ESET log: Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=b612a645083f7c459a5796485a0f0e47
# engine=14286
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-06 12:36:16
# local_time=2013-07-06 02:36:16 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1799 16775165 100 100 16367 238494266 9143 0
# compatibility_mode=5893 16776573 100 94 60865 124702167 0 0
# scanned=268800
# found=3
# cleaned=0
# scan_time=14582
sh=67D181F0D9FEC6690C0AE4C606DEA14A5C0E6CDD ft=1 fh=3b21a895403b5dee vn="multiple threats" ac=I fn="C:\Users\abc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\909DP3XR\WebCakesetup[1].exe"
sh=C67F6FE42E785BBBC2D88DBE179C536A72A6B201 ft=0 fh=0000000000000000 vn="HTML/ScrInject.B.Gen virus" ac=I fn="C:\Users\abc\AppData\Local\Mozilla\Firefox\Profiles\ci9dlxw2.default\Cache\9\F6\B2625d01"
sh=ADB0754D6A634043EBE0228D318686C3AFF7018F ft=1 fh=74fb63aaf4af7151 vn="a variant of Win32/SpeedingUpMyPC.B application" ac=I fn="C:\Users\abc\AppData\Local\Temp\DM\BygnNqs37vPIh87\software\OptimizerPro.exe"
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=b612a645083f7c459a5796485a0f0e47
# engine=14289
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-06 02:54:10
# local_time=2013-07-06 04:54:10 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1799 16775165 100 100 67841 238545740 60617 0
# compatibility_mode=5893 16776573 100 94 112339 124753641 0 0
# scanned=356356
# found=2
# cleaned=0
# scan_time=17457
sh=67D181F0D9FEC6690C0AE4C606DEA14A5C0E6CDD ft=1 fh=3b21a895403b5dee vn="multiple threats" ac=I fn="C:\Users\abc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\909DP3XR\WebCakesetup[1].exe"
sh=ADB0754D6A634043EBE0228D318686C3AFF7018F ft=1 fh=74fb63aaf4af7151 vn="a variant of Win32/SpeedingUpMyPC.B application" ac=I fn="C:\Users\abc\AppData\Local\Temp\DM\BygnNqs37vPIh87\software\OptimizerPro.exe" security check log Code:
Results of screen317's Security Check version 0.99.68
Windows 7 Service Pack 1 x86 (UAC is enabled) ``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date! `````````Anti-malware/Other Utilities Check:`````````
CCleaner
Java 7 Update 10
Java version out of Date!
Adobe Flash Player 11.7.700.202
Adobe Reader 10.1.7 Adobe Reader out of Date!
Mozilla Firefox (22.0) ````````Process Check: objlist.exe by Laurent````````
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
TVG DasTelefonbuch GelbeSeiten Map & Route win32 officemanager\OMAlarm.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` OTL log Code:
OTL logfile created on: 06.07.2013 18:03:42 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\abc\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,99 Gb Total Physical Memory | 1,24 Gb Available Physical Memory | 41,49% Memory free
5,98 Gb Paging File | 4,21 Gb Available in Paging File | 70,48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 285,47 Gb Total Space | 159,09 Gb Free Space | 55,73% Space Free | Partition Type: NTFS
Computer Name: abc-PC | User Name: abc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Processes (SafeList) ==========
PRC - C:\Users\abc\Desktop\OTL(1).exe (OldTimer Tools)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe (Adobe Systems, Inc.)
PRC - C:\Programme\Adobe\Reader 10.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Synaptics\Scrybe\Service\ScrybeUpdater.exe (Synaptics, Inc.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Programme\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
PRC - C:\Windows\OEM04Mon.exe (Creative Technology Ltd.)
PRC - C:\Programme\TVG\DasTelefonbuch GelbeSeiten Map & Route\win32\officemanager\OMAlarm.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Programme\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
MOD - C:\Users\abc\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_weblink.DEU ()
MOD - C:\Users\abc\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_Updater.DEU ()
MOD - C:\Users\abc\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_EScript.DEU ()
MOD - C:\Users\abc\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_rdlang32.deu ()
MOD - C:\Programme\Adobe\Reader 10.0\Reader\sqlite.dll ()
MOD - C:\Programme\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Programme\OpenOffice.org 3\program\libxslt.dll ()
MOD - C:\Programme\TVG\DasTelefonbuch GelbeSeiten Map & Route\win32\officemanager\OMAlarm.exe ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (vpnagent) -- C:\Programme\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (ServiceLayer) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (ScrybeUpdater) -- C:\Programme\Synaptics\Scrybe\Service\ScrybeUpdater.exe (Synaptics, Inc.)
SRV - (wlidsvc) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) -- C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (odserv) -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (catchme) -- C:\Users\abc\AppData\Local\Temp\catchme.sys File not found
DRV - (vpnva) -- C:\Windows\System32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (acsock) -- C:\Windows\System32\drivers\acsock.sys (Cisco Systems, Inc.)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (VSPerfDrv100) -- C:\Programme\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys (Microsoft Corporation)
DRV - (netw5v32) -- C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (OEM04Vid) -- C:\Windows\System32\drivers\OEM04Vid.sys (Creative Technology Ltd.)
