kroko998 | 17.05.2013 20:19 | Scan gestartet, wie lange dauert der ca?
Und danke für die schnelle Hilfe/antwort :-)
OTL.txt:OTL Logfile: Code:
OTL logfile created on: 17.05.2013 21:17:20 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\tobi\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
3,50 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 85,71% Memory free
7,00 Gb Paging File | 6,57 Gb Available in Paging File | 93,84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465,57 Gb Total Space | 192,14 Gb Free Space | 41,27% Space Free | Partition Type: NTFS
Drive D: | 1,86 Gb Total Space | 1,69 Gb Free Space | 90,91% Space Free | Partition Type: FAT
Drive E: | 612,32 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: TOBI7 | User Name: tobi | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\tobi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\HelpPane.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\WinRAR\rarext.dll ()
========== Services (SafeList) ==========
SRV - (AntiVirWebService) -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirMailService) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Hamachi2Svc) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (TunngleService) -- C:\Program Files\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (BBSvc) -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (BBUpdate) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (NMSAccess) -- C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (StarWindServiceAE) -- C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe (StarWind Software)
SRV - (RalinkRegistryWriter) -- C:\Program Files\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (VGPU) -- System32\drivers\rdvgkmd.sys File not found
DRV - (tsusbhub) -- system32\drivers\tsusbhub.sys File not found
DRV - (Synth3dVsc) -- System32\drivers\synth3dvsc.sys File not found
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (seehcri) -- C:\Windows\System32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (sptd) -- C:\Windows\System32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (StarOpen) -- C:\Windows\System32\drivers\StarOpen.sys ()
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) -- C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (tap0901t) -- C:\Windows\System32\drivers\tap0901t.sys (Tunngle.net)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (e1express) -- C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (netr28u) -- C:\Windows\System32\drivers\netr28u.sys (Ralink Technology Corp.)
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (mcdbus) -- C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (Ser2pl) -- C:\Windows\System32\drivers\ser2pl.sys (Prolific Technology Inc.)
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
IE - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 49 FC 1C 21 2D 53 CE 01 [binary data]
IE - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\..\SearchScopes\{22074F30-1E15-4F60-A8D3-99DD32112A05}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10263&src=kw&q={searchTerms}&locale=de_AT&apn_ptnrs=^AGU&apn_dtid=^YYYYYY^YY^AT&apn_uid=091015d2-1c53-46cd-a239-13fbab103c7e&apn_sauid=0B83C6C6-8EE7-4A77-8B61-DB99081B4273
IE - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..extensions.enabledAddons: toolbar@ask.com:3.15.13.100015
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - prefs.js..extensions.enabledItems: battlefieldheroespatcher@ea.com:5.0.134.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.12.25 13:29:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.12.25 13:29:02 | 000,000,000 | ---D | M]
[2010.04.16 06:08:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\tobi\AppData\Roaming\mozilla\Extensions
[2012.12.29 00:05:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\oei649hi.default\extensions
[2012.03.13 20:38:42 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\oei649hi.default\extensions\battlefieldheroespatcher@ea.com
[2013.01.17 15:03:48 | 000,000,000 | ---D | M] ("Avira SearchFree Toolbar plus Web Protection") -- C:\Users\tobi\AppData\Roaming\mozilla\Firefox\Profiles\oei649hi.default\extensions\toolbar@ask.com
[2012.08.06 16:53:50 | 000,007,915 | ---- | M] () (No name found) -- C:\Users\tobi\AppData\Roaming\mozilla\firefox\profiles\oei649hi.default\extensions\toolbar@ask.com\chrome\content\view_expiry.js
[2012.08.07 01:53:50 | 000,007,915 | ---- | M] () (No name found) -- C:\Users\tobi\AppData\Roaming\mozilla\firefox\profiles\oei649hi.default\extensions\toolbar@ask.com\chrome\content\Abine\chrome\content\ff\view_expiry.js
[2013.02.15 14:36:26 | 000,002,413 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\mozilla\firefox\profiles\oei649hi.default\searchplugins\askcom.xml
[2012.12.25 13:29:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2012.12.25 13:29:01 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.12.27 10:28:31 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012.12.25 13:28:59 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.12.25 13:28:59 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.12.25 13:28:59 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.12.25 13:28:59 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.12.25 13:28:59 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.12.25 13:28:59 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - default_search_provider: Ask (Enabled)
CHR - default_search_provider: search_url = hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=AVR-4&o=APN10263&locale=de_AT&apn_uid=091015d2-1c53-46cd-a239-13fbab103c7e&apn_ptnrs=%5EAGU&apn_sauid=0B83C6C6-8EE7-4A77-8B61-DB99081B4273&apn_dtid=%5EYYYYYY%5EYY%5EAT&q={searchTerms}
CHR - default_search_provider: suggest_url = hxxp://ss.websearch.ask.com/query?qsrc=2922&li=ff&sstype=prefix&q={searchTerms}
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - Extension: Avira Toolbar = C:\Users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaabfjnbeinlpljodiajipidiompfl\7.15.11.33397_0\
CHR - Extension: Google Drive = C:\Users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Google Mail = C:\Users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-1607755728-43842115-2870295034-1003..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKU\S-1-5-21-1607755728-43842115-2870295034-1003..\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Apple Inc.)
