Tinchen83 | 18.06.2013 18:55 | Hallo aharonov danke für deine schnelle Antwort. also ich habe jetzt alles abgearbeitet was in der liste ist.
1) defogger hat keine fehlermeldung rausgegeben
hier das OTL.txtOTL Logfile: Code:
OTL logfile created on: 18.06.2013 19:16:35 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Tinchen\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
3,25 Gb Total Physical Memory | 2,21 Gb Available Physical Memory | 68,08% Memory free
6,50 Gb Paging File | 5,32 Gb Available in Paging File | 81,91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 488,20 Gb Total Space | 418,10 Gb Free Space | 85,64% Space Free | Partition Type: NTFS
Drive D: | 443,21 Gb Total Space | 441,01 Gb Free Space | 99,50% Space Free | Partition Type: NTFS
Drive E: | 6,25 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive F: | 232,88 Gb Total Space | 232,78 Gb Free Space | 99,96% Space Free | Partition Type: NTFS
Drive G: | 1863,01 Gb Total Space | 877,27 Gb Free Space | 47,09% Space Free | Partition Type: NTFS
Computer Name: TINCHEN-PC | User Name: Tinchen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.06.17 19:03:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Tinchen\Desktop\OTL.exe
PRC - [2013.05.27 13:05:31 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2013.05.27 13:05:07 | 000,562,744 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe
PRC - [2013.05.27 13:05:05 | 000,079,584 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2013.05.27 13:05:01 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2013.05.27 13:05:00 | 000,345,312 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2013.05.13 13:21:42 | 000,601,928 | ---- | M] (BlueStack Systems, Inc.) -- C:\Programme\BlueStacks\HD-Agent.exe
PRC - [2013.05.13 13:20:52 | 000,384,840 | ---- | M] (BlueStack Systems, Inc.) -- C:\Programme\BlueStacks\HD-LogRotatorService.exe
PRC - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013.04.30 12:03:00 | 001,648,264 | ---- | M] (Ask) -- C:\Programme\Ask.com\Updater\Updater.exe
PRC - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013.04.04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013.01.27 12:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\NisSrv.exe
PRC - [2013.01.27 12:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\MsMpEng.exe
PRC - [2013.01.27 12:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe
PRC - [2013.01.18 16:21:02 | 000,873,248 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2013.01.18 16:21:00 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe
PRC - [2013.01.18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.11.23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012.08.13 11:08:08 | 010,376,704 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe
PRC - [2012.08.13 11:08:08 | 010,368,512 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin
PRC - [2012.07.17 15:49:00 | 001,713,904 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2012.07.17 15:49:00 | 000,194,304 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.10.01 02:57:18 | 000,718,688 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Xbox 360 Accessories\XBoxStat.exe
========== Modules (No Company Name) ==========
MOD - [2013.05.25 10:20:58 | 000,650,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\HD-Agent\3e9bf16c5d114953ae9a034cf42eb45e\HD-Agent.ni.exe
MOD - [2013.05.25 10:20:41 | 000,155,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\JSON\4e4a2bf1f922bbd51b0e01dac192a662\JSON.ni.dll
MOD - [2013.05.17 09:16:53 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll
MOD - [2013.05.17 09:16:29 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll
MOD - [2013.03.25 04:21:27 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\7ff638de44686eab4afaa8b3c8a9cfca\System.ServiceProcess.ni.dll
MOD - [2013.03.25 04:21:17 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll
MOD - [2013.03.25 04:20:41 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013.03.25 04:20:23 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013.03.25 04:20:19 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013.03.25 04:20:10 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2012.08.10 16:51:32 | 000,985,088 | ---- | M] () -- C:\Programme\OpenOffice.org 3\program\libxml2.dll
MOD - [2010.11.13 01:19:04 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.11.05 03:59:41 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll
========== Services (SafeList) ==========
SRV - [2013.06.12 17:10:40 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.05.27 13:05:31 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013.05.27 13:05:07 | 000,562,744 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService)
SRV - [2013.05.27 13:05:01 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013.05.18 09:01:55 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.05.13 13:20:52 | 000,384,840 | ---- | M] (BlueStack Systems, Inc.) [Auto | Running] -- C:\Programme\BlueStacks\HD-LogRotatorService.exe -- (BstHdLogRotatorSvc)
