netnocheiner | 20.11.2012 22:14 | Zitat:
Zitat von cosinus
(Beitrag 960290)
Überbleibsel sind Überbleibsel :D
Mit False Positive wird gemeint, dass eine völlig harmlos/legitime Datei vom Virenscanner "erkannt" wird als Schädling. Wenn aber Schädling die noch in einer Q stecken erkannt werden ist das folgerichtig und nicht falsch :) | Ansichtssache.:P Ich will einfach nur alles sehen was mir Angst machen könnte, und wenn ich was sehe, obwohl esmir keine Angst machen sollte, ist es ein 'false' postive für mich.:uglyhammer:
Hier der OTL-Bericht (hab vergessen Antivir zu beenden, aber es stand nichts davon in deinem Post; falls es Probleme gab,einfach sagen): Code:
OTL logfile created on: 20.11.2012 21:36:48 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Max\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,14 Gb Available Physical Memory | 57,03% Memory free
4,00 Gb Paging File | 2,74 Gb Available in Paging File | 68,59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149,04 Gb Total Space | 29,23 Gb Free Space | 19,61% Space Free | Partition Type: NTFS
Drive D: | 74,50 Gb Total Space | 71,53 Gb Free Space | 96,00% Space Free | Partition Type: NTFS
Computer Name: MAX-PC | User Name: Max | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.11.20 21:34:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Max\Desktop\OTL.exe
PRC - [2012.10.17 18:29:39 | 000,544,248 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
PRC - [2012.10.10 21:23:42 | 001,258,856 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.07.18 17:04:33 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.07.18 17:04:23 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.07.18 17:04:22 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.02.27 14:43:07 | 000,801,792 | ---- | M] (Yuna Software) -- C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
PRC - [2012.01.21 13:25:34 | 000,220,744 | ---- | M] (Geek Software GmbH) -- C:\Program Files (x86)\PDF24\pdf24.exe
PRC - [2011.10.14 07:01:50 | 000,994,360 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psia.exe
PRC - [2011.10.14 07:01:48 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\sua.exe
PRC - [2011.10.14 07:01:46 | 000,291,896 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
PRC - [2009.09.21 16:56:32 | 001,736,704 | ---- | M] (NETGEAR) -- C:\Program Files (x86)\NETGEAR\WNDA3100\WNDA3100.exe
PRC - [2006.09.19 08:07:28 | 000,827,392 | ---- | M] () -- C:\Windows\vsnpstd3.exe
========== Modules (No Company Name) ==========
MOD - [2006.09.19 08:07:28 | 000,827,392 | ---- | M] () -- C:\Windows\vsnpstd3.exe
========== Services (SafeList) ==========
SRV - [2012.10.27 16:20:21 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.10.17 18:29:39 | 000,544,248 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe -- (vpnagent)
SRV - [2012.10.10 21:23:42 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.10.09 16:14:20 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.08.17 16:02:30 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.07.18 17:04:33 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.07.18 17:04:23 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.07.13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011.10.14 07:01:50 | 000,994,360 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\psia.exe -- (Secunia PSI Agent)
SRV - [2011.10.14 07:01:48 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2011.03.28 20:11:06 | 002,292,096 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.02.29 02:07:18 | 000,942,080 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\NETGEAR\WNDA3100\jswpsapi.exe -- (jswpsapi)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.10.17 18:11:37 | 000,107,432 | R--- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\acsock64.sys -- (acsock)
DRV:64bit: - [2012.08.03 20:38:55 | 000,027,048 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpnva64.sys -- (vpnva)
DRV:64bit: - [2012.07.18 17:04:42 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.07.18 17:04:42 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2012.07.18 17:04:41 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.11.10 12:07:45 | 000,270,912 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011.05.15 13:00:43 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2011.05.15 13:00:42 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2011.03.21 12:22:06 | 000,452,200 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.09.01 09:30:58 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2010.02.25 17:51:02 | 000,029,696 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2009.10.21 12:01:34 | 000,767,488 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WNDA31w7x.sys -- (WNDA3100)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.01.13 09:30:00 | 000,560,128 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WN111v2x.sys -- (WN111v2)
DRV:64bit: - [2008.10.01 16:44:06 | 000,026,624 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\jswpslwfx.sys -- (JSWPSLWF)
DRV:64bit: - [2008.03.13 08:46:00 | 000,027,136 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ManyCam_x64.sys -- (ManyCam)
DRV:64bit: - [2007.03.27 17:18:58 | 010,550,272 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\snpstd3.sys -- (SNPSTD3)
DRV:64bit: - [2006.11.28 21:46:20 | 000,043,328 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PCAMp50a64.sys -- (PCAMp50a64)
DRV:64bit: - [2006.11.28 21:46:20 | 000,041,280 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PCASp50a64.sys -- (PCASp50a64)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0C 5D CE 40 DC C5 CD 01 [binary data]
IE - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 204.93.211.219:80
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: {b749fc7c-e949-447f-926c-3f4eed6accfe}:0.7.1.1
FF - prefs.js..extensions.enabledAddons: ich@maltegoetz.de:1.4.3
FF - prefs.js..network.proxy.http: "81.27.79.181"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.no_proxies_on: "localhost, 127.0.0.1, stealthy.co"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.10.27 16:20:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.27 16:20:18 | 000,000,000 | ---D | M]
[2011.05.15 10:01:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Max\AppData\Roaming\mozilla\Extensions
[2012.10.23 20:11:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\e8jea1mp.default\extensions
[2012.09.25 00:10:13 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\e8jea1mp.default\extensions\ich@maltegoetz.de
[2012.03.29 21:35:13 | 000,061,705 | ---- | M] () (No name found) -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}.xpi
[2012.07.26 00:01:50 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011.12.22 20:51:14 | 000,001,182 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\acronym-finder.xml
[2011.08.12 12:45:14 | 000,002,571 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\amazon-search-suggestions.xml
[2011.07.30 00:11:19 | 000,002,251 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\dc-database-en.xml
[2011.05.31 21:25:04 | 000,002,321 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\dictcc.xml
[2011.12.04 21:09:35 | 000,002,279 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\elder-scrolls-en.xml
[2011.08.14 17:36:23 | 000,001,660 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\leo-deu-eng.xml
[2011.07.30 00:11:09 | 000,002,262 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\marvel-database-en.xml
[2011.07.15 02:28:43 | 000,002,322 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\openthesaurus.xml
[2011.11.18 16:37:29 | 000,001,597 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\the-pirate-bay.xml
[2011.11.06 12:39:53 | 000,001,218 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\uespwiki-en.xml
[2011.05.31 21:24:58 | 000,002,006 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\urban-dictionary.xml
[2011.05.16 18:51:19 | 000,001,330 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\wikipedia-en.xml
[2012.03.18 22:11:17 | 000,001,997 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\wolframalpha.xml
[2011.12.10 02:02:33 | 000,002,057 | ---- | M] () -- C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\e8jea1mp.default\searchplugins\youtube-videosuche.xml
[2012.10.27 16:20:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.10.27 16:20:18 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.10.27 16:20:21 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.21 12:50:15 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.29 20:04:47 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.21 12:50:15 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.21 12:50:15 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.21 12:50:15 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.21 12:50:15 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2012.08.11 23:34:29 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe ()
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PlusService] C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe (Yuna Software)
O4 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000..\Run: [Duyci] C:\Users\Max\AppData\Roaming\Wiyvvo\iqzy.exe (Compagnia ? quale Compagnia?)
