subvision | 30.09.2012 14:48 | Wahrscheinlich neuer Virus: Avast VisthAux.exe deaktiviert und erster Sektor der Festplatte kann nicht gelesen werden Hallo liebe Leute.
Ich habe folgendes Problem. Ich nutze Windows 7 64 bit, Avast free Antivirus und die Comodo Firewall in der neuesten Version. Vom 03.09 bis zum 24.09 war ich im Urlaub. Als ich den Computer nach dem Urlaub eingeschaltet habe, wurde erstmal ein neues Netzwerk gefunden. Mir wurden mehrere Optionen geboten (zu Hause, Im Internetcafe, Flughafen). Ich wählte "Zu Hause".
Später fiel mir auf, daß das Wartungscenter mir anzeigte, dass Avast deaktiviert ist. Nämlich die Visthaux.exe Datei, um genau zu sein. Somit konnte ich keine Virendefinitionen mehr herunterladen und auch nicht das Programm updaten. Da hatte ich bereits einen Trojaner/Virus im Verdacht. Ich machte einen Check mit MBRCheck, aber der zeigte mir Standard-Windows 7 Code an. Sämtliche Versuche, die Visthaux.exe Datei im Wartungscenter zu aktivieren, brachten nix. Die Eingabe wurde einfach ignoriert.
Schlau, wie ich bin, hatte ich mit Acronis True Image Home (Western Digital Edition) ein Image meiner C Partition auf D gespeichert. Als ich die Recovery starten wollte kam die nächste Überraschung. Der erste Sektor meiner Festplatte konnte nicht gelesen werden. Ich wählte "ignorieren" und das Image wurde neu aufgespielt. Nach einem Reboot war Visthaux.exe immer noch deaktiviert.
Ich dachte, wenn es komplex ist, dann denke simpel. Also habe ich den Windows Scripting Host mit Hilfe von xp-antispy ausgeschaltet. Nach einem Reboot lief Avast auf einmal wieder. Ich habe den Verdacht, dass da ein VBScript im Hintergrund lief. Das hat erstmal dafür gesorgt, daß ich Avast wieder benutzen kann, der Übeltäter ist aber immer noch auf meinem System und ich weiß nicht, was der sonst noch so kann.
Ich glaube, daß jemand in meiner Wohnung war und den Schädling aufgespielt hat. Jemand, der Informationen sucht. Es geht da um eine Scheidung mit Rechtsstreitigkeiten. Leider habe ich hier ein kleines Büchlein liegen mit sämtlichen Passwörtern. Ich hätte ja nie gedacht, daß die mal jemand zu sehen bekommt. Das ist jedoch nur eine Vermutung - der Trojaner kann auch anders auf mein System gekommen sein.
Ich glaube, daß der Trojaner eine Maßanfertigung ist. Daher wird er auch von meinem Scanner nicht erkannt.
Was soll ich jetzt machen? Avast habe ich bereits kontaktiert, aber vor Montag wird das wohl nichts. Außerdem habe ich den Verdacht, daß meine Kommunikation jedweder Art kontrolliert wird. Daher weiß ich nicht, ob ich überhaupt eine Antwort-Mail erhalten werde.
Am Rande: Die Personen, welche mit der Scheidung zu tun haben, wurden auch gehackt (Symbian Handy, Unix System und Linux). Ich gehe also nicht davon aus, daß ich mir "zufällig" was eingefangen habe.
Über Hilfe jeder Art wäre ich sehr dankbar.
subvision
edit: Welche Logs werden gebraucht? Ich mache, was ich kann.
OTL Logs
OTL.txt
OTL Logfile: Code:
OTL logfile created on: 30.09.2012 16:37:40 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Micha\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,71 Gb Available Physical Memory | 67,89% Memory free
7,99 Gb Paging File | 6,46 Gb Available in Paging File | 80,78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 49,91 Gb Total Space | 22,85 Gb Free Space | 45,78% Space Free | Partition Type: NTFS
Drive D: | 415,75 Gb Total Space | 271,35 Gb Free Space | 65,27% Space Free | Partition Type: NTFS
Computer Name: X4 | User Name: Micha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.09.30 16:35:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Micha\Desktop\OTL.exe
PRC - [2012.08.31 16:02:03 | 002,754,984 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012.08.23 10:17:30 | 000,875,216 | ---- | M] (Comodo Security Solutions, Inc.) -- C:\Program Files (x86)\COMODO\GeekBuddy\unit.exe
PRC - [2012.08.23 10:17:30 | 000,874,192 | ---- | M] (Comodo Security Solutions, Inc.) -- C:\Program Files (x86)\COMODO\GeekBuddy\unit_manager.exe
PRC - [2012.08.23 10:17:28 | 000,070,352 | ---- | M] (Comodo Security Solutions Inc.) -- C:\Program Files (x86)\Common Files\Comodo\launcher_service.exe
PRC - [2012.08.21 11:12:26 | 004,282,728 | ---- | M] (AVAST Software) -- D:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012.08.21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) -- d:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.06.28 17:40:52 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- D:\Program Files (x86)\Winamp\winampa.exe
PRC - [2012.01.27 09:47:20 | 000,828,944 | ---- | M] (GlavSoft LLC.) -- C:\Program Files (x86)\Common Files\Comodo\tvnserver.exe
PRC - [2008.11.18 13:15:30 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
========== Modules (No Company Name) ==========
MOD - [2009.07.10 09:07:18 | 000,166,912 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL
MOD - [2009.02.06 18:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL
========== Services (SafeList) ==========
SRV:64bit: - [2012.08.06 12:24:22 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2012.07.28 04:09:44 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2012.09.30 13:11:55 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.09.28 18:43:27 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.09.28 14:19:56 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2012.09.28 13:54:28 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2012.09.19 11:29:44 | 002,365,792 | ---- | M] (TuneUp Software) [Auto | Running] -- D:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012.09.06 03:25:06 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.08.31 16:02:03 | 002,754,984 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012.08.23 10:17:28 | 000,070,352 | ---- | M] (Comodo Security Solutions Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Comodo\launcher_service.exe -- (CLPSLauncher)
