SchmerlenOtt | 09.03.2013 06:25 | Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.6.9 (03.06.2013:1)
OS: Microsoft Windows XP x86
Ran by Gerhard Admin on 08.03.2013 at 21:01:04,94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\DisplayName
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\URL
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\DisplayName
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\URL
~~~ Registry Keys
Successfully deleted: [Registry Key] hkey_current_user\software\conduit
Successfully deleted: [Registry Key] hkey_local_machine\software\conduit
Successfully deleted: [Registry Key] hkey_local_machine\software\freeze.com
Successfully deleted: [Registry Key] hkey_current_user\software\igearsettings
Successfully deleted: [Registry Key] hkey_current_user\software\softonic
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\bho.dll
Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT2431245
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{171debeb-c3d4-40b7-ac73-056a5eba4a7e}
Successfully deleted: [Registry Key] „hkey_current_user\software\appdatalow\askbardis“ Successfully deleted: [Registry Key] „hkey_current_user\software\ask.com“ Successfully deleted: [Registry Key] „hkey_current_user\software\asktoolbar“ Successfully deleted: [Registry Key] „hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products\a28b4d68debaa244eb686953b7074fef“
~~~ Files
~~~ Folders
Successfully deleted: [Folder] „C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\opencandy“
Successfully deleted: [Folder] „C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\pricegong“
Successfully deleted: [Folder] „C:\Programme\conduit“
~~~ FireFox
Successfully deleted: [File] C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\mozilla\firefox\profiles\wyb5vxgg.default\user.js
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08.03.2013 at 23:46:14,38
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
# AdwCleaner v2.114 - Datei am 09/03/2013 um 04:12:05 erstellt
# Aktualisiert am 05/03/2013 von Xplode
# Betriebssystem : Microsoft Windows XP Service Pack 3 (32 bits)
# Benutzer : Gerhard Admin - SACHFACH
# Bootmodus : Normal
# Ausgeführt unter : C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Ordner Gelöscht : C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\wyb5vxgg.default\Conduit
Ordner Gelöscht : C:\Dokumente und Einstellungen\Gerhard Admin\Lokale Einstellungen\Anwendungsdaten\Conduit
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\20604617293479961433209750898538827404032021801842
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
***** [Internet Browser] *****
-\\ Internet Explorer v8.0.6001.18702
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v19.0.2 (de)
Datei : C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\wyb5vxgg.default\prefs.js
Gelöscht : user_pref(„browser.search.defaultenginename“, „AVG Secure Search“);
Datei : C:\Dokumente und Einstellungen\Gerhard User\Anwendungsdaten\Mozilla\Firefox\Profiles\n6oyu0fl.default\prefs.js
C:\Dokumente und Einstellungen\Gerhard User\Anwendungsdaten\Mozilla\Firefox\Profiles\n6oyu0fl.default\user.js ... Gelöscht !
Gelöscht : user_pref(„browser.search.defaultenginename“, „AVG Secure Search“);
Gelöscht : user_pref(„browser.search.selectedEngine“, „AVG Secure Search“);
Gelöscht : user_pref(„browser.startup.homepage“, „hxxps://isearch.avg.com/?cid=&mid=&lang=&ds=&pr=&d=&v=&sap=hp[...]
*************************
AdwCleaner[S1].txt - [369 octets] - [09/03/2013 04:11:30]
AdwCleaner[S2].txt - [2853 octets] - [09/03/2013 04:12:05]
########## EOF - C:\AdwCleaner[S2].txt - [2913 octets] ########## Code:
OTL logfile created on: 09.03.2013 06:33:14 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\Gerhard Admin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,50 Gb Total Physical Memory | 2,98 Gb Available Physical Memory | 85,21% Memory free
13,83 Gb Paging File | 13,39 Gb Available in Paging File | 96,81% Paging File free
Paging file location(s): C:\pagefile.sys 5371 5371G:\pagef [Binary data over 200 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 465,76 Gb Total Space | 424,87 Gb Free Space | 91,22% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 421,70 Gb Free Space | 90,54% Space Free | Partition Type: NTFS
Drive E: | 465,76 Gb Total Space | 149,10 Gb Free Space | 32,01% Space Free | Partition Type: NTFS
Drive F: | 465,76 Gb Total Space | 421,80 Gb Free Space | 90,56% Space Free | Partition Type: NTFS
Drive G: | 465,76 Gb Total Space | 143,86 Gb Free Space | 30,89% Space Free | Partition Type: NTFS
Computer Name: SACHFACH | User Name: Gerhard Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Programme\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Programme\UltraMon\UltraMonTaskbar.exe (Realtime Soft Ltd)
PRC - C:\Programme\UltraMon\UltraMon.exe (Realtime Soft Ltd)
PRC - C:\Programme\Bitdefender\Bitdefender 2012\vsserv.exe (Bitdefender)
PRC - C:\Programme\Bitdefender\Bitdefender 2012\bdagent.exe (Bitdefender)
PRC - C:\Programme\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
PRC - C:\Programme\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
PRC - C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Bitdefender\Bitdefender 2012\updatesrv.exe (Bitdefender)
PRC - C:\WINDOWS\system32\lxeacoms.exe ( )
PRC - c:\Programme\Matrox Graphics Inc\PowerDesk\Services\Matrox.PowerDesk.Services.exe (Matrox Graphics Inc.)