O4 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000..\Run: [Feipsa] C:\Users\Max\AppData\Roaming\Osuhy\neve.exe (Compagnia ? quale Compagnia?)
O4 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000..\Run: [Fyagweo] C:\Users\Max\AppData\Roaming\Owysne\voag.exe (Compagnia ? quale Compagnia?)
O4 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000..\Run: [Wisdom-soft AutoScreenRecorder 3.1 Pro] 0 File not found
O4 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1001..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
F3:64bit: - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000 WinNT: Load - (C:\Users\Max\LOCALS~1\Temp\mszxfa.cmd) - C:\Users\Max\LOCALS~1\Temp\mszxfa.cmd (Compagnia ? quale Compagnia?)
F3 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000 WinNT: Load - (C:\Users\Max\LOCALS~1\Temp\mszxfa.cmd) - C:\Users\Max\LOCALS~1\Temp\mszxfa.cmd (Compagnia ? quale Compagnia?)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O15 - HKU\S-1-5-21-3975674286-3007113892-2621660134-1000\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 10.3.0)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Java Plug-in 10.7.2)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Java Plug-in 1.7.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.7.0_07)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1E5EB5F-F821-46DC-A7F2-FFC51F45EA77}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
MsConfig:64bit - StartUpReg: nMdQvhGrqSMKfoq.exe - hkey= - key= - File not found
MsConfig:64bit - State: "services" - Reg Error: Key error.
MsConfig:64bit - State: "startup" - Reg Error: Key error.
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012.11.20 21:34:41 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Max\Desktop\OTL.exe
[2012.11.20 20:16:35 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Max\Desktop\tdsskiller.exe
[2012.11.20 20:14:35 | 004,732,416 | ---- | C] (AVAST Software) -- C:\Users\Max\Desktop\aswMBR.exe
[2012.11.20 14:58:44 | 000,000,000 | ---D | C] -- C:\Users\Max\Documents\Uni
[2012.11.19 23:13:37 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Xoux
[2012.11.19 23:13:37 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Owysne
[2012.11.19 23:13:37 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Lioby
[2012.11.19 20:12:43 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Osuhy
[2012.11.19 20:12:43 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Fygee
[2012.11.19 20:12:43 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Ciowd
[2012.11.19 14:54:52 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{319151FB-D44F-4963-BBFE-F447B76F7028}
[2012.11.18 23:48:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Ricoh
[2012.11.18 19:38:09 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Wiyvvo
[2012.11.18 19:38:09 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Ibxyyr
[2012.11.18 19:38:09 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Asnya
[2012.11.18 15:49:32 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{CF9C6E5A-6805-4E30-80C2-FBA789A66888}
[2012.11.18 03:07:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2012.11.18 02:36:16 | 000,000,000 | ---D | C] -- C:\Users\Max\Local Settings
[2012.11.17 16:30:44 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{E30551CE-C126-4FE2-8EF4-B78B8E67D9C1}
[2012.11.17 02:38:16 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{39CC731D-E6F2-4043-A189-126C183D05F7}
[2012.11.16 14:38:01 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{393E2046-49FA-4435-B953-545C5CD9BC6E}
[2012.11.15 22:15:56 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{AAAB3978-2FB7-4010-B8FF-F96DF703CB67}
[2012.11.14 21:58:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
[2012.11.14 18:33:56 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\HorizonWimba
[2012.11.14 14:33:31 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{132CF4EB-668D-4CEC-AF72-9280A301C40B}
[2012.11.13 16:04:11 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{CD7D94D8-7EDA-4102-B301-8A4CA81A7869}
[2012.11.13 02:38:53 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{ADF65CF9-C573-4918-B21C-C986B9FF50BE}
[2012.11.12 14:38:40 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{5B05614E-C789-46F8-AB79-4E512626C558}
[2012.11.11 13:28:06 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{67E568EB-F635-4EA2-99BB-179A1D74E326}
[2012.11.10 14:41:58 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{170F3778-958A-4CE9-A661-7EBF167B838D}
[2012.11.09 16:18:06 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{19AFFE43-CCCB-4BF9-84D6-72D69242F8D4}
[2012.11.09 04:17:41 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{3CE167C9-8B04-4CD0-BC22-F8FBBC69CB0A}
[2012.11.08 16:17:29 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{6AF193CC-2276-4233-9EB5-0556FC14DC41}
[2012.11.07 16:21:21 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{FC0AC3C4-50F1-4675-9D98-05F305973D86}
[2012.11.06 19:49:14 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{5725FC92-6474-40FB-98FB-59695D715A82}
[2012.11.05 17:02:10 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{BC8DD572-3ED7-474A-8491-F059BB0B3AB0}
[2012.11.04 16:44:09 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{82F022E1-189B-4C17-8339-0E73EDF023A3}
[2012.11.04 03:08:15 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{3156638E-AB14-4D47-A472-73543CDB1035}
[2012.11.03 15:08:03 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{6FEADE73-6CC7-48E4-B563-C8C04B3A12C2}
[2012.11.02 18:22:54 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{9007DA8B-C8F5-4C8E-A654-7E025E5D5CD9}
[2012.11.01 20:20:22 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{D80794D0-D0BF-46D6-B0EF-26B301045328}
[2012.10.31 16:31:02 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{CB602A12-4D47-4D31-9C9C-27901E9C9F6C}
[2012.10.30 15:12:43 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{DE07DC95-4A65-4733-A630-84E9BB061675}