DRV - (OEM04Vfx) -- C:\Windows\System32\drivers\OEM04Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 D3 A3 17 3B F7 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.07.03 09:59:03 | 000,000,000 | ---D | M]
[2011.10.17 08:43:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\abc\AppData\Roaming\mozilla\Extensions
[2013.06.22 11:28:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\abc\AppData\Roaming\mozilla\Firefox\Profiles\ci9dlxw2.default\extensions
[2013.07.03 09:59:03 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\Extensions
[2013.07.03 09:59:03 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\browser\extensions
[2013.07.03 09:59:08 | 000,000,000 | ---D | M] (Default) -- C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Microsoft-Webtestaufzeichnung 10.0-Hilfsprogramm) - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Programme\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [OEM04Mon.exe] C:\Windows\OEM04Mon.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil32_11_7_700_202_Plugin.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1 [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\abc\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{42F893E3-E64D-4DC7-9973-E0F30DD02CCC}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{42F893E3-E64D-4DC7-9973-E0F30DD02CCC}: NameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{74558793-B7E4-4C2A-A12D-670F0DDE9738}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 60 Days ==========
[2013.07.06 18:01:59 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\abc\Desktop\OTL(1).exe
[2013.07.03 09:59:02 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.06.29 00:18:18 | 000,000,000 | ---D | C] -- C:\Users\abc\Documents\7-PDF Split & Merge
[2013.06.29 00:18:08 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\7-PDFSplitMerge
[2013.06.29 00:18:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-PDF
[2013.06.29 00:18:08 | 000,000,000 | ---D | C] -- C:\Program Files\7-PDF
[2013.06.26 19:13:42 | 000,000,000 | ---D | C] -- C:\Users\abc\.pdfsam
[2013.06.25 22:38:55 | 000,000,000 | ---D | C] -- C:\Users\abc\Documents\BMW Stellenangebote
[2013.06.24 19:52:17 | 000,000,000 | ---D | C] -- C:\Users\abc\Desktop\Elektr. Straßenfahrzeuge
[2013.06.22 11:37:52 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013.06.22 11:37:45 | 000,000,000 | ---D | C] -- C:\JRT
[2013.06.22 11:37:08 | 000,545,954 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\abc\Desktop\JRT.exe
[2013.06.22 11:23:54 | 000,000,000 | ---D | C] -- C:\Program Files\Uninstaller
[2013.06.22 11:19:36 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2013.06.20 20:17:07 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.06.20 19:54:54 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2013.06.20 19:54:44 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.06.20 19:54:44 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.06.20 19:54:44 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.06.20 19:54:25 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.06.20 19:54:02 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.06.20 19:52:15 | 005,081,444 | R--- | C] (Swearware) -- C:\Users\abc\Desktop\ComboFix.exe
[2013.06.20 18:01:46 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\abc\Desktop\tdsskiller.exe
[2013.06.19 11:45:04 | 000,000,000 | ---D | C] -- C:\b2643e4de09278eb733fb9
[2013.06.16 13:57:27 | 000,000,000 | ---D | C] -- C:\Users\abc\Desktop\EM Felder Biomedizin
[2013.06.12 18:21:54 | 000,000,000 | ---D | C] -- C:\Users\abc\Desktop\3.Semester (Master)
[2013.06.12 11:24:07 | 001,505,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
[2013.06.12 11:24:03 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cryptdlg.dll
[2013.06.12 11:23:56 | 000,903,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certutil.exe
[2013.06.12 11:23:55 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certenc.dll
[2013.06.12 11:23:46 | 000,627,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.06.12 11:23:45 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.06.12 11:23:45 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.06.12 11:23:45 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.06.12 11:23:44 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.06.12 11:23:42 | 003,968,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2013.06.12 11:23:42 | 003,913,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013.06.10 19:04:40 | 000,000,000 | ---D | C] -- C:\Users\abc\Desktop\Gassensorik
[2013.06.05 21:27:04 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\assembly
[2013.05.30 21:13:10 | 000,000,000 | ---D | C] -- C:\Users\abc\Desktop\ElectricalMachinesSoftware
[2013.05.30 20:14:04 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\Microsoft Corporation
[2013.05.30 19:56:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Sync Framework
[2013.05.30 19:55:48 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
[2013.05.30 19:55:35 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Synchronization Services
[2013.05.30 19:53:30 | 000,000,000 | ---D | C] -- C:\ProgramData\PreEmptive Solutions
[2013.05.30 19:49:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 3 SDK - Deutsch
[2013.05.30 19:49:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2013.05.30 19:45:23 | 000,000,000 | ---D | C] -- C:\Program Files\IIS
