Vielen Dank schonmal für die Antwort also Malware habe ich schonmal komplett drüber laufen lassen habe dann auf entfernen gedrückt und der PC wurde neugestartet. Nun sind die Objekte in der Quarantäne zu sehen. Ich poste ebend die Log Dateien dann hole ich mir OTL und wende es an.
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Datenbank Version: v2013.01.15.13
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 7.0.6002.18005
Patrick :: B...... [Administrator]
15.01.2013 21:16:07
MBAM-log-2013-01-15 (22-38-57).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|H:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 428613
Laufzeit: 1 Stunde(n), 19 Minute(n), 45 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 4
HKCR\CLSID\{2A6F082F-6AB3-4FC3-B43C-CA2836BFDD56} (Malware.Packer.as) -> Keine Aktion durchgeführt.
HKCR\TypeLib\{4D69DA40-213B-44A2-AA73-3AA9E392958A} (Malware.Packer.as) -> Keine Aktion durchgeführt.
HKCR\Interface\{016C72F0-4481-4D8C-9189-8F7DDDCE560D} (Malware.Packer.as) -> Keine Aktion durchgeführt.
HKCR\ASkin.mySkin (Malware.Packer.as) -> Keine Aktion durchgeführt.
Infizierte Registrierungswerte: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\WINDOWS\SYSTEM32\ASKIN.OCX (Malware.Packer.as) -> Daten: 1 -> Keine Aktion durchgeführt.
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 3
C:\Users\Patrick\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\1ede2ede-73317a7d (Trojan.Reveton) -> Keine Aktion durchgeführt.
C:\Windows\System32\ASkin.ocx (Malware.Packer.as) -> Keine Aktion durchgeführt.
C:\ProgramData\dsgsdgdsgdsgw.pad (Exploit.Drop.GSA) -> Keine Aktion durchgeführt.
(Ende)
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Datenbank Version: 4159
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
31.05.2010 22:17:36
mbam-log-2010-05-31 (22-17-36).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|G:\|H:\|)
Durchsuchte Objekte: 307140
Laufzeit: 52 Minute(n), 22 Sekunde(n)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 5
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 3
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijacker) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\M5T8QL3YW3 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows update service (Backdoor.IRCBot) -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
C:\Users\Patrick\AppData\Local\Temp\Qc2.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Public\winnvscr.exe (Backdoor.IRCBot) -> Delete on reboot.
Nun noch die Log Files OTL und Extras:OTL Logfile: Code:
OTL logfile created on: 15.01.2013 22:54:02 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Patrick\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 0,96 Gb Available Physical Memory | 47,82% Memory free
4,24 Gb Paging File | 2,86 Gb Available in Paging File | 67,32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 39,06 Gb Total Space | 0,80 Gb Free Space | 2,05% Space Free | Partition Type: NTFS
Drive D: | 61,50 Gb Total Space | 39,18 Gb Free Space | 63,71% Space Free | Partition Type: NTFS
Drive E: | 117,19 Gb Total Space | 79,88 Gb Free Space | 68,16% Space Free | Partition Type: NTFS
Drive H: | 15,14 Gb Total Space | 4,72 Gb Free Space | 31,19% Space Free | Partition Type: NTFS
Computer Name: BATMAN | User Name: Patrick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Patrick\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - E:\Counterstrie Source\Steam.exe (Valve Corporation)
PRC - C:\Programme\Garena Plus\GarenaMessenger.exe ()
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe (EIZO NANAO CORPORATION)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\EIZO\ScreenSlicer\ESCSlicer.exe (EIZO NANAO CORPORATION)
PRC - C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
PRC - C:\Programme\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Programme\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Programme\Logitech\LWS\LU\LogitechUpdate.exe (Logitech, Inc.)
PRC - C:\Programme\Logitech\LWS\LU\LULnchr.exe (Logitech, Inc.)
