Hallo,
hier einmal JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.7.2 (03.15.2013:1)
OS: Windows 7 Professional x86
Ran by **** on 21.03.2013 at 19:45:23,35
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] hkey_local_machine\software\babylon
Successfully deleted: [Registry Key] hkey_current_user\software\softonic
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\escort.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\prod.cap
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasmancs
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\Users\****\AppData\Roaming\pdfforge"
Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted: [File] C:\Users\****\AppData\Roaming\mozilla\firefox\profiles\lkhmbixr.default\user.js
Successfully deleted: [File] C:\Users\****\AppData\Roaming\mozilla\firefox\profiles\lkhmbixr.default\searchplugins\askcom.xml
Successfully deleted the following from C:\Users\****\AppData\Roaming\mozilla\firefox\profiles\lkhmbixr.default\prefs.js
user_pref("browser.search.defaultengine", "Ask.com");
user_pref("browser.search.defaultenginename", "Ask.com");
user_pref("browser.search.order.1", "Ask.com");
user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
user_pref("extensions.BabylonToolbar_i.babExt", "");
user_pref("extensions.BabylonToolbar_i.babTrack", "affID=101641");
user_pref("extensions.BabylonToolbar_i.hardId", "163143cf000000000000001eec0a03f9");
user_pref("extensions.BabylonToolbar_i.id", "163143cf000000000000001eec0a03f9");
user_pref("extensions.BabylonToolbar_i.instlDay", "15374");
user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.178:24:50");
user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
user_pref("extensions.toolbar@ask.com.install-event-fired", true);
Emptied folder: C:\Users\****\AppData\Roaming\mozilla\firefox\profiles\lkhmbixr.default\minidumps [112 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.03.2013 at 19:50:15,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ hier die Adwcleaner[s1]:
AdwCleaner Logfile:
AdwCleaner Logfile: Code:
# AdwCleaner v2.115 - Datei am 21/03/2013 um 21:32:56 erstellt
# Aktualisiert am 17/03/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzer : **** - LENOVO
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\****\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
Ordner Gelöscht : C:\Users\****\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\****\AppData\Roaming\OCS
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
***** [Internet Browser] *****
-\\ Internet Explorer v10.0.9200.16521
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.startfenster.com --> hxxp://www.google.com
-\\ Mozilla Firefox v19.0.2 (de)
Datei : C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\lkhmbixr.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\k2m9fqc1.default\prefs.js
[OK] Die Datei ist sauber.
-\\ Opera v [Version kann nicht ermittelt werden]
Datei : C:\Users\****\AppData\Roaming\Opera\Opera\operaprefs.ini
Gelöscht : Home URL=hxxp://www.startfenster.com
*************************
AdwCleaner[R1].txt - [2031 octets] - [21/03/2013 19:56:08]
AdwCleaner[R2].txt - [2091 octets] - [21/03/2013 19:58:33]
AdwCleaner[S1].txt - [2060 octets] - [21/03/2013 21:32:56]
########## EOF - C:\AdwCleaner[S1].txt - [2120 octets] ########## --- --- ---
--- --- ---
[/CODE]
die neue OTL:
OTL Logfile: Code:
OTL logfile created on: 21.03.2013 21:42:50 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\****\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16521)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 1,17 Gb Available Physical Memory | 58,95% Memory free
3,98 Gb Paging File | 2,99 Gb Available in Paging File | 75,12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 143,95 Gb Total Space | 46,12 Gb Free Space | 32,04% Space Free | Partition Type: NTFS
Drive F: | 1863,01 Gb Total Space | 1061,72 Gb Free Space | 56,99% Space Free | Partition Type: NTFS
Drive H: | 931,51 Gb Total Space | 334,72 Gb Free Space | 35,93% Space Free | Partition Type: NTFS
Drive I: | 931,51 Gb Total Space | 291,25 Gb Free Space | 31,27% Space Free | Partition Type: NTFS
Drive J: | 232,83 Gb Total Space | 28,84 Gb Free Space | 12,39% Space Free | Partition Type: FAT32
Computer Name: LENOVO | User Name: **** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\****\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\dradio-Recorder\phonostarTimer.exe ()
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\MARKEMENT\PCSUITE INSPECTOR\inspectorsvc.exe (Markement)
PRC - C:\Program Files\MARKEMENT\PCSUITE DEFRAG\pcsuitedefragsvc.exe (MARKEMENT)
PRC - C:\Program Files\1&1 Surf-Stick\AssistantServices.exe ()
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - C:\Program Files\FRITZ!Fernzugang\nwtsrv.exe (AVM Berlin)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Windows\vsnp325.exe ()
PRC - C:\Windows\tsnp325.exe ()
PRC - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\dradio-Recorder\phonostarTimer.exe ()
MOD - C:\Program Files\Notepad++\NppShell_05.dll ()
MOD - C:\Program Files\FILEminimizer Pictures\FILEMShell.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Windows\vsnp325.exe ()
MOD - C:\Windows\tsnp325.exe ()
========== Services (SafeList) ==========
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TomTomHOMEService) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (PCSUITEINSPECTORSVC) -- C:\Program Files\MARKEMENT\PCSUITE INSPECTOR\inspectorsvc.exe (Markement)
SRV - (PCSUITEDFRGSVC) -- C:\Program Files\MARKEMENT\PCSUITE DEFRAG\pcsuitedefragsvc.exe (MARKEMENT)
SRV - (WAS) -- C:\Windows\System32\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (W3SVC) -- C:\Windows\System32\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (AppHostSvc) -- C:\Windows\System32\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV - (UI Assistant Service) -- C:\Program Files\1&1 Surf-Stick\AssistantServices.exe ()
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (rpcapd) -- C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (nwtsrv) -- C:\Program Files\FRITZ!Fernzugang\nwtsrv.exe (AVM Berlin)
SRV - (certsrv) -- C:\Program Files\FRITZ!Fernzugang\certsrv.exe (AVM Berlin)
SRV - (avmike) -- C:\Program Files\FRITZ!Fernzugang\avmike.exe (AVM Berlin)
SRV - (O&O DriveLED) -- C:\Program Files\OO Software\DriveLED\oodlag.exe (O&O Software GmbH)
SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (EPSON_EB_RPCV4_01) -- C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
SRV - (EPSON_PM_RPCV4_01) -- C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
========== Driver Services (SafeList) ==========
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (tbhsd) -- C:\Windows\System32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (VBoxDrv) -- C:\Windows\System32\drivers\VBoxDrv.sys (Oracle Corporation)
DRV - (VBoxNetFlt) -- C:\Windows\System32\drivers\VBoxNetFlt.sys (Oracle Corporation)
DRV - (VBoxNetAdp) -- C:\Windows\System32\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV - (VBoxUSBMon) -- C:\Windows\System32\drivers\VBoxUSBMon.sys (Oracle Corporation)
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (AVEO) -- C:\Windows\System32\drivers\AVEOdcnt.sys (AVEO Corp)
DRV - (NPF) -- C:\Windows\System32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (ss_mdm) -- C:\Windows\System32\drivers\ss_mdm.sys (MCCI Corporation)
DRV - (ss_bus) -- C:\Windows\System32\drivers\ss_bus.sys (MCCI Corporation)
DRV - (ss_mdfl) -- C:\Windows\System32\drivers\ss_mdfl.sys (MCCI Corporation)
DRV - (NWIM) -- C:\Windows\System32\drivers\avmnwim.sys (AVM Berlin)
DRV - (avmaura) -- C:\Windows\System32\drivers\avmaura.sys (AVM Berlin)
DRV - (ATSwpWDF) -- C:\Windows\System32\drivers\ATSwpWDF.sys (AuthenTec, Inc.)
