| Belzebub | 08.04.2013 11:06 | Tapiui.DLL - Performance-Probleme & Absturz? Hallo!
Hab schon seit Längerem ein Problem, und zwar hängt sich mein Firefox regelmäßig auf und er arbeitet generell etwas langsam. Was mir dabei aufgefallen ist, ist das tapiui.dll sich ebenfalls aufhängt und instabil ist. Ein Virenscan von Avira hat nichts gezeigt, ebensowenig ein Hijack This-Scan. Eine Neuinstallation von Firefox war auch erfolglos. Im Safe Mode funktioniert er jedoch stabiler. Ich bin dennoch davon überzeugt, dass irgendwas in der DLL-Datei meinen Browser lahmt, es also kein Firefox-Problem ist.
Würde mich über euren Rat sehr freuen. Immer mit dem Gedanken surfen zu müssen dass der Browser jede Sekunde abstürzt ist mehr als nervig, und ein Browserwechsel kommt einfach nicht in Frage.
Danke schon mal im Vorraus!
MfG Code:
OTL logfile created on: 08.04.2013 11:25:19 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\#\Desktop\
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
7,98 Gb Total Physical Memory | 6,09 Gb Available Physical Memory | 76,31% Memory free
15,96 Gb Paging File | 13,89 Gb Available in Paging File | 87,03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97,56 Gb Total Space | 10,19 Gb Free Space | 10,45% Space Free | Partition Type: NTFS
Drive D: | 368,10 Gb Total Space | 102,66 Gb Free Space | 27,89% Space Free | Partition Type: NTFS
Drive E: | 455,86 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive G: | 698,63 Gb Total Space | 16,54 Gb Free Space | 2,37% Space Free | Partition Type: NTFS
Computer Name: #-PC | User Name: # | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.04.04 11:45:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\#\Desktop\I MOG DES NIT\OTL.exe
PRC - [2013.04.04 11:45:33 | 000,050,477 | ---- | M] () -- C:\Users\#\Desktop\I MOG DES NIT\Defogger.exe
PRC - [2013.04.03 20:30:59 | 001,104,280 | ---- | M] (Spotify Ltd) -- C:\Users\#\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2013.03.29 14:41:17 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2013.03.29 14:41:03 | 000,345,312 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2013.03.29 14:41:03 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2013.03.12 09:05:50 | 029,106,336 | ---- | M] (Dropbox, Inc.) -- C:\Users\#\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013.03.07 16:29:07 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.12.18 13:14:27 | 000,642,816 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2012.01.31 11:46:56 | 000,019,232 | ---- | M] (Autodesk, Inc.) -- C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
PRC - [2012.01.18 17:11:40 | 000,433,264 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe
PRC - [2012.01.18 17:11:32 | 000,354,416 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe
PRC - [2012.01.18 14:27:20 | 000,079,872 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
PRC - [2011.12.18 17:01:18 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011.09.15 00:19:54 | 000,086,016 | ---- | M] () -- C:\Programme\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe
PRC - [2009.12.15 22:49:00 | 000,185,632 | ---- | M] (Ralink Technology, Corp.) -- C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
PRC - [2009.12.10 11:16:08 | 001,643,808 | ---- | M] (Ralink Technology, Corp.) -- C:\Program Files (x86)\Ralink\Common\RaUI.exe
========== Modules (No Company Name) ==========
MOD - [2013.04.04 11:45:33 | 000,050,477 | ---- | M] () -- C:\Users\#\Desktop\I MOG DES NIT\Defogger.exe
MOD - [2013.03.07 16:29:21 | 003,069,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011.11.02 00:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.11.02 00:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009.12.10 11:16:08 | 000,918,816 | ---- | M] () -- C:\Program Files (x86)\Ralink\Common\RaWLAPI.dll
MOD - [2009.02.27 17:39:29 | 000,019,968 | ---- | M] () -- C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.deu
MOD - [2009.02.27 17:32:27 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\AcroTray.FRA
========== Services (SafeList) ==========
SRV:64bit: - [2013.03.18 20:18:09 | 000,114,688 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\tapiui64.exe -- (TCPSVCSd)
SRV:64bit: - [2012.12.19 21:56:00 | 000,240,640 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.04.07 15:04:24 | 000,127,800 | ---- | M] (HP) [Auto | Running] -- C:\Windows\SysNative\HPSIsvc.exe -- (HPSIService)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2008.07.29 14:20:28 | 004,737,024 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe -- (msvsmon90)