[2013.05.30 19:44:04 | 000,000,000 | ---D | C] -- C:\Users\abc\Documents\Visual Studio 2008
[2013.05.30 19:31:01 | 000,000,000 | ---D | C] -- C:\Windows\symbols
[2013.05.30 19:29:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2010
[2013.05.30 19:29:45 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Help Viewer
[2013.05.30 19:29:45 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft F#
[2013.05.30 19:29:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Merge Modules
[2013.05.30 19:29:45 | 000,000,000 | ---D | C] -- C:\Program Files\HTML Help Workshop
[2013.05.30 19:22:08 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 9.0
[2013.05.29 10:34:38 | 000,000,000 | ---D | C] -- C:\Users\abc\Documents\Visual Studio 2012
[2013.05.29 10:29:16 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2013.05.29 10:23:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ASP.NET
[2013.05.29 10:18:20 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll
[2013.05.29 10:17:34 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Kits
[2013.05.29 10:10:02 | 000,000,000 | ---D | C] -- C:\Windows\System32\1033
[2013.05.29 10:10:02 | 000,000,000 | ---D | C] -- C:\Windows\System32\1031
[2013.05.29 10:03:43 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SDKs
[2013.05.29 10:01:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 11.0
[2013.05.28 23:21:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2013.05.28 22:24:36 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\e-academy Inc
[2013.05.28 22:24:36 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\e-academy Inc
[2013.05.22 21:40:50 | 000,000,000 | ---D | C] -- C:\Users\abc\Desktop\TUM-WIN
[2013.05.20 10:09:33 | 000,000,000 | ---D | C] -- C:\Users\abc\Desktop\Speicherkarte Bilder 20-5-13
[2013.05.15 23:51:38 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wwanprotdim.dll
[2013.05.15 23:51:36 | 002,347,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013.05.15 23:51:20 | 000,218,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2013.05.15 23:51:06 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
[2013.05.15 23:51:06 | 000,101,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
========== Files - Modified Within 60 Days ==========
[2013.07.06 18:02:03 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\abc\Desktop\OTL(1).exe
[2013.07.06 17:33:51 | 000,013,624 | ---- | M] () -- C:\Users\abc\Desktop\security check log (wieder löschen).odt
[2013.07.06 17:33:50 | 000,000,098 | -H-- | M] () -- C:\Users\abc\Desktop\.~lock.security check log (wieder löschen).odt#
[2013.07.06 17:00:31 | 000,021,987 | ---- | M] () -- C:\Users\abc\Desktop\ESET log.odt
[2013.07.06 17:00:29 | 000,000,098 | -H-- | M] () -- C:\Users\abc\Desktop\.~lock.ESET log.odt#
[2013.07.06 13:01:40 | 000,000,546 | ---- | M] () -- C:\Windows\tasks\MATLAB R2011b Startup Accelerator.job
[2013.07.06 11:39:01 | 000,013,984 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.06 11:39:01 | 000,013,984 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.06 11:30:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.06 11:30:36 | 2408,087,552 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.05 22:32:26 | 000,699,666 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.07.05 22:32:26 | 000,654,464 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.07.05 22:32:26 | 000,149,774 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.07.05 22:32:26 | 000,122,336 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.07.02 20:06:21 | 000,022,384 | ---- | M] () -- C:\Users\abc\Desktop\Namensänderung.odt
[2013.07.01 10:14:30 | 000,094,084 | ---- | M] () -- C:\Users\abc\Documents\Felder_Biomedizin_Klausur_WS11_12.pdf
[2013.06.29 00:18:09 | 000,001,202 | ---- | M] () -- C:\Users\Public\Desktop\7-PDF Split & Merge.lnk
[2013.06.23 14:42:16 | 000,001,017 | ---- | M] () -- C:\Users\abc\Desktop\Dropbox.lnk
[2013.06.22 11:37:16 | 000,545,954 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\abc\Desktop\JRT.exe
[2013.06.22 11:25:41 | 000,648,201 | ---- | M] () -- C:\Users\abc\Desktop\adwcleaner.exe
[2013.06.20 19:52:24 | 005,081,444 | R--- | M] (Swearware) -- C:\Users\abc\Desktop\ComboFix.exe
[2013.06.20 18:16:12 | 343,254,034 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013.06.20 18:02:15 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\abc\Desktop\tdsskiller.exe
[2013.06.11 17:57:46 | 000,005,120 | ---- | M] () -- C:\Users\abc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.06.10 19:00:41 | 000,128,172 | ---- | M] () -- C:\Users\abc\Documents\Prüfanmeldung Energieversorgung lib Markt.PNG
[2013.06.09 18:20:27 | 000,234,202 | ---- | M] () -- C:\Users\abc\Desktop\Stdplan 3.Semester.pdf
[2013.06.08 15:14:17 | 001,199,463 | ---- | M] () -- C:\Users\abc\Desktop\TUM Create.pdf
[2013.05.30 13:20:11 | 000,037,496 | ---- | M] () -- C:\Users\abc\Documents\Key Visual Studio 2010 Ultimate.PNG
[2013.05.29 11:18:58 | 003,863,400 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.05.28 23:03:09 | 000,037,612 | ---- | M] () -- C:\Users\abc\Documents\Key Visual Studio 2010 Professiobal.PNG
[2013.05.28 22:36:43 | 000,045,223 | ---- | M] () -- C:\Users\abc\Documents\Key Windows8 und Visual Studio Ultimate.PNG
[2013.05.28 22:24:36 | 000,003,139 | ---- | M] () -- C:\Users\abc\Desktop\Secure Download Manager.lnk
[2013.05.28 22:21:19 | 000,034,685 | ---- | M] () -- C:\Users\abc\Documents\Key Microsoft Visual Studio.PNG