PRC - C:\Programme\GMX\GMX MultiMessenger\MESSENGR.EXE (GMX GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\Common Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
PRC - C:\Programme\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Programme\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f042f66c2ad8fd5b8c34fa22cd22079e\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b5df40c22ab563a816103629e2ca99d4\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\76c7188792164691232626c0fc9ae579\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\004bc6615f9c06df5c98859d35149fe6\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0c3da9004b277959e24a9fd606d3dd05\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\78157a494dc9a7e52be8840decfcd9cc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll ()
MOD - E:\Counterstrie Source\sdl.dll ()
MOD - E:\Counterstrie Source\bin\libcef.dll ()
MOD - E:\Counterstrie Source\bin\chromehtml.dll ()
MOD - E:\Counterstrie Source\bin\avcodec-53.dll ()
MOD - E:\Counterstrie Source\bin\avformat-53.dll ()
MOD - E:\Counterstrie Source\bin\avutil-51.dll ()
MOD - C:\Programme\Garena Plus\GarenaMessenger.exe ()
MOD - C:\Programme\Garena Plus\VersionModule.dll ()
MOD - C:\Programme\Garena Plus\Plugins\ggplugin.dll ()
MOD - C:\Programme\Garena Plus\lib\XLL.dll ()
MOD - C:\Programme\Garena Plus\Plugins\PluginNews.dll ()
MOD - C:\Programme\Garena Plus\Plugins\GarenaTalkPlugin.dll ()
MOD - C:\Programme\Garena Plus\ggspawn.dll ()
MOD - C:\Programme\Garena Plus\Plugins\StatsPlugin.dll ()
MOD - C:\Programme\Garena Plus\Plugins\PlatformPlugin.dll ()
MOD - C:\Programme\Garena Plus\lib\Http.dll ()
MOD - C:\Programme\Garena Plus\PluginModule.dll ()
MOD - C:\Programme\Garena Plus\CxImage.dll ()
MOD - C:\Programme\Garena Plus\lib\UILayout.dll ()
MOD - C:\Programme\Garena Plus\lib\XmlUIModule.dll ()
MOD - C:\Programme\Garena Plus\ggdownloader.dll ()
MOD - C:\Programme\Garena Plus\lib\delay_load\GaFileTransfer.dll ()
MOD - C:\Programme\Garena Plus\FileLoader.dll ()
MOD - C:\Programme\Garena Plus\PluginKernel.dll ()
MOD - C:\Programme\Garena Plus\lib\delay_load\ClientTcp.dll ()
MOD - C:\Programme\Garena Plus\lib\delay_load\UdtLib.dll ()
MOD - C:\Programme\Garena Plus\lib\fs\YYFileSystem.dll ()
MOD - C:\Programme\Garena Plus\DibModule.dll ()
MOD - C:\Programme\Garena Plus\ImageModule.dll ()
MOD - C:\Programme\Garena Plus\lib\delay_load\MediaEngine.dll ()
MOD - C:\Programme\Garena Plus\lib\delay_load\AudioMixerLib.dll ()
MOD - C:\Programme\Garena Plus\ServerMemAlloc.dll ()
MOD - C:\Programme\Garena Plus\lib\delay_load\RSALib.dll ()
MOD - C:\Programme\Garena Plus\lame_enc.dll ()
MOD - C:\Programme\Garena Plus\sqlite3.dll ()
MOD - C:\Programme\Garena Plus\lib\TaskManagerLib.dll ()
MOD - C:\Programme\Garena Plus\lib\MP3Module.dll ()
MOD - C:\Programme\Garena Plus\ggcode.dll ()
MOD - C:\Programme\Garena Plus\CommonLib.dll ()
MOD - C:\Programme\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll ()
MOD - C:\Programme\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll ()
MOD - C:\Programme\Logitech\LWS\Webcam Software\QTXml4.dll ()
MOD - C:\Programme\Logitech\LWS\Webcam Software\QTGui4.dll ()
MOD - C:\Programme\Logitech\LWS\Webcam Software\QTCore4.dll ()
MOD - C:\Programme\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Programme\Notepad++\NppShell_04.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Programme\WinRAR\RarExt.dll ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (ICQ Service) -- C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
SRV - (odserv) -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (UMVPFSrv) -- C:\Programme\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (Microsoft Office Groove Audit Service) -- C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (USBModem) -- system32\DRIVERS\lgusbmodem.sys File not found
DRV - (UsbDiag) -- system32\DRIVERS\lgusbdiag.sys File not found
DRV - (usbbus) -- system32\DRIVERS\lgusbbus.sys File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (GGSAFERDriver) -- C:\Program Files\Garena Plus\Room\safedrv.sys File not found
DRV - (GarenaPEngine) -- C:\Users\Patrick\AppData\Local\Temp\KPU1CBA.tmp File not found
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (LVUVC) -- C:\Windows\System32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) -- C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (gdrv) -- C:\Windows\gdrv.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (s816mdm) -- C:\Windows\System32\drivers\s816mdm.sys (MCCI Corporation)
DRV - (s816mgmt) -- C:\Windows\System32\drivers\s816mgmt.sys (MCCI Corporation)
DRV - (s816unic) -- C:\Windows\System32\drivers\s816unic.sys (MCCI)
DRV - (s816obex) -- C:\Windows\System32\drivers\s816obex.sys (MCCI Corporation)
DRV - (s816nd5) -- C:\Windows\System32\drivers\s816nd5.sys (MCCI Corporation)
DRV - (s816mdfl) -- C:\Windows\System32\drivers\s816mdfl.sys (MCCI Corporation)
DRV - (s816bus) -- C:\Windows\System32\drivers\s816bus.sys (MCCI Corporation)
DRV - (LUsbFilt) -- C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (ET5Drv) -- C:\Windows\System32\drivers\ET5Drv.sys ()
DRV - (JRAID) -- C:\Windows\System32\drivers\jraid.sys (JMicron Technology Corp.)
