Telophase | 18.05.2013 08:46 | Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Papab„r on 18.05.2013 at 9:19:54,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-2637854371-3477063950-4265566210-1003\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\pricegong
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\Toolbar.CT2269050
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\Toolbar.CT3197087
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{A057A204-BACC-4D26-9990-79A187E2698F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{A057A204-BACC-4D26-9990-79A187E26990}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
~~~ Files
Successfully deleted: [File] "C:\end"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Papab„r\AppData\Roaming\dvdvideosoftiehelpers"
Successfully deleted: [Folder] "C:\Users\Papab„r\AppData\Roaming\pdfforge"
Successfully deleted: [Folder] "C:\Users\Papab„r\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\Papab„r\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Papab„r\appdata\locallow\dvdvideosofttb"
Successfully deleted: [Folder] "C:\Users\Papab„r\appdata\locallow\pricegong"
Successfully deleted: [Folder] "C:\Program Files\conduit"
Successfully deleted: [Folder] "C:\Program Files\dvdvideosofttb"
~~~ FireFox
Successfully deleted: [File] C:\Users\Papab„r\AppData\Roaming\mozilla\firefox\profiles\crukbw8m.default-1353242511831\user.js
Emptied folder: C:\Users\Papab„r\AppData\Roaming\mozilla\firefox\profiles\crukbw8m.default-1353242511831\minidumps [172 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.05.2013 at 9:21:20,33
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ AdwCleaner Logfile: Code:
# AdwCleaner v2.301 - Datei am 18/05/2013 um 09:23:26 erstellt
# Aktualisiert am 16/05/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : Papabär - CERNNUNOS
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Papabär\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Ordner Gelöscht : C:\Program Files\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Program Files\iNTERNET_TURBO
Ordner Gelöscht : C:\ProgramData\AVG Security Toolbar
Ordner Gelöscht : C:\Users\Papabär\AppData\Local\AVG Security Toolbar
Ordner Gelöscht : C:\Users\Papabär\AppData\LocalLow\AVG Security Toolbar
Ordner Gelöscht : C:\Users\Papabär\AppData\LocalLow\iNTERNET_TURBO
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AVG Security Toolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\iNTERNET_TURBO
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\iNTERNET_TURBO Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winamp Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{09152F0B-739C-4DEC-A245-1AA8A37594F1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{471B163C-D832-47CF-87B9-70EC803DA402}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5DDFCBFC-6402-48B6-9EB5-E1061214D279}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{09152F0B-739C-4DEC-A245-1AA8A37594F1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F9073CE-EDC9-467D-92D7-8E2D776E53D5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKLM\Software\AVG Secure Search
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{09152F0B-739C-4DEC-A245-1AA8A37594F1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{471B163C-D832-47CF-87B9-70EC803DA402}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5DDFCBFC-6402-48B6-9EB5-E1061214D279}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7F9073CE-EDC9-467D-92D7-8E2D776E53D5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\Software\DVDVideoSoftTB
Schlüssel Gelöscht : HKLM\Software\iNTERNET_TURBO
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1BE542A6-161E-49E6-9CA1-339925439F99}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99CD118E-7918-4DA5-BB03-52F7427DF209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2176C0A-0B14-4CCE-97B1-A13AAFA83705}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DECF8567-739C-4DFD-9121-5FBA40D30B08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{09152F0B-739C-4DEC-A245-1AA8A37594F1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F9073CE-EDC9-467D-92D7-8E2D776E53D5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iNTERNET_TURBO Toolbar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{09152F0B-739C-4DEC-A245-1AA8A37594F1}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{09152F0B-739C-4DEC-A245-1AA8A37594F1}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{09152F0B-739C-4DEC-A245-1AA8A37594F1}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{09152F0B-739C-4DEC-A245-1AA8A37594F1}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
***** [Internet Browser] *****
-\\ Internet Explorer v9.0.8112.16483
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v21.0 (de)
Datei : C:\Users\Papabär\AppData\Roaming\Mozilla\Firefox\Profiles\crukbw8m.default-1353242511831\prefs.js
[OK] Die Datei ist sauber.
*************************
AdwCleaner[S1].txt - [6626 octets] - [18/05/2013 09:23:26]
########## EOF - C:\AdwCleaner[S1].txt - [6686 octets] ########## --- --- ---
OTL Logfile: Code:
OTL logfile created on: 18.05.2013 09:29:47 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Papabär\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,99 Gb Total Physical Memory | 1,75 Gb Available Physical Memory | 58,57% Memory free
6,18 Gb Paging File | 4,92 Gb Available in Paging File | 79,66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 100,09 Gb Total Space | 34,70 Gb Free Space | 34,67% Space Free | Partition Type: NTFS
Drive D: | 188,00 Gb Total Space | 86,00 Gb Free Space | 45,74% Space Free | Partition Type: NTFS
Computer Name: CERNNUNOS | User Name: Papabär | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Papabär\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trojan Remover\Trjscan.exe (Simply Super Software)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Users\Papabär\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - D:\Kies\Kies.exe (Samsung)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
PRC - C:\Program Files\ASCOMP Software\Synchredible\synchredible.exe (ASCOMP Software GmbH)
PRC - C:\Program Files\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Nokia)
PRC - C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfimon.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics)
PRC - C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (SAMSUNG Electronics co., LTD.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Windows\System32\lpksetup.exe (Microsoft Corporation)
PRC - C:\Windows\System32\StkCSrv.exe (Syntek America Inc.)
