Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Externe Festplatte befallen, Daten versteckt

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 25.07.2015, 16:35   #1
Ottel
 
Externe Festplatte befallen, Daten versteckt - Standard

Externe Festplatte befallen, Daten versteckt



Hallo Leute,
Ich bin neu hier im Board und fand die Beiträge die ich mir ab und zu durchgelesen habe sehr hilfreich, weswegen ich mich nun auch mit einem Probem an euch wende.

Ich habe mich heute mal der Externen Festplatte einer Bekannten angenommen, die sich in Australien dort wohl einen Virus draufgespielt hatte. Sämtliche Dateien waren nicht mehr in ihren Ordnern, die Festplatte an sich war aber nicht leer.
Als "Reparatur" hat sie sich einfach alle versteckten Datein auf der Festplatte anzeigen lassen, aber nichts desto trotz würde ich euch bitten, einmal rüber zu schauen und zu überprüfen ob die Festplatte gefahrlos für andere Leute zu benutzen ist.

Ich bin dem Standartprotokoll gefolgt und habe hier die Logfiles von:

Defogger:
Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 16:47 on 25/07/2015 (Otti)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...
Unable to read sptd.sys
SPTD -> Disabled (Service running -> reboot required)


-=E.O.F=-
         
FRST:
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x86) Version: 25-07-2015
durchgeführt von Otti (Administrator) auf OTTI-PC (25-07-2015 16:56:00)
Gestartet von C:\Users\Otti\Downloads
Geladene Profile: Otti (Verfügbare Profile: Otti)
Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) Sprache: Deutsch (Deutschland)
Internet Explorer Version 8 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avguard.exe
(ASUSTeK Computer Inc.) C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
(DeviceVM, Inc.) C:\ASUS.SYS\config\DVMExportService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\System32\PnkBstrA.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\DAODx.exe
(ASUSTeK Computer Inc.) C:\Program Files\ASUS\TurboV EVO\TurboVHelp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avmailc7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avwebg7.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(NEC Electronics Corporation) C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe


==================== Registry (Nicht auf der Ausnahmeliste) ==================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [1780224 2010-03-15] (VIA)
HKLM\...\Run: [TurboV EVO] => C:\Program Files\ASUS\TurboV EVO\TurboV_EVO.exe [9919104 2010-04-07] (ASUSTeK Computer Inc.)
HKLM\...\Run: [Six Engine] => C:\Program Files\ASUS\EPU\EPU.exe [5309056 2010-03-16] (
ASUSTeK Computer Inc.)
HKLM\...\Run: [NUSB3MON] => C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2010-01-22] (NEC Electronics Corporation)
HKLM\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe [43632 2010-01-19] ()
HKLM\...\Run: [tsnp2uvc] => C:\Program Files\Common Files\SNP2UVC\tsnp2uvc.exe [321024 2011-07-20] (Sonix Technology Co., Ltd.)
HKLM\...\Run: [Nvtmru] => "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-03] (NVIDIA Corporation)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\Antivirus\avgnt.exe [730416 2015-06-19] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.Systray.exe [134368 2015-06-02] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [217632 2015-07-07] (Geek Software GmbH)
HKU\S-1-5-21-3534099020-634075679-966876233-1000\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [2895552 2015-07-24] (Valve Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)

HKU\S-1-5-21-3534099020-634075679-966876233-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.ask.com/?l=dis&o=APN10375&gct=hp&apn_ptnrs=^AHP&apn_dtid=^YYYYYY^YY^DE&p2=^AHP^YYYYYY^YY^DE&tpid=SGT-SAT&apn_dbr=ff_16.0&apn_uid=4B8FE4C5-97CF-4033-A601-BCBD1EFFAD61&itbv=11.3.0.661&doi=2012-12-03
HKU\S-1-5-21-3534099020-634075679-966876233-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-05-27] (Oracle Corporation)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-10-02] (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-27] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-3534099020-634075679-966876233-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  Keine Datei
Toolbar: HKU\S-1-5-21-3534099020-634075679-966876233-1000 -> No Name - {5347542D-5341-5400-76A7-7A786E7484D7} -  Keine Datei
Toolbar: HKU\S-1-5-21-3534099020-634075679-966876233-1000 -> No Name - {41564952-412D-5637-00A7-7A786E7484D7} -  Keine Datei
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-10-02] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{C17DD923-E015-4AAE-9D11-5ADE08521ABA}: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Otti\AppData\Roaming\Mozilla\Firefox\Profiles\vd5nyfxp.default-1371114904938
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] ()
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files\Battlelog Web Plugins\2.6.2\npbattlelog.dll [2015-01-13] (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-27] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-27] (Oracle Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-05-28] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-05-28] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3534099020-634075679-966876233-1000: ubisoft.com/uplaypc -> C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-06-11] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Otti\AppData\Roaming\Mozilla\Firefox\Profiles\vd5nyfxp.default-1371114904938\Extensions\adblockpopups@jessehakanen.net.xpi [2013-06-16]
FF Extension: ExHentai Easy 2 - C:\Users\Otti\AppData\Roaming\Mozilla\Firefox\Profiles\vd5nyfxp.default-1371114904938\Extensions\jid1-7NbXi2AqS1oUFw@jetpack.xpi [2014-08-23]
FF Extension: Adblock Plus - C:\Users\Otti\AppData\Roaming\Mozilla\Firefox\Profiles\vd5nyfxp.default-1371114904938\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-16]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-07-04]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2015-07-04]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-07-04]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2015-07-04]
FF HKLM\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff [2013-01-13]

Chrome: 
=======
CHR Profile: C:\Users\Otti\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Otti\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-12]
CHR Extension: (YouTube) - C:\Users\Otti\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-12]
CHR Extension: (Google Search) - C:\Users\Otti\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-12]
CHR Extension: (Gmail) - C:\Users\Otti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-12]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

==================== Dienste (All) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AntiVirMailService; C:\Program Files\Avira\Antivirus\avmailc7.exe [827184 2015-06-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\Antivirus\sched.exe [450808 2015-06-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\Antivirus\avguard.exe [450808 2015-06-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\Antivirus\avwebg7.exe [1188360 2015-06-19] (Avira Operations GmbH & Co. KG)
S4 AODService; C:\Program Files\AMD\OverDrive\AODAssist.exe [136544 2009-10-22] ()
R2 AsSysCtrlService; C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [96896 2009-12-28] (ASUSTeK Computer Inc.)
R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [217280 2015-06-02] (Avira Operations GmbH & Co. KG)
R2 DvmMDES; C:\ASUS.SYS\config\DVMExportService.exe [319488 2009-10-16] (DeviceVM, Inc.) [Datei ist nicht signiert]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [919184 2015-06-03] (NVIDIA Corporation)
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1893008 2015-06-03] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20694160 2015-06-03] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1997168 2015-06-06] (Electronic Arts)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-07-11] ()
S4 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [11296 2009-08-04] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2013-08-03] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-06-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-06-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-20] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-24] (Avira Operations GmbH & Co. KG)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [99952 2010-01-11] (JMicron Technology Corp.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2013-08-03] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [13216 2009-07-16] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18576 2015-06-03] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [41648 2015-05-19] (NVIDIA Corporation)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [3564800 2011-07-22] ()
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2011-09-21] (Duplex Secure Ltd.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-06-19] (Avira Operations GmbH & Co. KG)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1127936 2010-03-02] (VIA Technologies, Inc.)

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-07-25 16:56 - 2015-07-25 16:56 - 00015117 _____ C:\Users\Otti\Downloads\FRST.txt
2015-07-25 16:55 - 2015-07-25 16:56 - 00000000 ____D C:\FRST
2015-07-25 16:55 - 2015-07-25 16:55 - 00000000 ____D C:\Users\Otti\Downloads\FRST-OlderVersion
2015-07-25 16:47 - 2015-07-25 16:48 - 00000020 _____ C:\Users\Otti\defogger_reenable
2015-07-25 14:45 - 2015-07-25 16:49 - 00000842 _____ C:\Windows\PFRO.log
2015-07-25 11:46 - 2015-07-25 16:55 - 01650688 _____ (Farbar) C:\Users\Otti\Downloads\FRST.exe
2015-07-25 11:46 - 2015-07-25 11:46 - 00380416 _____ C:\Users\Otti\Downloads\Gmer-19357.exe
2015-07-25 11:44 - 2015-07-25 11:44 - 00050477 _____ C:\Users\Otti\Downloads\Defogger.exe
2015-07-14 22:22 - 2015-07-14 22:22 - 01187008 _____ (Adobe Systems Incorporated) C:\Users\Otti\Downloads\flashplayer18_ha_install(2).exe
2015-07-13 11:56 - 2015-07-13 11:56 - 00000891 _____ C:\Users\Public\Desktop\Gothic III CP.lnk
2015-07-13 11:50 - 2015-07-13 11:50 - 30254306 _____ (Gothic 3 CPT / Spellbound ) C:\Users\Otti\Downloads\Gothic_3_Community_Patch_v1.6_Incremental.exe
2015-07-12 16:43 - 2015-07-25 09:00 - 00000000 ____D C:\Users\Otti\Documents\gothic3
2015-07-11 16:11 - 2015-07-11 16:11 - 01187520 _____ (Adobe Systems Incorporated) C:\Users\Otti\Downloads\flashplayer18_ha_install(1).exe
2015-07-09 02:52 - 2015-07-09 02:52 - 00001819 _____ C:\Users\Public\Desktop\PDF24 Creator.lnk
2015-07-09 02:52 - 2015-07-09 02:52 - 00001799 _____ C:\Users\Public\Desktop\PDF24 Fax.lnk
2015-07-09 02:52 - 2015-07-09 02:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
2015-07-09 02:52 - 2015-07-09 02:52 - 00000000 ____D C:\Program Files\PDF24
2015-07-09 02:46 - 2015-07-09 02:47 - 16381928 _____ (Geek Software GmbH ) C:\Users\Otti\Downloads\pdf24-creator-7.0.4.exe
2015-07-07 14:14 - 2015-07-07 14:14 - 08209285 _____ C:\Users\Otti\Downloads\Gothic2_130_de.exe
2015-07-07 12:31 - 2015-07-07 12:31 - 00009764 _____ C:\Users\Otti\Downloads\qLKGniPOExtrahieren Ordner.rar
2015-07-07 08:52 - 2015-07-25 16:51 - 00063168 _____ C:\Windows\setupact.log
2015-07-07 08:52 - 2015-07-07 08:52 - 00000000 _____ C:\Windows\setuperr.log
2015-07-04 13:17 - 2015-07-05 19:38 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-07-04 00:20 - 2015-07-04 00:20 - 00000000 ____D C:\Users\Otti\AppData\Local\CEF
2015-07-01 23:42 - 2015-07-14 22:23 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-01 23:42 - 2015-07-14 22:23 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-01 23:37 - 2015-07-01 23:37 - 01125056 _____ (Adobe Systems Incorporated) C:\Users\Otti\Downloads\flashplayer18_ha_install.exe

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-07-25 16:54 - 2011-09-21 18:43 - 00000000 ____D C:\Program Files\Steam
2015-07-25 16:53 - 2015-04-08 19:33 - 00000000 ____D C:\Users\Otti\Desktop\txt. und so
2015-07-25 16:53 - 2011-09-21 17:32 - 01891306 _____ C:\Windows\WindowsUpdate.log
2015-07-25 16:50 - 2012-12-12 22:18 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-25 16:49 - 2011-09-21 17:39 - 00000000 ____D C:\ProgramData\NVIDIA
2015-07-25 16:49 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-25 16:48 - 2009-07-14 06:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-25 16:48 - 2009-07-14 06:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-25 16:47 - 2011-09-21 17:32 - 00000000 ____D C:\Users\Otti
2015-07-25 16:21 - 2012-12-12 22:18 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-25 15:34 - 2011-12-21 13:43 - 00000452 _____ C:\Windows\Tasks\Norton Internet Security - Otti - Vollständiger Systemscan.job
2015-07-25 14:56 - 2011-09-21 17:57 - 00000177 ____H C:\dvmexp.idx
2015-07-25 14:45 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system
2015-07-25 14:29 - 2012-12-03 13:37 - 00000000 ____D C:\ProgramData\APN
2015-07-25 11:51 - 2011-09-21 17:35 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-25 11:49 - 2014-10-29 22:17 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-25 11:42 - 2014-10-29 22:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-07-25 11:42 - 2014-10-29 22:17 - 00000000 ____D C:\Program Files\ Malwarebytes Anti-Malware 
2015-07-25 11:42 - 2012-03-22 16:46 - 00001060 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-07-25 08:58 - 2011-09-21 18:06 - 00000000 ____D C:\Users\Otti\AppData\Local\CrashDumps
2015-07-25 01:23 - 2011-12-08 20:03 - 00000000 ____D C:\Users\Otti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-07-24 19:22 - 2011-09-21 18:43 - 00000000 ____D C:\Program Files\Common Files\Steam
2015-07-14 22:24 - 2011-09-21 20:56 - 00000000 ____D C:\Users\Otti\AppData\Local\Adobe
2015-07-12 16:42 - 2011-12-17 00:43 - 00000000 ____D C:\Users\Otti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-07-09 02:48 - 2011-09-21 21:03 - 00000000 ____D C:\Users\Otti\AppData\Roaming\Adobe
2015-07-06 13:08 - 2015-06-11 19:25 - 00001078 _____ C:\Users\Public\Desktop\Avira.lnk
2015-07-06 13:08 - 2015-05-04 20:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-07-06 13:08 - 2013-08-05 16:49 - 00000000 ____D C:\Program Files\Avira
2015-07-06 13:07 - 2015-05-04 20:28 - 00000000 ____D C:\ProgramData\Package Cache
2015-07-05 19:38 - 2012-05-04 02:47 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-07-03 13:48 - 2015-06-15 12:11 - 00000000 ____D C:\Users\Otti\AppData\Local\Game Dev Tycoon - Steam