[2012.10.29 17:20:38 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{F4F82240-FDB0-4058-B07B-2DB65F7DFEAB}
[2012.10.28 14:57:22 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{D46D8015-BBCA-46D7-BC43-0D7E47229EF1}
[2012.10.28 01:10:57 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{149BE589-BD71-47ED-AF1C-16EDAD357724}
[2012.10.27 16:20:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012.10.27 13:10:44 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{7F26638A-FCCE-4958-942A-958B1E22CD82}
[2012.10.26 13:53:26 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{B9A3AF11-591B-49CE-B89A-DBB18A79BEFA}
[2012.10.25 15:45:51 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{A8DF5CD7-B4EB-4871-B098-C2003D13E6EC}
[2012.10.24 18:58:29 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{DEFA80BC-9DE2-4287-B264-8CBD8F27A968}
[2012.10.23 14:05:37 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{5391A965-1368-44D7-BA15-57D455D6B735}
[2012.10.22 20:05:42 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{9B7FCCA5-0E30-4A8F-8AF1-637538EA5E40}
========== Files - Modified Within 30 Days ==========
[2012.11.20 21:34:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Max\Desktop\OTL.exe
[2012.11.20 21:14:01 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.11.20 20:59:35 | 000,000,512 | ---- | M] () -- C:\Users\Max\Desktop\MBR.dat
[2012.11.20 20:16:35 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Max\Desktop\tdsskiller.exe
[2012.11.20 20:15:09 | 004,732,416 | ---- | M] (AVAST Software) -- C:\Users\Max\Desktop\aswMBR.exe
[2012.11.20 19:53:29 | 000,001,392 | ---- | M] () -- C:\Windows\SysNative\ricdb.ini
[2012.11.20 19:41:33 | 000,013,536 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.20 19:41:33 | 000,013,536 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.20 19:33:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.11.20 19:33:43 | 1610,113,024 | -HS- | M] () -- C:\hiberfil.sys
[2012.11.18 23:37:17 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.11.18 23:37:17 | 000,654,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.11.18 23:37:17 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.11.18 23:37:17 | 000,130,022 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.11.18 23:37:17 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.11.18 15:22:21 | 000,001,073 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.17 14:36:47 | 000,275,856 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.11.12 19:44:33 | 002,257,761 | ---- | M] () -- C:\Users\Max\Documents\max2.jpg
[2012.11.12 19:40:56 | 002,143,760 | ---- | M] () -- C:\Users\Max\Documents\20121112_174352.jpg
[2012.11.12 19:40:53 | 002,300,647 | ---- | M] () -- C:\Users\Max\Documents\crawlinginmyskiiin.jpg
[2012.11.12 19:40:47 | 002,245,507 | ---- | M] () -- C:\Users\Max\Documents\20121112_175006.jpg
[2012.11.12 19:40:44 | 002,319,717 | ---- | M] () -- C:\Users\Max\Documents\20121112_175908.jpg
[2012.11.12 19:40:42 | 002,313,252 | ---- | M] () -- C:\Users\Max\Documents\max1.jpg
[2012.11.12 19:40:38 | 002,324,608 | ---- | M] () -- C:\Users\Max\Documents\20121112_180255.jpg
[2012.11.12 19:40:37 | 002,311,649 | ---- | M] () -- C:\Users\Max\Documents\20121112_180339.jpg
[2012.11.12 19:40:35 | 002,328,168 | ---- | M] () -- C:\Users\Max\Documents\20121112_180349.jpg
[2012.11.12 19:40:33 | 002,290,808 | ---- | M] () -- C:\Users\Max\Documents\20121112_180357.jpg
[2012.11.12 19:40:31 | 002,263,260 | ---- | M] () -- C:\Users\Max\Documents\20121112_180429.jpg
[2012.11.12 19:40:28 | 002,190,795 | ---- | M] () -- C:\Users\Max\Documents\20121112_180451.jpg
[2012.11.12 19:40:25 | 002,272,992 | ---- | M] () -- C:\Users\Max\Documents\20121112_180520.jpg
[2012.11.07 17:59:09 | 000,001,366 | ---- | M] () -- C:\Users\Max\Desktop\hulk.rtf
[2012.10.22 23:08:27 | 003,764,050 | ---- | M] () -- C:\Users\Max\Documents\20121022_151547.jpg
[2012.10.22 23:07:32 | 003,375,268 | ---- | M] () -- C:\Users\Max\Documents\20121022_151537.jpg
[2012.10.22 23:06:42 | 003,307,656 | ---- | M] () -- C:\Users\Max\Documents\20121022_151523.jpg
[2012.10.22 23:05:50 | 002,728,989 | ---- | M] () -- C:\Users\Max\Documents\20121022_151618.jpg
[2012.10.22 23:05:08 | 003,267,684 | ---- | M] () -- C:\Users\Max\Documents\20121022_151634.jpg
[2012.10.22 23:04:09 | 003,799,515 | ---- | M] () -- C:\Users\Max\Documents\20121022_151702.jpg
========== Files Created - No Company Name ==========
[2012.11.20 20:59:35 | 000,000,512 | ---- | C] () -- C:\Users\Max\Desktop\MBR.dat
[2012.11.18 23:46:16 | 000,001,392 | ---- | C] () -- C:\Windows\SysNative\ricdb.ini
[2012.11.17 03:11:12 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012.11.17 03:01:58 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012.11.12 19:26:28 | 002,143,760 | ---- | C] () -- C:\Users\Max\Documents\20121112_174352.jpg
[2012.11.12 19:25:51 | 002,300,647 | ---- | C] () -- C:\Users\Max\Documents\crawlinginmyskiiin.jpg
[2012.11.12 19:25:15 | 002,245,507 | ---- | C] () -- C:\Users\Max\Documents\20121112_175006.jpg
[2012.11.12 19:24:38 | 002,319,717 | ---- | C] () -- C:\Users\Max\Documents\20121112_175908.jpg
[2012.11.12 19:24:01 | 002,313,252 | ---- | C] () -- C:\Users\Max\Documents\max1.jpg
[2012.11.12 19:23:26 | 002,257,761 | ---- | C] () -- C:\Users\Max\Documents\max2.jpg
[2012.11.12 19:22:46 | 002,324,608 | ---- | C] () -- C:\Users\Max\Documents\20121112_180255.jpg
[2012.11.12 19:22:07 | 002,311,649 | ---- | C] () -- C:\Users\Max\Documents\20121112_180339.jpg
[2012.11.12 19:21:28 | 002,328,168 | ---- | C] () -- C:\Users\Max\Documents\20121112_180349.jpg
[2012.11.12 19:20:49 | 002,290,808 | ---- | C] () -- C:\Users\Max\Documents\20121112_180357.jpg
[2012.11.12 19:20:07 | 002,263,260 | ---- | C] () -- C:\Users\Max\Documents\20121112_180429.jpg
[2012.11.12 19:19:25 | 002,190,795 | ---- | C] () -- C:\Users\Max\Documents\20121112_180451.jpg
[2012.11.12 19:18:44 | 002,272,992 | ---- | C] () -- C:\Users\Max\Documents\20121112_180520.jpg
