Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Netzwerkprobleme - Schädling eingefangen?

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 15.06.2013, 11:44   #1
Bambaataa22
 
Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Moin,

mein Arbeitskollege hat Probleme mit seinem Rechner.
Und zwar kann Starmoney keinen Konatkt zum Starmoney-Service aufnehmen.
Dann scheitert z.B. die Lizenz-Überprüfung.
"Normales" Banking, z.B. Kontenabruf und Überweisungen funktionieren, Internet im Allgemeinen funktioniert auch.
Im Starmoney gibt es auch einen Reparatur-Modus der eine Onlineverbindung voraus setzt.
Der Download der automatisch startet wenn man die Reparatur aufruft bricht aber immer ab.

Ich hatte den Verdacht, dass es evtl. an dem Uralt-Siemens-Modem liegt, aber auf meinem Laptop funktioniert Starmoney einwandfrei in seinem Netzwerk.

Ich hab mir den Rechner angesehen und erstmal einen ganzen Sack an "Optimierern" runtergeschmissen. Darunter Norton Internet Security ComputerBildEdition, TuneUp, irgendwelche Privacy-Verbesserer, Reg-Cleaner, System-Scanner usw.

Dann hab ich diverse VPN-Geschichten deinstalliert.
Der Rechner war mal ein Heimarbeitsplatz von seiner Frau, wird aber jetzt als Wohnzimmer-PC eingesetzt.
Alles was noch an VPN- und Versicherungskram drauf ist kann runter wenn nötig.

MalwareBytes hat nichts gefunden, aber könnte sich bitte mal einer von euch die OTL-und GMER-Logs anschauen ob da irgendwas im Argen liegt?

Vielen Dank im Voraus!

MfG Bam

Code:
ATTFilter
OTL logfile created on: 14.06.2013 17:47:30 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\S. Voß HUK\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,93 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 60,03% Memory free
7,86 Gb Paging File | 6,29 Gb Available in Paging File | 80,12% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 458,87 Gb Total Space | 386,23 Gb Free Space | 84,17% Space Free | Partition Type: NTFS
Drive D: | 458,87 Gb Total Space | 456,39 Gb Free Space | 99,46% Space Free | Partition Type: NTFS
Drive K: | 931,28 Gb Total Space | 667,34 Gb Free Space | 71,66% Space Free | Partition Type: FAT32
Drive L: | 1863,01 Gb Total Space | 1793,28 Gb Free Space | 96,26% Space Free | Partition Type: NTFS
Drive M: | 931,51 Gb Total Space | 930,82 Gb Free Space | 99,93% Space Free | Partition Type: NTFS
 
Computer Name: BUERO | User Name: S. Voß HUK | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013.06.14 17:47:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\S. Voß HUK\Downloads\OTL.exe
PRC - [2013.02.13 12:38:24 | 000,844,144 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2013.02.13 12:38:14 | 001,509,232 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe
PRC - [2012.12.21 15:48:08 | 000,699,680 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) -- C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe
PRC - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.03.19 21:58:12 | 000,514,128 | ---- | M] (REINER SCT) -- C:\Windows\SysWOW64\cjpcsc.exe
PRC - [2011.05.24 10:33:30 | 001,840,128 | ---- | M] (MAGIX AG) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
PRC - [2010.04.27 11:09:52 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2010.04.20 17:13:56 | 002,104,320 | ---- | M] (AGFEO      ) -- C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe
PRC - [2010.03.26 04:29:36 | 000,563,744 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
PRC - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Programme\Acer\Acer Updater\UpdaterService.exe
PRC - [2009.12.09 11:24:16 | 000,076,320 | ---- | M] () -- C:\OEM\USBDECTION\USBS3S4Detection.exe
PRC - [2009.08.28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
PRC - [2009.01.27 19:45:38 | 000,059,392 | ---- | M] (AGFEO      ) -- C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tkmedia.exe
PRC - [2009.01.08 17:10:00 | 000,187,456 | ---- | M] (DATA BECKER GmbH & Co KG) -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe
PRC - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2013.05.16 03:07:14 | 018,022,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\1f0bb5336d1706c9b8ad2330f3642760\PresentationFramework.ni.dll
MOD - [2013.05.16 03:07:04 | 011,522,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\9b2940478ec555990b37af5448b8f509\PresentationCore.ni.dll
MOD - [2013.05.16 03:06:57 | 007,070,208 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\93a17ba6cb6753328f25466bc0bf1cb1\System.Core.ni.dll
MOD - [2013.05.16 03:06:53 | 003,883,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\a1949f57d2ec260e09768e98fecb0559\WindowsBase.ni.dll
MOD - [2013.05.16 03:06:51 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ddc3e8c2774eaec614d6775983652980\System.Configuration.ni.dll
MOD - [2013.02.14 04:18:46 | 000,221,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\7d8f6866864f78cf83d3701641c46178\System.ServiceProcess.ni.dll
MOD - [2013.01.10 04:32:15 | 001,812,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\40c7a89fe2cbf3c12a2c39e034da54cf\System.Xaml.ni.dll
MOD - [2013.01.10 04:15:01 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\fc476bbac36944e352c2f547352ffa64\System.Xml.ni.dll
MOD - [2013.01.10 04:14:55 | 009,095,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\f93dca0e4baa1dcb37cf75392b7c89da\System.ni.dll
MOD - [2013.01.10 04:14:51 | 014,416,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\6a1ccc1e1a79ce267d3d1808af382cd6\mscorlib.ni.dll
MOD - [2010.03.26 04:29:36 | 000,563,744 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
MOD - [2010.03.26 04:29:36 | 000,154,144 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2012.09.28 03:38:16 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2013.06.14 16:56:23 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.12.21 15:48:08 | 000,699,680 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Running] -- C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 8.0 OnlineUpdate)
SRV - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.11.09 12:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.03.19 21:58:12 | 000,514,128 | ---- | M] (REINER SCT) [Auto | Running] -- C:\Windows\SysWOW64\cjpcsc.exe -- (cjpcsc)
SRV - [2011.05.24 10:33:30 | 001,840,128 | ---- | M] (MAGIX AG) [Auto | Running] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2011.04.26 13:54:12 | 002,702,848 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2010.12.10 18:36:54 | 000,153,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2010.05.06 11:30:22 | 000,357,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2010.04.20 17:13:56 | 002,104,320 | ---- | M] (AGFEO      ) [Auto | Running] -- C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe -- (tksock)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.01 20:04:40 | 000,305,520 | ---- | M] (Egis Technology Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe -- (MWLService)
SRV - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Programme\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2010.01.15 23:08:38 | 000,935,208 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.12.09 11:24:16 | 000,076,320 | ---- | M] () [Auto | Running] -- C:\OEM\USBDECTION\USBS3S4Detection.exe -- (USBS3S4Detection)
SRV - [2009.08.28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.01.08 17:10:00 | 000,187,456 | ---- | M] (DATA BECKER GmbH & Co KG) [Auto | Running] -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe -- (DBService)
SRV - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService)
SRV - [2007.05.31 18:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007.05.31 18:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2013.02.12 06:12:06 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2012.09.28 04:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.09.28 03:12:52 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.09.20 06:35:36 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudserd.sys -- (ssudserd)
DRV:64bit: - [2012.09.20 06:35:36 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2012.09.20 06:35:36 | 000,102,368 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2012.05.14 08:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.08.07 14:56:22 | 000,116,096 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avmaudio.sys -- (avmaudio)
DRV:64bit: - [2011.06.10 14:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.03.29 10:50:26 | 000,034,672 | ---- | M] (REINER SCT) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cjusb.sys -- (cjusb)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.03.03 13:42:16 | 000,528,464 | ---- | M] (Paragon) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\Uim_IMx64.sys -- (Uim_IM)
DRV:64bit: - [2011.03.03 13:42:16 | 000,053,840 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\uimx64.sys -- (UimBus)
DRV:64bit: - [2011.03.03 13:42:14 | 000,037,456 | ---- | M] (Paragon Software Group) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hotcore3.sys -- (hotcore3)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.09.30 14:00:06 | 000,180,736 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010.09.30 14:00:06 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010.03.18 11:00:16 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2010.03.18 11:00:00 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2010.02.24 12:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11)
DRV:64bit: - [2010.01.28 03:33:38 | 000,116,736 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009.12.09 11:39:52 | 000,537,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.06.03 04:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009.06.03 04:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009.06.03 04:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2009.02.20 20:09:18 | 000,054,272 | ---- | M] (Siemens Home and Office Communication Devices GmbH & Co. KG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GigasetGenericUSB_x64.sys -- (GigasetGenericUSB_x64)
DRV:64bit: - [2009.01.14 19:55:38 | 000,092,672 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ser2pl64.sys -- (Ser2pl)
DRV - [2013.02.05 10:54:40 | 000,037,344 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2011.03.03 12:42:14 | 000,022,096 | ---- | M] (Paragon Software GmbH) [Kernel | On_Demand | Stopped] -- K:\Program Files (x86)\Paragon Software\Festplatten Manager 2011 Kompakt\bluescrn\biont_bs.sys -- (BioNT_BS)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.ewetel.de/index.htm [binary data]
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_x3950&r=173608102207pe458v135w4651v85o
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deDE392DE394
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.dmz.huk.de;*.hukvm.de;*.hukras.de;*.lan.huk-coburg.de;vtp.huk.de;vtp02.huk.de;vtp03.huk.de;vtp04.huk.de;vtp05.huk.de;vtpews.huk.de;crl1.huk-coburg.de;vtp.vrk.de;svks0009.vrk.de;sscd0040
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.149.137.1:8080
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2011.05.15 13:48:50 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: K:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2011.05.15 13:48:50 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: K:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@protectdisc.com/NPPDLicenseHelper: C:\Users\S. Voß HUK\AppData\Roaming\ProtectDisc\License Helper v2\NPPDLicenseHelper.dll ( )
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101753.dll (Amazon.com, Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\passworddepot@acebit.com: C:\Program Files (x86)\AceBIT\Password Depot 5\Firefox\ [2011.04.25 09:41:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{09F060FA-566D-42D7-BF79-97AB30863433}: K:\Program Files (x86)\Steganos Privacy Suite 2012\pfplugin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{00F0643E-B367-4779-B45D-7046EBA37A88}: K:\Program Files (x86)\Steganos Privacy Suite 2012\spmplugin3
 