[2013.05.28 21:47:05 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013.05.28 21:47:05 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013.05.20 00:21:34 | 000,357,138 | ---- | M] () -- C:\Users\abc\Documents\asos bestell 2.PNG
[2013.05.16 20:21:34 | 000,132,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.05.16 20:18:22 | 000,627,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.05.16 20:17:32 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.05.16 20:17:14 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.05.16 18:44:21 | 001,638,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.05.13 05:08:10 | 000,903,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\certutil.exe
[2013.05.13 05:08:06 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\certenc.dll
[2013.05.10 05:20:54 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptdlg.dll
========== Files Created - No Company Name ==========
[2013.07.06 17:33:50 | 000,000,098 | -H-- | C] () -- C:\Users\abc\Desktop\.~lock.security check log (wieder löschen).odt#
[2013.07.06 17:33:49 | 000,013,624 | ---- | C] () -- C:\Users\abc\Desktop\security check log (wieder löschen).odt
[2013.07.06 17:00:29 | 000,000,098 | -H-- | C] () -- C:\Users\abc\Desktop\.~lock.ESET log.odt#
[2013.07.06 17:00:27 | 000,021,987 | ---- | C] () -- C:\Users\abc\Desktop\ESET log.odt
[2013.07.02 18:27:57 | 000,022,384 | ---- | C] () -- C:\Users\abc\Desktop\Namensänderung.odt
[2013.07.01 10:14:53 | 000,094,084 | ---- | C] () -- C:\Users\abc\Documents\Felder_Biomedizin_Klausur_WS11_12.pdf
[2013.06.29 00:18:09 | 000,001,202 | ---- | C] () -- C:\Users\Public\Desktop\7-PDF Split & Merge.lnk
[2013.06.22 11:25:34 | 000,648,201 | ---- | C] () -- C:\Users\abc\Desktop\adwcleaner.exe
[2013.06.20 19:54:44 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.06.20 19:54:44 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.06.20 19:54:44 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.06.20 19:54:44 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.06.20 19:54:44 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.06.10 19:00:41 | 000,128,172 | ---- | C] () -- C:\Users\abc\Documents\Prüfanmeldung Energieversorgung lib Markt.PNG
[2013.06.09 18:20:27 | 000,234,202 | ---- | C] () -- C:\Users\abc\Desktop\Stdplan 3.Semester.pdf
[2013.06.08 15:14:16 | 001,199,463 | ---- | C] () -- C:\Users\abc\Desktop\TUM Create.pdf
[2013.05.30 13:20:11 | 000,037,496 | ---- | C] () -- C:\Users\abc\Documents\Key Visual Studio 2010 Ultimate.PNG
[2013.05.28 23:03:09 | 000,037,612 | ---- | C] () -- C:\Users\abc\Documents\Key Visual Studio 2010 Professiobal.PNG
[2013.05.28 22:36:43 | 000,045,223 | ---- | C] () -- C:\Users\abc\Documents\Key Windows8 und Visual Studio Ultimate.PNG
[2013.05.28 22:24:36 | 000,003,139 | ---- | C] () -- C:\Users\abc\Desktop\Secure Download Manager.lnk
[2013.05.28 22:21:19 | 000,034,685 | ---- | C] () -- C:\Users\abc\Documents\Key Microsoft Visual Studio.PNG
[2013.05.20 00:21:34 | 000,357,138 | ---- | C] () -- C:\Users\abc\Documents\asos bestell 2.PNG
[2012.04.01 10:37:33 | 000,000,297 | ---- | C] () -- C:\Users\abc\K_Clusterzentren.mat
[2012.03.11 14:46:56 | 000,000,337 | ---- | C] () -- C:\Users\abc\AppData\Local\Perfmon.PerfmonCfg
[2012.02.08 23:45:41 | 000,003,728 | ---- | C] () -- C:\Users\abc\.Xauthority
[2011.12.19 02:54:55 | 000,005,120 | ---- | C] () -- C:\Users\abc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.11.13 12:41:02 | 000,125,952 | ---- | C] () -- C:\Windows\System32\ZLhp2600.DLL
[2011.11.13 12:40:26 | 000,337,920 | ---- | C] () -- C:\Windows\System32\ZSHP2600.EXE
[2011.11.06 20:39:00 | 000,212,992 | ---- | C] () -- C:\Windows\System32\WMIMPLEX.dll
[2011.11.06 20:39:00 | 000,031,744 | ---- | C] () -- C:\Windows\System32\maplec.dll
[2011.11.06 20:39:00 | 000,020,480 | ---- | C] () -- C:\Windows\System32\maplecompat.dll
[2011.10.18 15:10:54 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.10.17 14:32:32 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2011.10.17 09:03:19 | 000,000,076 | RHS- | C] () -- C:\Windows\CT4CET.bin
========== ZeroAccess Check ==========
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report > OTL log 2 Code:
OTL Extras logfile created on: 06.07.2013 18:03:42 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\abc\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,99 Gb Total Physical Memory | 1,24 Gb Available Physical Memory | 41,49% Memory free
5,98 Gb Paging File | 4,21 Gb Available in Paging File | 70,48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 285,47 Gb Total Space | 159,09 Gb Free Space | 55,73% Space Free | Partition Type: NTFS
Computer Name: abc-PC | User Name: abc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1 -- [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1 -- [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1 -- [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1 -- [2011.12.05 01:05:29 | 000,000,000 | ---D | M]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0670BFC8-E329-4575-ACF4-8A106B473EBF}" = rport=137 | protocol=17 | dir=out | app=system |
"{1C00987B-D0C8-4D80-966E-93B7AEE3E81A}" = rport=445 | protocol=6 | dir=out | app=system |
"{219EC414-108D-4AEE-A36E-A1B9CF45EF30}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{22FA8EE2-E6AD-473F-9D82-E716F4DE4851}" = lport=138 | protocol=17 | dir=in | app=system |
"{2D58E453-F32A-486B-A504-724ABABCD248}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{398945FF-607B-4AB0-B185-62BB1D4000D4}" = rport=138 | protocol=17 | dir=out | app=system |