SRV - [2013.03.29 14:41:17 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013.03.29 14:41:03 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013.03.12 22:28:55 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.03.07 16:29:15 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.11.09 12:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.05.29 13:21:53 | 001,432,400 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV - [2012.01.31 11:46:56 | 000,019,232 | ---- | M] (Autodesk, Inc.) [Auto | Running] -- C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe -- (Autodesk Content Service)
SRV - [2012.01.23 09:38:24 | 007,515,000 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Programme\Tablet\Wacom\Wacom_Tablet.exe -- (TabletServiceWacom)
SRV - [2012.01.23 09:38:24 | 000,552,312 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Programme\Tablet\Wacom\Wacom_TouchService.exe -- (TouchServiceWacom)
SRV - [2012.01.18 17:11:40 | 000,433,264 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2012.01.18 17:11:32 | 000,354,416 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2012.01.18 14:27:20 | 000,079,872 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe -- (VMAuthdService)
SRV - [2011.12.18 17:01:18 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011.12.12 20:31:39 | 000,419,624 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.11.18 00:26:46 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011.09.15 00:19:54 | 000,086,016 | ---- | M] () [Auto | Running] -- C:\Programme\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe -- (mi-raysat_3dsmax2013_64)
SRV - [2011.08.29 23:11:04 | 000,846,448 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe -- (VMUSBArbService)
SRV - [2011.03.01 19:29:58 | 000,130,976 | ---- | M] (Futuremark Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.12.15 22:49:12 | 000,212,256 | ---- | M] (Ralink Technology, Corp.) [Auto | Running] -- C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe -- (RalinkRegistryWriter64)
SRV - [2009.12.15 22:49:00 | 000,185,632 | ---- | M] (Ralink Technology, Corp.) [Auto | Running] -- C:\Program Files (x86)\Ralink\Common\RaRegistry.exe -- (RalinkRegistryWriter)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013.03.29 14:41:21 | 000,130,016 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2013.03.29 14:41:21 | 000,100,712 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2013.03.29 14:41:21 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2012.12.19 22:48:48 | 011,278,336 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.12.19 21:32:54 | 000,552,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.11.06 13:11:52 | 000,096,256 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.10.11 18:33:09 | 000,086,584 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2012.09.28 11:32:56 | 000,053,760 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012.09.25 19:44:08 | 000,088,480 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2012.09.25 19:44:08 | 000,046,400 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2012.08.21 14:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.02.16 13:42:00 | 000,676,968 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2012.01.18 17:11:58 | 000,031,344 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\VMparport.sys -- (VMparport)
DRV:64bit: - [2012.01.18 17:11:56 | 000,063,088 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:64bit: - [2012.01.18 17:11:08 | 000,032,880 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMkbd.sys -- (vmkbd)
DRV:64bit: - [2012.01.18 17:10:38 | 000,030,320 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2012.01.18 14:06:00 | 000,045,680 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2012.01.18 14:06:00 | 000,020,080 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2011.11.21 00:19:34 | 000,279,616 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011.08.29 23:11:04 | 000,039,024 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2011.08.29 23:01:10 | 000,037,680 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmusb.sys -- (vmusb)
DRV:64bit: - [2011.08.08 15:59:12 | 000,116,336 | ---- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:64bit: - [2011.05.13 03:21:04 | 000,177,640 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm)
