OTL: Code:
OTL logfile created on: 21.04.2013 16:01:15 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\admin\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 1,26 Gb Available Physical Memory | 63,38% Memory free
3,98 Gb Paging File | 3,25 Gb Available in Paging File | 81,74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 148,95 Gb Total Space | 73,24 Gb Free Space | 49,17% Space Free | Partition Type: NTFS
Drive E: | 980,72 Mb Total Space | 963,09 Mb Free Space | 98,20% Space Free | Partition Type: FAT
Computer Name: ADMIN-PC | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: On | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Update-Service) -- C:\Windows\System32\UpdSvc.dll (Joosoft.com GmbH)
SRV - (TeamViewer7) -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (mbr) -- C:\Users\admin\AppData\Local\Temp\mbr.sys File not found
DRV - (huawei_enumerator) -- system32\DRIVERS\ew_jubusenum.sys File not found
DRV - (huawei_cdcacm) -- system32\DRIVERS\ew_jucdcacm.sys File not found
DRV - (ew_hwusbdev) -- system32\DRIVERS\ew_hwusbdev.sys File not found
DRV - (catchme) -- C:\Users\admin\AppData\Local\Temp\catchme.sys File not found
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (MonitorFunction) -- C:\Windows\System32\drivers\TVMonitor.sys (TeamViewer GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LUsbFilt) -- C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (BthAvrcp) -- C:\Windows\System32\drivers\BthAvrcp.sys (CSR, plc)
DRV - (WSDPrintDevice) -- C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (Serial) -- C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (netw5v32) -- C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{1}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page Before = hxxp://search.b1.org/?bsrc=4hixr&chid=c167991
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Before = hxxp://search.b1.org/?bsrc=4hixr&chid=c167991
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 73 21 09 8B 40 B4 CC 01 [binary data]
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\..\SearchScopes\{1}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\..\SearchScopes\{BDFFE5DB-AD20-49BA-8BA5-E5C262FCD6F8}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=114506&babsrc=SP_clro&mntrId=9c65cf9e000000000000001a6bfe2658
IE - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaultenginename,S: S", ""
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.order.1,S: S", ""
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.selectedEngine,S: S", ""
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.12.09 18:28:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.15 20:13:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.12.09 18:28:56 | 000,000,000 | ---D | M]
[2012.04.01 20:22:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\Extensions
[2012.04.01 20:22:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2013.04.21 01:06:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\Firefox\Profiles\21xq5wus.default\extensions
[2013.04.21 01:06:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\Firefox\Profiles\z24a0rb1.default\extensions
[2013.04.03 15:11:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013.03.27 04:17:36 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013.03.27 05:32:09 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.03.27 05:32:09 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013.03.27 05:32:09 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2013.03.27 05:32:09 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.03.27 05:32:09 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.03.27 05:32:09 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - Extension: No name found = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: No name found = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: No name found = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcapaopeljafjihcnecmoadikpfaehef\1\
CHR - Extension: No name found = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekofeaecaghdipehglnbbfefcjphhoam\1\
CHR - Extension: No name found = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\
CHR - Extension: No name found = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jffneeklbegfgjgbjpoefbnhmehkdecc\1\
CHR - Extension: No name found = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelocaekmibdobambaiolkbnjnekogdb\1\
CHR - Extension: No name found = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
O1 HOSTS File: ([2013.04.21 15:10:32 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\..Trusted Domains: fritz.repeater ([]* in Local intranet)
O15 - HKU\S-1-5-21-2070048282-3062225414-2777264324-1000\..Trusted Ranges: Range1 ([*] in Local intranet)
O16 - DPF: {28B66320-9687-4B13-8757-36F901887AB5} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/canvasx.cab (CanvasX Class)
O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/jordan.cab (JordanUploader Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AC0699E3-C9BB-4FE1-A3F9-9F8FA6A6E0CD}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EAD389B4-0EB8-49AC-A3A7-321172EAB820}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: LanmanWorkstation - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013.04.21 15:29:49 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\admin\Desktop\OTL.exe
[2013.04.21 15:10:36 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2013.04.21 14:54:37 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Local\Avg2013
[2013.04.21 01:34:23 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Local\temp
[2013.04.21 01:23:11 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.04.21 01:23:11 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.04.21 01:23:11 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.04.21 01:23:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.04.21 01:22:44 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.04.14 16:32:00 | 000,000,000 | ---D | C] -- C:\Users\admin\Desktop\Daten
[2013.04.12 13:32:49 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\Malwarebytes
[2013.04.12 13:32:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.04.12 13:32:24 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Local\Programs
[2013.04.03 15:11:47 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2013.03.29 02:36:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2013.03.28 00:05:39 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Local\WBFSManager
[2013.03.28 00:03:33 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WBFS Manager
[2013.03.28 00:03:30 | 000,000,000 | ---D | C] -- C:\Program Files\WBFS
[2013.03.27 20:22:10 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\uTorrent
[2013.03.22 21:08:48 | 000,000,000 | -H-D | C] -- C:\Program Files\Temp
[2013.03.22 19:09:11 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ChadSoft
[2013.03.22 19:09:09 | 000,000,000 | ---D | C] -- C:\Program Files\ChadSoft
[2012.06.11 19:14:50 | 016,418,456 | ---- | C] (Mozilla) -- C:\Users\admin\Firefox_Setup_13.0.exe
[2012.06.08 17:20:08 | 036,965,680 | ---- | C] (Microsoft Corporation) -- C:\Users\admin\IE9-Windows7-x64-9.0.6-deu.exe
[2012.06.08 17:18:34 | 017,010,016 | ---- | C] (Microsoft Corporation) -- C:\Users\admin\IE8-WindowsXP-x86-DEU.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.04.21 15:29:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\admin\Desktop\OTL.exe
[2013.04.21 15:17:31 | 000,019,328 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.04.21 15:17:31 | 000,019,328 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.04.21 15:13:13 | 008,560,888 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.04.21 15:13:13 | 003,037,604 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.04.21 15:13:13 | 002,668,528 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.04.21 15:13:13 | 002,392,754 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.04.21 15:10:32 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013.04.21 15:05:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.04.21 15:05:31 | 1602,723,840 | -HS- | M] () -- C:\hiberfil.sys
[2013.04.21 14:55:58 | 000,000,612 | ---- | M] () -- C:\Users\admin\Desktop\ComboFix - Verknüpfung.lnk
[2013.04.21 01:07:15 | 000,000,157 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013.04.20 17:42:38 | 000,000,512 | ---- | M] () -- C:\Users\admin\Desktop\MBR.dat
[2013.04.20 17:40:02 | 000,000,000 | ---- | M] () -- C:\Users\admin\defogger_reenable
[2013.04.17 16:22:25 | 000,027,789 | ---- | M] () -- C:\Users\admin\AppData\Local\recently-used.xbel