SRV - [2013.05.13 13:20:32 | 000,393,032 | ---- | M] (BlueStack Systems, Inc.) [Auto | Stopped] -- C:\Program Files\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc)
SRV - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013.02.26 00:22:34 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013.01.27 12:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013.01.27 12:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2013.01.18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2013.01.16 13:59:56 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2012.07.17 15:49:00 | 001,713,904 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - [2013.05.27 13:05:47 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2013.05.27 13:05:46 | 000,135,136 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2013.05.27 13:05:46 | 000,084,744 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2013.05.27 13:05:46 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2013.05.13 13:20:38 | 000,063,816 | ---- | M] (BlueStack Systems) [Kernel | Auto | Running] -- C:\Programme\BlueStacks\HD-Hypervisor-x86.sys -- (BstHdDrv)
DRV - [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013.02.26 00:22:06 | 008,939,296 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2013.01.20 16:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2013.01.17 15:06:08 | 000,083,872 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2013.01.17 15:06:07 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2010.02.24 12:22:10 | 000,185,472 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.delta-search.com/?affID=119294&babsrc=HP_ss&mntrId=de314e59000000000000002354f5d0da
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-search.com/?affID=119294&babsrc=HP_ss&mntrId=de314e59000000000000002354f5d0da
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B8 57 02 10 C7 07 CE 01 [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://www.delta-search.com/?q={searchTerms}&affID=119294&babsrc=SP_ss&mntrId=de314e59000000000000002354f5d0da
IE - HKCU\..\SearchScopes\{8F8D6446-8459-436E-A721-F399C9B1F9F0}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10263&src=kw&q={searchTerms}&locale=de_AT&apn_ptnrs=^AGU&apn_dtid=^YYYYYY^YY^AT&apn_uid=268ec90a-9cc6-4689-9cbd-d31b98d39b45&apn_sauid=55392B8C-0770-41F0-835B-E1B7A3A275F2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.at"
FF - prefs.js..extensions.enabledAddons: %7Bafe43e80-0abc-4df2-81a0-3fe44b74abe8%7D:1.300.436
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: D:\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Tinchen\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2013.01.16 10:55:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tinchen\AppData\Roaming\mozilla\Extensions
[2013.05.27 13:07:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tinchen\AppData\Roaming\mozilla\Firefox\Profiles\oa6k02l6.default\extensions
[2013.05.27 13:07:44 | 000,000,000 | ---D | M] (Avira SearchFree Toolbar plus Web Protection) -- C:\Users\Tinchen\AppData\Roaming\mozilla\Firefox\Profiles\oa6k02l6.default\extensions\toolbar@ask.com
[2012.12.13 22:29:00 | 000,199,445 | ---- | M] () (No name found) -- C:\Users\Tinchen\AppData\Roaming\mozilla\firefox\profiles\oa6k02l6.default\extensions\movie2kdownloader@movie2kdownloader.com.xpi
[2013.02.11 16:32:16 | 000,213,444 | ---- | M] () (No name found) -- C:\Users\Tinchen\AppData\Roaming\mozilla\firefox\profiles\oa6k02l6.default\extensions\torntv@torntv.com.xpi
[2013.04.04 00:09:18 | 000,580,368 | ---- | M] () (No name found) -- C:\Users\Tinchen\AppData\Roaming\mozilla\firefox\profiles\oa6k02l6.default\extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}.xpi
[2013.05.27 13:07:44 | 000,002,344 | ---- | M] () -- C:\Users\Tinchen\AppData\Roaming\mozilla\firefox\profiles\oa6k02l6.default\searchplugins\askcom.xml
[2013.02.11 16:46:58 | 000,001,294 | ---- | M] () -- C:\Users\Tinchen\AppData\Roaming\mozilla\firefox\profiles\oa6k02l6.default\searchplugins\delta.xml
[2013.05.18 09:01:56 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\browser\extensions
[2013.05.18 09:01:56 | 000,000,000 | ---D | M] (Default) -- C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013.02.11 16:46:44 | 000,006,484 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Erster Nutzer (Enabled) = D:\VideoLAN\VLC\npvlc.dll
CHR - plugin: Error reading preferences file
CHR - Extension: BIODIGITAL HUMAN = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\agoenciogemlojlhccbcpcfflicgnaak\0.9.5_0\
CHR - Extension: Wo ist meine Perry Guideline und Tipps = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkahoacbgbkdlelbejfiemfcijohoeaj\1.0.0_0\
CHR - Extension: Movie2kDownloader = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blaofbhgbmeikidhlkmjhbkbfohpgekf\1.0_0\
CHR - Extension: YouTube = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Human Body = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccmcdjbdhohdkneafoniplilibgkljhn\1.2_0\
CHR - Extension: Human Body = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccmcdjbdhohdkneafoniplilibgkljhn\1.2_0\.bak