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: hxxp://www.google.com
CHR - Extension: YouTube = C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google-Suche = C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Google Mail = C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
 
O1 HOSTS File: ([2013.06.14 17:36:07 | 000,000,825 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Password Depot 5) - {9F79B165-70F7-4C46-B1A5-8828E2FF21F9} - C:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll (AceBIT)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] K:\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-210379488-4132890845-1450444768-1001..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-210379488-4132890845-1450444768-1001..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe (Samsung Electronics)
O4 - HKU\S-1-5-21-210379488-4132890845-1450444768-1001..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Password Depot 5 - {9F79B165-70F7-4C46-B1A5-8828E2FF21F9} - C:\Program Files (x86)\AceBIT\Password Depot 5\PasswordDepot.exe (AceBIT GmbH)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {28B66320-9687-4B13-8757-36F901887AB5} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/canvasx64.cab (CanvasX Class)
O16:64bit: - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/jordan64.cab (JordanUploader Class)
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{77E05783-9DA1-425A-BBC3-9A5C89C94808}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (K:\PROGRA~1\PARAGO~1\FESTPL~1\bluescrn\bluescrn.exe)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.05.20 08:20:03 | 000,000,000 | ---D | C] -- C:\Users\S. Voß HUK\Documents\The Lonely Hearts Murders CE
[3 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.06.14 17:50:00 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.06.14 17:50:00 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.06.14 17:42:51 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.06.14 17:42:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.06.14 17:42:36 | 3163,901,952 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.14 17:29:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.06.14 17:24:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.06.14 16:52:45 | 001,746,324 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.06.14 16:52:45 | 000,757,356 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.06.14 16:52:45 | 000,701,816 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.06.14 16:52:45 | 000,172,606 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.06.14 16:52:45 | 000,139,382 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.06.14 16:52:40 | 001,746,324 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.06.14 15:27:55 | 000,000,277 | ---- | M] () -- C:\Users\S. Voß HUK\Documents\smoney_key.rtf
[2013.06.09 13:12:22 | 000,057,399 | ---- | M] () -- C:\Windows\wininit.ini
[2013.05.23 19:17:27 | 000,460,680 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[3 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.06.14 15:27:54 | 000,000,277 | ---- | C] () -- C:\Users\S. Voß HUK\Documents\smoney_key.rtf
[2013.05.23 19:17:16 | 000,460,680 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.02.15 10:53:22 | 000,110,592 | ---- | C] () -- C:\Windows\SysWow64\FsUsbExDevice.Dll
[2013.02.15 10:53:22 | 000,037,344 | ---- | C] () -- C:\Windows\SysWow64\FsUsbExDisk.Sys
[2012.12.28 11:18:12 | 000,000,017 | ---- | C] () -- C:\Users\S. Voß HUK\AppData\Local\resmon.resmoncfg
[2012.12.25 14:16:06 | 000,000,291 | ---- | C] () -- C:\Windows\game.ini
[2012.12.18 15:24:12 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2012.09.01 13:24:27 | 000,057,399 | ---- | C] () -- C:\Windows\wininit.ini
[2012.07.10 17:23:23 | 000,167,936 | ---- | C] () -- C:\Windows\SysWow64\SerialXP.dll
[2012.07.10 17:23:23 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\win32com.dll
[2012.07.10 15:33:09 | 000,000,827 | ---- | C] () -- C:\Windows\hbcikrnl.ini
[2012.06.26 16:02:40 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012.06.26 16:02:38 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012.06.26 16:02:38 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012.06.26 16:02:38 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012.06.26 16:02:38 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012.06.11 18:50:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.06.11 18:50:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.05.05 15:44:24 | 000,017,408 | ---- | C] () -- C:\Users\S. Voß HUK\AppData\Local\WebpageIcons.db
[2012.05.02 15:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010.03.20 01:05:19 | 000,131,472 | ---- | C] () -- C:\ProgramData\FullRemove.exe
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2012.09.14 15:28:50 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\4 Friends Games
[2011.04.25 09:42:14 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\AceBIT
[2010.12.22 18:40:11 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\AGFEO
[2012.12.15 15:19:20 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Alawar Stargaze
[2013.05.26 09:02:19 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\AlawarEntertainment
[2012.09.24 17:20:28 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\aliasworlds
[2012.12.17 11:24:00 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Amazon
[2010.08.24 15:37:55 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\AntiBrowserSpy 2009
[2012.12.23 14:54:14 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Artifex Mundi
[2013.01.13 15:06:24 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Artogon
[2012.11.19 20:46:30 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Ashampoo
[2012.10.18 15:43:32 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Az-Art
[2013.03.28 07:55:26 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\BlamGames
[2013.05.23 14:47:09 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Blue Tea Games
[2013.06.09 12:16:49 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Boomzap
[2011.07.15 13:31:15 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Canon
[2013.03.02 19:29:26 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\cerasus.media
[2013.04.25 14:38:27 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\DailyMagic
[2013.04.11 14:15:38 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Deep Shadows
[2013.05.05 12:36:37 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\DriverCure
[2013.05.18 14:54:48 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Eipix
[2013.02.13 15:42:01 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\EleFun Games
[2013.05.26 15:26:47 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Elephant Games
[2012.10.06 16:23:16 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Enki Games
[2013.06.02 14:32:44 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\ERS Game Studios
[2012.12.30 14:17:36 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Fenomen Games
[2013.02.10 14:43:37 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\FOP
[2013.02.06 16:57:09 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Friday's games
[2013.04.01 15:23:12 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Frogwares
[2012.09.15 12:30:26 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Fuzzy Bug Interactive
[2012.10.21 14:44:59 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Gogii
[2013.04.28 09:22:17 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Gogii Games
[2013.01.27 16:05:21 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\GrandMA Studios
[2012.01.31 13:59:41 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\IMSIDesign
[2013.03.03 15:01:32 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\JoyBits
[2010.08.24 19:51:07 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Leadertech
[2012.10.07 14:08:37 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\LegacyGames
[2012.10.03 15:32:52 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\MA2
[2012.10.01 15:06:22 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Mad Head Games
[2013.05.20 08:20:03 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\MagicIndie
[2012.09.26 17:26:34 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\MAGIX
[2013.04.14 13:19:11 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Mariaglorum
[2012.10.28 14:33:55 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\MumboJumbo
[2010.08.15 11:38:00 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\OEM
[2013.02.17 20:13:28 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Orneon
[2012.09.24 10:27:51 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\PeaceCraft3
[2011.12.30 15:26:05 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\PlayFirst
[2010.08.15 16:51:11 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\PowerCinema
[2013.02.09 19:55:29 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\ProtectDisc
[2012.11.15 10:52:40 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Samsung
[2012.09.16 10:29:39 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\simplitec
[2012.12.16 15:30:35 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Skunk Studios
[2012.09.07 15:35:12 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\SMIGames
[2013.05.05 12:36:37 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\SpeedMaxPc
[2013.06.14 17:38:38 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Steganos
[2012.09.25 19:12:43 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\TeamViewer