[2013.04.17 16:14:13 | 405,012,479 | ---- | M] () -- C:\Users\admin\Desktop\MarioKartWii.iso
[2013.04.15 20:22:03 | 000,000,129 | ---- | M] () -- C:\Users\admin\snannow
[2013.04.15 19:56:02 | 000,003,336 | ---- | M] () -- C:\bootsqm.dat
[2013.04.10 21:52:04 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.04.08 14:22:34 | 244,990,919 | ---- | M] () -- C:\Windows\MEMORY.DMP
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.04.21 14:55:58 | 000,000,612 | ---- | C] () -- C:\Users\admin\Desktop\ComboFix - Verknüpfung.lnk
[2013.04.21 01:23:11 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.04.21 01:23:11 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.04.21 01:23:11 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.04.21 01:23:11 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.04.21 01:23:11 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.04.21 01:06:33 | 000,000,157 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013.04.20 17:42:38 | 000,000,512 | ---- | C] () -- C:\Users\admin\Desktop\MBR.dat
[2013.04.20 17:40:02 | 000,000,000 | ---- | C] () -- C:\Users\admin\defogger_reenable
[2013.04.17 16:22:25 | 000,027,789 | ---- | C] () -- C:\Users\admin\AppData\Local\recently-used.xbel
[2013.04.17 16:02:25 | 405,012,479 | ---- | C] () -- C:\Users\admin\Desktop\MarioKartWii.iso
[2013.04.15 20:22:03 | 000,000,129 | ---- | C] () -- C:\Users\admin\snannow
[2013.04.15 19:56:02 | 000,003,336 | ---- | C] () -- C:\bootsqm.dat
[2013.04.03 15:11:54 | 000,001,081 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013.02.12 21:19:06 | 001,720,085 | ---- | C] () -- C:\Users\admin\Race.szs
[2013.02.12 21:19:06 | 000,429,114 | ---- | C] () -- C:\Users\admin\Race_G.szs
[2013.02.11 21:51:45 | 000,000,418 | ---- | C] () -- C:\Windows\hpwmdl28.dat.temp
[2012.09.25 20:46:34 | 000,241,438 | ---- | C] () -- C:\Windows\hpwins28.dat
[2012.06.08 17:31:17 | 074,761,776 | ---- | C] () -- C:\Users\admin\avast_free1426_antivirus_setup.exe
[2011.12.31 11:23:48 | 000,005,632 | ---- | C] () -- C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.12.09 18:20:55 | 000,259,558 | ---- | C] () -- C:\Windows\hpwins19.dat
[2011.12.07 22:17:07 | 000,098,304 | ---- | C] () -- C:\Windows\System32\redmonnt.dll
[2011.12.07 00:35:46 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2011.11.02 09:57:32 | 008,560,888 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2011.11.02 09:57:32 | 002,668,528 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2011.11.02 09:57:32 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2011.11.02 09:57:32 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
========== ZeroAccess Check ==========
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 05:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.10.07 22:47:40 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\AVG
[2013.02.07 18:55:32 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\B1Toolbar
[2013.01.18 21:41:46 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\DVDVideoSoft
[2011.12.09 19:07:00 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Leadertech
[2012.01.18 18:37:23 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Nokia
[2012.01.18 18:37:23 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Nokia Suite
[2011.12.31 11:03:28 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\PC Suite
[2013.01.04 17:00:26 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\phonostar GmbH
[2013.01.13 00:39:55 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\ProtectDISC
[2013.03.20 17:25:40 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Stellarium
[2012.07.22 14:50:11 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\T-Mobile
[2012.12.13 13:00:30 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\T-Mobile Internet Manager
[2012.04.01 20:22:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TomTom
[2012.09.04 22:37:12 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TuneUp Software
[2013.04.15 20:12:43 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\uTorrent
[2012.10.14 10:00:17 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2012.10.14 10:00:17 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\* >
[2013.04.21 01:07:15 | 000,049,976 | ---- | M] () -- C:\AdwCleaner[S1].txt
[2013.04.21 01:15:27 | 000,001,572 | ---- | M] () -- C:\AdwCleaner[S2].txt
[2009.06.10 23:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2013.04.15 19:56:01 | 000,005,120 | ---- | M] () -- C:\bootex.log
[2013.04.15 19:56:02 | 000,003,336 | ---- | M] () -- C:\bootsqm.dat
[2013.04.21 15:13:01 | 000,010,770 | ---- | M] () -- C:\ComboFix.txt
[2009.06.10 23:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2013.04.21 15:05:31 | 1602,723,840 | -HS- | M] () -- C:\hiberfil.sys
[2013.04.21 15:35:50 | 000,000,693 | ---- | M] () -- C:\Neu Textdokument.txt
[2013.04.21 15:05:35 | 2136,969,216 | -HS- | M] () -- C:\pagefile.sys
[2013.04.20 18:10:14 | 000,142,438 | ---- | M] () -- C:\TDSSKiller.2.8.16.0_20.04.2013_18.09.08_log.txt
< %SYSTEMDRIVE%\*.* >
[2013.04.21 01:07:15 | 000,049,976 | ---- | M] () -- C:\AdwCleaner[S1].txt
[2013.04.21 01:15:27 | 000,001,572 | ---- | M] () -- C:\AdwCleaner[S2].txt
[2009.06.10 23:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2013.04.15 19:56:01 | 000,005,120 | ---- | M] () -- C:\bootex.log
[2013.04.15 19:56:02 | 000,003,336 | ---- | M] () -- C:\bootsqm.dat
[2013.04.21 15:13:01 | 000,010,770 | ---- | M] () -- C:\ComboFix.txt
[2009.06.10 23:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2013.04.21 15:05:31 | 1602,723,840 | -HS- | M] () -- C:\hiberfil.sys
[2013.04.21 15:35:50 | 000,000,693 | ---- | M] () -- C:\Neu Textdokument.txt
[2013.04.21 15:05:35 | 2136,969,216 | -HS- | M] () -- C:\pagefile.sys
[2013.04.20 18:10:14 | 000,142,438 | ---- | M] () -- C:\TDSSKiller.2.8.16.0_20.04.2013_18.09.08_log.txt
< %PROGRAMFILES%\*.* >
[2009.07.14 06:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
Invalid Environment Variable: PROGRAMFILES(X86)
< %appdata%\*. >
[2011.12.07 00:00:25 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Adobe
[2012.02.06 14:46:16 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Ahead
[2013.01.07 22:44:21 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Apple Computer
[2012.10.07 22:47:40 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\AVG
[2013.02.07 18:55:32 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\B1Toolbar
[2011.12.23 21:13:22 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\CyberLink
[2013.01.18 21:41:46 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\DVDVideoSoft
[2011.12.09 18:37:25 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\HP
[2012.01.26 08:36:50 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\HpUpdate
[2011.11.02 01:05:18 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Identities
[2011.12.09 19:07:00 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Leadertech
[2011.12.09 19:04:43 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Logishrd
[2011.12.09 19:07:08 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Logitech
[2011.12.07 00:31:48 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Macromedia
[2013.04.12 13:32:49 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Malwarebytes
[2009.07.14 09:48:18 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Media Center Programs
[2013.02.23 14:38:57 | 000,000,000 | --SD | M] -- C:\Users\admin\AppData\Roaming\Microsoft
[2012.04.01 20:22:52 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Mozilla
[2012.01.18 18:37:23 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Nokia
[2012.01.18 18:37:23 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Nokia Suite
[2011.12.31 11:03:28 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\PC Suite
[2013.01.04 17:00:26 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\phonostar GmbH
[2013.01.13 00:39:55 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\ProtectDISC
[2013.04.10 19:41:49 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Skype
[2013.03.20 17:25:40 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Stellarium
[2012.07.22 14:50:11 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\T-Mobile
[2012.12.13 13:00:30 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\T-Mobile Internet Manager
[2012.04.01 20:22:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TomTom
[2012.09.04 22:37:12 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TuneUp Software
[2013.04.15 20:12:43 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\uTorrent
[2012.09.14 20:58:52 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\WinRAR
[2011.12.09 18:29:15 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Yahoo!