[2012.11.07 17:59:09 | 000,001,366 | ---- | C] () -- C:\Users\Max\Desktop\hulk.rtf
[2012.10.22 23:07:33 | 003,764,050 | ---- | C] () -- C:\Users\Max\Documents\20121022_151547.jpg
[2012.10.22 23:06:44 | 003,375,268 | ---- | C] () -- C:\Users\Max\Documents\20121022_151537.jpg
[2012.10.22 23:05:52 | 003,307,656 | ---- | C] () -- C:\Users\Max\Documents\20121022_151523.jpg
[2012.10.22 23:05:10 | 002,728,989 | ---- | C] () -- C:\Users\Max\Documents\20121022_151618.jpg
[2012.10.22 23:04:11 | 003,267,684 | ---- | C] () -- C:\Users\Max\Documents\20121022_151634.jpg
[2012.10.22 23:03:06 | 003,799,515 | ---- | C] () -- C:\Users\Max\Documents\20121022_151702.jpg
[2011.11.10 19:45:57 | 001,420,616 | ---- | C] () -- C:\Users\Max\2011-11-10 19.25.22.jpg
[2011.11.10 19:45:38 | 001,638,144 | ---- | C] () -- C:\Users\Max\2011-11-10 19.26.16.jpg
[2011.11.10 19:45:22 | 001,443,464 | ---- | C] () -- C:\Users\Max\2011-11-10 19.26.30.jpg
[2011.11.10 19:45:03 | 001,601,281 | ---- | C] () -- C:\Users\Max\2011-11-10 19.35.52.jpg
[2011.11.10 19:44:42 | 001,647,716 | ---- | C] () -- C:\Users\Max\2011-11-10 19.37.26.jpg
[2011.11.10 19:44:25 | 001,505,606 | ---- | C] () -- C:\Users\Max\2011-11-10 19.40.03.jpg
[2011.11.10 19:44:09 | 001,392,730 | ---- | C] () -- C:\Users\Max\2011-11-10 19.37.00.jpg
[2011.11.10 19:43:52 | 001,430,322 | ---- | C] () -- C:\Users\Max\2011-11-10 19.38.21.jpg
[2011.11.10 19:43:32 | 001,545,600 | ---- | C] () -- C:\Users\Max\2011-11-10 19.39.40.jpg
[2011.11.10 19:43:15 | 001,503,448 | ---- | C] () -- C:\Users\Max\2011-11-10 19.40.32.jpg
[2011.10.23 20:24:27 | 001,390,133 | ---- | C] () -- C:\Users\Max\2011-10-23 19.54.31.jpg
[2011.07.01 20:56:42 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2011.05.15 19:02:15 | 000,000,002 | ---- | C] () -- C:\Windows\msoffice.ini
[2011.05.15 18:25:41 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.05.15 09:39:17 | 001,526,976 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\wbemess.dll
========== LOP Check ==========
[2012.02.15 16:00:04 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\.minecraft
[2012.11.18 19:38:57 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Asnya
[2012.11.19 20:12:43 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Ciowd
[2011.11.10 12:09:18 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\DAEMON Tools Lite
[2012.09.23 00:55:29 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\DVDVideoSoft
[2012.11.19 20:12:59 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Fygee
[2012.11.18 19:38:09 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Ibxyyr
[2011.11.12 19:09:41 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Ivacy
[2012.11.19 23:14:04 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Lioby
[2011.11.13 00:47:34 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\ManyCam
[2011.09.11 02:43:24 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\MOVAVI
[2012.11.19 20:12:43 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Osuhy
[2012.11.19 23:13:37 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Owysne
[2012.08.10 04:11:21 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\uTorrent
[2012.11.18 19:38:09 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Wiyvvo
[2012.11.19 23:13:37 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Xoux
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2012.08.12 02:16:19 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN
[2011.09.08 21:05:00 | 000,000,000 | ---D | M] -- C:\ac51d54726d99835f64d333096
[2012.01.24 11:11:06 | 000,000,000 | ---D | M] -- C:\Boot
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2011.05.14 23:28:37 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2012.01.26 03:01:02 | 000,000,000 | ---D | M] -- C:\Kaspersky Rescue Disk 10.0
[2012.01.24 12:13:32 | 000,000,000 | ---D | M] -- C:\old
[2009.07.14 04:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2012.09.10 16:13:19 | 000,000,000 | R--D | M] -- C:\Program Files
[2012.11.19 18:35:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)
[2012.11.18 23:48:43 | 000,000,000 | ---D | M] -- C:\ProgramData
[2011.05.14 23:28:37 | 000,000,000 | -HSD | M] -- C:\Programme
[2011.05.14 23:28:38 | 000,000,000 | ---D | M] -- C:\Recovery
[2012.11.20 21:38:41 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2012.08.11 20:24:32 | 000,000,000 | ---D | M] -- C:\TDSSKiller_Quarantine
[2012.11.18 03:05:23 | 000,000,000 | ---D | M] -- C:\Temp
[2012.11.18 03:07:24 | 000,000,000 | R--D | M] -- C:\Users
[2012.11.18 15:18:00 | 000,000,000 | ---D | M] -- C:\Windows
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2012.02.15 16:00:04 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\.minecraft
[2011.09.08 21:03:05 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Adobe
[2012.11.18 19:38:57 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Asnya
[2012.08.02 22:38:18 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Avira
[2012.11.19 20:12:43 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Ciowd
[2011.11.10 12:09:18 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\DAEMON Tools Lite
[2012.01.02 02:30:54 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\dvdcss
[2012.09.23 00:55:29 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\DVDVideoSoft
[2012.11.19 20:12:59 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Fygee
[2012.11.18 19:38:09 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Ibxyyr
[2011.05.14 23:28:58 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Identities
[2011.11.12 19:09:41 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Ivacy
[2012.11.19 23:14:04 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Lioby
[2011.09.08 21:03:06 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Macromedia
[2012.01.26 15:54:10 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Malwarebytes
[2011.11.13 00:47:34 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\ManyCam
