inspigate | 30.01.2013 17:54 | Hallo,
vielen Dank für Deine Antwort.
Ihr habt hier im Forum eine "Checkliste", nach der ein neuer User vorgehen soll, wenn Er seine Probleme schildert. Zu meiner Schande muss ich gestehen, das ich nach erneutem Nachsehen selbst festgestellt habe, das diese "zipperei" und Anhängen der Logfiles nur nach ausdrücklichem auffordern des helfenden erwünscht ist.
Es ist also alles in Ordnung mit eurer Anleitung, wenn man denn Lesen kann...:-)
Ich wusste mit nur nicht wirklich zu helfen. Nachfolgend nun die integrierten Logiles
gmer.txt Code:
GMER 2.0.18454 - hxxp://www.gmer.net
Rootkit scan 2013-01-29 18:26:17
Windows 6.0.6002 Service Pack 2 x64 \Device\Harddisk0\DR0 -> \Device\0000004c ST315005 rev.CC34 1397,27GB
Running: gmer_2.0.18454.exe; Driver: C:\Users\Herzchen\AppData\Local\Temp\kxlyyuod.sys
---- Kernel code sections - GMER 2.0 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff9600016e700 3 bytes [C0, 83, 02]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 4 fffff9600016e704 3 bytes [01, C4, FA]
---- User code sections - GMER 2.0 ----
.text C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[836] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1972] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\ProgramData\Browser Manager\2.5.976.107\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe[1168] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Windows\SysWOW64\schtasks.exe[1640] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2200] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\ProgramData\Browser Manager\2.5.976.107\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe[2972] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3724] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3848] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text D:\Adobe\Acrobat 9.0\Acrobat\acrotray.exe[3896] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2136] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3468] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 00000000779b9455 7 bytes {MOV EDX, 0x97be28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 00000000779b967d 7 bytes {MOV EDX, 0x97be68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000779b96ad 7 bytes {MOV EDX, 0x97bda8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000779b96c5 7 bytes {MOV EDX, 0x97bd28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000779b96dd 7 bytes {MOV EDX, 0x97bf28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 00000000779b970d 7 bytes {MOV EDX, 0x97bf68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000779b9785 7 bytes {MOV EDX, 0x97bee8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000779b979d 7 bytes {MOV EDX, 0x97bea8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 00000000779b97e5 7 bytes {MOV EDX, 0x97bc68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000779b98d5 7 bytes {MOV EDX, 0x97bca8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000779b9b15 7 bytes {MOV EDX, 0x97bc28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000779baa25 7 bytes {MOV EDX, 0x97bde8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 00000000779baa9d 7 bytes {MOV EDX, 0x97bd68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 00000000779bac95 7 bytes {MOV EDX, 0x97bce8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 00000000779b9455 7 bytes {MOV EDX, 0x975a28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 00000000779b967d 7 bytes {MOV EDX, 0x975a68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000779b96ad 7 bytes {MOV EDX, 0x9759a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000779b96c5 7 bytes {MOV EDX, 0x975928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000779b96dd 7 bytes {MOV EDX, 0x975b28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 00000000779b970d 7 bytes {MOV EDX, 0x975b68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000779b9785 7 bytes {MOV EDX, 0x975ae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000779b979d 7 bytes {MOV EDX, 0x975aa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 00000000779b97e5 7 bytes {MOV EDX, 0x975868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000779b98d5 7 bytes {MOV EDX, 0x9758a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000779b9b15 7 bytes {MOV EDX, 