DRV - (SysTool) -- C:\Windows\System32\drivers\SysTool.sys ()
DRV - (sfvfs02) -- C:\Windows\System32\drivers\sfvfs02.sys (Protection Technology (StarForce))
DRV - (sfdrv01) -- C:\Windows\System32\drivers\sfdrv01.sys (Protection Technology (StarForce))
DRV - (sfhlp02) -- C:\Windows\System32\drivers\sfhlp02.sys (Protection Technology (StarForce))
DRV - (JGOGO) -- C:\Windows\System32\drivers\JGOGO.sys (JMicron )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = ICQ.com Suche
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\..\SearchScopes,DefaultScope = {6552C7DD-90A4-4387-B795-F8F96747DE19}
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SUNA_de
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\..\SearchScopes\{BE9654C9-9D79-42ec-B55A-3CAEB12DBF58}: "URL" = hxxp://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://web.de/"
FF - prefs.js..extensions.enabledAddons: DivXWebPlayer%40divx.com:2.0.2.039
FF - prefs.js..extensions.enabledAddons: moveplayer%40movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q="
FF - prefs.js..network.proxy.type: 4
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=sm&tb_ver=1.3.3&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Patrick\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.01.11 12:37:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.01.11 12:37:11 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 18.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.01.11 12:37:42 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 18.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.01.11 12:37:11 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{d591241b-9967-418c-9b7d-ee128131d60d}: C:\Program Files\GMX\GMX MultiMessenger\ThunderbirdSyncProxy [2009.06.28 14:39:21 | 000,000,000 | ---D | M]
[2008.09.06 18:20:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Patrick\AppData\Roaming\mozilla\Extensions
[2013.01.07 19:11:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\7y1omo7k.default\extensions
[2012.10.11 17:45:51 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\7y1omo7k.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012.07.25 18:12:23 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\7y1omo7k.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.10.28 21:17:54 | 000,000,000 | ---D | M] (PriceGong) -- C:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\7y1omo7k.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
[2009.03.25 20:53:59 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\7y1omo7k.default\extensions\moveplayer@movenetworks.com
[2012.08.22 17:29:20 | 000,101,863 | ---- | M] () (No name found) -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\extensions\ciuvo-extension@icq.de.xpi
[2012.02.09 21:43:54 | 000,550,833 | ---- | M] () (No name found) -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\extensions\DivXWebPlayer@divx.com.xpi
[2012.02.04 17:49:16 | 000,020,591 | ---- | M] () (No name found) -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2012.11.20 18:14:44 | 000,243,496 | ---- | M] () (No name found) -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2013.01.07 19:11:40 | 000,190,000 | ---- | M] () (No name found) -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
[2013.01.13 18:12:27 | 000,000,950 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-1.xml
[2011.10.01 18:39:43 | 000,000,950 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-10.xml
[2011.10.16 19:03:57 | 000,000,950 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-11.xml
[2011.11.11 18:59:00 | 000,000,950 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-12.xml
[2008.02.08 20:07:07 | 000,000,949 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-2.xml
[2009.03.24 19:25:32 | 000,000,950 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-3.xml
[2011.05.03 17:04:57 | 000,000,950 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-4.xml
[2011.06.24 23:47:35 | 000,000,950 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-5.xml
[2011.07.09 19:52:02 | 000,000,950 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-6.xml
[2011.08.21 12:05:07 | 000,000,950 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-7.xml
[2011.09.01 17:24:13 | 000,000,950 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-8.xml
[2011.09.01 17:28:42 | 000,000,950 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin-9.xml
[2011.03.30 13:14:34 | 000,001,042 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\icqplugin.xml
[2008.01.03 22:28:17 | 000,000,274 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\search.xml
[2011.11.06 20:19:33 | 000,003,915 | ---- | M] () -- C:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\7y1omo7k.default\searchplugins\sweetim.xml
[2013.01.11 12:37:07 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.01.11 12:37:07 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2013.01.11 12:37:41 | 000,262,704 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.01 18:39:05 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.31 16:50:20 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.01 18:39:05 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.01 18:39:05 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.01 18:39:05 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.01 18:39:05 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2008.02.23 19:37:29 | 000,226,662 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 ²©²Êͨ,²©²ÊÍø,½ð±¦²©188,²©²ÊͨÆÀ¼¶,°Ù¼ÒÀÖ,°ÂÃî°Ù¼ÒÀÖ
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com - Informationen zum Thema Sex links. Diese Website steht zum Verkauf!
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 7953 more lines...
