OTL Code:
OTL logfile created on: 26.06.2014 00:06:26 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Krissi\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,99 Gb Total Physical Memory | 1,35 Gb Available Physical Memory | 45,17% Memory free
6,21 Gb Paging File | 4,51 Gb Available in Paging File | 72,63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144,09 Gb Total Space | 50,15 Gb Free Space | 34,81% Space Free | Partition Type: NTFS
Drive D: | 144,00 Gb Total Space | 131,52 Gb Free Space | 91,33% Space Free | Partition Type: NTFS
Computer Name: KRISSI-PC | User Name: Krissi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Krissi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avnotify.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil32_13_0_0_214_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:\Programme\WEB.DE MailCheck\IE\WEB.DE_MailCheck_Broker.exe (1und1 Mail und Media GmbH)
PRC - C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Programme\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation)
PRC - C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\System32\ieconfig_1und1_svc.exe ()
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
PRC - c:\Programme\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Programme\Common Files\McAfee\MSC\McUICnt.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\MSM\McSmtFwk.exe (McAfee, Inc.)
PRC - C:\Programme\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics)
PRC - C:\Programme\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Programme\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe (SAMSUNG Electronics co., LTD.)
PRC - C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
PRC - C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
========== Modules (No Company Name) ==========
MOD - C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Programme\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Programme\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Programme\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Programme\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Programme\Samsung\Samsung Magic Doctor\HookDllPS2.dll ()
MOD - C:\Programme\Samsung\EasySpeedUpManager\HookDllPS2.dll ()
MOD - C:\Programme\Samsung\Easy Display Manager\HookDllPS2.dll ()
========== Services (SafeList) ==========
SRV - (ffdshow manager) -- C:\ProgramData\ffdshow manager\2.2.639.201\{16cdff19-861d-48e3-a751-d99a27784753}\ffdshowmngr.exe File not found
SRV - (ada747308081ce1) -- C:\Windows\System32\drivers\ada747308081ce1.sys ()
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (nvUpdatusService) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (fsssvc) -- C:\Programme\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (serviceIEConfig) -- C:\Windows\System32\ieconfig_1und1_svc.exe ()
SRV - (wlidsvc) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) -- C:\Programme\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (McProxy) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (EvtEng) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV - (RegSrvc) -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SQLWriter) -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (VMC302) -- System32\Drivers\VMC302.sys File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (esgiguard) -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys File not found
DRV - (ajxt) -- C:\Windows\System32\drivers\kvegscj.sys (Malwarebytes Corporation)
DRV - (ghpwv) -- C:\Windows\System32\drivers\bxdbbu.sys (Malwarebytes Corporation)
DRV - (ada747308081ce1) -- C:\Windows\System32\drivers\ada747308081ce1.sys ()
DRV - (avipbb) -- C:\Windows\System32\DRIVERS\avipbb.sys ()
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (Tcpip6) -- C:\Windows\System32\DRIVERS\tcpip.sys ()
DRV - (Tcpip) -- C:\Windows\System32\drivers\tcpip.sys ()
DRV - (tcpipreg) -- C:\Windows\System32\drivers\tcpipreg.sys ()
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\DRIVERS\avkmgr.sys ()
DRV - (DXGKrnl) -- C:\Windows\System32\drivers\dxgkrnl.sys ()
DRV - (usbscan) -- C:\Windows\System32\DRIVERS\usbscan.sys ()
DRV - (usbhub) -- C:\Windows\System32\DRIVERS\usbhub.sys ()
DRV - (usbccgp) -- C:\Windows\System32\DRIVERS\usbccgp.sys ()
DRV - (Wdf01000) -- C:\Windows\System32\drivers\Wdf01000.sys ()
DRV - (tssecsrv) -- C:\Windows\System32\DRIVERS\tssecsrv.sys ()
DRV - (Ntfs) -- C:\Windows\System32\drivers\ntfs.sys ()
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys ()
DRV - (nvlddmkm) -- C:\Windows\System32\DRIVERS\nvlddmkm.sys ()
DRV - (volsnap) -- C:\Windows\System32\drivers\volsnap.sys ()
DRV - (WudfPf) -- C:\Windows\System32\drivers\WudfPf.sys ()
DRV - (WUDFRd) -- C:\Windows\System32\DRIVERS\WUDFRd.sys ()
DRV - (KSecDD) -- C:\Windows\System32\Drivers\ksecdd.sys ()
DRV - (RDPWD) -- C:\Windows\System32\drivers\rdpwd.sys ()
DRV - (partmgr) -- C:\Windows\System32\drivers\partmgr.sys ()
DRV - (fssfltr) -- C:\Windows\System32\DRIVERS\fssfltr.sys ()
DRV - (Fs_Rec) -- C:\Windows\System32\drivers\fs_rec.sys ()
DRV - (mrxsmb10) -- C:\Windows\System32\DRIVERS\mrxsmb10.sys ()
DRV - (atksgt) -- C:\Windows\System32\DRIVERS\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\DRIVERS\lirsgt.sys ()
DRV - (usbehci) -- C:\Windows\System32\DRIVERS\usbehci.sys ()
DRV - (usbuhci) -- C:\Windows\System32\DRIVERS\usbuhci.sys ()
DRV - (srv2) -- C:\Windows\System32\DRIVERS\srv2.sys ()
DRV - (srvnet) -- C:\Windows\System32\DRIVERS\srvnet.sys ()
DRV - (mrxsmb20) -- C:\Windows\System32\DRIVERS\mrxsmb20.sys ()
DRV - (mrxsmb) -- C:\Windows\System32\DRIVERS\mrxsmb.sys ()
DRV - (AFD) -- C:\Windows\System32\drivers\afd.sys ()
DRV - (DfsC) -- C:\Windows\System32\Drivers\dfsc.sys ()
DRV - (bowser) -- C:\Windows\System32\DRIVERS\bowser.sys ()
DRV - (srv) -- C:\Windows\System32\DRIVERS\srv.sys ()
DRV - (mfehidk) -- C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) -- C:\Windows\System32\drivers\mfefirek.sys ()
DRV - (mfewfpk) -- C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\Windows\System32\drivers\mfeapfk.sys ()
DRV - (mferkdet) -- C:\Windows\System32\drivers\mferkdet.sys ()
DRV - (mfenlfk) -- C:\Windows\System32\DRIVERS\mfenlfk.sys ()
DRV - (cfwids) -- C:\Windows\System32\drivers\cfwids.sys ()
DRV - (mfebopk) -- C:\Windows\System32\drivers\mfebopk.sys ()
DRV - (HTTP) -- C:\Windows\System32\drivers\HTTP.sys ()
DRV - (tunnel) -- C:\Windows\System32\DRIVERS\tunnel.sys ()
DRV - (athr) -- C:\Windows\System32\DRIVERS\athr.sys ()
DRV - (WpdUsb) -- C:\Windows\System32\DRIVERS\wpdusb.sys ()
DRV - (volmgrx) -- C:\Windows\System32\drivers\volmgrx.sys ()
DRV - (pci) -- C:\Windows\System32\drivers\pci.sys ()