O4 - HKU\S-1-5-21-1607755728-43842115-2870295034-1003..\Run: [ctfmon.exe] C:\ProgramData\6z7ddo.dat (Microsoft Corporation)
O4 - HKU\S-1-5-21-1607755728-43842115-2870295034-1003..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKU\S-1-5-21-1607755728-43842115-2870295034-1003..\Run: [Speech Recognition] C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [scan_after_setup] c:\program files\avira\antivir desktop\avcenter.exe (Avira Operations GmbH & Co. KG)
O4 - HKU\S-1-5-18..\RunOnce: [scan_after_setup] c:\program files\avira\antivir desktop\avcenter.exe (Avira Operations GmbH & Co. KG)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\matis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = File not found
O4 - Startup: C:\Users\matis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\..Trusted Domains: livemeeting.com ([]https in Internet)
O15 - HKU\S-1-5-21-1607755728-43842115-2870295034-1003\..Trusted Domains: microsoftonline.com ([]https in Local intranet)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} hxxp://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.134.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: iLO 2 Remote Console Applet https://172.23.23.9/dvc.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CADAC394-445C-409E-9C8C-B359EB365CAB}: DhcpNameServer = 10.0.10.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006.09.12 13:05:25 | 001,003,520 | R--- | M] (Microsoft Corporation) - E:\autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2006.09.12 13:08:36 | 000,000,166 | R--- | M] () - E:\Autorun.inf -- [ CDFS ]
O33 - MountPoints2\{7eddc5ec-4267-11df-8347-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7eddc5ec-4267-11df-8347-806e6f6e6963}\Shell\AutoRun\command - "" = E:\autorun.exe -- [2006.09.12 13:05:25 | 001,003,520 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\{7eddc5ec-4267-11df-8347-806e6f6e6963}\Shell\setup\command - "" = E:\setup.exe -- [2006.09.20 16:16:48 | 000,253,952 | R--- | M] ()
O33 - MountPoints2\{d64d5a87-94ab-11df-9035-001bfcfa842f}\Shell - "" = AutoRun
O33 - MountPoints2\{d64d5a87-94ab-11df-9035-001bfcfa842f}\Shell\AutoRun\command - "" = G:\Setup.exe
O33 - MountPoints2\{d64d5a87-94ab-11df-9035-001bfcfa842f}\Shell\setup\command - "" = G:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.05.17 21:15:39 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\tobi\Desktop\OTL.exe
[2013.05.17 20:34:25 | 000,000,000 | ---D | C] -- C:\Users\tobi\AppData\Local\AskToolbar
[2013.05.17 20:33:47 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\ProgramData\6z7ddo.dat
[2013.05.17 20:33:47 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\ProgramData\rundll32.exe
[2013.05.17 20:33:42 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Users\tobi\7109388.dll
[2013.05.17 18:21:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GeoGebra 4.2
[2013.05.17 18:21:46 | 000,000,000 | ---D | C] -- C:\Program Files\GeoGebra 4.2
[2013.05.10 10:29:44 | 000,000,000 | ---D | C] -- C:\Users\tobi\AppData\Local\Game Dev Tycoon
[2013.05.10 10:29:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Dev Tycoon
[2013.05.10 10:29:05 | 000,000,000 | ---D | C] -- C:\Program Files\Game Dev Tycoon
[2013.05.10 10:28:48 | 000,000,000 | ---D | C] -- C:\Users\tobi\AppData\Local\Programs
[2013.05.10 10:28:26 | 111,408,498 | ---- | C] (Greenheart Games Pty. Ltd. ) -- C:\Users\tobi\Desktop\GameDevTycoon-135.exe
[2013.05.06 12:33:13 | 000,066,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avnetflt.sys
[2013.05.01 13:05:16 | 000,000,000 | ---D | C] -- C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\School Tycoon
[2013.05.01 13:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Cat Daddy Games
[2013.04.24 21:45:47 | 000,000,000 | ---D | C] -- C:\Users\tobi\Documents\Stronghold Crusader
[2013.04.23 21:58:48 | 000,000,000 | ---D | C] -- C:\Users\tobi\Documents\Stronghold Legends
[2013.04.23 20:08:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Firefly Studios
[2013.04.23 20:07:49 | 000,000,000 | ---D | C] -- C:\Users\tobi\Documents\Stronghold 2
[2013.04.22 20:45:00 | 000,000,000 | ---D | C] -- C:\Program Files\Firefly Studios
========== Files - Modified Within 30 Days ==========
[2013.05.17 21:15:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\tobi\Desktop\OTL.exe
[2013.05.17 20:52:35 | 008,554,806 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.05.17 20:52:35 | 002,803,486 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.05.17 20:52:35 | 000,299,742 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.05.17 20:52:35 | 000,037,606 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.05.17 20:48:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.05.17 20:48:17 | 2817,925,120 | -HS- | M] () -- C:\hiberfil.sys
[2013.05.17 20:46:00 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.05.17 20:41:44 | 095,023,320 | ---- | M] () -- C:\ProgramData\odd7z6.pad