DRV:64bit: - [2011.05.13 03:21:02 | 000,157,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus)
DRV:64bit: - [2011.05.13 03:21:02 | 000,036,328 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadadb.sys -- (androidusb)
DRV:64bit: - [2011.05.13 03:21:02 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV:64bit: - [2011.03.17 13:10:48 | 000,013,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:64bit: - [2011.03.17 13:10:36 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV:64bit: - [2011.03.17 13:10:34 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 13:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010.10.20 00:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010.06.14 09:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2010.04.27 04:25:16 | 000,161,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV:64bit: - [2010.04.27 04:25:16 | 000,127,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bbus.sys -- (ss_bbus)
DRV:64bit: - [2010.04.27 04:25:16 | 000,018,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdfl.sys -- (ss_bmdfl)
DRV:64bit: - [2010.03.06 01:41:05 | 000,020,480 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mvusbews.sys -- (mvusbews)
DRV:64bit: - [2009.12.10 11:15:56 | 000,787,968 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 02:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2012.10.11 18:33:09 | 000,086,584 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)
DRV - [2010.06.14 09:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DE BA 61 04 10 2B CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "YouTube-Videosuche"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7Ba95d8332-e4b4-6e7f-98ac-20b733364387%7D:0.6.3
FF - prefs.js..extensions.enabledAddons: %7B46868735-c3fa-47ce-8ce7-cce51a66aceb%7D:1.2
FF - prefs.js..extensions.enabledAddons: kitsuneymg%40gmail.com:1.0.6
FF - prefs.js..extensions.enabledAddons: %7Bb749fc7c-e949-447f-926c-3f4eed6accfe%7D:0.7.1.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..network.proxy.autoconfig_url: "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1))%20%7B%20return%20'PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us04.personalitycores.com%3A8000%3B%20PROXY%20ab-us06.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF - prefs.js..network.proxy.type: 2
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.0.0.4: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\#\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.19 13:01:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.03.08 12:51:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013.04.04 11:32:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2013.03.19 13:02:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\#\AppData\Roaming\mozilla\Extensions
[2013.03.25 22:04:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\#\AppData\Roaming\mozilla\Firefox\Profiles\4md1e8gj.default\extensions
[2013.03.19 13:03:32 | 002,163,784 | ---- | M] () (No name found) -- C:\Users\#\AppData\Roaming\mozilla\firefox\profiles\4md1e8gj.default\extensions\firebug@software.joehewitt.com.xpi
[2013.03.25 22:04:40 | 000,370,423 | ---- | M] () (No name found) -- C:\Users\#\AppData\Roaming\mozilla\firefox\profiles\4md1e8gj.default\extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi
[2013.03.19 13:04:04 | 000,006,516 | ---- | M] () (No name found) -- C:\Users\#\AppData\Roaming\mozilla\firefox\profiles\4md1e8gj.default\extensions\kitsuneymg@gmail.com.xpi
[2013.03.19 13:04:04 | 000,001,736 | ---- | M] () (No name found) -- C:\Users\#\AppData\Roaming\mozilla\firefox\profiles\4md1e8gj.default\extensions\{46868735-c3fa-47ce-8ce7-cce51a66aceb}.xpi
[2013.03.19 13:04:04 | 000,056,640 | ---- | M] () (No name found) -- C:\Users\#\AppData\Roaming\mozilla\firefox\profiles\4md1e8gj.default\extensions\{a95d8332-e4b4-6e7f-98ac-20b733364387}.xpi
[2013.03.25 22:02:51 | 000,061,705 | ---- | M] () (No name found) -- C:\Users\#\AppData\Roaming\mozilla\firefox\profiles\4md1e8gj.default\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}.xpi
[2013.03.19 13:03:38 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\#\AppData\Roaming\mozilla\firefox\profiles\4md1e8gj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.03.21 13:18:10 | 000,009,117 | ---- | M] () -- C:\Users\#\AppData\Roaming\mozilla\firefox\profiles\4md1e8gj.default\searchplugins\flickr.xml