DRV - (TermDD) -- C:\Windows\System32\DRIVERS\termdd.sys ()
DRV - (NDIS) -- C:\Windows\System32\drivers\ndis.sys ()
DRV - (ACPI) -- C:\Windows\System32\drivers\acpi.sys ()
DRV - (CLFS) -- C:\Windows\System32\CLFS.sys ()
DRV - (FltMgr) -- C:\Windows\System32\drivers\fltmgr.sys ()
DRV - (iScsiPrt) -- C:\Windows\System32\DRIVERS\msiscsi.sys ()
DRV - (MsRPC) -- C:\Windows\System32\drivers\msrpc.sys ()
DRV - (Ecache) -- C:\Windows\System32\drivers\ecache.sys ()
DRV - (disk) -- C:\Windows\System32\drivers\disk.sys ()
DRV - (Mup) -- C:\Windows\System32\Drivers\mup.sys ()
DRV - (RasSstp) -- C:\Windows\System32\DRIVERS\rassstp.sys ()
DRV - (NdisWan) -- C:\Windows\System32\DRIVERS\ndiswan.sys ()
DRV - (RasPppoe) -- C:\Windows\System32\DRIVERS\raspppoe.sys ()
DRV - (tdx) -- C:\Windows\System32\DRIVERS\tdx.sys ()
DRV - (PSched) -- C:\Windows\System32\DRIVERS\pacer.sys ()
DRV - (netbt) -- C:\Windows\System32\DRIVERS\netbt.sys ()
DRV - (RMCAST) -- C:\Windows\System32\DRIVERS\RMCAST.sys ()
DRV - (Smb) -- C:\Windows\System32\DRIVERS\smb.sys ()
DRV - (NativeWifiP) -- C:\Windows\System32\DRIVERS\nwifi.sys ()
DRV - (USBSTOR) -- C:\Windows\System32\DRIVERS\USBSTOR.SYS ()
DRV - (HidUsb) -- C:\Windows\System32\DRIVERS\hidusb.sys ()
DRV - (cdrom) -- C:\Windows\System32\DRIVERS\cdrom.sys ()
DRV - (kbdhid) -- C:\Windows\System32\DRIVERS\kbdhid.sys ()
DRV - (MRxDAV) -- C:\Windows\System32\drivers\mrxdav.sys ()
DRV - (rdbss) -- C:\Windows\System32\DRIVERS\rdbss.sys ()
DRV - (Npfs) -- C:\Windows\System32\drivers\npfs.sys ()
DRV - (udfs) -- C:\Windows\System32\DRIVERS\udfs.sys ()
DRV - (exfat) -- C:\Windows\System32\drivers\exfat.sys ()
DRV - (fastfat) -- C:\Windows\System32\drivers\fastfat.sys ()
DRV - (KMWDFILTER) -- C:\Windows\System32\DRIVERS\KMWDFILTER.sys ()
DRV - (VMC326) -- C:\Windows\System32\Drivers\VMC326.sys ()
DRV - (BTHPORT) -- C:\Windows\System32\Drivers\BTHport.sys ()
DRV - (BTHUSB) -- C:\Windows\System32\Drivers\BTHUSB.sys ()
DRV - (RFCOMM) -- C:\Windows\System32\DRIVERS\rfcomm.sys ()
DRV - (Modem) -- C:\Windows\System32\drivers\modem.sys ()
DRV - (Rasl2tp) -- C:\Windows\System32\DRIVERS\rasl2tp.sys ()
DRV - (PptpMiniport) -- C:\Windows\System32\DRIVERS\raspptp.sys ()
DRV - (Ndisuio) -- C:\Windows\System32\DRIVERS\ndisuio.sys ()
DRV - (MSTEE) -- C:\Windows\System32\drivers\MSTEE.sys ()
DRV - (MSPCLOCK) -- C:\Windows\System32\drivers\MSPCLOCK.sys ()
DRV - (MSPQM) -- C:\Windows\System32\drivers\MSPQM.sys ()
DRV - (VgaSave) -- C:\Windows\System32\drivers\vga.sys ()
DRV - (MSKSSRV) -- C:\Windows\System32\drivers\MSKSSRV.sys ()
DRV - (RDPENCDD) -- C:\Windows\System32\drivers\rdpencdd.sys ()
DRV - (mpsdrv) -- C:\Windows\System32\drivers\mpsdrv.sys ()
DRV - (nsiproxy) -- C:\Windows\System32\drivers\nsiproxy.sys ()
DRV - (ws2ifsl) -- C:\Windows\System32\drivers\ws2ifsl.sys ()
DRV - (IpFilterDriver) -- C:\Windows\System32\DRIVERS\ipfltdrv.sys ()
DRV - (luafv) -- C:\Windows\System32\drivers\luafv.sys ()
DRV - (rspndr) -- C:\Windows\System32\DRIVERS\rspndr.sys ()
DRV - (lltdio) -- C:\Windows\System32\DRIVERS\lltdio.sys ()
DRV - (IPNAT) -- C:\Windows\System32\DRIVERS\ipnat.sys ()
DRV - (Wanarpv6) -- C:\Windows\System32\DRIVERS\wanarp.sys ()
DRV - (Wanarp) -- C:\Windows\System32\DRIVERS\wanarp.sys ()
DRV - (NDProxy) -- C:\Windows\System32\drivers\ndproxy.sys ()
DRV - (NdisTapi) -- C:\Windows\System32\DRIVERS\ndistapi.sys ()
DRV - (tunmp) -- C:\Windows\System32\DRIVERS\tunmp.sys ()
DRV - (Filetrace) -- C:\Windows\System32\drivers\filetrace.sys ()
DRV - (NetBIOS) -- C:\Windows\System32\DRIVERS\netbios.sys ()
DRV - (RasAcd) -- C:\Windows\System32\DRIVERS\rasacd.sys ()
DRV - (spldr) -- C:\Windows\System32\drivers\spldr.sys ()
DRV - (TDTCP) -- C:\Windows\System32\drivers\tdtcp.sys ()
DRV - (TDPIPE) -- C:\Windows\System32\drivers\tdpipe.sys ()
DRV - (RDPCDD) -- C:\Windows\System32\DRIVERS\RDPCDD.sys ()
DRV - (FileInfo) -- C:\Windows\System32\drivers\fileinfo.sys ()
DRV - (AsyncMac) -- C:\Windows\System32\DRIVERS\asyncmac.sys ()
DRV - (IRENUM) -- C:\Windows\System32\drivers\irenum.sys ()
DRV - (cdfs) -- C:\Windows\System32\DRIVERS\cdfs.sys ()
DRV - (Msfs) -- C:\Windows\System32\drivers\msfs.sys ()
DRV - (Null) -- C:\Windows\System32\drivers\null.sys ()
DRV - (Beep) -- C:\Windows\System32\drivers\beep.sys ()
DRV - (MountMgr) -- C:\Windows\System32\drivers\mountmgr.sys ()
DRV - (QWAVEdrv) -- C:\Windows\System32\drivers\qwavedrv.sys ()
DRV - (usbvideo) -- C:\Windows\System32\Drivers\usbvideo.sys ()
DRV - (circlass) -- C:\Windows\System32\drivers\circlass.sys ()
DRV - (CmBatt) -- C:\Windows\System32\DRIVERS\CmBatt.sys ()
DRV - (BthEnum) -- C:\Windows\System32\DRIVERS\BthEnum.sys ()
DRV - (Wd) -- C:\Windows\System32\drivers\wd.sys ()
DRV - (kbdclass) -- C:\Windows\System32\DRIVERS\kbdclass.sys ()
DRV - (sffdisk) -- C:\Windows\System32\drivers\sffdisk.sys ()
DRV - (sffp_mmc) -- C:\Windows\System32\drivers\sffp_mmc.sys ()
DRV - (sffp_sd) -- C:\Windows\System32\drivers\sffp_sd.sys ()
DRV - (IPMIDRV) -- C:\Windows\System32\drivers\ipmidrv.sys ()
DRV - (gagp30kx) -- C:\Windows\System32\drivers\gagp30kx.sys ()
DRV - (uagp35) -- C:\Windows\System32\drivers\uagp35.sys ()
DRV - (monitor) -- C:\Windows\System32\DRIVERS\monitor.sys ()
DRV - (umbus) -- C:\Windows\System32\DRIVERS\umbus.sys ()
DRV - (crcdisk) -- C:\Windows\System32\drivers\crcdisk.sys ()
DRV - (usbprint) -- C:\Windows\System32\DRIVERS\usbprint.sys ()
DRV - (msdsm) -- C:\Windows\System32\drivers\msdsm.sys ()
DRV - (sdbus) -- C:\Windows\System32\DRIVERS\sdbus.sys ()
DRV - (ohci1394) -- C:\Windows\System32\DRIVERS\ohci1394.sys ()
DRV - (drmkaud) -- C:\Windows\System32\drivers\drmkaud.sys ()
DRV - (NETw3v32) -- C:\Windows\System32\DRIVERS\NETw3v32.sys ()
DRV - (mpio) -- C:\Windows\System32\drivers\mpio.sys ()
DRV - (BthPan) -- C:\Windows\System32\DRIVERS\bthpan.sys ()
DRV - (i8042prt) -- C:\Windows\System32\DRIVERS\i8042prt.sys ()
DRV - (mouclass) -- C:\Windows\System32\DRIVERS\mouclass.sys ()
DRV - (fdc) -- C:\Windows\System32\DRIVERS\fdc.sys ()
DRV - (flpydisk) -- C:\Windows\System32\DRIVERS\flpydisk.sys ()
DRV - (sermouse) -- C:\Windows\System32\drivers\sermouse.sys ()
DRV - (mouhid) -- C:\Windows\System32\DRIVERS\mouhid.sys ()
DRV - (pcmcia) -- C:\Windows\System32\DRIVERS\pcmcia.sys ()
DRV - (i2omp) -- C:\Windows\System32\drivers\i2omp.sys ()
DRV - (vga) -- C:\Windows\System32\DRIVERS\vgapnp.sys ()
DRV - (rdpdr) -- C:\Windows\System32\drivers\rdpdr.sys ()
DRV - (nv_agp) -- C:\Windows\System32\drivers\nv_agp.sys ()
DRV - (uliagpkx) -- C:\Windows\System32\drivers\uliagpkx.sys ()
DRV - (viaagp) -- C:\Windows\System32\drivers\viaagp.sys ()
DRV - (agp440) -- C:\Windows\System32\drivers\agp440.sys ()
DRV - (volmgr) -- C:\Windows\System32\drivers\volmgr.sys ()