DRV - (ZTEusbser6k) -- C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) -- C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) -- C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (16245902) -- C:\Windows\System32\drivers\16245902.sys (Kaspersky Lab)
DRV - (setup_9.0.0.722_25.12.2010_06-04drv) -- C:\Windows\System32\drivers\1624590.sys (Kaspersky Lab)
DRV - (OODrvled) -- C:\Windows\System32\drivers\OODrvled.sys (O&O Software GmbH)
DRV - (16245901) -- C:\Windows\System32\drivers\16245901.sys (Kaspersky Lab)
DRV - (Serial) -- C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (netw5v32) -- C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (SCDEmu) -- C:\Windows\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (USBPNPA) -- C:\Windows\System32\drivers\CM108.sys (C-Media Inc)
DRV - (SNP325) -- C:\Windows\System32\drivers\snp325.sys (Sonix Co. Ltd.)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (Ser2pl) -- C:\Windows\System32\drivers\ser2pl.sys (Prolific Technology Inc.)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (StarOpen) -- C:\Windows\System32\drivers\StarOpen.sys ()
DRV - (DCamUSBEMPIA) -- C:\Windows\System32\drivers\emDevice.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBEMPIA) -- C:\Windows\System32\drivers\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) -- C:\Windows\System32\drivers\emScan.sys (eMPIA Technology, Inc.)
DRV - (AVMUNET) -- C:\Windows\System32\drivers\avmunet.sys (AVM GmbH)
DRV - (pfc) -- C:\Windows\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (Wdm1) -- C:\Windows\System32\drivers\usbbc.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6C AF D5 88 62 89 CB 01 [binary data]
IE - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\..\SearchScopes\{374A2C4B-AA8C-4E50-889F-CBC74C34B436}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ANT&o=102823&src=crm&q={searchTerms}&locale=&apn_ptnrs=4P&apn_dtid=YYYYYYYYDE&apn_uid=f01f38ed-0820-44d8-b72d-fe21fffd47a4&apn_sauid=B1F6848F-A995-4D07-81E6-008C41D7A092
IE - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = fritz.box;192.168.178.1;<local>
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: 2020Player_IKEA%402020Technologies.com:5.0.93.0
FF - prefs.js..extensions.enabledAddons: fb_add_on%40avm.de:1.6.3
FF - prefs.js..extensions.enabledAddons: %7Bc50ca3c4-5656-43c2-a061-13e717f73fc8%7D:4.2.5
FF - prefs.js..extensions.enabledAddons: %7B19503e42-ca3c-4c27-b1e2-9cdb2170ee34%7D:1.5.4.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.3.4
FF - prefs.js..extensions.enabledItems: {71328583-3CA7-4809-B4BA-570A85818FBB}:0.6.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:4.0.1
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@doubletwist.com/NPPodcast: File not found
FF - HKCU\Software\MozillaPlugins\@phonostar.de/phonostar: C:\Program Files\dradio-Recorder\npphonostarDetectNP.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.11 21:58:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.03.11 21:58:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.3\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.3\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 5.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 5.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.11 21:58:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.03.11 21:58:05 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.3\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.3\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.02.22 19:45:40 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.02.22 19:45:43 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{1cfcaf72-e6f3-412a-bc20-7bcd7579014b}: C:\Program Files\1&1\1&1 MultiMessenger\ThunderbirdSyncProxy [2012.01.27 19:11:36 | 000,000,000 | ---D | M]
[2012.01.26 07:45:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Extensions
[2012.01.26 07:45:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Extensions\{718e30fb-e89b-41dd-9da7-e25a45638b28}
[2013.03.11 21:17:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\lkhmbixr.default\extensions
[2012.03.04 20:29:05 | 000,000,000 | ---D | M] (20-20 3D Viewer - IKEA) -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\lkhmbixr.default\extensions\2020Player_IKEA@2020Technologies.com
[2012.05.19 07:01:54 | 000,000,000 | ---D | M] ("FRITZ!Box AddOn") -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\lkhmbixr.default\extensions\fb_add_on@avm.de
[2013.03.07 07:39:03 | 000,348,483 | ---- | M] () (No name found) -- C:\Users\****\AppData\Roaming\mozilla\firefox\profiles\lkhmbixr.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
[2013.01.12 18:28:01 | 000,316,778 | ---- | M] () (No name found) -- C:\Users\****\AppData\Roaming\mozilla\firefox\profiles\lkhmbixr.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}.xpi
[2013.03.11 21:58:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013.03.11 21:58:15 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.12.14 10:45:24 | 000,170,080 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2013.03.11 21:58:11 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.03.11 21:58:11 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013.03.11 21:58:11 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2013.03.11 21:58:11 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.03.11 21:58:11 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.03.11 21:58:11 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (WebCGMHlprObj Class) - {56B38F40-4E70-11d4-A076-0080AD86BA2F} - C:\Windows\System32\cgmopenbho.dll (CGM Open Consortium, Inc.)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [snp325] C:\Windows\vsnp325.exe ()
O4 - HKLM..\Run: [tsnp325] C:\Windows\tsnp325.exe ()
O4 - HKU\S-1-5-21-3968005663-3115476455-970186232-1001..\Run: [] File not found
O4 - HKU\S-1-5-21-3968005663-3115476455-970186232-1001..\Run: [dradio-RecorderTimer] C:\Program Files\dradio-Recorder\phonostarTimer.exe ()
O4 - HKU\S-1-5-21-3968005663-3115476455-970186232-1001..\Run: [EPSON BX300F Series (Kopie 1)] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIEJE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-3968005663-3115476455-970186232-1001..\Run: [Note Manager] C:\Program Files\DGP1000\Note Manager.exe (Targa GmbH)
O4 - HKU\S-1-5-21-3968005663-3115476455-970186232-1001..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\..Trusted Domains: fritz.box ([]* in Local intranet)
O15 - HKU\S-1-5-21-3968005663-3115476455-970186232-1001\..Trusted Ranges: Range1 ([*] in Local intranet)
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} hxxp://esupport.epson-europe.com/selftest/de/Prg/ESTPTest.cab (EPSON Web Printer-SelfTest Control Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Java Plug-in 10.17.2)
O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Java Plug-in 1.7.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Java Plug-in 1.7.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A1A21165-C522-4E75-AA94-C55205D36929}: DhcpNameServer = 192.168.179.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AFDE7349-231E-4CB5-91E1-579B75766012}: DhcpNameServer = 192.168.178.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011.05.10 09:16:02 | 000,000,084 | ---- | M] () - F:\Autoruninf.blockiert -- [ NTFS ]
O32 - AutoRun File - [2007.08.09 02:49:08 | 000,000,038 | ---- | M] () - H:\autorun.inf.blockiert -- [ NTFS ]
O32 - AutoRun File - [2009.10.09 15:27:12 | 000,000,089 | ---- | M] () - I:\Autorun.inf.blockiert -- [ NTFS ]
O33 - MountPoints2\{00211ef0-64b6-11e2-aa6b-001eec0a03f9}\Shell - "" = AutoRun
O33 - MountPoints2\{00211ef0-64b6-11e2-aa6b-001eec0a03f9}\Shell\AutoRun\command - "" = J:\preinst.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\Install.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.03.21 19:45:13 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013.03.21 19:44:59 | 000,000,000 | ---D | C] -- C:\JRT