PRC - C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePodcast\8d615f862df4bbbce1e8db9d54e3f394\DevicePodcast.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceVideo\eddd2c10f7f26c7d9bc829d58a242107\DeviceVideo.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePhoto\ab17b49c15978762fa850b26cbf40381\DevicePhoto.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceMusic\d99262faddfef2aa5a9ebc3e3c8ec32a\DeviceMusic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\VideoManager\42181272db5142f8c30b840f9e332f74\VideoManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PhotoManager\e0814673978d88e7ef315affeea8306a\PhotoManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Phonebook\06fb33fe1cebe31db02a7eac1a0eff14\Phonebook.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\MusicManager\701a98ada48b780b469a5dd2e6cc9c0b\MusicManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\BATPlugin\c3454a3e90594f92a4f72e1f3ef5b79b\BATPlugin.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.MediaDB\3a2e264f8b8bf90827c54222d425a119\Kies.Common.MediaDB.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.AllShare\271b23fa48ab76fec3869dfd4ea08bf4\Kies.Common.AllShare.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.MainUI\24406f57b2cb550f87abd0550114e270\Kies.Common.MainUI.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DBManag#\9f9c16840f99762681d5d22b513d9d16\Kies.Common.DBManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\99c314ad36cb327c59650b7dd4fcc8b8\Kies.Common.DeviceServiceLib.FirmwareUpdate.Common.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\ebb02b742bfeaea2f90a1aa3d99c37bb\Kies.Common.DeviceServiceLib.FileService.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\79b19561e6e7dbe53b4de73806587710\Kies.Common.DeviceService.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Podcaster\08a6ddb876259567103239c9dfa86afc\Podcaster.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Plugin.Content#\8510c4ca824b6e0cd49db25b8fc25588\Kies.Plugin.ContentsManagerLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\c16c6f9947a9e8252dea5c6029aa6150\Kies.Common.DeviceServiceLib.DeviceManagement.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.Multime#\b8c103c865702d1a9668bd8c354608ce\Kies.Common.Multimedia.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\718b3bb48bb3216ad901c16c4c548239\Kies.Common.DeviceServiceLib.DeviceDataService.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceHost\3dc0083c87f0f44adde05b180aea3209\DeviceHost.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.Util\c3080b42764ab8ddebed6db271335002\Kies.Common.Util.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\23211ec645a6c9ef85d69795920f3e8f\Kies.UI.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\GongSolutions.Wpf.D#\f67e1afe33aa6c76e375dbd4fa132363\GongSolutions.Wpf.DragDrop.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Interface\ba1f218cdc4b19c824a8e8159fb4ed92\Kies.Interface.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies\3de72d3e20498c62099e85da7fd44b3c\Kies.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\1f0bb5336d1706c9b8ad2330f3642760\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\9b2940478ec555990b37af5448b8f509\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\a1949f57d2ec260e09768e98fecb0559\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ddc3e8c2774eaec614d6775983652980\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\93a17ba6cb6753328f25466bc0bf1cb1\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\0f4155c806e86a023b835d9070774f89\Kies.Theme.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\DummyStorePlugin\1b6f3c9a32cd1976fb79b2445e586939\DummyStorePlugin.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.StoreMa#\3c6667cbc29155082e58137643a1dff1\Kies.Common.StoreManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\52207264bac5068c2de665b3f41e8964\ASF_cSharpAPI.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.CRMMana#\657f2c28fc2068324d9b0f1d9d596361\Kies.Common.CRMManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Interop.FUSCryptLib\7296ee8d41eeb2bcc543df81eea19ebe\Interop.FUSCryptLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\9a1d52e92dab2e5f906e4edae93b8b8c\Kies.Common.DeviceServiceLib.FirmwareUpdate.Downloader.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Interop.DevFileServ#\fa06b799153f9c28c1866319b3db5580\Interop.DevFileServiceLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\d77da7b6668e27f63af7da941e221304\Kies.Common.DeviceServiceLib.FirmwareUpdate.FirmwareUpdateAgentHelper.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\ICSharpCode.SharpZi#\0969ff5a4924da7d8c6ebd3fca8f154b\ICSharpCode.SharpZipLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Interop.MP3FileInfo#\5f0b67eb5313c092d5b8b56426dd30e2\Interop.MP3FileInfoCOMLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Interop.OGGFileInfo#\b2c7788a3e89dfe8758d6184bac1b663\Interop.OGGFileInfoCOMLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Interop.P3MPINTERFA#\111be4cc197cabb6340170eeb54ae535\Interop.P3MPINTERFACECTRLLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Interop.PRPLAYERCOR#\29e8db641e3708219f13d2a3b7528278\Interop.PRPLAYERCORELib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Interop.DeviceServi#\ed97f510e91aff4e4f00987ec1fb8b70\Interop.DeviceServiceModelDBLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\0ec1f5148809454e7dd63148636a05b2\Kies.Common.DeviceServiceLib.Interface.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\CabLib\af22e5bb6307e2882abe5fbdb3c00c8e\CabLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Locale\5cf4d41e6de5af4c27e7b66b172f73df\Kies.Locale.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Interop.DeviceSearc#\4f4243b3bc2e4cdf0ec6e7ad5559aa20\Interop.DeviceSearchLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\48c087dd6e18fcbd057e0b1dd6cfa2fd\Kies.MVVM.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\dbe82a95ee3feebc5999138fdf36d3c9\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\7d8f6866864f78cf83d3701641c46178\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\40c7a89fe2cbf3c12a2c39e034da54cf\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\fc476bbac36944e352c2f547352ffa64\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\f93dca0e4baa1dcb37cf75392b7c89da\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\6a1ccc1e1a79ce267d3d1808af382cd6\mscorlib.ni.dll ()
MOD - C:\Program Files\program\libxml2.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\phonon4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\QtXmlPatterns4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\QtXml4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\QtWebKit4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\QtSql4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\QtScript4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\QtOpenGL4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\QtGui4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\QtNetwork4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\QtMultimediaKit1.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\QtDeclarative4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\QtCore4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\Imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\Imageformats\qico4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\Imageformats\qgif4.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\NService.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\CommonUpdateChecker.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\ssoengine.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\securestorage.dll ()
MOD - C:\Program Files\Nokia\Nokia Suite\mediaservice\dsengine.dll ()
MOD - C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe ()
MOD - C:\Program Files\Samsung\Samsung Update Plus\HMXML.dll ()
MOD - C:\Program Files\Brother\BrUtilities\BrLogAPI.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Samsung\Samsung Magic Doctor\HookDllPS2.dll ()
MOD - C:\Program Files\Samsung\EasySpeedUpManager\HookDllPS2.dll ()
MOD - C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ()
MOD - C:\Program Files\WinRAR\rarext.dll ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (AVG Security Toolbar Service) -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (IAANTMON) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (StkSSrv) -- C:\Windows\System32\StkCSrv.exe (Syntek America Inc.)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
DRV - (ADDMEM) -- C:\Users\PAPABR~1\AppData\Local\Temp\__Samsung_Update\ADDMEM.SYS File not found
DRV - (AVGIDSDriver) -- C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) -- C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) -- C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) -- C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) -- C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) -- C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) -- C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) -- C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ssudmdm) -- C:\Windows\System32\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (dg_ssudbus) -- C:\Windows\System32\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (nmwcdnsu) -- C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdnsuc) -- C:\Windows\System32\drivers\nmwcdnsuc.sys (Nokia)
DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (NETw5v32) -- C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (KMWDFILTER) -- C:\Windows\System32\drivers\KMWDFILTER.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (KMDFMEMIO) -- C:\Windows\System32\drivers\KMDFMEMIO.sys (SAMSUNG ELECTRONICS CO., LTD.)