< %appdata%\*.* >
< %localappdata%\*. >
[2011.12.07 00:00:25 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Adobe
[2011.12.07 00:01:16 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Ahead
[2011.11.02 01:04:55 | 000,000,000 | -HSD | M] -- C:\Users\admin\AppData\Local\Anwendungsdaten
[2013.01.07 21:58:50 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Apple
[2013.01.07 22:01:38 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Apple Computer
[2013.04.21 14:54:37 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Avg2013
[2013.02.07 18:17:26 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\B1E
[2013.03.17 15:18:09 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Diagnostics
[2013.03.02 00:13:59 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\ElevatedDiagnostics
[2013.01.25 23:40:14 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\fontconfig
[2013.01.25 23:40:11 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\gegl-0.2
[2013.01.18 21:36:48 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Google
[2011.12.09 18:36:13 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\HP
[2012.12.16 11:52:12 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Lidl_Fotos
[2012.06.24 20:57:25 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Macromedia
[2012.10.03 20:05:16 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\MFAData
[2013.02.14 14:08:40 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Microsoft
[2013.02.23 14:38:53 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Microsoft Help
[2012.06.11 19:15:42 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Mozilla
[2011.12.31 10:59:33 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Nokia
[2011.12.31 11:03:24 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\NokiaAccount
[2013.04.12 13:32:24 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Programs
[2012.12.26 14:38:43 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Quadriga Games
[2013.03.20 17:25:36 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\stellarium
[2013.04.21 15:37:07 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\temp
[2011.11.02 01:04:55 | 000,000,000 | -HSD | M] -- C:\Users\admin\AppData\Local\Temporary Internet Files
[2012.04.01 20:22:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\TomTom
[2011.11.02 01:04:55 | 000,000,000 | -HSD | M] -- C:\Users\admin\AppData\Local\Verlauf
[2012.09.05 22:40:27 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\VirtualStore
[2013.04.20 12:57:00 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\WBFSManager
[2013.01.26 00:53:36 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\webkit
[2012.09.14 21:05:54 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Local\Winterberg-Modifkation_fü
< %localappdata%\*.* >
[2012.09.19 09:14:32 | 000,005,632 | ---- | M] () -- C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.12.04 22:54:00 | 000,109,664 | ---- | M] () -- C:\Users\admin\AppData\Local\GDIPFONTCACHEV1.DAT
[2013.04.21 14:45:32 | 002,368,659 | -H-- | M] () -- C:\Users\admin\AppData\Local\IconCache.db
[2013.04.17 16:22:25 | 000,027,789 | ---- | M] () -- C:\Users\admin\AppData\Local\recently-used.xbel
< %allusersprofile%\*. >
[2013.01.13 00:14:37 | 000,000,000 | ---D | M] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013.02.07 18:23:59 | 000,000,000 | ---D | M] -- C:\ProgramData\4shared Desktop
[2012.12.18 16:37:02 | 000,000,000 | ---D | M] -- C:\ProgramData\Adobe
[2011.12.06 17:40:12 | 000,000,000 | ---D | M] -- C:\ProgramData\Ahead
[2011.11.02 01:04:45 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2013.01.13 00:39:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple
[2013.01.13 00:14:37 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple Computer
[2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2012.10.03 19:54:46 | 000,000,000 | ---D | M] -- C:\ProgramData\AVAST Software
[2012.10.07 22:48:26 | 000,000,000 | ---D | M] -- C:\ProgramData\AVG
[2012.06.08 16:26:46 | 000,000,000 | ---D | M] -- C:\ProgramData\Avira
[2012.09.04 22:36:56 | 000,000,000 | -H-D | M] -- C:\ProgramData\Common Files
[2011.12.23 21:13:21 | 000,000,000 | ---D | M] -- C:\ProgramData\CyberLink
[2012.12.13 13:02:54 | 000,000,000 | ---D | M] -- C:\ProgramData\DatacardService
[2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2011.11.02 01:04:45 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2011.11.02 01:04:45 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2011.12.09 18:33:43 | 000,000,000 | ---D | M] -- C:\ProgramData\Hewlett-Packard
[2011.12.09 18:36:15 | 000,000,000 | ---D | M] -- C:\ProgramData\HP
[2011.12.09 18:27:59 | 000,000,000 | ---D | M] -- C:\ProgramData\HP Product Assistant
[2011.12.07 21:22:53 | 000,000,000 | ---D | M] -- C:\ProgramData\ICQ
[2013.01.13 00:40:08 | 000,000,000 | ---D | M] -- C:\ProgramData\Lidl_Fotos
[2013.01.13 19:09:28 | 000,000,000 | ---D | M] -- C:\ProgramData\Logishrd
[2013.04.12 13:32:47 | 000,000,000 | ---D | M] -- C:\ProgramData\Malwarebytes
[2012.12.18 16:22:15 | 000,000,000 | ---D | M] -- C:\ProgramData\McAfee
[2013.04.21 14:54:46 | 000,000,000 | ---D | M] -- C:\ProgramData\MFAData
[2012.06.08 16:24:26 | 000,000,000 | --SD | M] -- C:\ProgramData\Microsoft
[2012.12.13 13:09:15 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft Help
[2012.06.11 19:15:37 | 000,000,000 | ---D | M] -- C:\ProgramData\Mozilla
[2011.12.06 17:38:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Nero
[2011.12.31 10:58:44 | 000,000,000 | ---D | M] -- C:\ProgramData\Nokia
[2011.12.31 10:55:59 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaInstallerCache
[2011.12.31 10:59:28 | 000,000,000 | ---D | M] -- C:\ProgramData\PC Suite
[2013.03.29 02:36:41 | 000,000,000 | ---D | M] -- C:\ProgramData\Skype
[2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2011.11.02 01:04:45 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2012.07.03 21:24:34 | 000,000,000 | ---D | M] -- C:\ProgramData\Sun
[2013.04.12 15:25:03 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP
[2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2012.04.01 20:23:04 | 000,000,000 | ---D | M] -- C:\ProgramData\TomTom
[2013.02.07 18:35:31 | 000,000,000 | ---D | M] -- C:\ProgramData\TuneUp Software
[2013.02.11 21:56:30 | 000,000,000 | ---D | M] -- C:\ProgramData\Uniblue
[2011.11.02 01:04:45 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2011.12.09 18:37:03 | 000,000,000 | ---D | M] -- C:\ProgramData\WEBREG
[2012.09.04 22:36:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2013.02.07 18:55:35 | 000,000,000 | -HSD | M] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2012.10.07 22:46:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
< %allusersprofile%\*.* >
[2013.02.28 13:29:13 | 000,003,600 | ---- | M] () -- C:\ProgramData\hpzinstall.log
< >
[2009.07.14 06:53:46 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.07.14 06:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2012.04.13 16:05:56 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
< HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Telephony\Providers >
"ProviderID0" = 1
"ProviderID1" = 2
"ProviderID2" = 3
"ProviderID3" = 4
"NextProviderID" = 5
"ProviderFileName0" = unimdm.tsp -- [2010.11.20 05:16:54 | 000,281,088 | ---- | M] (Microsoft Corporation)
"ProviderFileName1" = kmddsp.tsp -- [2009.07.14 03:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation)
"ProviderFileName2" = ndptsp.tsp -- [2009.07.14 03:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation)
"ProviderFileName3" = hidphone.tsp -- [2009.07.14 03:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation)
"NumProviders" = 4
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation /S >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache /S >
"DisplayName" = @%SystemRoot%\System32\dnsapi.dll,-101
"Group" = TDI
"ImagePath" = %SystemRoot%\system32\svchost.exe -k NetworkService -- [2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation)
"Description" = @%SystemRoot%\System32\dnsapi.dll,-102
"ObjectName" = NT AUTHORITY\NetworkService
"ErrorControl" = 1
"Start" = 2
"Type" = 32
"DependOnService" = Tdxnsi [binary data]
"ServiceSidType" = 1
"RequiredPrivileges" = SeChangeNotifyPrivilegeSeCreateGlobalPrivilege [binary data]
"FailureActions" = 80 51 01 00 00 00 00 00 00 00 00 00 03 00 00 00 14 00 00 00 01 00 00 00 C0 D4 01 00 01 00 00 00 E0 93 04 00 00 00 00 00 00 00 00 00 [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Parameters]
"ServiceDll" = %SystemRoot%\System32\dnsrslvr.dll -- [2011.03.03 07:38:01 | 000,132,608 | ---- | M] (Microsoft Corporation)
"ServiceDllUnloadOnStop" = 1
"extension" = %SystemRoot%\System32\dnsext.dll -- [2009.07.14 03:15:12 | 000,006,656 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Parameters\DnsCache]
"ShutdownOnIdle" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Security]
"Security" = 01 00 14 80 F8 00 00 00 04 01 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 C8 00 08 00 00 00 00 02 18 00 9D 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 02 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 02 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 04 00 00 00 00 02 14 00 8D 00 02 00 01 01 00 00 00 00 00 05 14 00 00 00 00 02 14 00 8D 00 02 00 01 01 00 00 00 00 00 05 13 00 00 00 00 02 18 00 CD 00 02 00 01 02 00 00 00 00 00 05 20 00 00 00 2C 02 00 00 00 02 28 00 CD 01 02 00 01 06 00 00 00 00 00 05 50 00 00 00 04 C9 44 AF 94 D9 D3 E5 2B E1 B7 1C 17 84 87 13 6E 1A FA 65 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00 [Binary data over 200 bytes]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\TriggerInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\TriggerInfo\0]
"Type" = 4
"Action" = 1
"GUID" = 07 9E 56 B7 21 84 E0 4E AD 10 86 91 5A FD AD 09 [binary data]
"Data0" = 5355UDP [binary data]
"DataType0" = 2
< HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost >
"RPCSS" = RpcEptMapperRpcSs [binary data]
"defragsvc" = defragsvc [binary data] -- [2009.07.14 03:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation)
"LocalSystemNetworkRestricted" = UxSmsWdiSystemHostNetmantrkwks [Binary data over 200 bytes]
"LocalService" = nsiWdiServiceHostw32timeEventSy [Binary data over 200 bytes]
"netsvcs" = AeLookupSvcCertPropSvcSCPolicySv [Binary data over 200 bytes]
"WerSvcGroup" = wersvc [binary data] -- [2009.07.14 03:16:18 | 000,065,024 | ---- | M] (Microsoft Corporation)
"LocalServiceNoNetwork" = DPSPLABFEmpssvcWwanSvc [binary data]
"termsvcs" = TermService [binary data]
"swprv" = swprv [binary data] -- [2009.07.14 03:16:15 | 000,313,856 | ---- | M] (Microsoft Corporation)
"LocalServiceNetworkRestricted" = DHCPeventlogAudioSrvBthHFSrvLm [Binary data over 200 bytes]
"LocalServicePeerNet" = PNRPSvcp2pimsvcp2psvcPnrpAutoReg [binary data]
"NetworkServiceAndNoImpersonation" = KtmRm [binary data]
"regsvc" = RemoteRegistry [binary data]
"LocalServiceAndNoImpersonation" = SSDPSRVupnphostSCardSvrTBSFont [Binary data over 200 bytes]
"DcomLaunch" = PowerPlugPlayDcomLaunch [binary data]
"NetworkServiceNetworkRestricted" = PolicyAgent [binary data]
"NetworkService" = CryptSvcDHCPTermServiceDNSCache [Binary data over 200 bytes]
"sdrsvc" = sdrsvc [binary data] -- [2010.11.20 05:21:08 | 000,125,952 | ---- | M] (Microsoft Corporation)
"WbioSvcGroup" = WbioSrvc [binary data] -- [2009.07.14 03:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation)
"imgsvc" = StiSvc [binary data]
"wcssvc" = WcsPlugInService [binary data] -- [2009.07.14 03:16:18 | 000,032,768 | ---- | M] (Microsoft Corporation)
"AxInstSVGroup" = AxInstSV [binary data] -- [2010.11.20 05:18:08 | 000,088,064 | ---- | M] (Microsoft Corporation)
"secsvcs" = WinDefend [binary data]
"bthsvcs" = bthserv [binary data] -- [2009.07.14 03:15:00 | 000,064,512 | ---- | M] (Microsoft Corporation)
"Update-Service-Installer-Service" = Update-Service-Installer-Service [binary data]
"Update-Service" = Update-Service [binary data]
"HPZ12" = Pml Driver HPZ12Net Driver HPZ12 [binary data]
"hpdevmgmt" = hpqcxs08hpqddsvc [binary data]
"HPService" = HPSLPSVC [binary data]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\AxInstSVGroup]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\defragsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalService]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalServiceAndNoImpersonation]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalServiceNetworkRestricted]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalServiceNoNetwork]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalSystemNetworkRestricted]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\netsvcs]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\NetworkService]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\NetworkServiceRemoteDesktopHyperVAgent]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\NetworkServiceRemoteDesktopPublishing]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\SDRSVC]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\swprv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\termsvcs]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\wcssvc]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\wercplsupport]
< HKEY_LOCAL_MACHINE\SOFTWARE\Joosoft.com >
[HKEY_LOCAL_MACHINE\SOFTWARE\Joosoft.com\UpdateClient]
< %SystemRoot%\system32\*.tsp >
[2009.07.14 03:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2009.07.14 03:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2009.07.14 03:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2009.07.14 03:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2010.11.20 05:16:54 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
< C:\Windows\system32\*.dll /510 >
[2013.01.20 15:46:51 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\admparse.dll
[2012.10.04 18:40:36 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
[2012.10.04 18:40:36 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