0x975828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000779baa25 7 bytes {MOV EDX, 0x9759e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 00000000779baa9d 7 bytes {MOV EDX, 0x975968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 00000000779bac95 7 bytes {MOV EDX, 0x9758e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2104] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4368] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 00000000779b9455 7 bytes {MOV EDX, 0x104ea28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 00000000779b967d 7 bytes {MOV EDX, 0x104ea68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000779b96ad 7 bytes {MOV EDX, 0x104e9a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000779b96c5 7 bytes {MOV EDX, 0x104e928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000779b96dd 7 bytes {MOV EDX, 0x104eb28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 00000000779b970d 7 bytes {MOV EDX, 0x104eb68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000779b9785 7 bytes {MOV EDX, 0x104eae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000779b979d 7 bytes {MOV EDX, 0x104eaa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 00000000779b97e5 7 bytes {MOV EDX, 0x104e868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000779b98d5 7 bytes {MOV EDX, 0x104e8a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000779b9b15 7 bytes {MOV EDX, 0x104e828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000779baa25 7 bytes {MOV EDX, 0x104e9e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 00000000779baa9d 7 bytes {MOV EDX, 0x104e968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 00000000779bac95 7 bytes {MOV EDX, 0x104e8e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4360] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Windows\SysWOW64\conime.exe[4384] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
.text C:\Users\Herzchen\Downloads\gmer_2.0.18454.exe[4168] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000077095fb7 5 bytes JMP 00000001755741c0
---- Threads - GMER 2.0 ----
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2708:1916] 0000000075b5f36f
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2708:3472] 0000000072fa0cb3
---- Processes - GMER 2.0 ----
Library C:\Program (*** suspicious ***) @ C:\Windows\system32\svchost.exe [316] 00000000730d0000
Library C:\Program (*** suspicious ***) @ C:\Windows\system32\svchost.exe [460] 00000000730d0000
Library C:\Program (*** suspicious ***) @ C:\Windows\system32\svchost.exe [1204] 00000000730d0000
Library C:\Program (*** suspicious ***) @ C:\Windows\System32\spoolsv.exe [1504] 00000000730d0000
Library C:\Windows\system32\dnssd.dll (*** suspicious ***) @ C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [1972] 00000000745d0000
Library C:\Windows\system32\dnssd.dll (*** suspicious ***) @ C:\Program Files (x86)\iTunes\iTunesHelper.exe [3724] 00000000745d0000
---- EOF - GMER 2.0 ---- OTL.txt Code:
OTL logfile created on: 29.01.2013 16:16:51 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Herzchen\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,49 Gb Available Physical Memory | 62,28% Memory free
8,21 Gb Paging File | 6,74 Gb Available in Paging File | 82,12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 164,75 Gb Total Space | 29,41 Gb Free Space | 17,85% Space Free | Partition Type: NTFS
Drive D: | 1220,50 Gb Total Space | 1193,60 Gb Free Space | 97,80% Space Free | Partition Type: NTFS
Computer Name: BASISLAGER | User Name: Herzchen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.01.29 16:16:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Herzchen\Downloads\OTL.exe
PRC - [2013.01.18 09:07:04 | 001,248,208 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2012.12.18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.12.05 18:10:34 | 002,403,352 | ---- | M] () -- C:\ProgramData\Browser Manager\2.5.976.107\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe
PRC - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2009.04.11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\conime.exe
PRC - [2008.06.11 21:43:26 | 000,640,376 | ---- | M] (Adobe Systems Inc.) -- D:\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2008.01.21 03:50:17 | 000,151,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\schtasks.exe