SRV - [2012.08.21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- d:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.03.11 21:13:24 | 002,815,496 | ---- | M] (COMODO) [Auto | Running] -- C:\Programme\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2012.01.27 09:47:20 | 000,828,944 | ---- | M] (GlavSoft LLC.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Comodo\tvnserver.exe -- (tvnserver)
SRV - [2011.09.27 21:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.11.18 13:15:30 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.08.21 11:13:13 | 000,969,200 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2012.08.21 11:13:13 | 000,359,464 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2012.08.21 11:13:13 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2012.08.21 11:13:12 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2012.08.21 11:13:12 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2012.08.21 11:13:11 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2012.08.03 10:23:28 | 000,035,064 | ---- | M] (Windows (R) Win 7 DDK provider) [File_System | System | Stopped] -- C:\Windows\SysNative\drivers\CFRMD.sys -- (CFRMD)
DRV:64bit: - [2012.07.28 06:07:44 | 010,278,912 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.07.28 03:14:46 | 000,368,640 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.05.14 08:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.09.02 08:30:46 | 000,042,776 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2011.09.02 08:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2011.09.02 08:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2011.06.10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.10.16 06:44:56 | 001,309,696 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\P17.sys -- (P17)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:35:53 | 000,051,712 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rtnic64.sys -- (RTL8023x64)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2005.03.29 01:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV - [2012.09.19 10:50:50 | 000,011,880 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- D:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
DRV - [2012.03.05 16:04:30 | 000,053,888 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Programme\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.1)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4C E6 90 83 6F 9D CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: artur.dubovoy@gmail.com:3.7.0
FF - prefs.js..extensions.enabledAddons: firefox@ghostery.com:2.8.3
FF - prefs.js..extensions.enabledAddons: stealthyextension@gmail.com:2.3.3
FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.5.6
FF - prefs.js..extensions.enabledAddons: wrc@avast.com:7.0.1466
FF - prefs.js..network.proxy.no_proxies_on: "localhost, 127.0.0.1, stealthy.co"
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: d:\Program Files\AVAST Software\Avast\WebRep\FF [2012.09.28 14:16:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: d:\Program Files (x86)\Mozilla Firefox\components [2012.09.28 13:59:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: d:\Program Files (x86)\Mozilla Firefox\plugins [2012.09.28 14:52:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: d:\Program Files (x86)\Mozilla Thunderbird\components [2012.09.28 14:37:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: d:\Program Files (x86)\Mozilla Thunderbird\plugins
[2012.09.28 13:59:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Micha\AppData\Roaming\mozilla\Extensions
[2012.09.28 14:26:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Micha\AppData\Roaming\mozilla\Firefox\Profiles\bensm4a1.default\extensions
[2012.09.28 14:26:28 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\Micha\AppData\Roaming\mozilla\Firefox\Profiles\bensm4a1.default\extensions\firefox@ghostery.com
[2012.09.28 14:26:24 | 000,213,554 | ---- | M] () (No name found) -- C:\Users\Micha\AppData\Roaming\mozilla\firefox\profiles\bensm4a1.default\extensions\artur.dubovoy@gmail.com.xpi
[2012.09.28 14:26:28 | 000,184,864 | ---- | M] () (No name found) -- C:\Users\Micha\AppData\Roaming\mozilla\firefox\profiles\bensm4a1.default\extensions\stealthyextension@gmail.com.xpi
[2012.09.28 14:26:28 | 000,529,316 | ---- | M] () (No name found) -- C:\Users\Micha\AppData\Roaming\mozilla\firefox\profiles\bensm4a1.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012.09.28 14:13:12 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Micha\AppData\Roaming\mozilla\firefox\profiles\bensm4a1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.09.28 14:16:24 | 000,000,000 | ---D | M] (avast! WebRep) -- D:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
O1 HOSTS File: ([2012.09.29 20:47:31 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - d:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - d:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - d:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - d:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [avast] d:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [P17RunE] C:\Windows\SysWow64\P17RunE.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WinampAgent] D:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O13 - gopher Prefix: missing
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/110926/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{317911D6-43D9-4A2C-9C41-CE2F7CB71F28}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{317911D6-43D9-4A2C-9C41-CE2F7CB71F28}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3D00864E-26A5-474A-A715-EE62AAFC2273}: NameServer = 8.26.56.26,156.154.70.22
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) - C:\Windows\SysWOW64\guard32.dll (COMODO)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012.09.30 16:35:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Micha\Desktop\OTL.exe