[2012.10.04 18:40:36 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
[2012.10.04 18:40:36 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
[2012.10.04 18:40:37 | 000,005,120 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 18:40:37 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
[2012.10.04 18:40:37 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
[2012.10.04 18:40:37 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.10.04 18:40:37 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
[2012.10.04 18:40:37 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
[2012.10.04 18:40:38 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.10.04 16:41:50 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
[2012.10.04 16:41:50 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
[2012.10.04 16:41:50 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
[2012.10.04 16:41:50 | 000,006,144 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
[2012.11.05 22:32:16 | 000,295,424 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\system32\atmfd.dll
[2012.11.05 22:32:09 | 000,034,304 | ---- | M] (Adobe Systems) -- C:\Windows\system32\atmlib.dll
[2012.07.04 23:14:34 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\browcli.dll
[2012.07.04 23:14:34 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\browser.dll
[2012.06.06 07:03:06 | 000,805,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\cdosys.dll
[2012.06.02 06:36:29 | 001,159,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\crypt32.dll
[2012.06.02 06:36:29 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\cryptnet.dll
[2012.06.02 06:36:29 | 000,140,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\cryptsvc.dll
[2012.08.02 18:57:20 | 000,490,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\d3d10level9.dll
[2012.09.25 00:16:53 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\system32\deployJava1.dll
[2012.10.09 19:40:31 | 000,193,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dhcpcore6.dll
[2012.10.09 19:40:31 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dhcpcsvc6.dll
[2012.11.02 07:11:31 | 000,376,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dpnet.dll
[2012.03.03 07:31:19 | 001,077,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\DWrite.dll
[2013.01.20 15:46:53 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dxtmsft.dll
[2013.01.20 15:46:53 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dxtrans.dll
[2013.01.20 15:46:53 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\icardie.dll
[2013.01.20 15:46:54 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\IEAdvpack.dll
[2013.01.20 15:46:54 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieakeng.dll
[2013.01.20 15:46:51 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieaksie.dll
[2013.01.20 15:46:51 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieakui.dll
[2013.01.20 15:46:53 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieapfltr.dll
[2013.01.20 15:46:52 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iedkcs32.dll
[2013.01.20 15:46:54 | 009,738,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieframe.dll
[2013.01.20 15:46:50 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iepeers.dll
[2013.01.20 15:46:53 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iernonce.dll
[2013.01.20 15:46:55 | 001,793,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iertutil.dll
[2013.01.20 15:46:53 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iesetup.dll
[2013.01.20 15:46:54 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iesysprep.dll
[2013.01.20 15:46:54 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieui.dll
[2012.03.01 07:33:23 | 000,159,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\imagehlp.dll
[2013.01.20 15:46:50 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\imgutil.dll
[2013.01.20 15:46:52 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\inseng.dll
[2012.10.03 18:40:35 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iphlpsvc.dll
[2013.01.20 15:46:51 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\jscript.dll
[2013.01.20 15:46:51 | 001,800,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\jscript9.dll
[2013.01.20 15:46:55 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\jsproxy.dll
[2012.08.11 01:56:14 | 000,542,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kerberos.dll
[2012.10.04 18:43:05 | 000,868,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kernel32.dll
[2012.10.04 18:43:05 | 000,293,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\KernelBase.dll
[2013.01.20 15:46:52 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\licmgr10.dll
[2012.05.14 06:33:42 | 000,769,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\localspl.dll
[2013.01.20 15:46:51 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msfeeds.dll
[2013.01.20 15:46:54 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msfeedsbs.dll
[2013.01.20 15:46:51 | 012,320,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mshtml.dll
[2013.01.20 15:46:52 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mshtmled.dll
[2013.01.20 15:46:54 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mshtmler.dll
[2012.04.07 13:26:29 | 002,342,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msi.dll
[2013.01.20 15:46:55 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msls31.dll
[2013.01.20 15:46:54 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msrating.dll
[2011.12.16 09:52:58 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msvcrt.dll
[2012.06.06 07:05:52 | 001,236,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msxml3.dll
[2012.06.06 07:05:52 | 001,390,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msxml6.dll
[2012.06.02 06:39:10 | 000,219,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ncrypt.dll
[2012.10.03 18:42:23 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ncsi.dll
[2012.07.04 23:16:56 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\netapi32.dll
[2012.10.03 18:42:24 | 000,175,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\netcorehc.dll
[2012.10.03 18:42:24 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\netevent.dll
[2012.10.03 18:42:26 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\nlaapi.dll
[2012.10.03 18:42:26 | 000,242,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\nlasvc.dll
[2012.09.25 00:16:58 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\system32\npDeployJava1.dll
[2012.01.04 10:58:41 | 000,442,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ntshrui.dll
[2013.01.20 15:46:51 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\occache.dll
[2013.01.20 15:46:51 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\pngfilt.dll
[2012.05.01 06:44:12 | 000,164,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\profsvc.dll
[2012.02.17 07:34:22 | 000,826,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpcore.dll