DRV - (iaNvStor) -- C:\Windows\System32\drivers\iaNvStor.sys (Intel Corporation)
DRV - (StkCMini) -- C:\Windows\System32\drivers\StkCMini.sys (Syntek)
DRV - (WSDPrintDevice) -- C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (NETw3v32) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (HPFXFAX) -- C:\Windows\System32\drivers\hpfxfax.sys (Hewlett Packard)
DRV - (HPFXBULK) -- C:\Windows\System32\drivers\hpfxbulk.sys (Hewlett Packard)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (bcm4sbxp) -- C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (se27unic) -- C:\Windows\System32\drivers\se27unic.sys (MCCI)
DRV - (SE27obex) -- C:\Windows\System32\drivers\SE27obex.sys (MCCI)
DRV - (SE27mgmt) -- C:\Windows\System32\drivers\SE27mgmt.sys (MCCI)
DRV - (SE27mdm) -- C:\Windows\System32\drivers\SE27mdm.sys (MCCI)
DRV - (SE27mdfl) -- C:\Windows\System32\drivers\SE27mdfl.sys (MCCI)
DRV - (SE27bus) -- C:\Windows\System32\drivers\SE27bus.sys (MCCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\Papabär\Desktop\Caelan\Autor_innen\Kerstin Ulrich\Kerstin Ulrich - Texte 01.13
IE - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "https://www.facebook.com/urs.barenkrafte?ref=tn_tnmn"
FF - prefs.js..extensions.enabledAddons: trackmenot%40mrl.nyu.edu:0.6.728
FF - prefs.js..extensions.enabledAddons: adblockpopups%40jessehakanen.net:0.7
FF - prefs.js..extensions.enabledAddons: %7B3d7eb24f-2740-49df-8937-200b1cc08f8a%7D:1.5.17
FF - prefs.js..extensions.enabledAddons: firefox%40ghostery.com:2.9.4
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130515
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.05.17 09:22:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.05.17 09:22:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.05.16 16:13:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.05.17 09:22:47 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.05.17 09:22:35 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.05.16 16:13:57 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2008.09.02 20:05:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Papabär\AppData\Roaming\mozilla\Extensions
[2013.05.16 10:52:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Papabär\AppData\Roaming\mozilla\Firefox\Profiles\crukbw8m.default-1353242511831\extensions
[2013.04.16 20:05:36 | 000,000,000 | ---D | M] (Flashblock) -- C:\Users\Papabär\AppData\Roaming\mozilla\Firefox\Profiles\crukbw8m.default-1353242511831\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2013.05.16 10:52:32 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Papabär\AppData\Roaming\mozilla\Firefox\Profiles\crukbw8m.default-1353242511831\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013.04.18 09:32:08 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\Papabär\AppData\Roaming\mozilla\Firefox\Profiles\crukbw8m.default-1353242511831\extensions\firefox@ghostery.com
[2013.03.03 17:45:23 | 000,134,804 | ---- | M] () (No name found) -- C:\Users\Papabär\AppData\Roaming\mozilla\firefox\profiles\crukbw8m.default-1353242511831\extensions\adblockpopups@jessehakanen.net.xpi
[2012.11.19 17:18:03 | 000,067,428 | ---- | M] () (No name found) -- C:\Users\Papabär\AppData\Roaming\mozilla\firefox\profiles\crukbw8m.default-1353242511831\extensions\trackmenot@mrl.nyu.edu.xpi
[2013.05.07 07:34:59 | 000,534,214 | ---- | M] () (No name found) -- C:\Users\Papabär\AppData\Roaming\mozilla\firefox\profiles\crukbw8m.default-1353242511831\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012.12.12 00:03:04 | 000,036,098 | ---- | M] () (No name found) -- C:\Users\Papabär\AppData\Roaming\mozilla\firefox\profiles\crukbw8m.default-1353242511831\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
[2013.05.17 09:22:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013.05.17 09:22:34 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013.05.17 09:22:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013.05.17 09:22:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2013.05.17 09:22:47 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) -- C:\USERS\PAPABäR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CRUKBW8M.DEFAULT-1353242511831\EXTENSIONS\{3D7EB24F-2740-49DF-8937-200B1CC08F8A}
File not found (No name found) -- C:\USERS\PAPABäR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CRUKBW8M.DEFAULT-1353242511831\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}
File not found (No name found) -- C:\USERS\PAPABäR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CRUKBW8M.DEFAULT-1353242511831\EXTENSIONS\ADBLOCKPOPUPS@JESSEHAKANEN.NET.XPI
File not found (No name found) -- C:\USERS\PAPABäR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CRUKBW8M.DEFAULT-1353242511831\EXTENSIONS\FIREFOX@GHOSTERY.COM
File not found (No name found) -- C:\USERS\PAPABäR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CRUKBW8M.DEFAULT-1353242511831\EXTENSIONS\TRACKMENOT@MRL.NYU.EDU.XPI
O1 HOSTS File: ([2013.05.17 10:04:56 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [KiesTrayAgent] D:\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe (Simply Super Software)
O4 - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003..\Run: [KiesPreload] D:\Kies\Kies.exe (Samsung)
O4 - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Papabär\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O4 - Startup: C:\Users\Papabär\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Papabär\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Papabär\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-2637854371-3477063950-4265566210-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube Download - C:\Users\Papabär\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Papabär\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 10.17.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60690B0E-8291-4CA5-8523-5143757F1E40}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8ABBBC40-5F9B-4C7C-9BFA-57B09F350444}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Papabär\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Papabär\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.05.18 09:19:51 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013.05.18 09:19:43 | 000,000,000 | ---D | C] -- C:\JRT
