![]() |
Plagegeister aller Art und deren Bekämpfung: Windows fehlerhaft, langsam, Malware???Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #1 |
| ![]() Windows fehlerhaft, langsam, Malware??? Hallo ihr Lieben, Ich brauche ganz dringend Hilfe. als ich vor 3 Tagen mein Notebook(altes acer) anschaltete, dauerte es viel länger als gewöhnlich. Als es dann hochgefahren war, sah ich, dass alle Schriften irgendwie komisch verpixelt aussahen, der Windows Defender meldete sich bei jedem Programm, dass ich ausführen wollte mit einer Sicherheitsabfrage, meine Tastatur war plötzlich amerikanisch, alle Programme im Schnellstart sind weg, beim löschen geht nichts mehr in den Papierkorb, die Taskleiste ist fix und die angeheftete Programme nicht mehr drauf. Außerdem sind alle Standard-Programme-Einstellungen weg, und lassen sich auch nicht mehr einstellen. Windowsfunktionen im Wartungscenter wie Systemoptimierung gehen nicht (Fehler 0x80070005). Avira und Malwarebytes laufen ergebnislos durch. Ich verstehe nicht, was da los ist, und google ist auch wenig hilfreich. Achja, benutze Windows 7. OTL hab ich auch laufen lassen, da ich aber mein Problem noch nicht benennen kann, poste ich erstmal die logs nicht.... Könnt ihr mir bitte helfen? Vielen Dank schonmal Geändert von champjan (26.10.2012 um 13:36 Uhr) |
![]() | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows fehlerhaft, langsam, Malware??? Sonst noch andere Scans gemacht? Wenn ja => http://www.trojaner-board.de/125889-...tml#post941520
__________________Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs posten!
__________________ |
![]() | #3 |
| ![]() Windows fehlerhaft, langsam, Malware??? OTL-Log unten, hoffe ich hab alle Namen gefunden und durch *** ersetzt...
__________________Vielen Dank. Hatte auch noch einen HijackThis scan, aber die logs soll man wohl hier nicht posten. OTL Logfile: Code:
ATTFilter OTL logfile created on: 26.10.2012 12:26:57 - Run 1 OTL by OldTimer - Version Folder = D:\Users\***\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: | Country: | Language: | Date Format: 1022,18 Mb Total Physical Memory | 299,64 Mb Available Physical Memory | 29,31% Memory free 2,00 Gb Paging File | 0,86 Gb Available in Paging File | 43,15% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 58,50 Gb Total Space | 17,11 Gb Free Space | 29,26% Space Free | Partition Type: NTFS Drive D: | 90,45 Gb Total Space | 24,36 Gb Free Space | 26,94% Space Free | Partition Type: NTFS Drive I: | 34,62 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: *** | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.10.26 12:26:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Users\***\Desktop\OTL.exe PRC - [2012.09.29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe PRC - [2012.09.25 11:00:45 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2012.09.25 10:52:56 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2012.09.25 10:52:48 | 000,386,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.09.19 19:20:40 | 000,079,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2012.09.10 19:50:26 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2012.04.03 18:19:42 | 000,863,360 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe PRC - [2012.04.03 18:19:40 | 000,502,912 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe PRC - [2012.04.02 15:44:14 | 001,058,912 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\Event Manager\EEventManager.exe PRC - [2012.02.27 00:01:02 | 000,142,432 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE PRC - [2011.12.12 00:00:00 | 000,122,000 | ---- | M] (Seiko Epson Corporation) -- C:\Windows\System32\EscSvc.exe PRC - [2011.11.25 16:32:36 | 000,687,400 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Update\NASvc.exe PRC - [2011.06.01 13:22:24 | 000,353,144 | ---- | M] (Telefónica I+D) -- C:\Program Files\o2\Nori\Nori.exe PRC - [2011.05.19 15:30:56 | 004,063,096 | ---- | M] (Telefónica I+D) -- C:\Program Files\o2\Mobile Connection Manager\EMMSN.exe PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE PRC - [2010.11.20 04:17:48 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010.09.29 15:08:58 | 000,200,624 | ---- | M] (Telefónica I+D) -- C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe ========== Modules (No Company Name) ========== MOD - [2012.09.10 19:50:25 | 002,244,064 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2011.06.01 13:22:38 | 000,190,328 | ---- | M] () -- C:\Program Files\o2\Nori\legplgs\plgice.dll MOD - [2011.06.01 13:22:36 | 000,201,080 | ---- | M] () -- C:\Program Files\o2\Nori\legplgs\plgalc.dll MOD - [2011.06.01 13:22:34 | 000,343,416 | ---- | M] () -- C:\Program Files\o2\Nori\legplgs\plgsie.dll MOD - [2011.06.01 13:22:34 | 000,214,392 | ---- | M] () -- C:\Program Files\o2\Nori\legplgs\plgzte.dll MOD - [2011.06.01 13:22:32 | 000,193,912 | ---- | M] () -- C:\Program Files\o2\Nori\legplgs\plgopt.dll MOD - [2011.06.01 13:22:32 | 000,193,400 | ---- | M] () -- C:\Program Files\o2\Nori\legplgs\plgser.dll MOD - [2011.06.01 13:22:30 | 000,293,752 | ---- | M] () -- C:\Program Files\o2\Nori\legplgs\plgnvt.dll MOD - [2011.06.01 13:22:28 | 000,409,976 | ---- | M] () -- C:\Program Files\o2\Nori\legplgs\plghwi.dll MOD - [2011.06.01 13:22:28 | 000,190,840 | ---- | M] () -- C:\Program Files\o2\Nori\legplgs\plgati.dll MOD - [2011.06.01 13:21:56 | 000,155,648 | ---- | M] () -- C:\Program Files\o2\Nori\legplgs\plgste.dll MOD - [2011.05.19 15:30:56 | 000,125,304 | ---- | M] () -- C:\Program Files\o2\Mobile Connection Manager\AgendaLib.dll MOD - [2011.01.20 16:49:42 | 000,021,880 | ---- | M] () -- C:\Program Files\o2\Mobile Connection Manager\langs\de_DE_md.dll MOD - [2010.12.01 18:29:54 | 000,508,760 | ---- | M] () -- C:\Program Files\o2\Mobile Connection Manager\sqlite3.dll MOD - [2009.07.14 03:15:45 | 000,364,544 | ---- | M] () -- C:\Windows\System32\msjetoledb40.dll ========== Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- -- (MSDTC) SRV - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012.09.25 11:00:45 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.09.25 10:52:56 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.09.10 21:43:57 | 004,537,664 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_5891ae0.dll -- (Akamai) SRV - [2012.09.10 19:50:25 | 000,114,144 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.08.01 09:51:17 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.02.27 00:01:02 | 000,142,432 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE -- (EPSON_PM_RPCV4_05) SRV - [2011.12.12 00:00:00 | 000,122,000 | ---- | M] (Seiko Epson Corporation) [Auto | Running] -- C:\Windows\System32\EscSvc.exe -- (EpsonScanSvc) SRV - [2011.11.25 16:32:36 | 000,687,400 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate) SRV - [2010.09.29 15:08:58 | 000,200,624 | ---- | M] (Telefónica I+D) [Auto | Running] -- C:\Program Files\o2\Mobile Connection Manager\ImpWiFiSvc.exe -- (TGCM_ImportWiFiSvc) SRV - [2010.08.26 20:18:46 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2008.08.15 05:46:20 | 000,284,016 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe -- (Adobe Version Cue CS4) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbdev.sys -- (hwusbdev) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT) DRV - File not found [Kernel | On_Demand | Stopped] -- D:\Users\***\AppData\Local\Temp\cpuz134\cpuz134_x32.sys -- (cpuz134) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a7qe7fj2) DRV - [2012.10.01 17:14:23 | 000,134,184 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012.09.24 09:58:11 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.09.13 10:58:17 | 000,083,792 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2012.08.27 15:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010.11.20 04:30:16 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 04:30:16 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 04:30:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 02:24:42 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 02:21:16 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - [2010.11.20 01:59:46 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.11.20 01:14:46 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 01:14:42 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2010.10.09 08:48:36 | 000,072,576 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV - [2010.08.31 12:09:00 | 000,208,896 