DRV - (isapnp) -- C:\Windows\System32\drivers\isapnp.sys ()
DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys ()
DRV - (mssmbios) -- C:\Windows\System32\DRIVERS\mssmbios.sys ()
DRV - (msisadrv) -- C:\Windows\System32\drivers\msisadrv.sys ()
DRV - (swenum) -- C:\Windows\System32\DRIVERS\swenum.sys ()
DRV - (AmdK8) -- C:\Windows\System32\drivers\amdk8.sys ()
DRV - (ViaC7) -- C:\Windows\System32\drivers\viac7.sys ()
DRV - (intelppm) -- C:\Windows\System32\DRIVERS\intelppm.sys ()
DRV - (AmdK7) -- C:\Windows\System32\drivers\amdk7.sys ()
DRV - (Processor) -- C:\Windows\System32\drivers\processr.sys ()
DRV - (Crusoe) -- C:\Windows\System32\drivers\crusoe.sys ()
DRV - (msahci) -- C:\Windows\System32\drivers\msahci.sys ()
DRV - (atapi) -- C:\Windows\System32\drivers\atapi.sys ()
DRV - (Compbatt) -- C:\Windows\System32\DRIVERS\compbatt.sys ()
DRV - (intelide) -- C:\Windows\System32\drivers\intelide.sys ()
DRV - (amdide) -- C:\Windows\System32\drivers\amdide.sys ()
DRV - (pciide) -- C:\Windows\System32\drivers\pciide.sys ()
DRV - (WmiAcpi) -- C:\Windows\System32\drivers\wmiacpi.sys ()
DRV - (ErrDev) -- C:\Windows\System32\drivers\errdev.sys ()
DRV - (KMDFMEMIO) -- C:\Windows\System32\DRIVERS\kmdfmemio.sys ()
DRV - (AgereSoftModem) -- C:\Windows\System32\DRIVERS\AGRSM.sys ()
DRV - (sbp2port) -- C:\Windows\System32\drivers\sbp2port.sys ()
DRV - (PEAUTH) -- C:\Windows\System32\drivers\peauth.sys ()
DRV - (BTHMODEM) -- C:\Windows\System32\drivers\bthmodem.sys ()
DRV - (HidBth) -- C:\Windows\System32\drivers\hidbth.sys ()
DRV - (usbcir) -- C:\Windows\System32\drivers\usbcir.sys ()
DRV - (usbohci) -- C:\Windows\System32\drivers\usbohci.sys ()
DRV - (HidIr) -- C:\Windows\System32\drivers\hidir.sys ()
DRV - (WacomPen) -- C:\Windows\System32\drivers\wacompen.sys ()
DRV - (sfloppy) -- C:\Windows\System32\drivers\sfloppy.sys ()
DRV - (Serial) -- C:\Windows\System32\drivers\serial.sys ()
DRV - (Parport) -- C:\Windows\System32\drivers\parport.sys ()
DRV - (Serenum) -- C:\Windows\System32\drivers\serenum.sys ()
DRV - (Parvdm) -- C:\Windows\System32\drivers\parvdm.sys ()
DRV - (HdAudAddService) -- C:\Windows\System32\drivers\HdAudio.sys ()
DRV - (bcm4sbxp) -- C:\Windows\System32\DRIVERS\bcm4sbxp.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1398413320&from=adks&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808AE0504E0504&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1398413320&from=adks&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808AE0504E0504&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = hxxp://www.qone8.com/web/?type=ds&ts=1398413320&from=adks&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808AE0504E0504&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.qone8.com/web/?type=ds&ts=1398413320&from=adks&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808AE0504E0504&q={searchTerms}
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
IE - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
IE - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1398413320&from=adks&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808AE0504E0504&q={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1398413320&from=adks&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808AE0504E0504&q={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://suche.web.de/webhp?src=br_startpage_ie [binary data]
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\..\SearchScopes,DefaultScope = {6B1D1FB7-7233-4F7C-802C-21A1DDB12754}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\..\SearchScopes\{6B1D1FB7-7233-4F7C-802C-21A1DDB12754}: "URL" = hxxp://go.web.de/br/ie9_search_web/?su={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1398413320&from=adks&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808AE0504E0504&q={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1398413320&from=adks&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808AE0504E0504&q={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://suche.web.de/webhp?src=br_startpage_ie [binary data]
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes,DefaultScope = {6B1D1FB7-7233-4F7C-802C-21A1DDB12754}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{09038620-190C-402B-A92F-18864E6AB22F}: "URL" = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=114435&tl=esgn10325&tt=040912_ccp_3612_4&babsrc=SP_ss&mntrId=d815f138000000000000002163884f46
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{4FC48B4A-3F22-4C53-A19E-3CDC622C3D8F}: "URL" = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{547F46FC-7017-48CF-B542-9D9485EDF3AD}: "URL" = hxxp://suche.web.de/search/web/?su={searchTerms}&origin=searchplugin
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{56FD3787-0C7F-429A-A098-E253993BC8B7}: "URL" = hxxp://wa.ui-portal.de/webde/webde/s?produkte.browser.link.ebaysuche&s_brand=webde&t_link=ebaysuche&ns_type=clickin&ns_url=hxxp://rover.ebay.com/rover/1/707-52222-30040-5/4?mpre=hxxp://shop.ebay.de/?_sacat=See-All-Categories&_nkw={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{5A817CF6-92D5-4DE5-AC38-82DF8A73EF28}: "URL" = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{6B1D1FB7-7233-4F7C-802C-21A1DDB12754}: "URL" = hxxp://go.web.de/br/ie9_search_web/?su={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{8879210E-B412-4955-A6BE-0A6692831E54}: "URL" = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{93EBA672-1622-4B69-8C07-5760A86A27D1}: "URL" = hxxp://go.web.de/suchbox/ie_amazon/?keywords={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{F2493A77-72D7-4EBE-8AD0-AE5CF044CF2B}: "URL" = hxxp://go.mail.com/br/ie8_search_web/?su={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{F84343E9-4DF1-4E54-B429-79B2CC201472}: "URL" = hxxp://go.web.de/br/ie8_search_amazon/?keywords={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1398413320&from=adks&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808AE0504E0504&q={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1398413320&from=adks&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808AE0504E0504&q={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://suche.web.de/webhp?src=br_startpage_ie [binary data]
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\SearchScopes,DefaultScope = {6B1D1FB7-7233-4F7C-802C-21A1DDB12754}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\SearchScopes\{6B1D1FB7-7233-4F7C-802C-21A1DDB12754}: "URL" = hxxp://go.web.de/br/ie9_search_web/?su={searchTerms}
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledAddons: toolbar@web.de:1.5.5