[2013.05.18 09:15:42 | 000,545,954 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Papabär\Desktop\JRT.exe
[2013.05.17 23:36:56 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Papabär\Desktop\tdsskiller.exe
[2013.05.17 22:36:28 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\Papabär\Desktop\aswMBR.exe
[2013.05.17 21:42:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.05.17 20:38:29 | 000,000,000 | ---D | C] -- C:\Users\Papabär\Desktop\mbar
[2013.05.17 10:13:36 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.05.17 09:50:54 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.05.17 09:50:54 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.05.17 09:50:54 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.05.17 09:50:48 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.05.17 09:50:29 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.05.17 09:48:40 | 005,066,411 | R--- | C] (Swearware) -- C:\Users\Papabär\Desktop\ComboFix.exe
[2013.05.17 09:22:33 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.05.16 16:13:57 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2013.05.16 09:00:45 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Papabär\Desktop\OTL.exe
[2013.05.16 03:14:16 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.05.16 03:01:02 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.05.16 03:01:02 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.05.16 03:01:02 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.05.16 03:01:02 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.05.16 03:01:01 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.05.16 03:01:01 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.05.16 03:01:00 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.05.15 14:42:49 | 000,000,000 | ---D | C] -- C:\Users\Papabär\Documents\Simply Super Software
[2013.05.15 14:42:49 | 000,000,000 | ---D | C] -- C:\Users\Papabär\AppData\Roaming\Simply Super Software
[2013.05.15 14:42:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
[2013.05.15 14:42:41 | 000,605,968 | ---- | C] (Igor Pavlov) -- C:\Windows\System32\ztv7z.dll
[2013.05.15 14:42:41 | 000,077,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ztvcabinet.dll
[2013.05.15 14:42:39 | 000,000,000 | ---D | C] -- C:\Program Files\Trojan Remover
[2013.05.15 14:42:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2013.05.15 09:45:11 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2013.05.15 09:45:05 | 002,049,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013.05.14 22:38:16 | 000,000,000 | ---D | C] -- C:\Users\Papabär\AppData\Roaming\Xaacac
[2013.05.14 22:38:16 | 000,000,000 | ---D | C] -- C:\Users\Papabär\AppData\Roaming\Ocosz
[2013.05.14 22:38:16 | 000,000,000 | ---D | C] -- C:\Users\Papabär\AppData\Roaming\Mabua
[2013.05.10 22:04:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Playrix Entertainment
[2013.05.10 21:57:28 | 000,000,000 | ---D | C] -- C:\Users\Papabär\AppData\Roaming\Der Schatten der Dämmerung
[2013.05.10 21:54:07 | 000,000,000 | ---D | C] -- C:\Users\Papabär\AppData\Roaming\Das Geheimnis der ägyptischen Mumie
[2013.05.10 21:46:53 | 000,000,000 | ---D | C] -- C:\Program Files\Mystery 2
[2013.05.10 09:42:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2002.03.11 11:06:30 | 001,822,520 | ---- | C] (Microsoft Corporation) -- C:\Program Files\instmsiw.exe
[2002.03.11 10:45:04 | 001,708,856 | ---- | C] (Microsoft Corporation) -- C:\Program Files\instmsia.exe
[1 C:\Users\Papabär\*.tmp files -> C:\Users\Papabär\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.05.18 09:27:46 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.05.18 09:25:37 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\SupBackGroundTask.job
[2013.05.18 09:25:29 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.05.18 09:25:28 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.05.18 09:25:20 | 000,123,389 | ---- | M] () -- C:\ProgramData\nvModes.001
[2013.05.18 09:25:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.05.18 09:25:12 | 3215,577,088 | -HS- | M] () -- C:\hiberfil.sys
[2013.05.18 09:24:11 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2013.05.18 09:17:11 | 000,632,031 | ---- | M] () -- C:\Users\Papabär\Desktop\adwcleaner.exe
[2013.05.18 09:15:47 | 000,545,954 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Papabär\Desktop\JRT.exe
[2013.05.18 00:12:34 | 000,127,518 | ---- | M] () -- C:\Users\Papabär\Desktop\TDSSKiller.Report.pdf
[2013.05.17 23:38:31 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Papabär\Desktop\tdsskiller.exe
[2013.05.17 23:24:43 | 000,000,512 | ---- | M] () -- C:\Users\Papabär\Desktop\MBR.dat
[2013.05.17 22:37:59 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\Papabär\Desktop\aswMBR.exe
[2013.05.17 22:35:10 | 000,578,393 | ---- | M] () -- C:\Users\Papabär\Pfingsthausaufgabe_Embryologie.pdf
[2013.05.17 20:36:51 | 000,377,856 | ---- | M] () -- C:\Users\Papabär\Desktop\gmer_2.1.19163.exe
[2013.05.17 20:33:49 | 000,025,407 | ---- | M] () -- C:\Users\Papabär\Desktop\Nächste Schritte zur Trojanersäuberung.odt
[2013.05.17 10:04:56 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013.05.17 09:48:41 | 005,066,411 | R--- | M] (Swearware) -- C:\Users\Papabär\Desktop\ComboFix.exe
[2013.05.17 08:24:30 | 000,659,530 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.05.17 08:24:30 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.05.17 08:24:30 | 000,141,256 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.05.17 08:24:30 | 000,111,422 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.05.16 22:51:02 | 000,123,389 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2013.05.16 13:33:32 | 000,017,225 | ---- | M] () -- C:\Users\Papabär\Desktop\Anfrage bei www.trojaner-board.de.odt
[2013.05.16 13:22:55 | 000,042,046 | ---- | M] () -- C:\Users\Papabär\Desktop\Scan auf C und Gesamtscan am 16.05..pdf