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet) DRV - [2010.08.26 19:39:32 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd) DRV - [2010.08.07 11:48:42 | 000,106,880 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2010.07.27 03:52:02 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV - [2009.07.14 02:18:07 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice) DRV - [2009.07.14 02:14:49 | 000,020,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDScan.sys -- (WSDScan) DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) DRV - [2009.07.14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\serial.sys -- (Serial) DRV - [2009.07.14 00:02:53 | 000,311,296 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7) DRV - [2009.07.14 00:02:46 | 001,096,704 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2009.01.30 10:12:00 | 007,544,832 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2006.07.06 13:44:00 | 000,168,448 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tifm21.sys -- (tifm21) DRV - [2004.10.08 10:51:08 | 001,270,540 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> IE - HKU\S-1-5-21-919462747-3820630327-1177556215-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Hotmail, Skype Download und Messenger sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN IE - HKU\S-1-5-21-919462747-3820630327-1177556215-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.23 19:10:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.25 23:13:51 | 000,000,000 | ---D | M] [2012.03.13 14:57:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012.05.07 13:36:37 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2010.08.27 01:04:43 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2012.09.10 19:50:26 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2010.03.08 12:24:04 | 000,103,168 | ---- | M] (Midasplayer Ltd) -- C:\Program Files\mozilla firefox\plugins\npmidas.dll [2010.07.12 18:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll [2012.03.13 14:57:28 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.10 19:50:23 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.03.13 14:57:28 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.03.13 14:57:28 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.03.13 14:57:28 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.03.13 14:57:28 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.08.26 20:15:20 | 000,000,855 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: activate.adobe.com O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll () O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll () O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [FUFAXRCV] C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKU\S-1-5-21-919462747-3820630327-1177556215-1002..\Run: [EPLTarget\P0000000000000000] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_TATIIVE.EXE (SEIKO EPSON CORPORATION) O4 - HKU\S-1-5-21-919462747-3820630327-1177556215-1002..\Run: [EPLTarget\P0000000000000001] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_TATIIVE.EXE (SEIKO EPSON CORPORATION) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - Startup: D:\Users\All Users\Adobe [2010.08.26 20:33:24 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Anwendungsdaten [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\All Users\Apple [2010.08.26 18:28:25 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Avira [2012.10.24 12:23:30 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Canneverbe Limited [2012.06.25 19:07:28 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\CanonBJ [2010.10.17 00:40:43 | 000,000,000 | -H-D | M] O4 - Startup: D:\Users\All Users\DAEMON Tools Lite [2010.08.26 19:38:48 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Desktop [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\All Users\Dokumente [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\All Users\EPSON [2012.10.24 22:33:17 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Favoriten [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\All Users\FLEXnet [2012.06.25 17:43:45 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Malwarebytes [2011.12.15 05:02:43 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Microsoft [2012.07.02 14:15:59 | 000,000,000 | --SD | M] O4 - Startup: D:\Users\All Users\Microsoft Help [2012.10.24 00:35:49 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Mozilla [2012.05.23 17:59:05 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Nero [2012.06.25 20:07:53 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\ntuser.pol () O4 - Startup: D:\Users\All Users\NVIDIA [2012.06.24 12:27:49 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Skype [2012.08.02 12:28:08 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Startmenü [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\All Users\Sun [2011.12.11 02:00:11 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Sync App Settings [2010.08.26 17:32:20 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\All Users\Vorlagen [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\All Users\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2010.08.26 18:30:46 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\Default\Anwendungsdaten [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Default\AppData [2010.08.26 15:27:47 | 000,000,000 | -H-D | M] O4 - Startup: D:\Users\Default\Cookies [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Default\Desktop [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Default\Documents [2010.08.26 15:34:33 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Default\Downloads [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Default\Druckumgebung [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Default\Eigene Dateien [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Default\Favorites [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Default\Links [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Default\Lokale Einstellungen [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Default\Music [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Default\Netzwerkumgebung [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Default\NTUSER.DAT () O4 - Startup: D:\Users\Default\NTUSER.DAT.LOG () O4 - Startup: D:\Users\Default\NTUSER.DAT.LOG1 () O4 - Startup: D:\Users\Default\NTUSER.DAT.LOG2 () O4 - Startup: D:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf () O4 - Startup: D:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms () O4 - Startup: D:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms () O4 - Startup: D:\Users\Default\Pictures [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Default\Recent [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Default\Saved Games [2009.07.14 04:04:25 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\Default\SendTo [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Default\Startmenü [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Default\Videos [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Default\Vorlagen [2010.08.26 15:34:33 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Anwendungsdaten [2010.08.27 02:46:54 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\AppData [2010.08.27 02:46:54 | 000,000,000 | -H-D | M] O4 - Startup: D:\Users\***\Application Data [2010.10.13 19:43:42 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\***\Contacts [2012.10.23 18:40:57 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Cookies [2010.08.27 02:46:54 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Desktop [2012.10.26 12:26:36 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Documents [2012.10.23 19:21:09 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Downloads [2012.10.23 18:40:57 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Druckumgebung [2010.08.27 02:46:54 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Eigene Dateien [2010.08.27 02:46:54 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Favorites [2012.10.23 18:40:57 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Library [2012.06.10 22:33:22 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\***\Links [2012.10.23 18:40:58 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Lokale Einstellungen [2010.08.27 02:46:54 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Music [2012.10.23 18:40:57 