[2013.05.17 20:41:15 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.05.17 20:39:36 | 000,014,800 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.05.17 20:39:36 | 000,014,800 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.05.17 20:34:06 | 000,001,025 | ---- | M] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\msconfig.lnk
[2013.05.17 20:33:56 | 000,002,633 | ---- | M] () -- C:\ProgramData\odd7z6.js
[2013.05.17 20:33:47 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\6z7ddo.dat
[2013.05.17 20:33:47 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\rundll32.exe
[2013.05.17 20:33:42 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Users\tobi\7109388.dll
[2013.05.17 20:11:00 | 000,000,316 | ---- | M] () -- C:\Windows\tasks\Microsoft.OnlineManagement.UpdateAgentTask.job
[2013.05.17 18:32:26 | 000,074,736 | ---- | M] () -- C:\Users\tobi\Documents\Mathe Geogebra 9.67).odt
[2013.05.17 18:21:56 | 000,001,809 | ---- | M] () -- C:\Users\Public\Desktop\GeoGebra.lnk
[2013.05.10 20:42:27 | 000,025,942 | ---- | M] () -- C:\Users\tobi\Documents\Mittsommermord Inhaltsangabe+Interpretation.odt
[2013.05.10 20:41:05 | 000,019,654 | ---- | M] () -- C:\Users\tobi\Documents\Mittsommermord Interpretation.odt
[2013.05.10 20:35:50 | 000,024,779 | ---- | M] () -- C:\Users\tobi\Documents\Mittsommermord Inhaltsangabe.odt
[2013.05.10 10:29:22 | 000,001,921 | ---- | M] () -- C:\Users\Public\Desktop\Game Dev Tycoon.lnk
[2013.05.07 17:56:55 | 199,416,992 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013.05.06 12:32:51 | 000,066,656 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avnetflt.sys
[2013.05.03 17:57:10 | 111,408,498 | ---- | M] (Greenheart Games Pty. Ltd. ) -- C:\Users\tobi\Desktop\GameDevTycoon-135.exe
[2013.05.01 13:05:16 | 000,003,007 | ---- | M] () -- C:\Users\tobi\Desktop\School Tycoon.lnk
[2013.04.22 21:02:27 | 000,001,968 | ---- | M] () -- C:\Users\Public\Desktop\Stronghold Legends.lnk
[2013.04.22 20:56:02 | 000,001,872 | ---- | M] () -- C:\Users\Public\Desktop\Stronghold 2.lnk
[2013.04.22 20:51:41 | 000,002,046 | ---- | M] () -- C:\Users\Public\Desktop\Stronghold Crusader Extreme.lnk
[2013.04.22 20:51:41 | 000,001,990 | ---- | M] () -- C:\Users\Public\Desktop\Stronghold Crusader.lnk
[2013.04.22 20:46:24 | 000,001,848 | ---- | M] () -- C:\Users\Public\Desktop\Stronghold.lnk
[2013.04.20 10:32:43 | 000,015,740 | ---- | M] () -- C:\Users\tobi\Documents\Englisch Application-- Üben f d SA.odt
========== Files Created - No Company Name ==========
[2013.05.17 20:34:06 | 000,001,025 | ---- | C] () -- C:\Users\tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\msconfig.lnk
[2013.05.17 20:33:56 | 000,002,633 | ---- | C] () -- C:\ProgramData\odd7z6.js
[2013.05.17 20:33:54 | 095,023,320 | ---- | C] () -- C:\ProgramData\odd7z6.pad
[2013.05.17 18:32:23 | 000,074,736 | ---- | C] () -- C:\Users\tobi\Documents\Mathe Geogebra 9.67).odt
[2013.05.17 18:21:56 | 000,001,809 | ---- | C] () -- C:\Users\Public\Desktop\GeoGebra.lnk
[2013.05.10 20:42:26 | 000,025,942 | ---- | C] () -- C:\Users\tobi\Documents\Mittsommermord Inhaltsangabe+Interpretation.odt
[2013.05.10 10:29:22 | 000,001,921 | ---- | C] () -- C:\Users\Public\Desktop\Game Dev Tycoon.lnk
[2013.05.01 13:05:16 | 000,003,007 | ---- | C] () -- C:\Users\tobi\Desktop\School Tycoon.lnk
[2013.04.22 21:02:27 | 000,001,968 | ---- | C] () -- C:\Users\Public\Desktop\Stronghold Legends.lnk
[2013.04.22 20:56:02 | 000,001,872 | ---- | C] () -- C:\Users\Public\Desktop\Stronghold 2.lnk
[2013.04.22 20:51:41 | 000,002,046 | ---- | C] () -- C:\Users\Public\Desktop\Stronghold Crusader Extreme.lnk
[2013.04.22 20:51:41 | 000,001,990 | ---- | C] () -- C:\Users\Public\Desktop\Stronghold Crusader.lnk
[2013.04.22 20:46:24 | 000,001,848 | ---- | C] () -- C:\Users\Public\Desktop\Stronghold.lnk
[2013.04.20 10:32:41 | 000,015,740 | ---- | C] () -- C:\Users\tobi\Documents\Englisch Application-- Üben f d SA.odt
[2012.09.05 19:54:42 | 000,000,000 | ---- | C] () -- C:\Windows\System32\Access.dat
[2011.06.24 07:24:44 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.06.24 07:24:33 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011.06.21 19:58:53 | 000,000,482 | RHS- | C] () -- C:\Users\tobi\ntuser.pol
[2011.06.21 18:31:14 | 000,000,546 | RHS- | C] () -- C:\ProgramData\ntuser.pol
========== ZeroAccess Check ==========
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 04:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report > --- --- ---
Extras.txt:OTL Logfile: Code:
OTL Extras logfile created on: 17.05.2013 21:17:20 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\tobi\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
3,50 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 85,71% Memory free
7,00 Gb Paging File | 6,57 Gb Available in Paging File | 93,84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465,57 Gb Total Space | 192,14 Gb Free Space | 41,27% Space Free | Partition Type: NTFS
Drive D: | 1,86 Gb Total Space | 1,69 Gb Free Space | 90,91% Space Free | Partition Type: FAT
