|
Plagegeister aller Art und deren Bekämpfung: GVU Version des BKA-TrojanersWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
27.06.2012, 15:42 | #1 |
| GVU Version des BKA-Trojaners Guten Tag, gerade habe ich mir den oben genannten Trojaner eingefangen. Was ein Tronjaner ist weiß ich, aber da hört es bei mir schon auf. Ich bin an meinem Laptop nun über den Gastzugang angemeldet. In meinen eigenen Account komme ich zwar noch rein, allerdings erscheint dann schnell die GVU-Seite. Könnt Ihr mir bei diesem Problem helfen? Ich habe einen Link zu diesem Forum auf der Seite der GVU gefunden. Gruß, Christian |
27.06.2012, 15:59 | #2 |
/// Malware-holic | GVU Version des BKA-Trojaners hi,
__________________Mit einem sauberen 2. Rechner eine OTLPE-CD erstellen und den infizierten Rechner dann von dieser CD booten: Falls Du kein Brennprogramm installiert hast, lade dir bitte ISOBurner herunter. Das Programm wird Dir erlauben, OTLPE auf eine CD zu brennen und sie bootfähig zu machen. Du brauchst das Tool nur zu installieren, der Rest läuft automatisch => Wie brenne ich eine ISO Datei auf CD/DVD. Lade OTLPENet.exe von OldTimer herunter und speichere sie auf Deinem Desktop. Anmerkung: Die Datei ist ca. 120 MB groß und es wird bei langsamer Internet-Verbindung ein wenig dauern, bis Du sie runtergeladen hast.
Bebilderte Anleitung: OTLpe-Scan
__________________ |
27.06.2012, 16:01 | #3 |
| GVU Version des BKA-Trojaners Und ohne Brenner? Habe bloß diesen Laptop und bin hier alleine.
__________________ |
27.06.2012, 16:02 | #4 |
/// Malware-holic | GVU Version des BKA-Trojaners keine freunde bzw bekannte wo man was brennen kann
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
27.06.2012, 16:06 | #5 |
| GVU Version des BKA-Trojaners Freunde und Bekannte ja, aber nicht hier in der nähe. Wie gesagt, bin hier alleine. Eine andere Möglichkeit gibt es nicht?! Verstehe leider garnichts mehr. |
27.06.2012, 16:07 | #6 |
/// Malware-holic | GVU Version des BKA-Trojaners doch gibts, aber umständlicher. Erstellen wir einen bootbaren USB Stick für OTLPE Wichtig: Der USB Stick muss mindestens 512 MB oder mehr haben. Sichere gegebenfalls alle Dateien von dem USB Stick, diese werden nach den folgenden Schritten nicht mehr vorhanden sein.
C:\).
Nun boote von mit der OTLPE USB Stick. Hinweis: Wie boote ich von CD (einfach statt ner CD USB Device auswählen)
__________________ --> GVU Version des BKA-Trojaners |
27.06.2012, 16:27 | #7 |
| GVU Version des BKA-Trojaners Bei dem Punkt "Downloade dir eeepcfr.zip und entpacke die Datei nach Systemroot (meistens C:\)." komme ich leider nicht weiter. Was muss ich dort genau tun? Danke schonmal für die Hilfe. (Hat doch geklappt) |
27.06.2012, 16:33 | #8 |
/// Malware-holic | GVU Version des BKA-Trojaners so wie es da steht, direkt auf c: kopieren und entpacken :-)
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
27.06.2012, 16:36 | #9 |
| GVU Version des BKA-Trojaners Dieses Programm findet leider keinen USB-Stick, obwohl einer drinne steckt. Vielleicht liegt es daran, dass ich das 2. zu installierende Programm auf den Desktop entpackt habe? Auf c konnte ich nicht entpacken, da dort der Zugriff verweigert wurde. Oder vielleicht liegt es daran, dass ich als Gast nichts auf C machen darf? Geändert von Christian_04 (27.06.2012 um 16:42 Uhr) |
27.06.2012, 16:50 | #10 |
/// Malware-holic | GVU Version des BKA-Trojaners hi dann mal nen anderen stick versuchen. falls nicht, musst du doch mal schauen das du die cd irgendwo gebrannt bekommst
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
27.06.2012, 17:41 | #11 |
| GVU Version des BKA-Trojaners Ich habe gerade erfahren, dass ich doch eine Brenner im Laptop habe und mir nun DVDs zum brennen gekauft. Der Laptop ist nun auch schon am brennen. Leider geht es bei 99% nicht weiter (Programmpunkt "Brennen"). Ich warte einfach noch ab. Ich habe nun aber ein anderes Bedenken, selbst wenn es mit dem Brennen nun klappt, versuche ich jeden der einzelnen Schritte weiter zu befolgen, aber ansich ist das für mich sehr sehr kompliziert. Ist das denn der einzige Weg, den Trojaner zu entfernen? |
27.06.2012, 17:44 | #12 |
/// Malware-holic | GVU Version des BKA-Trojaners ja ists warum sollte ichs sonst so schreiben...? dann brenne noch mal, auf langsamster stufe
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
27.06.2012, 18:29 | #13 |
| GVU Version des BKA-Trojaners So, ich habe nun die Datei auf die DVD bekommen und dann den laptop auch von der DVD aus gebootet. Hat nicht geklappt. Der Laptop konnte Windows nicht starten, hat nach dem Fehler gesucht und ihn anscheinend gefunden. Ich habe ihn neu gestartet und nun ist alles wie immer. Der Trojaner erscheint nicht mehr, wenn ich mich mit meinem eigenen Account einlogge. Aber ansich sollte es doch mit dem Punkt weiter gehen, oder?: • Dein System sollte jetzt einen REATOGO-X-PE Desktop anzeigen. |
27.06.2012, 18:34 | #14 |
/// Malware-holic | GVU Version des BKA-Trojaners dann mach dies hier: Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %USERPROFILE%\*.* %USERPROFILE%\Local Settings\Temp\*.exe %USERPROFILE%\Local Settings\Temp\*.dll %USERPROFILE%\Application Data\*.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs CREATERESTOREPOINT
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
27.06.2012, 19:37 | #15 |
| GVU Version des BKA-Trojaners OTL Logfile: Code:
ATTFilter OTL logfile created on: 27.06.2012 20:08:57 - Run 1 OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\Christian\Downloads Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,99 Gb Total Physical Memory | 1,74 Gb Available Physical Memory | 58,08% Memory free 5,99 Gb Paging File | 4,64 Gb Available in Paging File | 77,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 455,99 Gb Total Space | 281,10 Gb Free Space | 61,65% Space Free | Partition Type: NTFS Computer Name: CHRISTIAN-PC | User Name: Christian | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.06.27 19:38:38 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\Christian\Downloads\OTL.exe PRC - [2012.06.20 21:12:23 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2012.06.19 17:32:30 | 003,048,136 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe PRC - [2012.05.14 13:39:49 | 001,816,976 | ---- | M] (Bandoo Media, inc) -- C:\Programme\Searchqu Toolbar\Datamngr\datamngrUI.exe PRC - [2012.05.05 10:29:53 | 000,932,528 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe PRC - [2012.02.23 13:30:40 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Programme\Common Files\Apple\Internet Services\ubd.exe PRC - [2011.07.07 17:42:16 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2011.05.05 17:52:36 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2011.01.28 20:43:54 | 000,181,480 | ---- | M] (Acer Corp.) -- C:\Programme\Acer Arcade Deluxe\PlayMovie\PMVService.exe PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010.08.02 17:09:32 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2010.01.14 23:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2009.11.18 21:41:12 | 000,206,120 | ---- | M] (CyberLink) -- C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe PRC - [2009.11.18 21:41:06 | 000,156,968 | ---- | M] (CyberLink Corp.) -- C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe PRC - [2009.08.27 06:48:32 | 001,194,504 | ---- | M] (Dritek System Inc.) -- C:\Programme\Launch Manager\LManager.exe PRC - [2009.08.18 03:36:36 | 000,348,160 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe PRC - [2009.08.18 03:36:08 | 000,176,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe PRC - [2009.05.20 21:18:32 | 000,075,048 | ---- | M] () -- C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe PRC - [2009.02.26 19:36:46 | 000,030,040 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe PRC - [2008.06.24 17:06:06 | 001,840,424 | ---- | M] (Nero AG) -- C:\Programme\Common Files\Nero\Lib\NMIndexStoreSvr.exe PRC - [2007.02.20 11:07:40 | 000,199,752 | ---- | M] (Pinnacle Systems GmbH) -- C:\Programme\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe ========== Modules (No Company Name) ========== MOD - [2012.06.20 21:12:23 | 002,042,848 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll MOD - [2012.05.05 10:29:53 | 000,932,528 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe MOD - [2011.06.24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2011.06.24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2009.11.18 21:41:14 | 000,873,768 | ---- | M] () -- C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMediaLibrary.dll MOD - [2009.11.18 21:41:08 | 000,013,096 | ---- | M] () -- C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvcPS.dll MOD - [2009.08.16 17:06:02 | 000,141,312 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll ========== Win32 Services (SafeList) ========== SRV - [2012.06.27 19:34:26 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.06.20 21:12:23 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.06.19 17:32:30 | 003,048,136 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service) SRV - [2012.06.05 15:17:44 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2011.07.20 06:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv) SRV - [2011.07.07 17:42:16 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.05.05 17:52:36 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2011.01.28 20:44:12 | 000,241,648 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files\Acer Arcade Deluxe\PlayMovie\NavFilter\kmsvc.exe -- (CLKMSVC10_D20A29D4) SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2009.08.18 03:36:08 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.05.20 21:18:32 | 000,075,048 | ---- | M] () [Auto | Running] -- C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe -- (CLHNService) SRV - [2009.02.26 19:36:22 | 000,064,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service) SRV - [2006.10.26 15:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) SRV - [2005.11.17 14:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Programme\MSI\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | Auto | Stopped] -- system32\DRIVERS\mdmxsdk.sys -- (mdmxsdk) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a4n1sx3x) DRV - [2011.07.07 17:42:16 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2011.07.07 17:42:16 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.09.04 13:39:09 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd) DRV - [2010.06.17 16:27:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.12.10 16:45:04 | 000,027,168 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rrnetcap.sys -- (RRNetCapMP) DRV - [2009.12.10 16:45:04 | 000,027,168 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rrnetcap.sys -- (RRNetCap) DRV - [2009.10.05 16:31:50 | 001,221,632 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2009.08.18 04:48:06 | 004,994,560 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag) DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) DRV - [2009.06.24 12:23:12 | 000,159,776 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtHDMIV.sys -- (RTHDMIAzAudService) DRV - [2009.02.13 13:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio) DRV - [2008.09.04 06:12:56 | 000,223,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\k57nd60x.sys -- (k57nd60x) Broadcom NetLink (TM) DRV - [2006.09.28 11:47:48 | 000,283,776 | ---- | M] (AfaTech ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AF15BDA.sys -- (AF15BDA) DRV - [2005.09.23 22:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MarvinBus.sys -- (MarvinBus) DRV - [2005.02.23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\afc.sys -- (Afc) DRV - [2005.02.11 11:19:20 | 000,055,216 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k750bus.sys -- (k750bus) Sony Ericsson 750 driver (WDM) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0709&m=aspire_5738 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://startsear.ch/?aff=1 IE - HKLM\..\URLSearchHook: - No CLSID value found IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{C6121984-176B-48EC-B82A-0748EC325F06}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.searchnu.com/406 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie IE - HKCU\..\URLSearchHook: - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://startsear.ch/?aff=1&q={searchTerms} IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms} IE - HKCU\..\SearchScopes\{C6121984-176B-48EC-B82A-0748EC325F06}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deDE345 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.115.151:3128 ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Web Search" FF - prefs.js..browser.search.defaultenginename: "Search the web" FF - prefs.js..browser.search.defaulturl: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q=" FF - prefs.js..browser.search.order.1: "Search the web" FF - prefs.js..browser.search.selectedEngine: "Search the web" FF - prefs.js..browser.startup.homepage: "hxxp://www.searchnu.com/406" FF - prefs.js..keyword.URL: "hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q=" FF - prefs.js..network.proxy.ftp: "192.168.115.151" FF - prefs.js..network.proxy.ftp_port: 3128 FF - prefs.js..network.proxy.http: "192.168.115.151" FF - prefs.js..network.proxy.http_port: 3128 FF - prefs.js..network.proxy.no_proxies_on: "localho,t,127.0.0.1,*.local" FF - prefs.js..network.proxy.share_proxy_settings: true FF - prefs.js..network.proxy.socks: "192.168.115.151" FF - prefs.js..network.proxy.socks_port: 3128 FF - prefs.js..network.proxy.ssl: "192.168.115.151" FF - prefs.js..network.proxy.ssl_port: 3128 FF - prefs.js..network.proxy.type: 0 FF - user.js..browser.search.selectedEngine: "Search the web" FF - user.js..browser.search.order.1: "Search the web" FF - user.js..browser.search.defaultenginename: "Search the web" FF - user.js..keyword.URL: "hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q=" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Christian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.20 21:12:24 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.25 13:58:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.05.25 13:58:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012.05.25 13:58:41 | 000,000,000 | ---D | M] [2012.05.20 12:12:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\mozilla\Extensions [2010.08.31 21:51:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012.05.20 12:12:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\qm2uwvnu.default\extensions [2012.03.28 15:40:32 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\qm2uwvnu.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2012.05.20 12:11:55 | 000,000,000 | ---D | M] (Searchqu Toolbar) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\qm2uwvnu.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} [2011.10.29 18:37:20 | 000,000,000 | ---D | M] (toolplugin) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\qm2uwvnu.default\extensions\welcome@toolmin.com [2012.06.26 09:11:45 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\qm2uwvnu.default\searchplugins\icqplugin-1.xml [2011.08.17 23:04:28 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\qm2uwvnu.default\searchplugins\icqplugin-2.xml [2011.08.27 16:32:36 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\qm2uwvnu.default\searchplugins\icqplugin-3.xml [2011.09.08 07:36:05 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\qm2uwvnu.default\searchplugins\icqplugin-4.xml [2011.09.27 18:35:51 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\qm2uwvnu.default\searchplugins\icqplugin-5.xml [2011.10.01 14:46:56 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\qm2uwvnu.default\searchplugins\icqplugin-6.xml [2011.10.29 18:43:09 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\qm2uwvnu.default\searchplugins\icqplugin-7.xml [2011.11.10 19:06:42 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\qm2uwvnu.default\searchplugins\icqplugin-8.xml [2011.03.30 15:14:34 | 000,001,042 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\qm2uwvnu.default\searchplugins\icqplugin.xml [2012.05.20 12:11:50 | 000,002,519 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\qm2uwvnu.default\searchplugins\Search_Results.xml [2011.07.11 20:04:02 | 000,000,633 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\qm2uwvnu.default\searchplugins\startsear.xml [2012.05.20 12:12:03 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2010.01.25 14:06:23 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2012.06.27 20:12:56 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012.06.20 21:12:24 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.10.03 06:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2012.06.20 21:12:20 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.06.20 21:12:20 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.06.20 21:12:20 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.06.20 21:12:20 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2011.10.29 18:37:20 | 000,000,158 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search the web.src [2012.05.20 12:11:50 | 000,002,519 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml [2012.06.20 21:12:20 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.06.20 21:12:20 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2011.05.11 19:30:15 | 000,000,939 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: 127.0.0.1 71i.de O1 - Hosts: 127.0.0.1 adicqserver.71i.de O1 - Hosts: 127.0.0.1 adserver.71i.de O1 - Hosts: 127.0.0.1 im.adtech.de O1 - Hosts: 127.0.0.1 adserver.adtech.de O1 - Hosts: 127.0.0.1 adtech.de O1 - Hosts: 127.0.0.1 atwola.com O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Programme\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll () O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Programme\Searchqu Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Programme\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll () O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-89AF-189327213627} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [ArcadeDeluxeAgent] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink) O4 - HKLM..