FF - prefs.js..extensions.enabledAddons: {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: D:\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.09.13 21:50:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2009.06.15 11:00:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krissi\AppData\Roaming\mozilla\Extensions
[2014.06.20 12:43:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krissi\AppData\Roaming\mozilla\Firefox\Profiles\556kefvr.default\extensions
[2010.07.25 22:26:47 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Krissi\AppData\Roaming\mozilla\Firefox\Profiles\556kefvr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.04.14 14:53:54 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Krissi\AppData\Roaming\mozilla\Firefox\Profiles\556kefvr.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.01.08 22:32:07 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Krissi\AppData\Roaming\mozilla\Firefox\Profiles\556kefvr.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(131)
[2012.09.08 02:22:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krissi\AppData\Roaming\mozilla\Firefox\Profiles\556kefvr.default\extensions\staged
[2011.12.24 19:24:32 | 000,571,345 | ---- | M] () (No name found) -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\extensions\toolbar@web.de.xpi
[2012.09.08 02:22:42 | 000,169,792 | ---- | M] () (No name found) -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\extensions\staged\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
[2011.11.04 02:38:56 | 000,000,933 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\11-suche.xml
[2012.09.08 03:06:09 | 000,002,268 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\BabylonMngr.xml
[2009.12.01 17:12:22 | 000,002,204 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\bProtect.xml
[2011.11.04 02:38:56 | 000,002,419 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\englische-ergebnisse.xml
[2011.11.04 02:38:56 | 000,010,525 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\gmx-suche.xml
[2012.01.15 10:21:41 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-1.xml
[2011.03.05 19:57:11 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-10.xml
[2011.03.24 18:49:31 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-11.xml
[2011.05.01 16:26:42 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-12.xml
[2011.05.11 18:45:58 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-13.xml
[2011.05.11 22:42:26 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-14.xml
[2011.07.07 23:34:45 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-15.xml
[2011.08.19 13:07:12 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-16.xml
[2011.09.04 18:41:26 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-17.xml
[2011.09.09 14:00:04 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-18.xml
[2011.09.30 21:09:47 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-19.xml
[2010.07.24 11:14:50 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-2.xml
[2011.10.04 13:52:49 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-20.xml
[2011.10.17 12:27:27 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-21.xml
[2011.11.11 03:06:11 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-22.xml
[2010.07.24 11:17:22 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-3.xml
[2010.09.09 13:16:26 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-4.xml
[2010.09.17 03:56:31 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-5.xml
[2010.10.21 02:29:11 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-6.xml
[2010.11.13 06:11:40 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-7.xml
[2010.12.11 14:47:36 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-8.xml
[2011.03.02 15:00:21 | 000,000,950 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin-9.xml
[2011.09.25 14:49:54 | 000,000,618 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\icqplugin.src
[2011.11.04 02:38:56 | 000,002,457 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\lastminute.xml
[2011.05.11 22:42:28 | 000,005,508 | ---- | M] () -- C:\Users\Krissi\AppData\Roaming\mozilla\firefox\profiles\556kefvr.default\searchplugins\webde-suche.xml
[2014.02.28 23:27:03 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.01.23 05:54:02 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2012.01.23 05:54:02 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2012.01.23 05:54:02 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2012.01.23 05:54:02 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2012.01.23 05:54:02 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) -- C:\USERS\KRISSI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\556KEFVR.DEFAULT\EXTENSIONS\ADDON@DEALPLYSHOPPING.COM
[2010.05.31 20:32:58 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files\mozilla firefox\components\Scriptff.dll
========== Chrome ==========
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\divx\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\Common Files\McAfee\SystemCore\ScriptSn.20100722174826.dll (McAfee, Inc.)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (WEB.DE MailCheck BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Programme\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (WEB.DE MailCheck) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Programme\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH)
O3 - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\..\Toolbar\WebBrowser: (WEB.DE MailCheck) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Programme\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH)
O3 - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Toolbar\WebBrowser: (WEB.DE MailCheck) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Programme\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH)
O3 - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\..\Toolbar\WebBrowser: (WEB.DE MailCheck) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Programme\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [MailCheck IE Broker] C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck_Broker.exe (1und1 Mail und Media GmbH)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-381946461-3025875304-1193097581-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-381946461-3025875304-1193097581-1007..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-381946461-3025875304-1193097581-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-381946461-3025875304-1193097581-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Krissi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-381946461-3025875304-1193097581-1003\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-381946461-3025875304-1193097581-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-381946461-3025875304-1193097581-1007\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-381946461-3025875304-1193097581-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-381946461-3025875304-1193097581-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Policies\Microsoft\Internet Explorer\Recovery present