[2013.03.21 19:43:55 | 000,549,920 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\****\Desktop\JRT.exe
[2013.03.20 22:18:02 | 000,000,000 | ---D | C] -- C:\Users\****\Documents\Podcasts
[2013.03.20 22:16:33 | 000,000,000 | ---D | C] -- C:\Users\****\Documents\Aufnahmen
[2013.03.20 22:16:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dradio-Recorder
[2013.03.20 22:16:16 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\phonostar GmbH
[2013.03.20 22:16:11 | 000,000,000 | ---D | C] -- C:\Program Files\dradio-Recorder
[2013.03.20 20:08:10 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\****\Desktop\TDSSKiller.exe
[2013.03.20 17:30:28 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\****\Desktop\aswMBR.exe
[2013.03.20 14:13:59 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
[2013.03.20 14:13:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
[2013.03.20 14:13:51 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\Notepad++
[2013.03.20 14:13:51 | 000,000,000 | ---D | C] -- C:\Program Files\Notepad++
[2013.03.17 18:18:50 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\iSpy
[2013.03.17 18:18:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iSpy
[2013.03.17 18:18:30 | 000,000,000 | ---D | C] -- C:\Program Files\iSpy
[2013.03.17 17:39:09 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\****\Desktop\OTL.exe
[2013.03.17 11:12:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vision Objects
[2013.03.17 10:53:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Note Manager
[2013.03.17 10:53:49 | 000,000,000 | ---D | C] -- C:\Program Files\DGP1000
[2013.03.17 08:01:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileEdit
[2013.03.17 08:01:36 | 000,000,000 | ---D | C] -- C:\Program Files\FileEdit
[2013.03.17 08:01:25 | 001,069,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCOMCTL.OCX
[2013.03.17 08:01:25 | 000,218,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RICHTX32.OCX
[2013.03.16 19:03:01 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\SUPERAntiSpyware.com
[2013.03.16 19:02:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2013.03.16 19:02:27 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2013.03.16 19:02:27 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2013.03.16 18:48:25 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\Malwarebytes
[2013.03.16 18:47:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.03.16 18:47:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.03.16 18:47:34 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.03.16 18:47:34 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.03.16 18:47:22 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Local\Programs
[2013.03.15 18:48:18 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MWconn
[2013.03.15 16:59:14 | 000,000,000 | ---D | C] -- C:\Windows\System32\Wat
[2013.03.15 16:40:52 | 002,706,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.03.15 16:40:52 | 000,745,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2013.03.15 16:40:52 | 000,493,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.03.15 16:40:52 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\elshyph.dll
[2013.03.15 16:40:52 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2013.03.15 16:40:52 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2013.03.15 16:40:52 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2013.03.15 16:40:52 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2013.03.15 16:40:52 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.03.15 16:40:52 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2013.03.15 16:40:52 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2013.03.15 16:40:52 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2013.03.15 16:40:52 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013.03.15 16:40:52 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2013.03.15 16:40:52 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2013.03.15 16:40:52 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.03.15 16:40:52 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2013.03.15 16:40:52 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2013.03.15 16:40:51 | 002,877,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.03.15 16:40:51 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.03.15 16:40:51 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2013.03.15 16:40:51 | 000,719,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
[2013.03.15 16:40:51 | 000,629,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2013.03.15 16:40:51 | 000,391,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.03.15 16:40:51 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2013.03.15 16:40:51 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2013.03.15 16:40:51 | 000,242,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2013.03.15 16:40:51 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.03.15 16:40:51 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2013.03.15 16:40:51 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013.03.15 16:40:51 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2013.03.15 16:40:51 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013.03.15 16:40:51 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2013.03.15 16:40:51 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013.03.15 16:40:51 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013.03.15 16:40:51 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2013.03.15 16:39:01 | 002,284,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msmpeg2vdec.dll
[2013.03.15 16:39:01 | 001,158,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2013.03.15 16:39:01 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
[2013.03.15 16:39:01 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2013.03.15 16:39:01 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013.03.15 16:39:01 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013.03.15 16:39:01 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013.03.15 16:39:01 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013.03.15 16:39:01 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013.03.15 16:39:01 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013.03.15 16:39:01 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013.03.15 16:39:01 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013.03.15 16:39:01 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013.03.15 16:39:00 | 003,419,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2013.03.15 16:39:00 | 001,988,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2013.03.15 16:39:00 | 001,504,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
[2013.03.15 16:39:00 | 001,247,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2013.03.15 16:39:00 | 001,080,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2013.03.15 16:39:00 | 000,604,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2013.03.15 16:39:00 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
[2013.03.15 16:39:00 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2013.03.15 16:39:00 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2013.03.15 16:39:00 | 000,207,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
[2013.03.15 16:39:00 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAnimation.dll
[2013.03.15 16:39:00 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2013.03.15 15:45:04 | 000,105,088 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\ZTEusbser6k.sys
[2013.03.15 15:45:04 | 000,105,088 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\ZTEusbnmea.sys
[2013.03.15 15:45:04 | 000,105,088 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys
[2013.03.15 15:44:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1&1 Surf-Stick
[2013.03.15 15:44:41 | 000,000,000 | ---D | C] -- C:\Program Files\1&1 Surf-Stick
[2013.03.15 15:38:01 | 000,009,216 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\massfilter.sys
[2013.03.15 13:48:56 | 000,000,000 | ---D | C] -- C:\ProgramData\MDMA
[2013.03.13 23:57:21 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usb8023.sys
[2013.03.11 21:58:04 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.03.08 14:46:40 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013.03.08 14:46:11 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013.02.28 06:42:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013.02.28 06:41:50 | 000,861,088 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2013.02.28 06:41:14 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013.02.28 06:41:13 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013.02.22 19:45:39 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.03.21 21:44:26 | 000,013,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.03.21 21:44:26 | 000,013,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.03.21 21:41:42 | 000,724,332 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.03.21 21:41:42 | 000,673,938 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.03.21 21:41:42 | 000,154,274 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.03.21 21:41:42 | 000,125,854 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.03.21 21:36:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.03.21 21:36:45 | 1603,084,288 | -HS- | M] () -- C:\hiberfil.sys
[2013.03.21 19:55:35 | 000,609,993 | ---- | M] () -- C:\Users\****\Desktop\adwcleaner.exe
[2013.03.21 19:43:56 | 000,549,920 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\****\Desktop\JRT.exe
[2013.03.20 22:16:17 | 000,001,024 | ---- | M] () -- C:\Users\****\Desktop\dradio-Recorder.lnk
[2013.03.20 17:29:43 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\****\Desktop\aswMBR.exe
[2013.03.17 18:18:34 | 000,002,569 | ---- | M] () -- C:\Users\Public\Desktop\iSpy.lnk
[2013.03.17 17:39:48 | 000,000,000 | ---- | M] () -- C:\Users\****\defogger_reenable
[2013.03.17 14:52:23 | 000,377,856 | ---- | M] () -- C:\Users\****\Desktop\gmer_2.1.19155.exe
[2013.03.17 14:50:57 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\****\Desktop\OTL.exe
[2013.03.17 14:50:40 | 000,050,477 | ---- | M] () -- C:\Users\****\Desktop\Defogger.exe
[2013.03.17 12:55:27 | 000,000,218 | ---- | M] () -- C:\Users\****\.recently-used.xbel
[2013.03.17 11:12:43 | 000,001,106 | ---- | M] () -- C:\Users\Public\Desktop\MyScript Notes Lite.lnk
[2013.03.17 10:53:57 | 000,001,866 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NewShortcut3.lnk
[2013.03.17 10:53:55 | 000,002,675 | ---- | M] () -- C:\Users\Public\Desktop\Note Manager.lnk
[2013.03.16 19:02:30 | 000,001,931 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013.03.16 18:47:36 | 000,001,037 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.16 10:42:42 | 209,665,740 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013.03.15 17:04:20 | 000,322,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.03.15 16:40:52 | 002,706,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.03.15 16:40:52 | 000,745,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2013.03.15 16:40:52 | 000,493,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.03.15 16:40:52 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\elshyph.dll
[2013.03.15 16:40:52 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2013.03.15 16:40:52 | 000,158,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2013.03.15 16:40:52 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2013.03.15 16:40:52 | 000,138,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2013.03.15 16:40:52 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.03.15 16:40:52 | 000,117,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2013.03.15 16:40:52 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2013.03.15 16:40:52 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2013.03.15 16:40:52 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013.03.15 16:40:52 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2013.03.15 16:40:52 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2013.03.15 16:40:52 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.03.15 16:40:52 | 000,038,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2013.03.15 16:40:52 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2013.03.15 16:40:51 | 002,877,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.03.15 16:40:51 | 001,441,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.03.15 16:40:51 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2013.03.15 16:40:51 | 000,719,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
[2013.03.15 16:40:51 | 000,629,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2013.03.15 16:40:51 | 000,391,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.03.15 16:40:51 | 000,361,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2013.03.15 16:40:51 | 000,357,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2013.03.15 16:40:51 | 000,242,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2013.03.15 16:40:51 | 000,232,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.03.15 16:40:51 | 000,226,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2013.03.15 16:40:51 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013.03.15 16:40:51 | 000,073,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2013.03.15 16:40:51 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013.03.15 16:40:51 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2013.03.15 16:40:51 | 000,042,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013.03.15 16:40:51 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013.03.15 16:40:51 | 000,025,185 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2013.03.15 16:40:51 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2013.03.15 16:39:01 | 002,284,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msmpeg2vdec.dll
[2013.03.15 16:39:01 | 001,158,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2013.03.15 16:39:01 | 000,417,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
[2013.03.15 16:39:01 | 000,364,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2013.03.15 16:39:01 | 000,010,752 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013.03.15 16:39:01 | 000,009,728 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013.03.15 16:39:01 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013.03.15 16:39:01 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013.03.15 16:39:01 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013.03.15 16:39:01 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013.03.15 16:39:01 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013.03.15 16:39:01 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013.03.15 16:39:01 | 000,002,560 | -H-- | M] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013.03.15 16:39:00 | 003,419,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2013.03.15 16:39:00 | 001,988,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2013.03.15 16:39:00 | 001,504,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
[2013.03.15 16:39:00 | 001,247,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2013.03.15 16:39:00 | 001,080,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2013.03.15 16:39:00 | 000,604,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2013.03.15 16:39:00 | 000,293,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