\Run: [DATAMNGR] C:\Programme\Searchqu Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc) O4 - HKLM..\Run: [LManager] C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.) O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG) O4 - HKLM..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe (OLYMPUS IMAGING CORP.) O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.) O4 - HKLM..\Run: [PLFSetL] C:\Windows\\PLFSetL.exe () O4 - HKLM..\Run: [USBToolTip] C:\Programme\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (Pinnacle Systems GmbH) O4 - HKCU..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.) O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG) O4 - HKCU..\Run: [MobileDocuments] C:\Programme\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.) O4 - HKCU..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe (OLYMPUS IMAGING CORP.) O4 - HKCU..\Run: [Pando Media Booster] C:\Programme\Pando Networks\Media Booster\PMB.exe () O4 - HKCU..\Run: [Spotify] C:\Users\Christian\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Christian\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () O4 - Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.) O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {271A3CF5-5A54-447B-A08F-BE805F0DA60B} https://finanzcenter.sparkasse-bremen.de/_plugin/AXFOAM.cab (B+S Banksysteme AG DDBAC Plug-In) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{73A55C2C-FE56-4A76-9807-28D6E1AEFBC8}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C50B5E64-FEB9-43A5-8D7F-A5168348F856}: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\Datamngr\datamngr.dll) - C:\Programme\Searchqu Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc) O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\Datamngr\IEBHO.dll) - C:\Programme\Searchqu Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O24 - Desktop WallPaper: C:\Users\Christian\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\Christian\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{3145eed7-b819-11df-abf6-001f16b736b0}\Shell - "" = AutoRun O33 - MountPoints2\{3145eed7-b819-11df-abf6-001f16b736b0}\Shell\AutoRun\command - "" = E:\Welcome\Welcome.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.06.25 12:06:01 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Local\Macromedia [2012.06.20 19:34:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2012.06.20 19:33:40 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2012.06.20 19:33:39 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2012.06.20 19:30:29 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\Christian\*.tmp files -> C:\Users\Christian\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.06.27 19:36:02 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.06.27 19:34:28 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.06.27 19:29:49 | 000,010,880 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.06.27 19:29:49 | 000,010,880 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.06.27 19:20:28 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.06.27 19:19:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.06.27 19:19:11 | 2411,855,872 | -HS- | M] () -- C:\hiberfil.sys [2012.06.27 16:20:36 | 004,503,728 | ---- | M] () -- C:\ProgramData\l_0_00_re.pad [2012.06.25 01:56:20 | 000,657,910 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.06.25 01:56:20 | 000,619,146 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.06.25 01:56:20 | 000,131,250 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.06.25 01:56:20 | 000,107,466 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.06.20 21:33:49 | 000,164,907 | R--- | M] () -- C:\Users\Christian\Desktop\festival_timetable_67754.pdf [2012.06.20 13:20:37 | 000,000,444 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Christian.job [2012.06.20 12:41:59 | 000,150,181 | ---- | M] () -- C:\Users\Christian\Desktop\197777_10150906056233732_1079007482_n.jpg [2012.06.17 07:09:32 | 000,000,456 | ---- | M] () -- C:\Windows\tasks\Driver Robot.job [2012.06.15 16:08:47 | 001,635,831 | ---- | M] () -- C:\Users\Christian\Desktop\vmqmol2v.jpg [2012.06.15 12:47:24 | 000,508,888 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.06.09 15:50:22 | 000,453,816 | ---- | M] () -- C:\Users\Christian\Desktop\Schmidt, Christian 12-6-1 sepia.jpg [2012.06.09 15:50:16 | 000,387,822 | ---- | M] () -- C:\Users\Christian\Desktop\Schmidt, Christian 12-6-1 sw.jpg [2012.06.09 15:50:09 | 000,551,394 | ---- | M] () -- C:\Users\Christian\Desktop\Schmidt, Christian 12-6-1.jpg [2012.05.30 20:30:43 | 000,022,058 | ---- | M] () -- C:\Users\Christian\Desktop\592169_419659718066823_959468065_n.jpg [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\Christian\*.tmp files -> C:\Users\Christian\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.06.27 16:04:39 | 004,503,728 | ---- | C] () -- C:\ProgramData\l_0_00_re.pad [2012.06.20 21:33:52 | 000,164,907 | R--- | C] () -- C:\Users\Christian\Desktop\festival_timetable_67754.pdf [2012.06.20 12:41:54 | 000,150,181 | ---- | C] () -- C:\Users\Christian\Desktop\197777_10150906056233732_1079007482_n.jpg [2012.06.15 16:08:41 | 001,635,831 | ---- | C] () -- C:\Users\Christian\Desktop\vmqmol2v.jpg [2012.06.10 22:36:56 | 000,551,394 | ---- | C] () -- C:\Users\Christian\Desktop\Schmidt, Christian 12-6-1.jpg [2012.06.10 22:36:56 | 000,453,816 | ---- | C] () -- C:\Users\Christian\Desktop\Schmidt, Christian 12-6-1 sepia.jpg [2012.06.10 22:36:56 | 000,387,822 | ---- | C] () -- C:\Users\Christian\Desktop\Schmidt, Christian 12-6-1 sw.jpg [2012.05.30 20:30:43 | 000,022,058 | ---- | C] () -- C:\Users\Christian\Desktop\592169_419659718066823_959468065_n.jpg [2012.05.12 17:22:25 | 000,196,196 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat [2011.05.15 21:45:26 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat [2011.05.01 16:37:14 | 000,000,016 | ---- | C] () -- C:\Users\Christian\persistent_state [2010.10.24 15:22:56 | 000,006,642 | ---- | C] () -- C:\Windows\mgxoschk.ini [2010.10.24 14:56:13 | 000,000,126 | ---- | C] () -- C:\Windows\System32\AF15IRTBL.bin [2010.09.07 14:18:21 | 000,012,288 | ---- | C] () -- C:\Users\Christian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.01.12 15:28:12 | 000,072,083 | ---- | C] () -- C:\Users\Christian\.recently-used.xbel [2009.11.26 02:10:13 | 000,000,103 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\default.pls [2009.10.25 20:12:02 | 000,001,024 | ---- | C] () -- C:\Users\Christian\.rnd [2009.10.20 21:36:41 | 000,000,000 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\wklnhst.dat ========== LOP Check ========== [2010.01.25 14:17:40 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Acer GameZone Console [2010.01.25 14:17:41 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Atari [2011.03.09 22:11:04 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Babylon [2010.01.25 14:17:41 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Blitware [2010.09.04 13:59:27 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DAEMON Tools Lite [2010.09.07 16:28:30 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers [2010.01.25 14:17:42 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\eSobi [2012.05.20 16:52:38 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\go [2010.01.25 14:17:42 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\gtk-2.0 [2012.06.27 19:40:28 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ICQ [2010.07.21 15:41:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\LolClient [2010.10.08 19:39:34 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Need for Speed World [2011.03.31 18:59:09 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\OCS [2010.02.23 13:47:04 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\OpenOffice.org [2011.03.31 18:59:13 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Opera [2010.01.25 14:18:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\PowerCinema [2011.10.22 19:57:49 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ScreeNet iSaver [2011.04.11 07:22:36 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\SoftDMA [2012.06.27 19:25:56 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Spotify [2010.01.25 14:18:03 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Template [2012.06.27 20:13:42 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Thunderbird [2012.01.15 22:50:31 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\toolplugin [2012.06.17 07:09:32 | 000,000,456 | ---- | M] () -- C:\Windows\Tasks\Driver Robot.job [2012.05.02 11:04:31 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2010.01.25 13:41:43 | 000,000,000 | -H-D | M] -- C:\$INPLACE.