PRC - c:\Programme\Matrox Graphics Inc\PowerDesk SE\Matrox.Pdesk.ServicesHost.exe (Matrox Graphics Inc)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Programme\Bitdefender\Bitdefender 2012\bdmetrics.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\avc3al.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\UI\imsecurityal.ui ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\UI\accessl.ui ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\as2core\ashttpf.mdl ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\as2core\ashttpph.mdl ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\as2core\asimf.mdl ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\as2core\ashttprbl.mdl ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\as2core\ashttpbr.mdl ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\as2core\ashttpdsp.mdl ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\as2core\asimdsp.mdl ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\as2core\asimbr.mdl ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\procinfo.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\bdmltusrsrv.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\connector.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\excludemgr.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\framework.dll ()
MOD - C:\Programme\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\strdecoder.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\txmlutil.dll ()
MOD - \\?\C:\Programme\Gemeinsame Dateien\Bitdefender\Bitdefender Threat Scanner\trufos.dll ()
MOD - C:\WINDOWS\system32\LXEAPMON.DLL ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\lxeadrpp.dll ()
MOD - C:\WINDOWS\system32\MtxEscape.dll ()
MOD - C:\WINDOWS\system32\LXEAoem.dll ()
MOD - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AdistRes.DEU ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (JavaQuickStarterService) -- C:\Programme\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (StarMoney 8.0 OnlineUpdate) -- C:\Programme\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe (Star Finanz - Software Entwicklung und Vertriebs GmbH)
SRV - (vsserv) -- C:\Programme\Bitdefender\Bitdefender 2012\vsserv.exe (Bitdefender)
SRV - (SbieSvc) -- C:\Programme\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (TomTomHOMEService) -- C:\Programme\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (UPDATESRV) -- C:\Programme\Bitdefender\Bitdefender 2012\updatesrv.exe (Bitdefender)
SRV - (Update Server) -- C:\Programme\Gemeinsame Dateien\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe (BitDefender)
SRV - (FLEXnet Licensing Service) -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (lxea_device) -- C:\WINDOWS\system32\lxeacoms.exe ( )
SRV - (lxeaCATSCustConnectService) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxeaserv.exe ()
SRV - (Matrox Centering Service) -- c:\Programme\Matrox Graphics Inc\PowerDesk\Services\Matrox.PowerDesk.Services.exe (Matrox Graphics Inc.)
SRV - (Matrox.Pdesk.ServicesHost) -- c:\Programme\Matrox Graphics Inc\PowerDesk SE\Matrox.Pdesk.ServicesHost.exe (Matrox Graphics Inc)
SRV - (NMIndexingService) -- C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (STacSV) -- C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (ATMsrvc) -- C:\WINDOWS\system32\ATMsrvc.exe (Adobe Systems Incorporated)
========== Driver Services (SafeList) ==========
DRV - (PCIDump) -- File not found
DRV - (dgderdrv) -- System32\drivers\dgderdrv.sys File not found
DRV - (catchme) -- C:\DOKUME~1\GERHAR~1\LOKALE~1\Temp\catchme.sys File not found
DRV - (avc3) -- C:\WINDOWS\system32\drivers\avc3.sys (BitDefender)
DRV - (avchv) -- C:\WINDOWS\system32\drivers\avchv.sys (BitDefender)
DRV - (avckf) -- C:\WINDOWS\system32\drivers\avckf.sys (BitDefender)
DRV - (SbieDrv) -- C:\Programme\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (UltraMonUtility) -- C:\Programme\Gemeinsame Dateien\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys (Realtime Soft Ltd)
DRV - (bdselfpr) -- C:\Programme\Bitdefender\Bitdefender 2012\bdselfpr.sys (BitDefender LLC)
DRV - (AnyDVD) -- C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (bdsandbox) -- C:\WINDOWS\system32\drivers\bdsandbox.sys (BitDefender SRL)
DRV - (bdftdif) -- C:\Programme\Gemeinsame Dateien\Bitdefender\Bitdefender Firewall\bdftdif.sys (BitDefender LLC)
DRV - (trufos) -- C:\WINDOWS\system32\drivers\trufos.sys (BitDefender S.R.L.)
DRV - (bdfsfltr) -- C:\WINDOWS\system32\drivers\bdfsfltr.sys (BitDefender)
DRV - (sptd) -- C:\WINDOWS\system32\drivers\sptd.sys ()
DRV - (cpudrv) -- C:\Programme\SystemRequirementsLab\cpudrv.sys ()
DRV - (tifsfilter) -- C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (FsUsbExDisk) -- C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (ss_mdm) -- C:\WINDOWS\system32\drivers\ss_mdm.sys (MCCI Corporation)
DRV - (ss_bus) -- C:\WINDOWS\system32\drivers\ss_bus.sys (MCCI Corporation)
DRV - (ss_mdfl) -- C:\WINDOWS\system32\drivers\ss_mdfl.sys (MCCI Corporation)
DRV - (BDVEDISK) -- C:\WINDOWS\system32\drivers\bdvedisk.sys (BitDefender)
DRV - (cxbu0wdm) -- C:\WINDOWS\system32\drivers\cxbu0wdm.sys (OMNIKEY)
DRV - (Mtxparmx) -- C:\WINDOWS\system32\drivers\mtxparmx.sys (Matrox Graphics Inc.)
DRV - (MTXPAR) -- C:\WINDOWS\system32\drivers\MTXPARM.sys (Matrox Graphics Inc.)
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (sfng32) -- C:\WINDOWS\system32\drivers\sfng32.sys (Sonic Focus, Inc)
DRV - (BlueletAudio) -- C:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation.)
DRV - (Btcsrusb) -- C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation.)
DRV - (fpcibase) -- C:\WINDOWS\system32\drivers\fpcibase.sys (AVM Berlin)
DRV - (AVMCOWAN) -- C:\WINDOWS\system32\drivers\avmcowan.sys (AVM GmbH)
DRV - (HECI) -- C:\WINDOWS\system32\drivers\HECI.sys (Intel Corporation)
DRV - (BlueletSCOAudio) -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys (IVT Corporation.)
DRV - (BT) -- C:\WINDOWS\system32\drivers\btnetdrv.sys (IVT Corporation.)
DRV - (BTHidMgr) -- C:\WINDOWS\system32\drivers\BTHidMgr.sys (IVT Corporation.)
DRV - (BTHidEnum) -- C:\WINDOWS\system32\drivers\vbtenum.sys (IVT Corporation.)
DRV - (VcommMgr) -- C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation.)
DRV - (VComm) -- C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation.)
DRV - (ElbyCDFL) -- C:\WINDOWS\System32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (MTXPARH) -- C:\WINDOWS\system32\drivers\mtxparhm.sys (Matrox Graphics Inc.)
DRV - (X-Rite) -- C:\WINDOWS\system32\drivers\XrUsb.sys (X-Rite, Inc.)