[2013.03.15 16:39:00 | 000,249,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2013.03.15 16:39:00 | 000,220,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2013.03.15 16:39:00 | 000,207,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
[2013.03.15 16:39:00 | 000,187,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\UIAnimation.dll
[2013.03.15 16:39:00 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2013.03.15 16:33:56 | 000,001,889 | ---- | M] () -- C:\Users\Public\Desktop\1&1 Surf-Stick.lnk
[2013.03.12 21:38:28 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013.03.12 21:38:28 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013.03.11 21:49:15 | 000,001,075 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.03.08 14:46:00 | 000,094,112 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013.03.08 14:45:59 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2013.03.08 14:45:59 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2013.03.08 14:45:59 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013.03.08 14:45:59 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013.03.08 14:45:59 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.03.21 19:55:34 | 000,609,993 | ---- | C] () -- C:\Users\****\Desktop\adwcleaner.exe
[2013.03.20 22:16:17 | 000,001,024 | ---- | C] () -- C:\Users\****\Desktop\dradio-Recorder.lnk
[2013.03.17 18:18:34 | 000,002,569 | ---- | C] () -- C:\Users\Public\Desktop\iSpy.lnk
[2013.03.17 17:39:48 | 000,000,000 | ---- | C] () -- C:\Users\****\defogger_reenable
[2013.03.17 17:39:09 | 000,377,856 | ---- | C] () -- C:\Users\****\Desktop\gmer_2.1.19155.exe
[2013.03.17 17:39:09 | 000,050,477 | ---- | C] () -- C:\Users\****\Desktop\Defogger.exe
[2013.03.17 12:55:27 | 000,000,218 | ---- | C] () -- C:\Users\****\.recently-used.xbel
[2013.03.17 11:12:43 | 000,001,106 | ---- | C] () -- C:\Users\Public\Desktop\MyScript Notes Lite.lnk
[2013.03.17 10:53:57 | 000,001,866 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NewShortcut3.lnk
[2013.03.17 10:53:55 | 000,002,675 | ---- | C] () -- C:\Users\Public\Desktop\Note Manager.lnk
[2013.03.16 19:02:30 | 000,001,931 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013.03.16 18:47:36 | 000,001,037 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.16 10:42:42 | 209,665,740 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2013.03.15 16:40:51 | 000,025,185 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2013.03.15 15:44:43 | 000,001,889 | ---- | C] () -- C:\Users\Public\Desktop\1&1 Surf-Stick.lnk
[2013.03.11 21:49:15 | 000,001,087 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013.03.11 21:49:15 | 000,001,075 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.01.13 18:29:20 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2013.01.13 18:29:20 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2013.01.12 20:30:42 | 000,000,033 | ---- | C] () -- C:\Windows\Multimedia manager.INI
[2013.01.12 20:21:56 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2012.12.19 23:16:46 | 000,001,345 | ---- | C] () -- C:\Users\****\AppData\Roaming\csv2qif.ini
[2012.09.26 17:44:03 | 000,010,752 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2012.08.13 11:08:08 | 000,014,217 | ---- | C] () -- C:\Program Files\readme.html
[2012.05.08 14:15:36 | 000,000,005 | ---- | C] () -- C:\Program Files\basis-link
[2012.03.21 21:12:18 | 000,000,524 | ---- | C] () -- C:\Windows\System32\charset.dat
[2012.01.14 19:19:12 | 000,540,672 | ---- | C] () -- C:\Windows\_UnInst.exe
[2012.01.01 17:06:20 | 000,450,560 | ---- | C] () -- C:\Windows\System32\PEGRC32B.dll
[2012.01.01 17:06:20 | 000,188,416 | ---- | C] () -- C:\Windows\System32\PEGRC32A.dll
[2012.01.01 17:04:33 | 001,283,072 | ---- | C] () -- C:\Windows\System32\MhCglobal10.dll
[2011.12.30 13:26:00 | 000,064,000 | ---- | C] () -- C:\Windows\System32\esfw41.bin
[2011.06.10 18:01:12 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011.06.04 17:38:24 | 000,175,616 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011.06.04 17:38:23 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011.06.04 17:38:19 | 000,631,808 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011.06.04 17:38:19 | 000,243,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010.11.13 11:12:40 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.11.06 10:41:08 | 000,000,127 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010.10.31 16:50:50 | 000,000,000 | ---- | C] () -- C:\Users\****\AppData\Roaming\JFritz.lock
[2010.08.09 22:41:13 | 000,007,599 | ---- | C] () -- C:\Users\****\AppData\Local\Resmon.ResmonCfg
[2010.02.18 18:13:38 | 000,024,064 | ---- | C] () -- C:\Users\****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 24 bytes -> C:\Windows:A740170DCF394417
< End of report > --- --- ---
[/CODE]
und die neue Extras:
OTL Logfile: Code:
OTL Extras logfile created on: 21.03.2013 21:42:50 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\****\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16521)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 1,17 Gb Available Physical Memory | 58,95% Memory free
3,98 Gb Paging File | 2,99 Gb Available in Paging File | 75,12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 143,95 Gb Total Space | 46,12 Gb Free Space | 32,04% Space Free | Partition Type: NTFS
Drive F: | 1863,01 Gb Total Space | 1061,72 Gb Free Space | 56,99% Space Free | Partition Type: NTFS
Drive H: | 931,51 Gb Total Space | 334,72 Gb Free Space | 35,93% Space Free | Partition Type: NTFS
Drive I: | 931,51 Gb Total Space | 291,25 Gb Free Space | 31,27% Space Free | Partition Type: NTFS
Drive J: | 232,83 Gb Total Space | 28,84 Gb Free Space | 12,39% Space Free | Partition Type: FAT32
Computer Name: LENOVO | User Name: **** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
[HKEY_USERS\S-1-5-21-3968005663-3115476455-970186232-1001\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.reg [@ = regfile] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\BitBox\Client\BitBox.exe" "%1"
https [open] -- "C:\Program Files\BitBox\Client\BitBox.exe" "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Users\****\AppData\Local\Temp\RarSFX0\StsInstall.exe" = C:\Users\****\AppData\Local\Temp\RarSFX0\StsInstall.exe:*:Enabled:StsInstall
"C:\Program Files\Eurowin\MaxTax Deluxe\MAXTAX.exe" = C:\Program Files\Eurowin\MaxTax Deluxe\MAXTAX.exe:*:Enabled:MAXTAX -- (Steuersoft GmbH)
"C:\Program Files\Eurowin\MaxTax Deluxe\STMAXTAX.exe" = C:\Program Files\Eurowin\MaxTax Deluxe\STMAXTAX.exe:*:Enabled:STMAXTAX -- (Steuersoft GmbH)
"C:\Program Files\Eurowin\MaxTax Deluxe\EPUpdate.exe" = C:\Program Files\Eurowin\MaxTax Deluxe\EPUpdate.exe:*:Enabled:EPUpdate -- (Steuersoft GmbH)
"C:\Program Files\Eurowin\MaxTax Deluxe\DatabaseTool.exe" = C:\Program Files\Eurowin\MaxTax Deluxe\DatabaseTool.exe:*:Enabled:DatabaseTool -- (Steuersoft GmbH)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1B9DF4D3-8869-4E02-B016-433737D3EAB1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1C9AA0A3-5BCF-4813-9F44-22095B95BCC1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{278B306D-6377-4364-A110-7150EA3EA6E4}" = rport=137 | protocol=17 | dir=out | app=system |
"{2DDED28B-96BD-492A-9F74-0ED2054388D3}" = lport=10243 | protocol=6 | dir=in | app=system |
"{3159D566-6B97-4EA6-AF1C-889B0139918C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{32AD8D23-1199-43B1-ADA3-EF17D65A2004}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{3619C719-9E76-4594-96A2-6038E09C0CB7}" = lport=138 | protocol=17 | dir=in | app=system |
"{3806C0FE-F482-4C84-B915-523A31C48D2A}" = rport=445 | protocol=6 | dir=out | app=system |
"{39BF34C8-1787-4A53-ADEF-7D5511CF9DB8}" = lport=445 | protocol=6 | dir=in | app=system |
"{3CB9CB62-3FA0-4B4C-9087-1582271F66A9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{54F45E34-A097-4B35-82D0-69FF7A16A7D5}" = lport=139 | protocol=6 | dir=in | app=system |