Drive E: | 612,32 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: TOBI7 | User Name: tobi | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1607755728-43842115-2870295034-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "%1"
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0114DE8E-CF4F-4A2B-821A-8EB9552361DC}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{05FA732C-5BEF-41E8-9AB5-93A4A8BA3730}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{0D8601D4-A572-46B6-BF02-EECD15D5B4BB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{169CD5C8-4D6A-497D-9DA4-78CF0B2976C0}" = rport=10243 | protocol=6 | dir=out | app=system |
"{2795DE0B-39B2-41ED-A638-6835BECE455A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2BB81095-FABC-442A-ADA7-5AF143F4EF50}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2F6EEE01-830C-4248-B16E-82044DC7AD09}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{49E61651-04FC-4923-9004-BF054C915E5F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4ABE6228-5963-4850-8032-201C92EC7732}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5BA125FB-6968-45BC-9F24-C4CB867FA4A2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5CBFCB85-DA6D-4160-BF6B-6728003A0AC8}" = lport=138 | protocol=17 | dir=in | app=system |
"{5CF928E8-97CD-47C8-9F83-7B47CCA40D32}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5FAE44B2-A1D3-4087-802F-C045B8225963}" = rport=137 | protocol=17 | dir=out | app=system |
"{65437A6F-CB31-46D3-B649-ACF19EBEB562}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{6C91B6A7-7B09-420B-B5D8-D48DD78A6C81}" = lport=137 | protocol=17 | dir=in | app=system |
"{6EBE0409-8387-489E-9B27-9E5A988CFAD9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{72A96D0B-F52A-4114-B13D-4E4BE0BC25F8}" = lport=139 | protocol=6 | dir=in | app=system |
"{76E0D8DB-3397-4CFA-B0E0-263189D65E4D}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{89E17AFB-C2D4-4830-ADC7-74CC40AB8937}" = lport=10243 | protocol=6 | dir=in | app=system |
"{8E297D5C-A045-4683-A84E-37754E223638}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8F00389F-89EC-40C3-879A-32A00B95F88F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{91A79A92-16F1-4E00-8AAC-10C69470F1B8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{92FC88A7-E450-43FD-803F-A234DEA480F3}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A1EA0A52-E9E0-4D57-A260-58F83A03B67A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{A91E5E6D-03F7-4365-95E3-9A880D5B148A}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{B1F1576D-2A31-4D41-9B58-CECFD045AA89}" = lport=445 | protocol=6 | dir=in | app=system |
"{C6ED7A40-8A49-4D33-ACAC-D1BD995F982A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C73F3CAC-1A30-48C8-8BAE-9817D0243FEE}" = rport=139 | protocol=6 | dir=out | app=system |
"{CF09CB6D-2496-431E-8325-3C5C2CF24FB4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DBE9B6F9-FE0D-428D-938F-EEF11F236DA9}" = rport=445 | protocol=6 | dir=out | app=system |
"{F632531F-5059-469C-83B9-C8C34894BA11}" = rport=138 | protocol=17 | dir=out | app=system |
"{F7C90492-7C71-4729-B797-25C84BF77237}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FD1B031E-8F9B-4A73-ABF6-067E7D44EEE1}" = lport=2869 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0228DF2E-3125-4901-9A97-1FA9C6339B1F}" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3y.exe |
"{033D9638-E8A8-455A-8B99-0F0D7ECA83F4}" = protocol=17 | dir=in | app=c:\program files\tunngle\tnglctrl.exe |
"{0ACE4C03-FF9D-4951-A735-01F0153FE5CD}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"{10D30A54-2176-4B10-B819-BE180E141D55}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold\stronghold.exe |
"{11D27E35-3B63-4745-A8EC-E0DBF9B2A96F}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold crusader\stronghold crusader.exe |
"{1595173F-571F-4AB9-911D-3BA6C78E3E05}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1DAB0BA9-4DD4-4493-B5E3-113696481602}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{20C23B80-BAF1-4099-9EB7-C522D0526BC2}" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3x.exe |
"{2671854B-D436-4408-8FD6-B4163AA3BB6E}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold crusader\stronghold_crusader_extreme.exe |
"{2D9DFD8B-1251-4037-879C-317573A21739}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold crusader\stronghold_crusader_extreme.exe |
"{3060CA12-C001-4D6F-98D7-25BBE772D49B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{37759478-52BA-4038-BA72-4FEE0DBAE6CB}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{377B7B13-5484-41C8-BB74-B56ECE894564}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{38AFE3F1-9634-4D44-950A-A90F99DC979F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3A210802-B322-43B2-9750-8AF81887C7B7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3A820565-93AF-4FFC-AC26-36DEF63A5F14}" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3y.exe |
"{3E850D61-FC4A-4474-9E1F-0CFC92D45180}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold crusader\stronghold_crusader_extreme.exe |
