|
Log-Analyse und Auswertung: Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
17.02.2014, 18:23 | #31 |
| Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Hallo Schrauber Nein ich denke nicht... habe gleich in Software und Programme geschaut... da steht nichts... ich hatte mal Kaspersky CB Edition drauf... hmm... Emsisoft gleich kaufen wollte ich es nicht.. testen wäre schon besser.. hast du eine Idee ?? Gruß Vater und Sohn |
18.02.2014, 12:39 | #32 |
/// the machine /// TB-Ausbilder | Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Mach mir mal bitte einen Screenshot von der Meldung und hänge ihn hier an, ich regel das dann mit Emsisoft.
__________________
__________________ |
18.02.2014, 18:17 | #33 |
| Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Hallo Schrauber...
__________________Hier das Foto... Ich habe aber auch bei deinstallieren eine Nachricht an Emsisoft geschrieben... Die machen bei Deinstallieren eine Umfrage warum man es nicht nutzt und man kann bei -Fehlern eine Email Adresse angeben und die wollen dann antworten... Evtl geht das ja schneller bei dir... Gruß und Vater Sohn |
19.02.2014, 15:40 | #34 |
/// the machine /// TB-Ausbilder | Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Hi, ist in Klärung. Schick mir heute Abend bitte ne PM.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.02.2014, 16:23 | #35 |
/// the machine /// TB-Ausbilder | Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! is schon geklärt, du hast PM
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.02.2014, 11:00 | #36 |
| Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Hallo Schrauber... So Emsisoft ist jetzt drauf.. noch mal GROßES hier das erste Log von Emsisoft Code:
ATTFilter Emsisoft Anti-Malware - Version 8.1 Letztes Update: 21.02.2014 09:57:05 Benutzerkonto: Admin-PC\Admin Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\, F:\, G:\, H:\, Q:\ PUPs-Erkennung: An Archiv Scan: An ADS Scan: An Dateitypen-Filter: Aus Erweitertes Caching: An Direkter Festplattenzugriff: Aus Scan Beginn: 21.02.2014 09:58:26 Value: HKEY_USERS\S-1-5-21-2715126414-4153456669-2541334608-1010\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS -> LRCSPAL@XINGHAO.NET gefunden: Trace.Registry.Application.FireExt (A) Key: HKEY_USERS\S-1-5-21-2715126414-4153456669-2541334608-1010\SOFTWARE\SEARCHCORE FOR BROWSERS gefunden: Trace.Registry.Application.InstallAd (A) Key: HKEY_USERS\S-1-5-21-2715126414-4153456669-2541334608-1010\SOFTWARE\STARTSEARCH gefunden: Trace.Registry.Application.InstallAd (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{084D78A8-B084-4E14-A629-A2C419B0E3D9} gefunden: Trace.Registry.Application.AdSome (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{18D0F672-18B4-48E6-AD36-6E6BF01DBBC4} gefunden: Trace.Registry.Application.AdSome (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3D05F64F-71E3-48A5-BF6B-83315BC8AE1F} gefunden: Trace.Registry.Application.AdSome (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4DE778FE-F195-4EE3-9DAB-FE446C239221} gefunden: Trace.Registry.Application.AdSome (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{76F7B787-A67C-4C73-82C7-31F5E3AABC5C} gefunden: Trace.Registry.Application.AdSome (A) Key: HKEY_USERS\S-1-5-21-2715126414-4153456669-2541334608-1010\SOFTWARE\CONDUIT gefunden: Trace.Registry.Application.InstallAd (A) Gescannt 1093506 Gefunden 9 Scan Ende: 21.02.2014 14:21:11 Scan Zeit: 4:22:45 Code:
ATTFilter INFO ZUR PLATTFORMVERSION Windows : 6.1.7601.65536 (Win32NT) Common Language Runtime : 4.0.30319.18444 System.Deployment.dll : 4.0.30319.18408 built by: FX451RTMGREL clr.dll : 4.0.30319.18444 built by: FX451RTMGDR dfdll.dll : 4.0.30319.18408 built by: FX451RTMGREL dfshim.dll : 4.0.31106.0 (Main.031106-0000) QUELLEN Bereitstellungs-URL : file:///C:/Users/Admin/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/FRITZ!Box/FRITZ!Box%20USB-Fernanschluss.appref-ms%7C FEHLERZUSAMMENFASSUNG Es folgt eine Zusammenfassung der Fehler. Details zu diesen Fehlern werden später im Protokoll aufgelistet. * Die Aktivierung von C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRITZ!Box\FRITZ!Box USB-Fernanschluss.appref-ms| führte zu einer Ausnahme. Folgende Fehlermeldungen wurden entdeckt: + 'hxxp://clickonce.avm.de/usb-fernanschluss2/deutsch/fritzbox-usb-fernanschluss.application' konnte nicht heruntergeladen werden. + Der Remotename konnte nicht aufgelöst werden: 'clickonce.avm.de' FEHLERZUSAMMENFASSUNG FÜR DIE SPEICHERTRANSAKTION DER KOMPONENTE Es wurde kein Transaktionsfehler festgestellt. WARNUNGEN Während dieses Vorgangs gab es keine Warnungen. FORTSCHRITTSSTATUS DES VORGANGS * [23.02.2014 09:50:58] : Die Aktivierung von C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRITZ!Box\FRITZ!Box USB-Fernanschluss.appref-ms| wurde gestartet. FEHLERDETAILS Folgende Fehler wurden bei diesem Vorgang entdeckt. * [23.02.2014 09:51:44] System.Deployment.Application.DeploymentDownloadException (unbekannter Untertyp) - 'hxxp://clickonce.avm.de/usb-fernanschluss2/deutsch/fritzbox-usb-fernanschluss.application' konnte nicht heruntergeladen werden. - Quelle: System.Deployment - Stapelüberwachung: bei System.Deployment.Application.SystemNetDownloader.DownloadSingleFile(DownloadQueueItem next) bei System.Deployment.Application.SystemNetDownloader.DownloadAllFiles() bei System.Deployment.Application.FileDownloader.Download(SubscriptionState subState) bei System.Deployment.Application.DownloadManager.DownloadManifestAsRawFile(Uri& sourceUri, String targetPath, IDownloadNotification notification, DownloadOptions options, ServerInformation& serverInformation) bei System.Deployment.Application.DownloadManager.DownloadManifest(Uri& sourceUri, String targetPath, IDownloadNotification notification, DownloadOptions options, ManifestType manifestType, ServerInformation& serverInformation) bei System.Deployment.Application.DownloadManager.DownloadDeploymentManifestDirect(SubscriptionStore subStore, Uri& sourceUri, TempFile& tempFile, IDownloadNotification notification, DownloadOptions options, ServerInformation& serverInformation) bei System.Deployment.Application.DownloadManager.DownloadDeploymentManifest(SubscriptionStore subStore, Uri& sourceUri, TempFile& tempFile, IDownloadNotification notification, DownloadOptions options) bei System.Deployment.Application.ApplicationActivator.ProcessOrFollowShortcut(String shortcutFile, String& errorPageUrl, TempFile& deployFile) bei System.Deployment.Application.ApplicationActivator.PerformDeploymentActivation(Uri activationUri, Boolean isShortcut, String textualSubId, String deploymentProviderUrlFromExtension, BrowserSettings browserSettings, String& errorPageUrl) bei System.Deployment.Application.ApplicationActivator.ActivateDeploymentWorker(Object state) --- Interne Ausnahme --- System.Net.WebException - Der Remotename konnte nicht aufgelöst werden: 'clickonce.avm.de' - Quelle: System - Stapelüberwachung: bei System.Net.HttpWebRequest.GetResponse() bei System.Deployment.Application.SystemNetDownloader.DownloadSingleFile(DownloadQueueItem next) DETAILS ZUR SPEICHERTRANSAKTION DER KOMPONENTE Es sind keine Transaktionsinformationen verfügbar. und und der Drucker druckt nicht mehr... :-( Gruß Vater Sohn |
24.02.2014, 15:01 | #37 |
/// the machine /// TB-Ausbilder | Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Seit wann? Und was genau hast Du für Probleme mit Fritz? Funde durch Emsisoft einfach löschen lassen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.02.2014, 20:12 | #38 |
| Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Hallo Schrauber... Emsisoft Funde wurden gelöscht... Drucker geht seit 5 Tagen nicht mehr... hatte ihn aber auch nicht immer angeschlossen nur dann wenn ich was Drucken muss.. sonst steht der hier im weg ..(Treiber deinstalliert und dann wieder installiert... kein Änderung) Fritzbox: Erst geht das mit dem Surfen und dann auf mal werden keine Seiten aufgebaut.. DSL leuchte ist an.. aber kein Email oder surfen möglich nach Neustart alles okay... Manchmal bei PC Start schon das Problem... Die Fehlermeldung und kamen zum ersten mal... die Meldung war auch wieder da.. Gruß Vater Sohn |
25.02.2014, 17:32 | #39 |
/// the machine /// TB-Ausbilder | Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Moment, warum benutzt du die Software überhaupt?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
25.02.2014, 17:49 | #40 |
| Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Hallo Schrauber... ich denke weil es dabei war ? evtl habe ich da auch was eingestellt als ich versucht habe den Drucker an die Fritzbox anzuschließen. weil am PC lief der Drucker ja nicht und ich musste dringen was drucken... Nicht Gut?? Gruß Vater Sohn |
26.02.2014, 14:23 | #41 |
/// the machine /// TB-Ausbilder | Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Normalerweise braucht man die nicht. Mit der Fritzbox verbinden, Verbindungsdaten in die Fritzbox eintippen und los gehts. Deinstallier den Kram bitte mal.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.02.2014, 19:33 | #42 |
| Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Hallo Schrauber.... habe den Kram dann mal runter geworfen.. Drucker geht auch wieder :-) Gesten hatte ich wieder das Problem das ich Firefox, Thunderbird und WinExplorer nicht starten konnte... Standen aber im taskmanager 3x drin.. waren also gestartet aber wurden nicht angezeigt .. Also Fenster haben sich nicht geöffnet :-( Gruß Vater Sohn |
28.02.2014, 20:13 | #43 |
/// the machine /// TB-Ausbilder | Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Poste bitte nochmal ein frisches FRST log
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.03.2014, 09:58 | #44 |
| Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! Hallo und guten morgen Schrauber.. Hier das Log.. FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-02-2014 02 Ran by Admin (administrator) on ADMIN-PC on 01-03-2014 09:48:48 Running from C:\Users\Admin\Desktop\Trojanerbord\Programme Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe ( ) C:\Windows\system32\lxducoms.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Saitek) C:\Program Files\Saitek\SD6\Software\SaiMfd.exe () C:\Windows\System32\OEM\RunCmd_X64.exe (Microsoft Corporation) C:\Windows\system32\cmd.exe () C:\Program Files (x86)\Lexmark 5600-6600 Series\lxdumon.exe (Lexmark International Inc.) C:\Program Files (x86)\Lexmark 5600-6600 Series\ezprint.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe () c:\windows\system32\oem\setEvent.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Emsisoft GmbH) C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2start.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe (Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SaiMfd] - C:\Program Files\Saitek\SD6\Software\SaiMfd.exe [194560 2009-06-03] (Saitek) HKLM\...\Run: [PLD_FrameworkRun] - c:\Windows\System32\oem\RunCMD_X64.exe [337920 2009-08-11] () HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation) HKLM\...\Run: [lxdumon.exe] - C:\Program Files (x86)\Lexmark 5600-6600 Series\lxdumon.exe [676520 2010-02-04] () HKLM\...\Run: [EzPrint] - C:\Program Files (x86)\Lexmark 5600-6600 Series\ezprint.exe [131752 2010-02-04] (Lexmark International Inc.) HKLM-x32\...\Run: [WTClient] - C:\Windows\SysWOW64\WTClient.exe [32768 2009-08-19] (Tablet Driver) HKLM-x32\...\Run: [VolPanel] - C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [184320 2007-04-17] (Creative Technology Ltd) HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295072 2013-01-10] (RealNetworks, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SPIRunE] - Rundll32 SPIRunE.dll,RunDLLEntry HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [36864 2007-03-20] () HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-09-11] (DivX, LLC) HKLM-x32\...\Run: [emsisoft anti-malware] - c:\program files (x86)\emsisoft anti-malware\a2guard.exe [4330432 2014-02-15] (Emsisoft GmbH) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM\...\Winlogon: [Userinit] c:\windows\system32\userinit.exe,c:\program files\soluto\soluto.exe /userinit HKU\S-1-5-21-2715126414-4153456669-2541334608-1000\...