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} hxxp://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} https://as.photoprintit.de/ips-opdata/layout/default_cms01/activex/IPSUploader4.cab (IPSUploader4 Control)
O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.adobe.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{37FBAEDD-AAAA-4F86-8391-1917F8367B32}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Programme\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~2\ffdsho~1\22639~1.201\{16cdf~1\ffdsho~1.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\System32\Userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Users\Krissi\Pictures\Unser kleines Wunder\Familien-Shooting 02.08.13 + Ende November '13\IMG_20131215_0003 - Kopie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Krissi\Pictures\Unser kleines Wunder\Familien-Shooting 02.08.13 + Ende November '13\IMG_20131215_0003 - Kopie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{58c80f0a-4f5c-11de-a804-001377ad17b8}\Shell - "" = AutoRun
O33 - MountPoints2\{58c80f0a-4f5c-11de-a804-001377ad17b8}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014.06.25 23:59:45 | 000,000,000 | ---D | C] -- C:\FRST
[2014.06.25 23:59:03 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Krissi\Desktop\OTL.exe
[2014.06.25 23:54:35 | 001,073,152 | ---- | C] (Farbar) -- C:\Users\Krissi\Desktop\FRST.exe
[2014.06.25 23:39:14 | 000,052,440 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\kvegscj.sys
[2014.06.25 23:25:28 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\11CE19DA.sys
[2014.06.25 19:43:27 | 000,052,440 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\bxdbbu.sys
[2014.06.25 19:33:09 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\1F8F04E3.sys
[2014.06.25 14:44:42 | 000,411,552 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\xxqwcfsn.sys
[2014.06.25 14:43:54 | 000,411,552 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\pysdfqyd.sys
[2014.06.25 14:43:53 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014.06.25 14:01:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2014.06.25 13:32:04 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\7B305B94.sys
[2014.06.25 12:52:34 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\10AC4DA0.sys
[2014.06.25 12:51:59 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\48230029.sys
[2014.06.20 00:54:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014.06.20 00:54:37 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2014.06.15 21:58:09 | 000,000,000 | ---D | C] -- C:\Users\Krissi\AppData\Local\Adobe
[2014.06.12 15:01:56 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2014.06.12 15:01:55 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2014.06.12 15:01:55 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014.06.12 15:01:54 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014.06.12 15:01:54 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014.06.12 15:01:54 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2014.06.12 15:01:52 | 001,810,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014.06.12 15:01:52 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014.06.12 15:01:52 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2014.06.12 15:01:51 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014.06.12 15:01:49 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2014.06.12 15:01:49 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014.06.25 23:59:03 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Krissi\Desktop\OTL.exe
[2014.06.25 23:57:08 | 000,380,416 | ---- | M] () -- C:\Users\Krissi\Desktop\Gmer-19357.exe
[2014.06.25 23:54:36 | 001,073,152 | ---- | M] (Farbar) -- C:\Users\Krissi\Desktop\FRST.exe
[2014.06.25 23:53:33 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014.06.25 23:53:33 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014.06.25 23:40:39 | 000,674,258 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2014.06.25 23:40:39 | 000,634,468 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014.06.25 23:40:39 | 000,146,238 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2014.06.25 23:40:39 | 000,120,034 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014.06.25 23:39:14 | 000,052,440 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\kvegscj.sys
[2014.06.25 23:33:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.06.25 23:25:28 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\11CE19DA.sys
[2014.06.25 23:24:43 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\48230029.sys
[2014.06.25 23:14:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.06.25 22:04:16 | 000,000,476 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Krissi.job
[2014.06.25 19:43:27 | 000,052,440 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\bxdbbu.sys
[2014.06.25 19:33:09 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\1F8F04E3.sys
[2014.06.25 19:03:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.06.25 14:44:42 | 000,411,552 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\xxqwcfsn.sys
[2014.06.25 14:43:54 | 000,411,552 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\pysdfqyd.sys
[2014.06.25 13:58:35 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.06.25 13:58:03 | 3215,572,992 | -HS- | M] () -- C:\hiberfil.sys
[2014.06.25 13:32:04 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\7B305B94.sys
[2014.06.25 12:52:34 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\10AC4DA0.sys
[2014.06.25 10:57:52 | 000,037,248 | ---- | M] () -- C:\Windows\System32\drivers\ada747308081ce1.sys
[2014.06.24 20:00:02 | 000,110,296 | ---- | M] () -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014.06.20 00:54:48 | 000,000,899 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.06.13 12:41:13 | 000,699,056 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014.06.13 12:41:13 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014.06.13 03:25:20 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2014.05.28 18:39:36 | 001,810,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014.05.28 18:32:25 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014.05.28 18:31:33 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2014.05.28 18:31:17 | 000,065,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014.05.28 18:30:53 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014.05.28 18:30:25 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014.05.28 18:30:08 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2014.05.28 18:30:00 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2014.05.28 18:29:58 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2014.05.28 18:29:49 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2014.05.28 18:29:31 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014.05.28 18:28:35 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.06.25 23:57:08 | 000,380,416 | ---- | C] () -- C:\Users\Krissi\Desktop\Gmer-19357.exe