[2013.03.20 21:56:50 | 000,001,959 | ---- | M] () -- C:\Users\#\AppData\Roaming\mozilla\firefox\profiles\4md1e8gj.default\searchplugins\lastfm.xml
[2013.03.24 14:12:44 | 000,001,330 | ---- | M] () -- C:\Users\#\AppData\Roaming\mozilla\firefox\profiles\4md1e8gj.default\searchplugins\wikipedia-en.xml
[2013.03.20 01:21:24 | 000,002,057 | ---- | M] () -- C:\Users\#\AppData\Roaming\mozilla\firefox\profiles\4md1e8gj.default\searchplugins\youtube-videosuche.xml
[2013.03.19 13:01:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013.03.08 12:51:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013.03.07 16:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013.03.07 17:45:15 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.03.07 17:45:15 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013.03.07 17:45:15 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2013.03.07 17:45:15 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.03.07 17:45:15 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.03.07 17:45:15 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2012.01.31 21:59:38 | 000,000,856 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Autodesk Sync] C:\Programme\Autodesk\Autodesk Sync\AdSync.exe (Autodesk, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" File not found
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\#\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - Startup: C:\Users\#\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\#\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O8:64bit: - Extra context menu item: An vorhandene PDF-Datei anfügen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Linkziel in Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 10.17.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{80653630-F768-46F0-B696-39882B31D52F}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012.05.29 13:08:50 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2000.09.24 21:19:57 | 000,000,063 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{3d398fe6-c45b-11e1-bc6e-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{3d398fe6-c45b-11e1-bc6e-005056c00008}\Shell\AutoRun\command - "" = H:\SISetup.exe
O33 - MountPoints2\{40987338-13c4-11e1-b0b9-14dae96d8089}\Shell - "" = AutoRun
O33 - MountPoints2\{40987338-13c4-11e1-b0b9-14dae96d8089}\Shell\AutoRun\command - "" = F:\RunGame.exe
O33 - MountPoints2\{60f75e49-1147-11e1-9a2b-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{60f75e49-1147-11e1-9a2b-806e6f6e6963}\Shell\AutoRun\command - "" = E:\SETUP.EXE -- [2000.09.24 21:19:57 | 000,092,672 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.04.04 14:46:02 | 000,000,000 | ---D | C] -- D:\Daten\SimCity
[2013.04.04 14:44:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimCity™
[2013.04.04 14:44:17 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Common Files\EAInstaller
[2013.04.04 14:32:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Origin Games
[2013.04.04 14:32:34 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Roaming\Origin
[2013.04.04 14:32:33 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Local\Origin
[2013.04.04 14:31:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
[2013.04.04 14:31:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2013.04.04 14:31:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Electronic Arts
[2013.04.04 14:31:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Origin
[2013.04.04 11:32:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2013.04.03 22:13:21 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dll Suite 2013
[2013.04.03 22:13:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DLLSuite
[2013.03.29 14:41:32 | 000,130,016 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013.03.29 14:41:32 | 000,100,712 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013.03.29 14:41:32 | 000,028,600 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2013.03.23 20:58:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013.03.23 15:27:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daedalic Entertainment
[2013.03.20 17:47:03 | 000,000,000 | ---D | C] -- C:\Users\#\Desktop\backups
[2013.03.19 13:01:55 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Roaming\Mozilla
[2013.03.19 12:02:14 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Roaming\Sync App Settings
