janderman | 20.01.2014 13:27 | hallo und Danke! Hier die beiden log-dateien. Allerdings verbindet sich Firefox nicht mehr korrekt mit dem Netz. DuckDuckGo geht ganz langsam und zäh, google garnicht mehr. IE dagegen schon. Hat vll. was mit dem Java-Update zu tun, das ich vorher runtergeladen habe. Wenn ich außerdem Youtube-Videos anschaue, stoppt nach wie manchmal vor das Plugin und Firefox hängt für ca. eine 1/2 Minute.
OTL Logfile: Code:
OTL Extras logfile created on: 20.01.2014 13:09:27 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jan\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,94 Gb Total Physical Memory | 2,60 Gb Available Physical Memory | 66,17% Memory free
7,87 Gb Paging File | 6,09 Gb Available in Paging File | 77,41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 50,78 Gb Total Space | 2,79 Gb Free Space | 5,50% Space Free | Partition Type: NTFS
Drive D: | 68,36 Gb Total Space | 49,27 Gb Free Space | 72,08% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive G: | 3,73 Gb Total Space | 3,55 Gb Free Space | 95,10% Space Free | Partition Type: FAT32
Drive N: | 465,65 Gb Total Space | 385,91 Gb Free Space | 82,88% Space Free | Partition Type: FAT32
Computer Name: JAN-DELL | User Name: Jan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- D:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "D:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "d:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "d:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "D:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "D:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "d:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "d:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "D:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B0F82C7-C69C-4F64-9B66-85A69E14CE35}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{230EAA96-BB8A-464B-9780-CED79258E042}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{51223AA4-2A0D-4693-9BD1-C246E38CF96B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{68F42C8A-2542-4ECB-9CF0-6376C67A937E}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6C1961A3-257B-462F-B0FB-F13E492F2ABF}" = rport=10243 | protocol=6 | dir=out | app=system |
"{6C2167CB-B1BF-40D9-B9CD-BD73CE331003}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7841CED6-4ABB-45AA-BF22-7069652F1902}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{86FF26C7-3091-4591-AEB7-CB0AD916DEB7}" = lport=6004 | protocol=17 | dir=in | app=d:\program files (x86)\microsoft office\office12\outlook.exe |
"{8F050D59-D63C-47E4-94FA-609EEE6E477C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A226A35E-A37C-4C47-AF38-50A9821BE9B8}" = lport=10243 | protocol=6 | dir=in | app=system |
"{DA304FBD-7FFD-4CEB-AC2C-5D126777EA6F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{25FD692F-474D-4F58-81CB-1BDD10AE0709}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2CACBBB0-958B-4F6D-8298-64D4487BA77F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2D159253-5FB7-4F83-82CC-5E972B715F42}" = protocol=17 | dir=in | app=d:\program files (x86)\voipcheapcom\voipcheapcom.exe |
"{32EF9AA5-4C43-47AE-A2B5-DFFBD7D1DE39}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{41F9F877-D934-46ED-972E-536B47EBCDDD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{48C97AF7-FF54-4F82-B07F-EA8CD74E2D0F}" = protocol=17 | dir=in | app=c:\program files (x86)\sybase\sql anywhere 9\win32\dbsrv9.exe |
"{57CD38FF-3952-4C0F-B9C3-EA87A977DAF9}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{611EF8AF-5904-4722-BFEB-030FBC0D9531}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6AF61486-98AA-44D7-92AC-2AD1F967C4D1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{6EEFA939-A8BC-49D3-A6F6-13BB7E03EF96}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6EFB79AB-91B6-43AD-8DCB-1A99969E064E}" = protocol=6 | dir=out | app=system |
"{6F4F3120-DE14-4222-AD46-6C5578D90F06}" = dir=in | app=d:\program files (x86)\apowersoft\video converter studio\video converter studio.exe |
"{7207A22B-5233-4302-9C52-E76352A712AF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8844117C-C63F-4DB1-934C-65DA2EFE94EF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{908D7F3E-9C21-44FA-9F15-194748E5B113}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{91E1878B-E43F-4DFA-A29C-61F6E98B9CCA}" = protocol=6 | dir=in | app=c:\program files (x86)\sybase\sql anywhere 9\win32\dbsrv9.exe |
"{A2F39696-5D7B-4F38-9A36-CE74398231EB}" = protocol=6 | dir=in | app=d:\program files (x86)\voipcheapcom\voipcheapcom.exe |
"{BEE60F2C-AA7F-4371-868F-3302074307F0}" = dir=out | app=d:\program files (x86)\apowersoft\video converter studio\video converter studio.exe |