[2013.02.11 15:14:39 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\TOMI3
[2012.12.25 15:58:25 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Top Evidence
[2012.12.01 18:48:26 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\TuneUp Software
[2012.11.22 15:21:05 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\URSE Games
[2013.05.20 18:39:32 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Vast Studios
[2013.03.29 20:03:01 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\VendelGAMES
[2013.04.21 13:56:08 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Vogat Interactive
[2012.10.07 19:16:58 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\World-LooM
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 155 bytes -> C:\ProgramData\Temp:195E8317
@Alternate Data Stream - 155 bytes -> C:\ProgramData\Temp:02172F27
@Alternate Data Stream - 154 bytes -> C:\ProgramData\Temp:43F5FA9D
@Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:E6B95E40
@Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:3E8A3E87
@Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:0F64164E
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:AB689DEA
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:952245B1
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:84C34762
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:FFC3922F
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:F7BF538D
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:CE506F23
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:2CB9631F
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:FCBEDCFD
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:E265ED33
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:B61767F5
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:7BFFC6A9
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:5F56E7C1
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:5ECEFF17
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:1A8854EC
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:0410A323
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:B504E4C2
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:819394CC
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:6CF828C2
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:53BA2DF6
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:244E4E3A
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:A900C3A3
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:3F266659
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:0FD8569B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:869C6B4A
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:709E81D4
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:D987CB43
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:B6D84F71
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:5FC043A8
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:32AE8659
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:94A31742
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:7254CF01
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:401CAF8F
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:164561C8
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:000D6A25
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:F817E159
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:E36F5B57
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:D7D0B4AF
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:CBAF0C30
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:AC9F291E
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:32289BE8
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:EDE28CFC
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:BD34FFC5
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:8B3C3098
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:0C2A17F2
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:E6537A16
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:BF6A2C54
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:B139DDF3
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:94B25DF5
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:5D7E5A8F
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:B4530133
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:5E73E1C2
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:2AE74FF9
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:F68CB1A4
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:93DE1838
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:798A3728
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:54403233
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:512E1728
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:44712999
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:A88BE334
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:93EB7685
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:56699AAF
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:0B9176C0
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:E1F04E8D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:AABECEFB
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:A9ABA3FF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:8C12CFCD
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:254AD2ED
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:1FA4C06F
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:DF5C005A
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:B3A5945E
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:48862C37
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:0474F714
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:F3A185AE
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:DE875C30
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:2AC146B9
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:12258D63
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:F8DE80DB
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:C82CA1C0
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:8AC20936
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:4D066AD2
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:5453E5AF
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:5133A494
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:1E942FB9
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:E402E439
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:CE3AADB7
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:A9056F42
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:1B389835
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:01F9D1B4
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:E8AEB2BF
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:A13B696A
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:97AAB7F2
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:961B84C5
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:EBF0842B
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:D621CFB8
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:4A5CFD3B
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:E11D90D0
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:8B480195
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:206470A5
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:E5AF754F
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:A73595DE
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:363E775E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:2701CA70
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:C22674B6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:AECF4772
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:A4241298
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:6BEADDC0
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:24C072FF
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:11590865
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:10CB85CA
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:6A9CA6CB
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:A4E7D25F
@Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:774A0E14
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:BF6C4AAC
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:927EC486
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:6E2D80C8
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:E5BA9ADD
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:C368C9EA
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:B21F2857
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:8318A814
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:59A6876B
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:1A5822A3

< End of report >
         
Code:
ATTFilter
OTL Extras logfile created on: 14.06.2013 17:47:30 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\S. Voß HUK\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,93 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 60,03% Memory free
7,86 Gb Paging File | 6,29 Gb Available in Paging File | 80,12% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 458,87 Gb Total Space | 386,23 Gb Free Space | 84,17% Space Free | Partition Type: NTFS
Drive D: | 458,87 Gb Total Space | 456,39 Gb Free Space | 99,46% Space Free | Partition Type: NTFS
Drive K: | 931,28 Gb Total Space | 667,34 Gb Free Space | 71,66% Space Free | Partition Type: FAT32
Drive L: | 1863,01 Gb Total Space | 1793,28 Gb Free Space | 96,26% Space Free | Partition Type: NTFS
Drive M: | 931,51 Gb Total Space | 930,82 Gb Free Space | 99,93% Space Free | Partition Type: NTFS
 