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Programme\PriceGong\2.5.1\PriceGongIE.dll (PriceGong)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000\..\Toolbar\WebBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O4 - HKLM..\Run: [ATICCC] C:\Programme\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\JM\JMInsIDE.exe ()
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [Launch LGDCore] C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ScreenManager Pro for LCD (DDCCI)] C:\Programme\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe (EIZO NANAO CORPORATION)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000..\Run: [Facebook Update] C:\Users\Patrick\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000..\Run: [GarenaPlus] C:\Program Files\Garena Plus\GarenaMessenger.exe ()
O4 - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000..\Run: [GMX_GMX MultiMessenger] C:\Program Files\GMX\GMX MultiMessenger\MESSENGR.EXE (GMX GmbH)
O4 - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000..\Run: [Steam] E:\Counterstrie Source\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-2481620165-4217138233-3408023960-1000..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Web-Suche - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Programme\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Programme\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 10.7.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F0B8C6C-6AD3-443B-ABCC-AB9E0FB5ECB4}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{6f748bd0-1e0e-11df-a73d-001a4d7389d7}\Shell - "" = AutoRun
O33 - MountPoints2\{6f748bd0-1e0e-11df-a73d-001a4d7389d7}\Shell\AutoRun\command - "" = F:\USBAutoRun.exe
O33 - MountPoints2\{c4a49500-5ad2-11df-8aad-001a4d7389d7}\Shell - "" = AutoRun
O33 - MountPoints2\{c4a49500-5ad2-11df-8aad-001a4d7389d7}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.01.15 22:51:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Patrick\Desktop\OTL.exe
[2013.01.15 21:12:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.01.15 21:12:16 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.01.15 21:12:16 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.01.15 21:09:35 | 010,156,344 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Patrick\mbam-setup-1.70.0.1100.exe
[2013.01.12 15:22:46 | 029,671,038 | ---- | C] (Bytro Labs) -- C:\Users\Patrick\S1914JavaInstaller.exe
[2013.01.11 12:37:05 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.01.10 18:04:11 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.01.09 22:34:50 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Roaming\EIZO
[2013.01.09 22:34:22 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\Downloaded Installations
[2013.01.09 22:30:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EIZO
[2013.01.09 22:30:58 | 000,000,000 | ---D | C] -- C:\ProgramData\EIZO
[2013.01.09 22:30:58 | 000,000,000 | ---D | C] -- C:\Program Files\EIZO
[2013.01.09 19:07:26 | 002,048,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013.01.09 19:07:00 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2012.12.26 18:46:22 | 000,293,376 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2012.12.26 18:46:22 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2007.12.18 17:12:39 | 001,236,992 | ---- | C] (CPUID) -- C:\Program Files\cpuz.exe
========== Files - Modified Within 30 Days ==========
[2013.01.15 22:51:42 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Patrick\Desktop\OTL.exe
[2013.01.15 22:43:34 | 000,004,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.01.15 22:43:34 | 000,004,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.01.15 22:43:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.01.15 22:30:40 | 000,001,646 | ---- | M] () -- C:\Users\Patrick\Documents\T4EPlayer.conf
[2013.01.15 22:10:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.01.15 22:03:25 | 000,001,146 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2481620165-4217138233-3408023960-1000UA.job
[2013.01.15 21:12:18 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.01.15 21:09:50 | 010,156,344 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Patrick\mbam-setup-1.70.0.1100.exe
[2013.01.15 19:51:17 | 000,000,422 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{7FCA0E7B-7529-4C72-8CAE-62BBD24A8E7F}.job
[2013.01.15 19:03:01 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2481620165-4217138233-3408023960-1000Core.job
[2013.01.14 12:04:46 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.01.14 12:04:46 | 000,596,036 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.01.14 12:04:46 | 000,126,292 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.01.14 12:04:46 | 000,104,110 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.01.12 15:23:12 | 029,671,038 | ---- | M] (Bytro Labs) -- C:\Users\Patrick\S1914JavaInstaller.exe
[2013.01.11 11:45:13 | 000,381,608 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.01.09 22:34:46 | 000,001,948 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\EIZO ScreenSlicer.lnk