CHR - Extension: Klassische Spiele = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckmoikambnjgjnhaefiklkblfjoolnaf\11_0\
CHR - Extension: Google-Suche = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Delta Toolbar = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\
CHR - Extension: Anatomy 3D = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdgiaifohbadjmcpafbhhgkobokjoiod\1.5_0\
CHR - Extension: Anatomy 3D = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdgiaifohbadjmcpafbhhgkobokjoiod\1.5_0\.bak
CHR - Extension: Snow Leopard Theme = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibebhacjhbobicioklgmmgcikhffaajd\1_0\
CHR - Extension: Anatomy Games = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbplkkegndhkgnendpdhcffamoplajga\1.8_0\
CHR - Extension: Anatomy Games = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbplkkegndhkgnendpdhcffamoplajga\1.8_0\.bak
CHR - Extension: Snail Bob = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgepmhhoobiejapbkbcfjhddibldidi\2.0.0_0\
CHR - Extension: Where is my water? = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpaiobfbdlhdnfffhfbnadmampoeigpb\0.0.0.2_0\
CHR - Extension: Google Mail = C:\Users\Tinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BlueStacks Agent] C:\Programme\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Tinchen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.186.211.21 195.34.133.21
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1F6BB57D-775D-4F3E-A248-977E604122E6}: DhcpNameServer = 212.186.211.21 195.34.133.21
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011.08.19 09:39:35 | 000,000,000 | RH-D | M] - G:\autorun -- [ NTFS ]
O32 - Unable to obtain root file information for disk G:\
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.06.17 19:07:11 | 000,000,000 | ---D | C] -- C:\Users\Tinchen\AppData\Roaming\Malwarebytes
[2013.06.17 19:06:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.06.17 19:06:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.06.17 19:06:29 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.06.17 19:06:29 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.06.17 19:03:28 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Tinchen\Desktop\OTL.exe
[2013.06.14 16:49:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcatel Android Manager
[2013.06.14 16:48:46 | 000,000,000 | ---D | C] -- C:\Program Files\Mobile Action
[2013.06.14 16:37:30 | 000,000,000 | ---D | C] -- C:\Windows\Application Data
[2013.06.14 16:29:21 | 000,000,000 | ---D | C] -- C:\Users\Tinchen\AppData\Local\ElevatedDiagnostics
[2013.06.10 20:46:14 | 000,000,000 | ---D | C] -- C:\Users\Tinchen\AppData\Roaming\OpenOffice.org
[2013.06.10 20:45:31 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4.1
[2013.06.10 20:44:43 | 000,000,000 | ---D | C] -- C:\Program Files\OpenOffice.org 3
[2013.06.10 20:43:46 | 000,000,000 | ---D | C] -- C:\Users\Tinchen\Desktop\OpenOffice.org 3.4.1 (de) Installation Files
[2013.06.01 17:43:23 | 000,000,000 | ---D | C] -- C:\Users\Tinchen\AppData\Local\DoNotTrackPlus
[2013.06.01 17:43:13 | 000,000,000 | ---D | C] -- C:\Users\Tinchen\AppData\Local\AskToolbar
[2013.05.27 19:18:13 | 000,066,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avnetflt.sys
[2013.05.27 13:13:23 | 000,000,000 | ---D | C] -- C:\Users\Tinchen\AppData\Roaming\Avira
[2013.05.27 13:07:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013.05.27 13:07:31 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com
[2013.05.27 13:07:16 | 000,000,000 | ---D | C] -- C:\Users\Tinchen\AppData\Local\APN
[2013.05.27 13:07:09 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2013.05.27 13:07:07 | 000,135,136 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2013.05.27 13:07:07 | 000,084,744 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2013.05.27 13:07:07 | 000,037,352 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2013.05.27 13:07:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2013.05.27 13:07:05 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2013.05.25 10:18:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
[2013.05.25 10:18:03 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueStacks
[2013.05.25 10:18:03 | 000,000,000 | ---D | C] -- C:\Program Files\BlueStacks
[2013.05.22 10:50:08 | 000,000,000 | R--D | C] -- C:\Users\Tinchen\Documents\Scanned Documents
[2013.05.22 10:50:08 | 000,000,000 | ---D | C] -- C:\Users\Tinchen\Documents\Fax
========== Files - Modified Within 30 Days ==========
[2013.06.18 19:10:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.06.18 19:09:57 | 000,000,000 | ---- | M] () -- C:\Users\Tinchen\defogger_reenable
[2013.06.18 19:07:10 | 000,015,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.06.18 19:07:10 | 000,015,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.06.18 18:59:44 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.06.18 18:59:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.06.18 18:59:23 | 2616,696,832 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.18 09:00:10 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.06.17 19:37:31 | 000,053,289 | ---- | M] () -- C:\Users\Tinchen\Desktop\1.jpg