DRV - (SMBios) -- C:\WINDOWS\system32\drivers\SMBios.sys (Intel Corporation)
DRV - (AVMWAN) -- C:\WINDOWS\system32\drivers\avmwan.sys (AVM GmbH)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1659004503-879983540-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1659004503-879983540-682003330-1003\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1659004503-879983540-682003330-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search
IE - HKU\S-1-5-21-1659004503-879983540-682003330-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-1659004503-879983540-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1659004503-879983540-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledAddons: %7B097d3191-e6fa-4728-9826-b533d755359d%7D:0.7.18
FF - prefs.js..extensions.enabledAddons: %7BDDC359D1-844A-42a7-9AA1-88A850A938A8%7D:2.0.15
FF - prefs.js..extensions.enabledAddons: %7Ba7c6cf7f-112c-4500-a7ea-39801a327e5f%7D:2.0.11
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.14
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: FFToolbar@bitdefender.com:2.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.1.31
FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.3.3
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.9
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.91
FF - prefs.js..extensions.enabledItems: en-US@dictionaries.addons.mozilla.org:5.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.15.2: C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.9: C:\Programme\VideoLAN\VLC\npvlc.dll File not found
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.3: C:\Programme\TabletPlugins\npwacom.dll File not found
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Programme\TabletPlugins\npwacom.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Programme\Mozilla Firefox\components [2013.03.08 18:45:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2013.03.08 17:20:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.3\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2013.02.20 17:13:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.3\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins [2013.02.21 16:33:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\bdThunderbird@bitdefender.com: C:\Programme\Bitdefender\Bitdefender 2012\bdtbext\
[2010.08.29 12:27:22 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Extensions
[2010.08.10 13:32:34 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.08.29 12:27:22 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Extensions\home2@tomtom.com
[2013.03.09 06:25:41 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\wyb5vxgg.default\extensions
[2013.02.25 18:52:49 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\wyb5vxgg.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2013.03.09 06:25:41 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\wyb5vxgg.default\extensions\staged
[2012.09.08 18:20:28 | 000,455,379 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\wyb5vxgg.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi
[2013.02.25 18:52:49 | 000,342,692 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\wyb5vxgg.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}.xpi
[2013.02.24 13:05:37 | 000,817,280 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\wyb5vxgg.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.03.09 06:25:40 | 000,150,353 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\wyb5vxgg.default\extensions\{d57c9ff1-6389-48fc-b770-f78bd89b6e8a}.xpi
[2012.10.24 20:36:57 | 000,698,867 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\wyb5vxgg.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2013.03.09 06:25:41 | 000,872,587 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\wyb5vxgg.default\extensions\staged\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}.xpi
[2013.03.08 17:20:42 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.03.08 17:20:50 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2010.09.25 11:56:30 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Programme\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2011.09.10 18:07:55 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.30 19:12:39 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2011.09.10 18:07:55 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2011.09.10 18:07:55 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.10 18:07:55 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.09.10 18:07:55 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2013.03.08 18:51:36 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Lexmark ) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Programme\Lexmark Printable Web\bho.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\S-1-5-21-1659004503-879983540-682003330-1003\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\AutorunsDisabled [2012.12.23 14:35:48 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\UltraMon.lnk = C:\WINDOWS\Installer\{9069EE0A-7615-4D86-AD80-CA263E936DA6}\IcoUltraMon.ico ()
O4 - Startup: C:\Dokumente und Einstellungen\Gerhard Admin\Startmenü\Programme\Autostart\AutorunsDisabled [2012.03.20 13:47:55 | 000,000,000 | -H-D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1659004503-879983540-682003330-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1659004503-879983540-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1659004503-879983540-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1659004503-879983540-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: An vorhandenes PDF anfügen - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O15 - HKU\S-1-5-21-1659004503-879983540-682003330-1003\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-1659004503-879983540-682003330-1003\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1354982292937 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1354982385421 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8D37A496-7926-44AB-988C-B3AEA35DBAC4}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:AutorunsDisabled () -
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.08.09 17:21:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.03.09 04:22:58 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2013.03.08 21:01:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2013.03.08 21:00:40 | 000,000,000 | ---D | C] -- C:\JRT
[2013.03.08 20:52:40 | 000,547,791 | ---- | C] (Oleg N. Scherbakov) -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\JRT.exe
[2013.03.08 17:39:35 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013.03.08 17:36:46 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2013.03.08 17:36:46 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2013.03.08 17:36:46 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2013.03.08 17:36:46 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2013.03.08 17:35:24 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.03.08 17:34:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013.03.08 17:31:23 | 005,037,067 | R--- | C] (Swearware) -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\ComboFix.exe