[2012.09.30 13:12:08 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Local\Macromedia
[2012.09.30 13:11:54 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2012.09.30 13:11:53 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2012.09.30 13:09:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2012.09.29 20:47:32 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012.09.29 20:39:56 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.09.29 20:39:56 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.09.29 20:39:56 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.09.29 20:34:52 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012.09.29 20:34:38 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.09.29 19:16:49 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Canneverbe Limited
[2012.09.29 19:16:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
[2012.09.29 13:44:56 | 000,034,656 | ---- | C] (TuneUp Software) -- C:\Windows\SysNative\TURegOpt.exe
[2012.09.29 13:44:55 | 000,025,952 | ---- | C] (TuneUp Software) -- C:\Windows\SysNative\authuitu.dll
[2012.09.29 13:44:53 | 000,021,344 | ---- | C] (TuneUp Software) -- C:\Windows\SysWow64\authuitu.dll
[2012.09.29 13:44:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013
[2012.09.29 13:44:42 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\TuneUp Software
[2012.09.29 13:43:13 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012.09.29 13:43:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2012.09.29 13:43:02 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012.09.29 12:42:27 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2012.09.29 12:42:08 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[2012.09.29 12:27:36 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.09.29 12:26:58 | 000,116,224 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll
[2012.09.29 12:26:24 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll
[2012.09.28 23:20:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2012.09.28 23:10:35 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Logishrd
[2012.09.28 18:45:23 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\Nexus Mod Manager
[2012.09.28 18:45:23 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\Network Monitor 3
[2012.09.28 18:45:23 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\My Received Files
[2012.09.28 18:45:17 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\My Games
[2012.09.28 18:45:17 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\My Drivers
[2012.09.28 18:45:17 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\My Curse
[2012.09.28 18:45:17 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\Meine empfangenen Dateien
[2012.09.28 18:45:17 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\LogiShrd
[2012.09.28 18:45:17 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\GTA San Andreas User Files
[2012.09.28 18:45:17 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\Games for Windows - LIVE Demos
[2012.09.28 18:45:17 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\ForceField Shared Files
[2012.09.28 18:45:17 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\ArmA 2 Other Profiles
[2012.09.28 18:45:16 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\Youcam
[2012.09.28 18:45:16 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\The Lord of the Rings Online
[2012.09.28 18:45:16 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\ArmA 2
[2012.09.28 18:45:15 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\STALKER-SHOC
[2012.09.28 18:45:13 | 000,000,000 | ---D | C] -- C:\Users\Micha\Documents\S.T.A.L.K.E.R. - Call Of Pripyat
[2012.09.28 18:42:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2012.09.28 18:41:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2012.09.28 18:31:39 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Skype
[2012.09.28 18:31:34 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2012.09.28 18:31:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012.09.28 18:31:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012.09.28 18:31:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2012.09.28 18:15:03 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Local\Logishrd
[2012.09.28 18:14:33 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
[2012.09.28 18:07:09 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Leadertech
[2012.09.28 18:07:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LogiShrd
[2012.09.28 18:06:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
[2012.09.28 18:06:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Logishrd
[2012.09.28 18:05:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LogiShrd
[2012.09.28 18:05:48 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Logitech
[2012.09.28 18:05:48 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Logishrd
[2012.09.28 17:04:38 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Macromedia
[2012.09.28 17:04:38 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Adobe
[2012.09.28 17:04:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FLV Player
[2012.09.28 16:59:13 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\FastStone
[2012.09.28 16:57:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
[2012.09.28 16:56:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Image Viewer
[2012.09.28 14:53:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
[2012.09.28 14:52:44 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
[2012.09.28 14:52:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2012.09.28 14:52:35 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Winamp
[2012.09.28 14:48:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\COMODO