[2013.01.09 19:10:26 | 000,697,864 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013.01.09 19:10:26 | 000,074,248 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013.01.06 13:01:42 | 008,625,029 | ---- | M] () -- C:\Users\Patrick\Desktop\PaJo und Co.mp4
[2012.12.21 23:56:16 | 000,001,356 | ---- | M] () -- C:\Users\Patrick\AppData\Local\d3d9caps.dat
========== Files Created - No Company Name ==========
[2013.01.15 21:12:18 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.01.09 22:34:46 | 000,001,948 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\EIZO ScreenSlicer.lnk
[2013.01.06 13:01:40 | 008,625,029 | ---- | C] () -- C:\Users\Patrick\Desktop\PaJo und Co.mp4
[2012.12.06 20:29:04 | 000,127,242 | ---- | C] () -- C:\Users\Patrick\hfo-tyrrellp34-2.jpg
[2012.12.06 20:14:04 | 000,043,452 | ---- | C] () -- C:\Users\Patrick\1978-05-stewart-mc.jpg
[2012.12.06 20:12:10 | 000,054,752 | ---- | C] () -- C:\Users\Patrick\patrick1977ah7.jpg
[2012.12.06 20:04:29 | 000,487,625 | ---- | C] () -- C:\Users\Patrick\Tyrrell-P34_mp906_pic_59618.jpg
[2012.12.01 15:40:09 | 000,738,986 | ---- | C] () -- C:\Users\Patrick\image_1354372471445482.jpg
[2012.08.27 16:43:04 | 000,381,608 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.07.13 20:45:08 | 000,045,194 | ---- | C] () -- C:\Users\Patrick\AppData\Roaming\room_v3.dat
[2011.05.26 05:05:00 | 010,879,000 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll
[2011.05.26 05:05:00 | 000,333,336 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll
[2011.05.26 05:05:00 | 000,104,472 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe
[2011.05.26 04:56:28 | 000,027,872 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2011.03.22 22:58:22 | 000,014,168 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
[2011.03.22 17:09:29 | 000,046,658 | ---- | C] () -- C:\Users\Patrick\AppData\Roaming\room.dat
[2011.03.13 18:58:38 | 000,456,704 | ---- | C] () -- C:\Program Files\NuclearReactor_1_2.exe
[2010.05.26 16:37:48 | 000,000,000 | ---- | C] () -- C:\Users\Patrick\AppData\Roaming\chrtmp
[2009.01.16 21:25:02 | 000,022,328 | ---- | C] () -- C:\Users\Patrick\AppData\Roaming\PnkBstrK.sys
[2007.12.22 15:46:38 | 000,000,552 | ---- | C] () -- C:\Users\Patrick\AppData\Local\d3d8caps.dat
[2007.12.18 18:14:07 | 000,011,610 | ---- | C] () -- C:\Program Files\manual.html
[2007.12.18 17:58:50 | 000,185,856 | ---- | C] () -- C:\Program Files\Core Temp.exe
[2007.12.18 17:06:36 | 000,024,576 | ---- | C] () -- C:\Program Files\memtest.exe
[2007.10.11 14:48:32 | 000,052,736 | ---- | C] () -- C:\Users\Patrick\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.08.28 17:49:39 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2007.08.26 13:01:54 | 000,001,356 | ---- | C] () -- C:\Users\Patrick\AppData\Local\d3d9caps.dat
========== ZeroAccess Check ==========
[2006.11.02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:AA6DEB48
< End of report > --- --- ---
OTL Logfile: Code:
OTL Extras logfile created on: 15.01.2013 22:54:02 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Patrick\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 0,96 Gb Available Physical Memory | 47,82% Memory free
4,24 Gb Paging File | 2,86 Gb Available in Paging File | 67,32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 39,06 Gb Total Space | 0,80 Gb Free Space | 2,05% Space Free | Partition Type: NTFS
Drive D: | 61,50 Gb Total Space | 39,18 Gb Free Space | 63,71% Space Free | Partition Type: NTFS
Drive E: | 117,19 Gb Total Space | 79,88 Gb Free Space | 68,16% Space Free | Partition Type: NTFS
Drive H: | 15,14 Gb Total Space | 4,72 Gb Free Space | 31,19% Space Free | Partition Type: NTFS
Computer Name: BATMAN | User Name: Patrick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_USERS\S-1-5-21-2481620165-4217138233-3408023960-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 1
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{270E50D1-D1E0-4AE2-B915-03A0281ABFA4}" = rport=10243 | protocol=6 | dir=out | app=system |
"{3C5FC4EC-CC1E-4D2B-8E5B-4862302E3251}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{43AFC735-DD21-4B4B-A8EE-481B807D57CC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{49D71223-E8BB-4D06-94FB-A7B6E649F564}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4F78553D-BF02-439D-9B38-D2C346BAFE8C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5336DD28-9030-48E4-94E4-E92994A3B285}" = lport=10243 | protocol=6 | dir=in | app=system |
"{82334AA9-0156-425F-8632-4FC7E1601E8C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{874BCBF4-44DA-4E61-B4F6-BFE2447A3EDB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{87CFA695-B81C-46B4-B3FB-54A3E19B2D00}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D3E324E5-E3F2-4A39-BA0A-271E48A8EA0E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EC4B26F3-9135-4787-9406-6B6E2BABC2DB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FC7D8731-62D9-4A0B-B6E0-AA223B7B9AB1}" = lport=2869 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00BF4CBA-46CE-462F-9509-57423C2533CA}" = protocol=6 | dir=in | app=e:\counterstrie source\steamapps\common\trackmania nations forever\tmforever.exe |
"{02BD9D99-8958-4265-AE1B-A07B758D8251}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{05AF7572-2AE3-4E18-BDC7-86479BAF72E5}" = protocol=6 | dir=in | app=c:\program files\icq7.6\icq.exe |