Computer Name: BUERO | User Name: S. Voß HUK | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [CEWE FOTOSCHAU] -- "C:\Program Files (x86)\CEWE COLOR\Mein CEWE FOTOBUCH\CEWE FOTOSCHAU.exe" -d "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Fotoschau] -- "K:\Program Files (x86)\Pixum\Pixum Fotobuch\Fotoschau.exe" -d "%1" ()
Directory [Mein CEWE FOTOBUCH] -- "C:\Program Files (x86)\CEWE COLOR\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exe" "%1" ()
Directory [Pixum Fotobuch] -- "K:\Program Files (x86)\Pixum\Pixum Fotobuch\Pixum Fotobuch.exe" "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [CEWE FOTOSCHAU] -- "C:\Program Files (x86)\CEWE COLOR\Mein CEWE FOTOBUCH\CEWE FOTOSCHAU.exe" -d "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Fotoschau] -- "K:\Program Files (x86)\Pixum\Pixum Fotobuch\Fotoschau.exe" -d "%1" ()
Directory [Mein CEWE FOTOBUCH] -- "C:\Program Files (x86)\CEWE COLOR\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exe" "%1" ()
Directory [Pixum Fotobuch] -- "K:\Program Files (x86)\Pixum\Pixum Fotobuch\Pixum Fotobuch.exe" "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UacDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirstRunDisabled" = 0
"UacDisableNotify" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0CC16866-7415-4D57-9492-CB56E27C8E46}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{14BEDC3C-E871-4671-AB13-F296C8612040}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{18E49729-07DE-4079-B7D9-3B8305CCB431}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{1BD3BF3D-86ED-4CD2-A799-2CF69E883D3A}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{25254ABE-EFB1-4B50-9DC6-B0377D545553}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{278342F0-155A-4C74-825B-001D80391D3F}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{365CA878-DADF-4A77-8286-052F88F8CAF4}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{4521A7AC-A5AE-45B8-885E-25BA03AB4BEE}" = rport=137 | protocol=17 | dir=out | app=system | 
"{6A1E95F8-74C6-4347-BC3E-9A5F980208E8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{6CB9B534-53E2-40B7-A352-375713E94AF1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{719D62B5-ED15-42CC-A05A-33561FF01669}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{79CF02F3-F218-4E75-890C-AD653511B5D0}" = lport=445 | protocol=6 | dir=in | app=system | 
"{81BE7DD5-F835-4AC3-B6E0-1929B0C050CF}" = rport=138 | protocol=17 | dir=out | app=system | 
"{84A90717-5E5A-496D-A264-4C9ED7D48970}" = lport=137 | protocol=17 | dir=in | app=system | 
"{8A02ED68-8808-43E6-98DA-79BE99BD2DEE}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{9862430D-67AD-4C00-827D-41619952CC3E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{A3406086-B49B-4F47-B1AE-AF4E1710541F}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{B5017374-B68E-4B0C-8B52-AEF2D6B1C4A9}" = rport=139 | protocol=6 | dir=out | app=system | 
"{BAD45F3F-FEB5-45C7-85CD-CDE0220E072B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{BBE83C93-AD86-4E6E-BC58-44EA371B4638}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{C5502A75-443C-41C5-AB6B-EF871353945A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{C77E9F85-5E5C-4FA6-BCA4-A90DB11A8758}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{C8735A05-25E1-4D8E-896E-D6629C1AF9AD}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{C92A92BB-8DD8-45B6-835E-2BE65E80D305}" = rport=445 | protocol=6 | dir=out | app=system | 
"{E00C9ED6-D267-4D4D-AA6D-13186E0C2448}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{E0C6DAFD-9DF3-4A53-88C0-31C46E77811E}" = lport=139 | protocol=6 | dir=in | app=system | 
"{E4BAA152-A5CD-46E5-92D7-828A4328309B}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 | 
"{ED23BF2A-B863-44BC-8607-77619ED66D68}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{EFC6A029-1F83-4CB4-AADA-F9334CA9F41E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{F8640D0F-8EEB-4EF8-AD7F-09164E9E74B8}" = lport=138 | protocol=17 | dir=in | app=system | 
"{FE174412-58D4-4F73-AFE5-7F8E418EF9CC}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00BE4E82-947B-4F56-8497-A06E362A79C0}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | 
"{062EC9A7-EEA3-484A-92A1-4C9C0B0FDCED}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\homemedia\homemedia.exe | 
"{0F15739C-A145-4A16-900A-454A28BBA36D}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe | 
"{12C0DE5D-7A7A-4F27-A1A2-8D2171C12E6E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{1913DB34-DE75-4195-8440-D230D5D8E8BD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{220A4944-1ACA-4A67-87A9-5C6AA60D3E0A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{245CD60E-0F08-421E-B041-D1C88A1A4336}" = protocol=6 | dir=in | app=c:\users\s. voss huk\appdata\local\apps\2.0\5kmzqm8r.l9g\p314ae5j.zwe\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe | 
"{261A9459-637D-4F31-9E22-8082C610EBC7}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{2C75E379-2553-46A2-A6D3-C7C5FF21B7BC}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{31EEFF76-F298-40A4-8500-B970CCF04751}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{33470128-02E3-49A6-BFAD-61730CD8A596}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{35A21D43-D790-4BFF-863D-C8E5F86FF2EF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{35E2E4AD-5C55-4047-849F-6C0C340870C8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{438B7257-CBAB-4DFB-BED6-9823CDA39996}" = protocol=17 | dir=in | app=c:\users\s. voss huk\appdata\local\apps\2.0\5kmzqm8r.l9g\p314ae5j.zwe\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe | 
"{5134EFE3-948C-4220-84F4-052BC8BCD63D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{5283A62C-CD5E-4D42-A52E-DB65879389BB}" = protocol=17 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\app\starmoney.exe | 
"{59BBE1D4-F7DB-46ED-9936-1CBA97828D99}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{5A2D9600-30ED-459D-90A6-00BFA293B031}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe | 
"{80E9A385-EB72-43A1-A460-53D9386C7CD9}" = protocol=17 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\ouservice\starmoneyonlineupdate.exe | 
"{852FE4CA-E466-48C0-9EE7-502719107B6C}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe | 
"{88C58252-FB4C-4E53-9CBF-0A8F1EF96C30}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{9AFD0FFF-16DE-4A97-8F52-291BEA86BE28}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{A363DEE9-5558-4443-9F94-113890D88989}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | 
"{B55B064A-6EC2-41A1-AD23-9E9BC0962D3C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{B633BDE0-AF39-475B-90D5-B3D92F0FBC0C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B676F240-613A-4716-BF7C-34EB5038F29E}" = protocol=6 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\ouservice\starmoneyonlineupdate.exe | 
"{B8441ED8-5D1D-4D5D-91F8-95BDEEE2C742}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{B93E6A19-B3E4-452F-8230-AF2F5675AD32}" = protocol=6 | dir=out | app=system | 