[2012.09.28 14:48:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Comodo
[2012.09.28 14:48:24 | 000,000,000 | ---D | C] -- C:\ProgramData\CPA_VA
[2012.09.28 14:46:29 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\COMODO
[2012.09.28 14:39:30 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2012.09.28 14:38:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.09.28 14:37:44 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Thunderbird
[2012.09.28 14:37:44 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Local\Thunderbird
[2012.09.28 14:31:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
[2012.09.28 14:31:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2012.09.28 14:31:32 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2012.09.28 14:16:58 | 000,025,232 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012.09.28 14:16:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012.09.28 14:16:57 | 000,359,464 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012.09.28 14:16:55 | 000,059,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012.09.28 14:16:55 | 000,054,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012.09.28 14:16:54 | 000,969,200 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012.09.28 14:16:51 | 000,285,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012.09.28 14:16:51 | 000,071,600 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012.09.28 14:16:19 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012.09.28 14:16:19 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.09.28 14:16:11 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012.09.28 14:09:44 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Local\AMD
[2012.09.28 14:09:27 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\ATI
[2012.09.28 14:09:27 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Local\ATI
[2012.09.28 14:09:27 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012.09.28 14:07:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2012.09.28 14:07:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2012.09.28 14:07:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2012.09.28 14:07:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2012.09.28 14:06:36 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2012.09.28 14:06:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2012.09.28 14:06:08 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012.09.28 14:06:08 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2012.09.28 14:05:55 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2012.09.28 14:05:17 | 000,000,000 | ---D | C] -- C:\AMD
[2012.09.28 13:59:51 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Mozilla
[2012.09.28 13:59:51 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Local\Mozilla
[2012.09.28 13:59:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012.09.28 13:59:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.09.28 13:54:45 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Creative Installation Information
[2012.09.28 13:54:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Creative
[2012.09.28 13:54:44 | 000,419,840 | ---- | C] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2012.09.28 13:54:44 | 000,413,696 | ---- | C] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2012.09.28 13:54:43 | 002,873,820 | ---- | C] (Creative) -- C:\Windows\SysWow64\Sens_oal.dll
[2012.09.28 13:54:43 | 001,908,736 | ---- | C] (Creative) -- C:\Windows\SysNative\Sens_oal.dll
[2012.09.28 13:54:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
[2012.09.28 13:54:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Creative Labs Shared
[2012.09.28 13:54:23 | 000,000,000 | ---D | C] -- C:\Program Files\Creative
[2012.09.28 13:54:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Creative
[2012.09.28 13:54:06 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2012.09.28 13:54:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2012.09.28 13:52:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Creative
[2012.09.28 13:52:26 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Data
[2012.09.28 13:52:26 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DATA
[2012.09.28 13:47:50 | 000,000,000 | R--D | C] -- C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.09.28 13:47:50 | 000,000,000 | R--D | C] -- C:\Users\Micha\Searches
[2012.09.28 13:47:50 | 000,000,000 | R--D | C] -- C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.09.28 13:47:41 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Identities
[2012.09.28 13:47:39 | 000,000,000 | R--D | C] -- C:\Users\Micha\Contacts
[2012.09.28 13:47:38 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Local\VirtualStore
[2012.09.28 13:47:32 | 000,000,000 | --SD | C] -- C:\Users\Micha\AppData\Roaming\Microsoft
[2012.09.28 13:47:32 | 000,000,000 | R--D | C] -- C:\Users\Micha\Videos
[2012.09.28 13:47:32 | 000,000,000 | R--D | C] -- C:\Users\Micha\Saved Games
[2012.09.28 13:47:32 | 000,000,000 | R--D | C] -- C:\Users\Micha\Pictures
[2012.09.28 13:47:32 | 000,000,000 | R--D | C] -- C:\Users\Micha\Music
[2012.09.28 13:47:32 | 000,000,000 | R--D | C] -- C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.09.28 13:47:32 | 000,000,000 | R--D | C] -- C:\Users\Micha\Links
[2012.09.28 13:47:32 | 000,000,000 | R--D | C] -- C:\Users\Micha\Favorites
[2012.09.28 13:47:32 | 000,000,000 | R--D | C] -- C:\Users\Micha\Downloads
[2012.09.28 13:47:32 | 000,000,000 | R--D | C] -- C:\Users\Micha\Documents
[2012.09.28 13:47:32 | 000,000,000 | R--D | C] -- C:\Users\Micha\Desktop
[2012.09.28 13:47:32 | 000,000,000 | R--D | C] -- C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Vorlagen
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\AppData\Local\Verlauf
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\AppData\Local\Temporary Internet Files