[2013.06.17 19:34:01 | 000,053,938 | ---- | M] () -- C:\Users\Tinchen\Desktop\Unbenannt.jpg
[2013.06.17 19:06:41 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.06.17 19:03:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Tinchen\Desktop\OTL.exe
[2013.06.14 22:42:09 | 000,696,620 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.06.14 22:42:09 | 000,651,938 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.06.14 22:42:09 | 000,147,916 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.06.14 22:42:09 | 000,120,870 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.06.14 16:49:01 | 000,001,166 | ---- | M] () -- C:\Users\Public\Desktop\Alcatel Android Manager.lnk
[2013.06.14 16:40:02 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_WinUSB_01007.Wdf
[2013.06.11 10:36:54 | 130,374,088 | ---- | M] () -- C:\Users\Tinchen\Desktop\Erstes National-Kochbuch in praktisch unterrichtenden Gesprächen zwischen Koch K.pdf
[2013.06.11 09:25:37 | 000,296,640 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.06.10 20:46:24 | 000,001,197 | ---- | M] () -- C:\Users\Tinchen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
[2013.06.10 20:45:31 | 000,001,130 | ---- | M] () -- C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk
[2013.06.05 23:02:04 | 000,002,129 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013.05.27 19:18:03 | 000,066,656 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avnetflt.sys
[2013.05.27 13:07:54 | 000,002,016 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2013.05.27 13:05:47 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2013.05.27 13:05:46 | 000,135,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2013.05.27 13:05:46 | 000,084,744 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2013.05.27 13:05:46 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2013.05.25 10:19:14 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\Apps.lnk
[2013.05.25 10:19:12 | 000,001,765 | ---- | M] () -- C:\Users\Public\Desktop\Start BlueStacks.lnk
========== Files Created - No Company Name ==========
[2013.06.18 19:09:57 | 000,000,000 | ---- | C] () -- C:\Users\Tinchen\defogger_reenable
[2013.06.17 19:36:30 | 000,053,289 | ---- | C] () -- C:\Users\Tinchen\Desktop\1.jpg
[2013.06.17 19:32:44 | 000,053,938 | ---- | C] () -- C:\Users\Tinchen\Desktop\Unbenannt.jpg
[2013.06.17 19:06:41 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.06.14 16:49:01 | 000,001,166 | ---- | C] () -- C:\Users\Public\Desktop\Alcatel Android Manager.lnk
[2013.06.14 16:40:02 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_WinUSB_01007.Wdf
[2013.06.11 10:36:45 | 130,374,088 | ---- | C] () -- C:\Users\Tinchen\Desktop\Erstes National-Kochbuch in praktisch unterrichtenden Gesprächen zwischen Koch K.pdf
[2013.06.10 20:46:24 | 000,001,197 | ---- | C] () -- C:\Users\Tinchen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
[2013.06.10 20:45:31 | 000,001,130 | ---- | C] () -- C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk
[2013.05.27 13:07:54 | 000,002,016 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2013.05.25 10:19:14 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\Apps.lnk
[2013.05.25 10:19:12 | 000,001,765 | ---- | C] () -- C:\Users\Public\Desktop\Start BlueStacks.lnk
[2013.05.14 19:59:46 | 000,000,032 | ---- | C] () -- C:\Windows\setup.INI
[2013.04.08 16:34:04 | 000,036,892 | ---- | C] () -- C:\Windows\System32\bassmod.dll
[2013.03.05 19:54:34 | 000,114,176 | ---- | C] () -- C:\Users\Tinchen\AppData\Roaming\BabMaint.exe
[2013.03.05 19:53:51 | 000,079,360 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2013.01.20 21:11:06 | 000,007,607 | ---- | C] () -- C:\Users\Tinchen\AppData\Local\Resmon.ResmonCfg
[2013.01.17 15:01:39 | 000,083,872 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2013.01.17 15:01:22 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
========== ZeroAccess Check ==========
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013.05.15 13:58:29 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\AlawarEntertainment
[2013.03.05 19:54:34 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\BabSolution
[2013.02.11 16:32:30 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\Babylon
[2013.02.20 12:54:22 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\Big Fish Games
[2013.05.16 17:37:58 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\Broken Sword 2.5
[2013.02.02 18:01:03 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\bsnes
[2013.05.16 18:24:13 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\cerasus.media
[2013.02.11 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\Ghost Ship Studios
[2013.02.11 16:46:36 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\GoforFiles
[2013.05.16 17:39:44 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\Kalypso Media
[2013.06.10 20:46:14 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\OpenOffice.org