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2014-06-05 18:08 - 2014-06-19 21:44 - 0000096 _____ () C:\Users\Otti\AppData\Roaming\LauncherSettings_live.cfg
2014-06-03 19:00 - 2015-05-28 15:36 - 0138056 _____ () C:\Users\Otti\AppData\Roaming\PnkBstrK.sys
2014-10-20 20:19 - 2015-03-22 18:49 - 0001395 _____ () C:\Users\Otti\AppData\Roaming\SpeedRunnersLog.txt
2014-06-05 18:11 - 2014-06-05 18:11 - 0000039 _____ () C:\Users\Otti\AppData\Roaming\TheHunterSettings_steam_live.cfg
2015-06-16 00:03 - 2015-06-16 00:03 - 0007607 _____ () C:\Users\Otti\AppData\Local\Resmon.ResmonCfg

Einige Dateien in TEMP:
====================
C:\Users\Otti\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-07-23 02:46

==================== Ende vom log ============================
         
und FRST Addition
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x86) Version: 25-07-2015
durchgeführt von Otti an 2015-07-25 16:56:38
Gestartet von C:\Users\Otti\Downloads
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-3534099020-634075679-966876233-500 - Administrator - Disabled)
Gast (S-1-5-21-3534099020-634075679-966876233-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3534099020-634075679-966876233-1002 - Limited - Enabled)
Otti (S-1-5-21-3534099020-634075679-966876233-1000 - Administrator - Enabled) => C:\Users\Otti

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.0.42.34 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
AdVenture Capitalist (HKLM\...\Steam App 346900) (Version:  - Hyper Hippo Productions Ltd.)
Age of Empires II: HD Edition (HKLM\...\Steam App 221380) (Version:  - Hidden Path Entertainment, Ensemble Studios)
AMD OverDrive (HKLM\...\{EA18DE8E-B3E6-4D82-A086-9BE2316FA5A5}) (Version: 3.1.0.0342 - Advanced Micro Devices, Inc.)
Amnesia: The Dark Descent (HKLM\...\Steam App 57300) (Version:  - Frictional Games)
ANNO 1404 (HKLM\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.01.0000 - Ubisoft)
Anno 1404 (Version: 1.00.0000 - Ubisoft) Hidden
Assassin's Creed II (HKLM\...\Steam App 33230) (Version:  - Ubisoft Montreal)
Assassin's Creed IV Black Flag (HKLM\...\Steam App 242050) (Version:  - Ubisoft Montreal)
ATI Catalyst Install Manager (HKLM\...\{30EEC7C1-DE2F-2B49-41B1-8B90E05E6815}) (Version: 3.0.762.0 - ATI Technologies, Inc.)
Audiosurf (HKLM\...\Steam App 12900) (Version:  - Dylan Fitterer)
Avira (HKLM\...\{8467e01f-0496-42ce-b247-88ef205b4880}) (Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG)
Avira (Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.11.579 - Avira Operations GmbH & Co. KG)
Battle.net (HKLM\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 1942™ (HKLM\...\{5BE7BD06-512B-43bf-AD78-3BD2A5F5F7B3}) (Version: 1.6.20.0 - Electronic Arts)
Battlefield 3™ (HKLM\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM\...\Battlelog Web Plugins) (Version: 2.6.2 - EA Digital Illusions CE AB)
BioShock (HKU\S-1-5-21-3534099020-634075679-966876233-1000\...\{E280923D-C5D9-4728-8C79-AC9A0DC75875}) (Version: 2.62.0000 - 2K Games)
BioShock 2 (HKLM\...\{4A8B461A-9336-4CF9-98F4-14DD38E673F0}) (Version: 1.00.0000 - 2K Games)
BioShock Infinite (HKLM\...\BioShock Infinite_is1) (Version:  - )
Borderlands (HKLM\...\Steam App 8980) (Version:  - Gearbox Software)
CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform)
Crusader Kings II (HKLM\...\Steam App 203770) (Version:  - Paradox Development Studio)
Dead Space™ (HKLM\...\{4D87DC92-C328-46EC-A7B4-9C88129DC696}) (Version: 1.0.222.0 - Electronic Arts)
Diablo III (HKLM\...\Diablo III) (Version:  - Blizzard Entertainment)
Die Sims™ 3 (HKLM\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.21.123 - Electronic Arts)
Die Sims™ 3 Gib Gas-Accessoires (HKLM\...\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts)
Die Sims™ 3 Late Night (HKLM\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts)
Die Sims™ 3 Lebensfreude (HKLM\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts)
Die Sims™ 3 Luxus-Accessoires (HKLM\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts)
Die Sims™ 3 Reiseabenteuer (HKLM\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts)
Die Sims™ 3 Traumkarrieren (HKLM\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts)
Dota 2 (HKLM\...\Steam App 570) (Version:  - )
Dota 2 Test (HKLM\...\Steam App 205790) (Version:  - )
Dungeon Defenders Demo (HKLM\...\Steam App 201680) (Version:  - )
EPU (HKLM\...\{9C2AC00C-0C06-4B7E-97A4-A833808D54D6}) (Version: 1.02.20 - )
Express Gate (HKLM\...\{99AD9D6D-A456-49EE-8360-F22EE7AA1272}) (Version: 1.5.17.9 - DeviceVM, Inc.)
Fallout 3 (HKU\S-1-5-21-3534099020-634075679-966876233-1000\...\{974C4B12-4D02-4879-85E0-61C95CC63E9E}) (Version: 1.00.0000 - Bethesda Softworks)
Fallout: New Vegas (HKLM\...\Steam App 22380) (Version:  - Bethesda Softworks)
Far Cry® 3 (HKLM\...\Steam App 220240) (Version:  - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai)
FEAR (HKLM\...\{2B653229-9854-4989-B780-D978F5F13EAB}) (Version: 1.00.0000 - Vivendi Universal Games, Inc.)
FlatOut (HKLM\...\Steam App 6220) (Version:  - Bugbear Entertainment)
Free YouTube Download version 3.1.42.1212 (HKLM\...\Free YouTube Download_is1) (Version: 3.1.42.1212 - DVDVideoSoft Ltd.)
Game Dev Tycoon (HKLM\...\Steam App 239820) (Version:  - Greenheart Games)
Geneious 8.0.4 (HKLM\...\4435-7533-6274-7601) (Version: 8.0.4 - Biomatters Ltd)
Google Chrome (HKLM\...\Google Chrome) (Version: 44.0.2403.89 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
Gothic 3 (HKLM\...\Steam App 39500) (Version:  - Piranha – Bytes)
Gothic_Patch (HKLM\...\{302AC480-43D2-11D5-A818-00500435FC18}) (Version:  - )
Grand Theft Auto IV (HKLM\...\Steam App 12210) (Version:  - Rockstar North)
Grand Theft Auto: Episodes from Liberty City (HKLM\...\Steam App 12220) (Version:  - Rockstar North / Toronto)
Guitar Hero III (HKLM\...\{0CE1A6C0-F3F7-49E6-8F9D-2431F9827441}) (Version: 1.31 - Activision)
Heroes of Might & Magic V: Tribes of the East (HKLM\...\Steam App 15370) (Version:  - Nival)
Heroes of Newerth (HKLM\...\hon) (Version: 1.0.20 - S2 Games)
Heroes of the Storm (HKLM\...\Heroes of the Storm) (Version:  - Blizzard Entertainment)
Hitman 2: Silent Assassin (HKLM\...\Steam App 6850) (Version:  - Eidos)
Hitman: Blood Money (HKLM\...\Steam App 6860) (Version:  - Eidos)
ICQ7.2 (HKLM\...\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}) (Version: 7.2 - ICQ)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
Java 8 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
JMicron JMB36X Driver (HKLM\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.00.0000 - JMicron Technology Corp.)
Just Cause 2 (HKLM\...\Steam App 8190) (Version:  - Avalanche)
League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (Version: 3.0.1 - Riot Games ) Hidden
Left 4 Dead 2 (HKLM\...\Steam App 550) (Version:  - Valve)
Lethal League (HKLM\...\Steam App 261180) (Version:  - Team Reptile)
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
measure (HKLM\...\{5FC40A17-BC1D-4F59-A511-B308A669DBAA}) (Version: 4.6.11.1 - Phywe Systeme GmbH)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 RC (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50861 - Microsoft Corporation)
Microsoft Games for Windows - LIVE (HKLM\...\{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}) (Version: 3.1.186.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}) (Version: 3.1.99.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mirror's Edge (HKLM\...\Steam App 17410) (Version:  - DICE)
Monaco (HKLM\...\Steam App 113020) (Version:  - Pocketwatch Games)
Mozilla Firefox 39.0 (x86 de) (HKLM\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
NEC Electronics USB 3.0 Host Controller Driver (HKLM\...\InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}) (Version: 1.0.19.0 - NEC Electronics Corporation)
NEC Electronics USB 3.0 Host Controller Driver (Version: 1.0.19.0 - NEC Electronics Corporation) Hidden
NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.06 - NVIDIA Corporation)
NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5856 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.4.5.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.44 - NVIDIA Corporation)
NVIDIA Grafiktreiber 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.06 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
OpenOffice.org 3.3 (HKLM\...\{4286716B-1287-48E7-9078-3DC8248DBA96}) (Version: 3.3.9567 - OpenOffice.org)
Origin (HKLM\...\Origin) (Version: 9.1.15.109 - Electronic Arts, Inc.)
PAYDAY 2 (HKLM\...\Steam App 218620) (Version:  - OVERKILL - a Starbreeze Studio.)
PC Probe II (HKLM\...\{F7338FA3-DAB5-49B2-900D-0AFB5760C166}) (Version: 1.04.87 - ASUSTeK Computer Inc.)
PDF24 Creator 7.0.4 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
Platform (Version: 1.34 - VIA Technologies, Inc.) Hidden
Port Royale 2 (HKLM\...\Steam App 12470) (Version:  - Ascaron Entertainment ltd.)
Prince of Persia (HKLM\...\{7C11154F-3539-4CB5-979D-EF7913473E53}) (Version: 1.0 - Ubisoft)
PunkBuster Services (HKLM\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
Realtek Ethernet Controller Driver For Windows 7 (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.15.209.2010 - Realtek)
Roogoo (HKLM\...\Steam App 38210) (Version:  - Spidermonk Entertainment)
SEGA Genesis & Mega Drive Classics (HKLM\...\Steam App 34270) (Version:  - Sega)
SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.5.44 - NVIDIA Corporation) Hidden
Sim City 4 Deluxe (HKLM\...\{90EEF48B-EAAF-44DC-B2F6-6FB97D7DAC4E}) (Version: 1.0.0 - Doctor Strange)
SimCity™ Societies (HKLM\...\{0B5154C0-8F00-4616-B0AB-6240AE80D9CE}) (Version: 1.0.0.0 - Electronic Arts)
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.3.11079 - Skype Technologies S.A.)
Skype™ 6.20 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
South Park - The Stick of Truth Version 1.0.1353 (HKLM\...\{83736891-79AE-49BA-96F5-55DD6F2186AC}_is1) (Version: 1.0.1353 - Ubisoft)
SPEEDLINK CASE (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.54200.103 - Sonix)
SpeedRunners (HKLM\...\Steam App 207140) (Version:  - DoubleDutch Games)
StarCraft II (HKLM\...\StarCraft II) (Version:  - Blizzard Entertainment)
Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Super Amazing Wagon Adventure (HKLM\...\Steam App 250500) (Version:  - sparsevector)
TeamSpeak 3 Client (HKU\S-1-5-21-3534099020-634075679-966876233-1000\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Terraria (HKLM\...\Steam App 105600) (Version:  - Re-Logic)
The Elder Scrolls V: Skyrim (HKLM\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD Projekt RED)
TrackMania Nations Forever (HKLM\...\Steam App 11020) (Version:  - Nadeo)
TrackMania² Stadium Open Beta (HKLM\...\Steam App 233070) (Version:  - Nadeo)
Trine 2 (HKLM\...\Steam App 35720) (Version:  - Frozenbyte)
Tropico 3 - Steam Special Edition (HKLM\...\Steam App 23490) (Version:  - Haemimont Games)
TurboV EVO (HKLM\...\{491D92A9-69CA-4EB4-81D3-0106F9337957}) (Version: 1.02.20 - )
Ubisoft Game Launcher (HKLM\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Unturned (HKLM\...\Steam App 304930) (Version:  - Nelson Sexton)
Uplay (HKLM\...\Uplay) (Version: 4.4 - Ubisoft)
VIA Plattform-Geräte-Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.)
VirtualDJ Home FREE (HKLM\...\{5E1375CB-6792-4464-8715-CC3EC83D48FA}) (Version: 7.0.5 - Atomix Productions)
VLC media player 1.1.9 (HKLM\...\VLC media player) (Version: 1.1.9 - VideoLAN)
WinRAR 4.01 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)
YTD Video Downloader 3.9.6 (HKLM\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 3.9.6 - GreenTree Applications SRL) <==== ATTENTION

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{1c492e6a-2803-5ed7-83e1-1b1d4d41eb39}\InprocServer32 -> C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{30A2652A-DDF7-45e7-ACA6-3EAB26FC8A4E}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{41662FC2-0D57-4aff-AB27-AD2E12E7C273}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{448BB771-CFE2-47C4-BCDF-1FBF378E202C}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{7B342DC4-139A-4a46-8A93-DB0827CCEE9C}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\ooofilt.dll (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{7FA8AE11-B3E3-4D88-AABF-255526CD1CE8}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{82154420-0FBF-11d4-8313-005004526AB4}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{D0484DE6-AAEE-468a-991F-8D4B0737B57A}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{D2D59CD1-0A6A-4D36-AE20-47817077D57C}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{E5A0B632-DFBA-4549-9346-E414DA06E6F8}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{EE5D1EA4-D445-4289-B2FC-55FC93693917}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{F616B81F-7BB8-4F22-B8A5-47428D59F8AD}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)

==================== Wiederherstellungspunkte =========================

12-07-2015 16:40:11 DirectX wurde installiert
13-07-2015 11:54:57 Microsoft Visual C++ 2005 Redistributable wird installiert
23-07-2015 02:55:40 Geplanter Prüfpunkt