"{3ECF98AA-30F8-4E19-806F-8DE126C47F0A}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{40B2B240-1829-4CC5-B564-FF052FC639C4}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"{42B5B421-22E3-4014-A5AF-9A49484DDD8A}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\update service\update service.exe |
"{45D321C4-82DB-4001-92B6-741C6AA0D7B4}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{465164E2-2E85-404A-81DC-B1F5B093A972}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold legends\strongholdlegends.exe |
"{4F07BCB4-F488-4578-86C3-501080A5CF0C}" = protocol=6 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\autopatcher.exe |
"{521B0743-6F95-4AB5-A6D9-DA2730B78A51}" = protocol=17 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\anno5.exe |
"{5601BFE1-442A-43AA-AFC3-F33E95960978}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5DC79A07-5A4D-4AAB-923C-D333933C5CF2}" = protocol=17 | dir=in | app=c:\program files\ubisoft\die siedler 7\data\base\_dbg\bin\release\settlers7r.exe |
"{60CFAE1A-2062-4B17-AF49-BE7E5D825BB0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{61DF904C-AFEF-4D57-8195-3BACFF9BAF2A}" = protocol=6 | dir=in | app=c:\users\matis\appdata\roaming\dropbox\bin\dropbox.exe |
"{63AEC4E2-FD4D-486B-95D6-B02A87765A22}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{63F18A18-6F7E-43C5-A299-14B90BC367E2}" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"{684710D8-C66D-4C3A-BD48-D9A95825B3AB}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold crusader\stronghold crusader.exe |
"{6936B747-5440-4ACF-B26E-D8E8D18893E5}" = protocol=17 | dir=in | app=c:\program files\tunngle\tunngle.exe |
"{69B60DC5-1FBA-4EBE-9BBD-1DF2DF4474D4}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\update service\update service.exe |
"{6AF24658-23CD-41D9-8A56-CE106D327E33}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6D151039-7A4F-43F2-9C7C-A60D64711540}" = protocol=17 | dir=in | app=c:\program files\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |
"{6D42B22F-333D-4E60-AC11-BEFA102201E4}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{718A8D4E-B1D2-448E-8203-7EA0732EEB96}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7A016BF8-3CC4-4D06-87B6-930A991C951A}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold\stronghold.exe |
"{7A05D492-680C-4D0C-A4E3-221FA4090444}" = protocol=6 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{7DBC6269-1A55-439C-BD69-0378A035CEC0}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{7F41CF98-7971-4966-AD48-DB10E98DC7FF}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"{83D589ED-4300-494B-921D-BD612273277C}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold\stronghold.exe |
"{86AD3C08-8918-48AE-A05C-9F9B49CDAAAD}" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3x.exe |
"{8D8A5693-64D9-4C38-856E-F7BA1623FCF2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{909E5FF0-99CE-4E55-BDAE-3A7FBC650779}" = protocol=17 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\autopatcher.exe |
"{916A097B-8416-45CE-B56C-E74FDB0E3A43}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{92241DD5-FDDF-41BB-9547-8028F3A39190}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold crusader\stronghold_crusader_extreme.exe |
"{92B14325-30E2-4BB7-B0C0-68BCA456483F}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold crusader\stronghold crusader.exe |
"{94607E55-F933-4EA8-B3E2-8CB54ECF166F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{964D236A-1FED-486A-B8CC-18466ACD233E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{97A366CC-613E-4D9D-98DB-64A5C5E0CBAF}" = protocol=6 | dir=in | app=c:\program files\tunngle\tunngle.exe |
"{9945E9BE-F461-4C78-848C-6A64457BA961}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold\stronghold.exe |
"{9A601A37-5B46-4094-9E60-9246AD1C2756}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold legends\strongholdlegends.exe |
"{9BBC6298-CF52-4A35-B76D-8DD6E6016E7A}" = protocol=6 | dir=in | app=c:\program files\tunngle\tnglctrl.exe |
"{9BC7C4BC-FF68-4F9F-B8B3-5E28D8543B16}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9F6D8C8B-5B64-4EBC-81C9-9035564BAA73}" = protocol=17 | dir=in | app=c:\program files\microsoft games\rise of nations\thrones.exe |
"{A2382ABD-FCE5-476F-BE7D-AFFB3C093E92}" = protocol=17 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\initengine.exe |
"{A464DA39-C123-45E8-B1BE-CFA62842A993}" = protocol=6 | dir=in | app=c:\program files\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |
"{A4722766-8D5E-4479-B9D4-D4F5B768D72F}" = protocol=6 | dir=in | app=c:\program files\microsoft games\rise of nations\thrones.exe |
"{AB4E843F-35A6-4AEC-A9E7-69ACA4909CF4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{AB701FB0-FAEB-495F-9CAB-39319D3D49ED}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold crusader\stronghold crusader.exe |
"{ABAF4744-2319-4E33-96D6-5C10DBD54C64}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{ACBA6DAE-8F7A-4108-A2D1-DF7DB695AC0B}" = protocol=6 | dir=out | app=system |