[2013.05.06 08:20:32 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\Sahmon Games
[2013.02.22 14:07:14 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\SecondLife
[2013.04.05 21:15:30 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\Ubisoft
[2013.02.26 11:03:51 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\Unity
[2013.03.22 13:56:01 | 000,000,000 | ---D | M] -- C:\Users\Tinchen\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:A819A132
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:A4AF8D0D
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:F84B8DB5
< End of report > --- --- ---
hier das Extras.txtOTL EXTRAS Logfile: Code:
OTL Extras logfile created on: 18.06.2013 19:16:35 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Tinchen\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
3,25 Gb Total Physical Memory | 2,21 Gb Available Physical Memory | 68,08% Memory free
6,50 Gb Paging File | 5,32 Gb Available in Paging File | 81,91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 488,20 Gb Total Space | 418,10 Gb Free Space | 85,64% Space Free | Partition Type: NTFS
Drive D: | 443,21 Gb Total Space | 441,01 Gb Free Space | 99,50% Space Free | Partition Type: NTFS
Drive E: | 6,25 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive F: | 232,88 Gb Total Space | 232,78 Gb Free Space | 99,96% Space Free | Partition Type: NTFS
Drive G: | 1863,01 Gb Total Space | 877,27 Gb Free Space | 47,09% Space Free | Partition Type: NTFS
Computer Name: TINCHEN-PC | User Name: Tinchen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "D:\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "D:\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0646A4AF-E1C1-4D36-8FF2-570C3AA1CF7E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{09B057B2-1F0E-4E6C-9A07-644080D3E940}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{0D6BDCB2-D59A-46B4-88D6-A6192870D9BA}" = lport=10243 | protocol=6 | dir=in | app=system |
"{1B23FAFF-4408-4007-BC98-39BD6C6B6672}" = lport=445 | protocol=6 | dir=in | app=system |
"{248422B8-4923-4855-8381-757277E14A8D}" = rport=139 | protocol=6 | dir=out | app=system |
"{2D26C718-ECF1-433B-843B-18AC343AFCB3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3FBE641A-1D88-4F92-BFD9-124AE8B39D3E}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{4E87F82A-16D0-4FEA-8007-776FA0395A24}" = lport=138 | protocol=17 | dir=in | app=system |
"{525BED37-4645-4B5B-9449-C0700E7E9D47}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{54849AE2-0622-414F-928F-3B2EE9EBEFF5}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5874E954-C391-4253-9D9B-3BF1E45984BE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6540F3EF-574B-4C2A-A8D3-71765B9804B1}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6FC7A8E4-63FD-40D9-8AEE-B3322F06C3BD}" = lport=137 | protocol=17 | dir=in | app=system |
"{790469D0-CD8F-44BD-998C-400C7D37B34C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8BEAFCC4-4BC7-4433-9FC2-F7B030B10DEA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8D1D37AE-FD62-4027-8EE7-513914856C77}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{8FCDC83B-E9EB-44BC-B739-BA629BFA40BD}" = lport=2869 | protocol=6 | dir=in | app=system |
"{90212696-9D1B-4439-B2A1-7ECA797D6F1B}" = rport=445 | protocol=6 | dir=out | app=system |
"{994EBB8F-F416-4BFE-8198-236F1B71982C}" = lport=139 | protocol=6 | dir=in | app=system |
"{9EAC3636-0571-45CF-8A7F-8DC07835B750}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A1E5B44F-B541-4C0B-BFB1-FCD88597243B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files\dll-files.com fixer\dllfixer.exe |
"{AD1F8CDF-D8F3-4409-829B-041028D3AD83}" = rport=137 | protocol=17 | dir=out | app=system |
"{B567F5C8-61C6-4C7C-B7A9-EC09A2A95750}" = rport=138 | protocol=17 | dir=out | app=system |
"{CB769163-21E1-4D3E-A6D9-48CEB0D255DB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CC16E97F-506C-4800-B2F6-B241505EE6CB}" = lport=4000 | protocol=6 | dir=out | app=c:\program files\dll-files.com fixer\dllfixer.exe |
"{E99CF057-0F73-47A5-BD9F-2205EB094CA6}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EB816404-5223-490B-9641-0D1E5BAFB5C5}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{FB1F1022-D647-4C8D-ADCD-78244D7EF781}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D6D1AC5-7862-464E-8F9F-252FE19F2149}" = protocol=6 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\initengine.exe |
"{200FFCF0-2B03-44DD-B4D4-83C461192479}" = protocol=17 | dir=in | app=c:\nexon\combat arms eu\nmservice.exe |
"{27CCE94C-4C15-426D-89BB-ECFC956CA083}" = protocol=17 | dir=in | app=c:\program files\goforfiles\goforfilesdl.exe |
"{29BC0D16-3079-4714-8051-6A1FC0D5E400}" = protocol=6 | dir=in | app=c:\nexon\combat arms eu\nmservice.exe |
"{2BED4EF1-1179-426D-8A7F-2D52B59A574D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{30198086-92CE-4F8E-A179-ECC5A9DF8E6C}" = protocol=17 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\autopatcher.exe |
"{30E2A0E4-3C23-4F45-A5A2-B964FF0CDFBE}" = protocol=6 | dir=in | app=c:\program files\goforfiles\goforfilesdl.exe |