"{C520B71B-9D4B-4BCE-93E4-97AABA7D8464}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D6EA83EB-FD8F-4207-87FC-AEDDCCB16140}" = protocol=6 | dir=in | app=d:\program files (x86)\3cx assistant\tcx.assistant.client.exe |
"{E38A18D4-D14B-4A21-8289-1F35121E911F}" = protocol=17 | dir=in | app=d:\program files (x86)\3cx assistant\tcx.assistant.client.exe |
"{E7D3FC64-EE59-40BD-8B89-CA77BB95F162}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EF7D9D0F-0F6D-4460-98EA-04EE3C0F2218}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{0A6D6695-DEAD-45E5-B9C6-0F8AA56AED68}D:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=d:\program files (x86)\winamp\winamp.exe |
"TCP Query User{113DAE7D-C063-46C2-8681-1B3B8683D40E}D:\program files (x86)\phonerlite\phonerlite.exe" = protocol=6 | dir=in | app=d:\program files (x86)\phonerlite\phonerlite.exe |
"TCP Query User{15BE4A88-7628-48CB-A3B7-CBEA98F6A67D}D:\program files (x86)\3cx assistant\crm\3cx assistant crm.exe" = protocol=6 | dir=in | app=d:\program files (x86)\3cx assistant\crm\3cx assistant crm.exe |
"TCP Query User{3648D3E6-187F-405F-AA78-4DBEF653C89A}D:\program files (x86)\3cx assistant\crm\3cx assistant crm.exe" = protocol=6 | dir=in | app=d:\program files (x86)\3cx assistant\crm\3cx assistant crm.exe |
"TCP Query User{372CDD52-5CF4-45E5-9C17-44E255AD6BEA}D:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=d:\program files (x86)\winamp\winamp.exe |
"TCP Query User{5CE8FD73-C737-49AD-9FD7-54DBADDC54EE}D:\program files (x86)\microsoft office\office12\outlook.exe" = protocol=6 | dir=in | app=d:\program files (x86)\microsoft office\office12\outlook.exe |
"TCP Query User{61373FF2-30C3-4F03-9463-554C3CDFD7B0}D:\program files (x86)\voipcheapcom\voipcheapcom.exe" = protocol=6 | dir=in | app=d:\program files (x86)\voipcheapcom\voipcheapcom.exe |
"TCP Query User{644866F9-2264-4451-A9F3-F0413D7B54EB}D:\program files (x86)\3cx assistant\3cxphone.exe" = protocol=6 | dir=in | app=d:\program files (x86)\3cx assistant\3cxphone.exe |
"TCP Query User{B29DE417-14DD-4709-A5E7-75CAEBD5AFBD}C:\users\jan\appdata\local\thinstall\cache\stubs\5a7088e26595d67a19d0cab498e66a24f88a6cba\wswc.exe" = protocol=6 | dir=in | app=c:\users\jan\appdata\local\thinstall\cache\stubs\5a7088e26595d67a19d0cab498e66a24f88a6cba\wswc.exe |
"TCP Query User{BA6A620C-02B1-49B1-83CE-8CD9DB9F9FF6}D:\program files (x86)\java systems\bin\java.exe" = protocol=6 | dir=in | app=d:\program files (x86)\java systems\bin\java.exe |
"TCP Query User{C667FD74-514A-4E50-91D2-68CA9739EED1}D:\program files (x86)\3cx assistant\3cxphone.exe" = protocol=6 | dir=in | app=d:\program files (x86)\3cx assistant\3cxphone.exe |
"UDP Query User{17336AE4-BF92-470A-8DAF-A1D3E43519F1}D:\program files (x86)\voipcheapcom\voipcheapcom.exe" = protocol=17 | dir=in | app=d:\program files (x86)\voipcheapcom\voipcheapcom.exe |
"UDP Query User{188F2E16-3D17-478F-AE41-E9734C860350}D:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=d:\program files (x86)\winamp\winamp.exe |
"UDP Query User{3466B1AA-DCEC-41B6-9929-6878865256C8}D:\program files (x86)\java systems\bin\java.exe" = protocol=17 | dir=in | app=d:\program files (x86)\java systems\bin\java.exe |
"UDP Query User{34D28EBF-EA3D-4ED6-BCB3-863D1DFC1D9E}C:\users\jan\appdata\local\thinstall\cache\stubs\5a7088e26595d67a19d0cab498e66a24f88a6cba\wswc.exe" = protocol=17 | dir=in | app=c:\users\jan\appdata\local\thinstall\cache\stubs\5a7088e26595d67a19d0cab498e66a24f88a6cba\wswc.exe |
"UDP Query User{3695AB65-468D-41CF-A453-F58BAB154EF8}D:\program files (x86)\phonerlite\phonerlite.exe" = protocol=17 | dir=in | app=d:\program files (x86)\phonerlite\phonerlite.exe |
"UDP Query User{75E9348B-77A7-4CAC-B50A-144BE5CEDF64}D:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=d:\program files (x86)\winamp\winamp.exe |
"UDP Query User{B2F08A0F-41E0-4473-89DB-264F9E6693FA}D:\program files (x86)\3cx assistant\3cxphone.exe" = protocol=17 | dir=in | app=d:\program files (x86)\3cx assistant\3cxphone.exe |
"UDP Query User{E2927027-ABA4-47FD-9DC0-0623D2923F69}D:\program files (x86)\microsoft office\office12\outlook.exe" = protocol=17 | dir=in | app=d:\program files (x86)\microsoft office\office12\outlook.exe |
"UDP Query User{FAC80BFC-603A-41DD-9DF8-0BA7EF492F0B}D:\program files (x86)\3cx assistant\crm\3cx assistant crm.exe" = protocol=17 | dir=in | app=d:\program files (x86)\3cx assistant\crm\3cx assistant crm.exe |
"UDP Query User{FBB884CE-E98B-4F6E-8A6D-442CD6BD6D53}D:\program files (x86)\3cx assistant\crm\3cx assistant crm.exe" = protocol=17 | dir=in | app=d:\program files (x86)\3cx assistant\crm\3cx assistant crm.exe |