[2013.05.16 12:37:03 | 000,047,553 | ---- | M] () -- C:\Users\Papabär\Desktop\Gesamtscan 15.05..pdf
[2013.05.16 12:22:21 | 000,049,082 | ---- | M] () -- C:\Users\Papabär\Desktop\Scheduled Scan 15.05..pdf
[2013.05.16 09:00:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Papabär\Desktop\OTL.exe
[2013.05.16 03:34:15 | 000,397,672 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.05.15 09:29:46 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013.05.15 09:29:46 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013.05.10 22:04:45 | 000,000,650 | ---- | M] () -- C:\Users\Papabär\Desktop\Fishdom 2 Deluxe.lnk
[2013.05.10 21:53:13 | 000,019,398 | ---- | M] () -- C:\Users\Papabär\Desktop\Testchart Schamambu Stand 05.13.odt
[2013.05.10 21:45:02 | 000,018,922 | ---- | M] () -- C:\Users\Papabär\Desktop\Testchart Schamambu für Buchladen Leselust.odt
[2013.05.05 21:12:55 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.05.05 19:42:33 | 000,093,696 | ---- | M] () -- C:\Users\Papabär\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.05.04 12:04:34 | 000,015,078 | ---- | M] () -- C:\Users\Papabär\Desktop\Gebete an die Götter.odt
[2013.05.03 20:01:38 | 000,000,446 | ---- | M] () -- C:\Windows\tasks\Wise Registry Cleaner Schedule Task.job
[2013.05.01 11:17:44 | 000,018,134 | ---- | M] () -- C:\Users\Papabär\Desktop\Hollow Bones.odt
[2013.04.28 21:57:57 | 000,043,533 | ---- | M] () -- C:\Users\Papabär\Desktop\20130505 fruehlingsfest klein regenbogenfabrik.jpg
[2013.04.26 13:03:54 | 000,012,536 | ---- | M] () -- C:\Users\Papabär\Desktop\AHS.odt
[2013.04.22 09:57:44 | 000,011,938 | ---- | M] () -- C:\Users\Papabär\Desktop\Küchendienstplan.ods
[2013.04.19 08:39:39 | 000,647,419 | ---- | M] () -- C:\Users\Papabär\Desktop\Barth - Schreiben DRV-Bund ans Gericht, April 2013.pdf
[1 C:\Users\Papabär\*.tmp files -> C:\Users\Papabär\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.05.18 09:17:11 | 000,632,031 | ---- | C] () -- C:\Users\Papabär\Desktop\adwcleaner.exe
[2013.05.18 00:12:30 | 000,127,518 | ---- | C] () -- C:\Users\Papabär\Desktop\TDSSKiller.Report.pdf
[2013.05.17 23:24:43 | 000,000,512 | ---- | C] () -- C:\Users\Papabär\Desktop\MBR.dat
[2013.05.17 22:35:10 | 000,578,393 | ---- | C] () -- C:\Users\Papabär\Pfingsthausaufgabe_Embryologie.pdf
[2013.05.17 20:36:50 | 000,377,856 | ---- | C] () -- C:\Users\Papabär\Desktop\gmer_2.1.19163.exe
[2013.05.17 20:33:45 | 000,025,407 | ---- | C] () -- C:\Users\Papabär\Desktop\Nächste Schritte zur Trojanersäuberung.odt
[2013.05.17 09:50:54 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.05.17 09:50:54 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.05.17 09:50:54 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.05.17 09:50:54 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.05.17 09:50:54 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.05.16 13:33:30 | 000,017,225 | ---- | C] () -- C:\Users\Papabär\Desktop\Anfrage bei www.trojaner-board.de.odt
[2013.05.16 13:22:53 | 000,042,046 | ---- | C] () -- C:\Users\Papabär\Desktop\Scan auf C und Gesamtscan am 16.05..pdf
[2013.05.16 12:37:01 | 000,047,553 | ---- | C] () -- C:\Users\Papabär\Desktop\Gesamtscan 15.05..pdf
[2013.05.16 12:22:19 | 000,049,082 | ---- | C] () -- C:\Users\Papabär\Desktop\Scheduled Scan 15.05..pdf
[2013.05.15 14:42:41 | 000,185,616 | ---- | C] () -- C:\Windows\System32\ztvunrar39.dll
[2013.05.15 14:42:41 | 000,169,744 | ---- | C] () -- C:\Windows\System32\ztvunrar36.dll
[2013.05.15 14:42:41 | 000,153,088 | ---- | C] () -- C:\Windows\System32\UNRAR3.dll
[2013.05.15 14:42:41 | 000,077,312 | ---- | C] () -- C:\Windows\System32\ztvunace26.dll
[2013.05.15 14:42:41 | 000,075,264 | ---- | C] () -- C:\Windows\System32\unacev2.dll
[2013.05.10 22:04:45 | 000,000,650 | ---- | C] () -- C:\Users\Papabär\Desktop\Fishdom 2 Deluxe.lnk
[2013.05.10 21:45:40 | 000,019,398 | ---- | C] () -- C:\Users\Papabär\Desktop\Testchart Schamambu Stand 05.13.odt
[2013.05.01 11:18:26 | 000,015,078 | ---- | C] () -- C:\Users\Papabär\Desktop\Gebete an die Götter.odt
[2013.04.28 21:57:57 | 000,043,533 | ---- | C] () -- C:\Users\Papabär\Desktop\20130505 fruehlingsfest klein regenbogenfabrik.jpg
[2013.04.26 13:03:52 | 000,012,536 | ---- | C] () -- C:\Users\Papabär\Desktop\AHS.odt
[2013.04.22 09:50:07 | 000,011,938 | ---- | C] () -- C:\Users\Papabär\Desktop\Küchendienstplan.ods
[2013.04.19 08:39:36 | 000,647,419 | ---- | C] () -- C:\Users\Papabär\Desktop\Barth - Schreiben DRV-Bund ans Gericht, April 2013.pdf
[2013.02.05 18:52:54 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2013.02.05 18:52:50 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2013.02.05 18:52:50 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2013.02.05 18:52:50 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2013.02.05 18:52:50 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2012.08.13 12:08:08 | 000,014,217 | ---- | C] () -- C:\Program Files\readme.html
[2012.08.13 11:11:02 | 141,421,187 | ---- | C] () -- C:\Program Files\openofficeorg1.cab
[2012.08.13 11:09:30 | 003,166,208 | ---- | C] () -- C:\Program Files\openofficeorg341.msi
[2012.08.13 11:09:30 | 000,000,294 | ---- | C] () -- C:\Program Files\setup.ini
[2012.05.08 15:15:36 | 000,000,005 | ---- | C] () -- C:\Program Files\basis-link
[2011.12.29 14:17:08 | 000,000,000 | ---- | C] () -- C:\Windows\brdfxspd.dat
[2011.12.29 14:17:03 | 000,106,496 | ---- | C] () -- C:\Windows\System32\BrMuSNMP.dll
[2011.12.29 13:50:58 | 000,000,060 | R--- | C] () -- C:\Program Files\BRINST.INI
[2010.02.05 13:12:26 | 000,123,389 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010.02.05 13:11:00 | 000,123,389 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009.06.11 16:14:44 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.05.22 22:23:51 | 000,000,026 | ---- | C] () -- C:\Users\Papabär\AppData\Roaming\vispa.ini
[2008.10.21 18:14:37 | 000,000,680 | ---- | C] () -- C:\Users\Papabär\AppData\Local\d3d9caps.dat
[2008.09.14 10:24:06 | 000,093,696 | ---- | C] () -- C:\Users\Papabär\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.05.29 22:41:42 | 000,037,375 | ---- | C] () -- C:\Program Files\openoffice.org-xsltfilter.cab