~TR [2010.07.24 18:25:58 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN [2010.01.25 14:24:57 | 000,000,000 | -H-D | M] -- C:\$WINDOWS.~Q [2010.05.11 23:34:56 | 000,000,000 | ---D | M] -- C:\3de3a7e369d9e951425cd1fa65b5 [2009.09.19 23:41:18 | 000,000,000 | ---D | M] -- C:\Acer [2009.07.25 14:25:18 | 000,000,000 | ---D | M] -- C:\Book [2012.01.05 23:51:08 | 000,000,000 | -HSD | M] -- C:\Boot [2010.06.26 00:55:24 | 000,000,000 | ---D | M] -- C:\c6c92cc460f5ff9c0d1dde51a06a3a [2009.11.15 22:01:31 | 000,000,000 | ---D | M] -- C:\Casino [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2009.09.19 23:40:20 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2010.09.10 15:50:29 | 000,000,000 | ---D | M] -- C:\DVDVideoSoft [2009.09.19 23:43:13 | 000,000,000 | ---D | M] -- C:\Elements [2009.11.26 23:24:35 | 000,000,000 | ---D | M] -- C:\games [2010.05.02 19:15:43 | 000,000,000 | ---D | M] -- C:\GAMIGO [2009.02.11 22:12:45 | 000,000,000 | ---D | M] -- C:\Intel [2010.07.24 18:30:45 | 000,000,000 | ---D | M] -- C:\Keno [2009.09.24 18:42:49 | 000,000,000 | ---D | M] -- C:\Maxis [2009.03.12 05:11:16 | 000,000,000 | RH-D | M] -- C:\MSOCache [2009.09.19 23:45:12 | 000,000,000 | -H-D | M] -- C:\MyWinLockerData [2010.01.25 12:38:20 | 000,000,000 | ---D | M] -- C:\OEM [2009.07.14 04:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs [2010.11.04 21:33:23 | 000,000,000 | ---D | M] -- C:\PFiles [2012.06.20 19:33:40 | 000,000,000 | R--D | M] -- C:\Program Files [2012.06.27 20:12:57 | 000,000,000 | -H-D | M] -- C:\ProgramData [2009.09.19 23:40:20 | 000,000,000 | -HSD | M] -- C:\Programme [2010.01.25 15:07:28 | 000,000,000 | -HSD | M] -- C:\Recovery [2012.06.27 20:10:56 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2010.07.24 18:25:51 | 000,000,000 | R--D | M] -- C:\Users [2009.09.24 18:45:14 | 000,000,000 | ---D | M] -- C:\WIN32APP [2012.06.27 20:13:48 | 000,000,000 | ---D | M] -- C:\Windows < %PROGRAMFILES%\*.exe > < %LOCALAPPDATA%\*.exe > < %systemroot%\*. /mp /s > < MD5 for: AGP440.SYS > [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys < MD5 for: ATAPI.SYS > [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll < MD5 for: EXPLORER.EXE > [2011.02.26 07:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe [2009.07.14 03:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe [2011.02.26 07:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe [2009.10.31 07:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe [2011.02.26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe [2010.11.20 14:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\explorer.exe [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe [2009.08.03 07:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe [2009.08.03 07:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe [2009.10.31 08:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe < MD5 for: IASTOR.SYS > [2009.02.12 18:26:18 | 000,407,576 | ---- | M] (Intel Corporation) MD5=1ADAA4F16073FD0C7270F451FD024E97 -- C:\Acer\Preload\Autorun\DRV\AHCI\X64\IaStor.sys [2009.02.12 18:11:50 | 000,329,752 | ---- | M] (Intel Corporation) MD5=71ECC07BC7C5E24C3DD01D8A29A24054 -- C:\Acer\Preload\Autorun\DRV\AHCI\X86\IaStor.sys [2009.02.12 18:11:50 | 000,329,752 | ---- | M] (Intel Corporation) MD5=71ECC07BC7C5E24C3DD01D8A29A24054 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_e0c941a8b0e04b56\iaStor.sys [2009.02.12 18:11:50 | 000,329,752 | ---- | M] (Intel Corporation) MD5=71ECC07BC7C5E24C3DD01D8A29A24054 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_x86_neutral_7009a7672ee571e2\iaStor.sys [2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\drivers\iaStor.sys [2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_4f144d6467fc7c22\iaStor.sys [2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_x86_neutral_10aa509d6843c6fc\iaStor.sys < MD5 for: IASTORV.SYS > [2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\drivers\iaStorV.sys [2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys [2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys [2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys [2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys [2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys [2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys [2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys [2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys < MD5 for: NETLOGON.DLL > [2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll [2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll < MD5 for: NVSTOR.SYS > [2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\drivers\nvstor.sys [2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys [2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys [2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys [2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys [2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys [2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys [2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys [2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys < MD5 for: SCECLI.DLL > [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll [2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll [2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll < MD5 for: USER32.DLL > [2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll [2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll [2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll < MD5 for: USERINIT.EXE > [2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe [2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe < MD5 for: WINLOGON.EXE > [2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe [2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe [2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe [2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe [2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > [2010.09.04 13:39:09 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\Windows\system32\drivers\sptd.sys < %systemroot%\System32\config\*.sav > < %systemroot%\system32\*.dll /lockedfiles > < %USERPROFILE%\*.* > [2010.01.12 15:28:12 | 000,072,083 | ---- | M] () -- C:\Users\Christian\.recently-used.xbel [2009.12.16 23:11:11 | 000,001,024 | ---- | M] () -- C:\Users\Christian\.rnd [2012.06.27 20:09:30 | 004,456,448 | -HS- | M] () -- C:\Users\Christian\ntuser.dat [2012.06.27 20:09:30 | 000,262,144 | -HS- | M] () -- C:\Users\Christian\ntuser.dat.LOG1 [2010.01.25 13:57:37 | 000,000,000 | -HS- | M] () -- C:\Users\Christian\ntuser.dat.LOG2 [2011.01.02 21:43:42 | 000,065,536 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{0a442e2f-16a8-11e0-a377-001f16b736b0}.TM.blf [2011.01.02 21:43:42 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{0a442e2f-16a8-11e0-a377-001f16b736b0}.TMContainer00000000000000000001.regtrans-ms [2011.01.02 21:43:42 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{0a442e2f-16a8-11e0-a377-001f16b736b0}.TMContainer00000000000000000002.regtrans-ms [2012.06.27 19:20:24 | 000,065,536 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{3021da0b-c07c-11e1-9220-001f16b736b0}.TM.blf [2012.06.27 19:20:24 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{3021da0b-c07c-11e1-9220-001f16b736b0}.TMContainer00000000000000000001.regtrans-ms [2012.06.27 19:20:24 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{3021da0b-c07c-11e1-9220-001f16b736b0}.TMContainer00000000000000000002.regtrans-ms [2010.01.25 13:57:38 | 000,065,536 | -HS- | M] () -- C:\Users\Christian\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf [2010.01.25 13:57:38 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms [2010.01.25 13:57:38 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms [2010.10.12 17:09:34 | 000,065,536 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{f3941d8e-d60f-11df-9069-001f16b736b0}.TM.blf [2010.10.12 17:09:34 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{f3941d8e-d60f-11df-9069-001f16b736b0}.TMContainer00000000000000000001.regtrans-ms [2010.10.12 17:09:34 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{f3941d8e-d60f-11df-9069-001f16b736b0}.TMContainer00000000000000000002.regtrans-ms [2010.01.25 15:07:30 | 000,000,020 | -HS- | M] () -- C:\Users\Christian\ntuser.ini [2011.05.01 16:37:14 | 000,000,016 | ---- | M] () -- C:\Users\Christian\persistent_state [2010.01.25 15:14:08 | 000,000,784 | ---- | M] () -- C:\Users\Christian\UpgKit.log [1 C:\Users\Christian\*.tmp files -> C:\Users\Christian\*.tmp -> ] < %USERPROFILE%\Local Settings\Temp\*.exe > < %USERPROFILE%\Local Settings\Temp\*.dll > < %USERPROFILE%\Application Data\*.exe > < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 ========== Alternate Data Streams ========== @Alternate Data Stream - 941 bytes -> C:\Users\Christian\Documents\Antwort Personalnummer und Passwort.eml:OECustomProperty < End of report > OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 27.06.2012 20:08:57 - Run 1 OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\Christian\Downloads Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,99 Gb Total Physical Memory | 1,74 Gb Available Physical Memory | 58,08% Memory free 5,99 Gb Paging File | 4,64 Gb Available in Paging File | 77,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 455,99 Gb Total Space | 281,10 Gb Free Space | 61,65% Space Free | Partition Type: NTFS Computer Name: CHRISTIAN-PC | User Name: Christian | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) http [open] -- Reg Error: Key error. https [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) jsfile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation) jsefile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. vbefile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation) vbsfile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation) wsffile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\uusee\UUSeePlayer.exe" = C:\Program Files\uusee\UUSeePlayer.exe:*:Enabled:UUPlayer ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{030D8BC7-C879-450F-978A-025DF72273A4}" = lport=8394 | protocol=6 | dir=in | name=league of legends launcher | "{0A0F69FE-CEB0-4976-8D37-56CEBDC66DA3}" = lport=6882 | protocol=6 | dir=in | name=league of legends launcher | "{0A5F5C35-A02B-4591-86E6-43C991777A99}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{0C1BC55A-ACC2-415E-A757-94F6415959CA}" = lport=137 | protocol=17 | dir=in | app=system | "{2048D80E-043C-4326-B9BB-EA5B054F981C}" = lport=8394 | protocol=17 | dir=in | name=league of legends launcher | "{26DEDC57-11D9-427A-86F0-3B0680ECC9E1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{32DF87CD-E072-4F7C-BB87-89031AA8BC02}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{505A4C52-355D-4610-8D19-5D1CD6B8135A}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{519EE015-EED5-4576-87F1-49852D69480C}" = lport=2869 | protocol=6 | dir=in | app=system | "{55614CB6-AB16-450C-A09B-AE4C02F8B226}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{595292A2-548C-4DA0-846A-2225E1AEFD1D}" = lport=2869 | protocol=6 | dir=in | app=system | "{66A8019D-6469-41C6-B8F4-0E62F932FBB7}" = lport=10243 | protocol=6 | dir=in | app=system | "{6A8CBBEF-2164-4CFD-BBFB-95B84AADB3BE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6BEF9ECE-CF46-48D5-8FE6-49D803C8FFC6}" = rport=138 | protocol=17 | dir=out | app=system | "{6C3B3937-0D80-4E4E-8AA4-17FA57F2E364}" = rport=137 | protocol=17 | dir=out | app=system | "{71F207C2-39C0-4B55-8B05-261BFA67CEAC}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{77EEA97C-638C-4B83-A7DA-063A99159EAC}" = rport=445 | protocol=6 | dir=out | app=system | "{79AB7CA9-7834-417F-B678-31FB0E413E6F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{8378D6F2-4B0A-4F8A-847E-025A04D94EF8}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{9344C370-3371-4E12-8DCB-C076192E1CC7}" = lport=139 | protocol=6 | dir=in | app=system | "{9FD6433F-E608-4CCD-880B-634DC9ECA9DF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{A80B657C-C41D-46F4-983E-2000AB7232E0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{ADD28BD7-3605-4991-9727-31B6AF79B496}" = rport=139 | protocol=6 | dir=out | app=system | "{B49EC7EE-A444-4480-89D3-44F73722C0A4}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{BF235DF2-469A-4CB6-9F40-6AF5AD1ABD11}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C4F526E8-2E08-4968-99FF-9C8BEF856B46}" = lport=6882 | protocol=17 | dir=in | name=league of legends launcher | "{C88B6510-FD30-4ED1-8239-4719E56BC8CE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{D9FDB240-E7C8-4F91-98C2-61321B0F83A8}" = lport=138 | protocol=17 | dir=in | app=system | "{EDC8974D-6872-4D49-9D62-3151182C396D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{EE13EA30-CF2B-427B-9D20-D866C660A23B}" = rport=10243 | protocol=6 | dir=out | app=system | "{EF6624FE-D040-4374-9D2B-4D117F1C846C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F44C46EE-0C38-496E-8B58-240388220138}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F4657CAA-A839-4D1B-9B93-6F3381B8E2EA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F832D926-A37C-4753-8CAA-D8720006BC0D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F893EE03-425A-465D-8373-6F2D26AE2E00}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FB80DD62-D5AA-4AFA-BE08-4AC0C9AFB353}" = lport=445 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02C2609A-16FE-4B26-9777-B33CEE2D220C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{043F39EF-953A-4DFD-959C-5DCBE72C3E34}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{0AD63CA4-E4FB-4FCB-9EE2-9E7B8D955EB7}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{0BC94944-83EC-4B76-85EB-742902A5C9E5}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe | "{0C709260-7EB6-4541-94C8-4FEE3FD3AE4B}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 14\programs\rm.exe | "{134730B8-6192-4819-8C96-E9BD440AB416}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe | "{1860386E-7862-4B1F-940D-76B2E637FD83}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{209EDE16-0084-4BA1-8BA3-C0DF45DFF5FB}" = protocol=6 | dir=in | app=c:\users\christian\appdata\roaming\spotify\spotify.exe | "{22B0378E-63C3-4AD8-8B23-EA31D3028790}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\playmovie.exe | "{2FAB3623-29B5-4343-A4A8-52DBD0E1B46F}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{3705A63D-FE01-485B-A115-D1A62FA4CCCD}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe | "{3773FDE6-3F20-479E-893A-AF684B4C96C2}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "{380A3C4C-D79D-43B2-B64D-344E83B55CFA}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | "{386B5C5F-60E1-4FDE-B786-66B0DA47C060}" = protocol=17 | dir=in | app=c:\program files\msi\arcsoft\totalmedia\totalmedia.exe | "{3B649989-1F2F-4903-80AF-DD3A8A665D9A}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 14\programs\studio.exe | "{3B7C0189-E63F-404B-A548-1B3CA40B2CA8}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe | "{407F562D-DC1E-43D8-BE86-18FB40D2089F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{44313369-55A3-4DAD-880E-2106C1031AB1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{44BDB96B-639D-4797-848A-E88C5A3804AA}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{4CEFF72C-CA40-4CBF-86CC-E06FD8D3CCC6}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe | "{4D925050-3A9E-4CD7-B863-498ACE167F42}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{50051FC9-E029-43B1-AB25-2A90565A52CB}" = protocol=6 | dir=in | app=c:\program files\searchqu toolbar\datamngr\toolbar\dtuser.exe | "{507AC5D0-1632-466B-91F1-79058BD274E0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{51FB32BA-D249-4BD9-897E-3694506FB6F3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{53FEBE4D-389D-43E5-961B-B24329B871AE}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{565654F8-F40D-4390-93C6-8058E1ACD914}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe | "{589F0DAA-1918-47D5-9657-58B4CE36C46B}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | "{59D7ECC3-1D25-4D86-A5C5-E7571576410B}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe | "{5E01634E-2A53-4985-96FD-4760833E2255}" = protocol=6 | dir=in | app=c:\program files\league of legends\game\league of legends.exe | "{658C2063-09BE-47E7-BFDE-6F43B75A7AB3}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 14\programs\umi.exe | "{6605004F-2C39-4A6C-8A7E-345997AF47A9}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{68A82C14-EFE0-47A4-A73C-63EFE9D77288}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{6EC290F8-F5AA-478A-8A90-846C4AE9D253}" = protocol=6 | dir=in | app=c:\program files\mirandafusion\miranda32.exe | "{6EE36464-D350-4900-A43F-FDA6BE6254A5}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | "{73AD0032-2B6A-47EC-894D-2CDCB22810ED}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 14\programs\umi.exe | "{765AB022-314C-4767-9C4F-4C72D0FF840D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{77A618B2-539C-414B-A706-CD1B3D05760D}" = protocol=6 | dir=in | app=c:\users\christian\appdata\roaming\spotify\spotify.exe | "{77E7481A-0209-4355-BE82-078F1401D268}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | "{7D913E93-D266-4820-85A6-02A959B4E74F}" = protocol=6 | dir=in | app=c:\program files\league of legends\air\lolclient.exe | "{7FC92A1D-8F5D-4A56-A249-6A4C1D236805}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{833FFA05-C100-46DE-ABB6-867539A90E8A}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe | "{83E84871-F986-45E4-90BC-A3B05046C806}" = protocol=17 | dir=in | app=c:\program files\mirandafusion\miranda32.exe | "{8AC27CF7-5993-4CB9-A012-1C5C3CC62A13}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | "{8D514C19-9B7F-4B3D-9039-760270250D49}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe | "{8F20F5CD-DCD8-4175-BD2D-DEB43F554C2D}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{91E75D9F-73FD-4C28-8D50-97A840C36ED6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{91F5492E-1109-41DD-A9ED-0D7C1D97C6F0}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\pmvservice.exe | "{94A4C321-4E5E-458B-BD8B-10EBAF62DC44}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{966CDF24-683D-4A96-A1FC-E8EF144DCCA0}" = protocol=17 | dir=in | app=c:\program files\league of legends\game\league of legends.exe | "{9B132E60-84CF-40E6-8969-00C324B34C42}" = protocol=6 | dir=out | app=system | "{A65E0561-9E0D-49CA-A351-3B44FE560420}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe | "{A71605CF-A39B-4E02-8CBC-7E13B78561A8}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 14\programs\rm.exe | "{AC2E2622-512D-4385-A2BD-506869875F11}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | "{AC90AC80-5568-43D1-B2BE-0D7183030AF6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{AE4AF426-0752-41FE-A533-F7886DE302D8}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe | "{B0BBCF88-1C51-4F01-B584-25A7C5F46777}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{B66D92D0-B294-47E6-9BB8-B8B567975578}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe | "{B6B3551D-FD95-437D-A87B-9B35C5144050}" = protocol=17 | dir=in | app=c:\users\christian\appdata\roaming\spotify\spotify.exe | "{BD89EBC7-AD18-48AB-9F01-361FEEB75AA3}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe | "{C040B59B-F7BB-4209-8AB0-34036193CB32}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{C2EEFDDB-2306-47C7-97A8-87A57DEF3E60}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe | "{C2F2A452-C51B-4083-B298-7D25F94320C0}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{C4C74CD3-B877-4E63-8389-67A203139F4A}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe | "{C6BF72E3-F2AC-44F2-9B1E-A848AA94B346}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C76C168D-A079-462C-95BB-C18438B4B1F3}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{C979AD3A-E2B3-4958-B0EF-0A00E6AD37A0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{CB782159-24DD-428A-A41A-2ECFC7C572CA}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{CC36850E-F08F-48C3-85A0-5340206B2A36}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{CE72FEBD-0076-4E4E-A027-AC148EFA8F4F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{D0BC9415-C459-41F2-A74F-823499F1EF90}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{D11CF9B2-3453-4B20-A107-453A12D29699}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe | "{D3D6E206-7150-45D6-B181-5D88048D2072}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "{D5CFEE27-F3E4-4293-BD27-953090C4A7D7}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{D8F62CEC-534F-4286-8017-45143EA06492}" = protocol=17 | dir=in | app=c:\program files\league of legends\air\lolclient.exe | "{D9D6D6DF-8C0F-4988-A224-2E8183F40348}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{EE2764D4-AED7-4238-9C47-03ACA64BBE0B}" = protocol=6 | dir=in | app=c:\program files\msi\arcsoft\totalmedia\totalmedia.exe | "{EE3C9E9D-63A2-4AEB-B451-02930690B0FF}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe | "{EE5C5E55-8E35-4532-968C-325DC7288D64}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 14\programs\studio.exe | "{F075B802-3EB1-41BF-B877-5C1D4F35928A}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe | "{F5225D14-B3F5-4BBD-BE41-E7D43FED834B}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{F7EA5DA3-5C56-4495-8A69-B7D808EA7289}" = protocol=17 | dir=in | app=c:\program files\searchqu toolbar\datamngr\toolbar\dtuser.exe | "{FEC57B62-8344-4558-91FA-2149576F7775}" = protocol=17 | dir=in | app=c:\users\christian\appdata\roaming\spotify\spotify.exe | "TCP Query User{14B359CE-401B-4982-A08D-37F49A398191}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | "TCP Query User{2E3A1B16-3110-46D4-8D48-380CC6340E77}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe | "TCP Query User{318E3793-1FFC-4859-9889-0559D03C34E1}C:\program files\icq7.2\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe | "TCP Query User{34A00086-1175-4C31-8EF9-6706E04EC2F7}C:\program files\tvants\tvants.exe" = protocol=6 | dir=in | app=c:\program files\tvants\tvants.exe | "TCP Query User{3E230F18-4442-4E16-AE97-DB62A2B36986}C:\program files\heroes of newerth\hon.exe" = protocol=6 | dir=in | app=c:\program files\heroes of newerth\hon.exe | "TCP Query User{5DA0940E-DFA1-46C7-9158-F80611F3DBA7}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | "TCP Query User{6366646B-24E8-4FD1-85EF-7C7E82492FED}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=6 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "TCP Query User{69492027-7505-48F9-8CFC-5DBF8E99B197}C:\program files\icq7.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "TCP Query User{9FE5745B-7F63-4523-81CF-18AC10C2AB7E}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe | "TCP Query User{BDF0AD23-C626-48D1-9425-8A63436837E6}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{C89460DD-7097-4E29-8831-BDED700BC267}C:\program files\icq7.4\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.4\icq.exe | "TCP Query User{CDF18CA4-0CDA-4DE7-B957-3BC77261659E}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "TCP Query User{D9AF4050-8882-4790-85C3-F65B443BD3AC}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "TCP Query User{DA27EEF7-207B-4D1B-AECA-2EAC29AD6179}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | "TCP Query User{EA67B438-6156-48CA-A107-C9D6DEC23288}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | "TCP Query User{F635FF41-6E83-4134-917E-B3CF53D0150E}C:\users\christian\appdata\local\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\users\christian\appdata\local\google\chrome\application\chrome.exe | "UDP Query User{07C1E7B4-3A06-42CD-AE97-BAE09E249F56}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | "UDP Query User{0BCD3D01-EBA3-42A1-A510-9ED1D6762C91}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe | "UDP Query User{0CE9DE49-E6D4-4192-A20F-47E43B55580A}C:\users\christian\appdata\local\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\users\christian\appdata\local\google\chrome\application\chrome.exe | "UDP Query User{1E5EAE4E-2E91-41D3-BA71-8F14613222A7}C:\program files\icq7.