==================== Hosts Inhalt: ==========================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {212395F8-BF05-48CB-8DD8-CC09589DF3C0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-12] (Google Inc.)
Task: {260E6265-B5D2-43E2-A1CB-25C1AD7B3936} - System32\Tasks\{F9DDD321-AAE5-4267-A62E-46046C1DA01D} => H:\C&C G\generals.exe [2003-02-09] ()
Task: {31855B55-CA9B-460D-8772-021CB6D58D96} - System32\Tasks\{C17E8858-867F-44F9-8E08-BE03850DF90A} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=5.3.0.111.259&amp;LastError=404
Task: {390D5489-300C-463B-B86B-2979C85004AF} - System32\Tasks\Norton Internet Security - Otti - Vollständiger Systemscan => C:\Program Files\Norton Internet Security\Engine\17.9.0.12\navw32.exe
Task: {69A655CC-26B7-494E-B630-A69355641EBF} - System32\Tasks\ASUS\ASUS RegRun Loader => C:\Program Files\ASUS\AASP\1.01.02\AsLoader.exe [2009-12-28] (ASUSTeK Computer Inc.)
Task: {88EEE1FF-1FE5-48D8-8148-1FAB946D6C1E} - System32\Tasks\ASUS\RunDAOD => C:\Windows\DAODx.exe [2009-03-30] ()
Task: {93648F48-097D-47CE-AF18-E7E347D1BA99} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd)
Task: {9804ABC1-EFEE-4444-9248-BEF74E812770} - System32\Tasks\{D75400F9-CEF5-4B9A-8A35-583C9357DFC0} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=5.3.0.111.259&amp;LastError=12007
Task: {98415088-2D91-412A-8F50-86C0F8C528FF} - System32\Tasks\{56861F2F-779A-4A46-B206-DBEA0CDCC14C} => pcalua.exe -a C:\Users\Otti\Downloads\Diablo-III-8370-deDE-Installer-downloader.exe -d "C:\Program Files\Mozilla Firefox"
Task: {A97CA397-B93D-43D0-A171-0DE73D9B93EA} - System32\Tasks\{D2B8A2BB-6D39-4FDF-9DBB-257E057C55F3} => D:\SteamLibrary\SteamApps\common\PAYDAY 2\payday2_win32_release.exe [2015-07-17] ()
Task: {E41C18AC-9250-42F9-B625-11ED57641030} - System32\Tasks\ASUS\TurboVHelp => C:\Program Files\ASUS\TurboV EVO\TurboVHELP.exe [2010-04-02] (ASUSTeK Computer Inc.)
Task: {F2905056-495B-4773-9D29-FB4B97C3643B} - System32\Tasks\{FEAFA12A-00FB-49E0-AB06-AB93FE578D57} => pcalua.exe -a F:\DIRECTX\dxsetup.exe -d F:\DIRECTX
Task: {FE5205E8-7F93-4A10-924B-0184E8104307} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-12] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Internet Security - Otti - Vollständiger Systemscan.job => C:\Program Files\Norton Internet Security\Engine\17.9.0.12\navw32.exe

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2012-03-20 22:58 - 2015-05-28 05:50 - 00106128 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2014-06-03 19:00 - 2014-07-11 11:06 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe
2009-03-30 08:32 - 2009-03-30 08:32 - 00032768 ____R () C:\Windows\DAODx.exe
2011-09-21 19:09 - 2009-09-30 05:33 - 00024576 ____R () C:\Windows\system32\AsIO.dll
2011-09-21 19:09 - 2010-02-08 17:19 - 00053248 _____ () C:\Program Files\ASUS\TurboV EVO\HookKey32.dll
2011-09-21 19:09 - 2008-12-10 20:04 - 00253952 _____ () C:\Program Files\ASUS\TurboV EVO\pngio.dll
2015-06-19 12:30 - 2015-06-03 23:06 - 00011920 _____ () C:\Program Files\NVIDIA Corporation\Update Core\detoured.dll
2012-01-12 19:39 - 2011-05-28 23:04 - 00140288 _____ () C:\Program Files\WinRAR\rarext.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. The "AlternateShell" value will be restored.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer trusted/restricted ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-3534099020-634075679-966876233-1000\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

MSCONFIG\Services: APNMCP => 2
MSCONFIG\Services: Skype C2C Service => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: ApnTBMon => "C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: EKIJ5000StatusMonitor => C:\Windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: snp2uvc => C:\Windows\vsnp2uvc.exe