[2013.03.08 17:20:41 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2013.03.08 15:56:57 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2013.03.08 12:58:11 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\tdsskiller.exe
[2013.03.08 12:24:35 | 004,732,416 | ---- | C] (AVAST Software) -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\aswMBR.exe
[2013.03.06 14:13:03 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\OTL.exe
[2013.03.04 12:13:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\FreeFileSync
[2013.03.04 12:13:14 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\FreeFileSync
[2013.03.04 12:13:09 | 000,000,000 | ---D | C] -- C:\Programme\FreeFileSync
[2013.03.03 22:59:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2013.03.02 17:15:31 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Gerhard Admin\Eigene Dateien\PersBackup
[2013.03.02 17:14:51 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\PersBackup5
[2013.03.02 17:14:41 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Personal Backup
[2013.03.02 17:14:39 | 000,000,000 | ---D | C] -- C:\Programme\Personal Backup 5
[2013.02.28 22:48:30 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Gerhard Admin\Recent
[2013.02.28 04:27:26 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Matrox Graphics Inc
[2013.02.28 04:27:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Matrox Graphics Inc
[2013.02.28 04:27:23 | 000,000,000 | ---D | C] -- C:\Programme\Matrox Graphics Inc
[2013.02.26 23:18:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2013.02.24 13:01:13 | 000,000,000 | ---D | C] -- C:\Programme\SystemRequirementsLab
[2013.02.21 17:48:04 | 000,143,872 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2013.02.21 17:48:03 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2013.02.21 17:47:56 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2013.02.21 17:47:56 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2013.02.21 17:47:56 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013.02.21 17:47:37 | 000,000,000 | ---D | C] -- C:\Programme\Java
[2013.02.20 17:13:04 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Thunderbird
[2013.02.16 14:21:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\mbar
[2 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.03.09 06:32:23 | 000,011,411 | ---- | M] () -- C:\WINDOWS\Q-Dir.ini
[2013.03.09 04:18:59 | 000,012,724 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.03.09 04:18:29 | 000,002,283 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\UltraMon.lnk
[2013.03.09 04:16:01 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.03.08 20:57:15 | 000,597,667 | ---- | M] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\adwcleaner.exe
[2013.03.08 18:51:36 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013.03.08 17:39:46 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013.03.08 02:43:08 | 005,037,067 | R--- | M] (Swearware) -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\ComboFix.exe
[2013.03.07 22:39:41 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2013.03.07 19:01:02 | 013,786,977 | ---- | M] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\mbar-1.01.0.1021.zip
[2013.03.07 18:17:21 | 000,377,856 | ---- | M] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\gmer_2.1.19155.exe
[2013.03.06 23:14:57 | 000,547,791 | ---- | M] (Oleg N. Scherbakov) -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\JRT.exe
[2013.03.06 12:27:01 | 000,000,240 | ---- | M] () -- C:\WINDOWS\System32\checkdnsid.xml
[2013.03.06 12:19:17 | 000,005,290 | ---- | M] () -- C:\WINDOWS\Sandboxie.ini
[2013.03.04 12:15:21 | 000,000,710 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\FreeFileSync.lnk
[2013.03.02 19:53:04 | 002,604,911 | ---- | M] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Eigene Dateien\AutoRuns 2013-03-02.arn
[2013.03.02 17:14:42 | 000,000,727 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Personal Backup 5.lnk
[2013.03.01 17:37:00 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2013.02.28 23:04:20 | 000,001,104 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013.02.28 23:04:20 | 000,001,100 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013.02.26 16:26:19 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013.02.26 16:26:18 | 000,691,568 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013.02.26 16:26:18 | 000,071,024 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013.02.21 22:12:27 | 000,002,181 | ---- | M] () -- C:\WINDOWS\Helicon Debug Window.ini
[2013.02.21 17:47:43 | 000,094,112 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013.02.21 17:47:42 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2013.02.21 17:47:42 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2013.02.21 17:47:42 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2013.02.21 17:47:42 | 000,143,872 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2013.02.21 17:47:41 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
[2013.02.21 17:47:41 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2013.02.13 15:06:04 | 001,420,648 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013.02.13 14:37:26 | 000,665,020 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2013.02.13 14:37:26 | 000,580,178 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013.02.13 14:37:26 | 000,154,822 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2013.02.13 14:37:26 | 000,113,964 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013.02.11 21:29:13 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\tdsskiller.exe
[2 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.03.08 20:57:16 | 000,597,667 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\adwcleaner.exe
[2013.03.08 17:39:46 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2013.03.08 17:39:43 | 000,262,448 | RHS- | C] () -- C:\cmldr
[2013.03.08 17:36:46 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013.03.08 17:36:46 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013.03.08 17:36:46 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013.03.08 17:36:46 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013.03.08 17:36:46 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2013.03.07 19:03:09 | 013,786,977 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\mbar-1.01.0.1021.zip
[2013.03.07 18:17:20 | 000,377,856 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Desktop\gmer_2.1.19155.exe
[2013.03.04 12:13:14 | 000,000,710 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\FreeFileSync.lnk
[2013.03.02 19:53:00 | 002,604,911 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Eigene Dateien\AutoRuns 2013-03-02.arn