[2008.05.29 22:41:41 | 002,678,080 | ---- | C] () -- C:\Program Files\openoffice.org-writer.cab
[2008.05.29 22:41:33 | 000,207,388 | ---- | C] () -- C:\Program Files\openoffice.org-testtool.cab
[2008.05.29 22:41:31 | 002,504,975 | ---- | C] () -- C:\Program Files\openoffice.org-pyuno.cab
[2008.05.29 22:41:12 | 000,052,152 | ---- | C] () -- C:\Program Files\openoffice.org-onlineupdate.cab
[2008.05.29 22:41:11 | 001,209,478 | ---- | C] () -- C:\Program Files\openoffice.org-math.cab
[2008.05.29 22:41:07 | 000,118,910 | ---- | C] () -- C:\Program Files\openoffice.org-javafilter.cab
[2008.05.29 22:41:06 | 001,395,007 | ---- | C] () -- C:\Program Files\openoffice.org-impress.cab
[2008.05.29 22:41:01 | 000,086,870 | ---- | C] () -- C:\Program Files\openoffice.org-graphicfilter.cab
[2008.05.29 22:41:00 | 001,046,365 | ---- | C] () -- C:\Program Files\openoffice.org-draw.cab
[2008.05.29 22:41:00 | 000,002,769 | ---- | C] () -- C:\Program Files\openoffice.org-emailmerge.cab
[2008.05.29 22:40:55 | 002,031,954 | ---- | C] () -- C:\Program Files\openoffice.org-core09.cab
[2008.05.29 22:40:49 | 000,305,784 | ---- | C] () -- C:\Program Files\openoffice.org-core08.cab
[2008.05.29 22:40:43 | 004,249,333 | ---- | C] () -- C:\Program Files\openoffice.org-core07.cab
[2008.05.29 22:40:32 | 028,871,584 | ---- | C] () -- C:\Program Files\openoffice.org-core06.cab
[2008.05.29 22:36:41 | 018,803,720 | ---- | C] () -- C:\Program Files\openoffice.org-core05.cab
[2008.05.29 22:35:30 | 016,503,595 | ---- | C] () -- C:\Program Files\openoffice.org-core04.cab
[2008.05.29 22:34:38 | 009,118,675 | ---- | C] () -- C:\Program Files\openoffice.org-core03.cab
[2008.05.29 22:34:18 | 003,861,568 | ---- | C] () -- C:\Program Files\openoffice.org-core02.cab
[2008.05.29 22:34:04 | 015,105,268 | ---- | C] () -- C:\Program Files\openoffice.org-core01.cab
[2008.05.29 22:33:29 | 004,871,833 | ---- | C] () -- C:\Program Files\openoffice.org-calc.cab
[2008.05.29 22:33:12 | 001,912,368 | ---- | C] () -- C:\Program Files\openoffice.org-base.cab
[2008.05.29 22:33:04 | 000,043,005 | ---- | C] () -- C:\Program Files\openoffice.org-activex.cab
[2008.05.29 22:33:02 | 004,375,552 | ---- | C] () -- C:\Program Files\openofficeorg24.msi
========== ZeroAccess Check ==========
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.10.16 11:18:37 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2012.10.16 11:18:37 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2011.09.08 13:53:53 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Alawar
[2010.06.06 21:37:34 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Amazon
[2011.12.31 19:16:37 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\ASCOMP Software
[2011.07.08 17:06:43 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Audacity
[2011.02.07 11:07:39 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\AVG
[2012.10.14 23:41:15 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\AVG2013
[2011.09.08 12:38:50 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Awem
[2011.09.13 19:14:24 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Az-Art
[2011.08.29 19:15:24 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Brunhilda_intenium
[2013.04.04 18:54:02 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Curse Advertising
[2013.05.10 21:54:09 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Das Geheimnis der ägyptischen Mumie
[2013.05.10 21:57:29 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Der Schatten der Dämmerung
[2013.05.18 09:28:19 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Dropbox
[2012.11.27 13:21:36 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\DVDVideoSoft
[2011.08.28 17:03:00 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Flood Light Games
[2011.08.25 14:26:52 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\FloodLightGames
[2011.09.09 20:08:30 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Friday's games
[2011.08.09 23:04:54 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Gogii
[2011.12.28 00:09:15 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\HandBrake
[2013.05.14 22:38:16 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Mabua
[2010.06.20 13:52:45 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\MobMapUpdater
[2012.06.01 14:34:50 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Nokia
[2011.03.12 11:43:35 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Nokia Ovi Suite
[2012.03.16 19:22:36 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Nokia Suite
[2013.05.16 08:43:33 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Ocosz
[2010.08.12 20:30:45 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\OpenOffice.org
[2011.03.12 11:42:52 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\PC Suite
[2010.09.14 18:29:42 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\PC-FAX TX
[2011.08.28 18:14:05 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Phantasmat_intenium_se
[2011.08.29 00:08:06 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Princess Isabella
[2011.09.09 22:03:45 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\RainbowGames
[2012.08.29 23:28:21 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\runic games
[2013.03.22 11:49:29 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Samsung
[2010.12.07 22:05:42 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\ScanSoft
[2013.05.15 14:42:49 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Simply Super Software
[2011.08.29 18:16:25 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Sleepwalker Games
[2012.04.16 12:16:17 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Thunderbird
[2011.09.14 18:17:32 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\TrickySoftware
[2010.12.06 18:27:55 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\TS3Client
[2012.10.14 11:36:50 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\TuneUp Software
[2012.12.12 16:12:00 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Wise Registry Cleaner
[2013.05.16 09:13:31 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Xaacac