"UDP Query User{FDA54CFC-DB7C-40B9-937F-4DB546BAA052}D:\program files (x86)\3cx assistant\3cxphone.exe" = protocol=17 | dir=in | app=d:\program files (x86)\3cx assistant\3cxphone.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{26A24AE4-039D-4CA4-87B4-2F86416013FF}" = Java(TM) 6 Update 13 (64-bit)
"{4756C731-B54E-451A-9AF1-86E8AB1BEBBB}" = Nitro Reader 3
"{54D5AEEB-EBD9-4C0D-930D-98712597320C}" = 3CX Assistant
"{7AB6F8D7-7804-4662-BE8C-1AFCCD602D9F}" = Microsoft-Maus- und Tastatur-Center
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"Kyocera Product Library" = Kyocera Product Library
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Microsoft Mouse and Keyboard Center" = Microsoft-Maus- und Tastatur-Center
"WinRAR archiver" = WinRAR 4.00 beta 3 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01011662-76A8-41E8-B1A8-4F8821570AC5}" = Advanced Archive Password Recovery
"{0138F525-6C8A-333F-A105-14AE030B9A54}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{0197D136-598D-4968-BEEA-91C1B764F05D}" = Lexware buchhalter 2012
"{0F32914F-A633-4516-B531-7084C8F19F93}" = Haufe iDesk-Browser
"{1923679F-C14B-4790-BC54-EFA3FCDE147B}" = Lexware Elster
"{1D081AB0-B1CC-11E0-80C0-005056B12123}" = Haufe iDesk-Service
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 51
"{37BC8FCE-15B1-456E-A62C-EEB175B71340}" = Lexware reisekosten plus 2011
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50FC30FE-9758-3B08-B886-7BAABC047B61}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{786C5747-0C40-4930-9AFE-113BCE553101}" = Adobe Stock Photos 1.0
"{7F4C8163-F259-49A0-A018-2857A90578BC}" = Adobe InDesign CS2
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 6.2.0
"{89196F9A-2E0B-4197-A3DF-6EF78731EB35}" = Lexware online banking
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8EDBA74D-0686-4C99-BFDD-F894678E5101}" = Adobe Common File Installer
"{90120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{90120000-0014-0000-0000-0000000FF1CE}_PRO_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PRO_{A0516415-ED61-419A-981D-93596DA74165}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_PRO_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_PRO_{E64BA721-2310-4B55-BE5A-2925F9706192}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0407-1000-0000000FF1CE}_PRO_{26454C26-D259-4543-AA60-3189E09C5F76}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_PRO_{26454C26-D259-4543-AA60-3189E09C5F76}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) - Deutsch
"{B74D4E10-6884-0000-0000-000000000101}" = Adobe Bridge 1.0
"{C1C50448-C067-454A-80B2-334ECAC8F414}" = Lexware Admintools Plus
"{D34A78EB-78F2-48ab-8CAE-5D4DC255A491}" = Lexware reisekosten plus 2011
"{DAF15921-FA90-4427-82A2-1852A9BAC99A}" = Lexware Datenbank plus 2011
"{DF344785-0900-471E-B9F5-6F28C89AF638}" = TAXMAN Bibliothek 2012
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E9787678-119F-4D52-B551-6739B2B22101}" = Adobe Help Center 1.0
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F3C2ECAA-1B4D-4B75-9105-106B0D03EF02}" = Lexware Info Service
"{FA3FDB06-3368-4579-B2F2-5AE8AD6E7871}" = TAXMAN 2012
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe InDesign CS2 - {7F4C8163-F259-49A0-A018-2857A90578BC}" = Adobe InDesign CS2
"AntragsManager_is1" = AntragsManager
"Avira AntiVir Desktop" = Avira Internet Security
"Die Macht der Selbstbeherrschung_is1" = Die Macht der Selbstbeherrschung
"Die Macht des Steuerzahlers_is1" = Die Macht des Steuerzahlers
"Free YouTube Download_is1" = Free YouTube Download version 3.2.10.812
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mozilla Firefox 22.0 (x86 de)" = Mozilla Firefox 22.0 (x86 de)
"Mozilla Thunderbird 24.2.0 (x86 de)" = Mozilla Thunderbird 24.2.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"PhonerLite_is1" = PhonerLite 1.95
"PRO" = Microsoft Office Professional 2007
"SumatraPDF" = SumatraPDF
"Vermieter_EH" = Vermieter-Ratgeber
"VirtualKeyboard" = Virtual Keyboard 4.0.1
"VLC media player" = VLC media player 1.1.5
"Weiße Weste durch Umzug_is1" = Weiße Weste durch Umzug
"Winamp" = Winamp
"xp-AntiSpy" = xp-AntiSpy 3.98-2
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{46B70DEB-97B3-4E38-B746-EC16905E6A8F}" = WISO Sparbuch 2010
"{BAA9D87C-DA6A-48D0-BC07-135E5B2DE5A2}" = WISO Hausverwalter 2013
"Mozilla Firefox 26.0 (x86 de)" = Mozilla Firefox 26.0 (x86 de)
"Winamp Detect" = Winamp Erkennungs-Plug-in
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 18.01.2014 09:03:14 | Computer Name = Jan-Dell | Source = Microsoft-Windows-User Profiles Service | ID = 1511
Description = Das lokale Benutzerprofil wurde nicht gefunden. Sie werden mit einem
temporären Benutzerprofil angemeldet. Änderungen, die Sie am Benutzerprofil vornehmen,
gehen bei der Abmeldung verloren.