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Netzwerkumgebung [2010.08.27 02:46:54 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\NTUSER.DAT () O4 - Startup: D:\Users\***\ntuser.dat.LOG1 () O4 - Startup: D:\Users\***\ntuser.dat.LOG2 () O4 - Startup: D:\Users\***\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf () O4 - Startup: D:\Users\***\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms () O4 - Startup: D:\Users\***\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms () O4 - Startup: D:\Users\***\ntuser.ini () O4 - Startup: D:\Users\***\Pictures [2012.10.23 18:40:57 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Recent [2010.08.27 02:46:54 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Saved Games [2012.10.23 18:40:58 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Searches [2012.10.23 18:40:57 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\SendTo [2010.08.27 02:46:54 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Startmenü [2010.08.27 02:46:54 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Tracing [2012.06.26 20:39:08 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\***\Videos [2012.10.23 18:40:57 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Vorlagen [2010.08.27 02:46:54 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Anwendungsdaten [2010.08.26 15:38:01 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\AppData [2010.08.26 15:38:01 | 000,000,000 | -H-D | M] O4 - Startup: D:\Users\***\Application Data [2010.08.26 22:30:17 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\***\Contacts [2012.09.27 10:09:41 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Cookies [2010.08.26 15:38:01 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Desktop [2012.09.27 10:09:41 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Documents [2012.09.27 10:09:42 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Downloads [2012.09.27 10:09:42 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Druckumgebung [2010.08.26 15:38:01 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Eigene Dateien [2010.08.26 15:38:01 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Favorites [2012.09.27 10:09:41 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Links [2012.09.27 10:09:42 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Lokale Einstellungen [2010.08.26 15:38:01 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\***.MIG () O4 - Startup: D:\Users\***\Music [2012.09.27 10:09:41 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Netzwerkumgebung [2010.08.26 15:38:01 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\NTUSER.DAT () O4 - Startup: D:\Users\***\ntuser.dat.LOG1 () O4 - Startup: D:\Users\***\ntuser.dat.LOG2 () O4 - Startup: D:\Users\***\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf () O4 - Startup: D:\Users\***\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms () O4 - Startup: D:\Users\***\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms () O4 - Startup: D:\Users\***\ntuser.ini () O4 - Startup: D:\Users\***\Pictures [2012.09.27 10:09:41 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Recent [2010.08.26 15:38:01 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Saved Games [2012.09.27 10:09:42 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Searches [2012.09.27 10:09:42 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\SendTo [2010.08.26 15:38:01 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Startmenü [2010.08.26 15:38:01 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\***\Videos [2012.09.27 10:09:41 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\***\Vorlagen [2010.08.26 15:38:01 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE\AppData [2012.05.31 11:39:04 | 000,000,000 | -H-D | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Anwendungsdaten [2012.05.31 11:55:17 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\AppData [2012.05.31 11:55:17 | 000,000,000 | -H-D | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Cookies [2012.05.31 11:55:17 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Desktop [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Documents [2012.05.31 11:55:17 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Downloads [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Druckumgebung [2012.05.31 11:55:17 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Eigene Dateien [2012.05.31 11:55:17 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Favorites [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Links [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Lokale Einstellungen [2012.05.31 11:55:17 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Music [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Netzwerkumgebung [2012.05.31 11:55:17 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\NTUSER.DAT () O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\ntuser.dat.LOG1 () O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\ntuser.dat.LOG2 () O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf () O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms () O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms () O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\ntuser.ini () O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Pictures [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Recent [2012.05.31 11:55:17 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Saved Games [2009.07.14 04:04:25 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\SendTo [2012.05.31 11:55:17 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Startmenü [2012.05.31 11:55:17 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Videos [2009.07.14 04:04:25 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Mcx1-ACERASPIRE.AcerAspire\Vorlagen [2012.05.31 11:55:17 | 000,000,000 | -HSD | M] O4 - Startup: D:\Users\Public\Desktop [2012.10.24 12:25:24 | 000,000,000 | RH-D | M] O4 - Startup: D:\Users\Public\Documents [2010.09.27 23:13:29 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Public\Downloads [2010.08.26 15:27:51 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Public\Favorites [2009.07.14 04:04:25 | 000,000,000 | RH-D | M] O4 - Startup: D:\Users\Public\Libraries [2012.07.01 00:25:05 | 000,000,000 | RH-D | M] O4 - Startup: D:\Users\Public\Music [2010.08.26 15:27:51 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Public\Pictures [2010.08.26 15:27:52 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Public\Recorded TV [2010.08.26 22:50:11 | 000,000,000 | R--D | M] O4 - Startup: D:\Users\Public\Roaming [2012.06.10 22:33:24 | 000,000,000 | ---D | M] O4 - Startup: D:\Users\Public\Videos [2010.08.26 15:27:54 | 000,000,000 | R--D | M] O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 10.9.2) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1870C08F-25DD-4B36-B5E3-13F7E4ECD812}: NameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3675E778-E14C-450C-AD26-D623C226650A}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A759C026-85D8-43E5-AB1F-0A9F83D4E1AE}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C4A9AF33-225E-478C-BEA6-DEE131706175}: NameServer = O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2010.08.19 19:43:30 | 000,143,360 | R--- | M] (Huawei Technologies Co., Ltd.) - I:\AutoRun.exe -- [ CDFS ] O32 - AutoRun File - [2010.10.07 06:57:28 | 000,000,044 | R--- | M] () - I:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.10.26 02:13:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2012.10.26 02:13:32 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe [2012.10.26 02:13:09 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe [2012.10.26 02:13:09 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe [2012.10.26 02:13:09 | 000,093,672 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll [2012.10.26 02:12:46 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2012.10.25 23:13:51 | 000,821,736 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll [2012.10.25 22:51:47 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012.10.24 12:25:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2012.10.24 12:23:40 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2012.10.24 12:23:36 | 000,134,184 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys [2012.10.24 12:23:36 | 000,083,792 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys [2012.10.24 12:23:36 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys [2012.10.24 12:23:30 | 000,000,000 | ---D | C] -- D:\ProgramData\Avira [2012.10.24 12:23:30 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [2012.10.23 21:09:45 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll [2012.10.23 21:09:33 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe [2012.10.23 21:09:33 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll [2012.10.23 21:09:33 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll [2012.10.23 21:09:33 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll [2012.10.23 21:09:33 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll [2012.10.23 21:09:33 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll [2012.10.23 21:09:33 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll [2012.10.23 21:09:33 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll [2012.10.23 21:09:33 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll [2012.10.23 21:09:33 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll [2012.10.23 21:09:33 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll [2012.10.23 21:09:33 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll [2012.10.23 21:09:33 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll [2012.10.23 21:09:33 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll [2012.10.23 21:09:33 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll [2012.10.23 21:09:33 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll [2012.10.23 21:09:33 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll [2012.10.23 21:09:33 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll [2012.10.23 21:09:33 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll [2012.10.23 21:09:32 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll [2012.10.23 21:09:32 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll [2012.10.23 21:09:32 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll [2012.10.23 21:09:32 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll [2012.10.23 21:09:32 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll [2012.10.23 21:09:32 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll [2012.10.23 21:09:31 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll [2012.10.23 21:09:31 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll [2012.10.23 21:09:31 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll [2012.10.23 21:09:31 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll [2012.10.23 21:09:31 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll [2012.10.23 21:05:42 | 003,968,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe [2012.10.23 21:05:42 | 003,914,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe [2012.10.23 20:21:45 | 000,000,000 | ---D | C] -- C:\Windows\System32\%LocalAppData% [2012.10.23 19:44:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\EPSON [2012.10.23 19:30:34 | 000,000,000 | ---D | C] -- C:\Program Files\Epson Software [2012.10.23 19:30:03 | 000,475,496 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\ensppmon.dll [2012.10.23 19:30:03 | 000,475,496 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\enppmon.dll [2012.10.23 19:30:03 | 000,457,780 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\ensppui.dll [2012.10.23 19:30:03 | 000,457,780 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\enppui.dll [2012.10.23 19:30:03 | 000,249,344 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\enspres.dll [2012.10.23 19:30:03 | 000,249,344 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\enpres.dll [2012.10.23 19:30:03 | 000,000,000 | ---D | C] -- C:\Program Files\EpsonNet [2012.10.23 19:29:14 | 000,122,000 | ---- | C] (Seiko Epson Corporation) -- C:\Windows\System32\escsvc.exe [2012.10.23 19:29:13 | 000,342,016 | ---- | C] (Seiko Epson Corporation) -- C:\Windows\System32\esw2ud.dll [2012.10.23 19:29:03 | 000,000,000 | ---D | C] -- C:\Program Files\epson [2012.10.23 19:27:34 | 000,008,192 | ---- | C] (SEIKO EPSON CORP.) -- C:\Windows\System32\E_DCINST.DLL [2012.10.23 19:27:27 | 000,095,232 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\E_TLBIVE.DLL [2012.10.23 19:27:24 | 000,081,408 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\E_TD4BIVE.DLL [2012.10.23 19:27:14 | 000,000,000 | ---D | C] -- D:\ProgramData\EPSON [2012.09.26 12:51:12 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OxpsConverter.exe ========== Files - Modified Within 30 Days ========== [2012.10.26 11:40:00 | 000,016,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.10.26 11:40:00 | 000,016,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.10.26 11:32:41 | 000,000,437 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics [2012.10.26 11:32:13 | 000,016,384 | ---- | M] () -- C:\Windows\System32\Ikeext.etl [2012.10.26 11:32:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.10.26 11:31:57 | 803,872,768 | -HS- | M] () -- C:\hiberfil.sys [2012.10.26 02:12:54 | 000,093,672 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll [2012.10.26 02:12:53 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe [2012.10.26 02:12:53 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe [2012.10.26 02:12:53 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe [2012.10.26 02:12:52 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll [2012.10.26 02:12:52 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll [2012.10.25 22:32:56 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.10.25 22:32:56 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.10.25 22:32:56 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.10.25 22:32:56 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.10.24 12:25:24 | 000,001,856 | ---- | M] () -- D:\Users\Public\Desktop\Avira Control Center.lnk [2012.10.23 19:32:25 | 000,000,238 | ---- | M] () -- D:\Users\Public\Desktop\Anleitung für Epson Connect.url [2012.10.23 19:32:22 | 000,002,108 | ---- | M] () -- D:\Users\Public\Desktop\Epson Netzwerkhandbuch WF-2530 Series.lnk [2012.10.23 19:32:15 | 000,000,261 | ---- | M] () -- D:\Users\Public\Desktop\Epson Benutzerhandbuch WF-2530 Series.url [2012.10.23 19:29:14 | 000,000,842 | ---- | M] () -- D:\Users\Public\Desktop\EPSON Scan.lnk [2012.10.23 19:22:43 | 000,000,909 | ---- | M] () -- D:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.10.01 17:14:23 | 000,134,184 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys [2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys ========== Files Created - No Company Name ========== [2012.10.24 12:25:24 | 000,001,856 | ---- | C] () -- D:\Users\Public\Desktop\Avira Control Center.lnk [2012.10.23 19:32:25 | 000,000,238 | ---- | C] () -- D:\Users\Public\Desktop\Anleitung für Epson Connect.url [2012.10.23 19:32:22 | 000,002,108 | ---- | C] () -- D:\Users\Public\Desktop\Epson Netzwerkhandbuch WF-2530 Series.lnk [2012.10.23 19:32:15 | 000,000,261 | ---- | C] () -- D:\Users\Public\Desktop\Epson Benutzerhandbuch WF-2530 Series.url [2012.10.23 19:29:14 | 000,000,842 | ---- | C] () -- D:\Users\Public\Desktop\EPSON Scan.lnk [2012.08.21 05:17:16 | 000,039,904 | ---- | C] () -- C:\Windows\System32\dischandler.exe [2012.08.21 05:15:22 | 003,978,240 | ---- | C] () -- C:\Windows\System32\ffmpeg.dll [2012.08.21 05:14:04 | 000,112,640 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2012.08.21 05:12:48 | 000,271,360 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll [2012.08.21 05:12:34 | 000,099,840 | ---- | C] () -- C:\Windows\System32\ff_wmv9.dll [2012.08.21 05:12:32 | 000,157,184 | ---- | C] () -- C:\Windows\System32\ff_unrar.dll [2012.08.21 05:12:30 | 000,147,456 | ---- | C] () -- C:\Windows\System32\ff_libmad.dll [2012.08.21 05:12:28 | 001,525,760 | ---- | C] () -- C:\Windows\System32\ff_samplerate.dll [2012.08.21 05:12:28 | 000,211,968 | ---- | C] () -- C:\Windows\System32\ff_libdts.dll [2012.08.21 05:12:28 | 000,114,688 | ---- | C] () -- C:\Windows\System32\ff_liba52.dll [2012.08.21 05:12:24 | 000,330,240 | ---- | C] () -- C:\Windows\System32\ff_libfaad2.dll [2012.08.12 19:02:06 | 000,032,608 | ---- | C] () -- C:\Windows\king-uninstall.exe [2012.07.23 14:46:36 | 000,138,056 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2012.07.23 14:46:06 | 000,189,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2012.07.23 14:46:01 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2012.07.19 20:56:08 | 000,172,544 | ---- | C] () -- C:\Windows\System32\libbluray.dll [2012.07.19 20:56:02 | 006,894,331 | ---- | C] () -- C:\Windows\System32\avcodec-lav-54.dll [2012.07.19 20:56:02 | 001,111,581 | ---- | C] () -- C:\Windows\System32\avformat-lav-54.dll [2012.07.19 20:56:02 | 000,401,685 | ---- | C] () -- C:\Windows\System32\swscale-lav-2.dll [2012.07.19 20:56:02 | 000,232,895 | ---- | C] () -- C:\Windows\System32\avutil-lav-51.dll [2012.07.19 20:56:02 | 000,162,743 | ---- | C] () -- C:\Windows\System32\avfilter-lav-3.dll [2012.07.19 20:56:02 | 000,101,820 | ---- | C] () -- C:\Windows\System32\avresample-lav-0.dll [2012.06.23 17:23:24 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2012.06.23 17:22:51 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe [2012.06.17 23:15:04 | 000,198,144 | ---- | C] () -- C:\Windows\System32\spdif_test.exe [2012.06.17 23:14:58 | 000,097,792 | ---- | C] () -- C:\Windows\System32\ac3config.exe [2012.06.17 23:14:42 | 001,021,440 | ---- | C] () -- C:\Windows\System32\ac3filter_intl.dll [2012.05.13 00:42:16 | 001,272,320 | ---- | C] () -- C:\Windows\System32\avcodec-53.dll [2012.05.13 00:42:16 | 000,146,432 | ---- | C] () -- C:\Windows\System32\avutil-51.dll [2012.04.18 14:58:53 | 000,000,410 | RHS- | C] () -- D:\ProgramData\ntuser.pol [2011.12.07 21:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\Lagarith.dll [2011.09.08 16:00:52 | 000,150,528 | ---- | C] () -- C:\Windows\System32\mkx.dll [2011.09.08 16:00:48 | 000,142,336 | ---- | C] () -- C:\Windows\System32\mp4.dll [2011.09.08 16:00:42 | 000,123,392 | ---- | C] () -- C:\Windows\System32\ogm.dll [2011.09.08 16:00:38 | 000,249,856 | ---- | C] () -- C:\Windows\System32\dxr.dll [2011.09.08 16:00:34 | 000,113,152 | ---- | C] () -- C:\Windows\System32\dsmux.exe [2011.09.08 16:00:24 | 000,154,624 | ---- | C] () -- C:\Windows\System32\ts.dll [2011.09.08 16:00:10 | 000,137,728 | ---- | C] () -- C:\Windows\System32\mkv2vfr.exe [2011.09.08 16:00:06 | 000,358,400 | ---- | C] () -- C:\Windows\System32\gdsmux.exe [2011.09.08 15:59:54 | 000,080,384 | ---- | C] () -- C:\Windows\System32\mkzlib.dll [2011.09.08 15:59:52 | 000,024,576 | ---- | C] () -- C:\Windows\System32\mkunicode.dll [2011.05.30 15:42:50 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2011.05.23 09:46:30 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2011.03.03 13:39:56 | 000,109,568 | ---- | C] () -- C:\Windows\System32\avi.dll [2011.03.03 13:38:10 | 000,097,792 | ---- | C] () -- C:\Windows\System32\avs.dll [2011.03.03 13:37:50 | 000,093,184 | ---- | C] () -- C:\Windows\System32\avss.dll [2011.01.08 00:47:00 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat ========== ZeroAccess Check ========== [2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 04:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both < End of report > und:OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 26.10.2012 12:26:57 - Run 1 OTL by OldTimer - Version Folder = D:\Users\***\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: | Country: | Language: | Date Format: 1022,18 Mb Total Physical Memory | 299,64 Mb Available Physical Memory | 29,31% Memory free 2,00 Gb Paging File | 0,86 Gb Available in Paging File | 43,15% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 58,50 Gb Total Space | 17,11 Gb Free Space | 29,26% Space Free | Partition Type: NTFS Drive D: | 90,45 Gb Total Space | 24,36 Gb Free Space | 26,94% Space Free | Partition Type: NTFS Drive I: | 34,62 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: *** | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-919462747-3820630327-1177556215-1002\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" [2012.06.24 11:48:18 | 000,000,000 | ---D | M] Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01317951-F34C-4162-A26E-32432C334B05}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{0426707F-A55F-4784-AB40-8A0E9F026485}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe | "{0569FCBE-A21D-4CCB-B81B-878FDF1684B1}" = lport=2869 | protocol=6 | dir=in | app=system | "{09CADF12-3CE1-4BA0-840D-B5A6BFE8EA49}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{0C2E7617-D32F-498B-81B3-101F1FA24D6C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{0DDED58C-D6EA-4410-8B92-49F3D78F1CBA}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{11C9D81C-5692-4892-A3BB-7C83DED334CD}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{15F81160-C818-479D-A6DB-FA5958E397D7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1889A71D-D797-4EBC-96CA-8222B82DEA1C}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{1F055607-38EC-4470-8AEF-43549014BC24}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{1F109EC9-F3DB-47CF-9FFC-0E8EB1889C6E}" = lport=2869 | protocol=6 | dir=in | app=system | "{1F67196C-460D-429F-9851-61B48EC0D2FE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{23E17479-9DF6-4009-9954-8FA1274CC74B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2522AAC4-1D21-4168-A472-4A61FBB1D0F6}" = rport=138 | protocol=17 | dir=out | app=system | "{28C685EF-7ED2-4608-88CC-36FF92FFF110}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2C36160D-ED31-4600-BDCF-E57C5895B5EE}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{2D0D531A-DED5-4F07-8834-5C6313869BFC}" = lport=2869 | protocol=6 | dir=in | app=system | "{30C61123-351C-4A07-994E-4431AFF7CE0B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{33182441-CD4D-4C28-9234-1B9E6358D635}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{35FD9A8C-C528-4EED-B8E0-F0FCF467F6EB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{3601C9DF-DCCF-4A3D-8A0F-8EBD9827A0A2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{3AF86AD3-ADE1-4683-85CD-1489762CD2F9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{3D843518-7235-4C2F-BC83-E39159D5D006}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server | "{400C6798-F0D4-4246-966E-82208802F8A5}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{44A3E55A-84D4-442F-A2F8-A9A95D5DC6F0}" = rport=137 | protocol=17 | dir=out | app=system | "{4D9C372C-3E86-49F1-B530-B345F32B65D9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{5402353D-0E3F-4CAE-BFE5-D0CFBF1E3A12}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{56B6EE03-C243-4412-9439-6A173A62CEDE}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{59AF8638-9732-482F-897D-FE420347AB69}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 | "{61B32218-F32C-4094-8EB9-817B88D6AE97}" = lport=554 | protocol=6 | dir=in | app=c:\windows\ehome\ehshell.exe | "{622AE221-D718-41C9-9B3E-090AF868434A}" = rport=139 | protocol=6 | dir=out | app=system | "{6B7A70D2-2DA6-4C4E-88F9-AE5D3AB2B571}" = lport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{6C5B6D54-3788-4D15-9089-F81015FC9DD6}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server | "{6F61E290-FD17-448B-940A-7838B0F7BF4B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{729596CF-DD05-4DC4-AF39-5476AABA396D}" = lport=445 | protocol=6 | dir=in | app=system | "{7482BD28-6264-4866-9C4C-46DCC02794F8}" = lport=139 | protocol=6 | dir=in | app=system | "{8B6BD808-6942-4CA1-8733-AA203372853E}" = lport=138 | protocol=17 | dir=in | app=system | "{8BEEA1D8-FCE0-496D-9C4E-0D8AD3B4C94B}" = rport=445 | protocol=6 | dir=out | app=system | "{8D41A118-DFDD-40B3-9A83-D97AC95E6A23}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{91B81985-7D5B-4AEB-847B-906AB7DE5A8E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{92EED82A-91A4-463A-96A0-BB21F55A6A0E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{96FBD5A0-B676-4AF3-BEC6-7D74A674B8D4}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{979664D5-E3E6-4AE7-9509-7016A714BE67}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{9B0A52A5-E181-4FC0-97FC-8794A52109CE}" = lport=2869 | protocol=6 | dir=in | app=system | "{9E1B265A-97B2-4850-9A2D-F4EC36A22401}" = rport=2869 | protocol=6 | dir=out | app=system | "{A2B7D33F-AED4-467B-BD05-F98EE604D2D0}" = lport=3390 | protocol=6 | dir=in | app=system | "{A4DAACEE-5348-4B02-BA9E-DB24C28010D0}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\netproj.exe | "{A59D3973-9800-4F42-A2A9-8454DD897444}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{A6F06F59-A99D-4F9E-A938-0B5AF884EFC6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{AC55FDDB-FB17-4C42-B817-2268945A0AAA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B4812DB5-EAFF-4C12-8D5C-E72AF9C8DD8B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B7432C90-3DBE-4393-8F7E-95EF85DCFECE}" = lport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{BD6D4B2C-56FE-4406-AF6C-FCBEE352ACC4}" = lport=137 | protocol=17 | dir=in | app=system | "{C0380397-60B7-4C7C-9FE7-C631C6F7E797}" = lport=10243 | protocol=6 | dir=in | app=system | "{C11ECC1A-B60B-4F81-B10F-BE1E54611037}" = rport=10243 | protocol=6 | dir=out | app=system | "{C2F3940D-E8D9-45FA-86AE-76FB9F06ECD9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C61181F0-985A-45E1-AA59-6658C7EAD503}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C800A6BF-CDA5-4B6D-912A-D2D917AB8B41}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{D4938CD4-4977-4DC0-8221-19BECC2A2253}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D606D20D-09E6-4C13-9082-BD662784844E}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{D8EE8D55-49A1-4C4C-9716-886D99589B9A}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{DA26692E-2186-464C-9927-CFA631E40C38}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\netproj.exe | "{DE405469-1F0C-453A-9088-1D707A7CA883}" = lport=10244 | protocol=6 | dir=in | app=system | "{DFF5C5C7-72F1-4EB0-A811-4BC9F0E6144A}" = lport=10244 | protocol=6 | dir=in | app=system | "{E231E63E-55A0-49D5-8231-AD62148515B8}" = lport=2869 | protocol=6 | dir=in | app=system | "{E3DCA666-088A-4991-9E2E-FC6A24763884}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E690130B-C423-403A-998C-C6523029A97B}" = lport=3390 | protocol=6 | dir=in | app=system | "{E7DC4557-6A15-4DCD-9C40-F39EFB217FBF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{EA694F3C-6F3B-4382-94F4-DDED3059A55F}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe | "{F06A6868-836E-4F75-8C3B-893B066F3E10}" = lport=7777 | protocol=17 | dir=in | app=c:\windows\ehome\ehshell.exe | "{F51E62F8-D626-469B-8522-28DC0498732F}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FD21DD34-66CE-4CA0-B430-EDCDEE0B95D7}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{FDA832AF-3A00-43AD-A94C-94A4059079CB}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server | "{FE2B090B-3323-4DE8-A6BE-FCCE55BC4A02}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server | "{FE79C23D-991C-426C-84D2-E78B5479033A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01BFB718-0E37-4464-8993-F2FF931139EB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{04C4C757-0BA7-41C0-8665-0DD3D8B1E09B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{11236FC2-3829-430C-80AE-DF2B400B311E}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe | "{1279F747-03B1-46CA-94FD-577EF16445B7}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe | "{14CE9F7D-0C18-445F-BB1E-DD510A16C506}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{1A916E9B-B6A0-4BA4-8712-5AD8AA2AB339}" = protocol=6 | dir=out | svc=mcx2svc | app=c:\windows\system32\svchost.exe | "{2547E45D-1457-4C6C-A8D2-F2E9E7BB5E3D}" = protocol=17 | dir=in | app=e:\network\epsonnetsetup\eneasyapp.exe | "{29CE1E3B-C8AD-4B5E-B06B-9D791E866AEE}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{2F218F98-18EF-48CA-A440-D25AC01F5853}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{322487AD-B84D-431B-BD80-398D8624A5DA}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe | "{3437DD1A-F184-420E-9DB0-E7044399BBF2}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe | "{3786110F-E6A4-4D8A-B8A3-4F82BC4B4FB6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{38BE1B5C-C2E6-4F82-A222-CD3B6AE7D0D8}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{3A9AA540-D35C-497E-BED7-A82F0BFB36F3}" = protocol=6 | dir=out | app=system | "{468B1730-C7C1-4B00-9565-E9FCA654A1EA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{4698B2EA-8246-4757-B5EB-2105D1B41CDD}" = protocol=6 | dir=in | app=e:\network\epsonnetsetup\eneasyapp.exe | "{52212E20-BF4A-404F-A936-3A04AD99AC95}" = protocol=17 | dir=out | app=c:\windows\ehome\ehshell.exe | "{53AB3923-EEEE-400B-83BB-1F519F79AA08}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe | "{56A5B17A-3ADA-4C79-B680-CA0EA8DC703D}" = protocol=6 | dir=in | app=d:\users\katharina kothe\appdata\local\akamai\netsession_win.exe | "{5DB9F1D3-7FA9-45A1-AEB0-563395EA2051}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{6242D867-1825-4560-A7C5-435AE37B3117}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe | "{6306F548-2BAB-4A57-9B46-48D22EF80A7E}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe | "{6388178A-692F-43DD-9F55-3A664E0A8A2C}" = protocol=6 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{6A780753-83AA-417A-A151-52B8BBCF067D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{6E493F54-20DE-4213-95C9-DC9775278EC8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{6FA87BB7-DF2E-4088-AC96-AC3C46C25B9D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{70CF2208-87EB-43F5-9F25-E96B3E94C613}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{768C1348-F86E-443C-92B4-3CB074387C3C}" = protocol=6 | dir=out | svc=msiscsi | app=%systemroot%\system32\svchost.exe | "{7D2E2C33-3612-406B-ACAE-E2FDBF3A6FEE}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe | "{826D287E-7800-4218-A7E1-C98BEE37684D}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe | "{8326AEE8-25A0-496F-887B-855AACB18A2F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{88ED6A5A-AEA0-4F8A-8116-C0043FE253FC}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{8B18C83A-2ED1-4B26-BE6C-8BACD8D706A6}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{8E380993-52C3-48C6-8F27-57306B8CE99A}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe | "{9D28CD99-C967-4917-ACCF-6CCBBC3DC4C4}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe | "{9DEE47F8-A4EA-4F75-A657-08F37222E6A4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{A1911A50-4965-48C5-8B85-6A8E963F21CA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A71AD3A6-57BC-4E0C-A7F4-E893619F99EE}" = protocol=6 | dir=out | app=c:\windows\ehome\mcx2prov.exe | "{A92FB52A-7FED-47DD-A70E-F82B40B17962}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{AA13C96C-2127-4BBA-A769-07799188D519}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe | "{AC3CAD39-9107-4BA9-B244-DF622BAB3252}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{BC32A4E7-ED29-4C69-A8AE-83B89CCB9E57}" = protocol=17 | dir=in | app=d:\users\***\appdata\local\akamai\netsession_win.exe | "{CAF93B24-337B-4C47-961D-89558DDAF347}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{CE5E5CF2-075C-4BC3-A287-893E94C38C26}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcrmgr.exe | "{D18A5D3C-42BB-4B67-A896-9866547DEDC0}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{D202941B-5C13-45B0-A300-A442BFB32053}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D34F6768-FF02-42A7-AD26-B333CDDC115D}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe | "{D3D673C4-2ECE-461F-95BF-75F9D7123B8E}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{D659BECC-A6CB-4AFA-A805-142815C7FB52}" = protocol=6 | dir=in | svc=msiscsi | app=%systemroot%\system32\svchost.exe | "{DACC1903-6DC2-4CE8-9816-2844C7131041}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{E11E80A3-32EF-4CAF-BC36-777902EA5B67}" = protocol=6 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe | "{E1A6E71F-F262-4A20-A125-ACEF0FA6FA0A}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe | "{E7CA0DF6-5A4A-4952-BB6D-CEE15F3C9A50}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{EB78F8EB-85E4-4C27-AC25-23CB37F08A06}" = protocol=6 | dir=out | app=c:\windows\ehome\mcrmgr.exe | "{F0EE5FE3-2AC1-4344-B5B1-133E72F9DBD2}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{F9E6E961-0571-4033-8A85-D2906575B811}" = protocol=6 | dir=out | app=c:\windows\ehome\ehshell.exe | "TCP Query User{13584169-3241-4B3B-B296-7AF27730B305}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "TCP Query User{325E92E6-C174-45BF-8EAF-E97EDB861577}D:\users\***\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=d:\users\***\appdata\local\akamai\netsession_win.exe | "TCP Query User{605F88F9-0800-4F7A-A6E8-6BD30DB9CF18}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe | "TCP Query User{A4F92D4F-B960-41C9-BD6D-B05FE1124947}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe | "UDP Query User{25E41CE3-C203-4FB5-9192-7D7B04D6F801}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe | "UDP Query User{886DA2FC-C603-4B02-A62F-01BE2237EEB9}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "UDP Query