"{070AEAF2-1960-4BF4-A079-99CAFC50DC3C}" = protocol=17 | dir=in | app=e:\cod 4\iw3mp.exe |
"{10727D0C-5C5C-420B-B0FC-E69DDDF66EF3}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{1A39F617-0276-46B5-A1CD-8498D7DF2FE9}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{21EFCD1A-2E1F-40DB-ABB3-8F641D84AA5C}" = protocol=17 | dir=in | app=e:\counterstrie source\steamapps\pocca_1\counter-strike source\hl2.exe |
"{2822F5CA-C5BF-4358-AE43-BDCBB5129C2D}" = protocol=17 | dir=in | app=c:\program files\icq7.6\icq.exe |
"{293DA4D9-5197-42BE-AC74-0EA6E4FE8D87}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{2FDF4F15-D317-49B7-8761-0120FF5877FB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{30EAD7FC-E0EA-482F-9308-A3BAE7FDF123}" = dir=in | app=c:\users\patrick\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{430D6F6D-DD98-4C3A-98E2-63D5E73FDE5A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4418EF39-C1AA-448A-ABB7-9EDD555A02D1}" = protocol=6 | dir=in | app=c:\program files\icq7.6\icq.exe |
"{46F2DE00-377D-461C-82D9-7B3C548C5A2B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{4D0E9EDD-1877-43F8-81BD-23D93A71B054}" = protocol=17 | dir=in | app=c:\program files\icq7.6\icq.exe |
"{4D12269B-E8EB-4F07-9653-1F2355747121}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4DD63C63-700F-4F65-9EF7-B419971B1A2D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{51AC071E-909E-46D9-96A6-54930033B5A4}" = protocol=6 | dir=in | app=e:\counterstrie source\steamapps\pocca_1\counter-strike source\hl2.exe |
"{604BB95E-EBBA-43E6-BA88-A38FE5B8AC0E}" = protocol=6 | dir=in | app=c:\program files\icq7.6\icq.exe |
"{60D023C7-6E84-40ED-B234-93DF8B242075}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{671D12F8-3557-48C0-A223-3C14A2E8F35B}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{67B3EF0E-F06B-4A75-ACA7-666ED3CD2B69}" = protocol=6 | dir=in | app=e:\counterstrie source\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
"{71A34B90-0D9B-44A9-8F68-42164602A928}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{71EA9AC1-DB48-42DF-8127-6A97101130CE}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{751F07FD-A952-4047-8FC9-3C08A1BFA1B8}" = protocol=17 | dir=in | app=e:\counterstrie source\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
"{7A25E0D7-A789-4A7F-A6DA-308A6AF2B28B}" = protocol=6 | dir=out | app=system |
"{8788B39D-64E6-467C-A614-1C8596CF3D58}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8ADABA73-3B24-4993-B9FA-96866700F4B5}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{93913AF9-ED88-45B0-837C-D11ACC6776C0}" = protocol=17 | dir=in | app=c:\program files\icq7.6\icq.exe |
"{93C911BF-3BC4-4195-8282-C0ED8DF7CE40}" = protocol=6 | dir=in | app=e:\cod 4\iw3mp.exe |
"{9B34D632-B64A-4D5B-8200-F2358CA4D8AD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B911C285-6895-4C6A-8E3D-B06055234E25}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BFCABA16-1D24-43C3-A9EB-585CFAE266D7}" = protocol=17 | dir=in | app=e:\counterstrie source\steamapps\common\trackmania nations forever\tmforever.exe |
"{C463D96D-BB4C-47A6-9564-3DD19E2A08E5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CE0CA976-31D6-4080-B97D-A7734D432A06}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{E587B880-466E-40F5-9B7F-ADA43BA8F272}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{FB01D9C1-0DC6-4DC0-91B0-7E4F3762A5AB}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{FDC5E372-8F13-468C-AA06-81846AD8D632}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"TCP Query User{01473DC5-30FC-4847-B957-2BD05DAAA1FC}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{0B2638EA-2941-43A7-ACA9-C5F5AD6B207B}C:\windows\system32\dpnsvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dpnsvr.exe |
"TCP Query User{1DD354B7-FABE-4037-B17D-205C24232FFB}E:\cod 4\iw3mp.exe" = protocol=6 | dir=in | app=e:\cod 4\iw3mp.exe |
"TCP Query User{21EBA13E-14F7-40DB-A252-F049AE8C69AC}E:\valve\hltv.exe" = protocol=6 | dir=in | app=e:\valve\hltv.exe |
"TCP Query User{2EF5569D-CBEE-41B1-9954-4136276BFA7E}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{502A847D-09C0-463E-845D-F4A0B6B667E6}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{5BE534C4-FD4E-4162-BB9C-C762B9469AE4}E:\trackmania nations eswc\tmnationseswc.exe" = protocol=6 | dir=in | app=e:\trackmania nations eswc\tmnationseswc.exe |
"TCP Query User{62DD6B4B-6E89-4375-9739-1361E51E7685}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{674FFCE0-CC56-431F-B3E2-707493862078}E:\ea sports\f1_2002.exe" = protocol=6 | dir=in | app=e:\ea sports\f1_2002.exe |
"TCP Query User{8AEAB55B-06FC-44FB-8566-CC65EBDD2F45}E:\aoe2\age of empires 2\aoe 2\age of empires 2 & the conquerors\age2_x1.exe" = protocol=6 | dir=in | app=e:\aoe2\age of empires 2\aoe 2\age of empires 2 & the conquerors\age2_x1.exe |
"TCP Query User{AB8D3D94-37D1-4BB4-B419-439B6229EA03}\\dell-jonas\shareddocs\warcraft iii\war3.exe" = protocol=6 | dir=in | app=\\dell-jonas\shareddocs\warcraft iii\war3.exe |
"TCP Query User{AB97B901-D28B-4A77-A5FA-F7E1C505CA1F}E:\counterstrie source\steam.exe" = protocol=6 | dir=in | app=e:\counterstrie source\steam.exe |