Error - 18.01.2014 09:03:14 | Computer Name = Jan-Dell | Source = Microsoft-Windows-User Profiles Service | ID = 1500
Description = Sie konnten nicht angemeldet werden, da das lokal gespeicherte Profil
nicht geladen werden konnte. Überprüfen Sie, ob eine Netzwerkverbindung besteht
und das Netzwerk ordnungsgemäß funktioniert. Details - Nur ein Teil der ReadProcessMemory-
oder WriteProcessMemory-Anforderung wurde abgeschlossen.
Error - 18.01.2014 20:35:56 | Computer Name = Jan-Dell | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: firefox.exe, Version: 26.0.0.5087,
Zeitstempel: 0x52a0d273 Name des fehlerhaften Moduls: xul.dll, Version: 26.0.0.5087,
Zeitstempel: 0x52a0d20a Ausnahmecode: 0xc0000005 Fehleroffset: 0x0014e1a8 ID des fehlerhaften
Prozesses: 0x1324 Startzeit der fehlerhaften Anwendung: 0x01cf145d4bafde98 Pfad der
fehlerhaften Anwendung: D:\Program Files (x86)\Mozilla Firefox\firefox.exe Pfad
des fehlerhaften Moduls: D:\Program Files (x86)\Mozilla Firefox\xul.dll Berichtskennung:
a83c9707-80a1-11e3-bfda-0019d12a83a4
Error - 19.01.2014 05:54:21 | Computer Name = Jan-Dell | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "D:\Downloads\esetsmartinstaller_enu.exe".
Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche
Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In
Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error - 19.01.2014 08:31:04 | Computer Name = Jan-Dell | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "D:\Downloads\esetsmartinstaller_enu.exe".
Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche
Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In
Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error - 19.01.2014 10:50:36 | Computer Name = Jan-Dell | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files
(x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion
steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt
stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error - 19.01.2014 14:23:30 | Computer Name = Jan-Dell | Source = SideBySide | ID = 16842824
Description = Fehler beim Generieren des Aktivierungskontextes für "D:\Program Files
(x86)\3CX Assistant\CRM\3CX Assistant Microsoft Outlook Addin\3CX Assistant Microsoft
Outlook Addin.dll.Manifest". Fehler in Manifest- oder Richtliniendatei "D:\Program
Files (x86)\3CX Assistant\CRM\3CX Assistant Microsoft Outlook Addin\3CX Assistant
Microsoft Outlook Addin.dll.Manifest" in Zeile 4. Das asmv2:clrClassInvocation-Element
wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements
angezeigt, das von dieser Windows-Version nicht unterstützt wird.
Error - 20.01.2014 08:08:26 | Computer Name = Jan-Dell | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.69.0 kann nicht mehr unter Windows ausgeführt
werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: e44 Startzeit:
01cf15d7f01165c3 Endzeit: 16 Anwendungspfad: C:\Users\Jan\Desktop\OTL.exe Berichts-ID:
[ OSession Events ]
Error - 01.07.2013 03:34:42 | Computer Name = Jan-Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1996
seconds with 0 seconds of active time. This session ended with a crash.
Error - 07.07.2013 06:19:14 | Computer Name = Jan-Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7520
seconds with 180 seconds of active time. This session ended with a crash.
Error - 22.08.2013 10:04:15 | Computer Name = Jan-Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 18990
seconds with 1440 seconds of active time. This session ended with a crash.
Error - 15.09.2013 16:45:28 | Computer Name = Jan-Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4
seconds with 0 seconds of active time. This session ended with a crash.
Error - 22.09.2013 07:34:11 | Computer Name = Jan-Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 101
seconds with 0 seconds of active time. This session ended with a crash.
Error - 14.10.2013 08:54:01 | Computer Name = Jan-Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 20834
seconds with 360 seconds of active time. This session ended with a crash.
Error - 18.10.2013 08:59:01 | Computer Name = Jan-Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8371
seconds with 120 seconds of active time. This session ended with a crash.
Error - 22.10.2013 17:54:33 | Computer Name = Jan-Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 49925
seconds with 180 seconds of active time. This session ended with a crash.
Error - 24.10.2013 15:09:57 | Computer Name = Jan-Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 39672
seconds with 420 seconds of active time. This session ended with a crash.