[2013.03.19 12:02:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Sync App Settings
[2013.03.19 12:02:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allway Sync
[2013.03.19 12:01:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Allway Sync
[2013.03.19 11:57:00 | 000,000,000 | ---D | C] -- C:\ProgramData\RegInOut
[2013.03.19 11:53:12 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Local\Programs
[2013.03.19 11:52:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup
[2013.03.19 11:52:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MozBackup
[2013.03.19 11:17:03 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\IO
[2013.03.18 20:19:06 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Roaming\Jumping Bytes
[2013.03.18 20:18:14 | 000,493,056 | ---- | C] ( datenhaus GmbH) -- C:\Windows\SysWow64\dhRichClient3.dll
[2013.03.18 20:18:09 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Roaming\DesktopIconForAmazon
[2013.03.18 20:18:08 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Roaming\Opera
[2013.03.18 20:18:06 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Roaming\OCS
[2013.03.17 03:37:35 | 000,000,000 | ---D | C] -- D:\Daten\Anno 1404
[2013.03.16 22:56:44 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Roaming\Ubisoft
[2013.03.16 22:21:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Tages
[2013.03.16 21:54:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dungeon Keeper Complete Collection
[2013.03.16 17:43:15 | 000,000,000 | ---D | C] -- C:\Users\#\.tuxguitar-1.2
[2013.03.16 17:42:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuxGuitar
[2013.03.16 17:42:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TuxGuitar
[2013.03.14 23:50:58 | 000,000,000 | ---D | C] -- D:\Daten\Inventor Server SDK ACAD 2013
[2013.03.13 17:40:08 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013.03.12 23:28:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google SketchUp 8
[2013.03.12 23:08:42 | 000,000,000 | ---D | C] -- C:\ProgramData\ASGVIS
[2013.03.11 23:23:52 | 000,000,000 | ---D | C] -- C:\Lyrics
[2013.03.11 23:23:42 | 000,000,000 | ---D | C] -- C:\Users\#\AppData\Roaming\MiniLyrics
[2013.03.11 23:23:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniLyrics
[2013.03.11 23:23:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MiniLyrics
[2013.03.09 15:47:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Traffic Simulator Configuration Tool
[2013.03.09 15:47:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Network Addon Mod
[2013.03.09 15:43:39 | 000,000,000 | ---D | C] -- C:\Users\#\Desktop\NetworkAddonMod_Setup
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.04.08 11:26:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.04.08 11:24:55 | 000,000,168 | ---- | M] () -- C:\Users\#\defogger_reenable
[2013.04.08 11:08:16 | 000,017,360 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.04.08 11:08:16 | 000,017,360 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.04.08 11:00:20 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.04.08 11:00:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.04.08 11:00:05 | 2133,561,343 | -HS- | M] () -- C:\hiberfil.sys
[2013.04.07 23:55:00 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.04.06 14:59:35 | 003,072,936 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.04.04 14:32:44 | 001,620,762 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.04.04 14:32:44 | 000,699,342 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.04.04 14:32:44 | 000,654,660 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.04.04 14:32:44 | 000,149,164 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.04.04 14:32:44 | 000,122,118 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.04.04 00:22:45 | 000,000,214 | ---- | M] () -- C:\Users\#\Desktop\StoneSour.com.URL
[2013.04.02 17:17:13 | 000,001,179 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.03.29 14:41:21 | 000,130,016 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013.03.29 14:41:21 | 000,100,712 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013.03.29 14:41:21 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2013.03.29 14:35:47 | 000,001,017 | ---- | M] () -- C:\Users\#\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.03.19 11:52:49 | 037,593,770 | ---- | M] () -- D:\Daten\Firefox 19.0.2 (de) - 2013-03-19.pcv