"{4702CFAE-9947-44A5-8F3B-1E41FB122025}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{63E85681-1346-4050-AFCA-AE71CED77A2F}" = rport=139 | protocol=6 | dir=out | app=system |
"{81677B64-C732-4D26-84A2-6E1BC6889614}" = lport=137 | protocol=17 | dir=in | app=system |
"{A03B5B71-1A13-468A-9C46-8757EFF3A595}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B07EBCE6-5275-4C20-81CA-47F8A73411BC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B7BBA457-2B4B-40D9-928D-EAE19FE53CAB}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{D52CCBD5-C859-41C1-BC73-42F520C0641C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{ED7702F0-E5F6-4803-9E2E-0ADD31F02D5E}" = lport=445 | protocol=6 | dir=in | app=system |
"{F5AED12D-193A-452C-B188-6E3E48CFB08A}" = lport=139 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01C9A587-2BB3-4330-90C9-030506B7C011}" = protocol=6 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe |
"{040D999E-C07B-4060-8FA6-39AD54331750}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{116953CC-48BB-4768-BA13-9C77E5B8928B}" = protocol=17 | dir=in | app=c:\program files\nx client for windows\bin\nxssh.exe |
"{20EDCEDB-487F-44A6-8A29-2E62502C069D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{253A0745-BA39-43C8-8C47-2BD45F5F79E3}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{3C73740A-3898-4B4B-969A-6D5F713F4EBF}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{505A88E9-C33C-4CF3-BECF-010B591D265D}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{61278E0D-2BA6-4D6C-A83A-62D26D14813C}" = protocol=6 | dir=in | app=c:\users\abc\appdata\roaming\dropbox\bin\dropbox.exe |
"{6773560A-9DF6-4791-BD0D-FF8D04459940}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{68576115-3B22-4BAA-93A0-783CA603FE49}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{6AEED965-009D-4381-A43E-BD2D09D53795}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{6B650CC9-B5C2-4487-8C47-2FDC61EE2471}" = protocol=6 | dir=in | app=c:\windows\system32\msiexec.exe |
"{6BD1C00B-9D80-4901-A23A-40FC5512D152}" = protocol=17 | dir=in | app=c:\users\abc\appdata\roaming\dropbox\bin\dropbox.exe |
"{70995E8C-99E4-4EB9-820A-2C6E202F55F3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{798E5472-1C99-4D25-B6EB-963FDC644FEC}" = protocol=6 | dir=in | app=c:\program files\nx client for windows\nxclient.exe |
"{85EBC0DC-2FB1-4BF3-9D81-0C6CCAFBDBA7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{8886D9A7-5550-4290-8DEF-7489CAC0ACB0}" = protocol=17 | dir=in | app=c:\program files\nx client for windows\nxclient.exe |
"{8F877195-E571-4466-B6A3-225403D75E88}" = protocol=17 | dir=in | app=c:\windows\system32\msiexec.exe |
"{95876E26-1CC1-4B8C-8BB0-6F8EF7A3AD8D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{A90285E4-E02F-4E67-A09D-B62F223A9A1E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{AF8945A8-8598-41E9-94E6-13CE71B9B06D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C9A24375-4E43-4EF8-BD09-E69C04548A7B}" = protocol=17 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe |
"{E39825D2-4837-4406-8FE6-18B35F6CCF21}" = protocol=6 | dir=in | app=c:\program files\nx client for windows\bin\nxssh.exe |
"{F11DFAA6-191E-453E-998E-4E00F65AB740}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{60AB7808-FC2F-4EDA-A8DD-BA5DFEBAE3F5}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{6BBC8E17-2737-4571-AF0C-E4C495ABE1A3}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{74638EEA-4C6E-4179-B5F9-1C07AA1E2803}C:\program files\microsoft games\age of empires iii\age3.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"TCP Query User{8EB12B1B-82F8-41E6-A8A1-E4AC8CF66220}C:\program files\nx client for windows\bin\nxssh.exe" = protocol=6 | dir=in | app=c:\program files\nx client for windows\bin\nxssh.exe |
"TCP Query User{99D8FA21-41EA-487D-9082-7B00C840E263}C:\program files\maple 14\jre\bin\maple.exe" = protocol=6 | dir=in | app=c:\program files\maple 14\jre\bin\maple.exe |
"TCP Query User{CC37514B-29C4-4ED6-80F5-B10D11D5FE40}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{F25D2FB3-AB11-4B15-9D71-456AC6B95884}C:\program files\maple 14\jre\bin\maple.exe" = protocol=6 | dir=in | app=c:\program files\maple 14\jre\bin\maple.exe |
"TCP Query User{F3DC652E-01F0-4C80-9BE9-0BD8893675A1}C:\program files\nx client for windows\nxclient.exe" = protocol=6 | dir=in | app=c:\program files\nx client for windows\nxclient.exe |
"UDP Query User{161B8598-5433-428A-839A-0531930AB570}C:\program files\nx client for windows\bin\nxssh.exe" = protocol=17 | dir=in | app=c:\program files\nx client for windows\bin\nxssh.exe |
"UDP Query User{1E611272-2B6A-42CA-A5D2-93E38E05F715}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{44033CB0-A245-4FD8-976F-BEC669E77374}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{5E65C8BC-9551-4089-B38C-8D1292EE7B00}C:\program files\nx client for windows\nxclient.exe" = protocol=17 | dir=in | app=c:\program files\nx client for windows\nxclient.exe |
"UDP Query User{7F9CE1F0-74CE-453E-B53C-794C48E58048}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{8D9E9534-AFA0-442E-A97C-F88A95244019}C:\program files\maple 14\jre\bin\maple.exe" = protocol=17 | dir=in | app=c:\program files\maple 14\jre\bin\maple.exe |
