusCount = 102371 Latest Date = 2004/08/29 [0xfffd1cf3] 29/08/2004 17:29:30:430 :[msvLclnt.dll]VirusCount = 102371 Latest Date = 2004/08/29 und Logfile of HijackThis v1.98.2 Scan saved at 17:33:46, on 29.08.2004 Platform: Windows ME (Win9x 4.90.3000) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\SYSTEM\SSDPSRV.EXE C:\WINDOWS\SYSTEM\ATI2EVXX.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\TASKMON.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE C:\PROGRAMME\MOUSEWARE\SYSTEM\EM_EXEC.EXE C:\PROGRAMME\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE C:\PROGRAMME\NORTON ANTIVIRUS\POPROXY.EXE C:\PROGRAMME\T-DSL SPEEDMANAGER\SPEEDMGR.EXE C:\PROGRAMME\NORTON ANTIVIRUS\NAVAPW32.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\ROXIO SHARED\PROJECT SELECTOR\PROJSELECTOR.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\WINDOWS\SYSTEM\LEXBCES.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\REAL\UPDATE_OB\REALSCHED.EXE C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BASIS-SOFTWARE\BASIS1\TOADIMON.EXE C:\PROGRAMME\AVPERSONAL\AVGCTRL.EXE C:\PROGRAMME\MOZILLA1.7\MOZILLA.EXE C:\WINDOWS\SYSTEM\RPCSS.EXE C:\WINDOWS\SYSTEM\DDHELP.EXE C:\PROGRAMME\TRILLIAN\TRILLIAN.EXE C:\WINDOWS\SYSTEM\LEXPPS.EXE C:\WINDOWS\SYSTEM\RNAAPP.EXE C:\WINDOWS\SYSTEM\TAPISRV.EXE C:\PROGRAMME\T-DSL SPEEDMANAGER\TSMSVC.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BASIS-SOFTWARE\BASIS2\KERNEL.EXE C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BASIS-SOFTWARE\BASIS2\SC_WATCH.EXE C:\WINDOWS\SYSTEM\PSTORES.EXE C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BASIS-SOFTWARE\BASIS2\PROFILEMGR.EXE C:\PROGRAMME\WINACE\WINACE.EXE C:\WINDOWS\TEMP\~ACETEMP\HIJACKTHIS\HIJACKTHIS.EXE R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.t-online.de/service/redir/ie_t-online.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMME\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Norton eMail Protect] C:\Programme\Norton AntiVirus\POPROXY.EXE O4 - HKLM\..\Run: [T-DSL SpeedMgr] "C:\PROGRAMME\T-DSL SPEEDMANAGER\SPEEDMGR.EXE" O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET O4 - HKLM\..\Run: [projselector] "C:\Programme\Gemeinsame Dateien\Roxio Shared\Project Selector\projselector.exe" -r O4 - HKLM\..\Run: [LexStart] lexstart.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ToADiMon.exe] C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BASIS-SOFTWARE\BASIS1\ToADiMon.exe -TOnlineAutodialStart O4 - HKLM\..\Run: [AVGCtrl] C:\PROGRAMME\AVPERSONAL\AVGCTRL.EXE /min O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe O4 - HKLM\..\RunServices: [ATIPOLL] ati2evxx.exe O4 - HKLM\..\RunServices: [ATISmart] C:\WINDOWS\SYSTEM\ati2s9ag.exe O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\PROGRA~1\MOZILLA1.7\MOZILLA.EXE" -turbo O4 - Startup: trillian.lnk = C:\PROGRAMME\TRILLIAN\trillian.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL O14 - IERESET.INF: START_PAGE_URL=http://www.t-online.de/service/redir/ie_t-online.htm O16 - DPF: {40BF816B-D862-41B9-9445-ECA36D5F67F7} (Flatcast Viewer 4.10) - http://www.1mal1.com/flatcast/NpFv410.dll |
|
|
||
29.08.2004, 17:48
Member
Beiträge: 441 |
#4
Sieht wieder sauber aus.
Was ist mit der preinstt.exe? __________ Das Wertvollste im Leben ist die Zeit. Leben heißt, mit der Zeit richtig umzugehen. Neuaufsetzen des Systems/Absicherung! HJT Anleitung |
|
|
||
29.08.2004, 17:51
...neu hier
Themenstarter Beiträge: 4 |
#5
Die File ist weg....ich danke Dir ))))))
|
|
|
||
Habe unter anderem Ärger mit der File preinstt.exe (mit doppel T !!!). Kann man die einfach löschen oder ist die wichtig? Ist der Flatcast Viewer wichtig?