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | "UDP Query User{56DD86F6-AA71-4EA7-BAEB-D7D4B6C53EC2}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=17 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "UDP Query User{8853D2F5-D18C-49ED-9701-AB594C967BE2}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | "UDP Query User{AA0B2407-7BFE-4EAD-8292-AF7DC1900B5C}C:\program files\icq7.2\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe | "UDP Query User{B551FEA7-FDA7-43DF-B569-239C9A3195D2}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{C0D0B69C-5C3C-44C0-8F4C-2022441F4CF0}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe | "UDP Query User{D1664CA3-3E2E-4BA7-B99A-C4E87F5C08F7}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "UDP Query User{E212879A-EFB0-4A25-A8B1-229D68F73928}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | "UDP Query User{EEEAA8B2-CBB8-4F9C-9C06-431DA6B96A21}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | "UDP Query User{F3F6C5B2-401A-4D81-8B3E-AD8ED2D6B305}C:\program files\tvants\tvants.exe" = protocol=17 | dir=in | app=c:\program files\tvants\tvants.exe | "UDP Query User{F4E080F9-002A-470A-B39E-EF8C32EA53F8}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "UDP Query User{FE38EE65-8831-47EB-96FE-F3E7B2B7910F}C:\program files\icq7.4\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.4\icq.exe | "UDP Query User{FEE290C6-F042-442F-B431-D31841A53C58}C:\program files\heroes of newerth\hon.exe" = protocol=17 | dir=in | app=c:\program files\heroes of newerth\hon.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{033F0CE1-B6FC-EC7A-7914-81F14C8DBA0F}" = Catalyst Control Center Core Implementation "{0383A85E-58F1-4296-8CC4-8269A2A61B58}" = AudialsOne "{05B95480-732A-1081-8A94-D924326AF36F}" = CCC Help English "{0945589B-6CC4-FA00-3CBE-BD6028B26063}" = CCC Help Turkish "{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime "{0EAE6EF9-010E-0734-D0A0-2BB8040F90EA}" = CCC Help French "{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}" = Windows Media Center Add-in for Silverlight "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support "{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard "{133C8002-B64F-C9E7-7DAC-21BAE58DC041}" = CCC Help Russian "{150715F0-2800-A3C5-836E-F4F98AE3A775}" = ccc-core-static "{1A0B8239-664B-434A-99D8-C50793513249}" = Audials TV "{1D0FDD6D-3C5E-4588-8ED0-02DC88014BF2}" = Upgrade Kit "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{22EFABF6-7373-7755-4EA4-5240E7CCEEF7}" = Catalyst Control Center Graphics Previews Vista "{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8 "{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 29 "{270629EB-D776-04FC-0631-256177B7A021}" = CCC Help Swedish "{29D2987A-9FBC-1BD3-E463-12D50D94DBFC}" = Catalyst Control Center Graphics Full New "{2AB22900-5718-4617-523B-9DFDECB4749D}" = CCC Help Italian "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{38EE230F-F631-451F-8800-E29F5E5C9E7D}" = iTunes Library Updater "{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup "{3956AEA0-9299-CA45-5BF1-5A721F8E3A21}" = CCC Help Chinese Traditional "{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Acer Crystal Eye Webcam Video Class Camera "{3A1AB8E6-748E-4B95-AA2D-FE9952EB3106}" = OLYMPUS Master 2 "{3C152296-D7E4-59F4-B07E-43587CE985FE}" = CCC Help Norwegian "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{502D4628-92AD-416A-0580-00D64320DBB7}" = ATI Catalyst Install Manager "{51B83F5C-5660-4B73-AB18-C68993FEDEB3}" = Catalyst Control Center - Branding "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth "{62F7DA7E-CCCB-439C-A760-00C3926E761F}" = Microsoft Works "{66CB1DC8-FBA1-7436-08F3-061F7CB72C80}" = Skins "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes "{6C497312-7C1E-BB3C-D143-B8FD0C894CF1}" = CCC Help Polish "{6DE721A5-5E89-4D74-994C-652BB3C0672E}" = Pinnacle Video Treiber "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}" = RollerCoaster Tycoon 2 "{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World "{7B63B2922B174135AFC0E1377DD81EC2}" = "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110184263}" = Puzzle Express "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111232687}" = Ocean Express "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11170417}" = Luxor 2 "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}" = Dairy Dash "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11551977}" = Parking Dash "{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{88FC0C01-E4AA-3C3E-4612-3F11E69EF188}" = CCC Help German "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2 "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update "{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support "{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 "{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 "{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 "{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007 "{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007 "{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon 3 "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{926BD0E8-24A3-41D2-AF9B-340F1A37ED12}" = MobileMe Control Panel "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 "{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{98E3A37D-D424-C725-E06A-71C1151F682A}" = CCC Help Finnish "{99A37AC7-E724-4621-B167-500B5A52B69C}" = LastChaosGER "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9AF0B106-56F1-461B-A270-95BC1682E282}" = Broadcom Gigabit NetLink Controller "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C450606-ED24-4958-92BA-B8940C99D441}" = PixiePack Codec Pack "{9E78C42C-4FF9-4F41-BBC4-BF872606E79D}_is1" = Driver Robot 1.1.0.13 "{9FC83F04-9C3F-429B-92DE-1252235765E4}" = DDBAC "{A141F87A-A73B-368D-AB65-A997B3D1D2C4}" = CCC Help Spanish "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AAD2CA33-F716-4D1B-31F9-B52A847C4AF1}" = CCC Help Hungarian "{AADD1C8F-D59F-4D55-A726-768C71A205A8}" = Pinnacle Studio 14 "{AB104276-19BC-D12E-90EE-D358003A4EAF}" = CCC Help Greek "{ABBD20D8-60E7-885B-734A-DE745BFDF43B}" = CCC Help Czech "{AC76BA86-7AD7-1031-7B44-A95000000001}" = Adobe Reader 9.5.1 - Deutsch "{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger "{AEE701D3-6AF7-A8D5-145E-D0C01D528FAD}" = ccc-utility "{B1AD83A0-DC92-41E3-B111-E9472349768C}" = RollerCoaster Tycoon 2: Wacky Worlds "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0 "{B5080F69-EE95-49DC-F8A1-B7CBB2B5028D}" = CCC Help Korean "{B6CB5308-3B67-9861-97F5-0EB31CE21E63}" = CCC Help Chinese Standard "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{B7020783-0AB1-8D67-E850-673BD0C61E7F}" = CCC Help Thai "{BA1E1AFD-D1F2-4C52-88C3-186FC5E61604}" = RollerCoaster Tycoon 2: Time Twister "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die Sims™ 3 "{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail "{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser "{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari "{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials "{D0354121-07AF-DE06-1D0F-7490EFE2F67A}" = Catalyst Control Center Graphics Full Existing "{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call "{D6C9AF27-9414-46C8-B9D8-D878BA041031}" = Nero 8 Ultra Edition HD "{DA163DB8-C795-9EF2-7CF2-8B570BA9E39E}" = CCC Help Portuguese "{DA20E1A8-07CB-4EE7-9B72-A7E28C953F0E}" = Acer Product Registration "{DA7DF8E2-4B8F-4286-97FE-DE3FFFE9B728}" = iCloud "{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader "{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer "{E36BE564-B727-A80D-E9F0-7FFEB69120E5}" = CCC Help Dutch "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 "{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant "{E5A56A6C-7656-969C-457A-E7600A6F169B}" = Catalyst Control Center Graphics Light "{E5D9A29A-8903-968F-6394-CB8CC151084C}" = Catalyst Control Center Localization All "{EA926717-CE5A-4CB4-AB21-9E6E9565A458}" = RCT3 Soaked "{EE03DA2C-2154-7298-4461-F76C615932A9}" = CCC Help Japanese "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.9 "{EE9DEA81-3B77-7135-0E5B-B8C3092FE88A}" = CCC Help Danish "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5 "{F5C372A1-40F3-49DA-A049-F75CDE9177DC}" = Pinnacle Studio Ultimate Collection Plugins "{FF68083C-E11E-4A91-B54B-CD72AB5A0CF5}" = ArcSoft TotalMedia 3 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "CCleaner" = CCleaner (remove only) "Debut" = Debut Video Capture Software "EADM" = EA Download Manager "ENTERPRISE" = Microsoft Office Enterprise 2007 "Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition 2.0.0.1 (D) "GridVista" = Acer GridVista "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "Icy Tower v1.4_is1" = Icy Tower v1.4 "InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5 "InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8 "InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe "JDownloader" = JDownloader "Knoll Light Factory EZ Studio" = Knoll Light Factory EZ Studio "LManager" = Launch Manager "Magic Bullet Looks Studio" = Magic Bullet Looks Studio "MAGIX Foto Manager 2006 D" = MAGIX Foto Manager 2006 3.4.0.450 (D) "MAGIX Goya Base D" = MAGIX Goya Base 1.3.1.2 (D) "MAGIX Music Manager 2006 D" = MAGIX Music Manager 2006 7.4.0.438 (D) "MAGIX Online Druck Service D" = MAGIX Online Druck Service 2.3.2.0 (D) "Messer_is1" = Messer v0.992 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Mozilla Firefox 13.0.1 (x86 de)" = Mozilla Firefox 13.0.1 (x86 de) "Mozilla Thunderbird 10.0.1 (x86 de)" = Mozilla Thunderbird 10.