[2010.12.07 22:05:48 | 000,000,000 | ---D | M] -- C:\Users\Papabär\AppData\Roaming\Zeon
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4
< End of report > --- --- ---
OTL Logfile: Code:
OTL Extras logfile created on: 18.05.2013 09:29:47 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Papabär\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,99 Gb Total Physical Memory | 1,75 Gb Available Physical Memory | 58,57% Memory free
6,18 Gb Paging File | 4,92 Gb Available in Paging File | 79,66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 100,09 Gb Total Space | 34,70 Gb Free Space | 34,67% Space Free | Partition Type: NTFS
Drive D: | 188,00 Gb Total Space | 86,00 Gb Free Space | 45,74% Space Free | Partition Type: NTFS
Computer Name: CERNNUNOS | User Name: Papabär | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
[HKEY_USERS\S-1-5-21-2637854371-3477063950-4265566210-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
https [open] -- Reg Error: Value error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D8A82E3-FB25-467E-B5A7-30BE3D0DC581}" = lport=138 | protocol=17 | dir=in | app=system |
"{182BC3C4-9534-4BB0-828D-270D68249FDD}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{2C661C94-A73C-4682-93F7-E6C0F9A26A1B}" = rport=138 | protocol=17 | dir=out | app=system |
"{32DDD508-5184-4D9A-9121-D4E6C8228179}" = rport=137 | protocol=17 | dir=out | app=system |
"{4C07F45A-B3C7-4106-AFBE-720D4B6F5F70}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner |
"{584342B5-BC81-409A-B236-17278483CD02}" = rport=139 | protocol=6 | dir=out | app=system |
"{A5BD5B66-5099-4CEC-AC03-502C7C601FEE}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{A75C3297-EC91-4445-BDAC-B0500CEF650E}" = lport=137 | protocol=17 | dir=in | app=system |
"{AA31B417-EE46-4EFF-8885-12524BD02158}" = lport=139 | protocol=6 | dir=in | app=system |
"{C72611AF-2000-49D5-B768-91B00989F67D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{D8AC4681-D0AD-47B1-8D2F-A2C27617607C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{DCAB2756-7503-4795-A1B6-FF834279B9B5}" = lport=445 | protocol=6 | dir=in | app=system |
"{F40EB487-BC14-43AB-84BA-E8ADF8011404}" = rport=445 | protocol=6 | dir=out | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B0E9B2B-1B97-43D5-8D8B-AF3CD5EE613A}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe |
"{11195245-9FC7-4170-8295-5CE9ACD88716}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{13DE9F6D-88E8-44AC-9D28-28809D612AFD}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{1739C491-AC32-45F5-810F-A1EE4B24E358}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{19789A3A-6F62-475B-AC2C-EFA33142E50F}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{1D60AFC6-859D-4C5F-8E4A-CE9E0B503E56}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{1F6BED36-3230-4764-A8A3-F5EABB9EDE22}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{23D8D3BD-CF12-4DE7-8EC4-5E5F40477923}" = protocol=6 | dir=in | app=c:\program files\k-lite codec pack\filters\ac3config.exe |
"{25532F58-6279-477D-83B8-D32F152AF5D9}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.0.9.9551-to-3.1.0.9767-dede-downloader.exe |
"{2CA08CE7-8172-43B4-9967-B7B9AAA2AA90}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{35840F05-D87F-4E77-97FE-A5E8CC03AA01}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3B9D3255-CD43-4034-BC37-6A949CF02F2D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{3C5CF965-B1E9-40AC-987E-EA39280767C3}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{42F023BB-4DB8-4641-8459-8D5D41B0B19C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{445749A4-9740-4F97-97A0-30B63B13257B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{4695AE67-D0A4-4D12-B1E8-C10323A83CE4}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-dede-downloader.exe |
"{4A6A3898-B9AA-4043-9676-76A9592FA5BC}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{528C59BB-2B2E-47D5-8765-319CF47195F3}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{54D849BF-4EB9-4BE8-90D2-06F9F8A45B78}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-dede-downloader.exe |
"{5538CA87-4B5A-4BCF-BA2D-929DA54BB34F}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{60B04822-DFF2-4CF8-9309-D5FA6D12A203}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{6281A72A-4C99-434F-A109-42FBDF8A38D8}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-dede-downloader.exe |
"{675D9598-5C15-48CB-AA2F-728F6886D37C}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{7190BF33-DD1C-4540-B124-9B06497684F6}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-dede-downloader.exe |
"{76C52917-199E-4A6B-A881-4C13E5FFB404}" = protocol=17 | dir=in | app=c:\users\papabär\appdata\roaming\dropbox\bin\dropbox.exe |
"{81762DE2-4E99-4F58-9617-0ABF183B94E1}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\torchlight\torchlight.exe |
"{85BDDFFD-3B1E-4789-B7AD-BFDA04924F70}" = protocol=17 | dir=in | app=c:\program files\k-lite codec pack\filters\ac3config.exe |
"{8F2FAA60-66BD-44FA-8BA2-EC2F579CC87C}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-dede-downloader.exe |
"{96F079AF-F2DE-4196-898C-33B90C5C2D16}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{9C2AFB5D-586D-47E3-B570-43EC11F2FD22}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{9D635732-6EC5-426B-ACF0-AE797D8C3C89}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-dede-downloader.exe |
"{9F28B44E-0C14-48EF-B424-6AF42003383B}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.0.9.9551-to-3.1.0.9767-dede-downloader.exe |
"{B040E5C4-6C93-40E8-B44C-8F3D37D8342A}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{B3C5D727-2D1F-4BEB-BAE5-3FBBF06FC7BB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BD7C2660-C349-402B-9063-D74BDB524284}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\torchlight\torchlight.exe |
"{C699CEE2-955B-4DD7-8F03-57EC5B9BB6DF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{C8D1789B-BDD4-4307-9639-2DEB68D0DF42}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{CD08A699-21CD-4BD6-9ACA-C2A51CC1198C}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-dede-downloader.exe |