\Run: [MtdAcqu] - C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2006-03-08] (Creative Technology Ltd) HKU\S-1-5-21-2715126414-4153456669-2541334608-1000\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000 ==================== Internet (Whitelisted) ==================== ProxyServer: 216.155.139.115:3128 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xD3DA056485D9CE01 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = SearchScopes: HKLM-x32 - {90C03654-BF89-48C9-ABAB-3C6CFF9C7798} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {90C03654-BF89-48C9-ABAB-3C6CFF9C7798} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deDE368 BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO-x32: GetRight IE Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files (x86)\GetRight\xx2gr.dll (Headlight Software, Inc.) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll () BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No File Toolbar: HKCU - No Name - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No File Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPID.cab Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Winsock: Catalog5 10 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [28472] (AVM Berlin) Winsock: Catalog5-x64 10 %ProgramFiles%\FRITZ!DSL\\sarah.dll [34104] (AVM Berlin) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vx5a6cwc.Battlefield FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.102.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.110.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.122.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8064.0206 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=16.0.0.282 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=16.0.0.282 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Admin\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Admin\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Wörterbuch Deutsch (de-DE), Hunspell-unterstützt - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\profiles\extensions\de_DE@dicts.j3e.de [2011-03-18] FF Extension: Integrated Gmail - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\profiles\extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460} [2011-03-18] FF Extension: NoScript - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\profiles\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} [2011-03-18] FF Extension: DownloadHelper - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\profiles\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2012-10-24] FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\profiles\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2012-10-24] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-16] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-16] FF HKLM-x32\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [] FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-01-10] FF HKCU\...\Firefox\Extensions: [{12805837-47e5-429f-8db4-77fa8c07a0e1}] - C:\Program Files (x86)\bLyrics\130.xpi Chrome: ======= CHR HomePage: hxxp://www.google.com CHR DefaultSearchProvider: Linkury Smartbar Search CHR DefaultSearchURL: hxxp://www.google.com CHR Plugin: (Shockwave Flash) - C:\Users\Admin\AppData\Local\Google\Chrome\Application\15.0.874.106\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll No File CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll No File CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll No File CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation) CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Admin\AppData\Local\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\Admin\AppData\Local\Google\Chrome\Application\15.0.874.106\pdf.dll No File CHR Plugin: (vShare.tv plug-in) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll No File CHR Plugin: (vShare.tv plug-in) - C:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll No File CHR Plugin: (Windows Genuine Advantage) - C:\Program Files (x86)\Mozilla Firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation) CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll No File CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll No File CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll No File CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Default Plug-in) - default_plugin No File CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2012-11-29] CHR HKLM-x32\...\Chrome\Extension: [okaclkhnjaebofijaabgiahinbajiekd] - C:\Program Files (x86)\bLyrics\130.crx [2012-11-29] ==================== Services (Whitelisted) ================= R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4163584 2014-02-15] (Emsisoft GmbH) R2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-02] (Akamai Technologies, Inc.) S4 gfi_lanss9_attservice; C:\Program Files (x86)\GFI\LANguard 9\lnssatt.exe [329144 2010-11-13] (GFI Software Ltd.) S4 GFI_ReportCenter35; C:\Program Files (x86)\Common Files\GFI\ReportCenter\Framework v3.5\gfireporterservice.exe [111912 2009-06-16] (GFI Software Ltd.) S4 IGDCTRL; C:\Program Files\FRITZ!DSL\IGDCTRL.EXE [88888 2009-07-28] (AVM Berlin) S2 lxduCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\lxduserv.exe [29184 2009-10-16] (Lexmark International, Inc.) R2 lxdu_device; C:\Windows\system32\lxducoms.exe [1039360 2009-10-16] ( ) R2 lxdu_device; C:\Windows\SysWOW64\lxducoms.exe [589824 2009-10-16] ( ) R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [58345832 2011-09-22] (Microsoft Corporation) R2 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [311592 2009-08-06] (Egis Technology Inc.) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2013-08-13] () R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2013-08-13] () S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] () S4 sesvc; C:\Program Files (x86)\ShadowExplorer\sesvc.exe [9216 2011-01-02] (www.shadowexplorer.com) S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [431464 2011-09-22] (Microsoft Corporation) S4 TVersityMediaServer; C:\ProgramData\TVersity\Media Server\MediaServer.exe [1249064 2011-07-29] () S4 VMLiteService; C:\Program Files\VMLite\VMLite Workstation\VMLiteService.exe [426600 2010-08-21] (VMLite, Inc.) ==================== Drivers (Whitelisted) ==================== R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [70960 2013-08-24] (Emsisoft GmbH) R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH) R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH) R1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [17384 2013-03-28] (Emsisoft GmbH) R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [116096 2011-01-22] (AVM Berlin) R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [116480 2014-01-30] (AVM Berlin) R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH) S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-04-22] (EnTech Taiwan) S3 libusb0; C:\Windows\SysWOW64\drivers\libusb0.sys [33792 2005-03-09] () S3 papycpu; C:\Windows\SysWow64\Drivers\papycpu.sys [1984 1998-09-04] () S3 s125bus; C:\Windows\System32\DRIVERS\s125bus.sys [108296 2007-04-24] (MCCI Corporation) S3 s125mdfl; C:\Windows\System32\DRIVERS\s125mdfl.sys [19720 2007-04-24] (MCCI Corporation) S3 s125mdm; C:\Windows\System32\DRIVERS\s125mdm.sys [144648 2007-04-24] (MCCI Corporation) S3 s125mgmt; C:\Windows\System32\DRIVERS\s125mgmt.sys [126216 2007-04-24] (MCCI Corporation) S3 s125obex; C:\Windows\System32\DRIVERS\s125obex.sys [123656 2007-04-24] (MCCI Corporation) S3 SaiHFF04; C:\Windows\System32\DRIVERS\SaiHFF04.sys [171144 2007-05-01] (Saitek) S3 SaiIFF04; C:\Windows\System32\DRIVERS\SaiIFF04.sys [20608 2007-05-01] (Saitek) R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [16000 2009-06-10] (Saitek) R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [43264 2009-06-10] (Saitek) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [526392 2012-01-07] (Duplex Secure Ltd.) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-08-06] () R1 VBoxDrv; C:\Windows\System32\drivers\VBoxDrv.sys [204328 2010-08-11] (VMLite, Inc.) R3 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp.sys [146216 2010-08-11] (VMLite, Inc.) R3 VBoxNetFlt; C:\Windows\System32\DRIVERS\VBoxNetFlt.sys [165800 2010-08-11] (VMLite, Inc.) R3 vmlitediskmp; C:\Windows\System32\DRIVERS\vmlitediskmp.sys [147560 2010-01-11] (VMLite, Inc.) R1 vmlitedrv; C:\Windows\System32\drivers\vmlitedrv.sys [14952 2010-08-03] (VMLite, Inc.) R3 vmlitestor; C:\Windows\System32\DRIVERS\vmlitestor.sys [177768 2010-08-11] (VMLite, Inc.) R1 VMLiteUSBMon; C:\Windows\System32\drivers\vmliteusbmon.sys [135272 2010-08-18] (VMLite, Inc.) S3 WFMC_VAD; C:\Windows\System32\DRIVERS\wfmcvad.sys [24064 2010-02-08] (WiFi Media Connect) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-05] (Microsoft Corporation) S0 Lbd; system32\DRIVERS\Lbd.sys [X] S0x01000000 papycpu2; \SystemRoot\system32\drivers\papycpu2.sys [X] S3 Tablet2k; "%SystemRoot%\System32\Drivers\Tablet2k.sys" [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-01 09:08 - 2014-03-01 09:08 - 00001747 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 09:08 - 2014-03-01 09:08 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 09:08 - 2014-03-01 09:08 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 09:08 - 2014-03-01 09:08 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 09:08 - 2014-03-01 09:08 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 08:55 - 2014-03-01 08:55 - 00001809 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-03-01 08:54 - 2014-03-01 08:55 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-02-26 19:48 - 2014-02-26 20:23 - 00041472 _____ () C:\Users\Admin\Documents\umsatz Format2.xls 2014-02-26 18:11 - 2014-02-26 18:12 - 00113204 _____ () C:\Windows\system32\LexFiles.ulf 2014-02-26 18:11 - 2014-02-26 18:11 - 00000000 ____D () C:\Program Files\Lexmark Printable Web 2014-02-26 18:11 - 2014-02-26 18:11 - 00000000 ____D () C:\Program Files (x86)\Lexmark 5600-6600 Series 2014-02-26 18:11 - 2009-10-16 12:26 - 00001867 _____ () C:\Windows\SysWOW64\lxdu.loc 2014-02-26 18:11 - 2009-10-16 12:26 - 00001867 _____ () C:\Windows\system32\lxdu.loc 2014-02-26 18:11 - 2009-10-16 12:07 - 00335872 _____ () C:\Windows\SysWOW64\lxducomx.dll 2014-02-26 18:11 - 2009-10-16 12:07 - 00109056 _____ () C:\Windows\system32\lxduvs.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 01661952 _____ ( ) C:\Windows\system32\lxduserv.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 01338368 _____ ( ) C:\Windows\system32\lxduusb1.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 01291264 _____ ( ) C:\Windows\system32\lxducomc.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 01091584 _____ ( ) C:\Windows\system32\lxduhbn3.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 01069056 _____ ( ) C:\Windows\SysWOW64\lxduserv.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 01039360 _____ ( ) C:\Windows\system32\lxducoms.exe 2014-02-26 18:11 - 2009-10-16 12:06 - 00987648 _____ ( ) C:\Windows\system32\lxdupmui.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00897024 _____ ( ) C:\Windows\system32\lxdulmpm.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00860160 _____ ( ) C:\Windows\SysWOW64\lxduusb1.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00761856 _____ ( ) C:\Windows\SysWOW64\lxducomc.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00684032 _____ ( ) C:\Windows\SysWOW64\lxduhbn3.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00651264 _____ ( ) C:\Windows\SysWOW64\lxdupmui.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00610304 _____ ( ) C:\Windows\system32\lxducfg.exe 2014-02-26 18:11 - 2009-10-16 12:06 - 00589824 _____ ( ) C:\Windows\SysWOW64\lxducoms.exe 2014-02-26 18:11 - 2009-10-16 12:06 - 00580608 _____ ( ) C:\Windows\system32\lxducomm.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00577536 _____ ( ) C:\Windows\SysWOW64\lxdulmpm.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00548352 _____ ( ) C:\Windows\system32\lxduinpa.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00521216 _____ ( ) C:\Windows\system32\lxduih.exe 2014-02-26 18:11 - 2009-10-16 12:06 - 00513024 _____ ( ) C:\Windows\system32\lxduiesc.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00376832 _____ ( ) C:\Windows\SysWOW64\lxducomm.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00364544 _____ ( ) C:\Windows\SysWOW64\lxduinpa.