[2012.04.26 06:45:54 | 000,129,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpcorekmts.dll
[2012.04.26 06:45:55 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpwsx.dll
[2012.06.02 06:40:39 | 000,225,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\schannel.dll
[2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\shell32.dll
[2012.05.05 09:46:52 | 000,400,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\srcore.dll
[2012.09.26 00:47:43 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\synceng.dll
[2012.11.09 06:42:49 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\tzres.dll
[2011.12.07 21:20:54 | 000,114,000 | ---- | M] (Joosoft.com GmbH) -- C:\Windows\system32\UpdSvc.dll
[2013.01.20 15:46:52 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\url.dll
[2013.01.20 15:46:55 | 001,103,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\urlmon.dll
[2013.01.20 15:46:51 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\vbscript.dll
[2012.07.26 04:46:47 | 000,009,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Wdfres.dll
[2013.01.20 15:46:52 | 000,203,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\webcheck.dll
[2012.02.11 07:43:49 | 000,492,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\win32spl.dll
[2013.01.20 15:46:55 | 001,129,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wininet.dll
[2012.10.04 18:47:18 | 000,169,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\winsrv.dll
[2012.08.24 18:57:48 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wintrust.dll
[2012.03.01 07:29:16 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wmi.dll
[2012.06.03 00:19:23 | 000,577,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuapi.dll
[2012.06.03 00:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuaueng.dll
[2012.06.03 00:12:32 | 002,422,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wucltux.dll
[2012.07.26 05:20:40 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\WUDFCoinstaller.dll
[2012.07.26 05:20:40 | 000,172,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\WUDFPlatform.dll
[2012.07.26 05:20:40 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\WUDFSvc.dll
[2012.07.26 05:20:40 | 000,613,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\WUDFx.dll
[2012.06.03 00:12:13 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wudriver.dll
[2012.06.03 00:19:32 | 000,035,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wups.dll
[2012.06.03 00:19:33 | 000,045,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wups2.dll
[2012.06.02 15:19:42 | 000,171,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuwebv.dll
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:373E1720
< End of report > Extras: Code:
OTL Extras logfile created on: 21.04.2013 16:01:15 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\admin\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 1,26 Gb Available Physical Memory | 63,38% Memory free
3,98 Gb Paging File | 3,25 Gb Available in Paging File | 81,74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 148,95 Gb Total Space | 73,24 Gb Free Space | 49,17% Space Free | Partition Type: NTFS
Drive E: | 980,72 Mb Total Space | 963,09 Mb Free Space | 98,20% Space Free | Partition Type: FAT
Computer Name: ADMIN-PC | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: On | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
[HKEY_USERS\S-1-5-21-2070048282-3062225414-2777264324-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0289E9E9-D67F-44F3-BE71-27C1F1AC56DD}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{0294BB2F-6178-459D-8C46-8D1C40D6AD6B}" = rport=445 | protocol=6 | dir=out | app=system |
"{057550CC-1C7E-4C7B-A2F8-3A8DDC978C8C}" = lport=138 | protocol=17 | dir=in | app=system |
"{08E024BB-596A-4DFF-A430-159062EB67CE}" = lport=10243 | protocol=6 | dir=in | app=system |
"{19A5737B-0BEE-43C8-BCD3-3CC714AA4FD3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1C394E5E-2E0C-4AD5-9C1B-5098278624AA}" = lport=2869 | protocol=6 | dir=in | app=system |
"{25B9D31D-64EC-44F5-900B-17177C3E5D3C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{295EF879-34FC-4A05-A484-51AA1443280E}" = lport=445 | protocol=6 | dir=in | app=system |
"{2FA65B31-3A9D-4C20-AFC6-469495F0EF44}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{355A1ACA-3F2B-4202-9A10-6147424261B5}" = lport=139 | protocol=6 | dir=in | app=system |
"{39F2ABB6-1029-46BF-A08F-FCFC41AD9517}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4084E937-EAAA-47EE-9520-7BE7CE434C09}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{46D5062C-885A-4538-AB24-3357C7F8568D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4BF5EB07-06A2-40E2-B5B6-244EF5C49A0F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{5456EA1E-AF45-48BD-9C96-AB99A6CCF1D9}" = lport=139 | protocol=6 | dir=in | app=system |
"{57149B98-5C92-488D-882A-B74BD265F0AA}" = lport=445 | protocol=6 | dir=in | app=system |
"{6364B77A-8796-4078-B3CC-5963A3E70B4F}" = rport=139 | protocol=6 | dir=out | app=system |
"{6EFD3216-D4DB-448C-81DA-E8838C66FFD2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{73C6DC07-F045-4C18-86F9-2C6C586DA669}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{774F41E2-5835-4573-AA04-BC7731DDC493}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7823D2DD-4AD8-49EC-B85C-21F8F34C469D}" = rport=139 | protocol=6 | dir=out | app=system |
"{79521F5B-3BB3-4181-851D-75FD5E1912EB}" = rport=10243 | protocol=6 | dir=out | app=system |
"{7C7BD74E-D59D-40F9-8481-A74C4729E9DD}" = rport=138 | protocol=17 | dir=out | app=system |
"{7D8E1B99-D293-4315-B15F-C8D0CF1FC81B}" = rport=137 | protocol=17 | dir=out | app=system |
"{86444BB3-291D-4D31-A046-BB4AA3243C28}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{890E2FA0-A3CF-4C4D-BB1F-6FDAED88378F}" = lport=137 | protocol=17 | dir=in | app=system |
"{89CAA971-B27E-4AC9-9370-93953ED517D1}" = rport=445 | protocol=6 | dir=out | app=system |
"{98695CDB-4EA9-4CB9-B32C-71BCDE137CB9}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{99D6CF52-8945-4E15-A0A3-B94739825897}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A2847679-68B1-4355-87C5-0CC6A1040CBF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A768A429-5B60-42D5-8EE1-7BC79AA6290C}" = rport=138 | protocol=17 | dir=out | app=system |
"{AA851CA5-89F2-4D1E-A067-619E6754C21F}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{AF8150A9-8B4A-4262-900E-D368942052B3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B576B953-B857-4AB5-A852-E18B0DEFE0F7}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{BA2BB780-436E-45C7-AFBD-103B23D281F0}" = lport=138 | protocol=17 | dir=in | app=system |
"{BA76A520-263C-48BC-B9B9-43F3B9205E6E}" = lport=10243 | protocol=6 | dir=in | app=system |
"{BAD42DA8-4A18-4FDD-8C1F-57D7A5A8C124}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{BE10AB93-C4A6-464B-BE93-069E778BFF99}" = rport=10243 | protocol=6 | dir=out | app=system |
"{C232D951-55E7-4D04-9346-F88A07FC0B22}" = lport=137 | protocol=17 | dir=in | app=system |