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Startmenü
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\SendTo
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Recent
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Netzwerkumgebung
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Lokale Einstellungen
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Documents\Eigene Videos
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Documents\Eigene Musik
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Eigene Dateien
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Documents\Eigene Bilder
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Druckumgebung
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Cookies
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\AppData\Local\Anwendungsdaten
[2012.09.28 13:47:32 | 000,000,000 | -HSD | C] -- C:\Users\Micha\Anwendungsdaten
[2012.09.28 13:47:32 | 000,000,000 | -H-D | C] -- C:\Users\Micha\AppData
[2012.09.28 13:47:32 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Local\Temp
[2012.09.28 13:47:32 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Local\Microsoft
[2012.09.28 13:47:32 | 000,000,000 | ---D | C] -- C:\Users\Micha\AppData\Roaming\Media Center Programs
[2012.09.28 13:47:21 | 000,000,000 | ---D | C] -- C:\Recovery
[2012.09.28 13:47:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2012.09.28 13:47:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2012.09.28 13:47:20 | 000,000,000 | -HSD | C] -- C:\Programme
[2012.09.28 13:47:20 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2012.09.28 13:47:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2012.09.28 13:47:20 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2012.09.28 13:47:20 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2012.09.28 13:47:20 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2012.09.28 13:47:20 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2012.09.28 13:47:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2012.09.28 13:47:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2012.09.28 13:47:15 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.09.28 13:40:33 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2012.09.28 13:40:15 | 000,000,000 | -HSD | C] -- C:\System Volume Information
========== Files - Modified Within 30 Days ==========
[2012.09.30 16:35:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Micha\Desktop\OTL.exe
[2012.09.30 15:46:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.30 15:24:20 | 000,014,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.30 15:24:20 | 000,014,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.30 15:23:09 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.09.30 15:23:09 | 000,653,928 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.09.30 15:23:09 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.09.30 15:23:09 | 000,129,800 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.09.30 15:23:09 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.09.30 15:16:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.30 15:16:41 | 3219,738,624 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.29 20:47:31 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.09.29 19:35:50 | 000,274,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.09.29 13:44:50 | 000,001,080 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.09.28 22:15:13 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.09.28 22:15:13 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2012.09.28 18:42:12 | 000,000,643 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2012.09.28 14:55:32 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.09.28 14:48:36 | 000,002,043 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2012.09.28 14:16:51 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012.09.28 14:08:55 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2012.09.28 13:54:44 | 000,419,840 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2012.09.28 13:54:44 | 000,413,696 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2012.09.28 13:52:29 | 000,000,159 | RH-- | M] () -- C:\Windows\ctfile.rfc
[2012.09.28 13:43:12 | 000,052,953 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2012.09.28 13:43:12 | 000,052,953 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2012.09.19 11:29:46 | 000,034,656 | ---- | M] (TuneUp Software) -- C:\Windows\SysNative\TURegOpt.exe
[2012.09.19 11:29:40 | 000,025,952 | ---- | M] (TuneUp Software) -- C:\Windows\SysNative\authuitu.dll
[2012.09.19 11:29:40 | 000,021,344 | ---- | M] (TuneUp Software) -- C:\Windows\SysWow64\authuitu.dll
========== Files Created - No Company Name ==========
[2012.09.30 13:11:56 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.29 20:39:56 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.09.29 20:39:56 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.09.29 20:39:56 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.09.29 20:39:56 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.09.29 20:39:56 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.09.29 19:16:41 | 000,000,808 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
[2012.09.29 13:44:50 | 000,001,080 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2012.09.29 13:44:50 | 000,001,080 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013.lnk
[2012.09.29 12:28:09 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd
[2012.09.29 12:25:53 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml
[2012.09.29 12:25:34 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml
[2012.09.29 12:25:34 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml
[2012.09.29 12:25:08 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml
[2012.09.28 22:15:13 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.09.28 22:15:13 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012.09.28 18:45:16 | 000,148,124 | ---- | C] () -- C:\Users\Micha\Documents\Spiele.7z
[2012.09.28 18:45:16 | 000,007,016 | ---- | C] () -- C:\Users\Micha\Documents\stalke~1.ltx
[2012.09.28 18:42:12 | 000,000,643 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2012.09.28 16:57:30 | 000,001,174 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012.09.28 14:55:32 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.09.28 14:48:36 | 000,002,043 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2012.09.28 14:37:41 | 000,000,947 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2012.09.28 14:16:51 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2012.09.28 14:08:55 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.09.28 13:59:48 | 000,000,799 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.09.28 13:55:16 | 000,007,062 | ---- | C] () -- C:\Windows\SysWow64\audiopid.vxd
[2012.09.28 13:52:29 | 000,214,528 | ---- | C] () -- C:\Windows\SysNative\APOMgr64.DLL
[2012.09.28 13:52:29 | 000,166,912 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2012.09.28 13:52:29 | 000,089,088 | ---- | C] () -- C:\Windows\SysNative\CmdRtr64.DLL
[2012.09.28 13:52:29 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2012.09.28 13:52:29 | 000,000,159 | RH-- | C] () -- C:\Windows\ctfile.rfc
[2012.09.28 13:48:54 | 000,001,405 | ---- | C] () -- C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012.09.28 13:48:49 | 000,001,439 | ---- | C] () -- C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.09.28 13:43:07 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012.09.28 13:43:05 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012.09.28 13:40:15 | 3219,738,624 | -HS- | C] () -- C:\hiberfil.sys
[2012.07.28 03:39:50 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.07.28 03:39:50 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012.09.29 19:16:49 | 000,000,000 | ---D | M] -- C:\Users\Micha\AppData\Roaming\Canneverbe Limited
[2012.09.28 18:07:09 | 000,000,000 | ---D | M] -- C:\Users\Micha\AppData\Roaming\Leadertech
[2012.09.28 14:37:44 | 000,000,000 | ---D | M] -- C:\Users\Micha\AppData\Roaming\Thunderbird
[2012.09.29 13:44:42 | 000,000,000 | ---D | M] -- C:\Users\Micha\AppData\Roaming\TuneUp Software
========== Purity Check ==========
< End of report > --- --- ---
Extras.txt
OTL Logfile: Code:
OTL Extras logfile created on: 30.09.2012 16:37:40 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Micha\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,71 Gb Available Physical Memory | 67,89% Memory free
7,99 Gb Paging File | 6,46 Gb Available in Paging File | 80,78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 49,91 Gb Total Space | 22,85 Gb Free Space | 45,78% Space Free | Partition Type: NTFS
Drive D: | 415,75 Gb Total Space | 271,35 Gb Free Space | 65,27% Space Free | Partition Type: NTFS
Computer Name: X4 | User Name: Micha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- D:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with FastStone] -- "d:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "D:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with FastStone] -- "d:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "D:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0294BB2F-6178-459D-8C46-8D1C40D6AD6B}" = rport=445 | protocol=6 | dir=out | app=system |
"{057550CC-1C7E-4C7B-A2F8-3A8DDC978C8C}" = lport=138 | protocol=17 | dir=in | app=system |
"{08E024BB-596A-4DFF-A430-159062EB67CE}" = lport=10243 | protocol=6 | dir=in | app=system |
"{19A5737B-0BEE-43C8-BCD3-3CC714AA4FD3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{25B9D31D-64EC-44F5-900B-17177C3E5D3C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{295EF879-34FC-4A05-A484-51AA1443280E}" = lport=445 | protocol=6 | dir=in | app=system |
"{2FA65B31-3A9D-4C20-AFC6-469495F0EF44}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4084E937-EAAA-47EE-9520-7BE7CE434C09}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4810C109-80D8-4E37-AA9F-5C66B60C7F9E}" = rport=445 | protocol=6 | dir=out | app=system |
"{4AD636A3-B1E6-4148-8399-0170D8CBBACE}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{4BF5EB07-06A2-40E2-B5B6-244EF5C49A0F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{5456EA1E-AF45-48BD-9C96-AB99A6CCF1D9}" = lport=139 | protocol=6 | dir=in | app=system |
"{570DC54A-1FBC-44F7-8414-6072FF5F0F8B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{574AEA13-709C-4211-AD28-6A5A7E3BB341}" = rport=138 | protocol=17 | dir=out | app=system |
"{6364B77A-8796-4078-B3CC-5963A3E70B4F}" = rport=139 | protocol=6 | dir=out | app=system |
"{6CE8704B-3211-4C70-887D-B9CEF08992BA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6EFD3216-D4DB-448C-81DA-E8838C66FFD2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6F49495F-4D67-457E-9E38-58D5A0637D59}" = rport=10243 | protocol=6 | dir=out | app=system |
"{7976E497-245A-4F1C-9677-11CAC9466A56}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7C7BD74E-D59D-40F9-8481-A74C4729E9DD}" = rport=138 | protocol=17 | dir=out | app=system |
"{83B9CAFB-69D0-4F95-972A-9001D39A9434}" = lport=137 | protocol=17 | dir=in | app=system |
"{8470297F-3376-4224-8727-0D978BAF4CE3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{86444BB3-291D-4D31-A046-BB4AA3243C28}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{88976B1E-79C6-42E4-AF0D-1E42E6226170}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9ABA5117-7CB4-431C-99C2-D531B39A22F9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A4B4993B-559C-47D4-9558-FA3543E38D0C}" = lport=10243 | protocol=6 | dir=in | app=system |