PRC - [2007.07.24 10:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
========== Modules (No Company Name) ==========
MOD - [2013.01.18 09:07:02 | 000,460,240 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll
MOD - [2013.01.18 09:07:01 | 004,012,496 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\pdf.dll
MOD - [2013.01.18 09:06:15 | 000,597,968 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\libglesv2.dll
MOD - [2013.01.18 09:06:15 | 000,124,368 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\libegl.dll
MOD - [2013.01.18 09:06:13 | 001,552,848 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ffmpegsumo.dll
MOD - [2012.12.05 18:10:34 | 002,403,352 | ---- | M] () -- C:\ProgramData\Browser Manager\2.5.976.107\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe
MOD - [2012.12.05 18:09:41 | 002,148,376 | ---- | M] () -- C:\ProgramData\Browser Manager\2.5.976.107\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.dll
MOD - [2012.12.02 17:15:41 | 000,070,144 | ---- | M] () -- C:\Users\Herzchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\spext.dll
MOD - [2012.05.30 19:06:48 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012.05.30 19:06:30 | 001,242,512 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
========== Services (SafeList) ==========
SRV - [2012.12.18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.12.05 18:10:34 | 002,403,352 | ---- | M] () [Auto | Running] -- C:\ProgramData\Browser Manager\2.5.976.107\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe -- (Browser Manager)
SRV - [2012.10.10 21:23:42 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.10.10 12:26:53 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV - [2012.10.10 12:25:19 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.05.29 12:09:52 | 002,143,072 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.03.30 05:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.08.15 04:46:20 | 000,284,016 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe -- (Adobe Version Cue CS4)
SRV - [2007.07.24 10:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.04.25 11:11:36 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010.11.15 23:24:16 | 000,015,672 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\regi.sys -- (regi)
DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2008.07.01 08:44:00 | 000,214,032 | ---- | M] (AMD Technologies Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\ahcix64s.sys -- (ahcix64s)
DRV:64bit: - [2008.06.27 06:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2008.01.21 03:51:07 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2008.01.21 03:47:28 | 000,046,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:64bit: - [2007.09.29 13:30:46 | 000,091,648 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID)
DRV - [2012.05.08 14:21:42 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
DRV - [2008.08.14 06:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://search.babylon.com/?affID=114350&tt=4812_3&babsrc=HP_ss&mntrId=f093fd0d000000000000002421dec62d
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?affID=114350&tt=4812_3&babsrc=HP_ss&mntrId=f093fd0d000000000000002421dec62d
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - No CLSID value found
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=114350&tt=4812_3&babsrc=SP_ss&mntrId=f093fd0d000000000000002421dec62d
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=5B7F1D18-991C-40B8-9225-945CCD0263C5&apn_sauid=0C0D9A1C-5575-4788-921D-739668AE2AB9
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_deDE463
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{58bd07eb-0ee0-4df0-8121-dc9b693373df}: C:\ProgramData\Browser Manager\2.5.976.107\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension [2012.12.07 15:14:33 | 000,000,000 | ---D | M]
[2012.12.02 17:14:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
========== Chrome ==========
CHR - homepage: hxxp://search.babylon.com/?affID=114350&tt=4812_3&babsrc=HP_ss&mntrId=f093fd0d000000000000002421dec62d
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: hxxp://search.babylon.com/?affID=114350&tt=4812_3&babsrc=HP_ss&mntrId=f093fd0d000000000000002421dec62d