Error - 15.01.2014 18:27:43 | Computer Name = Jan-Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 49748
seconds with 4680 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 18.01.2014 09:02:59 | Computer Name = Jan-Dell | Source = DCOM | ID = 10010
Description =
Error - 19.01.2014 06:41:10 | Computer Name = Jan-Dell | Source = Service Control Manager | ID = 7031
Description = Der Dienst "Avira Browser-Schutz" wurde unerwartet beendet. Dies ist
bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
Error - 19.01.2014 06:55:54 | Computer Name = Jan-Dell | Source = Service Control Manager | ID = 7031
Description = Der Dienst "Avira Browser-Schutz" wurde unerwartet beendet. Dies ist
bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
Error - 19.01.2014 18:11:42 | Computer Name = Jan-Dell | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
< End of report > --- --- --- OTL Logfile: Code:
OTL logfile created on: 20.01.2014 13:09:27 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jan\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,94 Gb Total Physical Memory | 2,60 Gb Available Physical Memory | 66,17% Memory free
7,87 Gb Paging File | 6,09 Gb Available in Paging File | 77,41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 50,78 Gb Total Space | 2,79 Gb Free Space | 5,50% Space Free | Partition Type: NTFS
Drive D: | 68,36 Gb Total Space | 49,27 Gb Free Space | 72,08% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive G: | 3,73 Gb Total Space | 3,55 Gb Free Space | 95,10% Space Free | Partition Type: FAT32
Drive N: | 465,65 Gb Total Space | 385,91 Gb Free Space | 82,88% Space Free | Partition Type: FAT32
Computer Name: JAN-DELL | User Name: Jan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Jan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - D:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - D:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - D:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
PRC - D:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
PRC - D:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - D:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe (Avira Operations GmbH & Co. KG)
PRC - D:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
PRC - D:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Lexware\LxWebAccess\LxWebAccess.exe (Lexware GmbH & Co. KG)
PRC - C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG)
PRC - D:\Program Files (x86)\3CX Assistant\tcx.assistant.client.exe (3CX Ltd)
PRC - D:\Program Files (x86)\3CX Assistant\CRM\3CX Assistant CRM.exe (3CX Ltd)
PRC - C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe (iAnywhere Solutions, Inc.)
PRC - D:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation)
PRC - D:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\6ebbfafc5521934f7e1c154937a2788b\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\d473c19e69818875b9c739cad8f386a5\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ef0a534be135cd8f0d99d938d8b1814a\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\08d05898be584065b797a6dd48d9ad56\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\71d887ce964fb69b7f03c4fe7a3f28ff\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\e40d894a772b2cff5ffd5a84ef20d2d4\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\9de08286f7db6f78a1505f51d8342ef6\Microsoft.VisualStudio.Tools.Applications.Runtime.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9a1bc983c28c695729b3e46acdc6933e\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\09db78d6068543df01862a023aca785a\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\3a3fc0216674bdea0be809b305517c98\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\884bcbd22130ebeb1211bc7bcc3910c9\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\de853615c8224ba5d9aa9b76276c6d98\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\c9786062fbb311c543497e28c1e1a0c5\CustomMarshalers.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\de6ee26de5e4f343509de7e92ab48ba6\CustomMarshalers.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\cf58670896c5313b9b52f026f4455a5d\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Microsoft.Office.Tools.Common\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Common.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Microsoft.Office.Tools.Outlook\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Outlook.dll ()
MOD - C:\Windows\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\office.dll ()
MOD - C:\Windows\assembly\GAC\Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll ()
MOD - D:\Program Files (x86)\3CX Assistant\3CXTAPIClient.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll ()
MOD - C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll ()
MOD - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ()
MOD - D:\Program Files (x86)\Microsoft Office\Office12\ADDINS\ColleagueImport.dll ()
MOD - D:\Program Files (x86)\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- D:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- D:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirMailService) -- D:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirFirewallService) -- D:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AntiVirService) -- D:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (NitroReaderDriverReadSpool3) -- C:\Programme\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe (Nitro PDF Software)
SRV - (MBAMService) -- d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (Lexware_Datenbank_Plus) -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe (iAnywhere Solutions, Inc.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avfwot) -- C:\Windows\SysNative\drivers\avfwot.sys (Avira GmbH)