"UDP Query User{C5297E67-8BCB-488B-8312-EDA510AC288F}C:\program files\microsoft games\age of empires iii\age3.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"UDP Query User{FB849A29-7232-443D-9440-EA0C69530F4D}C:\program files\maple 14\jre\bin\maple.exe" = protocol=17 | dir=in | app=c:\program files\maple 14\jre\bin\maple.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0125D081-30D0-4A97-82A8-C28D444B6256}" = Microsoft SQL Server Compact 3.5 SP2 DEU
"{035400A4-29BD-3723-BEED-E2718A68CDE0}" = Microsoft Visual Studio 2010 Office Developer Tools (x86)
"{03A4C6A1-26E9-4DDB-81D9-B332E5BB10AD}" = Microsoft Sync Framework SDK v1.0 SP1 de
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{147DFAD8-34C3-4DE1-9FCA-ACEFDE9EF810}" = Synaptics Gesture Suite featuring SYNAPTICS | Scrybe
"{1570DE88-A78A-37FD-8A05-92620D160CCA}" = Microsoft Visual Studio 2010 Office Developer Tools (x86) Language Pack - DEU
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{1803A630-3C38-4D2B-9B9A-0CB37243539C}" = Microsoft ASP.NET MVC 2
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1D328E11-3B0C-388C-835D-C9C20E8C7734}" = Microsoft Help Viewer 1.0 Language Pack - DEU
"{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}" = Live! Cam Avatar
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 10
"{28C7A4BB-3966-4373-8376-C11F38290630}" = Microsoft SQL Server 2012 T-SQL Language Service
"{2A3CC014-FA33-4027-AECD-9A4845223209}" = Microsoft SQL Server 2012 Native Client
"{31C3C6EA-E991-405F-A3AA-2C070CCCC47C}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools - DEU
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3A523AF9-D32F-4C85-8388-0335731F3405}" = WCF RIA Services V1.0 SP2
"{3BB19A2B-B9C5-3872-8FDF-3047CC9F9841}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
"{4135C790-0387-36D7-9C2A-1B09A5900460}" = Microsoft Visual Studio 2010 Ultimate - DEU
"{41B31ABE-5A6E-498A-8F28-3BA3B8779A41}" = Dotfuscator Software Services - Community Edition
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{47C39E4A-28F2-33B1-B9B7-97F24E52D917}" = Microsoft Help Viewer 1.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C0B27C3-3E8F-4BD2-80FF-6E9E48EBD6D8}" = Microsoft-System-CLR-Typen für SQL Server 2012
"{5242B252-01BB-4F2E-BBF4-5C01BC3B6619}" = Microsoft SQL Server 2008 R2 Data-Tier Application Project
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{5A08C9D1-37AD-4A8D-90D3-33F92C578AA5}" = Microsoft SQL Server System CLR Types
"{616C6F39-4CE1-3434-A665-2F6A04C09A7F}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}" = Microsoft ASP.NET Web Pages
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{681F4E9F-34E0-36BD-BF2C-100554E403A5}" = Microsoft Visual F# 2.0 Runtime Language Pack - DEU
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A86554B-8928-30E4-A53C-D7337689134D}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{729A3000-BC8A-3B74-BA5D-5068FE12D70C}" = Microsoft Visual F# 2.0 Runtime
"{7BEC151D-ADA9-3EA9-9273-99BA82881971}" = Microsoft Visual Studio 2010 SharePoint Developer Tools
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E7D7400-4F4F-409D-8F8A-43BF1DAC575A}" = TouchChip USB Driver 2.6
"{8EAA9D70-C912-3708-92DD-0CCC26F386E1}" = Microsoft Visual Studio 2010 Performance Collection Tools - DEU
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00B2-0407-0000-0000000FF1CE}" = Microsoft – Speichern als PDF oder XPS – Add-In für 2007 Microsoft Office-Programme
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{91F54E1D-804A-46D8-A56C-53EA9C4B3177}" = Microsoft Silverlight 3 SDK - Deutsch
"{929F5BFC-60F0-34EC-A50B-2001AAC03D56}" = Microsoft Team Foundation Server 2010 Object Model - DEU
"{92C5C058-E941-47C3-B7E8-38A79C605969}" = Microsoft SQL Server 2008 R2 Transact-SQL Language Service
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031" = Microsoft .NET Framework 4.5 DEU Language Pack
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9C3B8582-A72A-4835-8903-877A834407BB}" = Microsoft SQL Server 2008 R2-Datenebenenanwendungs-Framework
"{9D7EF9D6-212E-3C87-AB96-ED9F2A6C3218}" = Microsoft .NET Framework 4.5 DEU Language Pack
"{9F612429-4A00-3D44-88CF-146DA2EE1F92}" = Microsoft .NET Framework 4.5
"{A106D33E-6B43-42C0-9BFC-D03303261FA7}" = Microsoft SQL Server 2008 R2 Management Objects
"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer
"{A41EB7B5-8883-4795-A587-AAD8A84A010D}" = Cisco AnyConnect Secure Mobility Client
"{A57025CC-5F2E-4D01-B387-06DB10500D43}" = Nokia Connectivity Cable Driver
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA57D6F1-6360-4397-B2D9-B21C69863D97}" = Secure Download Manager
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.6
"{AC41D924-8C68-4BD5-A7A1-0AE4176C31A6}" = Crystal Reports for Visual Studio
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.7) - Deutsch
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C6379B13-1DFD-4364-9FDD-4632AA90C99D}" = O&O SafeErase Professional
"{C8773FDB-D0DB-BE52-D536-F48F9886B57B}" = Adobe Download Assistant
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CE9BAD6E-60FC-46CC-82A2-5B0F2B1A0E36}" = Dotfuscator Software Services - Community Edition - DEU
"{CFCB8616-A5D1-4281-80E8-389F685BFAE2}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6A6CFAD-CD86-482B-90D1-6FCC4E252ACD}" = Microsoft Sync Services for ADO.NET v2.0 SP1 (x86) de
"{DA5B2BDC-F654-4A88-A669-4D34BC7846A1}" = PC Connectivity Solution
"{DB0AF767-7CC7-4E4D-B6BE-A200F20A2FB1}" = Microsoft Sync Framework Runtime v1.0 SP1 (x86) de
"{DBE8431C-CF9A-38C3-B42D-28B6FCE1EA3B}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{E4E9CBC9-1CF5-48E3-AF6F-1AB44A856346}" = Microsoft ASP.NET MVC 2 - DEU