"{AEDA2CF6-5380-446F-BC1D-143AE6C8B6D0}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold legends\strongholdlegends.exe |
"{B6D1DFD5-98D6-4224-A8B9-0EEE68A7C7C2}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{BCD9A2D5-F81F-459B-9C7B-31B72311C75A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BDFE22D6-4986-45B9-AAEF-DFB0E9EB5D13}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C4E06204-E0EF-4978-B667-5642D72D528C}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"{CB614D52-7070-479D-B4A3-FDBED86A03B7}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold legends\strongholdlegends.exe |
"{D6292CCB-F35B-4837-B0A1-F7EA0EF14189}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{DC83B970-652E-434C-B677-31F156FCF3D8}" = protocol=17 | dir=in | app=c:\users\matis\appdata\roaming\dropbox\bin\dropbox.exe |
"{E15F62EF-6E64-414B-84DD-64336103AC0C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E3ADCEB5-1FAB-4216-8796-E64B6BCAE4DC}" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"{E425E9EA-4FF3-4513-AA06-078C3A017573}" = protocol=6 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\anno5.exe |
"{E8226508-71C7-4720-8883-33BEBF06C53B}" = protocol=6 | dir=in | app=c:\program files\ubisoft\die siedler 7\data\base\_dbg\bin\release\settlers7r.exe |
"{EB61B8FC-1078-493B-A21F-998970CA1037}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{ED6B6A2B-D018-48BB-99D9-F63CA6A5B9B9}" = protocol=17 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{F042DB76-C5C0-4F95-9907-FD15D54C9F5B}" = protocol=6 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\initengine.exe |
"{FEAE8AC1-652C-4A68-9F41-B321DEDBB109}" = protocol=17 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"TCP Query User{747A19BD-85A4-42FE-86DE-9EED6134C444}C:\program files\intuwave\shared\mrouterruntime\mrouterruntime.exe" = protocol=6 | dir=in | app=c:\program files\intuwave\shared\mrouterruntime\mrouterruntime.exe |
"TCP Query User{90937136-D2C3-4DA3-BAA5-0D8A3972027F}C:\program files\microsoft games\age of empires iii\age3x.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3x.exe |
"TCP Query User{C4EAC5D0-E422-475F-9306-EC6FF94877A7}C:\program files\intuwave\shared\mrouterruntime\mrouterruntime.exe" = protocol=6 | dir=in | app=c:\program files\intuwave\shared\mrouterruntime\mrouterruntime.exe |
"TCP Query User{DD6216EF-0CD7-4C92-B775-C30AF7E34494}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{293BADC5-B526-4A52-A1D1-07419CF8835C}C:\program files\microsoft games\age of empires iii\age3x.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3x.exe |
"UDP Query User{56563E90-453D-4AD7-9057-1E08C20701CB}C:\program files\intuwave\shared\mrouterruntime\mrouterruntime.exe" = protocol=17 | dir=in | app=c:\program files\intuwave\shared\mrouterruntime\mrouterruntime.exe |
"UDP Query User{6D40CDC7-7F3C-44DB-AF60-50596F220016}C:\program files\intuwave\shared\mrouterruntime\mrouterruntime.exe" = protocol=17 | dir=in | app=c:\program files\intuwave\shared\mrouterruntime\mrouterruntime.exe |
"UDP Query User{979B84AC-B5B6-4423-BCE4-B2D8B54AE320}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{0B265E3D-17BD-3B47-D87A-FAC2B8E18124}" = ATI Problem Report Wizard
"{106B4413-ACBB-4CDE-8707-587DB9BD77EC}" = LogMeIn Hamachi
"{16D2C649-CBA8-44EE-B730-12584667D487}" = Stronghold 2
"{1C08A24C-B168-407E-A826-68FAF5F20710}" = Age of Empires III - The WarChiefs
"{1FF713E1-FE5E-4AD0-9C8C-B2E877846B45}" = Catalyst Control Center - Branding
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{209A11D6-9291-4C39-9632-F246DA4CA7A2}" = ZohoMeeting
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java(TM) 6 Update 30
"{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}" = Edimax Wireless LAN Card
"{2E060268-4175-201F-EABD-B91FC552DCA4}" = CCC Help Japanese
"{306D0BDC-4E4D-D95A-F067-5C2FD0A41055}" = Catalyst Control Center Graphics Full New
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{32652FCF-AC67-688C-0FB8-3AD5839ACFB7}" = CCC Help Russian
"{34341E0F-C3F4-4EA2-9E6B-55DDA2A67568}" = School Tycoon
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C67F5DC-F3BA-241E-D4EB-58D935822B74}" = CCC Help Hungarian
"{413B1AC7-E076-B765-C6BF-8780AE6124CB}" = ATI AVIVO Codecs
"{447A24EA-46BD-4F5B-AA2A-6A1B941BD2C3}" = Catalyst Control Center InstallProxy
"{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = Die Sims™ 3 Late Night
"{459699C3-9430-4381-964B-4248D87B49F9}" = Apple Mobile Device Support
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA68A73-DB9C-439D-9481-981C82BD008B}" = Nokia Connectivity Cable Driver
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{569FA061-07B7-3992-358E-3A58582B2E6D}" = ccc-core-static
"{5BBB8682-1335-410F-A79F-8E5611A54BD0}_is1" = Game Dev Tycoon Version 1.3.4
"{5DDB3393-E08B-447E-925F-6C00B95D0FE7}" = iCloud
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{66A405D2-BA14-4594-BF36-B3B544F0754E}" = Stronghold Legends
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = Die Sims 2
"{6FE7D13B-88D4-4870-B5D7-54D9E7D04661}" = CCC Help Portuguese