[2013.03.02 17:14:42 | 000,000,727 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Personal Backup 5.lnk
[2013.01.10 14:39:32 | 000,219,376 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2012.12.04 22:02:24 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2012.05.30 13:17:12 | 000,065,536 | ---- | C] () -- C:\WINDOWS\IFinst27.exe
[2012.05.28 15:05:54 | 000,002,060 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\.powerupdate.user.properties
[2012.04.10 18:20:05 | 000,011,411 | ---- | C] () -- C:\WINDOWS\Q-Dir.ini
[2012.02.14 23:11:20 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.02.04 22:45:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ATM.INI
[2011.12.16 13:28:08 | 000,044,344 | ---- | C] () -- C:\WINDOWS\System32\drivers\SEQCAL.SYS
[2011.12.16 13:28:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\Mplps.dll
[2011.06.13 15:27:25 | 000,000,132 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\search_result.xml
[2011.06.04 19:51:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\imwords.dat
[2011.06.04 19:51:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\im_markovian.dat
[2011.02.11 13:23:58 | 000,080,427 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\bdinstall.bin
[2010.12.17 17:11:02 | 000,000,640 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\clipboardmanager.ini
[2010.11.09 22:08:27 | 000,000,116 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\default.pls
[2010.09.24 15:10:58 | 000,786,622 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-1659004503-879983540-682003330-1003-0.dat
[2010.09.24 15:10:57 | 000,314,070 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat
[2010.09.22 16:52:25 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\$_hpcst$.hpc
[2010.09.21 10:07:05 | 000,000,850 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\AnwendungsdatenProductTweaks.xml
[2010.09.10 13:42:01 | 000,000,081 | -HS- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\.zreglib
[2010.09.09 14:32:17 | 000,000,385 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdatenuser_gensett.xml
[2010.08.25 19:17:18 | 000,000,376 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdatenprivacy.xml
[2010.08.16 11:18:57 | 000,000,406 | RHS- | C] () -- C:\Dokumente und Einstellungen\All Users\ntuser.pol
[2010.08.16 10:51:47 | 000,020,531 | -H-- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\T09F8
[2010.08.14 21:05:28 | 000,027,648 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.10 01:19:14 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\Gerhard Admin\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2010.07.08 09:37:14 | 000,101,544 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\LinkInstaller.exe
========== ZeroAccess Check ==========
[2010.08.10 01:15:26 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 03:22:25 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.02.09 11:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008.04.14 03:22:32 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 400 bytes -> C:\Dokumente und Einstellungen\Gerhard Admin\Lokale Einstellungen\Anwendungsdaten\desktop.ini:bf5af20ce7a419b1178ece347eddc338
< End of report > Code:
OTL Extras logfile created on: 09.03.2013 06:33:14 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\Gerhard Admin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,50 Gb Total Physical Memory | 2,98 Gb Available Physical Memory | 85,21% Memory free
13,83 Gb Paging File | 13,39 Gb Available in Paging File | 96,81% Paging File free
Paging file location(s): C:\pagefile.sys 5371 5371G:\pagef [Binary data over 200 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 465,76 Gb Total Space | 424,87 Gb Free Space | 91,22% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 421,70 Gb Free Space | 90,54% Space Free | Partition Type: NTFS
Drive E: | 465,76 Gb Total Space | 149,10 Gb Free Space | 32,01% Space Free | Partition Type: NTFS
Drive F: | 465,76 Gb Total Space | 421,80 Gb Free Space | 90,56% Space Free | Partition Type: NTFS
Drive G: | 465,76 Gb Total Space | 143,86 Gb Free Space | 30,89% Space Free | Partition Type: NTFS
Computer Name: SACHFACH | User Name: Gerhard Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL „%1“,%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_USERS\S-1-5-21-1659004503-879983540-682003330-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- „%1“ %*
cmdfile [open] -- „%1“ %*
comfile [open] -- „%1“ %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL „%1“,%*
exefile [open] -- „%1“ %*
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- „%1“ %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- „%1“
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- „%1“ /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- „C:\Programme\VideoLAN\VLC\vlc.exe“ --started-from-file --playlist-enqueue „%1“ ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- „C:\Programme\VideoLAN\VLC\vlc.exe“ --started-from-file --no-playlist-enqueue „%1“ ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
„FirstRunDisabled“ = 1
„AntiVirusDisableNotify“ = 0
„FirewallDisableNotify“ = 0
„UpdatesDisableNotify“ = 0
„AntiVirusOverride“ = 0
„FirewallOverride“ = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
„DisableSR“ = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
„Start“ = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
„Start“ = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
„EnableFirewall“ = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
„1900:UDP“ = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
„2869:TCP“ = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
„5985:TCP“ = 5985:TCP:*:Disabled:Windows-Remoteverwaltung
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
„%windir%\system32\sessmgr.exe“ = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
„%windir%\Network Diagnostic\xpnetdiag.exe“ = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
„%windir%\system32\sessmgr.exe“ = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
„%windir%\Network Diagnostic\xpnetdiag.exe“ = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
„C:\Programme\Bonjour\mDNSResponder.exe“ = C:\Programme\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Computer, Inc.)
„C:\WINDOWS\system32\lxeacoms.exe“ = C:\WINDOWS\system32\lxeacoms.exe:*:Enabled:S300-S400 Series Server -- ( )
„C:\Programme\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe“ = C:\Programme\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe:*:Enabled:Adobe Dreamweaver CS3 -- (Adobe Systems, Inc.)
„C:\Programme\Google\Google Earth\client\googleearth.exe“ = C:\Programme\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)
„C:\Programme\Google\Google Earth\plugin\geplugin.exe“ = C:\Programme\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- (Google)