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "NSS" = Norton Security Scan "Picasa 3" = Picasa 3 "Red Giant ToonIt Studio" = Red Giant ToonIt Studio "Searchqu Toolbar" = Searchqu Toolbar "SopCast" = SopCast 3.2.4 "SynTPDeinstKey" = Synaptics Pointing Device Driver "VLC media player" = VLC media player 1.1.11 "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR "zokyo_client" = fellody ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Spotify" = Spotify "UnityWebPlayer" = Unity Web Player ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 27.06.2012 10:05:19 | Computer Name = Christian-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16446, Zeitstempel: 0x4fb57c8f Name des fehlerhaften Moduls: IEBHO.dll, Version: 1.0.0.1, Zeitstempel: 0x4fb0ed9e Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002e802 ID des fehlerhaften Prozesses: 0x15fc Startzeit der fehlerhaften Anwendung: 0x01cd546de288631e Pfad der fehlerhaften Anwendung: C:\Program Files\Internet Explorer\iexplore.exe Pfad des fehlerhaften Moduls: C:\PROGRA~1\SEARCH~1\Datamngr\IEBHO.dll Berichtskennung: 204a5a61-c061-11e1-a36b-001f16b736b0 Error - 27.06.2012 10:05:19 | Computer Name = Christian-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16446, Zeitstempel: 0x4fb57c8f Name des fehlerhaften Moduls: IEBHO.dll, Version: 1.0.0.1, Zeitstempel: 0x4fb0ed9e Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002e802 ID des fehlerhaften Prozesses: 0xc30 Startzeit der fehlerhaften Anwendung: 0x01cd546de2d70fc7 Pfad der fehlerhaften Anwendung: C:\Program Files\Internet Explorer\iexplore.exe Pfad des fehlerhaften Moduls: C:\PROGRA~1\SEARCH~1\Datamngr\IEBHO.dll Berichtskennung: 2099a349-c061-11e1-a36b-001f16b736b0 Error - 27.06.2012 10:08:13 | Computer Name = Christian-PC | Source = WinMgmt | ID = 10 Description = Error - 27.06.2012 10:17:24 | Computer Name = Christian-PC | Source = WinMgmt | ID = 10 Description = Error - 27.06.2012 10:20:40 | Computer Name = Christian-PC | Source = Application Hang | ID = 1002 Description = Programm rundll32.exe, Version 6.1.7600.16385 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: e54 Startzeit: 01cd546fa9a1f581 Endzeit: 10 Anwendungspfad: C:\Windows\system32\rundll32.exe Berichts-ID: ef6b2c5f-c062-11e1-a7cc-001f16b736b0 Error - 27.06.2012 12:51:25 | Computer Name = Christian-PC | Source = WinMgmt | ID = 10 Description = Error - 27.06.2012 13:16:29 | Computer Name = Christian-PC | Source = WinMgmt | ID = 10 Description = Error - 27.06.2012 13:21:02 | Computer Name = Christian-PC | Source = WinMgmt | ID = 10 Description = Error - 27.06.2012 13:47:40 | Computer Name = Christian-PC | Source = Application Hang | ID = 1002 Description = Programm OTL.exe, Version 3.2.53.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1308 Startzeit: 01cd548c1e6dcadc Endzeit: 8 Anwendungspfad: C:\Users\Christian\Downloads\OTL.exe Berichts-ID: Error - 27.06.2012 14:08:12 | Computer Name = Christian-PC | Source = Application Hang | ID = 1002 Description = Programm OTL.exe, Version 3.2.53.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1408 Startzeit: 01cd548d068b388e Endzeit: 4 Anwendungspfad: C:\Users\Christian\Downloads\OTL.exe Berichts-ID: 08eafaee-c083-11e1-9220-001f16b736b0 [ Media Center Events ] Error - 05.07.2010 03:34:20 | Computer Name = Christian-PC | Source = MCUpdate | ID = 0 Description = 09:34:17 - Fehler beim Herstellen der Internetverbindung. 09:34:20 - Serververbindung konnte nicht hergestellt werden.. Error - 05.07.2010 03:34:34 | Computer Name = Christian-PC | Source = MCUpdate | ID = 0 Description = 09:34:25 - Fehler beim Herstellen der Internetverbindung. 09:34:25 - Serververbindung konnte nicht hergestellt werden.. Error - 05.11.2010 03:49:24 | Computer Name = Christian-PC | Source = MCUpdate | ID = 0 Description = 08:49:24 - Fehler beim Herstellen der Internetverbindung. 08:49:24 - Serververbindung konnte nicht hergestellt werden.. Error - 05.11.2010 03:49:35 | Computer Name = Christian-PC | Source = MCUpdate | ID = 0 Description = 08:49:29 - Fehler beim Herstellen der Internetverbindung. 08:49:29 - Serververbindung konnte nicht hergestellt werden.. Error - 19.11.2010 01:41:07 | Computer Name = Christian-PC | Source = MCUpdate | ID = 0 Description = 06:41:07 - Fehler beim Herstellen der Internetverbindung. 06:41:07 - Serververbindung konnte nicht hergestellt werden.. Error - 19.11.2010 01:41:19 | Computer Name = Christian-PC | Source = MCUpdate | ID = 0 Description = 06:41:12 - Fehler beim Herstellen der Internetverbindung. 06:41:12 - Serververbindung konnte nicht hergestellt werden.. [ OSession Events ] Error - 17.03.2012 17:24:11 | Computer Name = Christian-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 11 seconds with 0 seconds of active time. This session ended with a crash. Error - 17.03.2012 17:24:33 | Computer Name = Christian-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error - 06.04.2012 14:36:06 | Computer Name = Christian-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error - 09.04.2012 16:16:06 | Computer Name = Christian-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 15 seconds with 0 seconds of active time. This session ended with a crash. Error - 18.04.2012 16:05:32 | Computer Name = Christian-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 8 seconds with 0 seconds of active time. This session ended with a crash. Error - 02.05.2012 12:07:59 | Computer Name = Christian-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 17 seconds with 0 seconds of active time. This session ended with a crash. Error - 17.05.2012 05:08:12 | Computer Name = Christian-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error - 17.05.2012 15:58:55 | Computer Name = Christian-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1465 seconds with 120 seconds of active time. This session ended with a crash. Error - 09.06.2012 10:45:01 | Computer Name = Christian-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 14 seconds with 0 seconds of active time. This session ended with a crash. Error - 25.06.2012 02:53:06 | Computer Name = Christian-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 23481 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 27.06.2012 13:05:55 | Computer Name = Christian-PC | Source = atikmdag | ID = 43029 Description = Display is not active Error - 27.06.2012 13:06:23 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7038 Description = Der Dienst "SSDPSRV" konnte sich nicht als "NT AUTHORITY\LocalService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1352 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error - 27.06.2012 13:06:23 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "SSDP-Suche" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error - 27.06.2012 13:06:23 | Computer Name = Christian-PC | Source = Microsoft-Windows-Bits-Client | ID = 16392 Description = Fehler beim Starten des BITS-Dienstes. Fehler: 2147943515. Error - 27.06.2012 13:06:23 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Intelligenter Hintergrundübertragungsdienst" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147023781. Error - 27.06.2012 13:15:27 | Computer Name = Christian-PC | Source = atikmdag | ID = 52236 Description = CPLIB :: General - Invalid Parameter Error - 27.06.2012 13:15:27 | Computer Name = Christian-PC | Source = atikmdag | ID = 43029 Description = Display is not active Error - 27.06.2012 13:19:55 | Computer Name = Christian-PC | Source = atikmdag | ID = 52236 Description = CPLIB :: General - Invalid Parameter Error - 27.06.2012 13:19:55 | Computer Name = Christian-PC | Source = atikmdag | ID = 43029 Description = Display is not active Error - 27.06.2012 13:27:35 | Computer Name = Christian-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597 (Definition 1.129.469.0) < End of report > Ist das so richtig? |
Themen zu GVU Version des BKA-Trojaners |
account, bka-trojaner, chris, christian, erschein, erscheint, forum, gastzugang, gefunde, guten, laptop, link, problem, schnell, troja, trojaner, tronjaner, version, zugang |