[2009.07.14 19:18:18 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Media Center Programs
[2012.09.23 00:54:18 | 000,000,000 | --SD | M] -- C:\Users\Max\AppData\Roaming\Microsoft
[2011.09.11 02:43:24 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\MOVAVI
[2011.09.08 21:03:22 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Mozilla
[2011.09.11 02:43:26 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\NVIDIA
[2012.11.19 20:12:43 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Osuhy
[2012.11.19 23:13:37 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Owysne
[2012.10.02 20:42:31 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Skype
[2012.08.13 21:10:00 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\SUPERAntiSpyware.com
[2012.08.10 04:11:21 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\uTorrent
[2011.09.08 21:05:59 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\vlc
[2011.05.26 23:34:12 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\WinRAR
[2012.11.18 19:38:09 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Wiyvvo
[2012.11.19 23:13:37 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Xoux
< %APPDATA%\*.exe /s >
[2011.08.12 16:34:17 | 000,332,800 | ---- | M] (Compagnia ? quale Compagnia?) -- C:\Users\Max\AppData\Roaming\Osuhy\neve.exe
[2011.07.05 21:50:37 | 000,332,800 | ---- | M] (Compagnia ? quale Compagnia?) -- C:\Users\Max\AppData\Roaming\Owysne\voag.exe
[2011.11.05 20:11:16 | 000,332,800 | ---- | M] (Compagnia ? quale Compagnia?) -- C:\Users\Max\AppData\Roaming\Wiyvvo\iqzy.exe
< %SYSTEMROOT%\system32\drivers\*.sys /lockedfiles >
< %SYSTEMROOT%\System32\config\*.sav >
< %SYSTEMROOT%\*. /mp /s >
< %SYSTEMROOT%\system32\*.dll /lockedfiles >
< End of report > EDIT:
Extras.txt: Code:
OTL Extras logfile created on: 20.11.2012 21:36:48 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Max\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,14 Gb Available Physical Memory | 57,03% Memory free
4,00 Gb Paging File | 2,74 Gb Available in Paging File | 68,59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149,04 Gb Total Space | 29,23 Gb Free Space | 19,61% Space Free | Partition Type: NTFS
Drive D: | 74,50 Gb Total Space | 71,53 Gb Free Space | 96,00% Space Free | Partition Type: NTFS
Computer Name: MAX-PC | User Name: Max | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-3975674286-3007113892-2621660134-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0177D670-E4D9-4A7A-B870-EAC553575309}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{05DC2BF6-3723-40D4-9C4D-5DBD110F9B9D}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{0CE4F14A-BC99-4580-BACC-82318E301000}" = rport=137 | protocol=17 | dir=out | app=system |
"{181034E0-4BE3-49BE-AA2F-3163D6B8A651}" = rport=138 | protocol=17 | dir=out | app=system |
"{1B095E7D-C682-4AFD-9067-E77F958CDC44}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{1C976136-78BF-4ECE-8259-8E1B7160AB8A}" = lport=139 | protocol=6 | dir=in | app=system |
"{2D058946-38EF-4515-A028-8911F93E2F62}" = lport=2869 | protocol=6 | dir=in | app=system |
"{43467CDE-8F8F-480B-8EC6-22BAFEA4985B}" = lport=137 | protocol=17 | dir=in | app=system |
"{5349EA37-9515-4348-9050-1C4C5337C911}" = rport=445 | protocol=6 | dir=out | app=system |
"{5F8745CF-D48D-4F35-971C-589B6907E0A2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6491C8E1-B504-4735-B470-E80DFA928DA8}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{6E94BF30-7840-4AF3-8DEC-7FBC00C19C4B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{74B58830-9741-4B60-B40D-F0B3BF22FBF4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8629DAD6-3E8C-4DB2-8C50-41C7730F4EEF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A3173C1D-BA58-497D-940D-2BCAC49ABCCC}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{A4F42316-2B53-41F2-9597-4736A9BB8EF4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A51B2A82-446B-4191-A5D4-C6C06E421371}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B4F7EBA3-3FF9-4E44-89BE-C651EE14D991}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{B9D8AB71-69E9-4E18-A7BE-D1AB252A4BCC}" = lport=138 | protocol=17 | dir=in | app=system |
"{C46867F0-BFDB-4987-B355-4BBB10501C02}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E9A633DE-7ED5-413E-ADA0-030F75E8B2C7}" = rport=139 | protocol=6 | dir=out | app=system |
"{EF09DFDA-D6A6-49BF-9F59-89BA8B91A160}" = lport=445 | protocol=6 | dir=in | app=system |
"{F219B2FC-46BB-445D-9EAB-587AE787D7C2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{F34D3336-FC92-42AE-ADB6-7D09CC11120E}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{073B7B8B-020E-4FD1-918B-D5725E40E05D}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\topspeed\3.0\aoltpsd3.exe |
"{07B7B033-AB77-4BE2-8525-EF0CB03198A2}" = protocol=6 | dir=in | app=c:\users\max\downloads\setup-msgplus-501.exe |
"{0E910F8D-EACD-45D3-99CA-CB8DBBEC0E9B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\team fortress classic\hl.exe |
"{0EFD04A2-AB2D-4144-9E66-6CED9E24CEDE}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\1305480802\ee\aolsoftware.exe |
"{187B97F5-8B57-43A9-BE97-A5F4C582FF25}" = protocol=17 | dir=in | app=c:\program files (x86)\aol desktop 9.6\waol.exe |
"{1DA0A801-8DE5-4977-868E-322B53367CD9}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\acs\aolacsd.exe |
"{2169D3B2-F6AB-4844-90D9-7CE8C1FC96B4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{23130B23-D7F9-45B3-BB20-75BEAFD82109}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\acs\aolacsd.exe |
"{24D31768-3DA7-47AB-B7AF-3D4E655E1882}" = protocol=6 | dir=in | app=c:\program files (x86)\aol desktop 9.6\waol.exe |
"{2A3B1587-1F97-4BD2-99B9-7811C28C8CD1}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\topspeed\3.0\aoltpsd3.exe |
"{2B1C0897-2201-4C96-998E-A80F8A7E1A2D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforever.exe |
"{2C89A31E-FFD9-4B00-9871-D436462B4189}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\half-life\hl.exe |