CHR - Extension: No name found = C:\Users\Herzchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: No name found = C:\Users\Herzchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: No name found = C:\Users\Herzchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\
CHR - Extension: No name found = C:\Users\Herzchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2006.09.18 22:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] D:\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] D:\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8:64bit: - Extra context menu item: An vorhandene PDF-Datei anfügen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Herzchen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Linkziel in Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Herzchen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: PokerStars.eu - {07BA1DA9-F501-4796-8728-74D1B91A6CD5} - C:\Program Files (x86)\PokerStars.EU\PokerStarsUpdate.exe File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: corel.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: corel.com ([www] * in Trusted sites)
O15 - HKCU\..Trusted Domains: intervideo.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: intervideo.com ([www] * in Trusted sites)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7EE8DB3E-B5B8-4A74-8C1B-93E4F9AF9230}: NameServer = 192.168.0.1,8.8.8.8
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\25976~1.107\{c16c1~1\mngr.dll) - c:\ProgramData\Browser Manager\2.5.976.107\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Herzchen\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\Herzchen\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.04.21 14:00:11 | 000,000,000 | ---D | M] - D:\Autoplay -- [ NTFS ]
O32 - AutoRun File - [2010.04.02 13:03:16 | 003,048,072 | ---- | M] () - D:\autorun.exe -- [ NTFS ]
O32 - AutoRun File - [2010.03.29 17:24:43 | 000,000,050 | R--- | M] () - D:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.01.29 15:41:08 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.01.29 15:02:15 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\vi-VN
[2013.01.29 15:02:15 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\eu-ES
[2013.01.29 15:02:15 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\eu-ES
[2013.01.29 15:02:15 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ca-ES
[2013.01.29 15:02:15 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ca-ES
[2013.01.29 15:02:14 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\vi-VN
[2013.01.29 14:47:29 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.01.29 16:14:22 | 000,000,000 | ---- | M] () -- C:\Users\Herzchen\defogger_reenable
[2013.01.29 16:05:00 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.01.29 15:43:21 | 001,684,866 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.01.29 15:43:21 | 000,718,376 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.01.29 15:43:21 | 000,671,466 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.01.29 15:43:21 | 000,164,672 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.01.29 15:43:21 | 000,134,744 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.01.29 15:37:41 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.01.29 15:37:31 | 000,003,712 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.01.29 15:37:31 | 000,003,712 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.01.29 15:37:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.01.29 15:07:56 | 001,571,838 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.01.29 15:06:29 | 002,988,896 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.01.29 14:39:42 | 002,128,937 | ---- | M] () -- C:\Users\Herzchen\Desktop\Foto 2.JPG
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.01.29 16:14:22 | 000,000,000 | ---- | C] () -- C:\Users\Herzchen\defogger_reenable
[2012.10.26 19:20:36 | 001,571,838 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.09.03 23:41:55 | 000,069,632 | R--- | C] () -- C:\Windows\SysWow64\xmltok.dll
[2012.09.03 23:41:55 | 000,036,864 | R--- | C] () -- C:\Windows\SysWow64\xmlparse.dll
[2012.08.29 15:34:36 | 000,000,995 | ---- | C] () -- C:\Windows\eReg.dat