"{BF6C8DF2-C3FE-4036-B898-3373BA41E620}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{C583E380-A49A-4589-A0ED-F684A568D418}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{C77EF856-6C61-4836-95A9-554F9BA2797B}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | 
"{CDACD4C6-1DFE-4185-840F-9F52673073F6}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{CEE3C10E-4758-4A63-961C-79DC6131C020}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{D256C440-8BEB-4C11-A8CA-2219A57099B1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{D30E36DC-0C3F-49AB-A2A1-284EE1BC2676}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | 
"{E6B5E6C7-49F7-4E29-9A73-159C89F968C6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{EDA85143-2B82-49C0-A1D3-BC0ADE71F1BF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{FA482814-9BC1-4E5C-99CD-7909B162B5BA}" = protocol=6 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\app\starmoney.exe | 
"{FD0145A2-C053-4B5E-92DA-E236C7E111DB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX870_series" = Canon MX870 series MP Drivers
"{12D93D02-3C15-DF08-581F-52E4A1EB0A3D}" = AMD Drag and Drop Transcoding
"{18A5D014-E9AD-DEFE-FAFE-A409612F51B4}" = AMD Media Foundation Decoders
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{1FBEA8BA-D40B-48BC-85BC-EE2D5575F27C}" = Microsoft SQL Server VSS Writer
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{50BD00DC-127E-BF00-FDD5-E1A93AB3507C}" = ccc-utility64
"{567571C7-7156-48D9-A8D0-C88B8E85F0F4}" = TMS 5.1 SP1 Client
"{57F4B170-E76D-47F9-B6BA-F3D4FB7445B6}" = MAGIX Fotos auf DVD 2013 Deluxe
"{5A2C499A-B689-4CF4-8441-DD659164B939}" = MAGIX Speed burnR (MSI)
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile-Gerätecenter
"{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}" = Bing Maps 3D
"{7C39E0D1-E138-42B1-B083-213EC2CF7692}" = Microsoft SQL Server Native Client
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A1233BA3-F715-4604-A04A-248268369B04}" = Fotos auf DVD 2013 Deluxe Update
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BB009B20-0BA0-ABDF-1947-4D56639214C7}" = AMD Accelerated Video Transcoding
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DDA8FE2D-EA67-194C-D6A5-F52BC4FDA20F}" = ATI AVIVO64 Codecs
"{E85D1C80-28C4-76B8-5A5A-2C8D8B38D5D9}" = AMD Catalyst Install Manager
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"SP6" = Logitech SetPoint 6.15
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00B52299-F42A-40C3-8232-F987B86E3FD6}_is1" = Die Legende von Pocahontas
"{028ED9C4-25EE-4DEE-9CF4-91034BC89B18}" = Microsoft SQL Server 2005 Express Edition (SQLHUK)
"{02CF7793-9F94-45E9-BB0F-E0E5FAB463E6}_is1" = Romance of Rome
"{03AEAB60-A7B3-A8DB-468B-EB30FB4B40B0}" = CCC Help German
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{162ABED6-E60C-6CFF-100E-43C16ABBC5BE}" = CCC Help Chinese Standard
"{178E1C48-ECB1-4A3D-9EB9-B6B55AEDC2F5}" = VISonline Diagnose
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1CB724FF-D18C-8FFB-E7C9-0A09CF8EC066}" = CCC Help Japanese
"{1FCBD504-AB7D-4757-9A14-850348384B08}" = StarMoney
"{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{20C14CC3-5E3B-D39A-5B37-B15E59785063}" = CCC Help Chinese Traditional
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
"{2632A2C0-ECF4-7F79-7136-9FEA4C253A4C}" = CCC Help Turkish
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{29258311-EA49-11DE-967C-005056C00008}" = Paragon Festplatten Manager™ 2011 Kompakt
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie
"{30F712DA-64FE-5DBE-AE76-3F8EA3F8223C}" = CCC Help French
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C39B3CC-4EC8-C756-AF4B-72366504FCA5}" = CCC Help Hungarian
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{44AED858-95E2-43DE-BFF2-7DB35A27AB53}" = The Curse Of Ra
"{4968622A-4D3F-489E-9ACE-5FEC4CC0BDE3}" = MediaShow Espresso
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CC9D761-A9B6-D8EA-D2A9-B74B5A90B108}" = CCC Help Norwegian
"{4D43D635-6FDA-4FA5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{54B227A6-BDBE-69FA-D450-B99609063044}" = CCC Help Greek
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5A6DB7C1-E646-4842-A562-49C5EB8F2B47}" = StarMoney
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{62F7DA7E-CCCB-439C-A760-00C3926E761F}" = Microsoft Works
"{66815B84-05B8-4FA3-AACA-3E7C434F78B8}_is1" = Password Depot 5
"{67565ee8-222f-4073-933e-a2b9ab033e49}" = Nero 9 Essentials
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6C5F8503-55D2-4398-858C-362B7A7AF51C}" = Firebird SQL Server - MAGIX Edition
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72FD9E53-73D1-4FC3-98DB-7889FD119946}_is1" = freundin - Mystery Tales 2
"{73063172-E55E-405D-8E46-B9B666604FDC}" = LWP_eToken_Client
"{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{7b7e564b-0c70-4506-9ab6-b7a2044425ab}" = Gigaset QuickSync
"{7C587778-C433-980E-F3C1-203890DC4FBE}" = CCC Help Polish
"{7DC3EABF-66A2-6D79-B485-6328525CA387}" = CCC Help Swedish
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}" = Chicken Invaders 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}" = Spin & Win
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697}" = Granny In Paradise
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}" = Dream Day First Home
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}" = Dairy Dash
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}" = Farm Frenzy 2
"{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
"{843603C6-75B7-BAB5-80DE-E76FB28DEEF2}" = CCC Help Finnish
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8D9EEAC7-42D5-3951-612A-EAA7B684C592}" = CCC Help Italian
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0407-1000-0000000FF1CE}_Office14.SingleImage_{594128C9-2CDF-43CE-8103-DC100CF013B6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{95381165-5D16-4CD4-9162-57799A3F3AB5}" = PCLinq2 High-Speed USB Bridge Cable
"{9791DAED-B734-2835-988B-157BDA087496}" = CCC Help Dutch
"{98B740C3-FAA4-C523-7478-4DBCAB7B27D1}" = Catalyst Control Center Graphics Previews Common
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A38A0A7-177F-4D21-9E86-ACDF732B1150}" = HUK-COBURG Angebotssoftware VISonline
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F0CAC6D-9B0D-A95F-CF61-6E88952D6181}" = CCC Help Thai
"{9F5FD796-86F0-4360-85F8-D54C0F5411EB}" = Steuer-Spar-Erklärung 2011
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A58E2F1D-5766-43AE-803E-37B7F99931FB}" = VIS Aktualisierung
"{A625DB70-98D5-16FD-C49D-4B8B1B2304A4}" = CCC Help Spanish
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A90214C3-3A0C-2F05-6083-E1A4BAD9E30D}" = CCC Help Danish
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA123216-6DE0-E57C-DC57-4FECEACB482F}" = CCC Help Russian
"{ABEE079E-648E-488B-8301-0C3DB48C1BCE}_is1" = Acer GameZone Console
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.02) - Deutsch
"{AE395AC2-28CB-463F-87DC-00C8059781BF}" = 7Artifacs
"{AEB61F7A-4BBA-4292-A096-7893E09034A4}" = Steuer-Spar-Erklärung 2013
"{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}" = AAVUpdateManager
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B63DFA23-5C10-44B4-881D-45EFBF4A4761}" = MAGIX Screenshare
"{B906C11A-D193-4143-9FA7-E2EE8A5A8F21}" = Acer Arcade Movie