"{33009383-9FE1-4DC1-93B2-6E26DAFD9B8D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{382EBE33-18C4-48FD-A6BB-5F0632AA7156}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{3A1EAEAB-DC4C-4A22-8B66-619B868A860D}" = protocol=17 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\anno5.exe |
"{50EDD68C-3276-4EBB-8F1E-3FDDCDF7A476}" = protocol=17 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\initengine.exe |
"{57E73779-4A31-4E26-961F-7470E6702B9F}" = protocol=17 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |
"{610695D8-0CC6-494C-BEC2-3154AAB8E0FF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{6AE3800C-F49D-49A3-93B6-BB24BF946023}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{71516076-752A-484B-B0AE-46DB70BCA585}" = protocol=6 | dir=in | app=c:\program files\ubisoft\driver san francisco\driver.exe |
"{77956470-476D-46D5-A634-AA9E4F03B507}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7AFFF1C0-A51D-438E-9CAF-9C203A44EFD5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7F52910F-1E7D-4F7B-B0A9-AFB8F280A579}" = protocol=6 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |
"{8DBE9DF5-7DCF-41A9-8E36-3FD3D7581481}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8F927DA2-6593-4CD1-8564-337AE349C73D}" = protocol=6 | dir=in | app=c:\program files\goforfiles\goforfiles.exe |
"{9215A7B7-2927-47CA-B9CF-A3D33D7AA9AF}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{93D7E46E-06EF-483D-B53C-22BB96E3D719}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{96518691-CC3A-4E46-9DF0-C3DADA3CACBC}" = protocol=17 | dir=in | app=c:\program files\goforfiles\goforfiles.exe |
"{9CB182D8-8E38-49C6-A552-C78F92E8C4BA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{AA24980C-C24B-4F27-AB1D-F32B464DABBA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{ABD0D0E4-9E6C-4F03-8C3A-1C195E0C242F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{AC3880B3-D126-4AB3-BACA-AE0A05A812F0}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{BA99EAC2-2579-4A22-9EFC-31E98CA74212}" = protocol=6 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\anno5.exe |
"{C17F6414-A525-4946-94B3-632E68A5186A}" = protocol=6 | dir=in | app=c:\program files\ubisoft\related designs\anno 2070\autopatcher.exe |
"{C60E5367-13DC-47F5-8740-1546A8C20AB5}" = protocol=6 | dir=out | app=system |
"{D4CA13E7-61D3-496A-A8D6-ACD5EE6D6C24}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F51025D7-B01C-43A2-B5B3-8CB447B3E1AF}" = protocol=17 | dir=in | app=c:\program files\ubisoft\driver san francisco\driver.exe |
"{F9535604-8E52-489B-A51B-FCD36D266999}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FA5EB3E7-6BE1-4B08-948D-1F2E668CB3C0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FBFF2ECF-A059-4634-A3EF-477F21028BF6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{0249CA23-AE78-4DC9-8425-665B2D4B580B}C:\program files\secondlifeviewer\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\secondlifeviewer\slvoice.exe |
"TCP Query User{60EBE366-B1E7-49DD-ACB7-FD00F10637BB}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"TCP Query User{B8ACF1E1-D741-4035-81E2-F232415AC4DA}C:\udk\boowate the game-en\binaries\win32\udk.exe" = protocol=6 | dir=in | app=c:\udk\boowate the game-en\binaries\win32\udk.exe |
"TCP Query User{C268A1C6-824A-4936-9270-05FAE8FCB532}C:\program files\deep silver\nail'd\naild_x86.exe" = protocol=6 | dir=in | app=c:\program files\deep silver\nail'd\naild_x86.exe |
"TCP Query User{F11FBD5C-2D41-4EC3-BB99-E3AC79D6B4E6}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"TCP Query User{FA5897E5-65A7-4AFA-9D85-48748D002C7C}D:\anno1701\anno1701.exe" = protocol=6 | dir=in | app=d:\anno1701\anno1701.exe |
"UDP Query User{080C56F4-2B75-4E08-B488-34CDC6FE6255}C:\program files\secondlifeviewer\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\secondlifeviewer\slvoice.exe |
"UDP Query User{0DC80C6A-C089-463D-8BFD-3D6BA392D9F4}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"UDP Query User{420E569E-D260-46B5-A25D-D4D90039AC9E}C:\program files\deep silver\nail'd\naild_x86.exe" = protocol=17 | dir=in | app=c:\program files\deep silver\nail'd\naild_x86.exe |
"UDP Query User{79ED97B2-3C57-4919-BF7C-AEA95A164BED}C:\udk\boowate the game-en\binaries\win32\udk.exe" = protocol=17 | dir=in | app=c:\udk\boowate the game-en\binaries\win32\udk.exe |
"UDP Query User{8C71A108-EEB2-439A-9713-8D20C3740431}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"UDP Query User{EAFED6FF-1015-4571-96D8-CC0717BA079A}D:\anno1701\anno1701.exe" = protocol=17 | dir=in | app=d:\anno1701\anno1701.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{077A7810-A937-4465-AD08-ACED9807995F}" = ANNO 1602 Königs-Edition
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series" = Canon MG5100 series MP Drivers
"{149F9A5E-889D-474B-BA15-AFA0E614E5EA}_is1" = 100 Prozent Wimmelbild
"{15F3A6F5-06AE-4332-AE3E-21CD0416827A}" = Windows Live Mail
"{1B947146-366B-42CD-86D5-219993CE3EE2}" = Windows Live MIME IFilter
"{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1
"{289AC7E0-0AEE-4a7b-913C-709D9803D23E}" = Nexon Game Manager