"{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = Die Sims™ 3 Luxus-Accessoires
"{735619D4-B42A-437A-958C-199BFCAEDB38}" = Safari
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7FC3076B-750E-24BE-F7FF-26266F9256CF}" = CCC Help Italian
"{86206386-FAF7-A27A-66E9-7840DEA68848}" = CCC Help Danish
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8B217953-6EF2-E6F2-4742-C6CA98A9C294}" = CCC Help Dutch
"{8C3727F2-8E37-49E4-820C-03B1677F53B6}" = Stronghold Crusader Extreme
"{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = Die Sims™ 3 Traumkarrieren
"{917C79E9-9E4E-11D6-B27C-0003FFFFFFFC}" = Fritz und Fertig
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95A4C317-5EF8-7E59-BC82-5DFCB18EE17A}" = CCC Help English
"{9783B07B-362F-9552-84AD-058DB078086F}" = CCC Help Greek
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C916142-C18C-429D-BFED-40094A7E0BEB}" = Die Siedler 7
"{A2AA4204-C05A-4013-888A-AD153139297F}" = PC Connectivity Solution
"{A2CABB42-0936-44CD-B3E0-8A62B5303E70}" = CCC Help German
"{A39E4995-2D56-ABE5-D90B-2B3A685F7CE2}" = CCC Help Czech
"{A513E1BC-2F10-9661-3105-2674F11841AA}" = ccc-utility
"{A71F05F5-547F-DD24-2E03-E757F8DF833A}" = CCC Help Chinese Standard
"{A72D8248-4E4D-63CF-BF39-E041AF380012}" = Catalyst Control Center Graphics Full Existing
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ABB785A8-BCBB-D1C0-03B5-3F4E32083E07}" = CCC Help Korean
"{AEAE3EDB-AF9F-0BE8-F7E1-C5D6D6D74DB9}" = CCC Help Spanish
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B0261E53-B6F1-474A-864B-E7C3CBF468E0}" = iTunes
"{B4089055-D468-45A4-A6BA-5A138DD715FC}" = Bing Bar
"{B48E264C-C8CD-4617-B0BE-46E977BAD694}" = ANNO 2070
"{B6CF045D-51E5-6E4B-7C62-FD402ACB38FB}" = Catalyst Control Center Graphics Previews Common
"{B8367F2A-34C0-BC18-922A-96B4FDA40FA0}" = CCC Help Thai
"{B86C045F-2922-ECBD-4066-173B77820992}" = CCC Help Polish
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = Die Sims™ 3 Reiseabenteuer
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C01408FC-117C-44B7-8B0C-17794E526A01}" = Disc2Phone
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die Sims™ 3
"{C12631C6-804D-4B32-B0DD-8A496462F106}" = Die Sims™ 3 Einfach tierisch
"{C43C1415-3DFC-4089-9A32-0BECF28A6046}" = Age of Empires III - The Asian Dynasties
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}" = Stronghold
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{CC843AAD-000E-9AC0-ED35-95BFFC4B7019}" = ATI Catalyst Install Manager
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{CEBA2DEC-E9CD-D82A-7280-988D8430C39D}" = CCC Help Norwegian
"{CF06C093-A1D1-5CAB-DF87-B890377970D0}" = Catalyst Control Center Localization All
"{D1C46FAA-3378-A0B1-18D2-F52618E5517E}" = CCC Help Finnish
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{D3405B2E-79A5-3EAF-3E8C-20E8CD64F2D1}" = Catalyst Control Center Core Implementation
"{D3EF1442-F45D-AF2E-EE90-F168F83BD5D7}" = CCC Help French
"{D6E5C6D5-E96F-C90E-0BF5-94F6E4ED3B6A}" = Catalyst Control Center Graphics Previews Vista
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}" = Die Sims™ 3 Gib Gas-Accessoires
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{ED94BE03-E6CC-4268-B03A-92080E3035A6}_is1" = MCSkin3D Version 1.3
"{EEC010D0-1252-4E1D-BAD9-F1B8F414535C}" = PL-2303 Vista Driver Installer
"{EF36A836-BF89-4A4F-B079-057B0C68C1E0}" = Sid Meier's Civilization IV Colonization
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F241631E-ACF3-DE56-901C-0BC16D2423CE}" = CCC Help Turkish
"{F25BE225-4A79-941A-A257-1BB37968F773}" = Catalyst Control Center HydraVision Full
"{F31912BE-8FD6-4C46-A3CF-84C8655E7130}" = Fritz und Fertig 3
"{F8A2DD2D-581D-372A-71CD-1339CFE86EC8}" = Catalyst Control Center Graphics Light
"{FB6DE932-24CA-D1C0-2FD8-1DFCE4A33CC5}" = HydraVision
"{FED3F92F-4D03-82BE-E3D2-D9BD7E942000}" = CCC Help Swedish
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFF22903-7FDC-0E9C-7667-1B673026112A}" = CCC Help Chinese Traditional
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Mythology 1.0" = Age of Mythology
"Avira AntiVir Desktop" = Avira Antivirus Premium
"ExpressBurn" = Express Burn
"ExpressRip" = Express Rip
"Football Manager 2012_is1" = Football Manager 2012
"GameSpy Arcade" = GameSpy Arcade
"GeoGebra 4.2" = GeoGebra 4.2
"Google Chrome" = Google Chrome
"InstallShield_{1C08A24C-B168-407E-A826-68FAF5F20710}" = Age of Empires III - The WarChiefs
"InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"InstallShield_{C43C1415-3DFC-4089-9A32-0BECF28A6046}" = Age of Empires III - The Asian Dynasties
"Kanzler Forever_is1" = Kanzler Forever - v. 1.02.6
"LEGO Stunt Rally" = LEGO Stunt Rally
"LogMeIn Hamachi" = LogMeIn Hamachi
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 12.0 (x86 de)" = Mozilla Firefox 12.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Network Stumbler" = Network Stumbler 0.4.0 (remove only)
"NosTale(DE)_is1" = Nostale(DE)
"Origin" = Origin
"RealVNC_is1" = VNC Free Edition 4.1.3
"RiseOfNations 1.0" = Microsoft Rise Of Nations
"RiseofNationsExpansion 1.0" = Rise of Nations