"TCP Query User{C070CA64-A150-4719-8B62-6F3F4A4AC091}C:\program files\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
"TCP Query User{C0817D6F-9873-4E9C-83B2-BC5408BAD3B3}C:\program files\garena plus\room\garena_room.exe" = protocol=6 | dir=in | app=c:\program files\garena plus\room\garena_room.exe |
"TCP Query User{C153F5F1-4E51-4402-8B2E-DFC3FC907CFA}C:\program files\atube catcher\yct.exe" = protocol=6 | dir=in | app=c:\program files\atube catcher\yct.exe |
"TCP Query User{CFC802B7-3AF7-4987-AAAD-28AF6FD2AFFF}E:\warcraft iii\war3.exe" = protocol=6 | dir=in | app=e:\warcraft iii\war3.exe |
"TCP Query User{D0C027C1-E105-432F-81C3-53B35FA1AD89}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{FE84A943-8BBD-46E6-BE50-FB611C3D249B}C:\program files\gmx\gmx multimessenger\messengr.exe" = protocol=6 | dir=in | app=c:\program files\gmx\gmx multimessenger\messengr.exe |
"UDP Query User{1AB20EBD-D5D4-4F89-94E3-F7C914C6E8F9}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{1B210D9F-9E6A-42DD-B503-4B2E813501FC}E:\aoe2\age of empires 2\aoe 2\age of empires 2 & the conquerors\age2_x1.exe" = protocol=17 | dir=in | app=e:\aoe2\age of empires 2\aoe 2\age of empires 2 & the conquerors\age2_x1.exe |
"UDP Query User{2553D53E-A2B7-4321-A5F6-3EEF57D3F793}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{2707F88A-4CB7-4A66-ACB7-4543035A75C2}E:\ea sports\f1_2002.exe" = protocol=17 | dir=in | app=e:\ea sports\f1_2002.exe |
"UDP Query User{737C6A46-16C6-45FB-8355-80248A22DF97}C:\program files\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
"UDP Query User{8494790C-9D0E-4D83-B2DE-BB4527DABF8D}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{9975A198-DA75-43D8-87CA-DE48052C2315}C:\program files\atube catcher\yct.exe" = protocol=17 | dir=in | app=c:\program files\atube catcher\yct.exe |
"UDP Query User{A0952335-947C-4DA4-8BE4-5455FB8D0934}E:\counterstrie source\steam.exe" = protocol=17 | dir=in | app=e:\counterstrie source\steam.exe |
"UDP Query User{A7E12347-1659-46FA-8A39-5329EAB42B11}E:\trackmania nations eswc\tmnationseswc.exe" = protocol=17 | dir=in | app=e:\trackmania nations eswc\tmnationseswc.exe |
"UDP Query User{AAE01D9E-2985-40AB-9CD1-439EE8912BAA}E:\warcraft iii\war3.exe" = protocol=17 | dir=in | app=e:\warcraft iii\war3.exe |
"UDP Query User{C1D69E60-59C3-4F57-97B8-06E33C780206}C:\program files\garena plus\room\garena_room.exe" = protocol=17 | dir=in | app=c:\program files\garena plus\room\garena_room.exe |
"UDP Query User{C5AF4F83-9C61-410A-AF73-EBBEF633F3C5}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{CEBE2EE5-1678-4045-9120-EA88ED95D915}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{D3FB1609-B758-484A-A8BB-AC4DC70DB4B8}\\dell-jonas\shareddocs\warcraft iii\war3.exe" = protocol=17 | dir=in | app=\\dell-jonas\shareddocs\warcraft iii\war3.exe |
"UDP Query User{EF4A192D-1CC1-4842-952B-A42CD4B1F3EC}E:\cod 4\iw3mp.exe" = protocol=17 | dir=in | app=e:\cod 4\iw3mp.exe |
"UDP Query User{F7907AA0-7033-4FD3-83F9-360E3E666BEE}C:\program files\gmx\gmx multimessenger\messengr.exe" = protocol=17 | dir=in | app=c:\program files\gmx\gmx multimessenger\messengr.exe |
"UDP Query User{F9BF3633-8405-4905-BF68-E94615A649FB}C:\windows\system32\dpnsvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dpnsvr.exe |
"UDP Query User{FA362C5E-E269-4632-BC63-850893A36EB1}E:\valve\hltv.exe" = protocol=17 | dir=in | app=e:\valve\hltv.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam(TM)
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP610_series" = Canon MP610 series
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 10
"{292A177D-723F-4537-9985-BC8BFCD8B63D}" = EIZO ScreenSlicer
"{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}" = GTA2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Configurer
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE1008C-11A1-4F4F-8DB7-27573924DE78}" = DMIView B7.0108.01
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{580D6A69-F3F7-CB21-A5F5-3451A38CA1C2}" = Catalyst Control Center InstallProxy
"{5DE1B7CF-7429-40CA-987F-6BEE09B63787}" = Prime95
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{68D1CBD5-899D-037D-FC17-191811C44EA5}" = ATI Catalyst Install Manager
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{75E607CF-7BAE-4B88-84B3-97F3DF44BA28}" = FEARCombat
"{7644E42D-B096-457F-8B5B-901238FC81AE}" = ICQ7.6
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77A1C7DD-E4F6-4057-92FC-710219215987}" = Logitech G11 Keyboard Software 1.03
"{7A65E382-1843-4B46-861B-1BECB8354911}" = Falcon 4.0: Allied Force
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9580813D-94B1-4C28-9426-A441E2BB29A5}" = Counter-Strike: Source
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{AC76BA86-7AD7-1033-7646-A70000000000}" = Adobe Reader 7.0
"{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D3B1C799-CB73-42DE-BA0F-2344793A095C}" = Catalyst Control Center - Branding
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{DAB265AD-27B2-4651-B8D8-F4F3A8ECC705}" = ScreenManager Pro for LCD (DDC/CI)
"{E1640DA5-89B4-4F52-B15D-5DA3D14F29D4}" = LG USB Modem Drivers