==================== FirewallRules (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{E568A85F-3488-4295-AD5C-F3814D61B0FA}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{A9E0534C-D39E-4807-901F-FEDB6025091F}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{573A2CBA-DDA1-4D07-9AE4-8274B26F0A43}] => (Allow) D:\World of Warcraft\Launcher.exe
FirewallRules: [{A341FD75-CA47-42A3-A435-4030FCEA6F30}] => (Allow) D:\World of Warcraft\Launcher.exe
FirewallRules: [{9DAE4A5D-0818-4BA5-B355-43398E62720C}] => (Allow) D:\World of Warcraft\Launcher.patch.exe
FirewallRules: [{4DCA2361-29A6-4B99-8745-6219236D5C96}] => (Allow) D:\World of Warcraft\Launcher.patch.exe
FirewallRules: [{467A5113-CCD2-4111-947D-3D1F8E483ADB}] => (Allow) C:\Program Files\ICQ7.2\ICQ.exe
FirewallRules: [{93840C42-9FF7-4B9F-9E19-E9BF631E1F6E}] => (Allow) C:\Program Files\ICQ7.2\ICQ.exe
FirewallRules: [{DAAF1158-F8FF-4956-B07A-B6C83575AAFA}] => (Allow) C:\Program Files\ICQ7.2\ICQ.exe
FirewallRules: [{AFA5CA22-0E17-4923-B5BE-235315446348}] => (Allow) C:\Program Files\ICQ7.2\ICQ.exe
FirewallRules: [{D4DEDCCF-19F5-4192-8BDA-505C7D9DD83B}] => (Allow) C:\Program Files\ICQ7.2\aolload.exe
FirewallRules: [{C029ECB3-445A-4D5E-99C0-176570E472B1}] => (Allow) C:\Program Files\ICQ7.2\aolload.exe
FirewallRules: [{B666F467-9BC4-442F-97E0-4006B9DD1793}] => (Allow) E:\WoW Test\World of Warcraft Public Test\Launcher.exe
FirewallRules: [{8E64879A-AAAD-48B9-8E61-0DD806E4C57D}] => (Allow) E:\WoW Test\World of Warcraft Public Test\Launcher.exe
FirewallRules: [{0C42C1C6-0E4C-4241-8878-A34D1E6D809C}] => (Allow) E:\WoW Test\World of Warcraft Public Test\Launcher.patch.exe
FirewallRules: [{6C7AD351-0845-4F47-8AEA-55F62B919BF9}] => (Allow) E:\WoW Test\World of Warcraft Public Test\Launcher.patch.exe
FirewallRules: [{03D4C544-BBF1-487E-BA25-0A60BE018614}] => (Allow) E:\World of Warcraft\Launcher.exe
FirewallRules: [{279FFE3F-4B7C-42AD-8F3A-32CC6F43B152}] => (Allow) E:\World of Warcraft\Launcher.exe
FirewallRules: [{A6FB244B-F89A-4EA4-868B-F1EF7F1A9B3C}] => (Allow) E:\World of Warcraft\Launcher.patch.exe
FirewallRules: [{FEB4BC64-D50C-496A-A224-167513946BCF}] => (Allow) E:\World of Warcraft\Launcher.patch.exe
FirewallRules: [{52CDAF9D-044F-4859-A917-322F87BC3599}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{96586C3E-15CC-4980-87E7-D1B8CAAA03A7}E:\warcraft iii\war3.exe] => (Allow) E:\warcraft iii\war3.exe
FirewallRules: [UDP Query User{DCA09D93-DD03-43C1-AB7D-1CB5E147E855}E:\warcraft iii\war3.exe] => (Allow) E:\warcraft iii\war3.exe
FirewallRules: [TCP Query User{1F7797DB-BD7B-4E47-AC82-34E291AED0A7}E:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe
FirewallRules: [UDP Query User{636CD2BC-7259-42A0-B2CC-D285CFBB4B07}E:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe
FirewallRules: [{D70989FC-7720-4569-A26B-3CA3D490A0E2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.515\Agent.exe
FirewallRules: [{E4BED6F8-78B1-4792-A325-EEFAA690F53F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.515\Agent.exe
FirewallRules: [{C4C007F1-E78D-4B10-BC07-585A00768CB6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.516\Agent.exe
FirewallRules: [{A0D3BFBC-0453-4AA2-AD12-311105D783C0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.516\Agent.exe
FirewallRules: [{D6CD1D59-ED4E-4474-9D87-A21357D70DF5}] => (Allow) C:\Program Files\Diablo III Beta\Diablo III.exe
FirewallRules: [{E66780C7-C155-4CEB-B8E3-D6A356088FE8}] => (Allow) C:\Program Files\Diablo III Beta\Diablo III.exe
FirewallRules: [{76B3B89E-08B5-4840-B208-8E4230EC0498}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.649\Agent.exe
FirewallRules: [{A17AFCD0-C9B1-47B1-8638-BC90446B51D3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.649\Agent.exe
FirewallRules: [{2272C476-2915-4E3E-80F3-B1F24014B150}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{EAAB0B20-5C10-4E34-98AB-65764C0594BC}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [TCP Query User{05F0CA97-12C9-4A60-AC40-86D4C94CCBDA}C:\programdata\battle.net\agent\agent.649\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.649\agent.exe
FirewallRules: [UDP Query User{65BD2E2B-B2C3-4792-9D74-98488376C42D}C:\programdata\battle.net\agent\agent.649\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.649\agent.exe
FirewallRules: [TCP Query User{FF81B32F-D392-47E3-BC0F-3D8030FF090E}C:\program files\diablo iii beta\diablo iii.exe] => (Allow) C:\program files\diablo iii beta\diablo iii.exe
FirewallRules: [UDP Query User{D801B325-89B4-418C-9C30-0EF3A3AA4A05}C:\program files\diablo iii beta\diablo iii.exe] => (Allow) C:\program files\diablo iii beta\diablo iii.exe
FirewallRules: [{A8C1D08D-08F6-461B-A68E-D3F81DD2B0C5}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman 2 Silent Assassin\hitman2.exe
FirewallRules: [{3A06FA7E-AEBF-47E9-A4C0-D94A7B0923F1}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman 2 Silent Assassin\hitman2.exe
FirewallRules: [{A490D29C-331B-4728-9683-61457735592C}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman 2 Silent Assassin\config.exe
FirewallRules: [{92EC4CEE-6AA8-4AA8-8879-1BE0C5B993F9}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman 2 Silent Assassin\config.exe
FirewallRules: [{0D2FCEC1-6A15-44C3-9B8C-6444E5E9FF45}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman Blood Money\HitmanBloodMoney.exe
FirewallRules: [{1883B0E8-EF14-4FC1-9C9E-1819E0D38C82}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman Blood Money\HitmanBloodMoney.exe
FirewallRules: [{0CE86750-7537-4D03-AB33-406D1D3B1BD3}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman Blood Money\configure.exe
FirewallRules: [{C48C6730-224A-46E5-86F0-E7CF2F9B13D8}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman Blood Money\configure.exe
FirewallRules: [TCP Query User{1764764C-FD19-4C15-B299-D971E3B148E7}E:\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe
FirewallRules: [UDP Query User{ED3D5300-D335-43BC-93A5-18461F2934F2}E:\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe
FirewallRules: [TCP Query User{E9AD4D43-9545-453D-B639-F1E6DBDBF547}C:\programdata\battle.net\agent\agent.749\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.749\agent.exe
FirewallRules: [UDP Query User{0F878FC7-073B-4856-AF45-6B671FAE64FF}C:\programdata\battle.net\agent\agent.749\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.749\agent.exe
FirewallRules: [TCP Query User{A164D4CD-B1DE-4CF0-BBD0-FF8DD47F49F3}E:\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe
FirewallRules: [UDP Query User{B3FEA817-DF86-4037-A347-60B98C067355}E:\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe
FirewallRules: [{8E60F03B-866C-4994-92CE-4D032ADBCA0A}] => (Allow) C:\Program Files\Steam\SteamApps\common\dungeon defenders demo\Binaries\Win32\DungeonDefenders.exe
FirewallRules: [{49F95687-4AFB-4BA0-AF52-851F92C8A763}] => (Allow) C:\Program Files\Steam\SteamApps\common\dungeon defenders demo\Binaries\Win32\DungeonDefenders.exe
FirewallRules: [TCP Query User{BB0A4E42-766C-480E-A123-2F6EBFB096BA}E:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe
FirewallRules: [UDP Query User{335A9644-8FFA-47ED-847F-6165B104F5CC}E:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe
FirewallRules: [TCP Query User{F82639CF-EF49-4A3E-B09C-0B2352E173D9}C:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe] => (Allow) C:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe
FirewallRules: [UDP Query User{C0F3DBA2-129D-401D-A4DA-25DC8972F4B4}C:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe] => (Allow) C:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe
FirewallRules: [TCP Query User{3704E7FE-25F0-4611-B641-48713D4AD6AB}C:\programdata\battle.net\agent\agent.868\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.868\agent.exe
FirewallRules: [UDP Query User{C27B6CD4-5BF0-4C83-9109-BEA2778BEE9C}C:\programdata\battle.net\agent\agent.868\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.868\agent.exe
FirewallRules: [TCP Query User{C03462CD-672A-4291-817F-095DC4E694FC}C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader.exe] => (Allow) C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader.exe
FirewallRules: [UDP Query User{16992B69-EF89-432D-B0E2-913946A143BB}C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader.exe] => (Allow) C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader.exe
FirewallRules: [{0E05B281-A4B3-4DBC-BA94-C4AB44B086B8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.913\Agent.exe
FirewallRules: [{D43E50CF-3391-4873-A870-57346655AB02}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.913\Agent.exe
FirewallRules: [TCP Query User{E999B39F-F3D3-40DA-8B35-9907B9EAA645}C:\programdata\battle.net\agent\agent.954\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.954\agent.exe
FirewallRules: [UDP Query User{36342DE5-2EF6-4367-A5C4-250E53F5A050}C:\programdata\battle.net\agent\agent.954\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.954\agent.exe
FirewallRules: [{79A44702-3AFE-47C1-AAE7-DB79D8BA6F13}] => (Allow) D:\2K Games\Bioshock 2\SP\Builds\Binaries\Bioshock2.exe
FirewallRules: [{508E877F-B18A-455D-B2B9-7BFF9AEEC227}] => (Allow) D:\2K Games\Bioshock 2\SP\Builds\Binaries\Bioshock2.exe
FirewallRules: [{C03D883F-0C85-4035-A789-282E3EBC172E}] => (Allow) D:\2K Games\Bioshock 2\MP\Builds\Binaries\Bioshock2.exe
FirewallRules: [{731B2187-EABA-4E95-B12D-E51A402C21F6}] => (Allow) D:\2K Games\Bioshock 2\MP\Builds\Binaries\Bioshock2.exe
FirewallRules: [TCP Query User{A83941C7-82E1-42FD-B999-6D08E9553220}C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader(1).exe] => (Allow) C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader(1).exe
FirewallRules: [UDP Query User{94411FCA-8831-4979-B9E9-94EB776D3844}C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader(1).exe] => (Allow) C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader(1).exe
FirewallRules: [{6243AD7F-F734-4A3B-A3E9-3BA345B07843}] => (Allow) D:\Diablo III\Diablo III.exe
FirewallRules: [{527B18BD-C8CC-4AA3-853B-37007B844515}] => (Allow) D:\Diablo III\Diablo III.exe
FirewallRules: [TCP Query User{F1BDAD3D-27C3-4B5F-AB6D-EFCB475CF6E4}C:\programdata\battle.net\agent\agent.976\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.976\agent.exe
FirewallRules: [UDP Query User{F1874D76-E126-4088-A6F4-B4626133C55F}C:\programdata\battle.net\agent\agent.976\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.976\agent.exe
FirewallRules: [TCP Query User{0EEA1371-F366-4848-B7D6-57E57C7B4EBB}C:\programdata\battle.net\agent\agent.998\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.998\agent.exe
FirewallRules: [UDP Query User{47FB1774-5A72-4E0D-B267-5817CC27D0DA}C:\programdata\battle.net\agent\agent.998\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.998\agent.exe
FirewallRules: [TCP Query User{DF358BBB-C9A9-4F76-BED6-43B18766A637}C:\programdata\battle.net\agent\agent.1040\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.1040\agent.exe
FirewallRules: [UDP Query User{1693B1ED-D012-4CA2-9F5A-1917E5DFA10E}C:\programdata\battle.net\agent\agent.1040\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.1040\agent.exe
FirewallRules: [{880138E1-65F8-4FF2-B812-1FF88A3C7C92}] => (Allow) C:\Program Files\Steam\SteamApps\common\borderlands\Binaries\Borderlands.exe
FirewallRules: [{8F9AFAB6-B2A8-4EE1-AB3F-EC21CE55B2BB}] => (Allow) C:\Program Files\Steam\SteamApps\common\borderlands\Binaries\Borderlands.exe
FirewallRules: [TCP Query User{46267F84-A1C1-461F-8682-36DBC8C7FEDE}D:\guitar hero iii\gh3.exe] => (Block) D:\guitar hero iii\gh3.exe
FirewallRules: [UDP Query User{25BF16CE-4EEF-4F91-95DC-7F9DD2342ACD}D:\guitar hero iii\gh3.exe] => (Block) D:\guitar hero iii\gh3.exe
FirewallRules: [{272884C9-FF1B-4D06-8627-B9E9B04B92A2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe
FirewallRules: [{EFB1F124-0471-4972-8A86-A9078CC11594}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe
FirewallRules: [{B221F76D-14DF-4742-AC3E-94CAC52A0784}] => (Allow) C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{22F4F794-D602-494D-AF25-9047DD00AC1C}] => (Allow) C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{0425783C-CB3F-455D-9687-B0D1CE0117C7}] => (Allow) D:\Assassin's Creed II\AssassinsCreedIIGame.exe
FirewallRules: [{6541CD77-D363-4223-B349-1B6AB7D218B1}] => (Allow) D:\Assassin's Creed II\AssassinsCreedIIGame.exe
FirewallRules: [{58DEC5C5-C756-409C-A113-26625DB5924A}] => (Allow) D:\Assassin's Creed II\AssassinsCreedII.exe
FirewallRules: [{97BE214F-9FD7-4AEA-8273-5AA4B2F49CDE}] => (Allow) D:\Assassin's Creed II\AssassinsCreedII.exe
FirewallRules: [{E95B16E5-6E54-404B-864A-C3D5E82F39E5}] => (Allow) D:\Assassin's Creed II\UPlayBrowser.exe
FirewallRules: [{4B06FC8A-A5B9-416B-AB70-1100FA0C2C9D}] => (Allow) D:\Assassin's Creed II\UPlayBrowser.exe
FirewallRules: [TCP Query User{2D5E9B56-FD7C-4D71-871D-8A95716D419C}E:\warcraft iii\war3.exe] => (Block) E:\warcraft iii\war3.exe
FirewallRules: [UDP Query User{8BC5115D-3876-4C78-8E0A-8B062F7F5479}E:\warcraft iii\war3.exe] => (Block) E:\warcraft iii\war3.exe
FirewallRules: [{AF4E9EF3-B3E0-475A-ADCC-4934F2365851}] => (Allow) D:\Prince of Persia\Prince of Persia.exe
FirewallRules: [{9ADB38DE-162D-4AA3-8421-6ED153EBDEF2}] => (Allow) D:\Prince of Persia\Prince of Persia.exe
FirewallRules: [{C313EF7B-3312-4C73-B45C-4F215E2DDFE6}] => (Allow) D:\Prince of Persia\PrinceOfPersia_Launcher.exe
FirewallRules: [{1BBE6291-4B67-4428-A6B2-EF25FA036FC5}] => (Allow) D:\Prince of Persia\PrinceOfPersia_Launcher.exe
FirewallRules: [TCP Query User{3957A71D-F374-42A4-82EC-F54E31162431}D:\electronic arts\deadspace\deadspace.exe] => (Block) D:\electronic arts\deadspace\deadspace.exe
FirewallRules: [UDP Query User{28C11678-3FE6-44F2-BAC9-906C81604573}D:\electronic arts\deadspace\deadspace.exe] => (Block) D:\electronic arts\deadspace\deadspace.exe
FirewallRules: [TCP Query User{76D2DD88-F48C-4E28-9A59-AFD6BC4D957B}D:\electronic arts\deadspace\dead space.exe] => (Block) D:\electronic arts\deadspace\dead space.exe
FirewallRules: [UDP Query User{D1C93ADB-6154-4E1D-A17C-0012DFC4254D}D:\electronic arts\deadspace\dead space.exe] => (Block) D:\electronic arts\deadspace\dead space.exe
FirewallRules: [{35933EE3-F9AD-4334-A439-47B6D49479D5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe
FirewallRules: [{645483AD-43D2-44BD-8F03-20835B494638}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe
FirewallRules: [{325A6244-9B92-46E4-B9AC-D6116E907431}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe
FirewallRules: [{BC059A93-A380-453A-BD21-B7A58003BF11}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe
FirewallRules: [{F52BE773-E851-4196-AD7C-B7E444AA7EEB}] => (Allow) C:\Program Files\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe
FirewallRules: [{BA3C7D9F-F7C8-4E32-B0BA-3428A756C7DD}] => (Allow) C:\Program Files\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe
FirewallRules: [TCP Query User{34D6E995-FB14-4058-A1D0-345E8701F719}C:\program files\java\jre6\bin\java.exe] => (Allow) C:\program files\java\jre6\bin\java.exe
FirewallRules: [UDP Query User{37EE1F71-B728-4F17-BAF2-452B7F870A33}C:\program files\java\jre6\bin\java.exe] => (Allow) C:\program files\java\jre6\bin\java.exe
FirewallRules: [TCP Query User{15133073-817B-4729-94B9-7AAE23406460}C:\program files\java\jre6\bin\javaw.exe] => (Allow) C:\program files\java\jre6\bin\javaw.exe
FirewallRules: [UDP Query User{752A253E-DE53-4B24-AADA-8345C76BA07F}C:\program files\java\jre6\bin\javaw.exe] => (Allow) C:\program files\java\jre6\bin\javaw.exe
FirewallRules: [TCP Query User{3714A085-66AD-4E71-BF6E-71AA78545D4D}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{C27B4C30-292D-46E9-A90B-0BDED30AC2A9}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{31A67AF3-9FEB-4E65-BFFE-780B618AAE61}] => (Allow) C:\Program Files\Origin Games\Battlefield 1942\BF1942.exe
FirewallRules: [{7694C910-321C-4770-A206-C26D65AE2430}] => (Allow) C:\Program Files\Origin Games\Battlefield 1942\BF1942.exe
FirewallRules: [{2141C595-3A0D-42C8-9482-AFA254FE720B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe
FirewallRules: [{4493DC5D-D4D9-4602-91AF-D9CB92489154}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe
FirewallRules: [TCP Query User{8D2693C9-53C3-4BA4-9375-A88E0977113B}D:\heroes of newerth\hon.exe] => (Block) D:\heroes of newerth\hon.exe
FirewallRules: [UDP Query User{87AABD27-E609-4ECE-BEAA-518C7428EB9E}D:\heroes of newerth\hon.exe] => (Block) D:\heroes of newerth\hon.exe
FirewallRules: [{99634AC9-3115-4F1D-9914-B51BC762E627}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{80C7397A-6FF9-4068-B14F-326F7DB4E677}] => (Allow) C:\Program Files\Steam\SteamApps\common\ManiaPlanet_TMStadium\ManiaPlanetLauncher.exe
FirewallRules: [{A1CD4298-0885-4A77-B540-8089DCE76B0C}] => (Allow) C:\Program Files\Steam\SteamApps\common\ManiaPlanet_TMStadium\ManiaPlanetLauncher.exe
FirewallRules: [{C51CE07B-0494-4A6A-A89A-79D98A3CF732}] => (Allow) C:\Program Files\Steam\SteamApps\common\ManiaPlanet_TMStadium\ManiaPlanet.exe
FirewallRules: [{C9AD272B-4A78-4E58-A4B6-6A39936C0BB1}] => (Allow) C:\Program Files\Steam\SteamApps\common\ManiaPlanet_TMStadium\ManiaPlanet.exe
FirewallRules: [{A95E232C-B319-4BA0-9C65-1BED433C1622}] => (Allow) C:\Program Files\Steam\SteamApps\common\TrackMania Nations Forever\TmForever.exe
FirewallRules: [{F3209092-4D43-49CF-AF98-81F3FE8667DB}] => (Allow) C:\Program Files\Steam\SteamApps\common\TrackMania Nations Forever\TmForever.exe
FirewallRules: [{F4D9DF15-8DAA-4384-A9F6-CE9A828C6C56}] => (Allow) C:\Program Files\Steam\SteamApps\common\TrackMania Nations Forever\TmForeverLauncher.exe
FirewallRules: [{2D6C2AC8-4F23-41D6-B5B2-1F6EADF26422}] => (Allow) C:\Program Files\Steam\SteamApps\common\TrackMania Nations Forever\TmForeverLauncher.exe
FirewallRules: [{2E3A52B2-9761-4263-8CA3-6F563ECBFF07}] => (Allow) D:\F.E.A.R\FEAR.exe
FirewallRules: [{656AEB94-F935-43A4-A4E3-122EC7132AE4}] => (Allow) D:\F.E.A.R\FEAR.exe
FirewallRules: [{676ADBF2-1798-4815-9B7A-49FB3CE901C8}] => (Allow) D:\F.E.A.R\FEARMP.exe
FirewallRules: [{8BAB504C-4E98-4A56-A928-3828454483B1}] => (Allow) D:\F.E.A.R\FEARMP.exe
FirewallRules: [TCP Query User{E7AF5D4F-EF15-4A40-A03E-3443AF39AA9A}D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe
FirewallRules: [UDP Query User{5C6519CA-8BB6-4337-B94E-7F8FF6A379C6}D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe
FirewallRules: [TCP Query User{E5A8D9E6-2A8A-4DC6-B98E-C2D98076786A}D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Block) D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe
FirewallRules: [UDP Query User{43A26C19-0EE3-40AD-A046-29CD1BACA4B2}D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Block) D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe
FirewallRules: [TCP Query User{2FF589EC-9F9B-44EC-9715-75E83491C73D}D:\magic 2014 — duels of the planeswalkers\dotp_d14.exe] => (Block) D:\magic 2014 — duels of the planeswalkers\dotp_d14.exe
FirewallRules: [UDP Query User{B78212E9-3466-4B51-B568-F39DD06EEAE5}D:\magic 2014 — duels of the planeswalkers\dotp_d14.exe] => (Block) D:\magic 2014 — duels of the planeswalkers\dotp_d14.exe
FirewallRules: [{ADE60596-8BDF-443E-AC4B-8B4ED51290E3}] => (Allow) C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{0002D1DF-8D83-401F-8915-F378E9DB6864}] => (Allow) C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [TCP Query User{D8A390AD-4E3A-4332-9AFA-83AA3A78E957}D:\anno 1404\tools\anno4web.exe] => (Block) D:\anno 1404\tools\anno4web.exe
FirewallRules: [UDP Query User{EC343EE4-3123-4FC2-A343-B35F5E1D2862}D:\anno 1404\tools\anno4web.exe] => (Block) D:\anno 1404\tools\anno4web.exe
FirewallRules: [TCP Query User{1DB9693B-C1BF-4603-98DA-05B61DF94278}E:\magic 2014 — duels of the planeswalkers\dotp_d14.exe] => (Block) E:\magic 2014 — duels of the planeswalkers\dotp_d14.exe
FirewallRules: [UDP Query User{EFEC7492-6516-412A-93B7-7086CF135772}E:\magic 2014 — duels of the planeswalkers\dotp_d14.exe] => (Block) E:\magic 2014 — duels of the planeswalkers\dotp_d14.exe
FirewallRules: [TCP Query User{479A26BB-6461-498D-94A3-D0361FE5032D}D:\dead island\deadislandgame_x86_rwdi.exe] => (Block) D:\dead island\deadislandgame_x86_rwdi.exe
FirewallRules: [UDP Query User{A23471E0-459A-472F-8BE2-F62199E28B32}D:\dead island\deadislandgame_x86_rwdi.exe] => (Block) D:\dead island\deadislandgame_x86_rwdi.exe
FirewallRules: [{F9C77335-EA3F-4A95-996E-FCF0C6D65114}] => (Allow) C:\Program Files\Steam\SteamApps\common\Marvel Heroes\UnrealEngine3\Binaries\Win32\MarvelGame.exe
FirewallRules: [{00C66733-C1CF-4075-B11D-FAB7D2EBC2A5}] => (Allow) C:\Program Files\Steam\SteamApps\common\Marvel Heroes\UnrealEngine3\Binaries\Win32\MarvelGame.exe
FirewallRules: [TCP Query User{54566374-E743-460B-B0CD-AE04F8580DDD}D:\anno 1404\tools\anno4web.exe] => (Block) D:\anno 1404\tools\anno4web.exe
FirewallRules: [UDP Query User{8EB29137-663B-4786-99A0-7F87EFEC6F39}D:\anno 1404\tools\anno4web.exe] => (Block) D:\anno 1404\tools\anno4web.exe
FirewallRules: [{6ED7DA77-7316-40D0-98E1-23F6A7D76E45}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{F74AF459-9A7D-4916-B29D-68D60D479973}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{6A7003E2-F5BD-4C6E-97CB-4BB597FCF57C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{B8623E96-5E41-455D-9BA3-FECA9C84F24A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{03D54A90-E92D-4874-B66F-C00BC1F02DEC}D:\steamlibrary\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe] => (Block) D:\steamlibrary\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe
FirewallRules: [UDP Query User{E94D12D0-334B-4DB9-844C-CF9EF14555CC}D:\steamlibrary\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe] => (Block) D:\steamlibrary\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe
FirewallRules: [TCP Query User{2EA24E4C-060D-4E7E-AED0-C010241D8658}C:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe] => (Block) C:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe
FirewallRules: [UDP Query User{BA7EE73D-26E4-4222-B24F-6531175CC604}C:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe] => (Block) C:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe
FirewallRules: [{E7C36135-BB2D-430B-A799-5CCB7B502170}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{6D42EDEF-A367-4083-9CAF-4AE03FE79D27}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{7F7C8B25-BAC4-457E-960D-E6D784CECBE9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{F43A1D6E-3E8A-4344-8005-9617EA62A696}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{64B2EAD2-F488-447A-B17F-9751C1A3BC02}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{8300EB33-51CC-4E18-830B-E54FF15E32AA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{8EB3947B-0581-43E1-B85D-161DD0361F25}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{D8DB85C6-E2AB-4A3E-99A5-A0FEC926F3BD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{2526CDAC-79F6-43C5-B444-0201B7760886}] => (Allow) D:\SteamLibrary\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{2B74999D-72A7-48B1-B017-1B4A0C907CF7}] => (Allow) D:\SteamLibrary\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{D97A092E-7E32-48BF-A899-8C1CF2211A4E}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{A9318A99-42EF-4BCF-9F67-E5578DF5E66D}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{E830A068-1AED-44C6-9CCD-5147B4985FCD}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{0B40C744-0F8A-4070-84B2-01EA4B761D88}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{0CCC8685-6953-4D7C-88CF-0228E715D581}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{6ECD6B26-F0EA-4902-8D5B-6418A2988466}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{424CFC3F-541B-40B8-B3BA-533F8141A0EF}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{4DA40D0E-5DB9-423D-9DBB-8AE84BBFC74B}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{C1E2AC4E-68CF-441F-BDC8-2096423AF90F}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{06F4D475-06BB-4F37-B510-0D10C112ACCD}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{82A1CC89-879B-419E-A0BB-CAB5B4F2E3F1}] => (Allow) C:\Windows\System32\PnkBstrA.exe
FirewallRules: [{A639A706-06D1-4995-AF32-0819A7B8EA39}] => (Allow) C:\Windows\System32\PnkBstrA.exe
FirewallRules: [{81CF0714-56EF-4029-9BBE-4AF2568997C8}] => (Allow) C:\Windows\System32\PnkBstrB.exe
FirewallRules: [{45BF4069-9800-4429-9AC2-1D33A6C53B73}] => (Allow) C:\Windows\System32\PnkBstrB.exe
FirewallRules: [{427BD3D2-36BD-42F6-8B0E-02F8D25EFD94}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{9F4D8942-34B1-4BF5-B25B-284C7C946315}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{FF31A829-99CB-46D3-B745-2EE89F9AC1C7}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{B67AA204-A108-43B6-8CA9-5BB4D041E18D}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{B9FDFC38-182C-421E-8C50-D706EDC2B143}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{2A12023F-72B2-42C9-AE6D-F7234F2D7F03}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{B5727E9B-59A1-40F8-B58E-150491FB1B77}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{7F858E23-BE14-464E-8943-74B886D4EB87}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{011DB4AA-14F7-401D-899C-DBE0E97985B0}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{3F84FDB6-88B9-4F90-BECB-B25B4017FD17}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{554933FE-3FBB-4DC7-8569-E77624DD64D1}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{6039FDD4-4F1A-4559-8891-110F635F5753}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe
FirewallRules: [{15F9F389-8A75-40D6-8857-7E0F5C809ABA}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{54CF5F3A-00CA-49BE-8D9B-4DA5F39F10DF}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{40D2E168-3BAE-4AA2-81CF-D82A55B9F36A}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{B1BF2F1B-DF6F-4BB0-A0B1-DAB19763857F}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{2625B82F-F62C-4ED8-81D1-A6B3DE020AD1}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{E855FF44-F6FE-414B-A49F-95A2FD31E473}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{8EF8DC26-B0B7-4372-BA4D-E5D5235CF300}] => (Allow) D:\SteamLibrary\SteamApps\common\Audiosurf\engine\QuestViewer.exe
FirewallRules: [{0DC1F4B9-533B-466E-A10A-27205540D45B}] => (Allow) D:\SteamLibrary\SteamApps\common\Audiosurf\engine\QuestViewer.exe
FirewallRules: [{1EE76C8D-11FE-46D3-A3BB-7CBCF21B275B}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{30166ED7-E497-44E1-A972-F8E3F12DD937}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{281F9925-BEE6-4A50-93D6-4C87C2A0A834}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{3C2CC5DA-058A-47D5-B1BC-6CBB593CB818}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{41ADFF37-0AC7-40CA-89BC-6C27E5E5D16F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{25B722DB-A076-4D9A-BA82-9C06E6EF6E8E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{FCACE500-2C83-4E87-B962-C1E2D7E2AACC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{6B0AAB97-A26D-4119-BDCF-397BAB06E559}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{AC05E1FE-DF9F-41EC-BA6D-C3EFCC53381B}] => (Allow) D:\SteamLibrary\SteamApps\common\DayZ\DayZ.exe
FirewallRules: [{4A456AAD-2571-420F-B11C-2C10EE36EB7A}] => (Allow) D:\SteamLibrary\SteamApps\common\DayZ\DayZ.exe
FirewallRules: [{84DA8FF2-C2C3-44A3-80F1-13B8529DBD13}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{50DAE296-9717-4D15-99AB-E1F3ACC53D69}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{FC100A19-B707-48B4-BE6C-495C826880B7}] => (Allow) D:\Battle.net\Battle.net.exe
FirewallRules: [{6146C5BE-7933-43E5-965A-A63D298E1F06}] => (Allow) D:\Battle.net\Battle.net.exe
FirewallRules: [{609FA4C8-8255-4C1E-94C2-F2DC4103E261}] => (Allow) C:\Program Files\Steam\SteamApps\common\Free to Play\FTP.exe
FirewallRules: [{17845C48-00CA-40BF-8D42-EF7D68CC25D3}] => (Allow) C:\Program Files\Steam\SteamApps\common\Free to Play\FTP.exe
FirewallRules: [{DD7050DC-1D14-4494-AEEB-516343E13068}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{33EED445-7A34-4041-88A4-7C58E5DE269B}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{79006F9F-ADCD-4B97-BA87-DE9CD7D93E8C}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\farcry3.exe
FirewallRules: [{C21D905D-49DF-4BA8-8BDB-1737D4BAA0FF}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\farcry3.exe
FirewallRules: [{92573FDE-B00A-4BF5-9085-FFA09DB1E119}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe
FirewallRules: [{5A243312-8610-4171-88FA-C17FAACEDD91}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe
FirewallRules: [{2CDDA180-1AD4-49AD-A4EB-16C0F27CF125}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe
FirewallRules: [{7EE2999D-6458-4AD3-AE17-0E518FEC5C06}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe
FirewallRules: [{29F87D8C-E47D-483C-AD05-B1EFD7C7424A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{A37F1082-576E-44B1-9B3B-48A260460E0F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{80CC07D9-64A8-4DF2-A589-822701962296}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{F85DA0A2-E516-4A64-8F20-1F4E5F8F0673}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{72891B8E-6973-4CAC-8989-3E938A84F5A6}] => (Allow) D:\StarCraft II\StarCraft II.exe
FirewallRules: [{877E8F2A-4FCC-4F3B-8C84-31AC17955B9F}] => (Allow) D:\StarCraft II\StarCraft II.exe
FirewallRules: [TCP Query User{DA32A0DD-BF06-4ECB-88FB-AEE3AB1BD04D}D:\starcraft ii\versions\base28667\sc2.exe] => (Allow) D:\starcraft ii\versions\base28667\sc2.exe
FirewallRules: [UDP Query User{00D049C8-486B-46C5-9E1E-8389825AA167}D:\starcraft ii\versions\base28667\sc2.exe] => (Allow) D:\starcraft ii\versions\base28667\sc2.exe
FirewallRules: [{8669CF9C-D6AA-4FFC-A938-41D4A2C70FF7}] => (Allow) C:\Program Files\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{EE2E86A6-E17A-4143-88A0-F7B3A72968B4}] => (Allow) C:\Program Files\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [TCP Query User{8E8D3A44-97EC-4F20-8EC9-2AB50868D22D}D:\steamlibrary\steamapps\common\thehunter\game\thehunter.exe] => (Allow) D:\steamlibrary\steamapps\common\thehunter\game\thehunter.exe
FirewallRules: [UDP Query User{EAA7D2F3-9BD7-402D-A287-5C011007C5E4}D:\steamlibrary\steamapps\common\thehunter\game\thehunter.exe] => (Allow) D:\steamlibrary\steamapps\common\thehunter\game\thehunter.exe
FirewallRules: [{951FB2FB-BF2D-4E2B-830A-8785A44D3BE8}] => (Allow) D:\SteamLibrary\SteamApps\common\Magic 2014\DotP_D14.exe
FirewallRules: [{774D7E95-09DE-4013-A033-743F01985CA6}] => (Allow) D:\SteamLibrary\SteamApps\common\Magic 2014\DotP_D14.exe
FirewallRules: [{758887FF-E66F-41D1-ACBD-9579807F8660}] => (Allow) D:\SteamLibrary\SteamApps\common\theHunter\launcher\launcher.exe
FirewallRules: [{3D190ED8-B9BA-4553-AB7B-FB9B7A8E4BF2}] => (Allow) D:\SteamLibrary\SteamApps\common\theHunter\launcher\launcher.exe
FirewallRules: [{995ABA57-A52D-4069-8912-C42646A77089}] => (Allow) D:\SteamLibrary\SteamApps\common\the witcher 2\Launcher.exe
FirewallRules: [{4EEE7BFC-4EC0-4107-949B-4C5D7B79F957}] => (Allow) D:\SteamLibrary\SteamApps\common\the witcher 2\Launcher.exe
FirewallRules: [TCP Query User{C971B5C5-BD6E-441A-9EA1-507B6076B720}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{D6074904-862C-4554-A23F-89C9689B26BA}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{30B6605E-BBC0-499C-B5BD-83AC0E112D49}] => (Allow) D:\SteamLibrary\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{F85B2AF1-5B87-47B3-B55E-AF2B7107D286}] => (Allow) D:\SteamLibrary\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{BE2DCE7D-6214-4EDE-9741-8E7609E16F6A}] => (Allow) D:\SteamLibrary\SteamApps\common\PAYDAY 2\payday2_win32_release.exe
FirewallRules: [{8B74A210-B2D8-4C02-845E-985183A5BDD2}] => (Allow) D:\SteamLibrary\SteamApps\common\PAYDAY 2\payday2_win32_release.exe
FirewallRules: [{C77E2011-0C90-4091-A8CA-0F4BC034D559}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed 2\AssassinsCreedIIGame.exe
FirewallRules: [{3F230923-FD6D-4276-AF44-69D53AC56E9C}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed 2\AssassinsCreedIIGame.exe
FirewallRules: [{6BB7CA3A-0D66-4C8D-B140-AB57EB226B6C}] => (Allow) D:\SteamLibrary\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{07F3836B-EEA0-443E-88A8-24171ABD6B89}] => (Allow) D:\SteamLibrary\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{33E4EBF0-3E01-46C4-87B3-D5649F72E0A9}] => (Allow) D:\SteamLibrary\SteamApps\common\Super Amazing Wagon Adventure\WagonAdventure.exe
FirewallRules: [{43F9DE32-5A97-4EC4-8E30-78CF44F7A23D}] => (Allow) D:\SteamLibrary\SteamApps\common\Super Amazing Wagon Adventure\WagonAdventure.exe
FirewallRules: [{1A715213-B909-407A-9128-C3165E06CB55}] => (Allow) D:\SteamLibrary\SteamApps\common\Crusader Kings II\CK2game.exe
FirewallRules: [{A61A572F-C336-4B37-B4EE-F9C814A6B31B}] => (Allow) D:\SteamLibrary\SteamApps\common\Crusader Kings II\CK2game.exe
FirewallRules: [TCP Query User{9CDADCF9-080E-4A60-97C9-F3491FC59F90}D:\steamlibrary\steamapps\common\terraria\terrariaserver.exe] => (Block) D:\steamlibrary\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [UDP Query User{E2E72813-7AAF-44EA-A0EA-7D39808C6C6C}D:\steamlibrary\steamapps\common\terraria\terrariaserver.exe] => (Block) D:\steamlibrary\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [{6107C44F-815D-491B-ABBE-0880B8DB4674}] => (Allow) D:\SteamLibrary\SteamApps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{6FE3DE32-2EDF-49E9-9875-151F06021F96}] => (Allow) D:\SteamLibrary\SteamApps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{2BC8FAFA-A36C-42C5-8C04-E1E98634BD52}] => (Allow) D:\SteamLibrary\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{B1DDB7A1-5F00-47B0-BD20-F1B07913A585}] => (Allow) D:\SteamLibrary\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{0161E88A-B633-4727-9EBB-D8C984965C67}] => (Allow) D:\SteamLibrary\SteamApps\common\Trine 2\trine2_launcher.exe
FirewallRules: [{400E3C14-E9BD-4807-AA0C-34AD9A234AA5}] => (Allow) D:\SteamLibrary\SteamApps\common\Trine 2\trine2_launcher.exe
FirewallRules: [TCP Query User{ACAFB545-0BB9-4ACA-81DB-901322E5BF9B}D:\steamlibrary\steamapps\common\trine 2\trine2_32bit.exe] => (Allow) D:\steamlibrary\steamapps\common\trine 2\trine2_32bit.exe
FirewallRules: [UDP Query User{A2685D1A-E981-4F0A-80B8-2FCB6684758F}D:\steamlibrary\steamapps\common\trine 2\trine2_32bit.exe] => (Allow) D:\steamlibrary\steamapps\common\trine 2\trine2_32bit.exe
FirewallRules: [{09719E56-C9F6-4B38-AAA2-F05002CBE937}] => (Allow) D:\SteamLibrary\SteamApps\common\mirrors edge\Binaries\MirrorsEdge.exe
FirewallRules: [{F114DBD2-4BCA-4B57-9951-4F64669C4A7D}] => (Allow) D:\SteamLibrary\SteamApps\common\mirrors edge\Binaries\MirrorsEdge.exe
FirewallRules: [TCP Query User{B531253E-1173-4050-8D30-EBC135058B52}D:\steamlibrary\steamapps\common\far cry 3\bin\farcry3_d3d11.exe] => (Block) D:\steamlibrary\steamapps\common\far cry 3\bin\farcry3_d3d11.exe
FirewallRules: [UDP Query User{D03A3FEC-42B3-49D9-9BE5-283019D0EAD8}D:\steamlibrary\steamapps\common\far cry 3\bin\farcry3_d3d11.exe] => (Block) D:\steamlibrary\steamapps\common\far cry 3\bin\farcry3_d3d11.exe
FirewallRules: [TCP Query User{2F2A6484-443A-4248-913B-EFB82947825E}H:\warcraft iii\war3.exe] => (Allow) H:\warcraft iii\war3.exe
FirewallRules: [UDP Query User{7CB1CCB0-B700-4001-82C1-8D31F86EE48E}H:\warcraft iii\war3.exe] => (Allow) H:\warcraft iii\war3.exe
FirewallRules: [{DC48228E-8534-4FD1-AAD3-F64AD8AAADDD}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [{F7D9B3A2-C90D-4175-8357-EFE17746245A}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [{695EE005-79C1-43E6-8609-51EC571107AB}] => (Allow) D:\SteamLibrary\SteamApps\common\Roogoo\Roogoo.exe
FirewallRules: [{F3A4CF65-9E88-40B3-A53D-DEEB07AF718C}] => (Allow) D:\SteamLibrary\SteamApps\common\Roogoo\Roogoo.exe
FirewallRules: [{4CB6A84B-4BE5-43C4-81AF-A6CFA54C5344}] => (Allow) D:\SteamLibrary\SteamApps\common\FlatOut\flatout.exe
FirewallRules: [{F0BB7343-63EE-4C2A-B8E8-F9127B1962F0}] => (Allow) D:\SteamLibrary\SteamApps\common\FlatOut\flatout.exe
FirewallRules: [{9EFF69BE-3522-464F-8E98-D7F78A95D20D}] => (Allow) D:\SteamLibrary\SteamApps\common\Tropico 3\tropico3.exe
FirewallRules: [{C956A2DD-953A-4BC8-912E-87CF7306BAD6}] => (Allow) D:\SteamLibrary\SteamApps\common\Tropico 3\tropico3.exe
FirewallRules: [{0F98A126-DE04-4906-A44D-27936D5DC5BC}] => (Allow) D:\SteamLibrary\SteamApps\common\SpeedRunners\SpeedRunners.exe
FirewallRules: [{9BFFD0E1-5F62-4989-B4FE-85C98DEC1DD8}] => (Allow) D:\SteamLibrary\SteamApps\common\SpeedRunners\SpeedRunners.exe
FirewallRules: [{4D63FCA0-9D2B-41BB-9AA2-A00F9A59671C}] => (Allow) D:\SteamLibrary\SteamApps\common\Just Cause 2\JustCause2.exe
FirewallRules: [{23C372F5-DAFE-4976-BC18-89758A42AD04}] => (Allow) D:\SteamLibrary\SteamApps\common\Just Cause 2\JustCause2.exe
FirewallRules: [{6D6D4FF2-79B0-4A22-BE9F-1F578281F258}] => (Allow) D:\SteamLibrary\SteamApps\common\lethalleague\LethalLeague.exe
FirewallRules: [{B030D5BE-74E6-4A3D-A9FC-CBE466E7EB8A}] => (Allow) D:\SteamLibrary\SteamApps\common\lethalleague\LethalLeague.exe
FirewallRules: [TCP Query User{544C29AD-E24E-4123-BC07-336342A1DE7A}C:\program files\geneious\jre\bin\java.exe] => (Allow) C:\program files\geneious\jre\bin\java.exe
FirewallRules: [UDP Query User{3315995D-4CFB-4739-9AF4-3547769F7148}C:\program files\geneious\jre\bin\java.exe] => (Allow) C:\program files\geneious\jre\bin\java.exe
FirewallRules: [{E1BEBB8B-CAE6-46A1-B2DB-61F66CC5F54D}] => (Allow) D:\SteamLibrary\SteamApps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{035AE7C9-7F8F-42A1-92DC-ED8DFCEEC774}] => (Allow) D:\SteamLibrary\SteamApps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{06A413F3-D3F1-48F2-9760-0846EA05AB3D}] => (Allow) D:\SteamLibrary\SteamApps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{C2CD5402-7C0C-41F6-AE4A-05154EE8F187}] => (Allow) D:\SteamLibrary\SteamApps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [TCP Query User{F431765F-4205-4544-BC27-D6546082A2BE}D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Block) D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [UDP Query User{3AF5D673-39EB-40F7-9896-44B8A2D41E84}D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Block) D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [TCP Query User{ACB7A484-EC4B-45F1-8BF7-A8C6B8504E9C}D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Block) D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [UDP Query User{C70643F1-CC41-4DFF-8018-366F43C81DCF}D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Block) D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [{29C5102E-B2B2-4415-B047-C978F5C3B91B}] => (Allow) D:\SteamLibrary\SteamApps\common\Planetary Annihilation\PA.exe
FirewallRules: [{9DA54B2A-5177-4D9F-BA44-10905B78EA1B}] => (Allow) D:\SteamLibrary\SteamApps\common\Planetary Annihilation\PA.exe
FirewallRules: [{A5AED074-D454-4AF1-A16B-80C3E630B350}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{256E15DB-D5A1-418D-A07D-4BB47A8AE342}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{1DE54C33-6145-4A29-9425-926C623988FB}] => (Allow) D:\SteamLibrary\SteamApps\common\Port Royale 2\PR2.exe
FirewallRules: [{4D6CAFC6-854A-405D-A839-838D4117C466}] => (Allow) D:\SteamLibrary\SteamApps\common\Port Royale 2\PR2.exe
FirewallRules: [{4C58F486-2DD8-418E-A44A-BB7314344B93}] => (Allow) D:\SteamLibrary\SteamApps\common\Port Royale 2\PR2Config.exe
FirewallRules: [{AD56DF24-935F-402A-9713-60D51B06E78E}] => (Allow) D:\SteamLibrary\SteamApps\common\Port Royale 2\PR2Config.exe
FirewallRules: [TCP Query User{0E99E21F-00A0-4DCA-8712-E568FE89ACCF}C:\programdata\battle.net\agent\agent.3632\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3632\agent.exe
FirewallRules: [UDP Query User{C1841E25-07B5-44A5-96FF-367CCD8A0F01}C:\programdata\battle.net\agent\agent.3632\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3632\agent.exe
FirewallRules: [{7A47B7FE-95E9-4598-9B00-36CA7C5C02C7}] => (Allow) D:\SteamLibrary\SteamApps\common\Sega Classics\SEGAGenesisClassics.exe
FirewallRules: [{732378E6-6A02-4EC4-B807-40D3723038B7}] => (Allow) D:\SteamLibrary\SteamApps\common\Sega Classics\SEGAGenesisClassics.exe
FirewallRules: [TCP Query User{61F1E079-0AB6-4C3E-B356-9792ED776D4C}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{A92D1A85-EE4B-408B-AE89-4506C8D1D9C0}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{8D80575E-B390-488B-8DE1-C899CA4C3408}D:\heroes of the storm\versions\base34659\heroesofthestorm.exe] => (Allow) D:\heroes of the storm\versions\base34659\heroesofthestorm.exe
FirewallRules: [UDP Query User{479D4095-B4A3-4067-A1E5-63AB76B6677D}D:\heroes of the storm\versions\base34659\heroesofthestorm.exe] => (Allow) D:\heroes of the storm\versions\base34659\heroesofthestorm.exe
FirewallRules: [{25814D4B-7FB0-4977-8176-64D1B4189537}] => (Allow) D:\SteamLibrary\SteamApps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [{E60EBBEC-643F-4832-B231-2F92BDBBBD5D}] => (Allow) D:\SteamLibrary\SteamApps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [TCP Query User{36A225D5-0DCE-4CA7-9FFD-281F95BF4ED2}D:\heroes of the storm\versions\base34846\heroesofthestorm.exe] => (Allow) D:\heroes of the storm\versions\base34846\heroesofthestorm.exe
FirewallRules: [UDP Query User{AEFA2525-A07B-458A-ADEA-5769E5D1CBA1}D:\heroes of the storm\versions\base34846\heroesofthestorm.exe] => (Allow) D:\heroes of the storm\versions\base34846\heroesofthestorm.exe
FirewallRules: [{BDF8D20F-5CBC-4088-B4F0-A392A204CF1E}] => (Allow) D:\SteamLibrary\SteamApps\common\Space\spacegame\Binaries\Win32\spacegame-Win32-Shipping.exe
FirewallRules: [{5E83B031-F4B2-4185-86A5-368D1A15EBF6}] => (Allow) D:\SteamLibrary\SteamApps\common\Space\spacegame\Binaries\Win32\spacegame-Win32-Shipping.exe
FirewallRules: [TCP Query User{047B1566-774C-429E-ABAB-CC49EF8FCA1B}J:\neuer ordner\dawn of war - soulstorm( ua)\soulstorm.exe] => (Block) J:\neuer ordner\dawn of war - soulstorm( ua)\soulstorm.exe
FirewallRules: [UDP Query User{F914C1CE-3E32-47AF-9CDD-2D36EB310D3F}J:\neuer ordner\dawn of war - soulstorm( ua)\soulstorm.exe] => (Block) J:\neuer ordner\dawn of war - soulstorm( ua)\soulstorm.exe
FirewallRules: [{6D1ACC45-9F70-4DA1-B05C-1147602D5E54}] => (Allow) D:\SteamLibrary\SteamApps\common\Heroes of Might and Magic 5 Tribes of the East\bin\H5_Game.exe
FirewallRules: [{5A864CF4-BFBC-477B-97BE-9892DB08F2D5}] => (Allow) D:\SteamLibrary\SteamApps\common\Heroes of Might and Magic 5 Tribes of the East\bin\H5_Game.exe
FirewallRules: [{EA6DF6D6-CB19-4126-A88C-C474053699C6}] => (Allow) D:\SteamLibrary\SteamApps\common\Game Dev Tycoon\nw.exe
FirewallRules: [{E000B7E1-28A3-4432-B4CF-309743AE1097}] => (Allow) D:\SteamLibrary\SteamApps\common\Game Dev Tycoon\nw.exe
FirewallRules: [{72649A71-3A3D-4B71-9D32-65EFAA51C600}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{8BDA8251-F3A8-4EC0-98CB-387395CE1417}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{DC5A2A6D-544B-4136-B89E-2BF1C5BBBE95}] => (Allow) D:\SteamLibrary\SteamApps\common\Age2HD\Launcher.exe
FirewallRules: [{A404998B-5CEE-41CA-97E1-DE0FC75A48B6}] => (Allow) D:\SteamLibrary\SteamApps\common\Age2HD\Launcher.exe
FirewallRules: [{1533A207-FC63-4DC3-8C07-1A5C6C174F85}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{200D00AF-302D-4372-920E-CAE13137C349}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{38FC7F71-43E1-494D-B03F-306B0CA53B86}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{06028079-7D6E-4245-BEB9-31461143C1E5}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{616F6893-4E18-4C14-9A2B-5500E1F924A4}] => (Allow) D:\SteamLibrary\SteamApps\common\Gothic 3\Gothic3.exe
FirewallRules: [{1B731D39-69CC-47A8-9FC6-DC44DF3C54F0}] => (Allow) D:\SteamLibrary\SteamApps\common\Gothic 3\Gothic3.exe
FirewallRules: [{11D536ED-4BC8-4A7F-828B-D5101EE4B096}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Broadcom 802.11g Network Adapter
Description: Broadcom 802.11g Network Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Broadcom
Service: BCM43XX
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (07/25/2015 03:32:14 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/25/2015 08:57:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Gothic3.exe, Version: 1.60.25931.29, Zeitstempel: 0x47a1062b
Name des fehlerhaften Moduls: Engine.dll, Version: 1.60.25931.29, Zeitstempel: 0x47a10236
Ausnahmecode: 0xc0000005
Fehleroffset: 0x004abad6
ID des fehlerhaften Prozesses: 0x320
Startzeit der fehlerhaften Anwendung: 0xGothic3.exe0
Pfad der fehlerhaften Anwendung: Gothic3.exe1
Pfad des fehlerhaften Moduls: Gothic3.exe2
Berichtskennung: Gothic3.exe3