"Tunngle beta_is1" = Tunngle beta
"Ultimate Unlocker_UltimateUnlocker" = UltimateUnlocker
"Update Service" = Update Service
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.11 (32-Bit)
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1607755728-43842115-2870295034-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Avira SearchFree Toolbar plus Web Protection Updater
"GameRanger" = GameRanger
"TeamSpeak 3 Client" = TeamSpeak 3 Client
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 24.11.2012 14:09:35 | Computer Name = tobi7 | Source = Avira AntiVir | ID = 4117
Description =
Error - 24.11.2012 14:13:32 | Computer Name = tobi7 | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung
werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter
ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste
DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich
und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error - 24.11.2012 15:29:52 | Computer Name = tobi7 | Source = Bonjour Service | ID = 100
Description = mDNSCoreMachineSleep: mDNS_Lock: Locking failure! mDNS_busy (1) !=
mDNS_reentrancy (0)
Error - 24.11.2012 15:29:52 | Computer Name = tobi7 | Source = Bonjour Service | ID = 100
Description = mDNSCoreMachineSleep: mDNS_Unlock: Locking failure! mDNS_busy (1)
!= mDNS_reentrancy (0)
Error - 25.11.2012 13:51:41 | Computer Name = tobi7 | Source = Avira AntiVir | ID = 4117
Description =
Error - 25.11.2012 13:55:52 | Computer Name = tobi7 | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung
werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter
ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste
DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich
und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error - 25.11.2012 14:00:06 | Computer Name = tobi7 | Source = Windows Backup | ID = 4103
Description =
Error - 27.11.2012 13:29:45 | Computer Name = tobi7 | Source = Avira AntiVir | ID = 4117
Description =
Error - 27.11.2012 13:35:49 | Computer Name = tobi7 | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung
werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter
ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste
DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich
und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error - 28.11.2012 10:57:26 | Computer Name = tobi7 | Source = Avira AntiVir | ID = 4117
Description =
Error - 28.11.2012 11:01:26 | Computer Name = tobi7 | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung
werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter
ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste
DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich
und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error - 29.11.2012 10:23:58 | Computer Name = tobi7 | Source = Avira AntiVir | ID = 4117
Description =
[ System Events ]
Error - 17.05.2013 14:49:33 | Computer Name = tobi7 | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Computer Browser" ist vom Dienst "Server" abhängig, der
aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 17.05.2013 14:49:33 | Computer Name = tobi7 | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Computer Browser" ist vom Dienst "Server" abhängig, der
aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 17.05.2013 14:49:33 | Computer Name = tobi7 | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Computer Browser" ist vom Dienst "Server" abhängig, der
aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 17.05.2013 14:49:33 | Computer Name = tobi7 | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Computer Browser" ist vom Dienst "Server" abhängig, der
aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 17.05.2013 14:49:33 | Computer Name = tobi7 | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Computer Browser" ist vom Dienst "Server" abhängig, der
aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 17.05.2013 14:49:33 | Computer Name = tobi7 | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Computer Browser" ist vom Dienst "Server" abhängig, der
aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 17.05.2013 14:49:33 | Computer Name = tobi7 | Source = Service Control Manager | ID = 7001
Description = Der Dienst "HomeGroup Provider" ist vom Dienst "Function Discovery
Provider Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error - 17.05.2013 14:49:35 | Computer Name = tobi7 | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Computer Browser" ist vom Dienst "Server" abhängig, der
aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 17.05.2013 14:49:35 | Computer Name = tobi7 | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Computer Browser" ist vom Dienst "Server" abhängig, der
aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 17.05.2013 14:49:35 | Computer Name = tobi7 | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Computer Browser" ist vom Dienst "Server" abhängig, der
aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
< End of report > --- --- --- |