[2012.08.29 15:00:38 | 000,000,848 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2012.07.18 20:48:39 | 000,005,120 | ---- | C] () -- C:\Users\Herzchen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.12.31 15:25:56 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2011.12.24 15:46:07 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2011.12.24 15:45:46 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2011.12.24 15:45:24 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2011.12.19 15:04:08 | 000,000,732 | ---- | C] () -- C:\Users\Herzchen\AppData\Local\d3d9caps64.dat
========== ZeroAccess Check ==========
[2006.11.02 16:30:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2011.01.21 17:50:13 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2011.01.21 17:35:22 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.04.11 08:11:14 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008.01.21 03:50:58 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012.12.02 17:13:54 | 000,000,000 | ---D | M] -- C:\Users\Herzchen\AppData\Roaming\Babylon
[2012.10.07 17:20:16 | 000,000,000 | ---D | M] -- C:\Users\Herzchen\AppData\Roaming\DVDVideoSoft
[2012.10.07 17:19:30 | 000,000,000 | ---D | M] -- C:\Users\Herzchen\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.07.04 04:07:23 | 000,000,000 | ---D | M] -- C:\Users\Herzchen\AppData\Roaming\OpenCandy
[2012.10.26 19:22:04 | 000,000,000 | ---D | M] -- C:\Users\Herzchen\AppData\Roaming\Software4u
[2011.12.19 15:08:30 | 000,000,000 | ---D | M] -- C:\Users\Herzchen\AppData\Roaming\Telefónica
[2012.07.04 04:08:26 | 000,000,000 | ---D | M] -- C:\Users\Herzchen\AppData\Roaming\TuneUp Software
========== Purity Check ==========
< End of report > Extras.txt Code:
OTL Extras logfile created on: 29.01.2013 16:16:52 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Herzchen\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,49 Gb Available Physical Memory | 62,28% Memory free
8,21 Gb Paging File | 6,74 Gb Available in Paging File | 82,12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 164,75 Gb Total Space | 29,41 Gb Free Space | 17,85% Space Free | Partition Type: NTFS
Drive D: | 1220,50 Gb Total Space | 1193,60 Gb Free Space | 97,80% Space Free | Partition Type: NTFS
Computer Name: BASISLAGER | User Name: Herzchen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
InternetShortcut [print] -- rundll32.exe C:\Windows\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 87 5E 01 2E 2A FE CD 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0925116D-B0C7-4B20-A9C8-8670CDB77106}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{0EACFC2C-B60D-4753-A25F-2D2F026AD3D6}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{0EDFBC48-3313-42FB-804C-1B7A336F447E}" = rport=445 | protocol=6 | dir=out | app=system |
"{137D3F6E-EC67-4EB0-90F1-964DD33AEC3A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1C264855-E63F-4AA4-B8DE-9227AB894E48}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{1FC6DE7F-8182-4A6B-B343-1C5D5E084F32}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2DD6081A-7E53-46CA-983B-486901C1A99E}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3FEE8A70-1584-4EB6-9668-25FD05CDEE31}" = rport=139 | protocol=6 | dir=out | app=system |
"{423A9AF7-36EB-43F8-9D14-6C42BFACE4BF}" = rport=137 | protocol=17 | dir=out | app=system |
"{43B2BDB7-3C4A-4612-A2BF-4FE5F296058B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4CA3F155-DA3F-42B2-BA3D-B8A693325C0A}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{50415946-626E-40BF-B32C-5D2DC26C7EDB}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{55E811BF-73CD-4B4A-9A5A-FAE2A2316ED7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{6C770C96-014F-435D-A247-D5A6F9D5E991}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6C8B389C-0B46-4159-A922-00784D180E52}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6E62B7ED-CB93-4F41-8C9E-738B99479257}" = lport=10243 | protocol=6 | dir=in | app=system |
"{802DD5D0-EA30-421D-9C68-767F9658866F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{83D69F3B-E991-4B4A-897E-CE9DC873976E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{84F41BBC-21AC-4717-ADD9-40C4D68BCA28}" = lport=139 | protocol=6 | dir=in | app=system |
"{8804F9EF-E67E-4CED-8E48-B25F1B709513}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8EB8C011-EA6B-4FAE-9CCA-FA433224AF8E}" = rport=138 | protocol=17 | dir=out | app=system |