[2014.06.25 10:57:52 | 000,037,248 | ---- | C] () -- C:\Windows\System32\drivers\ada747308081ce1.sys
[2014.06.20 00:55:21 | 000,110,296 | ---- | C] () -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014.06.20 00:54:37 | 000,074,456 | ---- | C] () -- C:\Windows\System32\drivers\mbamchameleon.sys
[2014.06.20 00:54:37 | 000,051,928 | ---- | C] () -- C:\Windows\System32\drivers\mwac.sys
[2014.06.12 15:02:00 | 000,915,392 | ---- | C] () -- C:\Windows\System32\drivers\tcpip.sys
[2014.06.12 15:02:00 | 000,031,232 | ---- | C] () -- C:\Windows\System32\drivers\tcpipreg.sys
[2014.04.25 19:46:48 | 008,904,632 | ---- | C] () -- C:\Windows\System32\drivers\nvlddmkm.sys
[2014.03.23 15:24:51 | 000,136,216 | ---- | C] () -- C:\Windows\System32\drivers\avipbb.sys
[2014.03.23 15:24:51 | 000,037,352 | ---- | C] () -- C:\Windows\System32\drivers\avkmgr.sys
[2014.03.14 00:50:18 | 002,050,560 | ---- | C] () -- C:\Windows\System32\win32k.sys
[2014.02.28 22:42:34 | 000,221,568 | ---- | C] () -- C:\Windows\System32\drivers\netio.sys
[2014.01.13 18:24:28 | 000,000,947 | ---- | C] () -- C:\Users\Krissi\.recently-used.xbel
[2013.12.12 17:03:31 | 000,167,936 | ---- | C] () -- C:\Windows\System32\drivers\portcls.sys
[2013.12.12 17:03:31 | 000,130,048 | ---- | C] () -- C:\Windows\System32\drivers\drmk.sys
[2013.10.09 23:54:36 | 000,638,400 | ---- | C] () -- C:\Windows\System32\drivers\dxgkrnl.sys
[2013.10.09 23:54:36 | 000,037,376 | ---- | C] () -- C:\Windows\System32\cdd.dll
[2013.10.09 23:44:07 | 000,226,304 | ---- | C] () -- C:\Windows\System32\drivers\usbport.sys
[2013.10.09 23:44:07 | 000,197,632 | ---- | C] () -- C:\Windows\System32\drivers\usbhub.sys
[2013.10.09 23:44:07 | 000,073,216 | ---- | C] () -- C:\Windows\System32\drivers\usbccgp.sys
[2013.10.09 23:44:07 | 000,039,936 | ---- | C] () -- C:\Windows\System32\drivers\usbehci.sys
[2013.10.09 23:44:07 | 000,023,552 | ---- | C] () -- C:\Windows\System32\drivers\usbuhci.sys
[2013.10.09 23:44:07 | 000,006,016 | ---- | C] () -- C:\Windows\System32\drivers\usbd.sys
[2013.10.09 23:42:45 | 000,527,064 | ---- | C] () -- C:\Windows\System32\drivers\Wdf01000.sys
[2013.10.09 23:41:00 | 000,293,376 | ---- | C] () -- C:\Windows\System32\atmfd.dll
[2013.10.09 23:34:58 | 000,035,328 | ---- | C] () -- C:\Windows\System32\drivers\usbscan.sys
[2013.10.09 23:34:58 | 000,025,472 | ---- | C] () -- C:\Windows\System32\drivers\hidparse.sys
[2013.08.15 11:56:12 | 000,024,064 | ---- | C] () -- C:\Windows\System32\drivers\tssecsrv.sys
[2013.08.15 11:55:45 | 003,551,680 | ---- | C] () -- C:\Windows\System32\ntoskrnl.exe
[2013.04.24 14:11:04 | 001,082,232 | ---- | C] () -- C:\Windows\System32\drivers\ntfs.sys
[2013.04.11 15:13:42 | 000,049,152 | ---- | C] () -- C:\Windows\System32\csrsrv.dll
[2013.03.14 14:09:06 | 000,015,872 | ---- | C] () -- C:\Windows\System32\drivers\usb8023.sys
[2013.02.18 09:22:18 | 000,149,352 | ---- | C] () -- C:\Windows\System32\drivers\nvhda32v.sys
[2012.12.13 13:41:20 | 000,224,640 | ---- | C] () -- C:\Windows\System32\drivers\volsnap.sys
[2012.12.13 13:39:04 | 000,155,136 | ---- | C] () -- C:\Windows\System32\drivers\WUDFRd.sys
[2012.12.13 13:39:04 | 000,066,560 | ---- | C] () -- C:\Windows\System32\drivers\WUDFPf.sys
[2012.12.13 13:39:00 | 000,047,720 | ---- | C] () -- C:\Windows\System32\drivers\WdfLdr.sys
[2012.10.23 12:28:41 | 000,026,840 | ---- | C] () -- C:\Windows\System32\drivers\GEARAspiWDM.sys
[2012.09.08 04:16:47 | 000,039,272 | ---- | C] () -- C:\Windows\System32\drivers\fssfltr.sys
[2012.09.08 02:45:37 | 000,001,660 | ---- | C] () -- C:\Windows\System32\ASOROSet.bin
[2012.09.08 02:10:18 | 000,178,688 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2012.07.12 16:46:23 | 000,440,704 | ---- | C] () -- C:\Windows\System32\drivers\ksecdd.sys
[2008.12.29 18:13:24 | 000,025,600 | ---- | C] () -- C:\Users\Krissi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014.03.25 15:26:04 | 011,587,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Files - Unicode (All) ==========
[2013.11.19 14:28:55 | 105,031,188 | ---- | M] ()(C:\Windows\System32\???¸) -- C:\Windows\System32\Ẵᴼ¸
[2013.11.19 14:28:55 | 105,031,188 | ---- | C] ()(C:\Windows\System32\???¸) -- C:\Windows\System32\Ẵᴼ¸
[2013.11.15 20:44:19 | 104,496,569 | ---- | M] ()(C:\Windows\System32\????) -- C:\Windows\System32\䱲ᴼœ
[2013.11.15 20:44:19 | 104,496,569 | ---- | C] ()(C:\Windows\System32\????) -- C:\Windows\System32\䱲ᴼœ
[2013.11.15 13:44:51 | 104,401,821 | ---- | M] ()(C:\Windows\System32\????) -- C:\Windows\System32\�鉩ᴼ™
[2013.11.15 13:44:51 | 104,401,821 | ---- | C] ()(C:\Windows\System32\????) -- C:\Windows\System32\�鉩ᴼ™
[2013.11.14 23:50:08 | 104,278,918 | ---- | M] ()(C:\Windows\System32\???I) -- C:\Windows\System32\뗆鵼ᴼI
[2013.11.14 23:50:08 | 104,278,918 | ---- | C] ()(C:\Windows\System32\???I) -- C:\Windows\System32\뗆鵼ᴼI
[2013.11.12 01:10:50 | 103,792,856 | ---- | M] ()(C:\Windows\System32\????) -- C:\Windows\System32\繵捇ᴼ˜
[2013.11.12 01:10:50 | 103,792,856 | ---- | C] ()(C:\Windows\System32\????) -- C:\Windows\System32\繵捇ᴼ˜
[2013.10.23 12:37:02 | 102,551,358 | ---- | M] ()(C:\Windows\System32\?)??) -- C:\Windows\System32\槙)ᴼ˜
[2013.10.20 20:17:16 | 102,551,358 | ---- | C] ()(C:\Windows\System32\?)??) -- C:\Windows\System32\槙)ᴼ˜
[2013.10.18 14:26:03 | 101,760,430 | ---- | M] ()(C:\Windows\System32\????) -- C:\Windows\System32\ᤁ⿹ᴼš
[2013.10.18 14:26:03 | 101,760,430 | ---- | C] ()(C:\Windows\System32\????) -- C:\Windows\System32\ᤁ⿹ᴼš
[2013.10.10 23:13:01 | 100,332,977 | ---- | M] ()(C:\Windows\System32\???) -- C:\Windows\System32\䶎ᴼ
[2013.10.10 23:13:01 | 100,332,977 | ---- | C] ()(C:\Windows\System32\???) -- C:\Windows\System32\䶎ᴼ
[2013.10.09 23:54:59 | 100,163,860 | ---- | M] ()(C:\Windows\System32\????) -- C:\Windows\System32\킔㝒ᴼ‘
[2013.10.09 23:54:59 | 100,163,860 | ---- | C] ()(C:\Windows\System32\????) -- C:\Windows\System32\킔㝒ᴼ‘
[2013.10.01 15:23:00 | 098,609,570 | ---- | M] ()(C:\Windows\System32\????) -- C:\Windows\System32\ɚᴼ›
[2013.09.30 22:30:40 | 098,609,570 | ---- | C] ()(C:\Windows\System32\????) -- C:\Windows\System32\ɚᴼ›