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EAF7B35C-DCBE-4032-9ABF-C35C43D07124}" = Microsoft Sync Framework Services v1.0 SP1 (x86) de
"{EC66418E-DAA2-36D5-809E-40BEC94E622A}" = Microsoft Visual Studio Macro Tools - DEU Language Pack
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"5513-1208-7298-9440" = JDownloader 0.9
"7-PDF Split & Merge_is1" = 7-PDF Split & Merge Version 2.1.0 (Build 128)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced Video FX Engine" = Advanced Video FX Engine
"Avira AntiVir Desktop" = Avira Free Antivirus
"CCleaner" = CCleaner
"Cisco AnyConnect Secure Mobility Client" = Cisco AnyConnect Secure Mobility Client
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Creative OEM004" = Laptop Integrated Webcam Driver (1.03.01.1011)
"DasTelefonbuch GelbeSeiten Map & Route" = DasTelefonbuch GelbeSeiten Map & Route
"Dell Webcam Center" = Dell Webcam Center
"Dell Webcam Manager" = Dell Webcam Manager
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.15.1228
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HEROLD Telefonbuch DVD network" = HEROLD Telefonbuch DVD network
"HP Color LaserJet 2600 series" = HP Color LaserJet 2600 series
"Maple 14" = Maple 14
"Matlab R2011b" = MATLAB R2011b
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft Help Viewer 1.0 Language Pack - DEU" = Microsoft Help Viewer 1.0 Language Pack - DEU
"Microsoft Team Foundation Server 2010 Object Model - DEU" = Microsoft Team Foundation Server 2010-Objektmodell - DEU
"Microsoft Visual Studio 2010 Tools for Office Runtime (x86)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU" = Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU
"Microsoft Visual Studio 2010 Ultimate - DEU" = Microsoft Visual Studio 2010 Ultimate - DEU
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"Microsoft Visual Studio Macro Tools - DEU Language Pack" = Microsoft Visual Studio Macro Tools - DEU Language Pack
"MiKTeX 2.9" = MiKTeX 2.9
"Mozilla Firefox 22.0 (x86 de)" = Mozilla Firefox 22.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"nxclient_is1" = NX Client for Windows 3.5.0-7
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeXnicCenter_is1" = TeXnicCenter Version 1.0 Stable RC1
"TVWiz" = Intel(R) TV Wizard
"VLC media player" = VLC media player 2.0.5
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.01 (32-Bit)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"f031ef6ac137efc5" = Dell Driver Download Manager
"JDownloader Packages" = JDownloader Packages
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 22.06.2013 06:09:15 | Computer Name = abc-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\OO
Software\SafeErase\oosecmd.exe". Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 22.06.2013 06:11:30 | Computer Name = abc-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\MATLAB\R2011b\bin\win32\VCRT_check.exe".
Die
abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 23.06.2013 01:57:13 | Computer Name = abc-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: firefox.exe, Version: 21.0.0.4879,
Zeitstempel: 0x518ec3cc Name des fehlerhaften Moduls: xul.dll, Version: 21.0.0.4879,
Zeitstempel: 0x518ec306 Ausnahmecode: 0xc0000005 Fehleroffset: 0x001c9789 ID des fehlerhaften
Prozesses: 0xf18 Startzeit der fehlerhaften Anwendung: 0x01ce6fd653d42cc3 Pfad der
fehlerhaften Anwendung: C:\Program Files\Mozilla Firefox\firefox.exe Pfad des fehlerhaften
Moduls: C:\Program Files\Mozilla Firefox\xul.dll Berichtskennung: bf7cfded-dbc9-11e2-8426-002269c03207
Error - 23.06.2013 04:08:51 | Computer Name = abc-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\MATLAB\R2011b\bin\win32\vcrt_check.exe".
Die
abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 26.06.2013 03:37:17 | Computer Name = abc-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: TEXCNTR.EXE, Version: 1.0.0.0, Zeitstempel:
0x493c1915 Name des fehlerhaften Moduls: CrysEditEx.dll, Version: 0.7.0.0, Zeitstempel:
0x493c1494 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000e336 ID des fehlerhaften Prozesses:
0x159c Startzeit der fehlerhaften Anwendung: 0x01ce723ffa20a87f Pfad der fehlerhaften
Anwendung: C:\Program Files\TeXnicCenter\TEXCNTR.EXE Pfad des fehlerhaften Moduls:
C:\Program Files\TeXnicCenter\CrysEditEx.dll Berichtskennung: 39ae8673-de33-11e2-901d-002269c03207
[ Cisco AnyConnect Secure Mobility Client Events ]
Error - 06.07.2013 05:31:01 | Computer Name = abc-PC | Source = acvpnagent | ID = 67108866
Description = Function: CCapiCertStore::CCapiCertStore File: .\Certificates\CapiCertStore.cpp
Line:
70 Invoked Function: CapiCertUtils Return Code: -32767981 (0xFE0C0013) Description:
WINSECAPI_ERROR_GETUSERIMPERSONATIONTOKEN_FAILED
Error - 06.07.2013 05:31:01 | Computer Name = abc-PC | Source = acvpnagent | ID = 67108866
Description = Function: CCollectiveCertStore::addCapiStore File: .\Certificates\CollectiveCertStore.cpp
Line:
922 Invoked Function: CCapiCertStore::CCapiCertStore Return Code: -32767981 (0xFE0C0013)
Description:
WINSECAPI_ERROR_GETUSERIMPERSONATIONTOKEN_FAILED
Error - 06.07.2013 05:31:01 | Computer Name = abc-PC | Source = acvpnagent | ID = 67108866
Description = Function: CWinsecApiImpersonateUser::searchProcessesForUserToken File:
.\IPC\WinsecAPI.cpp Line: 1391 Invoked Function: Process32Next Return Code: 18 (0x00000012)
Description:
Es sind keine weiteren Dateien vorhanden.