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00364544 _____ ( ) C:\Windows\SysWOW64\lxducfg.exe 2014-02-26 18:11 - 2009-10-16 12:06 - 00339968 _____ ( ) C:\Windows\SysWOW64\lxduiesc.dll 2014-02-26 18:11 - 2009-10-16 12:06 - 00323584 _____ ( ) C:\Windows\SysWOW64\lxduih.exe 2014-02-26 18:11 - 2009-10-16 12:06 - 00126976 _____ (Lexmark International Inc.) C:\Windows\SysWOW64\lxdulnks.dll 2014-02-26 18:11 - 2009-10-16 11:56 - 00300032 _____ () C:\Windows\system32\lxdugrd.dll 2014-02-26 18:11 - 2009-07-14 05:43 - 00090624 _____ (Lexmark International, Inc.) C:\Windows\system32\lxduinsr.dll 2014-02-26 18:11 - 2009-07-14 05:43 - 00022528 _____ (Lexmark International, Inc.) C:\Windows\system32\lxducur.dll 2014-02-26 18:11 - 2009-07-14 05:42 - 00132608 _____ (Lexmark International, Inc.) C:\Windows\system32\lxdujswr.dll 2014-02-26 18:11 - 2009-07-14 05:41 - 00183296 _____ (Lexmark International, Inc.) C:\Windows\system32\lxduinsb.dll 2014-02-26 18:11 - 2009-07-14 05:41 - 00073216 _____ (Lexmark International, Inc.) C:\Windows\system32\lxducub.dll 2014-02-26 18:11 - 2009-07-14 05:39 - 00235520 _____ (Lexmark International, Inc.) C:\Windows\system32\lxduins.dll 2014-02-26 18:11 - 2009-07-14 05:39 - 00103936 _____ (Lexmark International, Inc.) C:\Windows\system32\lxducu.dll 2014-02-26 18:11 - 2009-07-14 05:38 - 00760320 _____ (Lexmark International, Inc.) C:\Windows\system32\lxduutil.dll 2014-02-26 18:11 - 2009-07-14 05:06 - 00147456 _____ (Lexmark International, Inc.) C:\Windows\SysWOW64\lxdujswr.dll 2014-02-26 18:11 - 2009-07-14 05:06 - 00106496 _____ (Lexmark International, Inc.) C:\Windows\SysWOW64\lxduinsr.dll 2014-02-26 18:11 - 2009-07-14 05:06 - 00036864 _____ (Lexmark International, Inc.) C:\Windows\SysWOW64\lxducur.dll 2014-02-26 18:11 - 2009-07-14 05:04 - 00200704 _____ (Lexmark International, Inc.) C:\Windows\SysWOW64\lxduinsb.dll 2014-02-26 18:11 - 2009-07-14 05:04 - 00090112 _____ (Lexmark International, Inc.) C:\Windows\SysWOW64\lxducub.dll 2014-02-26 18:11 - 2009-07-14 05:02 - 00176128 _____ (Lexmark International, Inc.) C:\Windows\SysWOW64\lxduins.dll 2014-02-26 18:11 - 2009-07-14 05:02 - 00077824 _____ (Lexmark International, Inc.) C:\Windows\SysWOW64\lxducu.dll 2014-02-26 18:11 - 2009-07-14 04:59 - 00544768 _____ (Lexmark International, Inc.) C:\Windows\SysWOW64\lxduutil.dll 2014-02-26 18:11 - 2009-05-21 03:26 - 00681984 _____ ( ) C:\Windows\system32\LXDUhcp.dll 2014-02-26 18:11 - 2009-05-21 01:14 - 00594944 _____ () C:\Windows\system32\LXDUinst.dll 2014-02-26 18:11 - 2009-05-20 15:57 - 00389120 _____ () C:\Windows\SysWOW64\LXDUinst.dll 2014-02-26 18:11 - 2009-04-28 05:57 - 00489472 _____ (Lexmark International, Inc.) C:\Windows\system32\LXDUwupd.dll 2014-02-26 18:11 - 2009-04-28 05:57 - 00014336 _____ (Lexmark International, Inc.) C:\Windows\system32\LXDUwupd.exe 2014-02-26 18:11 - 2008-03-06 01:56 - 00983121 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lxdugf.dll 2014-02-26 18:11 - 2008-03-06 01:56 - 00983121 _____ (Microsoft Corporation) C:\Windows\system32\lxdugf.dll 2014-02-26 18:11 - 2008-02-21 06:15 - 00065536 _____ (Lexmark International) C:\Windows\system32\LXDUcfg.dll 2014-02-26 18:10 - 2014-02-26 18:12 - 00000000 ____D () C:\Program Files\Lexmark 5600-6600 Series 2014-02-26 17:09 - 2014-02-26 17:09 - 00000112 _____ () C:\Windows\system32\snetcfg.log 2014-02-26 16:58 - 2014-01-09 03:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-02-26 16:58 - 2014-01-03 23:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-02-26 16:57 - 2014-02-26 16:57 - 00003764 _____ () C:\Windows\avmadd321.log 2014-02-26 16:57 - 2014-02-26 16:57 - 00001618 _____ () C:\Windows\avmadd32.log 2014-02-25 22:36 - 2014-02-25 22:36 - 00000966 _____ () C:\Windows\SysWOW64\a2scan_140225-174047.txt 2014-02-22 08:46 - 2014-02-22 08:46 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\EurekaLog 2014-02-21 14:41 - 2014-02-21 14:41 - 00001059 _____ () C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk 2014-02-21 09:43 - 2014-03-01 09:48 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware 2014-02-21 09:43 - 2014-02-21 14:41 - 00000000 ____D () C:\Users\Admin\Documents\Anti-Malware 2014-02-21 09:19 - 2014-02-21 09:19 - 00015395 _____ () C:\Users\Admin\Desktop\umsatz Format1.txt 2014-02-21 09:15 - 2014-02-21 09:15 - 06856861 _____ () C:\ProgramData\SPL79E0.tmp 2014-02-21 08:46 - 2014-02-26 16:51 - 00038654 _____ () C:\Windows\avmacc.log 2014-02-21 08:46 - 2014-02-21 08:47 - 00002408 _____ () C:\Windows\avmacc1.log 2014-02-21 08:43 - 2014-03-01 08:38 - 00002542 _____ () C:\Windows\setupact.log 2014-02-21 08:43 - 2014-02-26 17:47 - 00014086 _____ () C:\Windows\PFRO.log 2014-02-21 08:43 - 2014-02-21 08:43 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-20 17:18 - 2014-02-20 17:18 - 00018015 _____ () C:\Users\Admin\Documents\umsatz2.1.xlsx 2014-02-20 17:04 - 2014-02-20 17:04 - 06891249 _____ () C:\ProgramData\SPL6C68.tmp 2014-02-20 17:03 - 2014-02-21 08:30 - 00018181 _____ () C:\Users\Admin\Documents\umsatz Format1.xlsx 2014-02-20 16:47 - 2014-02-20 16:47 - 06851059 _____ () C:\ProgramData\SPLF4F9.tmp 2014-02-20 16:47 - 2014-02-20 16:47 - 00017640 _____ () C:\Users\Admin\Documents\umsatz Format.xlsx 2014-02-20 16:35 - 2014-02-20 16:35 - 00017028 _____ () C:\Users\Admin\Documents\umsatz2.xlsx 2014-02-20 16:29 - 2010-02-04 05:40 - 00086016 _____ () C:\Windows\system32\lxduoem.dll 2014-02-20 16:29 - 2010-02-04 05:39 - 00003584 _____ () C:\Windows\system32\LXDUPMRC.DLL 2014-02-20 16:29 - 2010-02-04 05:38 - 00014336 _____ () C:\Windows\system32\LXDUFXPU.DLL 2014-02-20 16:29 - 2009-05-14 07:24 - 00045568 _____ () C:\Windows\system32\LXDUPMON.DLL 2014-02-20 16:23 - 2014-02-20 16:23 - 00000000 ____D () C:\Program Files (x86)\Lexmark Toolbar 2014-02-20 15:04 - 2014-02-20 15:04 - 00015425 _____ () C:\Users\Admin\Documents\umsatz2.csv 2014-02-20 14:58 - 2009-10-15 17:32 - 00745984 _____ ( ) C:\Windows\system32\lxducoin.dll 2014-02-20 14:58 - 2008-03-11 16:14 - 00065632 _____ () C:\Windows\system32\lxduprpr.chm 2014-02-20 14:58 - 2008-03-06 01:56 - 01462272 _____ (Microsoft Corporation) C:\Windows\system32\lxdug.dll 2014-02-20 14:42 - 2014-02-20 14:42 - 00166228 _____ () C:\ProgramData\SPLC7F2.tmp 2014-02-20 14:38 - 2014-02-20 14:38 - 00015425 _____ () C:\Users\Admin\Documents\umsatz.csv 2014-02-16 18:57 - 2014-02-16 19:13 - 234141000 _____ (Emsisoft GmbH ) C:\Users\Admin\Desktop\EmsisoftInternetSecuritySetup.exe 2014-02-16 14:19 - 2014-02-16 14:50 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-02-16 11:21 - 2014-02-16 11:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-13 20:49 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 20:49 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 20:49 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-13 20:49 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 20:49 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 20:49 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 20:49 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 20:49 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 20:49 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-13 20:49 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 20:49 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 20:49 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 20:49 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 20:49 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 20:49 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 20:49 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 20:49 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 20:49 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 20:49 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 20:49 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 20:49 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 20:49 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 20:49 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 20:49 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 20:49 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-13 20:49 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 20:49 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 20:49 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 20:49 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 20:49 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 20:49 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 20:49 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 20:49 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 20:49 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 20:49 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 20:49 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 20:49 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 20:49 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 20:49 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 20:49 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 20:49 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-13 16:57 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-13 16:57 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-13 16:57 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-13 16:57 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-13 16:57 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-13 16:57 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-13 16:56 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-13 16:56 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-13 16:56 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-13 16:56 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-13 16:56 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-13 16:56 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-13 16:56 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-13 16:56 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-13 16:56 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-13 16:56 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-13 16:56 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-13 16:56 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-13 16:56 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-13 16:56 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-13 16:56 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-13 16:56 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-13 16:56 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-13 16:56 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-13 16:56 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-13 16:56 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-13 16:56 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-13 16:56 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-12 18:43 - 2014-02-12 18:43 - 02436139 _____ () C:\Users\Admin\Desktop\SV Walkin Dead.psd 2014-02-12 17:19 - 2014-02-12 17:19 - 00000000 ____D () C:\Users\Admin\Desktop\dead_font_walking 2014-02-12 17:17 - 2014-02-12 17:16 - 00017370 _____ () C:\Users\Admin\Desktop\dead_font_walking.zip 2014-02-10 20:20 - 2014-03-01 09:02 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-10 20:20 - 2014-02-21 10:03 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-09 10:13 - 2014-02-09 12:42 - 66451521 _____ () C:\Users\Admin\Desktop\Trauer HSV Farbe.psd 2014-02-05 05:02 - 2014-02-05 05:02 - 00119560 _____ () C:\Windows\system32\GDIPFONTCACHEV1.DAT 2014-02-05 03:56 - 2014-02-05 03:56 - 00000000 ____D () C:\Users\Public\Recorded TV 2014-02-04 19:51 - 2014-02-04 19:51 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ADMIN-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat 2014-02-04 19:51 - 2014-02-04 19:51 - 00000000 ____D () C:\RegBackup 2014-02-04 17:25 - 2014-02-04 17:25 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com 2014-02-04 17:25 - 2014-02-04 17:25 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com 2014-02-03 18:31 - 2014-02-05 03:51 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2014-02-03 17:18 - 2014-02-03 17:18 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-02-03 17:18 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-02-03 17:18 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-01-31 19:51 - 2014-01-31 19:51 - 02630806 _____ () C:\Users\Admin\Desktop\tyres_iii_by_katha83_by_katha83-d427yim.abr 2014-01-31 15:25 - 2014-01-31 15:25 - 00002758 _____ () C:\Users\Admin\Desktop\JRT.txt 2014-01-31 15:21 - 2014-01-31 15:21 - 00000000 ____D () C:\Windows\ERUNT 2014-01-31 14:08 - 2014-01-31 15:10 - 00000000 ____D () C:\AdwCleaner 2014-01-30 20:26 - 2014-01-30 20:25 - 00116480 _____ (AVM Berlin) C:\Windows\system32\Drivers\avmaura.sys ==================== One Month Modified Files and