DRV:64bit: - (avfwim) -- C:\Windows\SysNative\drivers\avfwim.sys (Avira GmbH)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (e1express) -- C:\Windows\SysNative\drivers\e1e6232e.sys (Intel Corporation)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://d8n4mx4j/argoweb/aaf001web/Login.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E2 F4 D1 61 5D 05 CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaulturl: "hxxp://www.google.de/search?hl=de&gl=de&lr=&ie=UTF-8&oe=UTF-8&meta=lr=lang_de&q="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://duckduckgo.com/"
FF - prefs.js..extensions.enabledAddons: i18nsideboard%40fxparlant.net:3.0
FF - prefs.js..extensions.enabledAddons: stealthyextension%40gmail.com:2.5
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.21
FF - prefs.js..extensions.enabledAddons: %7Bdd3d7613-0246-469d-bc65-2a3cc1668adc%7D:1.1.8
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.8.12
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0
FF - prefs.js..keyword.URL: "hxxp://www.google.de/search?hl=de&gl=de&lr=&ie=UTF-8&oe=UTF-8&meta=lr=lang_de&q="
FF - prefs.js..network.proxy.ftp: "193.254.236.205"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.http: "193.254.236.205"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.no_proxies_on: "localhost, 127.0.0.1, stealthy.co"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "193.254.236.205"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "193.254.236.205"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: D:\Program Files (x86)\Java Systems\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: D:\Program Files (x86)\Java Systems\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.51204.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: D:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: D:\Program Files (x86)\Mozilla Firefox\plugins [2014.01.16 20:00:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.2.0\extensions\\Components: d:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.2.0\extensions\\Plugins: d:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 26.0\extensions\\Components: D:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 26.0\extensions\\Plugins: D:\Program Files (x86)\Mozilla Firefox\plugins [2014.01.16 20:00:16 | 000,000,000 | ---D | M]
[2014.01.15 14:11:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jan\AppData\Roaming\mozilla\Extensions
[2014.01.15 14:11:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jan\AppData\Roaming\mozilla\Extensions\ideskbrowser@haufe.de
[2014.01.17 12:39:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jan\AppData\Roaming\mozilla\Firefox\Profiles\dj1uindl.default\extensions
[2013.11.13 11:08:31 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Jan\AppData\Roaming\mozilla\Firefox\Profiles\dj1uindl.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2013.08.10 11:52:52 | 000,000,000 | ---D | M] (Block site) -- C:\Users\Jan\AppData\Roaming\mozilla\Firefox\Profiles\dj1uindl.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
[2013.07.18 12:27:43 | 000,000,000 | ---D | M] (International Sideboard) -- C:\Users\Jan\AppData\Roaming\mozilla\Firefox\Profiles\dj1uindl.default\extensions\i18nsideboard@fxparlant.net
[2013.11.14 16:31:07 | 000,185,839 | ---- | M] () (No name found) -- C:\Users\Jan\AppData\Roaming\mozilla\firefox\profiles\dj1uindl.default\extensions\stealthyextension@gmail.com.xpi
[2014.01.15 13:59:26 | 000,536,648 | ---- | M] () (No name found) -- C:\Users\Jan\AppData\Roaming\mozilla\firefox\profiles\dj1uindl.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2014.01.17 12:39:25 | 000,940,775 | ---- | M] () (No name found) -- C:\Users\Jan\AppData\Roaming\mozilla\firefox\profiles\dj1uindl.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.12.23 09:45:30 | 000,001,981 | ---- | M] () -- C:\Users\Jan\AppData\Roaming\mozilla\firefox\profiles\dj1uindl.default\searchplugins\dictcc.xml
[2014.01.20 12:17:45 | 000,010,316 | ---- | M] () -- C:\Users\Jan\AppData\Roaming\mozilla\firefox\profiles\dj1uindl.default\searchplugins\duckduckgo.xml
[2014.01.07 12:13:35 | 000,003,623 | ---- | M] () -- C:\Users\Jan\AppData\Roaming\mozilla\firefox\profiles\dj1uindl.default\searchplugins\Google.xml
[2014.01.19 10:47:28 | 000,001,839 | ---- | M] () -- C:\Users\Jan\AppData\Roaming\mozilla\firefox\profiles\dj1uindl.default\searchplugins\ixquick-https---deutsch.xml
[2013.12.23 09:44:27 | 000,002,080 | ---- | M] () -- C:\Users\Jan\AppData\Roaming\mozilla\firefox\profiles\dj1uindl.default\searchplugins\metapedia-de.xml
[2013.12.23 09:44:58 | 000,000,983 | ---- | M] () -- C:\Users\Jan\AppData\Roaming\mozilla\firefox\profiles\dj1uindl.default\searchplugins\wortschatz-deutsch.xml
O1 HOSTS File: ([2014.01.17 22:17:05 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\Java Systems\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files (x86)\Java Systems\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [avgnt] D:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [LexwareInfoService] C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG)
O4 - HKLM..\Run: [PDFPrint] d:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
O4 - Startup: C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - D:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - D:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java-Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000019 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - D:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: argoserver ([]https in Vertrauenswürdige Sites)
O15 - HKCU\..Trusted Domains: d8n4mx4j ([]http in Vertrauenswürdige Sites)
O15 - HKCU\..Trusted Domains: d8n4mx4j ([]https in Vertrauenswürdige Sites)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{63D26AE7-4F39-40B0-B427-CE9528B32860}: NameServer = 8.8.8.8,192.168.3.12
O18:64bit: - Protocol\Handler\haufereader - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\haufereader - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014.01.20 13:08:33 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2014.01.20 13:08:27 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2014.01.20 13:08:27 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2014.01.20 13:08:27 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2014.01.20 13:05:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Jan\Desktop\OTL.exe