Error - 06.07.2013 05:31:01 | Computer Name = abc-PC | Source = acvpnagent | ID = 67108865
Description = Function: CWinsecApiImpersonateUser::acquireTokens File: .\IPC\WinsecAPI.cpp
Line:
101 CWinsecApiImpersonateUser::getUserImpersonationToken returned NULL
Error - 06.07.2013 05:31:01 | Computer Name = abc-PC | Source = acvpnagent | ID = 67108866
Description = Function: CWinsecApiImpersonateUser::CWinsecApiImpersonateUser File:
.\IPC\WinsecAPI.cpp Line: 81 Invoked Function: CWinsecApiImpersonateUser::acquireTokens
Return
Code: -32767981 (0xFE0C0013) Description: WINSECAPI_ERROR_GETUSERIMPERSONATIONTOKEN_FAILED
Error - 06.07.2013 05:31:01 | Computer Name = abc-PC | Source = acvpnagent | ID = 67108866
Description = Function: CCapiCertUtils::CCapiCertUtils File: .\Certificates\CapiCertUtils.cpp
Line:
92 Invoked Function: CWinsecApiImpersonateUser::CWinsecApiImpersonateUser Return
Code: -32767981 (0xFE0C0013) Description: WINSECAPI_ERROR_GETUSERIMPERSONATIONTOKEN_FAILED
Error - 06.07.2013 05:31:01 | Computer Name = abc-PC | Source = acvpnagent | ID = 67108866
Description = Function: CCapiCertStore::CCapiCertStore File: .\Certificates\CapiCertStore.cpp
Line:
70 Invoked Function: CapiCertUtils Return Code: -32767981 (0xFE0C0013) Description:
WINSECAPI_ERROR_GETUSERIMPERSONATIONTOKEN_FAILED
Error - 06.07.2013 05:31:01 | Computer Name = abc-PC | Source = acvpnagent | ID = 67108866
Description = Function: CCapiCertSmartcardStore::CCapiCertSmartcardStore File: .\Certificates\CapiCertSmartcardStore.cpp
Line:
40 Invoked Function: CCapiCertStore::CCapiCertStore Return Code: -32767981 (0xFE0C0013)
Description:
WINSECAPI_ERROR_GETUSERIMPERSONATIONTOKEN_FAILED
Error - 06.07.2013 05:31:01 | Computer Name = abc-PC | Source = acvpnagent | ID = 67108866
Description = Function: CCollectiveCertStore::addCapiSmartcardStore File: .\Certificates\CollectiveCertStore.cpp
Line:
959 Invoked Function: CCapiCertSmartcardStore::CCapiCertSmartcardStore Return Code:
-32767981 (0xFE0C0013) Description: WINSECAPI_ERROR_GETUSERIMPERSONATIONTOKEN_FAILED
Error - 06.07.2013 05:33:09 | Computer Name = abc-PC | Source = acvpnagent | ID = 67108866
Description = Function: CThread::invokeRun File: .\Utility\Thread.cpp Line: 376 Invoked
Function: IRunnable::Run Return Code: -32047093 (0xFE17000B) Description: BROWSERPROXY_ERROR_NO_PROXY_FILE
[ OSession Events ]
Error - 02.04.2012 20:28:07 | Computer Name = abc-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 3586 seconds with 600 seconds of active time. This session ended with a
crash.
Error - 03.04.2012 22:45:20 | Computer Name = abc-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 37 seconds with 0 seconds of active time. This session ended with a crash.
Error - 03.04.2012 22:45:48 | Computer Name = abc-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 18 seconds with 0 seconds of active time. This session ended with a crash.
Error - 07.04.2012 06:06:42 | Computer Name = abc-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 3817 seconds with 1260 seconds of active time. This session ended with a
crash.
Error - 07.04.2012 06:48:44 | Computer Name = abc-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 256 seconds with 120 seconds of active time. This session ended with a crash.
Error - 23.04.2012 13:44:11 | Computer Name = abc-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 20 seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 04.07.2013 15:11:53 | Computer Name = abc-PC | Source = BTHUSB | ID = 327697
Description = Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen
und wird nicht verwendet. Der Treiber wurde entladen.
Error - 04.07.2013 15:15:13 | Computer Name = abc-PC | Source = BTHUSB | ID = 327697
Description = Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen
und wird nicht verwendet. Der Treiber wurde entladen.
Error - 05.07.2013 04:40:00 | Computer Name = abc-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?05.?07.?2013 um 10:34:26 unerwartet heruntergefahren.
Error - 05.07.2013 04:41:50 | Computer Name = abc-PC | Source = WMPNetworkSvc | ID = 866300
Description =
Error - 05.07.2013 05:19:33 | Computer Name = abc-PC | Source = BTHUSB | ID = 327697
Description = Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen
und wird nicht verwendet. Der Treiber wurde entladen.
Error - 05.07.2013 08:51:52 | Computer Name = abc-PC | Source = BTHUSB | ID = 327697
Description = Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen
und wird nicht verwendet. Der Treiber wurde entladen.
Error - 05.07.2013 11:46:48 | Computer Name = abc-PC | Source = BTHUSB | ID = 327697
Description = Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen
und wird nicht verwendet. Der Treiber wurde entladen.
Error - 05.07.2013 14:23:00 | Computer Name = abc-PC | Source = BTHUSB | ID = 327697
Description = Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen
und wird nicht verwendet. Der Treiber wurde entladen.
Error - 05.07.2013 15:46:20 | Computer Name = abc-PC | Source = BTHUSB | ID = 327697
Description = Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen
und wird nicht verwendet. Der Treiber wurde entladen.
Error - 05.07.2013 16:03:16 | Computer Name = abc-PC | Source = BTHUSB | ID = 327697
Description = Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen
und wird nicht verwendet. Der Treiber wurde entladen.
< End of report > Und jetzt?
Vielen Dank :daumenhoc |