Folders ======= 2014-03-01 09:48 - 2014-02-21 09:43 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware 2014-03-01 09:48 - 2014-01-27 19:04 - 00000000 ____D () C:\FRST 2014-03-01 09:41 - 2010-02-26 13:10 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-01 09:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-03-01 09:09 - 2013-01-26 09:18 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2715126414-4153456669-2541334608-1000UA.job 2014-03-01 09:08 - 2014-03-01 09:08 - 00001747 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 09:08 - 2014-03-01 09:08 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 09:08 - 2014-03-01 09:08 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 09:08 - 2014-03-01 09:08 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 09:08 - 2014-03-01 09:08 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 09:02 - 2014-02-10 20:20 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-01 08:55 - 2014-03-01 08:55 - 00001809 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-03-01 08:55 - 2014-03-01 08:54 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-03-01 08:48 - 2011-08-01 17:54 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe 2014-03-01 08:46 - 2012-11-27 17:10 - 01354957 _____ () C:\Windows\WindowsUpdate.log 2014-03-01 08:45 - 2009-07-14 05:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-01 08:45 - 2009-07-14 05:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-01 08:44 - 2010-01-07 06:55 - 00769136 _____ () C:\Windows\system32\perfh007.dat 2014-03-01 08:44 - 2010-01-07 06:55 - 00175866 _____ () C:\Windows\system32\perfc007.dat 2014-03-01 08:44 - 2009-07-14 06:13 - 01816162 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-01 08:41 - 2010-02-26 13:10 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-01 08:38 - 2014-02-21 08:43 - 00002542 _____ () C:\Windows\setupact.log 2014-03-01 08:38 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-26 20:23 - 2014-02-26 19:48 - 00041472 _____ () C:\Users\Admin\Documents\umsatz Format2.xls 2014-02-26 20:18 - 2010-02-26 12:48 - 00000000 ____D () C:\ProgramData\lx_Cats 2014-02-26 18:32 - 2011-01-07 19:20 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\TS3Client 2014-02-26 18:20 - 2011-01-07 19:19 - 00000000 ____D () C:\Program Files (x86)\TeamSpeak 3 Client 2014-02-26 18:12 - 2014-02-26 18:11 - 00113204 _____ () C:\Windows\system32\LexFiles.ulf 2014-02-26 18:12 - 2014-02-26 18:10 - 00000000 ____D () C:\Program Files\Lexmark 5600-6600 Series 2014-02-26 18:11 - 2014-02-26 18:11 - 00000000 ____D () C:\Program Files\Lexmark Printable Web 2014-02-26 18:11 - 2014-02-26 18:11 - 00000000 ____D () C:\Program Files (x86)\Lexmark 5600-6600 Series 2014-02-26 18:11 - 2010-02-28 18:40 - 00003192 _____ () C:\Windows\System32\Tasks\Installation App Launcher 2014-02-26 17:47 - 2014-02-21 08:43 - 00014086 _____ () C:\Windows\PFRO.log 2014-02-26 17:44 - 2010-02-28 17:36 - 00084513 _____ () C:\ProgramData\lxdu.log 2014-02-26 17:35 - 2010-10-09 08:56 - 00001338 _____ () C:\ProgramData\lxduDiagnostics.log 2014-02-26 17:09 - 2014-02-26 17:09 - 00000112 _____ () C:\Windows\system32\snetcfg.log 2014-02-26 17:09 - 2012-06-16 16:39 - 00000000 ____D () C:\Program Files\FRITZ!Fernzugang 2014-02-26 17:08 - 2010-05-13 17:34 - 00000000 ____D () C:\Users\Admin\AppData\Local\Deployment 2014-02-26 17:08 - 2010-05-12 19:49 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRITZ!Box 2014-02-26 16:57 - 2014-02-26 16:57 - 00003764 _____ () C:\Windows\avmadd321.log 2014-02-26 16:57 - 2014-02-26 16:57 - 00001618 _____ () C:\Windows\avmadd32.log 2014-02-26 16:51 - 2014-02-21 08:46 - 00038654 _____ () C:\Windows\avmacc.log 2014-02-25 22:36 - 2014-02-25 22:36 - 00000966 _____ () C:\Windows\SysWOW64\a2scan_140225-174047.txt 2014-02-25 17:58 - 2010-05-12 19:50 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\FRITZ! 2014-02-25 17:57 - 2010-05-12 19:49 - 00375365 _____ () C:\Users\Admin\DesktopStCenter.txt 2014-02-23 12:58 - 2010-10-08 13:57 - 02008064 ___SH () C:\Users\Admin\Desktop\Thumbs.db 2014-02-23 12:53 - 2013-09-01 09:21 - 00000000 ____D () C:\Users\Admin\Desktop\Tim Melzer 2014-02-23 11:08 - 2013-01-26 09:18 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2715126414-4153456669-2541334608-1000Core.job 2014-02-23 09:49 - 2012-01-14 09:04 - 00284137 _____ () C:\Windows\SysWOW64\TVersityMediaServer.log 2014-02-22 09:38 - 2013-01-10 16:58 - 00003340 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2715126414-4153456669-2541334608-1000 2014-02-22 09:38 - 2013-01-10 16:58 - 00003206 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2715126414-4153456669-2541334608-1000 2014-02-22 08:46 - 2014-02-22 08:46 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\EurekaLog 2014-02-22 08:42 - 2011-01-16 12:20 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-21 14:41 - 2014-02-21 14:41 - 00001059 _____ () C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk 2014-02-21 14:41 - 2014-02-21 09:43 - 00000000 ____D () C:\Users\Admin\Documents\Anti-Malware 2014-02-21 10:03 - 2014-02-10 20:20 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-21 10:03 - 2012-04-04 11:04 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-21 10:03 - 2011-07-09 12:49 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-21 09:19 - 2014-02-21 09:19 - 00015395 _____ () C:\Users\Admin\Desktop\umsatz Format1.txt 2014-02-21 09:15 - 2014-02-21 09:15 - 06856861 _____ () C:\ProgramData\SPL79E0.tmp 2014-02-21 08:47 - 2014-02-21 08:46 - 00002408 _____ () C:\Windows\avmacc1.log 2014-02-21 08:43 - 2014-02-21 08:43 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-21 08:35 - 2010-06-26 09:07 - 00000000 ____D () C:\Windows\pss 2014-02-21 08:30 - 2014-02-20 17:03 - 00018181 _____ () C:\Users\Admin\Documents\umsatz Format1.xlsx 2014-02-21 08:19 - 2012-11-10 18:10 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Spotify 2014-02-20 17:18 - 2014-02-20 17:18 - 00018015 _____ () C:\Users\Admin\Documents\umsatz2.1.xlsx 2014-02-20 17:04 - 2014-02-20 17:04 - 06891249 _____ () C:\ProgramData\SPL6C68.tmp 2014-02-20 16:47 - 2014-02-20 16:47 - 06851059 _____ () C:\ProgramData\SPLF4F9.tmp 2014-02-20 16:47 - 2014-02-20 16:47 - 00017640 _____ () C:\Users\Admin\Documents\umsatz Format.xlsx 2014-02-20 16:35 - 2014-02-20 16:35 - 00017028 _____ () C:\Users\Admin\Documents\umsatz2.xlsx 2014-02-20 16:23 - 2014-02-20 16:23 - 00000000 ____D () C:\Program Files (x86)\Lexmark Toolbar 2014-02-20 15:04 - 2014-02-20 15:04 - 00015425 _____ () C:\Users\Admin\Documents\umsatz2.csv 2014-02-20 14:55 - 2009-09-17 22:29 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-02-20 14:42 - 2014-02-20 14:42 - 00166228 _____ () C:\ProgramData\SPLC7F2.tmp 2014-02-20 14:38 - 2014-02-20 14:38 - 00015425 _____ () C:\Users\Admin\Documents\umsatz.csv 2014-02-20 12:36 - 2010-02-26 13:10 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-20 12:36 - 2010-02-26 13:10 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-18 18:25 - 2010-07-06 16:16 - 00000000 ____D () C:\Program Files (x86)\FLV Player 2014-02-16 19:13 - 2014-02-16 18:57 - 234141000 _____ (Emsisoft GmbH ) C:\Users\Admin\Desktop\EmsisoftInternetSecuritySetup.exe 2014-02-16 14:55 - 2013-07-27 09:49 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-16 14:53 - 2010-02-26 14:16 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-16 14:50 - 2014-02-16 14:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-02-16 11:21 - 2014-02-16 11:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-16 11:03 - 2013-01-26 09:18 - 00004090 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2715126414-4153456669-2541334608-1000UA 2014-02-16 11:03 - 2013-01-26 09:18 - 00003694 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2715126414-4153456669-2541334608-1000Core 2014-02-14 17:11 - 2013-05-19 11:47 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-02-13 20:51 - 2010-07-11 13:14 - 01789506 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-13 18:39 - 2013-12-13 17:03 - 00000000 ____D () C:\Program Files (x86)\EVEMon 2014-02-13 16:41 - 2009-07-14 05:45 - 05003000 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-12 18:43 - 2014-02-12 18:43 - 02436139 _____ () C:\Users\Admin\Desktop\SV Walkin Dead.psd 2014-02-12 17:21 - 2010-02-08 10:14 - 00119968 _____ () C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-12 17:19 - 2014-02-12 17:19 - 00000000 ____D () C:\Users\Admin\Desktop\dead_font_walking 2014-02-12 17:16 - 2014-02-12 17:17 - 00017370 _____ () C:\Users\Admin\Desktop\dead_font_walking.zip 2014-02-10 20:18 - 2013-04-10 16:28 - 00000000 ____D () C:\Program Files\Eraser 2014-02-09 12:46 - 2014-01-26 08:00 - 00001732 _____ () C:\Users\Public\Desktop\Defraggler.lnk 2014-02-09 12:42 - 2014-02-09 10:13 - 66451521 _____ () C:\Users\Admin\Desktop\Trauer HSV Farbe.psd 2014-02-07 16:47 - 2010-03-07 18:25 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\FileZilla 2014-02-06 13:16 - 2014-02-13 20:49 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-13 20:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-13 20:49 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-13 20:49 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-13 20:49 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-13 20:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-13 20:49 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-13 20:49 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-13 20:49 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-13 20:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-13 20:49 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-13 20:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-13 20:49 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-13 20:49 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-13 20:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-13 20:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-13 20:49 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-13 20:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-13 20:49 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-13 20:49 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-13 20:49 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-13 20:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-13 20:49 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-13 20:49 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-13 20:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-13 20:49 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-13 20:49 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-13 20:49 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-13 20:49 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-13 20:49 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-13 20:49 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-13 20:49 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-13 20:49 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-13 20:49 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-13 20:49 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-13 20:49 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-13 20:49 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-13 20:49 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-13 20:49 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-05 05:02 - 2014-02-05 05:02 - 00119560 _____ () C:\Windows\system32\GDIPFONTCACHEV1.DAT 2014-02-05 03:56 - 2014-02-05 03:56 - 00000000 ____D () C:\Users\Public\Recorded TV 2014-02-05 03:51 - 2014-02-03 18:31 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2014-02-04 19:51 - 2014-02-04 19:51 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ADMIN-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat 2014-02-04 19:51 - 2014-02-04 19:51 - 00000000 ____D () C:\RegBackup 2014-02-04 17:25 - 2014-02-04 17:25 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com 2014-02-04 17:25 - 2014-02-04 17:25 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com 2014-02-03 19:23 - 2009-07-14 03:34 - 00000514 _____ () C:\Windows\win.ini 2014-02-03 17:21 - 2013-11-04 18:38 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-03 17:18 - 2014-02-03 17:18 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-02-03 17:18 - 2010-05-07 22:05 - 00000000 ____D () C:\Program Files (x86)\Java 2014-02-02 17:05 - 2013-10-25 16:34 - 00000000 ____D () C:\Users\Admin\AppData\Local\CrashDumps 2014-01-31 19:51 - 2014-01-31 19:51 - 02630806 _____ () C:\Users\Admin\Desktop\tyres_iii_by_katha83_by_katha83-d427yim.abr 2014-01-31 17:17 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-31 15:25 - 2014-01-31 15:25 - 00002758 _____ () C:\Users\Admin\Desktop\JRT.txt 2014-01-31 15:21 - 2014-01-31 15:21 - 00000000 ____D () C:\Windows\ERUNT 2014-01-31 15:10 - 2014-01-31 14:08 - 00000000 ____D () C:\AdwCleaner 2014-01-31 15:05 - 2010-03-28 15:38 - 00000000 ____D () C:\ProgramData\ICQ 2014-01-31 13:37 - 2010-07-11 11:10 - 00000000 ____D () C:\ProgramData\Apple 2014-01-30 20:25 - 2014-01-30 20:26 - 00116480 _____ (AVM Berlin) C:\Windows\system32\Drivers\avmaura.sys 2014-01-30 19:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-01 09:28 ==================== End Of Log ============================ --- --- --- |