"{5949E2B6-40F8-4711-AC81-14FB8A45FBA3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5D869046-80F0-4C5C-889A-ECA763EF3631}" = lport=2567 | protocol=6 | dir=in | name=messenger |
"{646D596C-6A70-4F42-80EE-D82220A0D660}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{84CE5EF7-8F17-40F4-9413-0AE23C17DD33}" = lport=137 | protocol=17 | dir=in | app=system |
"{91028991-3F36-424B-8BF2-D1CD9FD4D642}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{92B699B1-BC84-425C-980A-0F2610284A04}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BAC6A2A0-562E-4186-B1EC-A08A411D034F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CE3438A1-E34E-477D-A90A-C9D13D661330}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D87A2FB8-AA8E-4929-BAD1-EBEF41432656}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E66E461D-2920-4DA9-8F17-1DF2DF9091FB}" = rport=139 | protocol=6 | dir=out | app=system |
"{E8587130-5329-42BA-A93D-162D2994A371}" = rport=10243 | protocol=6 | dir=out | app=system |
"{EF4C6ADC-4F55-4D59-8016-24BDC2103B71}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{F5DDE83D-10DC-46F6-B2C9-C59B31C02BB8}" = lport=25 | protocol=6 | dir=in | name=dns |
"{F6423766-8452-4195-A8BD-F072BBE7D05B}" = rport=138 | protocol=17 | dir=out | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0397640E-6066-4208-879E-7712909C686C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{04C8A7EF-4054-4EE4-B2B2-37267FE550FF}" = protocol=6 | dir=in | app=c:\program files\google\google talk\googletalk.exe |
"{259EB788-F46D-4070-BEAA-A84B142C9C58}" = protocol=6 | dir=in | app=c:\users\****\appdata\local\akamai\netsession_win.exe |
"{2B602E64-D3D7-4D49-97D3-F2B519441F99}" = protocol=17 | dir=in | app=c:\program files\google\google talk\googletalk.exe |
"{2BF65765-6F32-4F38-90E1-36BD0F512361}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{337AF859-0192-4D10-9A1C-0D521A7E6032}" = protocol=17 | dir=in | app=c:\program files\java\jre6\launch4j-tmp\autoupdate.exe |
"{356EB979-687E-427A-93F6-F0D1C1FB3EC0}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"{366ACCE4-D361-438E-9D74-8A5053E5EC17}" = protocol=17 | dir=in | app=c:\program files\ninjalite\ninjalite\ninjali.exe |
"{38A50986-1ABB-4E2B-8F46-042C8B5C6DE9}" = protocol=6 | dir=in | app=c:\program files\eurowin\maxtax deluxe\databasetool.exe |
"{38E9C6B1-F9BA-436F-9857-F876260C6B16}" = protocol=17 | dir=in | app=c:\users\****\appdata\local\akamai\netsession_win.exe |
"{4303B030-210E-42DC-BC64-B6E19921F55E}" = protocol=6 | dir=in | app=c:\program files\eurowin\maxtax deluxe\maxtax.exe |
"{49A11C47-8305-4D30-8091-F14B43CDC659}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{49AE1150-16CF-4B41-A724-75C79286E7C9}" = protocol=6 | dir=in | app=c:\program files\eurowin\maxtax deluxe\maxtax.exe |
"{49EFFFA9-C2DC-49C1-8977-1A0D72E68044}" = protocol=6 | dir=in | app=c:\program files\java\jre6\launch4j-tmp\autoupdate.exe |
"{4A8F1260-5A00-4427-8FD8-077E9499365A}" = protocol=17 | dir=in | app=c:\users\****\appdata\local\apps\2.0\zdbh2x81.p30\75rmbvoa.jr4\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe |
"{4F2F1B26-E12B-4F62-A637-49B783DD1C1C}" = protocol=17 | dir=in | app=k:\1&1 multimessenger\messengr.exe |
"{51DC4B35-650D-439C-86D4-5A76051F7BA5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{566A7FDB-F18A-4610-A276-4FDE851A58EA}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{586714CF-C3F0-45F3-A500-71C99F741311}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{5A0A8829-6904-4E40-94FC-2153B8844C11}" = protocol=17 | dir=in | app=c:\windows\system32\wfs.exe |
"{6A8D0E8C-4E88-4BCB-92C8-D86996B4A1D5}" = protocol=17 | dir=in | app=c:\program files\ninjalite\ninjalite\xproxy.exe |
"{6A9299F5-A04C-4512-80CA-38EFAA0EE9B4}" = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"{6D14F310-709D-4136-9AD7-877634F16581}" = protocol=6 | dir=in | app=c:\users\****\appdata\local\apps\2.0\zdbh2x81.p30\75rmbvoa.jr4\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe |
"{6EB325C1-C586-4AA1-8A44-4D91B5EC9845}" = protocol=6 | dir=in | app=c:\program files\eurowin\maxtax deluxe\stmaxtax.exe |
"{72B0A3A6-DABF-4458-8244-3DB2682B0F28}" = protocol=17 | dir=in | app=c:\program files\eurowin\maxtax deluxe\stmaxtax.exe |
"{73DB5417-7DEF-4880-BEC8-3DA7225E4D08}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"{7C30E932-ABFA-49CC-9E63-246D8520091F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{802936C0-4760-41B2-A7B6-ED19C79571D2}" = protocol=17 | dir=in | app=c:\program files\eurowin\maxtax deluxe\maxtax.exe |
"{872C4B15-D96B-46D5-B7F6-01755E4C5D9B}" = protocol=17 | dir=in | app=c:\program files\eurowin\maxtax deluxe\databasetool.exe |
"{9006C8D5-AC04-4C86-893D-F1207B176611}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{90E1CB83-700C-4ED2-9EF7-7BE2F34AF1D4}" = protocol=17 | dir=in | app=c:\program files\eurowin\maxtax deluxe\databasetool.exe |
"{964A65ED-E50A-475C-9DE0-E99C2AF7019F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{96CB191D-0B61-4FEE-ACE2-8B4F216DF1E5}" = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"{9BAE5C0E-25D8-49DA-9B74-16C8ED1BD06F}" = protocol=17 | dir=in | app=c:\users\****\appdata\local\apps\2.0\zdbh2x81.p30\75rmbvoa.jr4\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe |
"{9F151451-F168-4A84-80C0-1C4F51537D3F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A4C5CD38-96F3-4231-BC79-337B14CDA835}" = protocol=6 | dir=in | app=k:\1&1 multimessenger\messengr.exe |
"{B14B86BB-6B5F-4A77-A6C1-F76C1AC3FDD6}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{B55FEB22-1030-451C-8D58-F9082A890658}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BD2D2077-3183-4DED-A82C-E8B554ACC50D}" = protocol=6 | dir=in | app=c:\users\****\appdata\local\apps\2.0\zdbh2x81.p30\75rmbvoa.jr4\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe |
"{C58C9B4B-8D11-4BE7-82A5-949CD5856C28}" = protocol=17 | dir=in | app=c:\program files\fritz!\igd_finder.exe |
"{C97C38C4-B9CE-4B28-B6F7-2C3A3307D1C7}" = protocol=17 | dir=in | app=c:\program files\eurowin\maxtax deluxe\epupdate.exe |
"{CA9908F2-76BD-4432-B636-AED8892174EF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CB96474C-9017-4FA2-8794-85D95F821352}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{CD434BC1-5CD0-47C2-B985-071D88B6FDF7}" = protocol=6 | dir=in | app=c:\program files\ninjalite\ninjalite\xproxy.exe |
"{CDCC9F88-203F-4A08-BAB9-8944D88B889A}" = protocol=17 | dir=in | app=c:\program files\eurowin\maxtax deluxe\stmaxtax.exe |
"{D5A1F3F1-7218-40D6-9082-9C3EE0F4F3FD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E0E02686-A483-417D-869A-EF6FDD14FBDF}" = protocol=17 | dir=in | app=c:\program files\eurowin\maxtax deluxe\maxtax.exe |
"{E355A7F0-0330-4302-A73F-91B7F72637D4}" = protocol=6 | dir=in | app=c:\program files\eurowin\maxtax deluxe\epupdate.exe |
"{E7489E38-90CA-40A5-83A9-E1A47B041572}" = protocol=6 | dir=out | app=system |
"{E7CB13DF-E10F-41F7-8BE2-7D21234A914A}" = protocol=6 | dir=in | app=c:\windows\system32\wfs.exe |
"{EAC7C9FA-EE66-431B-BC64-706C2BEB90FE}" = protocol=6 | dir=in | app=c:\program files\eurowin\maxtax deluxe\stmaxtax.exe |
"{EBF5DF4E-B0AD-432A-AA2B-AA69DAD54910}" = protocol=6 | dir=in | app=c:\program files\eurowin\maxtax deluxe\databasetool.exe |
"{F10FB82D-437D-4414-8819-2C479B00A178}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{F567AD1C-F904-4C32-876C-7EE7EB8B566B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F8D027DE-DBE1-4489-BA25-012E6507FA4D}" = protocol=6 | dir=in | app=c:\program files\ninjalite\ninjalite\ninjali.exe |
"{FD8BA5AA-2F7C-4B23-8058-09F25D731E1E}" = protocol=6 | dir=in | app=c:\program files\fritz!\igd_finder.exe |
"TCP Query User{11CF5B4C-1672-47FC-B59A-FD29EFE96A82}C:\program files\space threat\space_threat_server.exe" = protocol=6 | dir=in | app=c:\program files\space threat\space_threat_server.exe |