[2014.01.19 18:58:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
[2014.01.18 13:51:33 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\Andrej_Koch
[2014.01.18 13:51:23 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Virtual Keyboard
[2014.01.18 13:51:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual Keyboard
[2014.01.18 12:03:08 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014.01.18 11:52:02 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014.01.17 22:18:47 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014.01.17 22:03:59 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2014.01.17 22:03:59 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2014.01.17 22:03:59 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2014.01.17 22:03:54 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014.01.17 22:03:46 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2014.01.16 23:37:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2014.01.16 19:07:32 | 000,000,000 | ---D | C] -- C:\FRST
[2014.01.16 15:30:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Die Macht des Steuerzahlers
[2014.01.15 14:13:58 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\Netviewer
[2014.01.15 14:11:40 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Haufe Mediengruppe
[2014.01.15 14:11:40 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\Haufe Mediengruppe
[2014.01.15 14:00:43 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Lexware
[2014.01.15 14:00:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lexware
[2014.01.15 14:00:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DataDesign
[2014.01.15 13:58:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sybase
[2014.01.15 13:58:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft WSE
[2014.01.15 13:54:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Haufe
[2014.01.15 13:52:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lexware
[2014.01.15 13:45:55 | 000,000,000 | ---D | C] -- C:\ProgramData\lexware
[2014.01.15 13:45:49 | 001,929,216 | ---- | C] (Amyuni Technologies
Amyuni | Quality PDF Developer Tools for .NET, Silverlight, 64-bit SDK, Citrix Ready) -- C:\Windows\SysWow64\cdintf250.dll
[2014.01.15 13:45:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Haufe
[2014.01.15 13:45:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Haufe
[2014.01.15 13:45:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2014.01.15 13:45:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2014.01.15 13:44:49 | 000,455,680 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deploytk.dll
[2014.01.15 13:44:49 | 000,181,760 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe
[2014.01.15 13:44:49 | 000,165,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe
[2014.01.15 13:44:49 | 000,165,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe
[2014.01.15 13:44:43 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2014.01.15 13:44:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2014.01.15 13:42:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Lexware
[2014.01.15 13:42:01 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\Lexware
[2014.01.15 13:35:03 | 000,000,000 | ---D | C] -- C:\Users\Jan\Documents\Amazon Downloader Logs
[2014.01.15 08:07:16 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys
[2014.01.15 08:07:16 | 000,007,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbd.sys
[2014.01.09 18:05:59 | 000,000,000 | ---D | C] -- C:\Users\Jan\Documents\Steuer-Sparbuch
[2014.01.07 12:21:53 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Nitro
[2014.01.07 12:21:53 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\FileOpen
[2014.01.07 12:21:53 | 000,000,000 | ---D | C] -- C:\ProgramData\FileOpen
[2014.01.07 12:21:39 | 000,029,712 | ---- | C] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalmon2.dll
[2014.01.07 12:21:39 | 000,017,936 | ---- | C] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalui2.dll
[2014.01.07 12:21:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Nitro
[2014.01.07 12:21:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nitro
[2014.01.07 12:21:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nitro
[2014.01.07 12:21:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nitro
[2014.01.07 12:21:12 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Downloaded Installations
[2014.01.07 12:11:09 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\Google
[2014.01.07 11:32:30 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\PhonerLite
[2014.01.05 15:47:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Weiße Weste durch Umzug
[2014.01.03 23:48:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
========== Files - Modified Within 30 Days ==========
[2014.01.20 13:05:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Jan\Desktop\OTL.exe
[2014.01.20 13:00:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.01.20 08:45:51 | 000,015,040 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.01.20 08:45:51 | 000,015,040 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.01.20 08:42:45 | 001,613,340 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014.01.20 08:42:45 | 000,696,832 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2014.01.20 08:42:45 | 000,652,150 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014.01.20 08:42:45 | 000,148,128 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2014.01.20 08:42:45 | 000,121,082 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014.01.20 08:37:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.01.20 08:37:53 | 3169,259,520 | -HS- | M] () -- C:\hiberfil.sys