01.03.2014, 09:59 | #45 |
| Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! und hier das zweite Log Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-02-2014 02 Ran by Admin at 2014-03-01 09:49:26 Running from C:\Users\Admin\Desktop\Trojanerbord\Programme Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Emsisoft Anti-Malware (Enabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Emsisoft Anti-Malware (Enabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3003 - Acer Incorporated) Acer GameZone Console (HKLM-x32\...\{8ed9688e-4f79-4308-91ca-f1c37ca142b4}_is1) (Version: 5.1.0.2 - Oberon Media, Inc.) Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.02.3004 - Acer Incorporated) Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0812 - Acer Incorporated) Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.01.3014 - Acer Incorporated) Adobe After Effects CS4 (HKLM-x32\...\Adobe_3dcb365ab9e01871fb8c6f27b0ea079) (Version: 9 - Adobe Systems Incorporated) Adobe After Effects CS4 (x32 Version: 9 - Adobe Systems Incorporated) Hidden Adobe After Effects CS4 Presets (x32 Version: 9 - Adobe Systems Incorporated) Hidden Adobe After Effects CS4 Third Party Content (x32 Version: 9 - Adobe Systems Incorporated) Hidden Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.3.0.3670 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.3.0.3670 - Adobe Systems Incorporated) Hidden Adobe Anchor Service CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe Bridge CS4 (x32 Version: 3 - Adobe Systems Incorporated) Hidden Adobe CMaps CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe Color Video Profiles AE CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated) Adobe Community Help (x32 Version: 3.0.0 - Adobe Systems Incorporated) Hidden Adobe CSI CS4 (x32 Version: 1 - Adobe Systems Incorporated) Hidden Adobe CSI CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden Adobe Default Language CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe Device Central CS4 (x32 Version: 2 - Adobe Systems Incorporated) Hidden Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.2 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.2.2 - Adobe Systems Incorporated) Hidden Adobe Dreamweaver CS4 (HKLM-x32\...\Adobe_acce07fd2c8fe7f9e3f26243e626578) (Version: 10.0 - Adobe Systems Incorporated) Adobe Dreamweaver CS4 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden Adobe Dynamiclink Support (x32 Version: 1 - Adobe Systems Incorporated) Hidden Adobe ExtendScript Toolkit CS4 (x32 Version: 3.0.0 - Adobe Systems Incorporated) Hidden Adobe Extension Manager CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Fonts All (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe Media Encoder CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Media Encoder CS4 Additional Exporter (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Media Encoder CS4 Exporter (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Media Encoder CS4 Importer (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated) Adobe Media Player (x32 Version: 0.0.0 - Adobe Systems Incorporated) Hidden Adobe MotionPicture Color Files CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe Output Module (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe PDF Library Files CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Search for Help (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Service Manager Extension (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Setup (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe Type Support CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden Adobe Update Manager CS4 (x32 Version: 6.0.0 - Adobe Systems Incorporated) Hidden Adobe XMP Panels CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden AdobeColorCommonSetRGB (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc) Akamai NetSession Interface Service (HKLM-x32\...\Akamai) (Version: - ) AMD Accelerated Video Transcoding (Version: 13.15.100.30830 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden AMD AVIVO64 Codecs (Version: 11.7.0.11109 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2013.0830.1944.33589 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{1E9871B6-7C44-9A3A-A1C0-F9729663C7F5}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - ATI Technologies Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.80830.1925 - Advanced Micro Devices, Inc.) Hidden AMD System Monitor (HKLM-x32\...\{13EE03A3-7B77-47BC-9C42-B60576AB3A08}) (Version: 1.0.0 - Advanced Micro Devices, Inc.) Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Application Profiles (HKLM-x32\...\{626E44DE-8E53-7570-CFDB-06EBF8595CA8}) (Version: 2.0.4232.33935 - Advanced Micro Devices, Inc.) Application Profiles (HKLM-x32\...\{6B3BA8FB-FEE1-E839-2F6E-5C121ECDAE9F}) (Version: 2.0.4385.36018 - Advanced Micro Devices, Inc.) Application Profiles (HKLM-x32\...\{7156BCE1-5D8D-1A41-565E-E8E8EA604328}) (Version: 2.0.4301.35982 - Advanced Micro Devices, Inc.) Application Profiles (HKLM-x32\...\{93DF9F1F-17EB-82C0-F82B-9ABC230D6DE5}) (Version: 2.0.4315.34200 - Advanced Micro Devices, Inc.) Application Profiles (HKLM-x32\...\{A231A6F2-2C80-6203-ED35-2CFB96B25A38}) (Version: 2.0.4719.35969 - Advanced Micro Devices, Inc.) Application Profiles (HKLM-x32\...\{C496ED25-F3EC-0CBC-37DB-B31C6E6592C9}) (Version: 2.0.4331.36041 - Advanced Micro Devices, Inc.) Application Profiles (HKLM-x32\...\{DCA75ECE-39A9-0648-CB77-F6D759364CF9}) (Version: 2.0.4469.34733 - Advanced Micro Devices, Inc.) Application Profiles (HKLM-x32\...\{EBBE64F6-7E23-5857-891F-045560AECC7F}) (Version: 2.0.4674.34053 - Advanced Micro Devices, Inc.) Audacity 1.2.6 (HKLM-x32\...\Audacity_is1) (Version: - ) AVM FRITZ!Box Dokumentation (HKLM-x32\...\AVMFBox) (Version: - AVM Berlin) AVS Update Manager 1.0 (HKLM-x32\...\AVS Update Manager_is1) (Version: - Online Media Technologies Ltd.) AVS Video Converter 6 (HKLM-x32\...\AVS4YOU Video Converter 6_is1) (Version: - Online Media Technologies Ltd.) AVS4YOU Software Navigator 1.4 (HKLM-x32\...\AVS4YOU Software Navigator_is1) (Version: - Online Media Technologies Ltd.) Battlefield 2(TM) (HKLM-x32\...\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}) (Version: - ) Battlefield 2: Special Forces (HKLM-x32\...\{50D4CB89-AF34-4978-96DC-C3034062E901}) (Version: - ) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.0.0.0 - Electronic Arts) Battlefield: Bad Company™ 2 (HKLM-x32\...\{3AC8457C-0385-4BEA-A959-E095F05D6D67}) (Version: 1.0.0.0 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.1.7 - EA Digital Illusions CE AB) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Bonjour-Druckdienste (HKLM\...\{4CE925AF-6519-4FEB-BEBD-DE2BFE2944EB}) (Version: 2.0.0.36 - Apple Inc.) Borderlands (HKLM-x32\...\{52B65911-1559-4ED5-9461-46957FDD48CD}) (Version: 1.0.295 - 2K Games) Call of Duty: Modern Warfare 2 - Multiplayer (HKLM-x32\...\Steam App 10190) (Version: - Infinity Ward) Call of Duty: Modern Warfare 2 (HKLM-x32\...\Steam App 10180) (Version: - Infinity Ward) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2009.1124.2131.38610 - ATI Technologies, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.0930.2237.38732 - ATI Technologies, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.1026.2246.39002 - ATI Technologies, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.1125.2142.38865 - ATI Technologies, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2011.0524.2352.41027 - ATI Technologies, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform) Choice Guard (x32 Version: 1.2.87.0 - Microsoft Corporation) Hidden Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Connect (x32 Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden ConvertHelper 2.2 (HKLM-x32\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1) (Version: - DownloadHelper) ConvertXtoDVD 4.1.19.365 (HKLM-x32\...\{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1) (Version: 4.1.19.365 - ) Counter-Strike (HKLM-x32\...\Steam App 10) (Version: - Valve) Counter-Strike: Global Offensive Beta (HKLM-x32\...\Steam App 730) (Version: - ) Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) Counter-Strike: Source Beta (HKLM-x32\...\Steam App 260) (Version: - ) Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited) Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.00 - ) Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited) Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: - Creative Technology Limited) Dairy Dash (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}) (Version: - Oberon Media) Darkest Hour: Europe '44-'45 (HKLM-x32\...\Steam App 1280) (Version: - Darkest Hour Team) DashCommand (HKLM-x32\...\{FB891630-1C0D-437E-A04E-34543B2CF0A8}) (Version: 3.0.1 - Palmer Performance Engineering) Day of Defeat (HKLM-x32\...\Steam App 30) (Version: - Valve) Dead Island (HKLM-x32\...\Steam App 91310) (Version: - Techland) Dead Space (HKLM-x32\...\Steam App 17470) (Version: - EA Redwood Shores) Deathmatch Classic (HKLM-x32\...\Steam App 40) (Version: - Valve) DebugMode Wax 2.0 (HKLM-x32\...\DebugMode Wax 2.0) (Version: - ) Defraggler (HKLM\...\Defraggler) (Version: 2.16 - Piriform) DH Driver Cleaner Professional Edition (HKLM-x32\...\Driver Cleaner Pro) (Version: Version 1.5 - Ruud Ketelaars) DiRT 2 (HKLM-x32\...\Steam App 12840) (Version: - Codemasters) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.87 - DivX, LLC) DivxToDVD 0.5.2b (HKLM-x32\...\VSO DivxToDVD_is1) (Version: 0.5.2b - VSO-Software SARL) Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media) DVDx 4.0 Open Edition (HKLM-x32\...\DVDx 4.0 Open Edition) (Version: 4.0 (Open Edition) - labDV) eBay Worldwide (HKLM-x32\...\{AAF89271-2594-468D-B578-96B2E30C41C4}) (Version: 2.1.0703 - OEM) Emsisoft Anti-Malware (HKLM-x32\...\{BC30E5E7-047D-4232-A7E8-F2CB7CC7B2E0}_is1) (Version: 8.1 - Emsisoft GmbH) Eraser 6.0.10.2620 (HKLM\...\{6E5159B4-A519-41EF-80EF-AD58371515DF}) (Version: 6.0.2620 - The Eraser Project) eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) eSobi v2 (HKLM-x32\...\InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.4.000274 - esobi Inc.) eSobi v2 (x32 Version: 2.0.4.000274 - esobi Inc.) Hidden EVEMon (HKLM-x32\...\EVEMon) (Version: 1.8.4.4125 - battleclinic.com) EVEREST Ultimate Edition v5.50 (HKLM-x32\...\EVEREST Ultimate Edition_is1) (Version: 5.50 - Lavalys, Inc.) Exact Audio Copy 1.0beta3 (HKLM-x32\...\Exact Audio Copy) (Version: 1.0beta3 - Andre Wiethoff) Excel Protection Remover (HKLM-x32\...\ST6UNST #1) (Version: - ) EXIFeditor (HKLM-x32\...\{50FC1CE8-FF32-4F3B-B654-050DD6ECD474}) (Version: 1.0.0 - kiwi.software.NET) Exif-Viewer 2.50 (HKLM-x32\...\Exif-Viewer) (Version: 2.50 - Ralf Bibinger) FileZilla Client 3.5.3 (HKCU\...\FileZilla Client) (Version: 3.5.3 - FileZilla Project) FLAC 1.2.1b (remove only) (HKLM-x32\...\FLAC) (Version: 1.2.1b - Xiph.org) FLV Player 2.0 (build 25) (HKLM-x32\...\FLV Player) (Version: 2.0 (build 25) - Martijn de Visser) Free Video to MP3 Converter version 3.5 (HKLM-x32\...\Free Video to MP3 Converter_is1) (Version: - DVDVideoSoft Limited.) FRITZ!DSL64 (HKLM\...\{2D5D9603-22CF-4B99-83F6-0CD20330F62E}) (Version: 2.04.03 - AVM Berlin) Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.0.0.0 - Futuremark Corporation) GameShadow (HKLM-x32\...\{B2390904-74BD-48AA-B2CC-6612F8D46379}) (Version: 2.03.0000 - GameShadow Ltd) GetRight (HKLM-x32\...\GetRight_is1) (Version: - Headlight Software, Inc.) GFI LANguard 9.0 ReportPack (HKLM-x32\...\{3F67FD4A-380F-4081-A506-1D2C0091A93E}) (Version: 9.0.2009.0709 - GFI Software Ltd) GFI LANguard 9.6 (HKLM-x32\...