"{BAF19BB1-7716-4F37-5C47-E9DD9A70BC0F}" = Catalyst Control Center InstallProxy
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BE5D79E8-0B8E-4E97-97E1-3CDEBAB2DEB1}" = Sven XXX - XXL
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help
"{CCD2BAD2-0919-40CB-80CC-E9538B0E4C2E}" = Steuer-Spar-Erklärung 2012
"{D0837A59-83E6-3392-1BD9-86D3445676DB}" = CCC Help Korean
"{D70AB273-113B-D7DE-5C8D-82CABA7CB0AF}" = Catalyst Control Center Localization All
"{DC8772D4-C75F-5235-63E2-BBC73F909B7A}" = CCC Help Czech
"{DCF0739A-23F1-4E7A-A538-AC4580B28F55}" = Shrek(R) SuperSlam
"{DED7FD3C-DDD2-43BB-B0F5-B07F9D0430D3}" = CCC Help Portuguese
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}" = eBay Worldwide
"{E157F2EB-E06F-B57F-9105-68F348DB2EAD}" = CCC Help English
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E2F2B987-F2BC-4969-95F2-92099486B811}" = StarMoney
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{EC36B80D-3A0B-44D2-A066-9F346FE05D54}" = TurboFLOORPLAN Garten- & Landschaftsarchitekt
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EF036F44-A287-BC23-3F6E-AAE6FDEF47EF}" = Catalyst Control Center InstallProxy
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{F902AB2B-7816-4CBD-A385-F2549F62956B}" = StarMoney
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"{FBF2527B-5904-49EE-A420-F2827AE55681}" = StarMoney 8.0 S-Edition
"{FC338210-F594-11D3-BA24-00001C3AB4DF}" = cyberJack Base Components
"3D Wohnungsplaner 10_is1" = DATA BECKER 3D Wohnungsplaner 10
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.17
"Ashampoo Burning Studio 2013_is1" = Ashampoo Burning Studio 2013 v.11.0.5
"BFG-Awakening - Das Himmelsschloss Sammleredition" = Awakening: Das Himmelsschloss Sammleredition
"BFGC" = Big Fish Games: Game Manager
"BFG-Chimeras - Melodie der Rache Sammleredition" = Chimeras: Melodie der Rache Sammleredition
"BFG-Detective Quest - Der glaeserne Schuh Sammleredition" = Detective Quest: Der gläserne Schuh Sammleredition
"BFG-Farmington Tales" = Farmington Tales
"BFG-Phantasmat - Eisiger Gipfel" = Phantasmat: Eisiger Gipfel
"BFG-Sable Maze - Sullivan River" = Sable Maze: Sullivan River
"BFG-Sacra Terra - Der Kuss des Todes" = Sacra Terra: Der Kuss des Todes
"BFG-Sacra Terra - Der Kuss des Todes Sammleredition" = Sacra Terra: Der Kuss des Todes, Sammleredition
"BFG-Spirits of Mystery - Der dunkle Minotaurus Sammleredition" = Spirits of Mystery: Der dunkle Minotaurus Sammleredition
"BFG-The Beast of Lycan Isle" = The Beast of Lycan Isle
"BFG-The Saint - Abgrund der Verzweiflung" = The Saint: Abgrund der Verzweiflung
"BFG-Time Mysteries - Das letzte Raetsel" = Time Mysteries: Das letzte Rätsel
"BFG-Time Mysteries - Das letzte Raetsel Sammleredition" = Time Mysteries: Das letzte Rätsel Sammleredition
"BFG-Toedliche Sonate - Ein Dana Knightstone-Roman" = Tödliche Sonate: Ein Dana Knightstone-Roman
"BFG-Unfinished Tales - Unsterbliche Liebe" = Unfinished Tales: Unsterbliche Liebe
"BFG-Unfinished Tales - Unsterbliche Liebe Sammleredition" = Unfinished Tales: Unsterbliche Liebe Sammleredition
"BFG-Verbotene Geheimnisse - Alien Town" = Verbotene Geheimnisse: Alien Town
"BFG-Web of Deceit - Die Schwarze Witwe Sammleredition" = Web of Deceit: Die Schwarze Witwe Sammleredition
"Briefe aus dem Jenseits" = Briefe aus dem Jenseits
"Canon MX870 series Benutzerregistrierung" = Canon MX870 series Benutzerregistrierung
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Casual Games" = Casual Games 1 
"Coffee Break PacMan" = Coffee Break PacMan
"Color Eggs II" = Color Eggs II
"Das Vermächtnis der Insel" = Das Vermächtnis der Insel
"Deep Blue Sea – Die Schatztaucherin_is1" = Deep Blue Sea – Die Schatztaucherin
"DEUTSCHLAND SPIELT Spiele Post" = DEUTSCHLAND SPIELT Spiele Post
"Diamond Drop (VOLLVERSION)" = Diamond Drop (VOLLVERSION)
"Dino & Aliens" = Dino & Aliens
"DSGPlayer" = DEUTSCHLAND SPIELT GAME CENTER
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Geheime Fälle: Die gestohlene Venus 2" = Geheime Fälle: Die gestohlene Venus 2
"HaaliMkx" = Haali Media Splitter
"Hotkey Utility" = Hotkey Utility
"Hühner-Attacke (VOLLVERSION)" = Hühner-Attacke (VOLLVERSION)
"Hühner-Rache" = Hühner-Rache
"I Have No Tomatoes" = I Have No Tomatoes v1.5
"Identity Card" = Identity Card
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{DCF0739A-23F1-4E7A-A538-AC4580B28F55}" = Shrek(R) SuperSlam
"InstallShield_{EC36B80D-3A0B-44D2-A066-9F346FE05D54}" = TurboFLOORPLAN Garten- & Landschaftsarchitekt
"Jäger des Geisterhauses_is1" = Jäger des Geisterhauses
"Kalender-Excel-8.7.1_is1" = Kalender-Excel-8.7.1
"Kalender-Excel-8.9_is1" = Kalender-Excel-8.9
"Love Over Death" = Love Over Death
"Mad Cars" = Mad Cars
"Magic Ball 2" = Magic Ball 2
"MAGIX_{57F4B170-E76D-47F9-B6BA-F3D4FB7445B6}" = MAGIX Fotos auf DVD 2013 Deluxe
"MAGIX_{5A2C499A-B689-4CF4-8441-DD659164B939}" = MAGIX Speed burnR (MSI)
"Mein CEWE FOTOBUCH" = Mein CEWE FOTOBUCH
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"MP Navigator EX 3.1" = Canon MP Navigator EX 3.1
"MyMDb_0" = MyMDb 3.6
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Pixum Fotobuch" = Pixum Fotobuch
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"Rasputins Curse" = Rasputins Curse
"Robinson Crusoe and the Cursed Pirates" = Robinson Crusoe and the Cursed Pirates
"Santa Hanta_is1" = Santa Hanta 2.4c
"Secret Diaries: Florence Ashford" = Secret Diaries: Florence Ashford
"secrets of tahiti" = secrets of tahiti
"Shadow Wolf Mysteries Bane of the Family_is1" = Shadow Wolf Mysteries Bane of the Family de
"Speed Dial Utility" = Canon Kurzwahlprogramm
"Super Puzzle" = Super Puzzle
"The Mystery of the Crystal Portal - Die versunkene Welt" = The Mystery of the Crystal Portal - Die versunkene Welt
"tksuite_tksuite_server" = AGFEO TK-Suite Server
"Tory's Shop'n' Rush" = Tory's Shop'n' Rush
"Verschleierte Wirklichkeit" = Verschleierte Wirklichkeit
"WinLiveSuite_Wave3" = Windows Live Essentials
"Wondershare Vivideo_is1" = Wondershare Vivideo(Build 2.0.0.12)
"Zoo Safari_is1" = Zoo Safari
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Protect Disc License Helper" = Protect Disc License Helper 1.0.125 (IE)
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Protect Disc License Helper" = Protect Disc License Helper 1.0.125 (IE)
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-210379488-4132890845-1450444768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f018cf21c0452c64" = AVM FRITZ!Box USB-Fernanschluss
"MyFreeCodec" = MyFreeCodec
"Protect Disc License Helper" = Protect Disc License Helper 1.0.125 (IE)
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 25.05.2013 12:08:57 | Computer Name = Buero | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16576,
 Zeitstempel: 0x515e30fe  Name des fehlerhaften Moduls: pdIEAddOn.dll, Version: 5.3.0.0,
 Zeitstempel: 0x4d8b468d  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00004f5a  ID des fehlerhaften
 Prozesses: 0x120c  Startzeit der fehlerhaften Anwendung: 0x01ce59612a71aedb  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE  Pfad
 des fehlerhaften Moduls: C:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll
Berichtskennung:
 66de7529-c555-11e2-b5ad-90fba6e09548
 