"{AF8150A9-8B4A-4262-900E-D368942052B3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B56EF66B-A1C6-4EFE-95DF-D99E52766ED8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B7181ACC-C4D5-4512-AAF3-B2CAE8AB7190}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{BAA119F3-441C-4C55-988A-27AEA27A9900}" = rport=137 | protocol=17 | dir=out | app=system |
"{BE10AB93-C4A6-464B-BE93-069E778BFF99}" = rport=10243 | protocol=6 | dir=out | app=system |
"{C232D951-55E7-4D04-9346-F88A07FC0B22}" = lport=137 | protocol=17 | dir=in | app=system |
"{C2A4D13A-961E-4BFB-9AE3-6B6E190F1376}" = lport=138 | protocol=17 | dir=in | app=system |
"{C428A183-FD79-40B5-990D-895328F43AC8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CC9E314B-95DC-40B7-9942-214414DE0C1A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CF0676E6-E2EC-438A-9741-7029DEBD00CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D7F8C559-0DFD-49B6-9416-0C102797FE9B}" = rport=139 | protocol=6 | dir=out | app=system |
"{E5A21E87-89BD-49CC-8454-2B33C59220FD}" = lport=445 | protocol=6 | dir=in | app=system |
"{EEB6A9BB-A7DD-4821-A010-9FE92B58FD90}" = lport=139 | protocol=6 | dir=in | app=system |
"{F534D21D-02A4-4E48-A237-A3745ED5E6D3}" = rport=137 | protocol=17 | dir=out | app=system |
"{F92A4524-02D8-460E-BCE2-C846E112E68D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{F9C1EEE5-72B7-40C6-BC7C-64E9DF7DEB39}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{003C7A18-60D9-4C89-94D8-DE42C1AA1D76}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{02A4D600-582A-4C14-ADFE-C125CF0CB18F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0E7F6679-510D-42F2-88CC-7A9C65A86751}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{1473D86F-6F04-46A3-9153-CD04272511DC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2CCABDB8-759B-4713-9E07-97839453F8A8}" = protocol=6 | dir=out | app=system |
"{471575DE-E82A-4121-8B9A-04371AD35BB1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4849799C-D8E9-4360-8F9A-6B5F2BCC7EA4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{549295BD-B95E-4E30-97C2-626203387B9A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{55384AE6-C304-4442-B979-B753A4C52D66}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{56E808A1-BFD0-4B79-B567-B9FA848D697F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{57565851-D5B5-446A-97C5-07B334F0DDA3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{61FB8AD2-C831-45AB-9DFB-D685C3A8300D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{62F27534-2769-4D2F-B42F-E96E62F64F44}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{65901CFC-D156-4C8F-90EA-C26D256CA195}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{68F6992D-6E9D-4F14-88EC-3E0B8BEC7EFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{690F4192-D01A-4F37-BDDD-7036766F3A4C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{76EE8F32-E271-46B3-B54C-5A60A795353E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8642AF85-31DC-4BB3-8E9D-1E478C224084}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8B222F82-E2BD-44D6-A7D8-D807F503F45B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A5589677-56C4-46C1-A86B-1F0B5425786F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AB3FBA72-52C3-4476-9A38-230DBE05659B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{AD9E1445-4E34-4E02-824B-BB389CB9F4E0}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BC7833D1-AE4B-4CAB-BDD5-6EA587E5C763}" = protocol=6 | dir=out | app=system |
"{C7BD812F-76C2-4CD8-AEF6-8D163282BF81}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CE504808-152F-4073-8BB9-0F8E7C4D30C6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D3648D1D-2BA3-4973-9B7E-EDC907B6E342}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DC0788E7-C70D-4ED1-9D48-AD1A53362A49}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DE5392CB-F939-4182-9CBA-3FD663E2C455}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E39B3A45-4C07-48D1-9769-8D7E093C8A41}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{E3BFCA2C-CA17-44B7-85BE-5D86CA526A20}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E4026AA7-03A1-446D-82BE-EF18B8612121}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E8715BB0-E132-4617-B344-62E03BFE2C1C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E926E57D-011D-4F63-BCC5-FFCFDC28D091}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EF77F35D-C983-4399-9F22-7866E80DFC54}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{EFA98652-B437-42AA-B7D3-EFFD71ED4ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F2A46565-3D03-4FFC-8614-269514F5083F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F7DCF881-DB9D-4779-8D1C-CCCBAC7C73FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FC6E344C-38E4-466C-8CA5-3800385B3CE1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{6C2E334F-37F5-C312-53BA-1482F9A6FD4D}" = ccc-utility64
"{81D00339-968D-15D1-3499-8431658E896F}" = AMD Catalyst Install Manager
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{9387E5ED-7D5D-A744-6BDC-8F6CB26DE09A}" = AMD Fuel
"{D6AB1F5B-FED6-49A9-9747-327BD28FB3C7}" = COMODO Internet Security
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{E6F5D8BE-0B00-6DD9-18F9-D4045798FCBE}" = AMD Media Foundation Decoders
"{F55458B0-DCA9-38C9-6C8D-829F22463A55}" = AMD Drag and Drop Transcoding
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"sp6" = Logitech SetPoint 6.32
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01496C89-6117-AD97-3CB3-98AF2026070C}" = CCC Help German
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0486991B-63F4-5106-06CE-404D7BA55041}" = CCC Help Italian
"{177A3BC5-ECD3-BFF1-4D87-C4B417924DF2}" = CCC Help Russian
"{19BB1AF9-981C-4539-9113-D2F88F031C1D}" = GeekBuddy
"{19D368B2-5601-007B-A296-535706E00D97}" = CCC Help English
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{278FA289-F502-D888-A3BA-5FA10308AAAD}" = CCC Help Danish
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{44F77218-4BBD-1B74-88B7-FC302868F2B3}" = CCC Help Japanese