Ich hatte neulich das Problem, dass im IE (den ich eh kaum nehm) eine Porno-Suchseite als Start-Seite war. Und wenn ich auf eine Seite wollte hat er das halt blockiert und ich kam wieder auf ne andere Suchseite...aber ich glaub das habsch schon wegge-hijackt :o)
Logfile of HijackThis v1.98.2
Scan saved at 15:29:09, on 29.08.2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAMME\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\PROGRAMME\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
C:\PROGRAMME\NORTON ANTIVIRUS\POPROXY.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAMME\T-DSL SPEEDMANAGER\SPEEDMGR.EXE
C:\PROGRAMME\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAMME\GEMEINSAME DATEIEN\ROXIO SHARED\PROJECT SELECTOR\PROJSELECTOR.EXE
C:\PROGRAMME\GEMEINSAME DATEIEN\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BASIS-SOFTWARE\BASIS1\TOADIMON.EXE
C:\PROGRAMME\AVPERSONAL\AVGCTRL.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAMME\TRILLIAN\TRILLIAN.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAMME\T-DSL SPEEDMANAGER\TSMSVC.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAMME\MOZILLA1.7\MOZILLA.EXE
C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BASIS-SOFTWARE\BASIS2\KERNEL.EXE
C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BASIS-SOFTWARE\BASIS2\SC_WATCH.EXE
C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BASIS-SOFTWARE\BASIS2\PROFILEMGR.EXE
C:\PROGRAMME\OUTLOOK EXPRESS\MSIMN.EXE
C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BASIS-SOFTWARE\BASIS2\TONCHKML32.EXE
C:\PROGRAMME\WINACE\WINACE.EXE
C:\WINDOWS\TEMP\~ACETEMP\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.t-online.de/service/redir/ie_t-online.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
O2 - BHO: (no name) - {8403CB53-12B3-4537-9DEC-4F12F70A883D} - C:\WINDOWS\SYSTEM\ANTI-PP.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMME\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Norton eMail Protect] C:\Programme\Norton AntiVirus\POPROXY.EXE
O4 - HKLM\..\Run: [T-DSL SpeedMgr] "C:\PROGRAMME\T-DSL SPEEDMANAGER\SPEEDMGR.EXE"
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [projselector] "C:\Programme\Gemeinsame Dateien\Roxio Shared\Project Selector\projselector.exe" -r
O4 - HKLM\..\Run: [LexStart] lexstart.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ToADiMon.exe] C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BASIS-SOFTWARE\BASIS1\ToADiMon.exe -TOnlineAutodialStart
O4 - HKLM\..\Run: [AVGCtrl] C:\PROGRAMME\AVPERSONAL\AVGCTRL.EXE /min
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ATIPOLL] ati2evxx.exe
O4 - HKLM\..\RunServices: [ATISmart] C:\WINDOWS\SYSTEM\ati2s9ag.exe
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\PROGRA~1\MOZILLA1.7\MOZILLA.EXE" -turbo
O4 - Startup: trillian.lnk = C:\PROGRAMME\TRILLIAN\trillian.exe
O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} - (no file)
O9 - Extra button: Microsoft® JavaScript® Console - {7BE6152A-8437-436E-A999-8AE34E6E1838} - (no file)
O9 - Extra 'Tools' menuitem: JavaScript Console - {7BE6152A-8437-436E-A999-8AE34E6E1838} - (no file)
O9 - Extra button: (no name) - {237AA178-C3BC-4f67-A8BB-D8BC14BA0B89} - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} - (no file) (HKCU)
O9 - Extra button: Microsoft® JavaScript® Console - {7BE6152A-8437-436E-A999-8AE34E6E1838} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: JavaScript Console - {7BE6152A-8437-436E-A999-8AE34E6E1838} - (no file) (HKCU)
O9 - Extra button: (no name) - {237AA178-C3BC-4f67-A8BB-D8BC14BA0B89} - (no file) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.t-online.de/service/redir/ie_t-online.htm
O16 - DPF: {40BF816B-D862-41B9-9445-ECA36D5F67F7} (Flatcast Viewer 4.10) - http://www.1mal1.com/flatcast/NpFv410.dll
Danke Jungs :o)