User{A0DA0603-87A6-4631-BA21-88A430A7088A}D:\users\***\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=d:\users\***\appdata\local\akamai\netsession_win.exe | "UDP Query User{C07702E1-A825-482C-B7EF-0FA737967633}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01E9B2FF-DAF4-4529-9CC9-2101625517C7}" = nero.prerequisites.msi "{034DCAF9-96E7-4936-9A07-712F80B5181E}" = Nero RescueAgent 11 "{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4 "{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4 "{05A6B1CD-AA10-46A0-8D5C-6AD2A9EEFC8B}" = Nero Burning ROM 11 "{098727E1-775A-4450-B573-3F441F1CA243}" = kuler "{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4 "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour "{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}" = Epson FAX Utility "{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4 "{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4 "{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4 "{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}" = Nero ControlCenter 11 "{14F70205-1940-4000-88C7-BE799A6B2CAD}" = Adobe Soundbooth CS4 "{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4 "{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4 "{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4 "{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB "{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR "{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server "{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4 "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources "{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9 "{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models "{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman) "{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4 "{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4 "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player "{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4 "{3A6829EF-0791-4FDD-9382-C690DD0821B9}" = Adobe Flash Player 10 ActiveX "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4 "{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin "{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print "{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4 "{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit "{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets "{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4 "{47C6F987-685A-41AE-B092-E75B277AEE39}" = Adobe Flash CS4 Extension - Flash Lite STI others "{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4 "{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs "{53F7746A-96AA-49A5-86B8-59989680DAC5}" = Nero Burning ROM 11 Help (CHM) "{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter "{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4 "{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support "{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection "{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4 "{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support "{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update "{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content "{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4 "{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4 "{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files "{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer "{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4 "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4 "{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8AAB4176-A747-493A-A42C-B63CFADFD8E3}" = NVIDIA PhysX "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8F01524C-0676-4CC1-B4AE-64753C723391}" = Epson Event Manager "{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 "{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 "{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 "{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}_PRJPRO_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}_VISPRO_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}_PRJPRO_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}_PRJPRO_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0410-0000-0000000FF1CE}_PRJPRO_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0410-0000-0000000FF1CE}_VISPRO_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007 "{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{8446EB22-A746-46DC-B1BD-E0DFA1F3CDDA}" = Microsoft Office Project 2007 Service Pack 3 (SP3) "{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007 "{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007 "{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{CE144BF4-4950-4CDB-A5F7-CCE1888F49CB}" = Microsoft Office Visio 2007 Service Pack 3 (SP3) "{90120000-0054-0407-0000-0000000FF1CE}" = Microsoft Office Visio MUI (German) 2007 "{90120000-0054-0407-0000-0000000FF1CE}_VISPRO_{3CB0380B-0413-4C44-A63B-DCD6369EAF4E}" = Microsoft Office Visio 2007 Service Pack 3 (SP3) "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0407-0000-0000000FF1CE}_PRJPRO_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0407-0000-0000000FF1CE}_VISPRO_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00B4-0407-0000-0000000FF1CE}" = Microsoft Office Project MUI (German) 2007 "{90120000-00B4-0407-0000-0000000FF1CE}_PRJPRO_{C8D442F2-CF33-486E-8079-A704A2E80A39}" = Microsoft Office Project 2007 Service Pack 3 (SP3) "{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007 "{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4 "{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A6EC82A0-1414-475D-8AFD-469089F3080D}" = Adobe Contribute CS4 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch "{AC76BA86-1033-F400-7760-000000000004}_952" = Adobe Acrobat 9.5.2 - CPSID_83708 "{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter "{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4 "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail "{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4 "{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content "{B1846721-A8E6-46C7-83B6-0DCF7ADB4267}" = Nero Burning ROM 11 "{B29AD377-CC12-490A-A480-1452337C618D}" = Connect "{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4 "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4 "{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module "{BD3374D3-C2E6-42B7-A80B-E850B6886246}" = Adobe Flash CS4 STI-other "{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter "{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components 11 "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4 "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant "{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content "{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D01CE99A-8802-483C-A79F-298B691EB432}" = Nero RescueAgent 11 Help (CHM) "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4 "{D4D66270-9147-4BDF-9946-FCA2B303AA8F}" = Nero ControlCenter 11 Help (CHM) "{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4 "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup "{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5 "{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4 "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{F7B05784-334C-4F76-8BAB-30ABEB7FD534}" = TIPCI "{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4 "{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4 "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs "{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All "5513-1208-7298-9440" = JDownloader 0.9 "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection "Agere Systems Soft Modem" = Agere Systems HDA Modem "Akamai" = Akamai NetSession Interface Service "Allway Sync_is1" = Allway Sync version 9.1.7 "Avira AntiVir Desktop" = Avira Free Antivirus "AviSynth" = AviSynth 2.5 "CANONIJINBOXADDON100" = Canon Inkjet Printer Driver Add-On Module "CCleaner" = CCleaner "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player "ENTERPRISE" = Microsoft Office Enterprise 2007 "Epson Connect Guide" = Anleitung für Epson Connect "EPSON PC-FAX Driver 2" = Epson PC-FAX Driver "EPSON Scanner" = EPSON Scan "EPSON WF-2530 Series" = EPSON WF-2530 Series Printer Uninstall "ESET Online Scanner" = ESET Online Scanner v3 "Free Video to DVD Converter_is1" = Free Video to DVD Converter version "HUAWEI DataCard Driver" = HUAWEI DataCard Driver "ImgBurn" = ImgBurn "InstallShield_{F7B05784-334C-4F76-8BAB-30ABEB7FD534}" = Texas Instruments PCIxx21/x515/xx12 drivers. "king.com" = king.com (remove only) "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version "Media Player - Codec Pack" = Media Player Codec Pack 4.2.2 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Mozilla Firefox 15.0.1 (x86 de)" = Mozilla Firefox 15.