\InstallShield_{CBE19707-CF6D-4819-9574-3DFD568960FA}) (Version: 9.6.2010.1113 - GFI Software Ltd) GFI LANguard 9.6 (x32 Version: 9.6.2010.1113 - GFI Software Ltd) Hidden GFI ReportCenter Framework (HKLM-x32\...\{722C2EC9-745F-44EA-A119-D548DB55A3B0}) (Version: 3.6.2009.0630 - GFI Software Ltd) GIMP 2.6.10 (HKLM\...\GIMP-2_is1) (Version: 2.6.10 - The GIMP Team) Google Earth (HKLM-x32\...\{6F545E5E-4595-11E2-93B6-B8AC6F97B88E}) (Version: 7.0.2.8415 - Google) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden Grand Prix Legends (HKLM-x32\...\Grand Prix Legends) (Version: - ) Granny In Paradise (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697}) (Version: - Oberon Media) GRID (HKLM-x32\...\{5A0B7BA5-4682-4273-81C2-69B17E649103}) (Version: 1.00.0000 - Codemasters) GTR Evolution (HKLM-x32\...\Steam App 8660) (Version: - SimBin Studios) Half-Life (HKLM-x32\...\Steam App 70) (Version: - Valve) Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve) Half-Life 2: Deathmatch (HKLM-x32\...\Steam App 320) (Version: - Valve) Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version: - Valve) Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version: - Valve) Half-Life 2: Lost Coast (HKLM-x32\...\Steam App 340) (Version: - Valve) Half-Life Deathmatch: Source (HKLM-x32\...\Steam App 360) (Version: - Valve) Half-Life: Blue Shift (HKLM-x32\...\Steam App 130) (Version: - Gearbox) Hama Cromo Pad (HKLM-x32\...\{975E4CAE-D408-48DA-9346-65D7DB72B7DE}) (Version: 1.00.0000 - GASIA) Hitman: Sniper Challenge (HKLM-x32\...\Steam App 205930) (Version: - IO Interactive) HOMEFRONT (HKLM-x32\...\Steam App 55100) (Version: - THQ) Host OpenAL (HKLM-x32\...\Host OpenAL) (Version: 1.00 - Creative Technology Limited) Hotfix für Microsoft Visual C++ 2010 Express - DEU (KB2565057) (HKLM-x32\...\{DEEB5FE3-40F5-3C5B-8F85-5306EF3C08F4}.KB2565057) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual C++ 2010 Express - DEU (KB2635973) (HKLM-x32\...\{DEEB5FE3-40F5-3C5B-8F85-5306EF3C08F4}.KB2635973) (Version: 1 - Microsoft Corporation) Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 1.00.3004 - Acer Incorporated) iArt 3 (HKLM-x32\...\iArt_is1) (Version: - iPodSoft) iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.) ICQ7.2 (HKLM-x32\...\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}) (Version: 7.2 - ICQ) Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3001 - Acer Incorporated) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden ImTOO Video Converter Ultimate 6 (HKLM-x32\...\ImTOO Video Converter Ultimate 6) (Version: 6.8.0.1101 - ImTOO) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) Java 7 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417025FF}) (Version: 7.0.250 - Oracle) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 35 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216033FF}) (Version: 6.0.350 - Oracle) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) JMicron JMB36X Driver (HKLM-x32\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.00.0000 - JMICRON Technology Corp.) Junk Mail filter update (x32 Version: 14.0.8064.206 - Microsoft Corporation) Hidden kuler (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Left 4 Dead (HKLM-x32\...\Steam App 500) (Version: - Valve) Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve) Left 4 Dead Authoring Tools (HKLM-x32\...\Steam App 513) (Version: - Valve) Lexmark 5600-6600 Series (HKLM\...\Lexmark 5600-6600 Series) (Version: - Lexmark International, Inc.) Lexmark Printable Web (HKLM-x32\...\{D2C5E510-BE6D-42CC-9F61-E4F939078474}) (Version: 1.0.0.0 - ) Lidl-Fotos (HKLM-x32\...\Lidl-Fotos_is1) (Version: - ) Metro 2033 (HKLM-x32\...\Steam App 43110) (Version: - THQ) Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Digital Image Library 9 - Blocker (x32 Version: 9.00.0000 - Microsoft Corporation) Hidden Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Help Viewer 1.0 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.0 Language Pack - DEU) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 (Version: 1.1.40219 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.1 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.1 Language Pack - DEU) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 Language Pack - DEU (Version: 1.1.40219 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0100-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Language Pack 2007 - German/Deutsch (HKLM-x32\...\OMUI.de-de) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office O MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office SharePoint Designer MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office X MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Picture It! Foto Premium 10 (HKLM-x32\...\PictureItPrem_v10) (Version: 10.0.0715 - Microsoft Corporation) Microsoft Picture It! Foto Premium 10 (x32 Version: 10.0.0715 - Microsoft Corporation) Hidden Microsoft Picture It!-Bibliothek 10 (x32 Version: 10.0.0715 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2008 (64-bit) (HKLM\...\Microsoft SQL Server 10 Release) (Version: - Microsoft Corporation) Microsoft SQL Server 2008 (64-bit) (Version: - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Browser (HKLM-x32\...\{4AF2248C-B3DF-46FB-9596-87F5DB193689}) (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2008 Common Files (Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Services (Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Shared (Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Native Client (HKLM\...\{12FE6AA6-65D2-40EE-B925-62193128A0E6}) (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2008 RsFx Driver (Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{0125D081-30D0-4A97-82A8-C28D444B6256}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (HKLM\...\{C3EAE456-7E7A-451F-80EF-F34C7A13C558}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server VSS Writer (HKLM\...\{28D06854-572C-4A65-83E5-F8CAF26B9FDC}) (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft Visual C++ Compilers 2010 Standard - enu - x86 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{f45b48a7-f616-4211-b927-17cab6a96613}) (Version: 8.0.58298 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.218 (HKLM\...\{BBBE35B2-9349-3C48-BD3D-F574B17C7924}) (Version: 9.0.21022.218 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{D285FC5F-3021-32E9-9C59-24CA325BDC5C}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 (HKLM\...\{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 Express - DEU (HKLM-x32\...\Microsoft Visual C++ 2010 Express - DEU) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 Express - DEU (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (HKLM\...\{3C983A67-DFB2-3D3D-AD9E-CA1A5A09FD18}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (HKLM-x32\...\Microsoft Visual Studio 2010 Service Pack 1) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.40303 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40308 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU (Version: 10.0.40303 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.40303 - Microsoft Corporation) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version: - Pavel Cvrcek) Mozilla Firefox 27.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 26.0 - Mozilla) Mozilla Thunderbird 24.3.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.3.0 (x86 de)) (Version: 24.3.0 - Mozilla) Mp3tag v2.50 (HKLM-x32\...\Mp3tag) (Version: v2.50 - Florian Heidenreich) MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Mumble and Murmur (HKLM-x32\...\Mumble) (Version: 1.2.2 - Mumble) Music Manager (HKCU\...\MusicManager) (Version: - Google, Inc.) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.0 - F.J. Wechselberger) MyWinLocker (HKLM-x32\...\{68301905-2DEA-41CE-A4D4-E8B443B099BA}) (Version: 3.1.72.0 - Egis Technology Inc.) Need For Speed™ World (HKLM-x32\...\{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1) (Version: 1.0.0.659 - Electronic Arts) Nero 9 Essentials (HKLM-x32\...\{18c5b800-77b3-4e83-9bcd-967c26a1d75a}) (Version: - Nero AG) Nero Burning ROM 10 (HKLM-x32\...\{7A5D731D-B4B3-490E-B339-75685712BAAB}) (Version: 10.2.11000.12.100 - Nero AG) Nero Burning ROM 10 (HKLM-x32\...\{FE83F463-7E61-4B18-9FA0-B94B90A0B6B9}) (Version: 10.5.10300 - Nero AG) Nero BurningROM 10 Help (CHM) (x32 Version: 10.5.10100 - Nero AG) Hidden Nero BurnRights 10 (HKLM-x32\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.2.10300.0.102 - Nero AG) Nero BurnRights 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Control Center 10 (x32 Version: 10.2.10600.0.6 - Nero AG) Hidden Nero ControlCenter (x32 Version: 9.0.0.1 - Nero AG) Hidden Nero ControlCenter 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Core Components 10 (x32 Version: 2.0.17400.8.2 - Nero AG) Hidden Nero DiscSpeed (x32 Version: 5.4.7.201 - Nero AG) Hidden Nero DiscSpeed Help (x32 Version: 5.4.4.100 - Nero AG) Hidden Nero DriveSpeed (x32 Version: 4.4.7.201 - Nero AG) Hidden Nero DriveSpeed Help (x32 Version: 4.4.4.100 - Nero AG) Hidden Nero Express Help (x32 Version: 9.4.9.100 - Nero AG) Hidden Nero InfoTool (x32 Version: 6.4.7.201 - Nero AG) Hidden Nero InfoTool Help (x32 Version: 6.4.4.100 - Nero AG) Hidden Nero Installer (x32 Version: 4.4.8.1 - Nero AG) Hidden Nero Online Upgrade (x32 Version: 1.3.0.0 - Nero AG) Hidden Nero StartSmart (x32 Version: 9.4.11.209 - Nero AG) Hidden Nero StartSmart Help (x32 Version: 9.4.1.100 - Nero AG) Hidden Nero StartSmart OEM (x32 Version: 9.16.0.100 - Nero AG) Hidden Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG) NeroExpress (x32 Version: 9.4.10.505 - Nero AG) Hidden neroxml (x32 Version: 1.0.0 - Nero AG) Hidden No More Room in Hell (HKLM-x32\...\Steam App 224260) (Version: - No More Room in Hell Team) Norton Online Backup (HKLM-x32\...\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 1.2.0.36 - Symantec) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.7 - ) NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation) OnlineFotoservice (HKLM-x32\...\OnlineFotoservice) (Version: - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 8.5.0.4550 - Electronic Arts, Inc.) PageshotsPro 1.0.0 (HKLM-x32\...\PageshotsPro_is1) (Version: 1.0.0 - PageshotsPro) <==== ATTENTION particleIllusion 3.0.4 (HKLM-x32\...\{F77685F4-49DC-4B8E-B41F-F399FE2787C7}_is1) (Version: 3.0.4 - wondertouch LLC) PAYDAY: The Heist (HKLM-x32\...\Steam App 24240) (Version: - ) PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden Photoshop Camera Raw (x32 Version: 5.0 - Adobe Systems Incorporated) Hidden Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.8 - Google, Inc.) Pixel Bender Toolkit (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden Portal (HKLM-x32\...\Steam App 400) (Version: - Valve) PS3 Media Server (HKLM-x32\...\PS3 Media Server) (Version: 1.90.1 - PS3 Media Server) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.) QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) RACE 07 (HKLM-x32\...\Steam App 8600) (Version: - SimBin Studios) Race: The WTCC Game (HKLM-x32\...\Steam App 4230) (Version: - SimBin Studios) Rapture3D 2.3.26 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound) RealDownloader (x32 Version: 1.3.0 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.0 - RealNetworks) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Recuva (HKLM\...\Recuva) (Version: 1.44 - Piriform) Red Orchestra: Ostfront 41-45 (HKLM-x32\...\Steam App 1200) (Version: - Tripwire Interactive) RESIDENT EVIL 5 (HKLM-x32\...\{AC08BBA0-96B9-431A-A7D0-D8598E493775}) (Version: 1.0.0.129 - CAPCOM CO., LTD.) Ricochet (HKLM-x32\...\Steam App 60) (Version: - Valve) S.T.A.L.K.E.R. - Shadow of Chernobyl (HKLM-x32\...\S.T.A.L.K.E.R. - Shadow of Chernobyl_is1) (Version: 1.0000 - THQ) Saitek SD6 Programming Software 6.6.6.9 (HKLM\...\{899FCA36-ADAF-4612-8579-B37DDB0C092F}) (Version: 6.6.6.9 - Saitek) Service Pack 3 für SQL Server 2008 (KB2546951) (64-bit) (HKLM\...\KB2546951) (Version: 10.3.5500.0 - Microsoft Corporation) ShadowExplorer 0.8 (HKLM-x32\...\ShadowExplorer_is1) (Version: 0.8.430.0 - ShadowExplorer.com) Sierra Utilities (HKLM-x32\...\Sierra Utilities) (Version: - ) Silent Hunter 4 Wolves of the Pacific (HKLM-x32\...\{0D005F09-A5F4-473B-A901-5735C6AF5628}) (Version: 1.03.0000 - Ubisoft) SIW version 2010.07.14 (HKLM-x32\...\{AB67580-257C-45FF-B8F4-C8C30682091A}_is1) (Version: 2010.07.14 - Topala Software Solutions) SmartCopy (HKLM-x32\...