[2014.01.19 18:58:38 | 000,000,774 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk
[2014.01.19 18:58:37 | 000,000,786 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Creator.lnk
[2014.01.18 13:51:23 | 000,000,771 | ---- | M] () -- C:\Users\Jan\Desktop\Virtual Keyboard.lnk
[2014.01.17 22:17:05 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2014.01.17 20:29:22 | 000,002,222 | -H-- | M] () -- C:\Users\Jan\Documents\Default.rdp
[2014.01.17 20:19:36 | 000,155,070 | ---- | M] () -- C:\Users\Jan\Desktop\shopping-ecco-store-zuerich-limmatquai.jpg
[2014.01.17 17:01:08 | 001,444,399 | ---- | M] () -- C:\Users\Jan\Desktop\Standortsuche Street One 2013.pdf
[2014.01.16 15:30:23 | 000,001,361 | ---- | M] () -- C:\Users\Public\Desktop\Die Macht des Steuerzahlers.lnk
[2014.01.16 08:20:49 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2012.lnk
[2014.01.16 08:07:07 | 000,552,792 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014.01.15 16:00:25 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014.01.15 16:00:25 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014.01.15 13:59:36 | 000,000,153 | ---- | M] () -- C:\Windows\ODBC.INI
[2014.01.15 13:54:59 | 000,002,319 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
[2014.01.15 13:44:44 | 000,455,680 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deploytk.dll
[2014.01.15 13:44:44 | 000,181,760 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe
[2014.01.15 13:44:44 | 000,165,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe
[2014.01.15 13:44:44 | 000,165,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe
[2014.01.09 17:14:58 | 000,000,981 | ---- | M] () -- C:\Windows\wiso.ini
[2014.01.07 12:21:38 | 000,002,003 | ---- | M] () -- C:\Users\Public\Desktop\Nitro Reader.lnk
[2014.01.07 12:12:05 | 000,118,784 | ---- | M] () -- C:\Windows\SysNative\dmusic64.exe
[2014.01.07 11:32:30 | 000,000,028 | ---- | M] () -- C:\Users\Jan\AppData\Roaming\PhonerLitesettings.ini
[2014.01.05 15:47:34 | 000,001,447 | ---- | M] () -- C:\Users\Public\Desktop\Weiße Weste durch Umzug.lnk
[2014.01.03 23:50:02 | 000,001,204 | ---- | M] () -- C:\Users\Jan\Documents\cc_20140103_234954.reg
[2014.01.03 12:41:04 | 000,027,417 | ---- | M] () -- C:\Users\Jan\Desktop\Unbenannt.JPG
[2014.01.02 13:40:20 | 000,123,019 | ---- | M] () -- C:\Users\Jan\Desktop\LC Waikiki- Doch keine Deutschlandsexpansion- « fabeau.pdf
========== Files Created - No Company Name ==========
[2014.01.19 18:58:38 | 000,000,774 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk
[2014.01.19 18:58:37 | 000,000,786 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Creator.lnk
[2014.01.18 13:51:23 | 000,000,771 | ---- | C] () -- C:\Users\Jan\Desktop\Virtual Keyboard.lnk
[2014.01.17 22:03:59 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2014.01.17 22:03:59 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2014.01.17 22:03:59 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2014.01.17 22:03:59 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2014.01.17 22:03:59 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2014.01.17 20:19:36 | 000,155,070 | ---- | C] () -- C:\Users\Jan\Desktop\shopping-ecco-store-zuerich-limmatquai.jpg
[2014.01.17 17:01:04 | 001,444,399 | ---- | C] () -- C:\Users\Jan\Desktop\Standortsuche Street One 2013.pdf
[2014.01.16 15:30:23 | 000,001,361 | ---- | C] () -- C:\Users\Public\Desktop\Die Macht des Steuerzahlers.lnk
[2014.01.15 13:59:36 | 000,000,153 | ---- | C] () -- C:\Windows\ODBC.INI
[2014.01.15 13:54:59 | 000,002,319 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
[2014.01.15 13:52:37 | 000,002,669 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN 2012.lnk
[2014.01.07 12:21:38 | 000,002,499 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Reader 3.lnk
[2014.01.07 12:21:38 | 000,002,003 | ---- | C] () -- C:\Users\Public\Desktop\Nitro Reader.lnk
[2014.01.07 12:12:05 | 000,118,784 | ---- | C] () -- C:\Windows\SysNative\dmusic64.exe
[2014.01.07 11:32:30 | 000,000,028 | ---- | C] () -- C:\Users\Jan\AppData\Roaming\PhonerLitesettings.ini
[2014.01.05 15:47:34 | 000,001,447 | ---- | C] () -- C:\Users\Public\Desktop\Weiße Weste durch Umzug.lnk
[2014.01.03 23:49:56 | 000,001,204 | ---- | C] () -- C:\Users\Jan\Documents\cc_20140103_234954.reg
[2014.01.02 13:40:26 | 000,123,019 | ---- | C] () -- C:\Users\Jan\Desktop\LC Waikiki- Doch keine Deutschlandsexpansion- « fabeau.pdf
[2013.06.17 18:13:26 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013.06.17 18:12:17 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.06.17 18:12:17 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.06.17 18:12:17 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2013.06.11 14:34:10 | 000,805,537 | ---- | C] () -- C:\Users\Jan\AppData\Local\census.cache
[2013.06.11 14:33:56 | 000,097,923 | ---- | C] () -- C:\Users\Jan\AppData\Local\ars.cache
[2013.06.11 13:57:22 | 000,000,036 | ---- | C] () -- C:\Users\Jan\AppData\Local\housecall.guid.cache
[2013.03.12 11:55:46 | 000,000,981 | ---- | C] () -- C:\Windows\wiso.ini
[2013.02.07 18:50:20 | 001,590,298 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.02.07 18:16:40 | 000,007,593 | ---- | C] () -- C:\Users\Jan\AppData\Local\Resmon.ResmonCfg
[2012.02.27 09:41:52 | 000,202,240 | ---- | C] () -- C:\Windows\SysWow64\LXPrnUtil10.dll
[2012.02.27 09:40:44 | 000,304,128 | ---- | C] () -- C:\Windows\SysWow64\LxDNT100.dll
[2012.02.27 09:38:36 | 000,133,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvmc100.dll
[2012.02.27 09:38:18 | 000,069,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvm100.dll
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.07.26 03:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Files - Unicode (All) ==========
[2013.10.17 06:37:27 | 101,413,064 | ---- | M] ()(C:\Windows\SysWow64\????) -- C:\Windows\SysWow64\瑺‹
[2013.10.17 06:37:27 | 101,413,064 | ---- | C] ()(C:\Windows\SysWow64\????) -- C:\Windows\SysWow64\瑺‹
< End of report > --- --- --- |