"{D6E17EEA-44CC-4515-8ABE-B72D74C0FAE0}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-dede-downloader.exe |
"{EEE17A37-B899-47A7-B7BC-D77D6C9828D1}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{F6911BB0-087D-42AF-8D1A-5767056AD464}" = protocol=6 | dir=in | app=c:\users\papabär\appdata\roaming\dropbox\bin\dropbox.exe |
"{FD7C559B-D498-40B3-9F63-75B9233F4F16}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{FF6C2AEB-B625-43D9-865F-6A27B401FAA1}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"TCP Query User{13A7E0BD-AB5C-489B-9285-EE5761CD516F}C:\program files\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
"TCP Query User{4012DBB0-053A-45F5-9A3D-D4B8492FF1DC}C:\program files\windows sidebar\sidebar.exe" = protocol=6 | dir=in | app=c:\program files\windows sidebar\sidebar.exe |
"TCP Query User{8BCA55D2-6B08-4DBB-8149-AE25A653622A}C:\users\papabär\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\papabär\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{6D9D563F-A616-4581-936B-E3F2F447E149}C:\users\papabär\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\papabär\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{7D05EAF9-D435-4B12-AF15-7430E6342CE1}C:\program files\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
"UDP Query User{DE3576CA-8912-4D6F-B035-B8D7A07F61DD}C:\program files\windows sidebar\sidebar.exe" = protocol=17 | dir=in | app=c:\program files\windows sidebar\sidebar.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1
"{00AF10C1-44BD-4862-9D7F-24E6BA3E87FD}" = imagine digital freedom - Samsung
"{02570AE0-BEE0-4A6C-BE3F-D806E9F2EA17}" = ScanSoft PaperPort 11
"{038A524F-58DB-438A-8391-8F7F0CA14B9E}" = Microsoft® Winter Fun Pack 2004 for Windows® XP
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.6300
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04983D37-2202-4295-94A2-8B547C66133F}" = Atheros WLAN Client
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{090962E2-4BE8-4A8A-86B0-7A5ED31C1273}" = USB2.0 UVC WebCam
"{09298F26-A95C-31E2-9D95-2C60F586F075}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution III
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{1BAA7DE9-6EDC-4432-B32E-B1911543BE2C}" = AVG 2013
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1
"{26A24AE4-039D-4CA4-87B4-2F83216037FF}" = Java(TM) 6 Update 37
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{2DFB5485-A3EF-4298-9280-4AF80C9F4BE9}" = Microsoft SQL Server VSS Writer
"{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor
"{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2
"{3B69A712-4CBC-40B1-AE55-0203075FD093}" = Nokia Suite
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{48A5AB54-6327-43DC-A376-4AC74C5D40B0}" = AVG 2013
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{547DCEC7-DD2A-47E9-82C7-5CF1EAB526DA}" = Microsoft SQL Server Native Client
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}" = Brother MFL-Pro Suite MFC-255CW
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7390478C-8581-415E-92E9-2997D9306B81}" = PC Connectivity Solution
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{7B46F9CF-CF60-492E-816E-95EB1A9D1BB4}" = Play Camera
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 5.2.0
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A40407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DE3F260-B88E-42CE-90E7-73C78C37D95E}" = 32 Bit HP BiDi Channel Components Installer
"{A1D6721B-9C28-4E3F-9DE1-C6584B99465D}" = Intel(R) PROSet/Wireless WiFi-Software
"{A57025CC-5F2E-4D01-B387-06DB10500D43}" = Nokia Connectivity Cable Driver
"{A5F483F0-2D79-4FCA-AE09-D0D96E23EBF7}" = Samsung Update Plus
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.5) - Deutsch
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"17D063A0A9F5D5A225B76B1D9BCB5ADBE85C8382" = Windows-Treiberpaket - Nokia pccsmcfd “LegacyDriver” (05/31/2012 7.1.2.0)
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9
"AVG" = AVG 2013
"Digital Editions" = Adobe Digital Editions
"Fishdom 2 Deluxe_is1" = Fishdom 2 Deluxe
"Free Studio_is1" = Free Studio version 5.3.3
"Free YouTube Download_is1" = Free YouTube Download version 3.1.35.903
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.35.1031
"InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{7B46F9CF-CF60-492E-816E-95EB1A9D1BB4}" = Play Camera
"InstallShield_{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"InstallShield_{A5F483F0-2D79-4FCA-AE09-D0D96E23EBF7}" = Samsung Update Plus
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.2.5
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 21.0 (x86 de)" = Mozilla Firefox 21.0 (x86 de)
"Mozilla Thunderbird 17.0.6 (x86 de)" = Mozilla Thunderbird 17.0.6 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Nokia Suite" = Nokia Suite
"NVIDIA Drivers" = NVIDIA Drivers
"ProInst" = Intel PROSet Wireless
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Steam App 41500" = Torchlight
"Synchredible_is1" = Synchredible
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Trojan Remover_is1" = Trojan Remover 6.8.6
"USB2.0 UVC 1.3M WebCam" = USB2.0 UVC 1.3M WebCam
"VLC media player" = VLC media player 1.1.11
"WinRAR archiver" = WinRAR Archivierer
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 7.67
"World of Warcraft" = World of Warcraft
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-2637854371-3477063950-4265566210-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"101a9f93b8f0bb6f" = Curse Client
"Dropbox" = Dropbox
"MyFreeCodec" = MyFreeCodec
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 18.05.2013 03:26:36 | Computer Name = Cernnunos | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 18.05.2013 03:26:25 | Computer Name = Cernnunos | Source = DCOM | ID = 10016
Description =
Error - 18.05.2013 03:26:36 | Computer Name = Cernnunos | Source = Service Control Manager | ID = 7000
Description =
Error - 18.05.2013 03:30:05 | Computer Name = Cernnunos | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
< End of report > --- --- --- |