Error: (07/23/2015 02:52:32 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/23/2015 02:11:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Gothic3.exe, Version: 1.60.25931.29, Zeitstempel: 0x47a1062b
Name des fehlerhaften Moduls: Engine.dll, Version: 1.60.25931.29, Zeitstempel: 0x47a10236
Ausnahmecode: 0xc0000005
Fehleroffset: 0x004abad6
ID des fehlerhaften Prozesses: 0x4b4
Startzeit der fehlerhaften Anwendung: 0xGothic3.exe0
Pfad der fehlerhaften Anwendung: Gothic3.exe1
Pfad des fehlerhaften Moduls: Gothic3.exe2
Berichtskennung: Gothic3.exe3

Error: (07/15/2015 11:19:45 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/14/2015 01:51:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Gothic3.exe, Version: 1.60.25931.29, Zeitstempel: 0x47a1062b
Name des fehlerhaften Moduls: SharedBase.dll, Version: 1.60.25931.29, Zeitstempel: 0x47a0ff42
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000a7aea
ID des fehlerhaften Prozesses: 0xf20
Startzeit der fehlerhaften Anwendung: 0xGothic3.exe0
Pfad der fehlerhaften Anwendung: Gothic3.exe1
Pfad des fehlerhaften Moduls: Gothic3.exe2
Berichtskennung: Gothic3.exe3