"TCP Query User{13D0F55E-B091-4E6F-A42A-E5085E0FA27E}C:\program files\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
"TCP Query User{16D78EEC-4236-46B8-BE25-7AA9C6FEBA40}C:\program files\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"TCP Query User{28776DE6-79A6-4AB9-A59A-4EDB3367E0F1}C:\program files\dradio-recorder\phonostar.exe" = protocol=6 | dir=in | app=c:\program files\dradio-recorder\phonostar.exe |
"TCP Query User{2A3B3308-035A-4B8E-97ED-437625BFCB84}C:\windows\system32\wfs.exe" = protocol=6 | dir=in | app=c:\windows\system32\wfs.exe |
"TCP Query User{37677313-CAAF-498D-B23A-DAC9FA2071EB}C:\program files\hausakte\bin\hausakteserver.exe" = protocol=6 | dir=in | app=c:\program files\hausakte\bin\hausakteserver.exe |
"TCP Query User{3FE04CF8-DC2A-4CF8-A2BA-DD60C3AB75D3}C:\downloads\software\fritz.box_fon_wlan_7050.04.31.recover-image.exe" = protocol=6 | dir=in | app=c:\downloads\software\fritz.box_fon_wlan_7050.04.31.recover-image.exe |
"TCP Query User{46B9EC4D-B48A-4023-AC62-52A2E866C131}K:\1&1 multimessenger\messengr.exe" = protocol=6 | dir=in | app=k:\1&1 multimessenger\messengr.exe |
"TCP Query User{47735FE9-7692-4CFD-AB19-B9325265AAA0}C:\program files\free download manager\fdm.exe" = protocol=6 | dir=in | app=c:\program files\free download manager\fdm.exe |
"TCP Query User{48A5B49F-42AE-41D7-9804-B420D889F975}C:\program files\jfritz\jfritz.exe" = protocol=6 | dir=in | app=c:\program files\jfritz\jfritz.exe |
"TCP Query User{60F8B743-ADD3-4841-9094-AEADE6661D12}C:\downloads\software\fritz.box_fon_wlan_7170.04.80.recover-image.exe" = protocol=6 | dir=in | app=c:\downloads\software\fritz.box_fon_wlan_7170.04.80.recover-image.exe |
"TCP Query User{61649917-17C4-4907-93ED-934A2E5F937F}C:\program files\dgp1000\note manager.exe" = protocol=6 | dir=in | app=c:\program files\dgp1000\note manager.exe |
"TCP Query User{641F8D31-B2C0-4585-AE87-B84E40BC775F}C:\users\****\appdata\local\temp\_istmp1.dir\_istmp0.dir\igd_finder.exe" = protocol=6 | dir=in | app=c:\users\****\appdata\local\temp\_istmp1.dir\_istmp0.dir\igd_finder.exe |
"TCP Query User{65340B56-6E4F-4E7F-9FEC-7B766CAF1D9D}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=6 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe |
"TCP Query User{696AB71B-755A-4911-8932-172AB7D544A8}C:\program files\java\jre6\launch4j-tmp\autoupdate.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\launch4j-tmp\autoupdate.exe |
"TCP Query User{7E86FE07-360F-4C27-B71D-F302B70A50FA}C:\program files\free download manager\fdmwi.exe" = protocol=6 | dir=in | app=c:\program files\free download manager\fdmwi.exe |
"TCP Query User{8233D25B-D0D8-4C46-80CA-E556E38B7F27}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{85B51D95-0F9F-4431-87D5-CD9B56C3219B}I:\emule\emule.exe" = protocol=6 | dir=in | app=%programfiles%\emule\emule.exe |
"TCP Query User{9009471C-1C09-4FF8-AA09-B0FBACED95C1}C:\program files\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"TCP Query User{94A11803-8A56-4929-B732-B2A81200BAC4}C:\downloads\software\support_freeedition_do94767783_de.exe" = protocol=6 | dir=in | app=c:\downloads\software\support_freeedition_do94767783_de.exe |
"TCP Query User{A4679D34-697F-433E-9660-FCEF757A245F}C:\program files\dgp1000\note manager.exe" = protocol=6 | dir=in | app=c:\program files\dgp1000\note manager.exe |
"TCP Query User{AC7706F6-D073-473F-96C5-FD9E6F3ABEB6}C:\downloads\software\fritz.box_fon_wlan_7050.04.31.recover-image.exe" = protocol=6 | dir=in | app=c:\downloads\software\fritz.box_fon_wlan_7050.04.31.recover-image.exe |
"TCP Query User{B3EE3D6A-CEC9-4ED0-AAA5-4E947CFBE04D}F:\hessen3d.exe" = protocol=6 | dir=in | app=f:\hessen3d.exe |
"TCP Query User{D197837B-D60B-4A2E-A4DF-155EA23F0B76}C:\users\****\appdata\local\temp\_istmp1.dir\_ins5576._mp" = protocol=6 | dir=in | app=c:\users\****\appdata\local\temp\_istmp1.dir\_ins5576._mp |
"TCP Query User{D5D5C9FC-A4E3-4294-949B-962D804C5B7A}C:\program files\fritz!\frifax32.exe" = protocol=6 | dir=in | app=c:\program files\fritz!\frifax32.exe |
"TCP Query User{DFF3A6D0-52BB-46FE-8581-F977F6152D54}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{F1F0D63C-083E-4111-8875-7F98DCB4C951}C:\program files\ispy\ispy\ispy.exe" = protocol=6 | dir=in | app=c:\program files\ispy\ispy\ispy.exe |
"TCP Query User{FF483B5F-B5BA-4362-855F-4644BF1F35A4}C:\program files\1&1\1&1 multimessenger\messengr.exe" = protocol=6 | dir=in | app=c:\program files\1&1\1&1 multimessenger\messengr.exe |
"UDP Query User{0B5F472C-B0A9-484E-BA3A-5A35E11C3BB7}C:\program files\java\jre6\launch4j-tmp\autoupdate.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\launch4j-tmp\autoupdate.exe |
"UDP Query User{219CC222-3AFC-4C39-AAD8-2F5C349EE420}C:\users\****\appdata\local\temp\_istmp1.dir\_ins5576._mp" = protocol=17 | dir=in | app=c:\users\****\appdata\local\temp\_istmp1.dir\_ins5576._mp |
"UDP Query User{220FD576-79E7-4AE9-B1D3-8860D6A75EBB}C:\program files\1&1\1&1 multimessenger\messengr.exe" = protocol=17 | dir=in | app=c:\program files\1&1\1&1 multimessenger\messengr.exe |
"UDP Query User{26C05F2E-F522-4086-A93F-AC622E4EF2E5}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=17 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe |
"UDP Query User{2B19483B-B9E7-4975-B622-7E6E9F7F34D7}C:\program files\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
"UDP Query User{32012F94-3D3D-4DC9-9B41-DA58AD1F2740}C:\program files\jfritz\jfritz.exe" = protocol=17 | dir=in | app=c:\program files\jfritz\jfritz.exe |
"UDP Query User{39983F8C-7B77-4991-8D34-693EA546DC43}C:\program files\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"UDP Query User{4D6039C8-1AA5-47A7-9D02-378A78A40847}I:\emule\emule.exe" = protocol=17 | dir=in | app=%programfiles%\emule\emule.exe |
"UDP Query User{6AEFB385-DE65-4145-A32A-29C45E94A878}C:\downloads\software\fritz.box_fon_wlan_7050.04.31.recover-image.exe" = protocol=17 | dir=in | app=c:\downloads\software\fritz.box_fon_wlan_7050.04.31.recover-image.exe |
"UDP Query User{70DD2079-30A8-4E09-8392-40771801B297}C:\program files\dgp1000\note manager.exe" = protocol=17 | dir=in | app=c:\program files\dgp1000\note manager.exe |
"UDP Query User{7666D796-93FD-4A25-9D62-4587ED293BCA}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{7CBDB0BF-CDF4-4418-97F6-140D804D0398}C:\downloads\software\fritz.box_fon_wlan_7170.04.80.recover-image.exe" = protocol=17 | dir=in | app=c:\downloads\software\fritz.box_fon_wlan_7170.04.80.recover-image.exe |
"UDP Query User{7CC496BC-FC0C-4016-813F-7B526C5916DA}C:\program files\free download manager\fdmwi.exe" = protocol=17 | dir=in | app=c:\program files\free download manager\fdmwi.exe |
"UDP Query User{8114A5E5-4E35-4DCB-AAD0-E5AF002F2300}C:\program files\hausakte\bin\hausakteserver.exe" = protocol=17 | dir=in | app=c:\program files\hausakte\bin\hausakteserver.exe |
"UDP Query User{86DDA632-617B-4B98-8AB0-F6FA8B80A96B}C:\windows\system32\wfs.exe" = protocol=17 | dir=in | app=c:\windows\system32\wfs.exe |
"UDP Query User{895AEF11-CE54-4D64-AD7D-47D641AAF32E}K:\1&1 multimessenger\messengr.exe" = protocol=17 | dir=in | app=k:\1&1 multimessenger\messengr.exe |
"UDP Query User{96BEFB1E-A8A7-4D8C-95C0-6CDC9E18B21B}F:\hessen3d.exe" = protocol=17 | dir=in | app=f:\hessen3d.exe |
"UDP Query User{B212B35E-71F9-48B0-8E80-4C63E65119DB}C:\downloads\software\fritz.box_fon_wlan_7050.04.31.recover-image.exe" = protocol=17 | dir=in | app=c:\downloads\software\fritz.box_fon_wlan_7050.04.31.recover-image.exe |
"UDP Query User{B2D85AF0-A36F-476A-8DB8-ED3424E4A93B}C:\program files\ispy\ispy\ispy.exe" = protocol=17 | dir=in | app=c:\program files\ispy\ispy\ispy.exe |
"UDP Query User{B5360CA2-8118-45A6-881E-A2856A052D27}C:\downloads\software\support_freeedition_do94767783_de.exe" = protocol=17 | dir=in | app=c:\downloads\software\support_freeedition_do94767783_de.exe |
"UDP Query User{BAD8BEFB-B84D-4AAD-9195-7EEFE0BFA207}C:\program files\space threat\space_threat_server.exe" = protocol=17 | dir=in | app=c:\program files\space threat\space_threat_server.exe |