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Notepad++" = Notepad++ "NVIDIA Drivers" = NVIDIA Drivers "o2DE" = Mobile Connection Manager "PokerStars" = PokerStars "PRJPRO" = Microsoft Office Project Professional 2007 "PunkBusterSvc" = PunkBuster Services "VISPRO" = Microsoft Office Visio Professional 2007 "VLC media player" = VLC media player 2.0.1 "WF-2530 Series Netg" = Epson Netzwerkhandbuch WF-2530 Series "WF-2530 Series Useg" = Epson Benutzerhandbuch WF-2530 Series "WinLiveSuite" = Windows Live Essentials "WinRAR archiver" = WinRAR ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 25.10.2012 20:09:08 | Computer Name = *** | Source = Microsoft-Windows-User Profiles Service | ID = 1542 Description = Die Klassenregistrierungsdatei kann nicht geladen werden. DETAIL - Das System kann die angegebene Datei nicht finden. Error - 25.10.2012 20:09:09 | Computer Name = *** | Source = Microsoft-Windows-User Profiles Service | ID = 1542 Description = Die Klassenregistrierungsdatei kann nicht geladen werden. DETAIL - Das System kann die angegebene Datei nicht finden. Error - 25.10.2012 20:12:29 | Computer Name = *** | Source = MsiInstaller | ID = 11500 Description = Error - 26.10.2012 05:14:15 | Computer Name = *** | Source = Microsoft-Windows-User Profiles Service | ID = 1542 Description = Die Klassenregistrierungsdatei kann nicht geladen werden. DETAIL - Das System kann die angegebene Datei nicht finden. Error - 26.10.2012 05:14:35 | Computer Name = *** | Source = Microsoft-Windows-User Profiles Service | ID = 1542 Description = Die Klassenregistrierungsdatei kann nicht geladen werden. DETAIL - Das System kann die angegebene Datei nicht finden. Error - 26.10.2012 05:32:23 | Computer Name = ***| Source = Microsoft-Windows-User Profiles Service | ID = 1542 Description = Die Klassenregistrierungsdatei kann nicht geladen werden. DETAIL - Das System kann die angegebene Datei nicht finden. Error - 26.10.2012 05:32:40 | Computer Name = *** | Source = Microsoft-Windows-User Profiles Service | ID = 1542 Description = Die Klassenregistrierungsdatei kann nicht geladen werden. DETAIL - Das System kann die angegebene Datei nicht finden. Error - 26.10.2012 05:56:00 | Computer Name = *** | Source = Microsoft-Windows-User Profiles Service | ID = 1542 Description = Die Klassenregistrierungsdatei kann nicht geladen werden. DETAIL - Das System kann die angegebene Datei nicht finden. Error - 26.10.2012 05:56:00 | Computer Name = *** | Source = Microsoft-Windows-User Profiles Service | ID = 1542 Description = Die Klassenregistrierungsdatei kann nicht geladen werden. DETAIL - Das System kann die angegebene Datei nicht finden. Error - 26.10.2012 05:56:30 | Computer Name = *** | Source = Microsoft-Windows-User Profiles Service | ID = 1542 Description = Die Klassenregistrierungsdatei kann nicht geladen werden. DETAIL - Das System kann die angegebene Datei nicht finden. Error - 26.10.2012 05:56:30 | Computer Name = *** | Source = Microsoft-Windows-User Profiles Service | ID = 1542 Description = Die Klassenregistrierungsdatei kann nicht geladen werden. DETAIL - Das System kann die angegebene Datei nicht finden. Error - 26.10.2012 06:26:46 | Computer Name = *** | Source = Microsoft-Windows-User Profiles Service | ID = 1542 Description = Die Klassenregistrierungsdatei kann nicht geladen werden. DETAIL - Das System kann die angegebene Datei nicht finden. [ Media Center Events ] Error - 17.10.2012 09:06:04 | Computer Name = *** | Source = Microsoft-Windows-Media Center Extender | ID = 700 Description = Error - 19.10.2012 04:48:23 | Computer Name = *** | Source = MCUpdate | ID = 0 Description = 10:48:22 - Fehler beim Herstellen der Internetverbindung. 10:48:23 - Serververbindung konnte nicht hergestellt werden.. Error - 19.10.2012 04:48:39 | Computer Name = ***| Source = MCUpdate | ID = 0 Description = 10:48:28 - Fehler beim Herstellen der Internetverbindung. 10:48:28 - Serververbindung konnte nicht hergestellt werden.. Error - 19.10.2012 06:04:25 | Computer Name = *** | Source = Microsoft-Windows-Media Center Extender | ID = 700 Description = Error - 20.10.2012 07:19:55 | Computer Name = *** | Source = MCUpdate | ID = 0 Description = 13:19:51 - Fehler beim Herstellen der Internetverbindung. 13:19:52 - Serververbindung konnte nicht hergestellt werden.. Error - 24.10.2012 05:31:35 | Computer Name = *** | Source = MCUpdate | ID = 0 Description = 11:31:30 - Fehler beim Herstellen der Internetverbindung. 11:31:34 - Serververbindung konnte nicht hergestellt werden.. Error - 24.10.2012 05:31:56 | Computer Name = *** | Source = MCUpdate | ID = 0 Description = 11:31:40 - Fehler beim Herstellen der Internetverbindung. 11:31:40 - Serververbindung konnte nicht hergestellt werden.. Error - 24.10.2012 17:35:56 | Computer Name = *** | Source = Microsoft-Windows-Media Center Extender | ID = 700 Description = Error - 26.10.2012 05:23:35 | Computer Name = *** | Source = MCUpdate | ID = 0 Description = 11:23:34 - Fehler beim Herstellen der Internetverbindung. 11:23:35 - Serververbindung konnte nicht hergestellt werden.. Error - 26.10.2012 05:23:50 | Computer Name = *** | Source = MCUpdate | ID = 0 Description = 11:23:40 - Fehler beim Herstellen der Internetverbindung. 11:23:40 - Serververbindung konnte nicht hergestellt werden.. [ OSession Events ] Error - 26.01.2012 17:24:19 | Computer Name = AcerAspire | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6437 seconds with 60 seconds of active time. This session ended with a crash. [ System Events ] Error - 25.10.2012 15:58:44 | Computer Name = *** | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{1870C08F-25DD-4B36-B5E3-13F7E4ECD812} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error - 25.10.2012 16:43:56 | Computer Name = ***| Source = ipnathlp | ID = 31004 Description = Error - 25.10.2012 16:43:57 | Computer Name = *** | Source = ipnathlp | ID = 31004 Description = Error - 25.10.2012 17:25:25 | Computer Name = *** | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{1870C08F-25DD-4B36-B5E3-13F7E4ECD812} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error - 26.10.2012 05:15:39 | Computer Name = *** | Source = DCOM | ID = 10005 Description = Error - 26.10.2012 05:15:39 | Computer Name = *** | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error - 26.10.2012 05:15:39 | Computer Name = *** | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 26.10.2012 05:28:57 | Computer Name = *** | Source = ipnathlp | ID = 31004 Description = Error - 26.10.2012 05:36:56 | Computer Name = *** | Source = Server | ID = 2505 Description = Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{1870C08F-25DD-4B36-B5E3-13F7E4ECD812} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error - 26.10.2012 05:56:39 | Computer Name = *** | Source = VDS Basic Provider | ID = 33554433 Description = [ Windows PowerShell Events ] Error - 23.10.2012 14:21:44 | Computer Name = *** | Source = PowerShell | ID = 103 Description = Error - 24.10.2012 08:21:00 | Computer Name = *** | Source = PowerShell | ID = 103 Description = Error - 26.10.2012 05:45:03 | Computer Name = *** | Source = PowerShell | ID = 103 Description = Error - 26.10.2012 05:50:54 | Computer Name = ***| Source = PowerShell | ID = 103 Description = < End of report > Geändert von champjan (26.10.2012 um 15:20 Uhr) |
![]() | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows fehlerhaft, langsam, Malware??? Es ging eher um Logs deines Virenscanners oder von Malwarebytes, FALLS es Funde dadrin gibt Oder hat niemals ein Virenscanner bisher angeschlagen?
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #5 |
| ![]() Windows fehlerhaft, langsam, Malware??? nein, keine funde, gar nichts leider. eset läuft grad noch |
![]() |
Themen zu Windows fehlerhaft, langsam, Malware??? |
acer, altes, amerika, avira, brauche, defender, dringend, fehler, fehlerhaft, fix, google, langsam, länger, löschen, malwarebytes, nicht mehr, nichts, notebook, papierkorb, plötzlich, programm, programme, schriften, taskleiste, tastatur, trojaner?!, windows, windows kaputt?! |