"{C390A5C5-F78A-4FAD-B42D-FBC01752BC62}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C428A183-FD79-40B5-990D-895328F43AC8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CBD68C1E-4E6B-4AF9-824C-20695B503522}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CF0676E6-E2EC-438A-9741-7029DEBD00CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EF39548D-8A5B-4381-8B2B-134C0DA50873}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F534D21D-02A4-4E48-A237-A3745ED5E6D3}" = rport=137 | protocol=17 | dir=out | app=system |
"{F9C1EEE5-72B7-40C6-BC7C-64E9DF7DEB39}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{003C7A18-60D9-4C89-94D8-DE42C1AA1D76}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{02A4D600-582A-4C14-ADFE-C125CF0CB18F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{08784D4D-4A8C-458F-B75A-F55AE13BDA90}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{0A9D4366-EEF8-4347-8F6D-CE5E8D44D889}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe |
"{0AE6F878-56CA-4C71-8324-3B3BA7A22E5B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{1473D86F-6F04-46A3-9153-CD04272511DC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{1480D539-CB0D-467C-B9A2-574E013E339C}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{15467F33-B300-40DC-8300-B0163A3F1124}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1561E84A-1A89-4E87-B119-312BEB19CD30}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxs08.exe |
"{15713B3A-0202-4C1E-A474-0A033D4C6C61}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{19B76E88-E8E2-43B1-977C-94DCD0CF13F3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{1AEAEBD9-4106-4BF0-AC45-A14375CF76DE}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{1BD5047D-99E7-4699-9335-5D64F38B12ED}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{1C1A42FB-7147-421B-AC2F-47408E03A838}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{200EDC43-1E0E-4384-A7E8-C870EC3F8F04}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{234940D2-34CF-41B8-A688-6505792B0D49}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{26112E74-3C0F-4B58-8D14-DA1AC4645928}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxm08.exe |
"{287EC52A-C4DC-417B-B26F-12D7680C60ED}" = dir=in | app=c:\program files\iminent\iminent.messengers.exe |
"{31A6C8D1-8585-4009-9D04-A586C083E1EE}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{39A728D7-0E1E-433D-B37B-5B8739EAF1CB}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{3D0CBA47-BDA9-4E60-963D-EDACE08EA474}" = protocol=6 | dir=out | app=system |
"{471877E7-283B-493C-AC1D-41A02D9D9324}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{4849799C-D8E9-4360-8F9A-6B5F2BCC7EA4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{48C53922-A352-44C6-ADA4-F9A5313FFD38}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{4DCCB63F-DE35-4DAB-A6C4-BDBF66F51B22}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{4F606E6C-D5EA-453E-80BC-BCA5D96B4E52}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{50CE4F52-9AA3-414D-9813-F03377AE5740}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{5406DA16-0C76-484E-933E-723D202D04FE}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{546E396B-04E8-4A0A-A245-6EBFBBA8879A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{56E808A1-BFD0-4B79-B567-B9FA848D697F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{5D393711-DBDC-4ED6-A5D4-9F09A346FC9C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{606ABA54-3E3F-453A-B852-B380B8928AB5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{61FB8AD2-C831-45AB-9DFB-D685C3A8300D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{62F27534-2769-4D2F-B42F-E96E62F64F44}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{63D4DAEA-A79A-4092-A3E8-9D1132F993B4}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{65901CFC-D156-4C8F-90EA-C26D256CA195}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{660D1945-7033-4D99-8DFA-9117A297B03E}" = protocol=17 | dir=in | app=c:\users\admin\appdata\roaming\utorrent\utorrent.exe |
"{687368C9-6511-41BB-8A3C-BCB1F983D05B}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe |
"{68F6992D-6E9D-4F14-88EC-3E0B8BEC7EFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6BEA9F89-E530-4AA6-AD54-709BA444C256}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |
"{70402E3D-CACD-4009-974A-CBE5EE3DCA34}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{73FE9AA5-A40B-4753-B4BE-DC36B7384B2A}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpzwiz01.exe |
"{783461E1-F80F-4872-A302-9D9A725D1BD0}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe |
"{7A222CF1-BB25-4278-B851-15F3124ACC81}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{7EFA88AF-88E3-419D-8C36-CD158F2A4A05}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{830F3040-1134-4873-BD44-83A33D4D9A0E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{8642AF85-31DC-4BB3-8E9D-1E478C224084}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{868A2495-8EDA-4F85-963E-C10E1F3E53B8}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe |
"{90FFB48E-D85F-409F-A5EA-669E4BCE0F23}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{96B4EB9B-7041-4C9D-BF26-F51FE3F0AE9D}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe |
"{9EC62232-5A57-4FF3-A3FE-EA2399E5CE5B}" = dir=in | app=c:\program files\iminent\iminent.exe |
"{A04F41B7-65CF-4239-95F1-A7124624E31D}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{A092F86B-00F8-4F36-AFE0-98043A938204}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{A2C90C10-4D9E-41EB-8084-78285E238F0D}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{A465FB40-F1A7-4665-B4EA-A25C8BABE5C9}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{A5589677-56C4-46C1-A86B-1F0B5425786F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A7833B24-47F2-4ACE-A17E-1CEFE274AFB4}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{A9612641-1071-4090-A778-59B3F557D6D4}" = protocol=6 | dir=in | app=c:\users\admin\appdata\roaming\utorrent\utorrent.exe |
"{AB3FBA72-52C3-4476-9A38-230DBE05659B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{AC2AF457-5267-4E51-8993-4AA19E15E810}" = dir=in | app=d:\setup\hpznui01.exe |
"{B1A487DF-0EA5-4CBB-9FF2-9152D0671D4E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B9C8E8F5-C6E3-4520-988D-AA50E318D30E}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{BC37089C-B844-4C58-9369-75C2C2FF1F0E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BC7833D1-AE4B-4CAB-BDD5-6EA587E5C763}" = protocol=6 | dir=out | app=system |
"{BE2B4925-D9A6-4B0C-B305-0831BBD00CCB}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqfxt08.exe |