[2013.03.18 20:18:09 | 000,114,688 | ---- | M] () -- C:\Windows\SysNative\tapiui64.exe
[2013.03.12 22:58:07 | 000,003,120 | ---- | M] () -- C:\Windows\SysWow64\ALLFSAF8a.ocx
[2013.03.11 18:26:55 | 000,000,224 | ---- | M] () -- C:\Users\#\Desktop\Franz Liszt - Ungarische Rhapsodie no.2 - YouTube.URL
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.04.08 11:24:55 | 000,000,168 | ---- | C] () -- C:\Users\#\defogger_reenable
[2013.04.04 00:22:45 | 000,000,214 | ---- | C] () -- C:\Users\#\Desktop\StoneSour.com.URL
[2013.03.19 13:01:52 | 000,001,179 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.03.19 13:01:52 | 000,001,169 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013.03.19 11:52:24 | 037,593,770 | ---- | C] () -- D:\Daten\Firefox 19.0.2 (de) - 2013-03-19.pcv
[2013.03.18 20:23:21 | 001,009,654 | ---- | C] () -- D:\Daten\Fox_Movie_World_65.SV6
[2013.03.18 20:23:21 | 000,535,520 | ---- | C] () -- D:\Daten\Majesty Legoland 17.SV6
[2013.03.18 20:23:18 | 105,040,768 | ---- | C] () -- D:\Daten\Fonts.zip
[2013.03.18 20:23:15 | 093,151,006 | ---- | C] () -- D:\Daten\Conan_-_Monnos.7z
[2013.03.18 20:23:15 | 000,470,360 | ---- | C] () -- D:\Daten\bookmarks.html
[2013.03.18 20:23:15 | 000,058,116 | ---- | C] () -- D:\Daten\AutoSave_Untitled.skp
[2013.03.18 20:18:14 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll
[2013.03.18 20:18:09 | 000,114,688 | ---- | C] () -- C:\Windows\SysNative\tapiui64.exe
[2013.03.12 22:58:07 | 000,003,120 | ---- | C] () -- C:\Windows\SysWow64\ALLFSAF8a.ocx
[2013.03.11 18:26:55 | 000,000,224 | ---- | C] () -- C:\Users\#\Desktop\Franz Liszt - Ungarische Rhapsodie no.2 - YouTube.URL
[2012.11.06 14:07:39 | 000,000,153 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2012.05.11 13:19:58 | 000,045,568 | ---- | C] () -- C:\Windows\UniFish3.exe
[2012.05.10 12:16:04 | 000,013,931 | ---- | C] () -- C:\Windows\SysWow64\RaCoInst.dat
[2012.05.10 09:51:24 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2012.05.10 09:51:24 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\clauth2.dll
[2012.05.10 09:51:24 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\clauth1.dll
[2012.05.10 09:51:24 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll
[2012.05.10 09:51:24 | 000,000,073 | ---- | C] () -- C:\Windows\SysWow64\ssprs.dll
[2012.05.10 09:51:24 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI
[2012.05.02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.03.21 21:19:10 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat
[2012.03.09 06:31:26 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.03.09 06:31:26 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.01.05 17:41:50 | 000,000,037 | ---- | C] () -- C:\Users\#\AppData\Roaming\Winamp_BackupWinamp_Backup_Integrity.winampbackup
[2011.12.19 14:47:28 | 000,197,120 | ---- | C] () -- C:\Windows\patchw32.dll
[2011.12.18 17:01:24 | 000,189,672 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011.12.18 17:01:18 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011.12.12 01:13:39 | 000,000,400 | ---- | C] () -- C:\Windows\g_lfolqn712.ini
[2011.12.12 01:13:39 | 000,000,400 | ---- | C] () -- C:\Windows\SysWow64\drivers\bfrpsej167.dat
[2011.11.18 18:47:20 | 000,000,533 | ---- | C] () -- C:\Windows\eReg.dat
[2011.11.17 20:58:15 | 001,597,720 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.11.17 20:40:11 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.10.25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012.10.06 16:50:58 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\.minecraft
[2012.06.20 15:54:29 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Abvent
[2012.06.20 15:54:29 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Abvent_Artlantis4
[2012.09.25 12:59:04 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\ASCOMP Software
[2012.11.10 18:04:11 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Ashampoo
[2011.12.19 14:48:45 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Atari
[2012.11.20 21:30:01 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Autodesk
[2012.02.16 13:09:15 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\DAEMON Tools Lite
[2013.03.19 11:17:09 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\DesktopIconForAmazon
[2013.04.08 11:01:08 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Dropbox
[2013.04.07 23:13:41 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\FileZilla