"{948429EB-B723-450A-A142-50FB7A341AD1}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{98AE2A01-BE8D-4313-8381-EDD5FF5F0797}" = lport=138 | protocol=17 | dir=in | app=system |
"{A4E00D8D-D527-4FCC-B499-B5E3D8842CA9}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{B5E20F9A-ED04-4E85-BDD4-8A8D76BA4576}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{BB235248-AFDD-4567-986B-D3EAF5A285C1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{C06A1926-4B61-4635-A1EA-CB2855A392BA}" = lport=137 | protocol=17 | dir=in | app=system |
"{D7050CB2-3DD3-41D3-88B9-B8A145B6951E}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{DEE26011-C430-437D-87EE-C0D37E395E1A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E030A802-7BED-4FE1-ACA8-FAB17DED6E7A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E6B7AB9A-2950-45AB-AF08-1C6390E9937C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E998853A-0E33-40DD-B709-EA061B9BD08B}" = lport=445 | protocol=6 | dir=in | app=system |
"{F9FA3DEA-31B0-412B-AA69-61B3756A7DA7}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{FC9A3D88-91A9-44A1-B119-2058E588CF7B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{033D10F6-4958-420C-A0B9-5479BB94DA27}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{061A8114-B7D6-4678-8071-7E765BBFFF49}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{17CE8588-BCD3-42C6-BF3D-91A8423DB40E}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{1AFFBBC8-A0B8-4C83-9138-63BEEFE7D36E}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{205D4B1D-F47B-4681-AAD2-B896DAD8FEC8}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{22038800-5519-4E5A-B79A-095A370ED6E9}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{2E315945-7481-43F0-9872-EB9994C5B1AE}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{39B17692-4F2D-4DF5-A6F2-31FD3BAF8B6E}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{3A4E7557-A1A7-4A7C-B2B7-E3782B6BAA92}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3C83B862-22D4-4187-BCC3-E5D483BB226C}" = protocol=6 | dir=out | app=system |
"{3FE5DD4B-C231-420A-BFD3-8E6C51F75670}" = protocol=6 | dir=in | app=d:\tom clancy's splinter cell conviction\src\system\gu.exe |
"{471455FE-0C47-40C6-A6BA-36603615459E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{479296B4-F7A3-47C0-9AF5-B65F4D33D0C9}" = protocol=6 | dir=in | app=d:\idevice manager\software4u.idevicemanager.exe |
"{4E429141-2238-4EEC-90A5-16C03A46D24E}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{6E209E49-9083-4A10-AF30-E7C5A41B1A8E}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{7C107856-E508-4A5E-963D-6B8ABC85605B}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{819AFA8F-FB1A-436B-9506-CC8190DDB8ED}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{8FABBD77-F958-4F58-A454-BCEFAE4BDA3E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{93A1AB46-3B9F-4916-A45F-5735B28E23FD}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{96273C52-5658-4C57-88EB-90C3139BE5B1}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9759F2F8-A927-4E53-837A-088683EBB805}" = protocol=17 | dir=in | app=d:\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{97EAF46D-98C3-4DC0-8151-D2D104E0F624}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{98651290-AEF4-4620-B25D-BD749C1F8169}" = protocol=17 | dir=in | app=d:\tom clancy's splinter cell conviction\src\system\gu.exe |
"{A1135F23-AD9F-4A63-A730-593EB3DA9EB5}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A1AF1DE9-2804-422D-A608-425641EB7DC8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{A60F5688-1149-4017-9AE8-4E93632EBD5F}" = protocol=6 | dir=in | app=d:\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{AA41F950-320F-466B-8FA8-AC3ED91F4F34}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AABC3BB6-308F-425E-90A3-F6704B6C1289}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{AD35A598-7620-4048-B740-503261F8F19B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{ADCFD34E-6A85-41AB-9587-3B8B101E5C43}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{B28CF1DC-6745-4B7F-B6C6-F8593A0DEB37}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B6E1B303-55C4-4F5B-BCA3-74BD4EE129AE}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{C1134623-5C74-454F-AF80-456F682158E6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CAF07322-8E40-41BA-BC1B-66769762E1D5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EB081CD7-44A3-47E1-9639-46D13C261343}" = protocol=17 | dir=in | app=d:\idevice manager\software4u.idevicemanager.exe |