Error - 26.05.2013 09:25:54 | Computer Name = Buero | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16576,
 Zeitstempel: 0x515e30fe  Name des fehlerhaften Moduls: pdIEAddOn.dll, Version: 5.3.0.0,
 Zeitstempel: 0x4d8b468d  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00004f5a  ID des fehlerhaften
 Prozesses: 0xea4  Startzeit der fehlerhaften Anwendung: 0x01ce5a0aacad2058  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE  Pfad
 des fehlerhaften Moduls: C:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll
Berichtskennung:
 ca1f4e87-c607-11e2-b5ad-90fba6e09548
 
Error - 26.05.2013 13:00:47 | Computer Name = Buero | Source = Windows Backup | ID = 4104
Description = 
 
Error - 30.05.2013 12:16:47 | Computer Name = Buero | Source = Application Hang | ID = 1002
Description = Programm IEXPLORE.EXE, Version 10.0.9200.16576 kann nicht mehr unter
 Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf 
in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
 zu suchen.    Prozess-ID: 23b4    Startzeit: 01ce5d4e1f317c1c    Endzeit: 15    Anwendungspfad:
 C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE    Berichts-ID:   
 
Error - 02.06.2013 08:53:11 | Computer Name = Buero | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: HauntedLegends_TheUndertakerCE_RC.exe,
 Version: 0.0.0.0, Zeitstempel: 0x51234949  Name des fehlerhaften Moduls: unknown,
 Version: 0.0.0.0, Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 
0x1c20674a  ID des fehlerhaften Prozesses: 0x3d94  Startzeit der fehlerhaften Anwendung:
 0x01ce5f8d47bea427  Pfad der fehlerhaften Anwendung: K:\Program Files (x86)\Haunted
 Legends - Der Bestatter\HauntedLegends_TheUndertakerCE_RC.exe  Pfad des fehlerhaften
 Moduls: unknown  Berichtskennung: 61244ad3-cb83-11e2-b5ad-90fba6e09548
 
Error - 02.06.2013 13:00:52 | Computer Name = Buero | Source = Windows Backup | ID = 4104
Description = 
 
Error - 05.06.2013 17:40:10 | Computer Name = Buero | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16576,
 Zeitstempel: 0x515e30fe  Name des fehlerhaften Moduls: pdIEAddOn.dll, Version: 5.3.0.0,
 Zeitstempel: 0x4d8b468d  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00004f5a  ID des fehlerhaften
 Prozesses: 0x1118  Startzeit der fehlerhaften Anwendung: 0x01ce62334908731f  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE  Pfad
 des fehlerhaften Moduls: C:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll
Berichtskennung:
 7ec8b21a-ce28-11e2-b5ad-90fba6e09548
 
Error - 06.06.2013 07:11:28 | Computer Name = Buero | Source = Application Hang | ID = 1002
Description = Programm StarMoney.exe, Version 3.0.6.31 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 47a8    Startzeit:
 01ce62a625b60d5e    Endzeit: 0    Anwendungspfad: C:\Program Files (x86)\StarMoney 8.0 
S-Edition\app\StarMoney.exe    Berichts-ID:   
 
Error - 06.06.2013 08:17:06 | Computer Name = Buero | Source = Software Protection Platform Service | ID = 8200
Description = Lizenzerwerb-Fehlerdetails.   hr=0xC004C32A
 
Error - 06.06.2013 08:17:06 | Computer Name = Buero | Source = Software Protection Platform Service | ID = 8208
Description = Fehler bei der Erfassung des authentischen Tickets (hr=0xC004C32A)
 für die Vorlagen-ID 66c92734-d682-4d71-983e-d6ec3f16059f.
 
Error - 09.06.2013 13:00:50 | Computer Name = Buero | Source = Windows Backup | ID = 4104
Description = 
 
[ Cisco AnyConnect Secure Mobility Client Events ]
Error - 14.06.2013 11:11:58 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: Directory::ReadDir File: .\Utility\Directory.cpp Line: 156
Invoked
 Function: ::FindNextFile Return Code: 18 (0x00000012) Description: Es sind keine 
weiteren Dateien vorhanden.   
 
Error - 14.06.2013 11:11:58 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: PluginLoader::QuickCreatePlugin File: c:\temp\build\thehoff\DaVinci_MR20.640871216917\DaVinci_MR2\vpn\Common\Utility/PluginLoader.h
Line:
 145 Invoked Function: PluginLoader::CreateInstance Return Code: -29294580 (0xFE41000C)
Description:
 PLUGINLOADER_ERROR_COULD_NOT_CREATE 
 
Error - 14.06.2013 11:11:58 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: PluginLoader::QuickCreatePlugin File: c:\temp\build\thehoff\DaVinci_MR20.640871216917\DaVinci_MR2\vpn\Common\Utility/PluginLoader.h
Line:
 145 Invoked Function: PluginLoader::CreateInstance Return Code: -29294580 (0xFE41000C)
Description:
 PLUGINLOADER_ERROR_COULD_NOT_CREATE 
 
Error - 14.06.2013 11:11:58 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: PluginLoader::QuickCreatePlugin File: c:\temp\build\thehoff\DaVinci_MR20.640871216917\DaVinci_MR2\vpn\Common\Utility/PluginLoader.h
Line:
 145 Invoked Function: PluginLoader::CreateInstance Return Code: -29294580 (0xFE41000C)
Description:
 PLUGINLOADER_ERROR_COULD_NOT_CREATE 
 
Error - 14.06.2013 11:12:00 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: ProfileMgr::loadProfile File: .\ProfileMgr.cpp Line: 518 Invoked
 Function: ProfileMgr::loadProfile Return Code: -33554423 (0xFE000009) Description:
 GLOBAL_ERROR_UNEXPECTED Duplicate host <vpngw3.huk-coburg.de> found in the profile
 <C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Profile\prfVTP.xml>.
 Host discarded.
 