"{489BC3B4-AEF9-E14A-11BC-B70FDE9D543D}" = CCC Help Chinese Traditional
"{4A85AE1B-9727-261D-9EAF-07C1AECCF977}" = CCC Help Turkish
"{502699FF-F586-54B1-91E8-E85D9FAE0D6D}" = CCC Help Greek
"{53EF1C4D-0705-98F2-1889-A69BBF9F03F3}" = CCC Help Thai
"{548A4EF3-BD97-0813-B469-E1E2FC9DE487}" = CCC Help Korean
"{55533224-CAD0-39B5-6297-E1B2D1D8F176}" = AMD VISION Engine Control Center
"{590828E0-9BA6-3E4D-8491-A1D9CC3EB8CE}" = CCC Help French
"{6563FAF5-84F9-0A35-C032-182EBC4C3BDB}" = CCC Help Finnish
"{6D46F639-5F2F-90F3-4B60-EB2EF264B82E}" = CCC Help Spanish
"{70210CF8-CAB1-8FEB-D964-C33AFE18730B}" = CCC Help Czech
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{8B1AEC85-4507-28BD-F3BA-4A5D732752E7}" = CCC Help Hungarian
"{8C5ACED4-34D3-23BB-F90E-2F90420321BC}" = Catalyst Control Center Localization All
"{A3DAD349-E48E-AE45-3F26-7B80A4FFCD26}" = Catalyst Control Center InstallProxy
"{B0B1A8A5-4711-BB6C-DD59-9794AD928368}" = CCC Help Dutch
"{B33D2348-2938-1A03-0CD3-E6F7101244E0}" = CCC Help Polish
"{B7C8D838-9C3A-1177-B80A-E3C512FD8AF5}" = CCC Help Swedish
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}" = TuneUp Utilities 2013
"{DDCB737A-EEC8-3815-42DA-69011A55E3E5}" = Catalyst Control Center Graphics Previews Common
"{E170E984-6B20-79C2-1E9F-0256EC5ADFB4}" = CCC Help Chinese Standard
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E866E52C-1F56-4CCF-0071-CA915F8CFEDA}" = CCC Help Norwegian
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F4811919-F252-4B25-9AB2-8859A85810B5}" = TuneUp Utilities Language Pack (de-DE)
"{F5D245CC-C332-1E8E-CCB1-75E0C3C4D6F1}" = CCC Help Portuguese
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ALchemy" = Creative ALchemy
"AudioCS" = Creative Audio-Systemsteuerung
"avast" = avast! Free Antivirus
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition
"FastStone Image Viewer" = FastStone Image Viewer 4.6
"FLV Player" = FLV Player 2.0 (build 25)
"Mozilla Firefox 15.0.1 (x86 de)" = Mozilla Firefox 15.0.1 (x86 de)
"Mozilla Thunderbird 15.0.1 (x86 de)" = Mozilla Thunderbird 15.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"TeamViewer 7" = TeamViewer 7
"TuneUp Utilities 2013" = TuneUp Utilities 2013
"WaveStudio 7" = Creative WaveStudio 7
"Winamp" = Winamp
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Erkennungs-Plug-in
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 28.09.2012 17:06:40 | Computer Name = X4 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: TeamViewer_Service.exe, Version:
7.0.14563.0, Zeitstempel: 0x5040c2cd Name des fehlerhaften Moduls: unknown, Version:
0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x742f6a34
ID
des fehlerhaften Prozesses: 0x744 Startzeit der fehlerhaften Anwendung: 0x01cd9dbcd0297eb9
Pfad
der fehlerhaften Anwendung: C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
Pfad
des fehlerhaften Moduls: unknown Berichtskennung: 6538cdd5-09b0-11e2-bb78-00e04c53cc0c
Error - 29.09.2012 07:12:53 | Computer Name = X4 | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 29.09.2012 07:13:00 | Computer Name = X4 | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 29.09.2012 07:13:05 | Computer Name = X4 | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 29.09.2012 07:13:05 | Computer Name = X4 | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 29.09.2012 07:13:06 | Computer Name = X4 | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 29.09.2012 07:14:02 | Computer Name = X4 | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 29.09.2012 07:14:11 | Computer Name = X4 | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 29.09.2012 07:20:42 | Computer Name = X4 | Source = ESENT | ID = 215
Description = WinMail (3312) WindowsMail0: Die Sicherung wurde abgebrochen, weil
sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen
wurde.
Error - 29.09.2012 07:20:49 | Computer Name = X4 | Source = ESENT | ID = 215
Description = WinMail (3548) WindowsMail0: Die Sicherung wurde abgebrochen, weil
sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen
wurde.
[ System Events ]
Error - 30.09.2012 05:04:57 | Computer Name = X4 | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\system32\DRIVERS\CFRMD.sys
nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
des Treibers zu erhalten.
Error - 30.09.2012 05:05:35 | Computer Name = X4 | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
CFRMD
Error - 30.09.2012 05:07:40 | Computer Name = X4 | Source = WMPNetworkSvc | ID = 866287
Description =
Error - 30.09.2012 09:14:57 | Computer Name = X4 | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\system32\DRIVERS\CFRMD.sys
nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
des Treibers zu erhalten.
Error - 30.09.2012 09:15:35 | Computer Name = X4 | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
CFRMD
Error - 30.09.2012 09:15:38 | Computer Name = X4 | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Computerbrowser" wurde mit folgendem Fehler beendet: %%1115
Error - 30.09.2012 09:15:38 | Computer Name = X4 | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Server" wurde mit folgendem Fehler beendet: %%13
Error - 30.09.2012 09:16:40 | Computer Name = X4 | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\system32\DRIVERS\CFRMD.sys
nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
des Treibers zu erhalten.
Error - 30.09.2012 09:17:16 | Computer Name = X4 | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
CFRMD
Error - 30.09.2012 09:19:18 | Computer Name = X4 | Source = WMPNetworkSvc | ID = 866287
Description =
< End of report > --- --- ---
Oh, hatte ich vergessen, zu erwähnen. WLan hab ich ausgestellt.
Die Kaspersky Rescue CD 10 kann nicht gebootet werden. Vielleicht hilft das ja jemandem weiter, mir zu helfen.
Habe 2 Kopien vom ISO-Image gemacht und beide laufen nicht. Was habe ich mir da bloß eingefangen? |