"{EC3A5215-D5BF-416F-81D3-18F0E3FF64F4}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{EDD9376A-02F1-4267-B243-9D8C79963C8F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F53AB695-A3CF-40ED-A827-C7E35BAB64AC}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{F627A7F7-FCBE-4A0A-BC14-98613FD33B4A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{F8C74914-625E-4CC1-AA10-FD0B5C3AFA83}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F9C7EFA6-2ED5-42BD-B4CD-768684E28971}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{2AB4E444-EED8-478C-BBB0-4ADB356371AA}C:\program files (x86)\corel\dvd9\windvd.exe" = protocol=6 | dir=in | app=c:\program files (x86)\corel\dvd9\windvd.exe |
"TCP Query User{821B9BCD-396B-4DFD-B986-3440A79F9012}C:\program files (x86)\ubisoft\splinter cell pandora tomorrow\pandora.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\splinter cell pandora tomorrow\pandora.exe |
"TCP Query User{9208993D-0038-45A2-A8A7-6C82F1CB9D0F}C:\program files (x86)\corel\dvd9\windvd.exe" = protocol=6 | dir=in | app=c:\program files (x86)\corel\dvd9\windvd.exe |
"TCP Query User{C0FFD717-5898-49D8-BBA4-3403FCA4A36D}D:\tom clancy's splinter cell conviction\src\system\uplaybrowser.exe" = protocol=6 | dir=in | app=d:\tom clancy's splinter cell conviction\src\system\uplaybrowser.exe |
"TCP Query User{C74C0A1E-EE4F-452A-96AB-002659DB2BE3}D:\tom clancy's splinter cell conviction\src\system\conviction_game.exe" = protocol=6 | dir=in | app=d:\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"TCP Query User{D36256E0-38E6-4A1A-A2EB-1A9A7ABC6CFD}C:\program files (x86)\corel\windvd11\windvd.exe" = protocol=6 | dir=in | app=c:\program files (x86)\corel\windvd11\windvd.exe |
"UDP Query User{0EB99A89-CBE7-4E91-9703-D82D0025C68B}D:\tom clancy's splinter cell conviction\src\system\conviction_game.exe" = protocol=17 | dir=in | app=d:\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"UDP Query User{636AF192-5D84-40F7-9744-81114E5F2936}C:\program files (x86)\corel\dvd9\windvd.exe" = protocol=17 | dir=in | app=c:\program files (x86)\corel\dvd9\windvd.exe |
"UDP Query User{728AFEEE-E6BB-46B5-A87F-49F8E486FFA4}C:\program files (x86)\corel\dvd9\windvd.exe" = protocol=17 | dir=in | app=c:\program files (x86)\corel\dvd9\windvd.exe |
"UDP Query User{B93DE7AF-FACA-4E8D-94ED-7DEB3E7150E9}C:\program files (x86)\corel\windvd11\windvd.exe" = protocol=17 | dir=in | app=c:\program files (x86)\corel\windvd11\windvd.exe |
"UDP Query User{C8D6FE59-CB9D-4957-A1D8-74DD87DA1D97}D:\tom clancy's splinter cell conviction\src\system\uplaybrowser.exe" = protocol=17 | dir=in | app=d:\tom clancy's splinter cell conviction\src\system\uplaybrowser.exe |
"UDP Query User{D6145BAC-A789-4131-A27B-AF6BB39F8BD5}C:\program files (x86)\ubisoft\splinter cell pandora tomorrow\pandora.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\splinter cell pandora tomorrow\pandora.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{63B4D80D-7BAC-4D1D-B9B6-27FF54197982}" = Regi
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"NVIDIA Drivers" = NVIDIA Drivers
"VLC media player" = VLC media player 2.1.0-git
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03DEEAD2-F3B7-45BF-9006-A25D015F00D2}" = Adobe Flash Player 10 Plugin
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = Browser Manager
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3A6829EF-0791-4FDD-9382-C690DD0821B9}" = Adobe Flash Player 10 ActiveX
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{47C6F987-685A-41AE-B092-E75B277AEE39}" = Adobe Flash CS4 Extension - Flash Lite STI others
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6D8DDB4A-C263-40DE-BA16-AFDAD159D59A}" = Tom Clancy's Splinter Cell Conviction
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A128921B-D03F-4BFB-8141-C365AA48D660}" = Adobe Setup
"{A2881E09-38DB-4F79-9135-00FDA01768A7}" = Adobe Creative Suite 4 Design Premium
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.5) - Deutsch
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD3374D3-C2E6-42B7-A80B-E850B6886246}" = Adobe Flash CS4 STI-other
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE026CFE-73FE-4FED-9D5F-2C8D4DB512B0}" = TuneUp Utilities Language Pack (de-DE)