"{390DD8BB-BB57-4942-A029-2D913E4E9D74}" = Microsoft Security Client
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{400C31E4-796F-4E86-8FDC-C3C4FACC6847}" = Junk Mail filter update
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{690F5BA3-5DEB-42CD-962B-F687EE59FAA7}" = Windows Live Essentials
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{70854FE6-3BF1-4C69-94D0-BEB821102E34}" = Windows Live Mail
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{8256F87F-8554-4457-8C3D-3F3324697D9F}" = Windows Live ID Sign-in Assistant
"{850FD908-5381-4D6D-BE6E-8E489B366FFF}" = Lost Horizon
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{8913AC02-67B8-4B52-91B2-BBA7B9C265B5}" = Windows Live Writer Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{91AC4ECB-8C44-47CA-833D-0769B8CD0E7E}_is1" = Mystery Stories - Expedition des Grauens
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C362EEE-BEDE-4E97-9930-8F463B95BFF0}_is1" = Mystery Stories - Das Geisterschiff
"{A2433A63-5F5D-40E5-B529-9123C2B3E734}" = Anno 1701
"{A7FC82AC-986D-48D5-8AAE-A75C1D829E0A}" = BlueStacks Notification Center
"{A8E41E44-204B-438D-975B-6F46A028C60E}_is1" = The Second Guest Version 2.0
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC4C38FD-A54C-4CA5-92EE-D983CD81293E}" = Microsoft Xbox 360 Accessories 1.2
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.03) - Deutsch
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B48E264C-C8CD-4617-B0BE-46E977BAD694}" = ANNO 2070
"{B727564C-47D3-473A-AC9E-F4BE7B1BD5D3}" = Windows Live UX Platform Language Pack
"{B978866B-F235-0200-0000-000000000000}" = Alcatel Android Manager
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{D2C146B1-948D-47EF-8387-5D1C6B980F7C}" = Windows Live Writer
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1203F8C-FF34-4968-A4A5-B4F1F8533DAB}" = Photo Common
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"1ClickDownload" = HDVidCodec
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"BFGC" = Big Fish Games: Game Manager
"BlueStacks App Player" = BlueStacks App Player
"Driver San Francisco" = Driver San Francisco
"DSGPlayer" = DEUTSCHLAND SPIELT GAME CENTER
"DXBX_is1" = DXBX 0.5 Release
"ffdshow_is1" = ffdshow v1.2.4422 [2012-04-09]
"Garten-Glück: Jetzt wird renoviert!" = Garten-Glück: Jetzt wird renoviert!
"Google Chrome" = Google Chrome
"Haus der 1000 Türen - Das Juwel des Zarathustra" = Haus der 1000 Türen - Das Juwel des Zarathustra
"Haus der 1000 Türen - Familiengeheimnisse" = Haus der 1000 Türen - Familiengeheimnisse
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300
"MegaTrainer eXperience_is1" = MegaTrainer eXperience V1.1.4.3
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 21.0 (x86 de)" = Mozilla Firefox 21.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"The Book Of Unwritten Tales_is1" = The Book Of Unwritten Tales Version 1.02
"The Island - Castaway" = The Island - Castaway
"VLC media player" = VLC media player 2.0.5
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.20 (32-Bit)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Avira SearchFree Toolbar plus Web Protection Updater
"UnityWebPlayer" = Unity Web Player
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 13.06.2013 10:45:45 | Computer Name = Tinchen-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "d:\Anno1701\Tools\Tages\DrvSetup_x64.exe".
Die
abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 14.06.2013 06:33:11 | Computer Name = Tinchen-PC | Source = BstHdAndroidSvc | ID = 0
Description = Der Dienst kann nicht gestartet werden. System.ApplicationException:
Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
state)
Error - 15.06.2013 07:11:20 | Computer Name = Tinchen-PC | Source = BstHdAndroidSvc | ID = 0
Description = Der Dienst kann nicht gestartet werden. System.ApplicationException:
Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
state)
Error - 15.06.2013 11:13:49 | Computer Name = Tinchen-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "d:\Anno1701\Tools\Tages\DrvSetup_x64.exe".
Die
abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 16.06.2013 03:50:12 | Computer Name = Tinchen-PC | Source = BstHdAndroidSvc | ID = 0
Description = Der Dienst kann nicht gestartet werden. System.ApplicationException:
Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
state)
Error - 16.06.2013 06:22:51 | Computer Name = Tinchen-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: firefox.exe, Version: 21.0.0.4879,
Zeitstempel: 0x518ec3cc Name des fehlerhaften Moduls: xul.dll, Version: 21.0.0.4879,
Zeitstempel: 0x518ec306 Ausnahmecode: 0xc0000005 Fehleroffset: 0x001c9789 ID des fehlerhaften
Prozesses: 0x6bc Startzeit der fehlerhaften Anwendung: 0x01ce6a66533238f0 Pfad der
fehlerhaften Anwendung: C:\Program Files\Mozilla Firefox\firefox.exe Pfad des fehlerhaften
Moduls: C:\Program Files\Mozilla Firefox\xul.dll Berichtskennung: b2d95f36-d66e-11e2-b4c9-002354f5d0da
Error - 16.06.2013 08:21:49 | Computer Name = Tinchen-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "d:\Anno1701\Tools\Tages\DrvSetup_x64.exe".