Error: (07/13/2015 11:46:23 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Gothic3.exe, Version 1.60.25931.29 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1aa4

Startzeit: 01d0bd4a9cf8df5c

Endzeit: 632

Anwendungspfad: D:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exe

Berichts-ID:

Error: (07/13/2015 06:35:28 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/12/2015 07:26:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Gothic3.exe, Version: 1.60.25931.29, Zeitstempel: 0x47a1062b
Name des fehlerhaften Moduls: Engine.dll, Version: 1.60.25931.29, Zeitstempel: 0x47a10236
Ausnahmecode: 0xc0000005
Fehleroffset: 0x004abad6
ID des fehlerhaften Prozesses: 0x1a6c
Startzeit der fehlerhaften Anwendung: 0xGothic3.exe0
Pfad der fehlerhaften Anwendung: Gothic3.exe1
Pfad des fehlerhaften Moduls: Gothic3.exe2
Berichtskennung: Gothic3.exe3

Error: (07/12/2015 05:12:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Gothic3.exe, Version: 1.60.25931.29, Zeitstempel: 0x47a1062b
Name des fehlerhaften Moduls: Engine.dll, Version: 1.60.25931.29, Zeitstempel: 0x47a10236
Ausnahmecode: 0xc0000005
Fehleroffset: 0x003a0a75
ID des fehlerhaften Prozesses: 0x1814
Startzeit der fehlerhaften Anwendung: 0xGothic3.exe0
Pfad der fehlerhaften Anwendung: Gothic3.exe1
Pfad des fehlerhaften Moduls: Gothic3.exe2
Berichtskennung: Gothic3.exe3


Systemfehler:
=============
Error: (07/24/2015 02:40:30 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (07/24/2015 02:40:30 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.

Error: (07/23/2015 11:34:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (07/23/2015 11:34:58 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.

Error: (07/23/2015 11:34:26 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "SSDP-Suche" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (07/23/2015 11:34:25 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SSDP-Suche erreicht.

Error: (07/22/2015 02:12:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (07/22/2015 02:12:21 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.

Error: (07/22/2015 02:11:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "SSDP-Suche" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (07/22/2015 02:11:14 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SSDP-Suche erreicht.


Microsoft Office:
=========================
Error: (07/25/2015 03:32:14 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"d:\steamlibrary\steamapps\common\Trine 2\tools\luac_x64.exe

Error: (07/25/2015 08:57:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Gothic3.exe1.60.25931.2947a1062bEngine.dll1.60.25931.2947a10236c0000005004abad632001d0c6a060ee618aD:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exeD:\SteamLibrary\steamapps\common\Gothic 3\Engine.dll709a8701-329a-11e5-a752-20cf3093393a

Error: (07/23/2015 02:52:32 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"d:\steamlibrary\steamapps\common\Trine 2\tools\luac_x64.exe

Error: (07/23/2015 02:11:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Gothic3.exe1.60.25931.2947a1062bEngine.dll1.60.25931.2947a10236c0000005004abad64b401d0c4d11c924827D:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exeD:\SteamLibrary\steamapps\common\Gothic 3\Engine.dll4cd77810-30cf-11e5-986b-20cf3093393a

Error: (07/15/2015 11:19:45 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"d:\steamlibrary\steamapps\common\Trine 2\tools\luac_x64.exe

Error: (07/14/2015 01:51:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Gothic3.exe1.60.25931.2947a1062bSharedBase.dll1.60.25931.2947a0ff42c0000005000a7aeaf2001d0bdb982eea28fD:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exeD:\SteamLibrary\steamapps\common\Gothic 3\SharedBase.dll20d16d48-29ba-11e5-8c31-20cf3093393a

Error: (07/13/2015 11:46:23 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Gothic3.exe1.60.25931.291aa401d0bd4a9cf8df5c632D:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exe

Error: (07/13/2015 06:35:28 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"d:\steamlibrary\steamapps\common\Trine 2\tools\luac_x64.exe

Error: (07/12/2015 07:26:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Gothic3.exe1.60.25931.2947a1062bEngine.dll1.60.25931.2947a10236c0000005004abad61a6c01d0bcba227dc7faD:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exeD:\SteamLibrary\steamapps\common\Gothic 3\Engine.dll29aec87f-28bb-11e5-9261-20cf3093393a

Error: (07/12/2015 05:12:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Gothic3.exe1.60.25931.2947a1062bEngine.dll1.60.25931.2947a10236c0000005003a0a75181401d0bcb52ee69cc1D:\SteamLibrary\SteamApps\common\Gothic 3\Gothic3.exeD:\SteamLibrary\SteamApps\common\Gothic 3\Engine.dll715ea270-28a8-11e5-9261-20cf3093393a


==================== Memory info =========================== 

Processor: AMD Phenom(tm) II X4 955 Processor
Percentage of memory in use: 61%
Total physical RAM: 3326.18 MB
Available physical RAM: 1283.71 MB
Total Virtual: 6650.65 MB
Available Virtual: 4403.06 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:294.04 GB) (Free:129.31 GB) NTFS
Drive d: () (Fixed) (Total:392.66 GB) (Free:83.24 GB) NTFS
Drive e: () (Fixed) (Total:244.71 GB) (Free:189.25 GB) NTFS
Drive h: () (Fixed) (Total:232.88 GB) (Free:75.06 GB) NTFS
Drive j: (MEMUP 1TB) (Fixed) (Total:931.51 GB) (Free:619.1 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 232.9 GB) (Disk ID: 24C249AC)
Partition 1: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 101FB8C2)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=294 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=637.4 GB) - (Type=OF Extended)

========================================================
Disk: 2 (Size: 931.5 GB) (Disk ID: 000E0861)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== Ende vom log ============================
         
GMER:
Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-07-25 17:10:33
Windows 6.1.7601 Service Pack 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-3 ST31000528AS rev.CC38 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\Otti\AppData\Local\Temp\kxldapod.sys


---- System - GMER 2.1 ----

SSDT   968531C6                                                                                                            ZwCreateSection
SSDT   9685319E                                                                                                            ZwCreateSymbolicLinkObject
SSDT   968531A3                                                                                                            ZwLoadDriver
SSDT   96853199                                                                                                            ZwOpenSection
SSDT   968531D0                                                                                                            ZwRequestWaitReplyPort
SSDT   968531CB                                                                                                            ZwSetContextThread
SSDT   968531D5                                                                                                            ZwSetSecurityObject
SSDT   968531A8                                                                                                            ZwSetSystemInformation
SSDT   968531DA                                                                                                            ZwSystemDebugControl
SSDT   96853167                                                                                                            ZwTerminateProcess
SSDT   96853162                                                                                                            ZwWriteVirtualMemory

---- Kernel code sections - GMER 2.1 ----

.text  ntkrnlpa.exe!ZwRollbackEnlistment + 142D                                                                            8324CA15 1 Byte  [06]
.text  ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                                              83286212 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text  ntkrnlpa.exe!KeRemoveQueueEx + 11F7                                                                                 8328D58C 1 Byte  [C6]
.text  ntkrnlpa.exe!KeRemoveQueueEx + 11F7                                                                                 8328D58C 4 Bytes  [C6, 31, 85, 96]
.text  ntkrnlpa.exe!KeRemoveQueueEx + 11FF                                                                                 8328D594 4 Bytes  [9E, 31, 85, 96]
.text  ntkrnlpa.exe!KeRemoveQueueEx + 1313                                                                                 8328D6A8 4 Bytes  [A3, 31, 85, 96]
.text  ntkrnlpa.exe!KeRemoveQueueEx + 13AF                                                                                 8328D744 4 Bytes  [99, 31, 85, 96]
.text  ...                                                                                                                 
.text  C:\Windows\system32\DRIVERS\atksgt.sys                                                                              section is writeable [0xA11B1300, 0x3B6D8, 0xE8000020]
.text  C:\Windows\system32\DRIVERS\lirsgt.sys                                                                              section is writeable [0xA1000300, 0x1BEE, 0xE8000020]

---- Registry - GMER 2.1 ----

Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                    
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                 C:\Program Files\DAEMON Tools Lite\
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                 0x00 0x00 0x00 0x00 ...
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                 0
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                              0x47 0xAC 0x87 0xE5 ...
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001                           
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                        0x20 0x01 0x00 0x00 ...
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                     0x4B 0x37 0x83 0xD6 ...
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0                      
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                0xF9 0xFC 0x31 0xE6 ...
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                     C:\Program Files\DAEMON Tools Lite\
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                     0x00 0x00 0x00 0x00 ...
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                     0
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                  0x47 0xAC 0x87 0xE5 ...
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)       
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                            0x20 0x01 0x00 0x00 ...
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                         0x4B 0x37 0x83 0xD6 ...
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)  
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                    0xF9 0xFC 0x31 0xE6 ...

---- EOF - GMER 2.1 ----
         
Ich habe noch zusätzlich eine Logfile von einem Malewarebytes Scan von der besagten externen Festplatte, allerdings würde dann der Post zu lang, soll ich diesen zusätzlich als Anhang hinzufügen?

Ich bedanke mich bereits im vorraus schonmal für die Hilfe und die Arbeit die ihr euch macht

MfG
Ottel

Alt 25.07.2015, 16:39   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Externe Festplatte befallen, Daten versteckt - Standard

Externe Festplatte befallen, Daten versteckt



hi,

Lade Dir bitte von hier Revo Uninstaller Download Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
  • Installiere und starte das Programm. (Bebilderte Anleitung zu Revo Uninstaller)
  • Klicke auf Optionen und wähle als Sprache Deutsch.
  • Suche im Uninstallerfeld nach den Programmen:

    YTD Video Downloader 3.9.6


  • Wähle die Programme nacheinander aus und klicke jedes Mal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

 




Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________

__________________

Alt 25.07.2015, 18:02   #3
Ottel
 
Externe Festplatte befallen, Daten versteckt - Standard

Externe Festplatte befallen, Daten versteckt



Hallo Schrauber, danke für die schnelle Antwort.