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E3993D46-AE3F-402E-9F9D-EEBDFBEC3564}" = Corel WinDVD 9
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe_55230b0b70661df0f212e88f0b655f7" = Adobe Creative Suite 4 Design Premium
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.33.1005
"Google Chrome" = Google Chrome
"InstallShield_{E3993D46-AE3F-402E-9F9D-EEBDFBEC3564}" = Corel WinDVD 9
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"PokerStars.eu" = PokerStars.eu
"PROHYBRIDR" = 2007 Microsoft Office system
"TuneUp Utilities 2012" = TuneUp Utilities 2012
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"InstallShield_{E3993D46-AE3F-402E-9F9D-EEBDFBEC3564}" = Corel WinDVD 9
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 29.01.2013 00:33:39 | Computer Name = Basislager | Source = Bonjour Service | ID = 100
Description =
Error - 29.01.2013 00:33:39 | Computer Name = Basislager | Source = Bonjour Service | ID = 100
Description =
Error - 29.01.2013 00:33:39 | Computer Name = Basislager | Source = Bonjour Service | ID = 100
Description =
Error - 29.01.2013 09:39:37 | Computer Name = Basislager | Source = WinMgmt | ID = 10
Description =
Error - 29.01.2013 09:39:51 | Computer Name = Basislager | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung chrome.exe, Version 24.0.1312.56, Zeitstempel
0x50f8e9e4, fehlerhaftes Modul ntdll.dll, Version 6.0.6001.18538, Zeitstempel 0x4cb733e1,
Ausnahmecode 0xc0000374, Fehleroffset 0x000ababb, Prozess-ID 0xc1c, Anwendungsstartzeit
01cdfe261a225971.
Error - 29.01.2013 09:45:54 | Computer Name = Basislager | Source = VSS | ID = 8194
Description =
Error - 29.01.2013 10:06:44 | Computer Name = Basislager | Source = WinMgmt | ID = 10
Description =
Error - 29.01.2013 10:07:19 | Computer Name = Basislager | Source = WinMgmt | ID = 10
Description =
Error - 29.01.2013 10:10:30 | Computer Name = Basislager | Source = ESENT | ID = 215
Description = WinMail (3556) WindowsMail0: Die Sicherung wurde abgebrochen, weil
sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen
wurde.
Error - 29.01.2013 10:10:31 | Computer Name = Basislager | Source = ESENT | ID = 215
Description = WinMail (3828) WindowsMail0: Die Sicherung wurde abgebrochen, weil
sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen
wurde.
Error - 29.01.2013 10:38:51 | Computer Name = Basislager | Source = WinMgmt | ID = 10
Description =
[ OSession Events ]
Error - 30.12.2012 06:27:07 | Computer Name = Basislager | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 171837
seconds with 420 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 12.09.2012 15:40:13 | Computer Name = Herzchen-PC | Source = cdrom | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\CdRom0.
Error - 12.09.2012 15:40:19 | Computer Name = Herzchen-PC | Source = cdrom | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\CdRom0.
Error - 12.09.2012 15:40:26 | Computer Name = Herzchen-PC | Source = cdrom | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\CdRom0.
Error - 12.09.2012 15:40:31 | Computer Name = Herzchen-PC | Source = cdrom | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\CdRom0.
Error - 12.09.2012 15:40:35 | Computer Name = Herzchen-PC | Source = cdrom | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\CdRom0.
Error - 13.09.2012 07:28:15 | Computer Name = Herzchen-PC | Source = HTTP | ID = 15016
Description =
Error - 13.09.2012 07:28:57 | Computer Name = Herzchen-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 14.09.2012 06:12:38 | Computer Name = Herzchen-PC | Source = HTTP | ID = 15016
Description =
Error - 14.09.2012 06:13:15 | Computer Name = Herzchen-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 15.09.2012 03:34:40 | Computer Name = Herzchen-PC | Source = HTTP | ID = 15016
Description =
[ TuneUp Events ]
Error - 03.11.2012 04:54:17 | Computer Name = Basislager | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 03.11.2012 04:54:17 | Computer Name = Basislager | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 08.11.2012 09:46:02 | Computer Name = Basislager | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 08.11.2012 09:46:02 | Computer Name = Basislager | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
< End of report > ich hoffe, ich hab jetzt alles richtig gemacht. |