"UDP Query User{C80EAD03-B7BA-4B7F-BABE-8939F9648BCD}C:\program files\dradio-recorder\phonostar.exe" = protocol=17 | dir=in | app=c:\program files\dradio-recorder\phonostar.exe |
"UDP Query User{C98B97D7-9619-4F92-8C83-921BD9B55C1C}C:\program files\free download manager\fdm.exe" = protocol=17 | dir=in | app=c:\program files\free download manager\fdm.exe |
"UDP Query User{E29558D5-824A-405E-926D-DAD3F3AF6093}C:\program files\fritz!\frifax32.exe" = protocol=17 | dir=in | app=c:\program files\fritz!\frifax32.exe |
"UDP Query User{E621B0A8-9356-4BF4-A3AD-772AC485C348}C:\program files\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"UDP Query User{F04D7D5D-CDE4-48D7-BCF8-2167E5E8F4D0}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{F42D82AF-6082-437E-A153-E4BA3A9452DA}C:\program files\dgp1000\note manager.exe" = protocol=17 | dir=in | app=c:\program files\dgp1000\note manager.exe |
"UDP Query User{F89D4BAB-DDA8-4D82-8AE9-8DF2E89AAEC9}C:\users\****\appdata\local\temp\_istmp1.dir\_istmp0.dir\igd_finder.exe" = protocol=17 | dir=in | app=c:\users\****\appdata\local\temp\_istmp1.dir\_istmp0.dir\igd_finder.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0138F525-6C8A-333F-A105-14AE030B9A54}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{0281B504-85AC-4041-9E16-D10AA814D69D}" = iSpy
"{188F5452-6C4E-4CA9-8E57-CF72E5331D2B}" = Note Manager Software
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{3A6F4A31-8CFD-46B4-8385-E1F384DB121E}" = PDF-XChange Viewer
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{408CD2E8-3977-449B-8102-76F158D4885F}" = Oracle VM VirtualBox 4.0.4
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{53480150-81CB-4A86-B378-86B6F08AF80B}" = O&O DriveLED
"{53480870-02D8-48FB-BC27-72C956885168}" = O&O MediaRecovery
"{53B0213C-CC0C-4340-90BF-BFC7D3FE5BB4}" = QuickMark
"{556C14EF-56D1-4EC1-B886-CA36B8AE6E66}" = StarMoney 6.0
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5DC36978-AB9A-4A23-9C12-D90D2BB781B7}" = AVM FRITZ!Fernzugang
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7235252A-39A3-4889-AF58-18B82040310E}" = AVEO USB2.0 PC Camera
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{843DECF5-2CCA-49EA-AFB9-612388EB1A80}" = mh-tools
"{8732F9DD-0E44-4F8A-B460-A0B769AB1C13}" = calibre
"{8927E07C-97F7-4A54-88FB-D976F50DD46E}" = Turbo Lister 2
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{94FA9FA6-5294-494D-A8F1-1E654CBB5736}" = Epson Easy Photo Print 2
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A00F8237-F496-44D2-0001-E3CCF8CD58AE}" = Photomizer
"{A62F50D4-EED7-4417-A382-E89ABCF11BAC}" = SketchUp DWG Importer
"{A82E3AFE-0BD9-4A17-9A58-9112B5C679C5}" = MyScript Notes Lite
"{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}" = PixiePack Codec Pack
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}" = 1&1 Surf-Stick
"{AA0FB0B5-D853-4F87-9261-A4BC7D503E0D}" = Microsoft Image Composite Editor
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.0) - Deutsch
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AF5B3ED5-70D3-48CF-A00F-FC29F5261A37}_is1" = JFritz 0.7.4.1
"{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)
"{B3B4E8E4-E2A4-11D6-8D31-00105A629F49}" = eMedia fortgeschrittene Keyboard-Schule
"{B4E10F9C-AB1E-4204-8700-A01C8490A149}" = KOMPAS-3D LT V8 Plus
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BEF106F8-2689-4530-925A-E1117836E8CD}" = Google SketchUp 7
"{BFBB91DB-9F0F-4A9C-9669-A97DA3512CF2}" = RealSpeak Solo fur Deutsch - Steffi
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{DAB4E2E7-5E5C-499F-A533-303AAD4C8981}" = WiiGSC
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{E6C44758-FF49-47D1-8182-65E3818ACE23}" = AuthenTec TrueSuite
"{EEC010D0-1252-4E1D-BAD9-F1B8F414535C}" = PL-2303 Vista Driver Installer
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F82C6574-AD88-4B40-A432-970BC77F1BD2}" = DesignPro 5
"{F9466082-90E9-4BE4-92F0-CF0AF195B0CF}" = hama PC-Webcam AC-140
"{FA761F4B-F2C3-4D07-9A44-BEEA137C6291}" = WISO Bau & Kauf Planung
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFCB1B04-5B1C-4A17-AA60-CA6F00BA50F9}" = StarMoney
"1&1 MultiMessenger" = 1&1 MultiMessenger
"7-Zip" = 7-Zip 4.65
"ABBYY FineReader 10.0.102.109" = ABBYY FineReader 10.0.102.109
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Any DWG DXF Converter_is1" = Any DWG DXF Converter 2010
"Audiograbber" = Audiograbber 1.83 SE
"Audiograbber-Lame" = Audiograbber Lame-MP3-Plugin
"AVIConverter" = AVIConverter 4.0.1
"Avira AntiVir Desktop" = Avira Free Antivirus
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Camtasia Studio 3" = Camtasia Studio 3
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"CCleaner" = CCleaner
"DaumenkinoDruck" = Daumenkino - Druckmaschine
"DivX Setup.divx.com" = DivX-Setup
"dradio-Recorder_is1" = dradio-Recorder Version 3.02.6
"Duplicate Cleaner" = Duplicate Cleaner 2.1b
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink DE_is1" = DVD Shrink 3.2 deutsch (DeCSS-frei)
"EPSON BX300F Series" = EPSON BX300F Series Printer Uninstall
"EPSON Scanner" = EPSON Scan
"FileEdit" = FileEdit 0.01.817
"FILEminimizer Pictures_is1" = FILEminimizer Pictures
"FileZilla Client" = FileZilla Client 3.3.1
"Free Download Manager_is1" = Free Download Manager 3.0
"Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 5.0.14.627
"FRITZ! 2.0" = AVM FRITZ!fax für FRITZ!Box
"GPL Ghostscript 9.04" = GPL Ghostscript
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"Inkscape" = Inkscape 0.48.1
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"InstallShield_{F82C6574-AD88-4B40-A432-970BC77F1BD2}" = DesignPro 5
"IrfanView" = IrfanView (remove only)
"IsoViewX30Uc" = ITEDO IsoView ActiveX Control 3.0
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 7.1.0
"LHTTSENG" = L&H TTS3000 British English
"LHTTSGED" = L&H TTS3000 Deutsch
"LiveUSB Creator" = LiveUSB Creator (remove only)
"LoqTTS-Stefan_is1" = Loquendo TTS: Stefan (German)
"LoqTTS-Ulrike_is1" = Loquendo TTS: Ulrike (German)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100
"MARKEMENT_DEFRAG_PRO_is1" = PCSUITE DEFRAG
"MAXTAXDel" = eurowin maxtax
"Micam-1.4_is1" = Micam 1.4
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox 19.0.2 (x86 de)" = Mozilla Firefox 19.0.2 (x86 de)
"Mozilla Thunderbird 17.0.4 (x86 de)" = Mozilla Thunderbird 17.0.4 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"Notepad++" = Notepad++
"Organizer V97.1" = Lotus Organizer 97 GS
"PCSUITE_INSPECTOR_PRO_is1" = PCSUITE INSPECTOR
"pepakura_designer3en" = Pepakura Designer 3
"PhotoStitch" = Canon Utilities PhotoStitch
"PowerISO" = PowerISO
"PrimoPDF" = PrimoPDF -- by Nitro PDF Software
"QuickTime" = QuickTime
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"ROM Papyrus Autor" = Papyrus Autor 14.01
"Shockwave" = Shockwave
"TomTom HOME" = TomTom HOME 2.8.2.2264
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"TVWiz" = Intel(R) TV Wizard
"VLC media player" = VLC media player 2.0.5
"WinPcapInst" = WinPcap 4.1.2
"Wireshark" = Wireshark 1.4.2
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 5.8.9
"WISO Bau & Kauf Finanzierung" = WISO Bau & Kauf Finanzierung
"Workshop Information System - WIS" = Workshop Information System - WIS
"XMind" = XMind
"XnView_is1" = XnView 1.98.2
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
"ZUB®-Bauteilkalkulator_is1" = ZUB®-Bauteilkalkulator 1.2.0.20
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-3968005663-3115476455-970186232-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"NiedersachsenViewer Plus" = NiedersachsenViewer Plus
========== Last 20 Event Log Errors ==========
[ System Events ]
Error - 21.03.2013 16:33:12 | Computer Name = Lenovo | Source = DCOM | ID = 10010
Description =
< End of report > --- --- ---
Mfg
civil |