Hier ist die Logfile vom Combofix, gemeckert hat das Suchprogramm nicht:
Code:
ATTFilter
ComboFix 15-07-23.01 - Otti 25.07.2015  18:44:43.1.4 - x86
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.3326.1948 [GMT 2:00]
ausgeführt von:: c:\users\Otti\Downloads\ComboFix.exe
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Otti\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\users\Otti\AppData\Roaming\SpeedRunnersLog.txt
E:\install.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2015-06-25 bis 2015-07-25  ))))))))))))))))))))))))))))))
.
.
2015-07-25 16:34 . 2015-07-25 16:34	--------	d-----w-	c:\program files\VS Revo Group
2015-07-25 14:55 . 2015-07-25 14:57	--------	d-----w-	C:\FRST
2015-07-09 00:52 . 2015-07-09 00:52	--------	d-----w-	c:\program files\PDF24
2015-07-03 22:20 . 2015-07-03 22:20	--------	d-----w-	c:\users\Otti\AppData\Local\CEF
2015-07-01 21:42 . 2015-07-14 20:23	778416	----a-w-	c:\windows\system32\FlashPlayerApp.exe
2015-07-01 21:42 . 2015-07-14 20:23	142512	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-25 09:49 . 2014-10-29 20:17	98520	----a-w-	c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-06-19 01:02 . 2015-05-04 19:02	136728	----a-w-	c:\windows\system32\drivers\avipbb.sys
2015-06-19 01:02 . 2015-05-04 19:02	108448	----a-w-	c:\windows\system32\drivers\avgntflt.sys
2015-06-18 06:41 . 2014-10-29 20:17	51928	----a-w-	c:\windows\system32\drivers\mwac.sys
2015-06-18 06:41 . 2014-10-29 20:17	94936	----a-w-	c:\windows\system32\drivers\mbamchameleon.sys
2015-06-18 06:41 . 2012-03-22 14:46	23256	----a-w-	c:\windows\system32\drivers\mbam.sys
2015-06-07 21:00 . 2014-06-03 17:00	139888	----a-w-	c:\windows\system32\drivers\PnkBstrK.sys
2015-06-07 21:00 . 2014-06-03 17:00	348672	----a-w-	c:\windows\system32\PnkBstrB.exe
2015-06-07 21:00 . 2013-12-12 00:47	348672	----a-w-	c:\windows\system32\PnkBstrB.xtr
2015-06-07 20:59 . 2013-12-12 00:37	290184	----a-w-	c:\windows\system32\PnkBstrB.ex0
2015-06-03 21:04 . 2014-07-15 13:28	1316000	----a-w-	c:\windows\system32\nvspbridge.dll
2015-06-03 21:04 . 2013-10-29 09:57	1320304	----a-w-	c:\windows\system32\nvspcap.dll
2015-05-28 13:36 . 2014-06-03 17:00	138056	----a-w-	c:\users\Otti\AppData\Roaming\PnkBstrK.sys
2015-05-28 07:00 . 2015-06-19 10:38	939264	----a-w-	c:\windows\system32\nvumdshim.dll
2015-05-28 07:00 . 2015-06-19 10:38	912712	----a-w-	c:\windows\system32\nvhdagenco3220103.dll
2015-05-28 07:00 . 2015-06-19 10:38	28480	----a-w-	c:\windows\system32\nvhdap32.dll
2015-05-28 07:00 . 2015-06-19 10:38	22946960	----a-w-	c:\windows\system32\nvoglv32.dll
2015-05-28 07:00 . 2015-06-19 10:38	162624	----a-w-	c:\windows\system32\drivers\nvhda32v.sys
2015-05-28 07:00 . 2015-06-19 10:38	13304280	----a-w-	c:\windows\system32\nvopencl.dll
2015-05-28 07:00 . 2015-06-19 10:38	128512	----a-w-	c:\windows\system32\nvoglshim32.dll
2015-05-28 07:00 . 2015-06-19 10:38	982856	----a-w-	c:\windows\system32\NvIFR.dll
2015-05-28 07:00 . 2015-06-19 10:38	9115464	----a-w-	c:\windows\system32\drivers\nvlddmkm.sys
2015-05-28 07:00 . 2015-06-19 10:38	154256	----a-w-	c:\windows\system32\nvinit.dll
2015-05-28 07:00 . 2015-06-19 10:38	974480	----a-w-	c:\windows\system32\NvFBC.dll
2015-05-28 07:00 . 2015-06-19 10:38	912712	----a-w-	c:\windows\system32\nvdispgenco3235306.dll
2015-05-28 07:00 . 2015-06-19 10:38	1049232	----a-w-	c:\windows\system32\nvdispco3235306.dll
2015-05-28 07:00 . 2015-06-19 10:38	2599056	----a-w-	c:\windows\system32\nvcuvid.dll
2015-05-28 07:00 . 2015-06-19 10:38	11830320	----a-w-	c:\windows\system32\nvcuda.dll
2015-05-28 07:00 . 2015-06-19 10:38	37741712	----a-w-	c:\windows\system32\nvcompiler.dll
2015-05-28 07:00 . 2010-06-14 22:07	2986392	----a-w-	c:\windows\system32\nvapi.dll
2015-05-28 07:00 . 2010-06-14 22:07	14987528	----a-w-	c:\windows\system32\nvwgf2um.dll
2015-05-28 07:00 . 2010-06-14 22:07	12852152	----a-w-	c:\windows\system32\nvd3dum.dll
2015-05-28 03:52 . 2015-06-19 10:41	571024	----a-w-	c:\windows\system32\nvStreaming.exe
2015-05-28 03:50 . 2010-06-13 22:09	672064	----a-w-	c:\windows\system32\nvvsvc.exe
2015-05-28 03:50 . 2010-06-13 22:09	2554184	----a-w-	c:\windows\system32\nvsvcr.dll
2015-05-28 03:50 . 2010-06-13 22:09	61584	----a-w-	c:\windows\system32\nvshext.dll
2015-05-28 03:50 . 2010-06-13 22:09	375112	----a-w-	c:\windows\system32\nvmctray.dll
2015-05-28 03:50 . 2010-06-13 22:09	4385424	----a-w-	c:\windows\system32\nvcpl.dll
2015-05-28 03:50 . 2010-06-13 22:09	3020104	----a-w-	c:\windows\system32\nvsvc.dll
2015-05-27 00:16 . 2014-08-07 09:34	96352	----a-w-	c:\windows\system32\WindowsAccessBridge.dll
2015-05-20 15:19 . 2015-05-04 19:02	37896	----a-w-	c:\windows\system32\drivers\avkmgr.sys
2015-05-19 03:29 . 2015-06-19 10:29	41648	----a-w-	c:\windows\system32\drivers\nvvad32v.sys
2015-05-19 03:14 . 2013-09-01 17:37	57520	----a-w-	c:\windows\system32\nvaudcap32v.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\steam.exe" [2015-07-23 2895552]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2010-03-15 1780224]
"TurboV EVO"="c:\program files\ASUS\TurboV EVO\TurboV_EVO.exe" [2010-04-07 9919104]
"Six Engine"="c:\program files\ASUS\EPU\EPU.exe" [2010-03-16 5309056]
"NUSB3MON"="c:\program files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-01-22 106496]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
"tsnp2uvc"="c:\program files\Common Files\SNP2UVC\tsnp2uvc.exe" [2011-07-20 321024]
"ShadowPlay"="c:\windows\system32\nvspcap.dll" [2015-06-03 1320304]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-06-03 2754704]
"avgnt"="c:\program files\Avira\Antivirus\avgnt.exe" [2015-06-19 730416]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2015-04-30 334896]
"Avira Systray"="c:\program files\Avira\Launcher\Avira.Systray.exe" [2015-06-02 134368]
"PDFPrint"="c:\program files\PDF24\pdf24.exe" [2015-07-07 217632]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-11-21 16:57	959904	----a-w-	c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16	357696	----a-w-	c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EKIJ5000StatusMonitor]
2010-09-02 13:23	1638400	----a-w-	c:\windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-08-27 07:20	22041192	----a-r-	c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2uvc]
2009-08-12 14:06	662016	----a-w-	c:\windows\vsnp2uvc.exe
.
R2 MBAMService;MBAMService;c:\program files\ Malwarebytes Anti-Malware \mbamservice.exe [2015-06-18 1133880]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2015-06-18 51928]
R3 Origin Client Service;Origin Client Service;c:\program files\Origin\OriginClientService.exe [2015-06-06 1997168]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R4 AODService;AODService;c:\program files\AMD\OverDrive\AODAssist.exe [2009-10-22 136544]
R4 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-09-21 691696]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2015-05-20 37896]
S2 AntiVirMailService;Avira Email-Schutz;c:\program files\Avira\Antivirus\avmailc7.exe [2015-06-19 827184]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\Antivirus\sched.exe [2015-06-19 450808]
S2 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\Antivirus\avwebg7.exe [2015-06-19 1188360]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-12-28 96896]
S2 Avira.ServiceHost;Avira Service Host;c:\program files\Avira\Launcher\Avira.ServiceHost.exe [2015-06-02 217280]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys [2015-03-24 37896]
S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [2009-10-16 319488]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-06-03 919184]
S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-06-03 1893008]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2015-06-03 20694160]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-05-28 410768]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2015-06-18 23256]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-01-22 59904]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-01-22 139648]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-06-03 18576]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2015-05-19 41648]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-10-19 31288]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2010-03-02 1127936]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-07-22 22:22	995144	----a-w-	c:\program files\Google\Chrome\Application\44.0.2403.89\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-12-12 20:18]
.
2015-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-12-12 20:18]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://de.ask.com/?l=dis&o=APN10375&gct=hp&apn_ptnrs=^AHP&apn_dtid=^YYYYYY^YY^DE&p2=^AHP^YYYYYY^YY^DE&tpid=SGT-SAT&apn_dbr=ff_16.0&apn_uid=4B8FE4C5-97CF-4033-A601-BCBD1EFFAD61&itbv=11.3.0.661&doi=2012-12-03
IE: Free YouTube Download - c:\users\Otti\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Otti\AppData\Roaming\Mozilla\Firefox\Profiles\vd5nyfxp.default-1371114904938\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
WebBrowser-{5347542D-5341-5400-76A7-7A786E7484D7} - (no file)
WebBrowser-{41564952-412D-5637-00A7-7A786E7484D7} - (no file)
HKLM-Run-Nvtmru - c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe
MSConfigStartUp-ApnTBMon - c:\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
AddRemove-Battlelog Web Plugins - c:\program files\Battlelog Web Plugins\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3534099020-634075679-966876233-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:51,27,41,c7,9f,c8,28,04,a5,24,8e,27,d4,65,80,f6,79,17,cd,5a,cd,6a,6f,
   97,ac,47,56,8a,c0,23,f1,6f,92,b7,49,1d,38,6f,01,87,8e,ad,0b,a8,86,d8,c3,9c,\
"??"=hex:b5,33,74,b2,61,ce,10,dd,2c,cb,33,5c,33,6e,6a,9d
.
[HKEY_USERS\S-1-5-21-3534099020-634075679-966876233-1000\Software\SecuROM\License information*]
"datasecu"=hex:c8,a2,8e,b9,e0,64,7d,c5,0f,d4,c0,bb,0a,99,6f,64,8d,79,14,eb,5a,
   81,ed,16,6f,ee,65,a5,f0,b3,9d,6c,d9,cb,69,49,9f,69,09,c2,f1,17,1b,1b,05,ee,\
"rkeysecu"=hex:ea,a2,90,7c,c4,34,ba,95,ea,ab,dc,db,59,de,fe,81
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Avira\Antivirus\avguard.exe
c:\windows\system32\taskhost.exe
c:\windows\DAODx.exe
c:\program files\ASUS\TurboV EVO\TurboVHELP.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
c:\windows\system32\conhost.exe
c:\windows\system32\conhost.exe
c:\program files\Avira\Antivirus\avshadow.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\users\Otti\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
c:\windows\system32\sppsvc.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Steam\bin\steamwebhelper.exe
c:\program files\Common Files\Steam\SteamService.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-07-25  18:56:28 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2015-07-25 16:56
.
Vor Suchlauf: 8 Verzeichnis(se), 138.251.120.640 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 138.209.284.096 Bytes frei
.
- - End Of File - - 2858E28DC328DA3CF4C3D3A619F1790C
A36C5E4F47E84449FF07ED3517B43A31
         
Ich weiß jetzt nicht, ob ich was falsch verstanden habe, aber sollte ich das mit angeschlossener externen Festplatte drüberlaufen lassen? Ich hatte die Externe nämlich für die Zeit in der ich hier privat am Rechner bin abgestöpselt.

PS: Als ich die Festplatte sicher entfernen wollte, wurde mit gesagt dass noch etwas auf die Festplatte zugreift und das entfernen deshalb nicht möglich ist. Mysteriös, da sämtliche Anwendungen geschlossen waren.

MfG,
Ottel
__________________

Alt 26.07.2015, 13:11   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Externe Festplatte befallen, Daten versteckt - Standard

Externe Festplatte befallen, Daten versteckt



PLatte dran und nicht mehr ab machen.


Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Externe Festplatte befallen, Daten versteckt
antivirus, avira, computer, desktop, downloader, error, festplatte, firefox, flash player, helper, home, mozilla, mp3, registry, required, rundll, scan, security, software, stick, svchost.exe, system, usb, virus, windows, windows xp




Ähnliche Themen: Externe Festplatte befallen, Daten versteckt


  1. Externe Festplatte Daten verschwunden Antivir findet keinen Virus
    Plagegeister aller Art und deren Bekämpfung - 23.12.2013 (10)
  2. Externe Festplatte formatiert, wichtige Daten verloren
    Alles rund um Mac OSX & Linux - 06.12.2013 (16)
  3. GVU Trojaner - Persönliche Daten sichern, Externe Festplatte überprüfen & System neu aufsetzen
    Plagegeister aller Art und deren Bekämpfung - 16.09.2013 (2)
  4. Laptop und externe Festplatte befallen
    Plagegeister aller Art und deren Bekämpfung - 11.09.2013 (13)
  5. externe festplatte trojaner daten nicht mehr sichtbar
    Plagegeister aller Art und deren Bekämpfung - 28.03.2013 (1)
  6. externe Festplatte und USB Stick vom Trojaner befallen ?
    Plagegeister aller Art und deren Bekämpfung - 12.03.2013 (9)
  7. Externe Festplatte zeigt nur Verknüpfungen an - Daten mit Linux sichern
    Alles rund um Windows - 13.11.2012 (3)
  8. Webspace befallen - Weiterleitung auf externe Websites
    Plagegeister aller Art und deren Bekämpfung - 10.08.2012 (2)
  9. Externe Festplatte stark befallen!
    Log-Analyse und Auswertung - 03.08.2012 (3)
  10. S.M.A.R.T data recovery - Desktop schwarz, Daten versteckt, Startmenü leer
    Log-Analyse und Auswertung - 14.05.2012 (3)
  11. Probleme mit zugriff auf daten auf eine externe festplatte
    Netzwerk und Hardware - 28.11.2011 (1)
  12. Daten auf der externe Festplatte sind nur noch 2 k groß
    Log-Analyse und Auswertung - 14.11.2011 (2)
  13. Externe Festplatte zeigt keine Daten mehr an
    Plagegeister aller Art und deren Bekämpfung - 26.07.2011 (11)
  14. Alle Daten auf externe Festplatte nur Verknüpfungen...HILFE
    Plagegeister aller Art und deren Bekämpfung - 25.06.2011 (1)
  15. Windows Vista Recovery(Festplatte Defekt)Trojaner dazu schwarzer Bildschirm und alle Daten versteckt
    Log-Analyse und Auswertung - 31.05.2011 (7)
  16. Externe Festplatte wieder herstellen der daten.
    Alles rund um Windows - 17.03.2009 (1)
  17. Daten weg (externe Festplatte von freecom) 400 GB
    Alles rund um Windows - 30.08.2007 (11)

Zum Thema Externe Festplatte befallen, Daten versteckt - Hallo Leute, Ich bin neu hier im Board und fand die Beiträge die ich mir ab und zu durchgelesen habe sehr hilfreich, weswegen ich mich nun auch mit einem Probem - Externe Festplatte befallen, Daten versteckt...
Archiv
Du betrachtest: Externe Festplatte befallen, Daten versteckt auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.