Error - 14.06.2013 11:12:00 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: CIPv4ChangeRouteHelper::FindBestRoute File: .\IPv4ChangeRouteHelper.cpp
Line:
 2624 Invoked Function: CIPv4RouteTable::FindMatchingRoute Return Code: -33095647 
(0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 14.06.2013 11:12:00 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: CRouteMgr::UpdatePublicAddress File: .\RouteMgr.cpp Line: 
2182 Invoked Function: CChangeRouteTable::FindBestRouteInterface Return Code: -33095647
 (0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 14.06.2013 11:12:00 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::applyHostConfigForNoVpn File: .\MainThread.cpp
Line:
 8405 Invoked Function: CHostConfigMgr::DeterminePublicInterface Return Code: -33095647
 (0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 14.06.2013 11:12:00 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::MainLoop File: .\MainThread.cpp Line: 379 Invoked
 Function: CMainThread::applyHostConfigForNoVpn Return Code: -33095647 (0xFE070021)
Description:
 ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 14.06.2013 11:36:45 | Computer Name = Buero | Source = acvpnagent | ID = 67110873
Description = Termination reason code 7: The agent has been stopped.
 
[ System Events ]
Error - 14.06.2013 11:12:37 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:12:48 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:12:48 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:42:01 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:42:37 | Computer Name = Buero | Source = Ntfs | ID = 262281
Description = Auf dem Volume "L:" konnte der Transaktionsressourcen-Manager aufgrund
 eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in
 den Daten enthalten.
 
Error - 14.06.2013 11:42:47 | Computer Name = Buero | Source = Microsoft-Windows-BitLocker-Driver | ID = 24620
Description = Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf
 "\\?\Volume{9ae5ce6b-7702-11dc-9bbd-806e6f6e6963}" können nicht gelesen werden.
 
Error - 14.06.2013 11:42:47 | Computer Name = Buero | Source = Microsoft-Windows-BitLocker-Driver | ID = 24620
Description = Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf
 "\\?\Volume{9ae5ce6c-7702-11dc-9bbd-806e6f6e6963}" können nicht gelesen werden.
 
Error - 14.06.2013 11:43:27 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:43:38 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:43:38 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
 
< End of report >
         
Code:
ATTFilter
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-06-15 12:18:47
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD10 rev.80.0 931,51GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\SDBC1~1.VOH\AppData\Local\Temp\fgldqpob.sys


---- User code sections - GMER 2.1 ----

.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[1992] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69                 0000000076ee1465 2 bytes [EE, 76]
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[1992] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155                0000000076ee14bb 2 bytes [EE, 76]
.text   ...                                                                                                                                                * 2
.text   C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe[1280] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   0000000076ee1465 2 bytes [EE, 76]
.text   C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe[1280] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  0000000076ee14bb 2 bytes [EE, 76]
.text   ...                                                                                                                                                * 2
.text   C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3244] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint                         0000000077de000c 1 byte [C3]
.text   C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3244] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin                    0000000077e6f85a 5 bytes JMP 0000000177e1d571
.text   C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe[3356] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                         0000000076ee1465 2 bytes [EE, 76]
.text   C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe[3356] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                        0000000076ee14bb 2 bytes [EE, 76]
.text   ...                                                                                                                                                * 2

---- User IAT/EAT - GMER 2.1 ----

IAT     C:\Windows\Explorer.EXE[2720] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!FreeLibraryAndExitThread]                                             [10002350] C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll
IAT     C:\Windows\Explorer.EXE[2720] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!CreateThread]                                                         [10003450] C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll
IAT     C:\Windows\Explorer.EXE[2720] @ C:\Windows\system32\SHELL32.dll[KERNEL32.dll!LoadLibraryA]                                                         [100011e0] C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll

---- Threads - GMER 2.1 ----

Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1828]                                                            0000000077e23e45
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1844]                                                            0000000077e22e25
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1928]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1932]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1936]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1940]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1944]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1948]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1952]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1964]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1968]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1972]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1196]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1244]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1276]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2092]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2096]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2100]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2104]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2108]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2112]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2116]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2120]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2124]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2128]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2132]                                                            0000000077e23e45
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2136]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2140]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2144]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2148]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2152]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2332]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2436]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2980]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2984]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2988]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:3984]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:3988]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:3992]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:3996]                                                            0000000073be29e1
Thread  C:\Windows\System32\svchost.exe [4252:792]                                                                                                         000007fef1f89688

---- EOF - GMER 2.1 ----
         

 

Themen zu Netzwerkprobleme - Schädling eingefangen?
adobe, adobe reader xi, becker, bho, curse, ebay, error, excel, failed, festplatte, firefox, flash player, format, home, iexplore.exe, install.exe, internet, logfile, ntdll.dll, pirates, plug-in, pmmupdate.exe, realtek, registry, rundll, schädling, secrets, security, senden, software, starmoney, svchost.exe, temp, usb, windows




Ähnliche Themen: Netzwerkprobleme - Schädling eingefangen?


  1. Schädling aus Email eingefangen
    Plagegeister aller Art und deren Bekämpfung - 13.10.2015 (9)
  2. Netzwerkprobleme
    Alles rund um Windows - 18.08.2015 (7)
  3. Netzwerkprobleme/auslastung
    Plagegeister aller Art und deren Bekämpfung - 10.06.2015 (15)
  4. TR/Mediyes.J.1 und Netzwerkprobleme
    Log-Analyse und Auswertung - 26.08.2014 (7)
  5. GVU Virus befällt PC, Browser öffnet, dennoch Blackscreen beim Booten und Netzwerkprobleme
    Plagegeister aller Art und deren Bekämpfung - 26.09.2013 (21)
  6. GVU Virus befällt PC, Browser öffnet, dennoch Blackscreen beim Booten und Netzwerkprobleme
    Mülltonne - 21.09.2013 (2)
  7. Netzwerkprobleme wg. IP-Adresse durch Gema-Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 19.10.2012 (28)
  8. Dateivolumenüberprüfung, Netzwerkprobleme + Schneckentempo hoch 10! - Virus eingefangen?
    Plagegeister aller Art und deren Bekämpfung - 01.03.2012 (1)
  9. Netzwerkprobleme nach Entfernen Zbot
    Log-Analyse und Auswertung - 17.07.2010 (3)
  10. hartnäckiger Schädling
    Plagegeister aller Art und deren Bekämpfung - 22.06.2009 (1)
  11. Spam-Schädling
    Plagegeister aller Art und deren Bekämpfung - 13.01.2009 (1)
  12. evt. Schädling
    Mülltonne - 28.10.2007 (1)
  13. Schädling eingefangen?
    Log-Analyse und Auswertung - 24.09.2007 (3)
  14. Schädling eingefangen? Bitte um Hilfe...
    Log-Analyse und Auswertung - 01.08.2007 (2)
  15. Schädling eingefangen !!Hilfe !!!
    Plagegeister aller Art und deren Bekämpfung - 24.04.2006 (6)
  16. Schädling oder nicht Schädling ?!?
    Plagegeister aller Art und deren Bekämpfung - 07.05.2004 (0)
  17. Netzwerkprobleme mit Win ME und XP
    Netzwerk und Hardware - 22.02.2004 (11)

Zum Thema Netzwerkprobleme - Schädling eingefangen? - Moin, mein Arbeitskollege hat Probleme mit seinem Rechner. Und zwar kann Starmoney keinen Konatkt zum Starmoney-Service aufnehmen. Dann scheitert z.B. die Lizenz-Überprüfung. "Normales" Banking, z.B. Kontenabruf und Überweisungen funktionieren, Internet - Netzwerkprobleme - Schädling eingefangen?...
Archiv
Du betrachtest: Netzwerkprobleme - Schädling eingefangen? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.