"{2FC55DBD-4B33-476D-9017-87B1D1CBC000}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{2FFB1E25-A2DC-4280-A702-A182706CA9D6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{37B20030-47D9-460C-BA24-CCD0260D439E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\counter-strike\hl.exe |
"{3E8025DD-4CEE-4544-8E08-5352101306D5}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\system information\sinf.exe |
"{3F6A6C6A-A5F9-4896-953B-90837065C1DB}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{4457FCCE-A4D9-4407-8D57-A06B0DADFDBD}" = protocol=6 | dir=in | app=c:\program files (x86)\aol desktop 9.6\aolbrowser\aolbrowser.exe |
"{47BB0751-055F-40E7-A42A-F4A0EF06ECD0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5CB4A015-3FA8-41CE-B808-AA72860DA7AC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5F4E49D7-0FE9-434C-97B9-6A476451D3F7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\peggle extreme\peggleextreme.exe |
"{601C4F1B-5FB4-48B0-B24D-DF36863484D7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\half-life\hl.exe |
"{6523FAEB-7A50-4BF9-9227-51612F175677}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\moon base alpha\binaries\win32\moonbasealphagame.exe |
"{68AA2909-0A75-4531-BB0C-2CBFC3955336}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\1305480802\ee\aolsoftware.exe |
"{6AD00153-E7A8-467D-AF1C-66E2F9845F86}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforever.exe |
"{6BD401E7-ED98-4C9B-B588-ABB880E86446}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\team fortress classic\hl.exe |
"{90AF58B7-2DBD-48CE-ABE7-5DBC9F8B48E4}" = protocol=17 | dir=in | app=c:\program files (x86)\aol desktop 9.6\aolbrowser\aolbrowser.exe |
"{979F8844-E07D-4568-AAF3-9C8E1B735C32}" = protocol=17 | dir=in | app=c:\users\max\downloads\setup-msgplus-501.exe |
"{9BD64D6E-E536-4446-8202-4CBA2A7A4CCA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\half-life\hl.exe |
"{9E590996-1D6C-40AC-81BD-EBF823C66C92}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{A1280294-1BB8-4BBB-A918-BCE650E23E93}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{B1DA823C-6298-43DD-BCF0-53061D8D12BF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\day of defeat\hl.exe |
"{B361C90F-963C-4472-8D71-7741CAE3D38C}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\system information\sinf.exe |
"{B3B4A880-4DFF-499E-9A25-F25DFBB6BFCD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\peggle extreme\peggleextreme.exe |
"{B4C3E8AF-04AF-4933-8015-819DDD59C0FD}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{B7D978F5-71DC-43D4-BE45-9143E3A53F1A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\half-life\hl.exe |
"{BC207B56-91C4-479E-A94B-B43F440C3663}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
"{C26F3EF6-CAB1-4556-B224-65451CD0AFFE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\day of defeat\hl.exe |
"{C368BE99-E412-4ADC-8A3D-F43D41A03CD0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\counter-strike\hl.exe |
"{C4C4F6E2-615F-498F-B955-A2B025FC7836}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{C6ECB584-1149-4CF1-AA5C-87160E545F1C}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\acs\aoldial.exe |
"{C7F625FF-8556-4474-BCD5-FEE40F4E260C}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{CA1C27B7-1962-4F2B-8EB3-DC55EC3CA898}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{CC9B3F42-576D-438F-B63D-159EE92E4FAD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{CD9DE40F-95C0-4E5F-B49D-27557C9E1AE9}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{DB4DFADD-9CE2-4301-BF8B-1DC5A62DBE47}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\counter-strike\hl.exe |
"{E0DA42C7-F41F-4C14-9617-E37A251A2CD7}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\acs\aoldial.exe |
"{E511BE4A-A801-4B33-BE94-F00E83662127}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
"{EDCBD489-961A-4412-8C19-FEBD81ABB813}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\counter-strike\hl.exe |
"{F256AE38-4CC6-45DE-BCE0-0F4C4B16D0B8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\moon base alpha\binaries\win32\moonbasealphagame.exe |
"{FCEED16B-87FF-4CCB-A1CA-F1AFACC7828F}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{FDDBD0A5-F48C-4BB9-90B4-8A6309AC3B64}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"TCP Query User{181E4DDE-C6B7-40F3-8E9E-6875F8A2CC5F}C:\program files (x86)\steam\steamapps\cashaddi\half-life 2 deathmatch\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\half-life 2 deathmatch\hl2.exe |
"TCP Query User{1848F742-8B70-4F05-8667-6A569046646C}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"TCP Query User{218E7C6A-A342-414C-9B43-175B600E8F4A}C:\users\max\appdata\roaming\owysne\voag.exe" = protocol=6 | dir=in | app=c:\users\max\appdata\roaming\owysne\voag.exe |
"TCP Query User{22B563AA-B372-40DC-8659-7FA95DB8ECF5}C:\users\max\appdata\roaming\wiyvvo\iqzy.exe" = protocol=6 | dir=in | app=c:\users\max\appdata\roaming\wiyvvo\iqzy.exe |
"TCP Query User{593462F0-1DFA-440C-B55A-C8319ABCBF23}C:\windows\syswow64\java.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\java.exe |
"TCP Query User{7616EBA7-F3C1-48EB-A215-8220203F2A8B}C:\program files (x86)\steam\steamapps\cashaddi\half-life 2 deathmatch\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\half-life 2 deathmatch\hl2.exe |
"TCP Query User{7F4D0631-4843-4C15-8476-213F3EBBDD5C}C:\users\max\appdata\roaming\owysne\voag.exe" = protocol=6 | dir=in | app=c:\users\max\appdata\roaming\owysne\voag.exe |
"TCP Query User{8A3C2A82-0BA6-4451-9268-2D10FF798286}C:\users\max\appdata\roaming\wiyvvo\iqzy.exe" = protocol=6 | dir=in | app=c:\users\max\appdata\roaming\wiyvvo\iqzy.exe |
"TCP Query User{9A404F08-2CEE-445C-A378-678C2F763257}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |
"TCP Query User{9F6F20A4-2E7B-4174-838B-BC79BF040C12}C:\users\max\appdata\roaming\osuhy\neve.exe" = protocol=6 | dir=in | app=c:\users\max\appdata\roaming\osuhy\neve.exe |