„C:\Programme\VideoLAN\VLC\vlc.exe“ = C:\Programme\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- ()
„C:\Programme\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe“ = C:\Programme\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe:*:Enabled:StarMoney 8.0 OnlineUpdate -- (Star Finanz - Software Entwicklung und Vertriebs GmbH)
„C:\Programme\StarMoney 8.0 S-Edition\app\StarMoney.exe“ = C:\Programme\StarMoney 8.0 S-Edition\app\StarMoney.exe:*:Enabled:StarMoney 8.0 -- (Star Finanz - Software Entwicklung und Vertriebs GmbH)
„C:\Programme\Kabel Deutschland\Installations-Software\KDI.exe“ = C:\Programme\Kabel Deutschland\Installations-Software\KDI.exe:*:Enabled:Kabel Deutschland Installer -- (mquadr.at software engineering & consulting GmbH)
„C:\Programme\CmapTools IHMC\jre\bin\javaw.exe“ = C:\Programme\CmapTools IHMC\jre\bin\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary -- (Sun Microsystems, Inc.)
„C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Dropbox\bin\Dropbox.exe“ = C:\Dokumente und Einstellungen\Gerhard Admin\Anwendungsdaten\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.)
„C:\Programme\PhraseExpress\PhraseExpress.exe“ = C:\Programme\PhraseExpress\PhraseExpress.exe:*:Enabled:PhraseExpress -- (Bartels Media GmbH)
„C:\Programme\BlueSoleil\BlueSoleil_.exe“ = C:\Programme\BlueSoleil\BlueSoleil_.exe:*:Enabled:BlueSoleil -- (IVT Corporation.)
„C:\WINDOWS\system32\dpvsetup.exe“ = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
„{010C0B4A-DC93-4BB4-893B-BDDE95355A3E}“ = Freeware PDF Unlocker
„{0180F30F-52A8-4414-8E3B-931917211845}“ = AquaSoft DiaShow Studio 6
„{022D2599-2316-4927-89F1-9188894CEB02}“ = StarMoney
„{04AF207D-9A77-465A-8B76-991F6AB66245}“ = Adobe Help Viewer CS3
„{052FDD78-A6EA-3187-8386-C82F4CA3A929}“ = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
„{08B32819-6EEF-4057-AEDA-5AB681A36A23}“ = Adobe Bridge Start Meeting
„{0A0CADCF-78DA-33C4-A350-CD51849B9702}“ = Microsoft .NET Framework 4 Extended
„{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}“ = Adobe WinSoft Linguistics Plugin
„{1A3E23D7-7A1E-43EC-B35D-EB2A31BED943}“ = Video DVD Maker v3.32.0.80
„{1FCBD504-AB7D-4757-9A14-850348384B08}“ = StarMoney
„{2072844E-635C-4A37-AB67-F886B89DAB53}“ = StarMoney 8.0 S-Edition
„{22FC7536-BE5C-4E88-8069-C24689D34EC5}“ = Snagit 10.0.1
„{248057F8-58C8-4E44-9182-9AF85DF787FC}“ = Adobe Setup
„{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}“ = Adobe ExtendScript Toolkit 2
„{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1“ = Media Player Classic - Home Cinema 1.6.0.4014
„{26A24AE4-039D-4CA4-87B4-2F83217015FF}“ = Java 7 Update 15
„{29E5EA97-5F74-4A57-B8B2-D4F169117183}“ = Adobe Stock Photos CS3
„{2AB9289D-6432-4CC0-8869-A195C3F0CFCC}“ = Bitdefender Antivirus Plus 2012
„{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}“ = WebFldrs XP
„{36B107C0-F8AD-42D5-B0CD-58035C5A4B47}“ = Duden Korrektor PLUS Update
„{3C3901C5-3455-3E0A-A214-0B093A5070A6}“ = Microsoft .NET Framework 4 Client Profile
„{411E0CC3-587A-468C-B461-95FAFD05E4DE}“ = Adobe InDesign CS3
„{438BB9B4-65FE-4626-91D9-A8F57B18001D}“ = Bluesoleil2.6.0.8 Release 070517
„{47879FA7-BC8F-4D7F-8057-86D0416579FA}“ = StarMoney
„{4A03706F-666A-4037-7777-5F2748764D10}“ = Java Auto Updater
„{4AA5B8A5-BEEF-4AD8-B11D-4443A042EA4F}“ = Adobe Dreamweaver CS3
„{54793AA1-5001-42F4-ABB6-C364617C6078}“ = Adobe Linguistics CS3
„{56A3E6C9-919E-4578-ACBE-F1A5C7B99A90}“ = DesignCAD 3D Max 18
„{56C049BE-79E9-4502-BEA7-9754A3E60F9B}“ = neroxml
„{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}“ = Google Earth
„{5B4383F2-37EE-4E97-AD81-F5FF76F286DA}“ = OutlookAddInNet3Setup
„{5C81B189-5456-40C4-9313-7FE6FA6DD64C}“ = Office-Bibliothek
„{5CF1F472-846B-44E8-9750-A2112DA32CB6}“ = MemoMaster 4
„{5E2ABE05-B7AD-4D77-8A19-BDA0E4302190}“ = Google SketchUp 8
„{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}“ = Adobe Setup
„{67EC0AB2-8CF7-4415-9F70-7FBC593C0D5E}“ = ScanSoft PDF Create! 4
„{6ABE0BEE-D572-4FE8-B434-9E72A289431B}“ = Adobe Fonts All
„{6B0A882B-3AB7-45FE-B1E1-9A832413D699}“ = MonacoOPTIX 2.0
„{6B708481-748A-4EB4-97C1-CD386244FF77}“ = Adobe MotionPicture Color Files
„{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}“ = AHV content for Acrobat and Flash
„{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}“ = Adobe Color Common Settings
„{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}“ = Adobe Asset Services CS3
„{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}“ = Microsoft Visual C++ 2005 Redistributable
„{716E0306-8318-4364-8B8F-0CC4E9376BAC}“ = MSXML 4.0 SP2 Parser and SDK
„{73B5D990-04EA-4751-B10F-5534770B91F2}“ = Adobe Color EU Recommended Settings
„{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}“ = Intel(R) PRO Network Connections 12.1.12.0
„{7D386596-0E80-4808-8AAE-C1DDA8212F7F}“ = Adobe Setup
„{802771A9-A856-4A41-ACF7-1450E523C923}“ = Adobe XMP Panels CS3
„{8AEBFD30-B94F-4A49-8106-03039708BDD4}“ = Duden Korrektor Patch 012009
„{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}“ = Adobe Device Central CS3
„{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}“ = Adobe Type Support
„{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}“ = TomTom HOME Visual Studio Merge Modules
„{8FB53850-246A-3507-8ADE-0060093FFEA6}“ = Visual Studio Tools for the Office system 3.0 Runtime
„{90120000-0020-0407-0000-0000000FF1CE}“ = Compatibility Pack für 2007 Office System
„{90140000-2005-0000-0000-0000000FF1CE}“ = Microsoft Office File Validation Add-In
„{90176341-0A8B-4CCC-A78D-F862228A6B95}“ = Adobe Anchor Service CS3
„{9017CEAF-BE5A-4F73-8A0E-C87E26971E55}“ = TomTom HOME
„{9069EE0A-7615-4D86-AD80-CA263E936DA6}“ = UltraMon
„{91110407-6000-11D3-8CFE-0150048383C9}“ = Microsoft Office Professional Edition 2003
„{9BE518E6-ECC6-35A9-88E4-87755C07200F}“ = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
„{9C9824D9-9000-4373-A6A5-D0E5D4831394}“ = Adobe Bridge CS3
„{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}“ = Adobe CMaps
„{A2D81E70-2A98-4A08-A628-94388B063C5E}“ = Adobe Color - Photoshop Specific
„{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}“ = Microsoft .NET Framework 3.0 Service Pack 2
„{A45C5EC7-F13E-4414-99BE-47373935C0FE}“ = Eraser 6.0.10.2620
„{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}“ = SigmaTel Audio
„{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}“ = Google Update Helper
„{AABF76CA-D460-42F0-BB2C-80DF44E8850F}“ = Adobe Creative Suite 3 Design Standard
„{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}“ = PDF Settings
„{AC76BA86-1033-F400-7760-000000000003}“ = Adobe Acrobat 8 Professional - English, Français, Deutsch
„{AC76BA86-7AD7-1031-7B44-AB0000000001}“ = Adobe Reader XI (11.0.02) - Deutsch
„{B1A70A4D-549B-4C56-9C00-EF55A22E52B6}“ = StarMoney
„{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}“ = Adobe Camera Raw 4.0
„{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}“ = Adobe Setup
„{B671CBFD-4109-4D35-9252-3062D3CCB7B2}“ = Adobe SING CS3