Die
abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 17.06.2013 03:04:07 | Computer Name = Tinchen-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "d:\Anno1701\Tools\Tages\DrvSetup_x64.exe".
Die
abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 18.06.2013 01:45:13 | Computer Name = Tinchen-PC | Source = BstHdAndroidSvc | ID = 0
Description = Der Dienst kann nicht gestartet werden. System.ApplicationException:
Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
state)
Error - 18.06.2013 12:59:49 | Computer Name = Tinchen-PC | Source = BstHdAndroidSvc | ID = 0
Description = Der Dienst kann nicht gestartet werden. System.ApplicationException:
Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
state)
[ Media Center Events ]
Error - 03.03.2013 11:21:21 | Computer Name = Tinchen-PC | Source = MCUpdate | ID = 0
Description = 16:21:21 - Fehler beim Herstellen der Internetverbindung. 16:21:21
- Serververbindung konnte nicht hergestellt werden..
Error - 03.03.2013 11:21:55 | Computer Name = Tinchen-PC | Source = MCUpdate | ID = 0
Description = 16:21:50 - Fehler beim Herstellen der Internetverbindung. 16:21:50
- Serververbindung konnte nicht hergestellt werden..
[ System Events ]
Error - 16.06.2013 03:52:26 | Computer Name = Tinchen-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden
Fehlers nicht gestartet: %%1069
Error - 16.06.2013 03:58:06 | Computer Name = Tinchen-PC | Source = atapi | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.
Error - 16.06.2013 07:07:52 | Computer Name = Tinchen-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = Der Speicher wurde beim letzten Leistungsübergang des Systems von
der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte
Firmware verfügbar ist.
Error - 18.06.2013 01:45:13 | Computer Name = Tinchen-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
beendet: %%1064
Error - 18.06.2013 01:47:24 | Computer Name = Tinchen-PC | Source = Service Control Manager | ID = 7038
Description = Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser"
mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern
Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
Management Console (MMC).
Error - 18.06.2013 01:47:24 | Computer Name = Tinchen-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden
Fehlers nicht gestartet: %%1069
Error - 18.06.2013 02:45:18 | Computer Name = Tinchen-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = Der Speicher wurde beim letzten Leistungsübergang des Systems von
der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte
Firmware verfügbar ist.
Error - 18.06.2013 12:59:49 | Computer Name = Tinchen-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
beendet: %%1064
Error - 18.06.2013 13:02:08 | Computer Name = Tinchen-PC | Source = Service Control Manager | ID = 7038
Description = Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser"
mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern
Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
Management Console (MMC).
Error - 18.06.2013 13:02:08 | Computer Name = Tinchen-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden
Fehlers nicht gestartet: %%1069
< End of report > --- --- ---
hier das Gmer.txt
GMER Logfile: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-06-18 19:52:46
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD10EAVS-00D7B1 rev.01.01A01 931,51GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Tinchen\AppData\Local\Temp\fwdirfog.sys
---- System - GMER 2.1 ----
SSDT 91128256 ZwCreateSection
SSDT 91128260 ZwRequestWaitReplyPort
SSDT 9112825B ZwSetContextThread
SSDT 91128265 ZwSetSecurityObject
SSDT 9112826A ZwSystemDebugControl
SSDT 911281F7 ZwTerminateProcess
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82A7E9F5 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AB81F2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 82ABF53C 4 Bytes [56, 82, 12, 91] {PUSH ESI; ADC BYTE [EDX], 0x91}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1553 82ABF898 4 Bytes [60, 82, 12, 91] {PUSHA ; ADC BYTE [EDX], 0x91}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1597 82ABF8DC 4 Bytes [5B, 82, 12, 91] {POP EBX; ADC BYTE [EDX], 0x91}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1613 82ABF958 4 Bytes [65, 82, 12, 91] {ADC BYTE [GS:EDX], 0x91}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1667 82ABF9AC 4 Bytes [6A, 82, 12, 91]
.text ...
.vmp2 C:\Windows\system32\drivers\acedrv11.sys entry point in ".vmp2" section [0x9CB5F69D]
.text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0x9CB65000, 0xBB22, 0xE8000020]
.text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0x9CB8A300, 0x1BEE, 0xE8000020]
---- EOF - GMER 2.1 ---- --- --- --- |