[2013.09.19 13:37:25 | 098,352,290 | ---- | M] ()(C:\Windows\System32\???) -- C:\Windows\System32\⊸䘗ᴼ
[2013.09.19 13:37:25 | 098,352,290 | ---- | C] ()(C:\Windows\System32\???) -- C:\Windows\System32\⊸䘗ᴼ
[2013.09.10 15:09:20 | 096,940,255 | ---- | M] ()(C:\Windows\System32\???) -- C:\Windows\System32\蘷妽ᴼ
[2013.09.10 15:09:20 | 096,940,255 | ---- | C] ()(C:\Windows\System32\???) -- C:\Windows\System32\蘷妽ᴼ
========== Alternate Data Streams ==========
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:373E1720
< End of report > OTL Extras Code:
OTL Extras logfile created on: 26.06.2014 00:06:26 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Krissi\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,99 Gb Total Physical Memory | 1,35 Gb Available Physical Memory | 45,17% Memory free
6,21 Gb Paging File | 4,51 Gb Available in Paging File | 72,63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144,09 Gb Total Space | 50,15 Gb Free Space | 34,81% Space Free | Partition Type: NTFS
Drive D: | 144,00 Gb Total Space | 131,52 Gb Free Space | 91,33% Space Free | Partition Type: NTFS
Computer Name: KRISSI-PC | User Name: Krissi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.reg [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- "%1" %*
http [open] -- Reg Error: Value error.
https [open] -- Reg Error: Value error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Directory [AddToPlaylistVLC] -- "D:\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "D:\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{142890DF-4AAD-4D66-AB88-B7F9F814D07F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1B2497C2-9244-4CE8-A7C7-51FE7E92B2A5}" = rport=139 | protocol=6 | dir=out | app=system |
"{27CEFFAF-842B-460F-93CA-3CD834075537}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4A2B3146-08CE-40B8-BDF4-85836A8148BB}" = rport=445 | protocol=6 | dir=out | app=system |
"{50C73B9D-C87F-49A7-8C66-51513B24B85A}" = rport=138 | protocol=17 | dir=out | app=system |
"{5E182C44-84CC-4D3C-BF28-EE7C73C7B247}" = lport=139 | protocol=6 | dir=in | app=system |
"{663AC32B-516A-418A-B91D-030082CDB9ED}" = rport=137 | protocol=17 | dir=out | app=system |
"{68121BFD-7B52-43F1-B027-08CB466590EA}" = lport=138 | protocol=17 | dir=in | app=system |
"{7602E6F3-3FA1-4A49-95F0-B7356C6FE12A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{7612CC18-368D-4379-9FD9-6C229B41D7C5}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{77F9C8D6-8731-4178-9F50-1D16ABF5BAA1}" = lport=445 | protocol=6 | dir=in | app=system |
"{7D480B1F-75EE-49CA-A48E-42E6EA32594E}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{A2D2C53F-0509-4C5D-8686-10B226E2552B}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{C2606E35-6873-4C47-9882-98127C97F6A4}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{C511FC2E-1B6B-47FC-99FB-F85EBBD6ED4C}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{D89EB9D1-2863-4C3B-941C-50C71F7F8D12}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{DB7BC9C5-A8F0-470E-AAD0-C4BB40CD92BB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F09ACBD6-A8A7-4FE8-881F-F24D647B4812}" = lport=137 | protocol=17 | dir=in | app=system |
"{F760D1E4-0B50-4E51-B7A6-EB686E3976EF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FFCDEE3A-5052-4D36-8F4F-DEBCF6298495}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06F0D01E-6A01-4FE5-877F-15C94558C307}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{1ED4CBEE-3CEC-45D7-9475-C811877C5BC8}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"{2C5CE09C-0F7F-4A51-B3BE-86AA873DA491}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{368B32F3-91E7-43EA-8CC5-52A4CF348ADF}" = protocol=17 | dir=in | app=c:\windows\system32\msiexec.exe |
"{39C3A882-2EDD-4D76-9299-C7CAA9486F02}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{4EB334C5-E250-4170-91D3-12FA823D83D5}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{62EC5331-D65C-4D5D-B295-5DCCFF44F045}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{6AD1B9BD-5D1D-477A-B0EC-A33F15B22DEE}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{72D1A043-3A59-43D6-8374-6D576B4B944F}" = dir=out | name=core networking - system ip core |
"{7B942282-C231-4B4E-B8FC-FF173651B04E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{91D5E265-E433-4374-82C8-36EA23066813}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{9B169E0A-8523-4E61-88CB-BD9D97717EA6}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"{9CC7FAC8-514E-4816-B10D-EA9D8C401DAD}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{A5211B85-BD55-48DB-B8A3-045BBCBCFE4A}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{ABA3F48D-04CE-433D-B083-D44B3E7B9B5F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B48A66D2-FC0B-4F1B-A130-227C8B9BD017}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B8882197-58B0-4B3A-8EC9-9AA649391E4A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{BA7A9EDA-9D0E-4FFC-A9E8-2FE4DA8AFBA5}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BE93EB60-F4CC-42AE-8704-DDFDD6BB7E5E}" = dir=in | name=core networking - system ip core |
"{CD99E126-41B9-4720-AC03-58DE101113A5}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"{D478ED30-D21A-4A55-830F-E34149884F20}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D64A733B-0229-4DB2-B69E-14063CEE17F6}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{DE8677A0-8133-4DE5-B421-30594267AAF4}" = protocol=6 | dir=in | app=c:\windows\system32\msiexec.exe |
"{E2A902E2-3CAB-451F-96AB-0872A2EF7777}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{F6274F77-9D28-47A0-A489-BE4F8A573AA0}" = dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{FA33A7C7-67B4-4229-A03B-6F5CE1F28919}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"{FB0BAAFB-D319-412E-8035-1FB10677F481}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"TCP Query User{3318EE59-36C2-4B2E-AD00-453A4FB3D485}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{5F024BFC-5371-4623-A55C-4AA62F9037BB}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{AB2AE9A2-8C90-4361-B8CB-0BA8E5C3E01B}C:\program files\icq7.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe |
"UDP Query User{28125176-D76F-43B4-8E54-C9FF00D6BE13}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{D0291C42-0491-4D6A-AC6B-C96FC94CB191}C:\program files\icq7.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe |
"UDP Query User{FD64B5CB-888F-4C3C-BF40-24D2AE27F1E8}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1
"{02602409-9189-4567-BC07-562605243B69}" = Windows Live Remote Client Resources
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.6300
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{04983D37-2202-4295-94A2-8B547C66133F}" = Atheros WLAN Client