"TCP Query User{A4219D3D-EACA-4490-BE3C-2C5F47879F16}C:\program files (x86)\steam\steamapps\cashaddi\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\team fortress 2\hl2.exe |
"TCP Query User{D9C7370E-7FB3-4458-96ED-2C80576D40C5}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{0862FF82-6D83-4B5D-8156-C953446DC14B}C:\users\max\appdata\roaming\wiyvvo\iqzy.exe" = protocol=17 | dir=in | app=c:\users\max\appdata\roaming\wiyvvo\iqzy.exe |
"UDP Query User{0B535A95-436C-412F-B9DA-04A0208C2420}C:\program files (x86)\steam\steamapps\cashaddi\half-life 2 deathmatch\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\half-life 2 deathmatch\hl2.exe |
"UDP Query User{2C990DF5-049A-4C94-B1F1-3AC365B512B1}C:\users\max\appdata\roaming\owysne\voag.exe" = protocol=17 | dir=in | app=c:\users\max\appdata\roaming\owysne\voag.exe |
"UDP Query User{4DCF87B2-5615-4B1C-95B9-8318B39155C8}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{5AE2CDE6-372C-4F0E-BD0D-F9AF29E6AD7C}C:\users\max\appdata\roaming\wiyvvo\iqzy.exe" = protocol=17 | dir=in | app=c:\users\max\appdata\roaming\wiyvvo\iqzy.exe |
"UDP Query User{67869E89-9642-444D-ABF0-766E6A46F9A5}C:\windows\syswow64\java.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\java.exe |
"UDP Query User{6D45A719-6E60-4FC8-9BDB-78F072D5B464}C:\users\max\appdata\roaming\owysne\voag.exe" = protocol=17 | dir=in | app=c:\users\max\appdata\roaming\owysne\voag.exe |
"UDP Query User{762B0221-788D-4BAF-B4C9-C2DA181BC296}C:\program files (x86)\steam\steamapps\cashaddi\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\team fortress 2\hl2.exe |
"UDP Query User{81F5D7C9-6A18-4562-A7BF-FD7D24220EAB}C:\program files (x86)\steam\steamapps\cashaddi\half-life 2 deathmatch\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\cashaddi\half-life 2 deathmatch\hl2.exe |
"UDP Query User{A0AF255C-EC18-4332-B847-1667055720FA}C:\users\max\appdata\roaming\osuhy\neve.exe" = protocol=17 | dir=in | app=c:\users\max\appdata\roaming\osuhy\neve.exe |
"UDP Query User{AFA3C7EE-6F00-4DCB-9CB5-421C39EB8751}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |
"UDP Query User{F26FF8F3-40AF-47E0-A3A3-3387EE1ADCB4}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86417003FF}" = Java(TM) 7 Update 3 (64-bit)
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.57.1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"Speccy" = Speccy
"WinRAR archiver" = WinRAR 4.00 (64-Bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B6A9773-F8F8-4D3F-BCF0-029D2B87DB8A}" = Deus Ex - Invisible War
"{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216035FF}" = Java(TM) 6 Update 35
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{39930321-4C58-4B8B-BCBF-342698C9801D}" = Max Payne
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69BCC264-0D43-469F-8434-31E738982E7B}" = Cisco AnyConnect Secure Mobility Client
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 4.2.0
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{95140000-00AF-0407-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{C0100D9E-2372-45E2-BDA5-BD18F9B03298}" = WNDA3100
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D2883AB6-09B4-4981-AAF8-E695411EEC9A}" = Sculptris Alpha 6
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2948988-2C6C-4070-BC8B-A1D77FE97D09}_is1" = Running with rifles Demo version 0.4
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EFE1AB94-5466-4B6E-BE31-FF4C115FD25D}" = Max Payne 2
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"CDisplay_is1" = CDisplay 1.8
"Cisco AnyConnect Secure Mobility Client" = Cisco AnyConnect Secure Mobility Client
"DAEMON Tools Lite" = DAEMON Tools Lite
"Deus Ex" = Deus Ex
"InstallShield_{C0100D9E-2372-45E2-BDA5-BD18F9B03298}" = NETGEAR RangeMax Duo Wireless-N USB Adapter WNDA3100
"InstallShield_{D2883AB6-09B4-4981-AAF8-E695411EEC9A}" = Sculptris Alpha 6
"IrfanView" = IrfanView (remove only)
"JFK Reloaded" = JFK Reloaded 1.1
"KainUninstallKey" = Legacy of Kain
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.1.1000
"ManyCam" = ManyCam 2.6.55 (remove only)
"Messenger Plus!" = Messenger Plus! 5
"Mozilla Firefox 16.0.2 (x86 de)" = Mozilla Firefox 16.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Octodad" = Octodad
"OpenAL" = OpenAL
"Secunia PSI" = Secunia PSI (2.0.0.4003)
"Steam App 10" = Counter-Strike
"Steam App 130" = Half-Life: Blue Shift
"Steam App 320" = Half-Life 2: Deathmatch
"Steam App 50" = Half-Life: Opposing Force
"Steam App 70" = Half-Life
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.11
"WinLiveSuite" = Windows Live Essentials
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 28.09.2012 11:56:14 | Computer Name = Max-PC | Source = acvpndownloader | ID = 67108866
Description =
Error - 28.09.2012 11:56:14 | Computer Name = Max-PC | Source = acvpndownloader | ID = 67108866
Description =
Error - 28.09.2012 11:57:40 | Computer Name = Max-PC | Source = acvpninstall | ID = 67108866
Description =
Error - 28.09.2012 11:57:40 | Computer Name = Max-PC | Source = acvpninstall | ID = 67108866
Description =
Error - 28.09.2012 11:57:40 | Computer Name = Max-PC | Source = acvpninstall | ID = 67108866
Description =
Error - 28.09.2012 11:57:40 | Computer Name = Max-PC | Source = acvpninstall | ID = 67108866
Description =
Error - 28.09.2012 11:57:40 | Computer Name = Max-PC | Source = acvpninstall | ID = 67108866
Description =
Error - 28.09.2012 11:57:40 | Computer Name = Max-PC | Source = acvpninstall | ID = 67108866
Description =
Error - 18.11.2012 14:54:29 | Computer Name = Max-PC | Source = Application Hang | ID = 1002
Description = Programm firefox.exe, Version 16.0.2.4680 kann nicht mehr unter Windows
ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: e58 Startzeit:
01cdc5a9061ccef1 Endzeit: 235 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Berichts-ID:
Error - 20.11.2012 09:50:24 | Computer Name = Max-PC | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Max\Downloads\esetsmartinstaller_enu.exe".
Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche
Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In
Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
[ Cisco AnyConnect Secure Mobility Client Events ]
Error - 20.11.2012 16:02:16 | Computer Name = Max-PC | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::applyHostConfigForNoVpn File: .\MainThread.cpp
Line:
9309 Invoked Function: CHostConfigMgr::DeterminePublicInterface Return Code: -28835824
(0xFE480010) Description: HOSTCONFIGMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE
Error - 20.11.2012 16:02:16 | Computer Name = Max-PC | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::genericNoticeCategoryHandler File: .\MainThread.cpp
Line:
6588 Invoked Function: CMainThread::applyHostConfigForNoVpn Return Code: -28835824
(0xFE480010) Description: HOSTCONFIGMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE
Error - 20.11.2012 16:02:16 | Computer Name = Max-PC | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::processNotice File: .\MainThread.cpp Line: 6201
Invoked
Function: CMainThread::genericNoticeCategoryHandler Return Code: -28835824 (0xFE480010)
Description:
HOSTCONFIGMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE
Error - 20.11.2012 16:02:16 | Computer Name = Max-PC | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::noticeHandler File: .\MainThread.cpp Line: 6151
Invoked
Function: CMainThread::processNotice Return Code: -28835824 (0xFE480010) Description:
HOSTCONFIGMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE
Error - 20.11.2012 16:02:16 | Computer Name = Max-PC | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::OnEventSignaled File: .\MainThread.cpp Line:
5923 Invoked Function: CMainThread::noticeHandler Return Code: -28835824 (0xFE480010)
Description:
HOSTCONFIGMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE
Error - 20.11.2012 16:02:21 | Computer Name = Max-PC | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::applyHostConfigForNoVpn File: .\MainThread.cpp
Line:
9309 Invoked Function: CHostConfigMgr::DeterminePublicInterface Return Code: -28835824
(0xFE480010) Description: HOSTCONFIGMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE
Error - 20.11.2012 16:02:21 | Computer Name = Max-PC | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::genericNoticeCategoryHandler File: .\MainThread.cpp
Line:
6588 Invoked Function: CMainThread::applyHostConfigForNoVpn Return Code: -28835824
(0xFE480010) Description: HOSTCONFIGMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE
Error - 20.11.2012 16:02:21 | Computer Name = Max-PC | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::processNotice File: .\MainThread.cpp Line: 6201
Invoked
Function: CMainThread::genericNoticeCategoryHandler Return Code: -28835824 (0xFE480010)
Description:
HOSTCONFIGMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE
Error - 20.11.2012 16:02:21 | Computer Name = Max-PC | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::noticeHandler File: .\MainThread.cpp Line: 6151
Invoked
Function: CMainThread::processNotice Return Code: -28835824 (0xFE480010) Description:
HOSTCONFIGMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE
Error - 20.11.2012 16:02:21 | Computer Name = Max-PC | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::OnEventSignaled File: .\MainThread.cpp Line:
5923 Invoked Function: CMainThread::noticeHandler Return Code: -28835824 (0xFE480010)
Description:
HOSTCONFIGMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE
[ Media Center Events ]
Error - 06.09.2011 15:38:40 | Computer Name = Max-PC | Source = Microsoft-Windows-Media Center Extender | ID = 301
Description =
Error - 06.09.2011 15:39:00 | Computer Name = Max-PC | Source = Microsoft-Windows-Media Center Extender | ID = 301
Description =
Error - 06.09.2011 15:39:13 | Computer Name = Max-PC | Source = Microsoft-Windows-Media Center Extender | ID = 301
Description =
[ System Events ]
Error - 15.09.2012 16:55:48 | Computer Name = Max-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?15.?09.?2012 um 22:53:44 unerwartet heruntergefahren.
Error - 15.09.2012 16:56:04 | Computer Name = MAX-PC | Source = BugCheck | ID = 1001
Description =
Error - 02.10.2012 15:59:41 | Computer Name = Max-PC | Source = NetBT | ID = 4321
Description = Der Name "WORKGROUP :1d" konnte nicht auf der Schnittstelle mit
IP-Adresse 192.168.0.107 registriert werden. Der Computer mit IP-Adresse 192.168.0.100
hat nicht zugelassen, dass dieser Computer diesen Namen verwendet.
Error - 10.10.2012 17:02:00 | Computer Name = Max-PC | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error - 10.10.2012 17:24:52 | Computer Name = Max-PC | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error - 19.10.2012 08:41:44 | Computer Name = Max-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597
(Definition 1.139.124.0)
Error - 28.10.2012 09:51:14 | Computer Name = Max-PC | Source = NetBT | ID = 4321
Description = Der Name "WORKGROUP :1d" konnte nicht auf der Schnittstelle mit
IP-Adresse 192.168.0.101 registriert werden. Der Computer mit IP-Adresse 192.168.0.100
hat nicht zugelassen, dass dieser Computer diesen Namen verwendet.
Error - 12.11.2012 09:00:03 | Computer Name = Max-PC | Source = NetBT | ID = 4321
Description = Der Name "WORKGROUP :1d" konnte nicht auf der Schnittstelle mit
IP-Adresse 192.168.1.126 registriert werden. Der Computer mit IP-Adresse 192.168.1.124
hat nicht zugelassen, dass dieser Computer diesen Namen verwendet.
Error - 12.11.2012 14:17:34 | Computer Name = Max-PC | Source = BTHUSB | ID = 327696
Description = Die beiderseitige Authentifizierung zwischen dem lokalen Bluetooth-Adapter
und einem Gerät mit Bluetooth-Adapteradresse (18:e2:c2:3f:ac:2f) ist fehlgeschlagen.
Error - 16.11.2012 22:33:20 | Computer Name = Max-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler
beendet: %%6704
< End of report > |