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{FD5705C1-E925-9D79-7C2E-2A4FDC962036}" = ATI Catalyst Control Center Ex
"{FE163F11-1919-4257-A280-FF5AF8DAEECB}" = ICQ Sparberater
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"aTube Catcher" = aTube Catcher
"Avira AntiVir Desktop" = Avira Free Antivirus
"Canon MP610 series Benutzerregistrierung" = Canon MP610 series Benutzerregistrierung
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FileZilla Client" = FileZilla Client 3.3.5.1
"Flight Simulator 9.0" = Microsoft Flight Simulator 2004 - Das Jahrhundert der Luftfahrt
"FolderVisualizer_is1" = FolderVisualizer
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
"GMX MultiMessenger" = GMX MultiMessenger
"ICQToolbar" = ICQ Toolbar
"im" = Garena Plus
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"KaloMa_is1" = KaloMa 4.72
"Logitech Vid" = Logitech Vid HD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 18.0 (x86 de)" = Mozilla Firefox 18.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"Notepad++" = Notepad++
"PriceGong" = PriceGong 2.5.1
"SideWinder Force Feedback 2" = SideWinder Force Feedback 2
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"Steam App 10" = Counter-Strike
"Steam App 11020" = TrackMania Nations Forever
"Steam App 211" = Source SDK
"Steam App 215" = Source SDK Base
"T4EPlayer" = T4E Player
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"VLC media player" = VideoLAN VLC media player 0.8.6d
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-2481620165-4217138233-3408023960-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"171a3bd25b2ddd36" = vroute.info
"Steam App 240" = Counter-Strike: Source
"Steam App 300" = Day of Defeat: Source
"Steam App 320" = Half-Life 2: Deathmatch
"Steam App 340" = Half-Life 2: Lost Coast
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 09.01.2013 17:54:34 | Computer Name = Batman | Source = EventSystem | ID = 4621
Description =
Error - 10.01.2013 13:04:44 | Computer Name = Batman | Source = Windows Search Service | ID = 3006
Description =
Error - 10.01.2013 13:04:44 | Computer Name = Batman | Source = Windows Search Service | ID = 3007
Description =
Error - 10.01.2013 17:21:11 | Computer Name = Batman | Source = EventSystem | ID = 4621
Description =
Error - 12.01.2013 10:24:44 | Computer Name = Batman | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung MsiExec.exe, Version 4.5.6002.18005, Zeitstempel
0x49e01c42, fehlerhaftes Modul MSIFECF.tmp, Version 1.0.0.0, Zeitstempel 0x50b652fb,
Ausnahmecode 0xc0000417, Fehleroffset 0x00014682, Prozess-ID 0x1604, Anwendungsstartzeit
01cdf0d07f0c9fe4.
Error - 13.01.2013 07:10:09 | Computer Name = Batman | Source = Windows Search Service | ID = 3013
Description =
Error - 13.01.2013 07:10:09 | Computer Name = Batman | Source = Windows Search Service | ID = 3013
Description =
Error - 13.01.2013 07:11:53 | Computer Name = Batman | Source = Windows Search Service | ID = 3013
Description =
Error - 13.01.2013 07:11:53 | Computer Name = Batman | Source = Windows Search Service | ID = 3013
Description =
Error - 14.01.2013 07:37:04 | Computer Name = Batman | Source = EventSystem | ID = 4621
Description =
[ Media Center Events ]
Error - 18.04.2008 13:31:41 | Computer Name = Batman | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
gescheitert.
[ OSession Events ]
Error - 09.02.2008 10:20:33 | Computer Name = Batman | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2086
seconds with 60 seconds of active time. This session ended with a crash.
Error - 16.04.2008 16:06:11 | Computer Name = Batman | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1511
seconds with 300 seconds of active time. This session ended with a crash.
Error - 20.05.2008 16:18:01 | Computer Name = Batman | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 10195
seconds with 60 seconds of active time. This session ended with a crash.
Error - 14.05.2009 15:30:28 | Computer Name = Batman | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 9412
seconds with 2040 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 13.01.2013 08:43:01 | Computer Name = Batman | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error - 14.01.2013 05:54:22 | Computer Name = Batman | Source = Service Control Manager | ID = 7026
Description =
Error - 14.01.2013 13:02:24 | Computer Name = Batman | Source = Service Control Manager | ID = 7026
Description =
Error - 15.01.2013 06:45:38 | Computer Name = Batman | Source = Service Control Manager | ID = 7026
Description =
Error - 15.01.2013 17:03:12 | Computer Name = Batman | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error - 15.01.2013 17:03:14 | Computer Name = Batman | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error - 15.01.2013 17:03:17 | Computer Name = Batman | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error - 15.01.2013 17:03:19 | Computer Name = Batman | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error - 15.01.2013 17:03:21 | Computer Name = Batman | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error - 15.01.2013 17:44:13 | Computer Name = Batman | Source = Service Control Manager | ID = 7026
Description =
< End of report > --- --- --- |