"{04B45310-A5FE-4425-BFCA-1A6D8920DE74}" = OpenOffice.org 3.0
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution III
"{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}" = Risen
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 21
"{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety
"{2DFB5485-A3EF-4298-9280-4AF80C9F4BE9}" = Microsoft SQL Server VSS Writer
"{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}" = Microsoft Games for Windows - LIVE Redistributable
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{302AC480-43D2-11D5-A818-00500435FC18}" = Gothic_Patch
"{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3A65A74A-5B6E-451A-92D8-50F1182BBE9A}" = Windows Live Remote Service Resources
"{40FE74B5-71A1-4393-A0AB-21D6E1DA5A66}" = Gothic 2 Gold
"{4903D172-DCCB-392F-93A3-34CA9D47FE3D}" = Microsoft .NET Framework 4.5.1
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B55E0A8-07F5-4966-9B7B-D32C8ADC0FF4}" = Samsung Converter
"{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}" = Google Earth
"{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"{547DCEC7-DD2A-47E9-82C7-5CF1EAB526DA}" = Microsoft SQL Server Native Client
"{5A9AA2C0-972F-4239-AA41-E409434194D5}" = MobileMe Control Panel
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{6041D07D-CBC6-4119-8C35-D95B77AD5FBA}" = InternetExplorer-WEB.DE-Addon
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{713E5AB1-2389-43A6-8313-CB4D3C44C4FA}" = Samsung USB Driver
"{71A51B09-E7D3-11DB-A386-005056C00008}" = Vimicro UVC Camera
"{71A51B59-E7D3-11DB-A386-005056C00008}" = Namuga 1.3M Webcam
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B46F9CF-CF60-492E-816E-95EB1A9D1BB4}" = Play Camera
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E106A57-A17E-431D-B48F-175E42EB9F74}" = imagine digital freedom - Samsung
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90850407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031" = Microsoft .NET Framework 4.5.1 (Deutsch)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E871D09-064D-3BC9-963B-3AB8ABE1273D}" = Microsoft .NET Framework 4.5.1 (DEU)
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.0) - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}" = Samsung Master
"{AED53CDF-1046-4C6B-B5E2-C195125ECDA0}" = Intel(R) PROSet/Wireless WiFi-Software
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 310.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 310.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.1031
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}" = Samsung Update Plus
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F59205C8-E5FB-43F5-AAB2-16C1760D4F59}" = FaceFilter Studio 2
"{F5A4F780-DF0C-444F-BA82-637CCF5C8052}" = Windows Live Family Safety
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"1&1 Mail & Media GmbH 1und1DesktopIconsInstaller" = WEB.DE Desktop Icons
"1&1 Mail & Media GmbH 1und1Softwareaktualisierung" = WEB.DE Softwareaktualisierung
"1&1 Mail & Media GmbH Toolbar IE8" = WEB.DE MailCheck für Internet Explorer
"Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 14 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Avira AntiVir Desktop" = Avira Free Antivirus
"CCleaner" = CCleaner
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup" = DivX-Setup
"InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"InstallShield_{7B46F9CF-CF60-492E-816E-95EB1A9D1BB4}" = Play Camera
"InstallShield_{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"Macaosolitaire_1.0" = Macaosolitaire 1.0
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware Version 2.0.2.1012
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NVIDIA Drivers" = NVIDIA Drivers
"Opera 12.17.1863" = Opera 12.17
"Paperport Removal Tool_is1" = Paperport Removal Tool
"PhotoScape" = PhotoScape
"ProInst" = Intel PROSet Wireless
"RarZilla Free Unrar 2.53" = RarZilla Free Unrar 2.53
"SereneScreen Marine Aquarium 2" = SereneScreen Marine Aquarium 2
"SimpleOCR 3.1" = SimpleOCR 3.1
"Speedpasch_1.0" = Speedpasch 1.0
"Speedpyramid_1.0" = Speedpyramid 1.0
"Stepok's One Click Wipe und Recomposit_is1" = One Click Wipe 2
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 2.0.2
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinLiveSuite" = Windows Live Essentials
"Zoo Tycoon 1.0" = Zoo Tycoon: Complete Collection
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-381946461-3025875304-1193097581-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-381946461-3025875304-1193097581-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 25.06.2014 11:19:57 | Computer Name = Krissi-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 25.06.2014 11:19:57 | Computer Name = Krissi-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3198
Error - 25.06.2014 11:19:57 | Computer Name = Krissi-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3198
Error - 25.06.2014 11:19:58 | Computer Name = Krissi-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 25.06.2014 11:19:58 | Computer Name = Krissi-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4196
Error - 25.06.2014 11:19:58 | Computer Name = Krissi-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4196
Error - 25.06.2014 18:00:30 | Computer Name = Krissi-PC | Source = VSS | ID = 12289
Description =
Error - 25.06.2014 18:00:30 | Computer Name = Krissi-PC | Source = VSS | ID = 12289
Description =
Error - 25.06.2014 18:00:30 | Computer Name = Krissi-PC | Source = VSS | ID = 12289
Description =
Error - 25.06.2014 18:00:30 | Computer Name = Krissi-PC | Source = VSS | ID = 12289
Description =
[ System Events ]
Error - 25.06.2014 07:59:47 | Computer Name = Krissi-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 25.06.2014 07:59:47 | Computer Name = Krissi-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 25.06.2014 07:59:47 | Computer Name = Krissi-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 25.06.2014 08:01:39 | Computer Name = Krissi-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 25.06.2014 08:01:39 | Computer Name = Krissi-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 25.06.2014 08:01:39 | Computer Name = Krissi-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 25.06.2014 08:01:39 | Computer Name = Krissi-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 25.06.2014 08:02:14 | Computer Name = Krissi-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 25.06.2014 08:43:54 | Computer Name = Krissi-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 25.06.2014 08:44:42 | Computer Name = Krissi-PC | Source = Service Control Manager | ID = 7000
Description =
< End of report > |