„{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}“ = Adobe BridgeTalk Plugin CS3
„{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}“ = Adobe Default Language CS3
„{BAFCA6AC-8B37-405B-B57E-C1D45DE70ACC}“ = 3Dconnexion 3DxWare 10 Beta 9 (32-bit)
„{BB3E446F-A88E-4D91-9905-9138965561E3}“ = Matrox PowerDesk-SE
„{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}“ = Adobe Flash Player 9 ActiveX
„{BE5F3842-8309-4754-92D5-83E02E6077A3}“ = Adobe Extension Manager CS3
„{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}“ = Microsoft .NET Framework 2.0 Service Pack 2
„{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}“ = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU
„{C5BD220A-EFE8-48A5-B70E-9503D535FACE}“ = Adobe WAS CS3
„{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}“ = System Requirements Lab for Intel
„{C8D7A672-F697-4572-AC62-C856053A8DBC}“ = Adobe Illustrator CS3
„{C911A0C2-2236-3164-AA47-F2566C01AE5E}“ = Microsoft .NET Framework 4 Extended DEU Language Pack
„{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}“ = Microsoft .NET Framework 1.1
„{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}“ = Microsoft .NET Framework 3.5 SP1
„{CF097717-F174-4144-954A-FBC4BF301031}“ = Nero 7 Premium
„{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}“ = SAMSUNG USB Driver for Mobile Phones
„{D0DFF92A-492E-4C40-B862-A74A173C25C5}“ = Adobe Version Cue CS3 Client
„{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}“ = Adobe PDF Library Files
„{D3C605D8-3A5E-4BAD-965D-2C61441BF2AC}“ = Adobe Photoshop CS3
„{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}“ = Adobe Color JA Extra Settings
„{DDA3C325-47B2-4730-9672-BF3771C08799}_is1“ = XMedia Recode Version 3.1.3.0
„{DF74C7BA-5C9F-4F17-8B6F-5ECE08280F34}“ = ScanSoft OmniPage 16
„{E2F2B987-F2BC-4969-95F2-92099486B811}“ = StarMoney
„{E69AE897-9E0B-485C-8552-7841F48D42D8}“ = Adobe Update Manager CS3
„{E78BFA60-5393-4C38-82AB-E8019E464EB4}“ = Microsoft .NET Framework 1.1 German Language Pack
„{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}“ = Adobe InDesign CS3 Icon Handler
„{EAC2DDAB-5035-44EE-AA13-65D40CF46FF1}“ = Kabel Deutschland Installations-Software
„{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}“ = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
„{F251B999-08A9-4704-999C-9962F0DFD88E}“ = Virtual Desktop Manager Powertoy for Windows XP
„{F3586612-687E-4F67-B070-CB511E18B5B3}“ = calibre
„{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}“ = Microsoft Office Live Add-in 1.5
„{F750C986-5310-3A5A-95F8-4EC71C8AC01C}“ = Microsoft .NET Framework 4 Client Profile DEU Language Pack
„{F7DAC756-8358-484B-928C-457F4E0E4B82}“ = Cherry Smart Device Package V1.10 Build 4
„{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}“ = Adobe Color NA Extra Settings
„1PW“ = 1PW Passwortverwaltung
„7-Zip“ = 7-Zip 9.20
„ac‘tivAid“ = ac‘tivAid v1.3.2.dev42
„Adobe Acrobat 8 Professional - English, Français, Deutsch“ = Adobe Acrobat 8.3.1 Professional
„Adobe Acrobat 8 Professional - English, Français, Deutsch_831“ = Adobe Acrobat 8.3.1 - CPSID_83708
„Adobe Flash Player Plugin“ = Adobe Flash Player 11 Plugin
„Adobe_25db75244653b42cb93dc27939d1c0e“ = Adobe Dreamweaver CS3
„Adobe_3e054d2218e7aa282c2369d939e58ff“ = Adobe ExtendScript Toolkit 2
„Adobe_6c8e2cb4fd241c55406016127a6ab2e“ = Adobe Color Common Settings
„Adobe_c5cbed37a01f242ac41d8f4528b7a0d“ = Adobe Creative Suite 3 Design Standard hinzufügen oder entfernen
„AnyDVD“ = AnyDVD
„AquaSoft DiaShow Studio 6“ = AquaSoft DiaShow Studio 6
„AutoHotkey“ = AutoHotkey 1.0.48.05
„AVMFBox“ = AVM FRITZ!Box Dokumentation
„AVMFBoxPrinter“ = AVM FRITZ!Box Druckeranschluss
„Bitdefender“ = Bitdefender Antivirus Plus 2012
„CCleaner“ = CCleaner
„CloneCD“ = CloneCD
„Converber“ = Converber 2.3.1
„Defraggler“ = Defraggler
„Digitale Bibliothek 4“ = Digitale Bibliothek 4
„DYMO Label v.8“ = DYMO Label v.8
„eminecMYmap“ = eminec MYmap v.5
„EPSON Scanner“ = EPSON Scan
„FileZilla Client“ = FileZilla Client 3.5.3
„FreeFileSync“ = FreeFileSync 5.12
„HECI“ = Intel(R) Management Engine Interface
„Helicon Filter_is1“ = Helicon Filter 4.93.2
„ie8“ = Windows Internet Explorer 8
„IHMC CmapTools v5.04.02“ = IHMC CmapTools v5.04.02
„Kabel Deutschland Installations-Software“ = Kabel Deutschland Installations-Software
„Lexmark S300-S400 Series“ = Lexmark S300-S400 Series
„LimanPro1“ = Liman Pro 1.0
„MapCreator 2“ = MapCreator 2
„Matrox XPDM Uninstaller“ = Matrox Driver
„Microsoft .NET Framework 1.1 (1033)“ = Microsoft .NET Framework 1.1
„Microsoft .NET Framework 4 Client Profile“ = Microsoft .NET Framework 4 Client Profile
„Microsoft .NET Framework 4 Client Profile DEU Language Pack“ = Microsoft .NET Framework 4 Client Profile DEU Language Pack
„Microsoft .NET Framework 4 Extended“ = Microsoft .NET Framework 4 Extended
„Microsoft .NET Framework 4 Extended DEU Language Pack“ = Microsoft .NET Framework 4 Extended DEU Language Pack
„MozBackup“ = MozBackup 1.4.10
„Mozilla Firefox 19.0.2 (x86 de)“ = Mozilla Firefox 19.0.2 (x86 de)
„Mozilla Thunderbird 17.0.3 (x86 de)“ = Mozilla Thunderbird 17.0.3 (x86 de)
„MozillaMaintenanceService“ = Mozilla Maintenance Service
„MSCompPackV1“ = Microsoft Compression Client Pack 1.0 for Windows XP
„MSNINST“ = MSN
„Papyrus Autor“ = Papyrus Autor -- from R.O.M. logicware GmbH
„Personal Backup 5_is1“ = Personal Backup 5.4
„PhotoZoom Pro 2“ = BenVista PhotoZoom Pro 2.2.8
„PhotoZoom Professional“ = PhotoZoom Professional 1.2.2
„PhraseExpress_is1“ = PhraseExpress v9.0.156
„PPTminimizer 2006_is1“ = PPTminimizer 2006
„Q-Dir“ = Q-Dir
„Recuva“ = Recuva
„ROM Papyrus Autor“ = Papyrus Autor 3.53
„Sandboxie“ = Sandboxie 3.76 (32-bit)
„SilverFast Epson“ = SilverFast Epson 6.6.2r4
„SilverFast Epson TWAIN_is1“ = SilverFast Epson TWAIN
„Speccy“ = Speccy
„SpeedCommander 14“ = SpeedCommander 14
„SumatraPDF“ = SumatraPDF 2.2.1
„Typograf“ = Typograf4.8f
„Unlocker“ = Unlocker 1.9.0
„VLC media player“ = VLC media player 1.1.11
„Wdf01009“ = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
„WebSpider2“ = Xaldon WebSpider2
„Windows Media Format Runtime“ = Windows Media Format 11 runtime
„Windows Media Player“ = Windows Media Player 11
„Windows XP Service Pack“ = Windows XP Service Pack 3
„WMFDist11“ = Windows Media Format 11 runtime
„wmp11“ = Windows Media Player 11
„Wudf01000“ = Microsoft User-Mode Driver Framework Feature Pack 1.0
„XMedia Recode“ = XMedia Recode 3.0.8.5
„XPSEPSCLP“ = XML Paper Specification Shared Components Language Pack 1.0
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1659004503-879983540-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
„Dropbox“ = Dropbox
„MyFreeCodec“ = MyFreeCodec
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 02.03.2013 15:08:03 | Computer Name = SACHFACH | Source = Windows Search Service | ID = 3013
Description = Eintrag <C:\DOKUMENTE UND EINSTELLUNGEN\GERHARD ADMIN\RECENT\ZUCHT
DEVARIO SHANENSIS.PAP.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.