\{B7BD291B-D415-4484-89A4-82077504BE93}_is1) (Version: - Northstar Systems Corp.) SmartLauncher (HKLM-x32\...\{57634571-FD82-4BEC-B822-A1ED7765474F}_is1) (Version: - Northstar Systems Corp.) Sniper: Ghost Warrior (HKLM-x32\...\Steam App 34830) (Version: - City Interactive S.A.) Sound Blaster X-Fi (HKLM-x32\...\{0C9D0200-FA32-44B7-BBB3-7C03F700C4A0}) (Version: 1.0 - ) Source SDK (HKLM-x32\...\Steam App 211) (Version: - Valve) Source SDK Base 2007 (HKLM-x32\...\Steam App 218) (Version: - Valve) Speccy (HKLM\...\Speccy) (Version: 1.10 - Piriform) Spotify (HKCU\...\Spotify) (Version: 0.9.7.16.g4b197456 - Spotify AB) Sql Server Customer Experience Improvement Program (Version: 10.3.5500.0 - Microsoft Corporation) Hidden Star Defender 4 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114803710}) (Version: - Oberon Media) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) StreamTransport version: 1.0.2.2171 (HKLM-x32\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - ) Suite Shared Configuration CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden Sweet Home 3D version 3.3 (HKLM-x32\...\Sweet Home 3D_is1) (Version: - eTeks) TCPEye 1.0 (HKLM-x32\...\{998C9435-DAF8-4BDF-B9A5-F844B01D524C}_is1) (Version: - Free Software Relase) Team Fortress Classic (HKLM-x32\...\Steam App 20) (Version: - Valve) TeamSpeak 2 RC2 (HKLM-x32\...\Teamspeak 2 RC2_is1) (Version: 2.0.32.60 - Dominating Bytes Design) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.13.1 - TeamSpeak Systems GmbH) Tom Clancy's H.A.W.X (HKLM-x32\...\{6E36A172-06FB-4BC8-B7FC-D30D219E6776}) (Version: 1.02.00000 - Ubisoft) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) Trust Tablet Driver (HKLM-x32\...\TabletDriver) (Version: - ) TVAnts 1.0 (HKLM-x32\...\TVAnts 1.0) (Version: - ) TVersity Codec Pack 1.7 (HKLM-x32\...\TVersity Codec Pack) (Version: 1.7 - TVersity Inc.) TVersity Media Server 1.9.7 (HKLM-x32\...\TVersity Media Server) (Version: 1.9.7 - TVersity) Tweaking.com - Windows Repair (All in One) (HKLM-x32\...\Tweaking.com - Windows Repair (All in One)) (Version: 2.2.0 - Tweaking.com) Überwachungstool für die Intel® Turbo-Boost-Technologie (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.115.11 - Intel) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) UltraMon (HKLM\...\{B49673F8-7AB6-4A14-8213-C8A7BE370010}) (Version: 3.0.10 - Realtime Soft Ltd) Unlocker 1.9.1 (HKLM-x32\...\Unlocker) (Version: 1.9.1 - Cedrick Collomb) Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) Unterstützungsdateien für Microsoft SQL Server 2008-Setup (HKLM\...\{D8125A39-ADEE-4187-B04D-DB6CF489AF61}) (Version: 10.3.5500.0 - Microsoft Corporation) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0100-0407-0000-0000000FF1CE}_OMUI.de-de_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{199DF7B6-169C-448C-B511-1054101BE9C9}) (Version: - Microsoft) Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM-x32\...\{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2744EF05-38E1-4D5D-B333-E021EDAEA245}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_OMUI.de-de_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{128A5449-CF71-4DA4-A746-F49E3B5DB584}) (Version: - Microsoft) Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version: - Microsoft) Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version: - Microsoft) Update for Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_OMUI.de-de_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_OMUI.de-de_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_OMUI.de-de_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_OMUI.de-de_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Visual C++ 2008 x86 Runtime - (v9.0.30729) (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM-x32\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation) VMLite Workstation (HKLM\...\{197F2BEF-2705-406E-8CEB-8E404FFFE414}) (Version: 3.2.6 - VMLite) Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.00.3005 - Acer Incorporated) WinCDEmu (HKLM-x32\...\WinCDEmu) (Version: 3.6 - Bazis) Windows Live Call (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8064.0206 - Microsoft Corporation) Windows Live Essentials (x32 Version: 14.0.8064.206 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 14.0.8064.206 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Live Mail (x32 Version: 14.0.8064.0206 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live Sync (HKLM-x32\...\{ED636101-1959-4360-8BF7-209436E7DEE4}) (Version: 14.0.8064.206 - Microsoft Corporation) Windows Live Writer (x32 Version: 14.0.8064.0206 - Microsoft Corporation) Hidden Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows XP Mode (HKLM\...\{1374CC63-B520-4f3f-98E8-E9020BF01CFF}) (Version: 1.3.7600.16422 - Microsoft Corporation) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) World of Padman (HKLM-x32\...\World of Padman) (Version: 1.1 - Padworld Entertainment) XBMC (HKCU\...\XBMC) (Version: - Team XBMC) Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org) ==================== Restore Points ========================= 11-02-2014 18:15:37 Removed Firebird SQL Server - MAGIX Edition 13-02-2014 19:49:01 Windows Update 16-02-2014 13:53:16 Windows Update 21-02-2014 07:46:43 Gerätetreiber-Paketinstallation: AVM Berlin AVM USB-Fernanschluss 22-02-2014 07:47:25 Windows Update 25-02-2014 15:45:07 Windows Update 26-02-2014 16:09:21 FRITZ!Fernzugang wird entfernt 26-02-2014 16:54:39 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2014-01-29 18:50 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0115A5A6-E64A-403E-ACAA-CC03CCEA8961} - System32\Tasks\{BEC36182-3C31-41AF-903B-DA5417E01792} => C:\Users\Admin\Downloads\tomtom\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Binaries\Borderlands.exe Task: {0286D2A2-1E63-4032-841E-4B977FBD7810} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2715126414-4153456669-2541334608-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {03720371-86AE-43B6-B7F3-CCCD57810264} - System32\Tasks\{1C5F50C9-41C0-4A0A-A6B2-3E2F0B13CB70} => C:\Users\Admin\Downloads\tomtom\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Binaries\Borderlands.exe Task: {213B6E15-7BE6-418F-8F75-647F45A8AD3C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-02-26] (Google Inc.) Task: {235F1315-633F-499C-BF8D-B6181DF4CCE6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd) Task: {2ACED018-5D04-4F29-AA26-9741A1FA425A} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2715126414-4153456669-2541334608-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {38A89AE3-A38B-4CD6-8BDC-5975B69B9DE2} - System32\Tasks\{0D6D11F9-1C40-46D7-8CA3-4C7C0D126EBD} => C:\Users\Admin\Downloads\tomtom\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Binaries\Borderlands.exe Task: {3B9857BE-320A-4982-BFEE-A6C0E0C60B7F} - System32\Tasks\{A399484D-F591-4733-818C-DC7338273965} => C:\SIERRA\gpl\gpl.exe [2007-03-22] (Sierra On-Line Inc. Bellevue, WA 98007) Task: {469FB8FD-7554-41A4-9C22-96FF12E791BC} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2715126414-4153456669-2541334608-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {70577F12-FB82-400B-AE8A-2F65F7CA8ECC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-02-26] (Google Inc.) Task: {71E9F36C-EAFA-43DE-9D06-E10AD4DAB409} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {729350B7-1537-4BD9-800C-4747F4334C0D} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2715126414-4153456669-2541334608-1010 Task: {8B0B1CDA-71D1-48E7-A959-E5E3773CB4A5} - System32\Tasks\{A9F987D8-E27B-4A6E-AF95-591274BBCFE1} => C:\Users\Admin\Downloads\tomtom\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Binaries\Borderlands.exe Task: {8D9B1BA3-47A8-40DA-BF16-BEE94378AE41} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2715126414-4153456669-2541334608-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {8EC55220-8702-49AC-A22D-1920809C22C3} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2715126414-4153456669-2541334608-1000UA => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2013-01-26] (Google Inc.) Task: {91C39897-7AD6-452A-9089-B91838183D53} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2715126414-4153456669-2541334608-1000Core => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2013-01-26] (Google Inc.) Task: {99CE50B9-986C-46A7-B0DB-F48DEE09F083} - System32\Tasks\AdobeAAMUpdater-1.0-Admin-PC-Admin => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20] (Adobe Systems Incorporated) Task: {9A2FD0BA-7ABB-4DCF-B0FC-0C513C3C9B3A} - System32\Tasks\{0D305426-792B-4830-AD55-34D63689F52D} => C:\Adobe After Effects CS5.5\Set-up.exe Task: {9E14EB50-1670-438F-9CFE-D6355012E8C3} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {B13BF095-8749-44B1-BDD1-441F4E7BFFC0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-21] (Adobe Systems Incorporated) Task: {BA83B7BA-EB12-4347-B67A-BAF1C658BAE0} - System32\Tasks\{42B98F6C-E6A1-449C-864F-8840083F92D0} => C:\Users\Admin\Downloads\tomtom\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Binaries\Borderlands.exe Task: {BF24A726-5A9A-4E70-BFBF-DD3F82A8C814} - System32\Tasks\{19667509-9130-4E49-922E-3A85A064D196} => C:\Users\Admin\Downloads\tomtom\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Binaries\Borderlands.exe Task: {C0F6313F-C440-45B2-8CD7-C7A9DAD819B1} - System32\Tasks\{C26A75A3-8B13-4FA8-9F1E-A1E2761ABEDB} => C:\SIERRA\gpl\gpl.exe [2007-03-22] (Sierra On-Line Inc. Bellevue, WA 98007) Task: {C3B15D4E-F036-45FA-B197-E9157035C5C5} - System32\Tasks\{40252C16-B304-4946-A21A-A72C62710961} => C:\Users\Admin\Downloads\tomtom\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Borderlands Claptraps New Robot Revolution DLC-RELOADED\Binaries\Borderlands.exe Task: {C3BA5DA4-6B3E-4D2F-B2B1-E1844B234BFA} - System32\Tasks\{B049F9BB-5F69-4D85-8268-E17D45B6EEBA} => C:\Users\Admin\Downloads\Sony Ericsson PC Suite 2.10.46.exe Task: {DD8F72FA-2BD2-4376-9223-B2ACAF44D269} - System32\Tasks\{FA0972CC-1C72-4D7D-B73F-EA0731EAA574} => C:\Adobe After Effects CS5.5\Set-up.exe Task: {E1D0CF52-AE3F-4B90-A040-F7F7DCFFD02B} - System32\Tasks\{E69133B3-03F7-47EA-9DD3-C1E9E8FB0D20} => C:\SIERRA\gpl\gpl.exe [2007-03-22] (Sierra On-Line Inc. Bellevue, WA 98007) Task: {EC0F8BBE-33EC-4DFB-AA57-AF4A72872C88} - System32\Tasks\Recovery Management\Burn Notification => C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe [2009-07-09] (Acer) Task: {EF70E2A3-ECEE-4200-B9EC-029EFB9A6D83} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 5600-6600 Series\ezprint.exe [2010-02-04] (Lexmark International Inc.) Task: {F25783B2-2843-4A07-A384-80AD1BF7669B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2715126414-4153456669-2541334608-1000Core.job => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2715126414-4153456669-2541334608-1000UA.job => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-02-20 16:29 - 2009-05-14 07:24 - 00045568 _____ () C:\Windows\System32\LXDUPMON.DLL 2014-02-20 16:29 - 2010-02-04 05:40 - 00086016 _____ () C:\Windows\System32\LXDUOEM.DLL 2014-02-26 18:12 - 2009-10-16 12:07 - 00186880 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdudrpp.dll 2010-03-20 13:56 - 2013-08-13 20:01 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2011-03-23 19:59 - 2013-08-13 20:01 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2010-02-26 12:37 - 2009-08-19 20:49 - 01400320 _____ () C:\Windows\system32\lxdudrs64.dll 2010-02-26 12:37 - 2009-08-19 20:49 - 00025600 _____ () C:\Windows\system32\lxducaps64.dll 2010-02-26 12:37 - 2009-08-19 20:39 - 00054784 _____ () C:\Windows\system32\lxducnv464.dll 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2009-09-17 22:58 - 2009-08-11 04:51 - 00337920 _____ () C:\Windows\System32\OEM\RunCmd_X64.exe 2014-02-26 18:11 - 2010-02-04 06:10 - 00676520 _____ () C:\Program Files (x86)\Lexmark 5600-6600 Series\lxdumon.exe 2009-08-26 12:08 - 2009-08-26 13:31 - 00225280 _____ () c:\windows\system32\oem\setEvent.exe 2013-08-29 01:23 - 2013-08-29 01:23 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2014-02-26 18:11 - 2010-02-04 05:52 - 00380928 _____ () C:\Program Files (x86)\Lexmark 5600-6600 Series\lxduscw.dll 2014-02-26 18:11 - 2010-02-04 05:36 - 00188416 _____ () C:\Program Files (x86)\Lexmark 5600-6600 Series\lxdudatr.dll 2014-02-26 18:11 - 2010-02-04 05:52 - 01036288 _____ () C:\Program Files (x86)\Lexmark 5600-6600 Series\lxduDRS.dll 2014-02-26 18:11 - 2010-02-04 05:52 - 00081920 _____ () C:\Program Files (x86)\Lexmark 5600-6600 Series\lxducaps.dll 2014-02-26 18:11 - 2010-02-04 05:35 - 00069632 _____ () C:\Program Files (x86)\Lexmark 5600-6600 Series\lxducnv4.dll 2014-02-26 18:11 - 2010-02-04 05:51 - 00380928 _____ () C:\Program Files (x86)\Lexmark 5600-6600 Series\iptk.dll 2014-02-26 18:11 - 2007-09-06 06:11 - 00151552 _____ () C:\Program Files (x86)\Lexmark 5600-6600 Series\lxduptp.dll 2009-07-13 22:03 - 2009-07-14 02:15 - 00364544 _____ () C:\Windows\SysWOW64\msjetoledb40.dll 2010-09-24 17:06 - 2009-02-06 18:52 - 00073728 _____ () C:\Windows\SysWOW64\CmdRtr.DLL 2010-09-24 17:06 - 2009-03-26 14:46 - 00148480 _____ () C:\Windows\SysWOW64\APOMngr.DLL 2009-08-26 04:29 - 2009-08-26 04:29 - 00150016 _____ () C:\Windows\SysWOW64\OemSpiE.dll 2013-08-29 01:25 - 2013-08-29 01:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 13:16 - 2014-01-20 13:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-02-16 11:21 - 2014-02-16 11:21 - 03578992 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-02-21 10:03 - 2014-02-21 10:03 - 16265096 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:1D32EC29 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: AMD External Events Utility => 2 MSCONFIG\Services: Apple Mobile Device => 2 MSCONFIG\Services: avmike => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: certsrv => 2 MSCONFIG\Services: Creative Audio Engine Licensing Service => 3 MSCONFIG\Services: CTAudSvcService => 2 MSCONFIG\Services: FirebirdServerMAGIXInstance => 3 MSCONFIG\Services: FLEXnet Licensing Service => 3 MSCONFIG\Services: Futuremark SystemInfo Service => 3 MSCONFIG\Services: gfi_lanss9_attservice => 2 MSCONFIG\Services: GFI_ReportCenter35 => 2 MSCONFIG\Services: Greg_Service => 2 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: gusvc => 3 MSCONFIG\Services: IAANTMON => 2 MSCONFIG\Services: IGDCTRL => 2 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: Lavasoft Ad-Aware Service => 2 MSCONFIG\Services: lxdu_device => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: NAUpdate => 2 MSCONFIG\Services: Nero BackItUp Scheduler 4.0 => 3 MSCONFIG\Services: nwtsrv => 2 MSCONFIG\Services: RealNetworks Downloader Resolver Service => 2 MSCONFIG\Services: sesvc => 2 MSCONFIG\Services: Steam Client Service => 3 MSCONFIG\Services: SwitchBoard => 3 MSCONFIG\Services: TomTomHOMEService => 3 MSCONFIG\Services: TurboBoost => 3 MSCONFIG\Services: TVersityMediaServer => 2 MSCONFIG\Services: Updater Service => 2 MSCONFIG\Services: VMLiteService => 2 MSCONFIG\Services: WinTabService => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SmartCopy.lnk => C:\Windows\pss\SmartCopy.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SmartLauncher.lnk => C:\Windows\pss\SmartLauncher.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^UltraMon.lnk => C:\Windows\pss\UltraMon.lnk.CommonStartup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: AdobeCS4ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe" MSCONFIG\startupreg: ApnUpdater => "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: ArcadeDeluxeAgent => "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" MSCONFIG\startupreg: CloneCDTray => "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: DAEMON Tools Pro Agent => "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun MSCONFIG\startupreg: Device Detection => G:\Tools\Lidl_Fotos\dd.exe MSCONFIG\startupreg: EgisTecLiveUpdate => "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe" MSCONFIG\startupreg: emsisoft anti-malware => "C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe" /d=60 MSCONFIG\startupreg: Eraser => "C:\PROGRA~1\Eraser\Eraser.exe" --atRestart MSCONFIG\startupreg: Google Update => "C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: Hotkey Utility => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe MSCONFIG\startupreg: ISUSPM Startup => C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup MSCONFIG\startupreg: ISUSScheduler => "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start MSCONFIG\startupreg: MusicManager => "C:\Users\Admin\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" MSCONFIG\startupreg: mwlDaemon => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe MSCONFIG\startupreg: NortonOnlineBackupReminder => "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED MSCONFIG\startupreg: PlayMovie => "C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe" MSCONFIG\startupreg: ProfilerU => C:\Program Files\Saitek\SD6\Software\ProfilerU.exe MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun MSCONFIG\startupreg: Spotify => "C:\Users\Admin\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Admin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" MSCONFIG\startupreg: Steam => "D:\Games\steam.exe" -silent MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe MSCONFIG\startupreg: UnlockerAssistant => "C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe" MSCONFIG\startupreg: WinampAgent => "C:\Program Files (x86)\Winamp\winampa.exe" ==================== Faulty Device Manager Devices ============= Name: Standardtastatur (PS/2) Description: Standardtastatur (PS/2) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (03/01/2014 09:26:31 AM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (03/01/2014 08:52:47 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/26/2014 05:38:37 PM) (Source: Application Hang) (User: ) Description: Programm NOTEPAD.EXE, Version 6.1.7600.16385 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 4a4 Startzeit: 01cf331103966f08 Endzeit: 32 Anwendungspfad: C:\Windows\system32\NOTEPAD.EXE Berichts-ID: 6db78ce7-9f04-11e3-9c22-90fba62bc3cb Error: (02/26/2014 05:11:36 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (02/25/2014 05:31:39 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (02/24/2014 08:49:18 PM) (Source: Application Hang) (User: ) Description: Programm EVEMon.exe, Version 1.8.4.4125 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: fc8 Startzeit: 01cf3199652fae95 Endzeit: 16 Anwendungspfad: C:\Program Files (x86)\EVEMon\EVEMon.exe Berichts-ID: bc79766b-9d8c-11e3-bcc7-90fba62bc3cb Error: (02/24/2014 08:46:46 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (02/23/2014 07:34:46 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (02/23/2014 01:00:26 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/23/2014 10:27:35 AM) (Source: Application Hang) (User: ) Description: Programm webwatch.exe, Version 1.0.24.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 120c Startzeit: 01cf30796fcae71f Endzeit: 16 Anwendungspfad: C:\Program Files\FRITZ!DSL\webwatch.exe Berichts-ID: b3ad8937-9c6c-11e3-892d-90fba62bc3cb System errors: ============= Error: (03/01/2014 08:39:35 AM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: Lbd papycpu2 Error: (03/01/2014 08:38:43 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "lxduCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (03/01/2014 08:38:43 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxduCATSCustConnectService erreicht. Error: (03/01/2014 08:37:50 AM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\papycpu2.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (02/27/2014 06:09:55 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: Lbd papycpu2 Error: (02/27/2014 06:09:20 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "lxduCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (02/27/2014 06:09:20 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxduCATSCustConnectService erreicht. Error: (02/27/2014 06:08:08 PM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\papycpu2.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (02/26/2014 06:17:57 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "lxduCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (02/26/2014 06:17:57 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxduCATSCustConnectService erreicht. Microsoft Office Sessions: ========================= Error: (12/04/2010 07:32:51 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 28 seconds with 0 seconds of active time. This session ended with a crash. Error: (10/10/2010 04:07:29 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6535.5002, Microsoft Office Version: 12.0.6425.1000. This session lasted 560 seconds with 420 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-01-29 18:49:26.310 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-29 18:49:26.248 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-19 18:31:31.406 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume6\Windows\winsxs\wow64_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6002.18005_none_56eb524ed945a70c\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-19 18:31:31.288 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume6\Windows\winsxs\wow64_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6002.18005_none_56eb524ed945a70c\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-19 18:31:31.165 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume6\Windows\winsxs\wow64_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6002.18005_none_56eb524ed945a70c\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-16 22:29:18.949 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume6\Windows\winsxs\wow64_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_d6005436ad01f9a3\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-16 22:29:18.840 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume6\Windows\winsxs\wow64_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_d6005436ad01f9a3\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-16 22:29:18.731 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume6\Windows\winsxs\wow64_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_d6005436ad01f9a3\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-16 22:28:18.921 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume6\Windows\winsxs\wow64_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6002.18005_none_56eb524ed945a70c\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-16 22:28:18.811 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume6\Windows\winsxs\wow64_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6002.18005_none_56eb524ed945a70c\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 54% Total physical RAM: 4087.08 MB Available physical RAM: 1852.48 MB Total Pagefile: 8172.34 MB Available Pagefile: 4826.01 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:455.95 GB) (Free:116.74 GB) NTFS Drive d: (DATA) (Fixed) (Total:456.46 GB) (Free:243.3 GB) NTFS Drive f: (ACER) (Fixed) (Total:366.76 GB) (Free:195.97 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive g: (Volume) (Fixed) (Total:274.98 GB) (Free:234.68 GB) NTFS Drive h: (Games) (Fixed) (Total:275.12 GB) (Free:76.61 GB) NTFS Drive m: (SCANDISK) (Removable) (Total:7.44 GB) (Free:5 GB) FAT32 Drive p: (MS) (Removable) (Total:1.88 GB) (Free:0 GB) FAT Drive q: (Iomega HDD) (Fixed) (Total:596.17 GB) (Free:367.05 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 1226C5E7) Partition 1: (Not Active) - (Size=19 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=456 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=456 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 932 GB) (Disk ID: 7E8E1FA3) Partition 1: (Not Active) - (Size=15 GB) - (Type=27) Partition 2: (Active) - (Size=367 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=275 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=275 GB) - (Type=OF Extended) ======================================================== Disk: 2 (MBR Code: Windows XP) (Size: 596 GB) (Disk ID: CBD306F8) Partition: GPT Partition Type. ======================================================== Disk: 3 (Size: 7 GB) (Disk ID: 0013B6A1) Partition 1: (Not Active) - (Size=7 GB) - (Type=0B) ======================================================== Disk: 7 (Size: 2 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ Emsisoft hat beim ausführen des Programms gemeckert.. ? habe es dann aber zugelassen.. |
Themen zu Windows 7: Neue E-Mail Adresse erstellt und gleich Spoof Mail bekommen... Ebay rät Trojaner Check! |
brauche, browser, check, code, e-mail, ebay, erstellt, fake, falsch, fehler, fehlermeldung, keine rückmeldung, mails, neue, neustart, paypal, programm, rückmeldung, spiele, spielen, start, starten, suche, trojaner, windows, windows 7 |