"{BF9D6D6E-0828-414E-803F-7E277B6CDA32}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C014B92D-D2C5-43C1-A260-862F12F342B2}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{C0C410ED-7072-4BC7-8783-4CC47666B314}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{C277039F-73E7-4586-B23C-DD42B7D0F8F7}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{CE504808-152F-4073-8BB9-0F8E7C4D30C6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D08BEB11-F339-454C-922E-F47544319100}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{D0F48B35-C3AF-4234-AE37-48B22AC63EC6}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{D3648D1D-2BA3-4973-9B7E-EDC907B6E342}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D6964518-0A82-4623-A2EC-BA0D8E943903}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposfx08.exe |
"{E08AD3A1-9E0C-4745-978A-C14ABD58B5A2}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{E2DE239C-0F7A-45E2-A325-EA32A31B64D1}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{E4A49ECF-B99E-45C5-B75F-BCC3C4D7120B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E5E513C6-05C3-4D83-81C7-375A85EAC4B7}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{E81E0E3A-96DE-48BE-8638-C4F4B630D41D}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe |
"{E8715BB0-E132-4617-B344-62E03BFE2C1C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E926E57D-011D-4F63-BCC5-FFCFDC28D091}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EDEBA130-3735-485B-B5C7-A9C7C0217C02}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EF5F63B1-EABE-4E71-8C7A-B9ED5136F9B2}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{EF97AA4B-128D-452E-8ED0-F0180134A473}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{EFA98652-B437-42AA-B7D3-EFFD71ED4ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F7DCF881-DB9D-4779-8D1C-CCCBAC7C73FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{80D7F786-A2B3-4529-BA5A-D59B0352BAB8}C:\users\admin\documents\technisches\emergency4\em4.exe" = protocol=6 | dir=in | app=c:\users\admin\documents\technisches\emergency4\em4.exe |
"TCP Query User{A2F8FF65-F4EC-498E-910B-2421A5ECEE45}C:\users\admin\appdata\local\temp\fritz!wlan repeater 300e\fsetup.exe" = protocol=6 | dir=in | app=c:\users\admin\appdata\local\temp\fritz!wlan repeater 300e\fsetup.exe |
"TCP Query User{A6767E04-E570-417C-8262-B36DBA18D63D}C:\program files\icq7.6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.6\icq.exe |
"TCP Query User{A893A849-8354-4D89-AD7C-9D3D91DE1984}C:\users\admin\desktop\utorrent-3.3.0.29462.exe" = protocol=6 | dir=in | app=c:\users\admin\desktop\utorrent-3.3.0.29462.exe |
"TCP Query User{B6E5B9B5-B072-440A-A0D6-33747DBBC48D}C:\users\admin\appdata\local\temp\fritz!wlan repeater 300e\fsetup.exe" = protocol=6 | dir=in | app=c:\users\admin\appdata\local\temp\fritz!wlan repeater 300e\fsetup.exe |
"TCP Query User{E8F63785-51CB-4916-BA80-2FA5D4248D50}C:\program files\sixteen tons entertainment\emergency4\em4.exe" = protocol=6 | dir=in | app=c:\program files\sixteen tons entertainment\emergency4\em4.exe |
"UDP Query User{51981182-A0A1-461D-BC92-A82DDB6FBE91}C:\users\admin\appdata\local\temp\fritz!wlan repeater 300e\fsetup.exe" = protocol=17 | dir=in | app=c:\users\admin\appdata\local\temp\fritz!wlan repeater 300e\fsetup.exe |
"UDP Query User{94E9C410-298E-481A-8C0C-40994B59A17B}C:\users\admin\desktop\utorrent-3.3.0.29462.exe" = protocol=17 | dir=in | app=c:\users\admin\desktop\utorrent-3.3.0.29462.exe |
"UDP Query User{CC661B3B-EBC3-41D3-84EB-1155D7B14F67}C:\users\admin\appdata\local\temp\fritz!wlan repeater 300e\fsetup.exe" = protocol=17 | dir=in | app=c:\users\admin\appdata\local\temp\fritz!wlan repeater 300e\fsetup.exe |
"UDP Query User{CC9D2AFA-44DD-4A9F-9927-41AE62A6374C}C:\program files\sixteen tons entertainment\emergency4\em4.exe" = protocol=17 | dir=in | app=c:\program files\sixteen tons entertainment\emergency4\em4.exe |
"UDP Query User{E6BC30C9-7554-439F-AB28-75CF185C5BF2}C:\users\admin\documents\technisches\emergency4\em4.exe" = protocol=17 | dir=in | app=c:\users\admin\documents\technisches\emergency4\em4.exe |
"UDP Query User{E9AF8593-1423-44E5-A3E2-3E87136E31B0}C:\program files\icq7.6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.6\icq.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{013C4AC1-64FB-46EA-9320-D34CEB65BDBC}" = AVG 2013
"{0680FE0B-DEBA-419F-A0AC-8D990F32DE60}" = AVG 2013
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0A5825FD-0FB7-4e45-9037-858D463F2943}" = BPDSoftware
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{2951A232-69BA-4925-BB9A-CEEB72B18B4F}" = BPDSoftware_Ini
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{3A4D5E2D-988D-4ee9-8E7F-3AC200A2B8F5}" = 4500G510nz_Software_Min
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{40255140-E947-46E1-A841-C1F27AB309CB}" = AVG 2013
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{446472DE-79C0-4708-B06E-0F8FAFDA6918}" = AVG 2013
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{55EB7967-5BB1-4EA2-8AFF-B2F9E487E553}" = PC Connectivity Solution
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{572F2A62-70CD-4429-8758-6D4D6DC696E1}" = 4500_Help
"{5B05FF91-F20C-4832-A8DE-E1912639C17C}" = 4500G510nz
"{5BB4D7C1-52F2-4BFD-9E40-0D419E2E3021}" = bpd_scan
"{5D412B61-F3A7-42C6-9C07-29BBD3D442B1}" = AVG 2013
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6697D99E-E550-4498-B793-4A8DD8A1821F}" = ProductContext
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{690879A5-18EF-447B-98D6-B699D51008AB}" = 4500_G510nz_Help
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}" = HP Officejet 4500 G510n-z
"{8E503D23-7969-45EE-B488-F80B8AE28D39}" = AVG 2013
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4C534E-431F-4A17-97D4-D1682B19A054}" = Emergency4
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.02) - Deutsch
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B2455727-ED8F-4643-8A6E-F4AB8DE3633D}" = Network
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{E11448F2-0B44-4239-B04E-D88FE743E929}" = Officejet J4500 Series
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{EF3E420F-2DCF-4C24-8E37-896801901031}" = Nero 7 Essentials
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4811919-F252-4B25-9AB2-8859A85810B5}" = TuneUp Utilities Language Pack (de-DE)
"{F6D8F2FE-B9BE-4C7C-98F2-2954B5A26AF2}" = SZS Modifier
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FDEC11CC-4BD6-4a8c-A398-3CCD8E43EACA}" = J4500
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG" = AVG 2013
"Avira AntiVir Desktop" = Avira Free Antivirus
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"GIMP-2_is1" = GIMP 2.8.2
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HP Document Manager" = HP Document Manager 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Mozilla Firefox 20.0 (x86 de)" = Mozilla Firefox 20.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"ST6UNST #1" = FMS32-PRO Version 3.1.5
"ST6UNST #2" = FMS32-PRO Version 3.1.5 (C:\Program Files\Heirue-Soft\FMS32-PRO\)
"TeamViewer 7" = TeamViewer 7
"TVWiz" = Intel(R) TV Wizard
"uTorrent" = µTorrent
"WBFS Manager 3.0" = WBFS Manager 3.0
"WinRAR archiver" = WinRAR 4.20 (32-Bit)
========== Last 20 Event Log Errors ==========
Error: Unable to start EventLog service!
< End of report > |