Kontext:
Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät
funktioniert nicht. (0x8007001f)
Error - 03.03.2013 18:05:48 | Computer Name = SACHFACH | Source = NTBackup | ID = 8001
Description = Ende der Sicherung von ‚E:‘ ‚Es wurden Warnungen oder Fehler gefunden.‘
Überprüfen:
Off Modus: Append Typ: Normal Einzelheiten finden Sie im Sicherungsbericht.
Error - 03.03.2013 18:05:48 | Computer Name = SACHFACH | Source = NTBackup | ID = 8019
Description = Vorgang beenden: Es wurden Warnungen oder Fehler gefunden. Weitere
Informationen finden Sie im Sicherungsbericht.
Error - 04.03.2013 06:48:35 | Computer Name = SACHFACH | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung Persbackup.exe, Version 5.4.3.2, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 04.03.2013 11:11:27 | Computer Name = SACHFACH | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung Photoshop.exe, Version 10.0.1.0, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 04.03.2013 11:26:41 | Computer Name = SACHFACH | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung Foxit Reader.exe, Version 4.3.0.1110, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 06.03.2013 08:55:22 | Computer Name = SACHFACH | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung firefox.exe, Version 19.0.0.4794, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 07.03.2013 16:02:01 | Computer Name = SACHFACH | Source = EventSystem | ID = 4614
Description = Das COM+-Ereignissystem hat eine Inkonsistenz in seinem internen Status
erkannt. Fehler bei der Assertion „GetLastError() == 122L“ in Zeile 162 von d:\comxp_sp3\com\com1x\src\events\shared\sectools.cpp.
Wenden Sie sich an den Microsoft-Produktsuppor
Error - 07.03.2013 16:02:06 | Computer Name = SACHFACH | Source = crypt32 | ID = 131080
Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer
von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
ist fehlgeschlagen mit dem Fehler: The server name or address could not be resolved
.
Error - 08.03.2013 23:11:44 | Computer Name = SACHFACH | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung adwcleaner.exe, Version 2.1.1.4, fehlgeschlagenes
Modul unknown, Version 0.0.0.0, Fehleradresse 0x18805312.
[ System Events ]
Error - 08.03.2013 10:29:18 | Computer Name = SACHFACH | Source = sbp2port | ID = 262153
Description = Das Gerät hat innerhalb der Fehlerwartezeit nicht geantwortet.
Error - 08.03.2013 10:29:33 | Computer Name = SACHFACH | Source = sbp2port | ID = 262153
Description = Das Gerät hat innerhalb der Fehlerwartezeit nicht geantwortet.
Error - 08.03.2013 10:29:48 | Computer Name = SACHFACH | Source = sbp2port | ID = 262153
Description = Das Gerät hat innerhalb der Fehlerwartezeit nicht geantwortet.
Error - 08.03.2013 10:30:03 | Computer Name = SACHFACH | Source = sbp2port | ID = 262153
Description = Das Gerät hat innerhalb der Fehlerwartezeit nicht geantwortet.
Error - 08.03.2013 10:30:18 | Computer Name = SACHFACH | Source = sbp2port | ID = 262153
Description = Das Gerät hat innerhalb der Fehlerwartezeit nicht geantwortet.
Error - 08.03.2013 11:02:14 | Computer Name = SACHFACH | Source = Service Control Manager | ID = 7009
Description = Zeitüberschreitung (30000 ms) beim Verbindungsversuch mit Dienst lxeaCATSCustConnectService.
Error - 08.03.2013 11:02:14 | Computer Name = SACHFACH | Source = Service Control Manager | ID = 7000
Description = Der Dienst „lxeaCATSCustConnectService“ wurde aufgrund folgenden Fehlers
nicht gestartet: %%1053
Error - 08.03.2013 23:18:22 | Computer Name = SACHFACH | Source = Service Control Manager | ID = 7009
Description = Zeitüberschreitung (30000 ms) beim Verbindungsversuch mit Dienst lxeaCATSCustConnectService.
Error - 08.03.2013 23:18:22 | Computer Name = SACHFACH | Source = Service Control Manager | ID = 7000
Description = Der Dienst „lxeaCATSCustConnectService“ wurde aufgrund folgenden Fehlers
nicht gestartet: %%1053
Error - 08.03.2013 23:18:22 | Computer Name = SACHFACH | Source = Service Control Manager | ID = 7009
Description = Zeitüberschreitung (30000 ms) beim Verbindungsversuch mit Dienst StarMoney
8.0 OnlineUpdate.
< End of Report > |