[2012.05.10 17:08:57 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\IrfanView
[2013.03.18 20:19:06 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Jumping Bytes
[2012.01.13 00:40:20 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Leadertech
[2013.03.07 21:00:56 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\LucasArts
[2013.04.07 19:56:30 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\MiniLyrics
[2012.03.27 17:58:55 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Miranda
[2012.06.20 17:20:04 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\ML
[2012.01.19 15:01:46 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Notepad++
[2013.03.18 20:18:06 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\OCS
[2011.11.22 20:24:21 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\OpenOffice.org
[2013.03.18 20:18:08 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Opera
[2013.04.05 00:42:47 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Origin
[2012.05.29 16:03:37 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Samsung
[2013.04.07 15:10:20 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Spotify
[2013.03.19 12:02:14 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Sync App Settings
[2013.02.25 01:01:06 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\SyncTunesDesktop
[2012.07.25 21:36:31 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\TeamViewer
[2011.11.17 16:51:48 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Thunderbird
[2013.03.16 22:56:44 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Ubisoft
[2013.03.08 17:25:26 | 000,000,000 | ---D | M] -- C:\Users\#\AppData\Roaming\Wargaming.net
========== Purity Check ==========
< End of report > Code:
OTL Extras logfile created on: 04.04.2013 11:47:21 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\#\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
7,98 Gb Total Physical Memory | 5,90 Gb Available Physical Memory | 73,93% Memory free
15,96 Gb Paging File | 13,61 Gb Available in Paging File | 85,25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97,56 Gb Total Space | 11,00 Gb Free Space | 11,27% Space Free | Partition Type: NTFS
Drive D: | 368,10 Gb Total Space | 105,41 Gb Free Space | 28,64% Space Free | Partition Type: NTFS
Drive G: | 698,63 Gb Total Space | 16,54 Gb Free Space | 2,37% Space Free | Partition Type: NTFS
Computer Name: #-PC | User Name: # | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0EAFD372-F733-4535-9172-8FFBD1917453}" = rport=445 | protocol=6 | dir=out | app=system |
"{12548A41-58AC-4688-9F3C-5291C5AF171A}" = lport=427 | protocol=6 | dir=in | name=advanced tcp/ip slp port |
"{1590EFEC-41CC-45EF-A764-7749C281890E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2498CA81-C4FB-48E1-A344-07D5F2857051}" = rport=10243 | protocol=6 | dir=out | app=system |
"{47EDF200-F5B6-4339-9DB1-2D8DEBD44F7D}" = lport=50248 | protocol=6 | dir=in | name=autodesk content service |
"{4F2049A5-32F0-4599-BDD0-08898050BD08}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{52AB130B-9CBF-4C37-AC0D-EFA40F8AF825}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{563E890C-59AB-4753-A16E-056A68771F8D}" = rport=139 | protocol=6 | dir=out | app=system |
"{60887AD5-1D98-4DDF-891A-549CBF611E01}" = lport=161 | protocol=6 | dir=in | name=advanced tcp/ip snmp port |
"{68237433-71E4-4816-B230-5F56FCE94BC1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6C38B0AA-1AD6-4EDC-B0A9-08249FF3F55D}" = lport=445 | protocol=6 | dir=in | app=system |
"{6E4D52D0-5C54-44FF-A8D6-B1EA118138D3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6F754A2C-2BD5-4310-BA92-517BB35BB7EA}" = lport=10243 | protocol=6 | dir=in | app=system |
"{75F1F681-93D7-47AA-B8BB-FAC25A326FCF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{79818E8A-AAC6-401D-B8F9-CD76BEF23309}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{7DCD4572-59F5-4D80-99AC-AE221DB6BCA9}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{82854198-C21A-403D-9F19-5E7F89A49106}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{84C0CFAD-8477-44BB-ACF6-4ECA03969AE3}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{85649610-FBBE-4539-BEA9-138954C5A9BB}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{900DAA92-DE92-4B44-9F7A-4FF73E8E093B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9B79133C-713E-4665-A2AA-209D1DC01FD1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A661C632-7D8B-4F51-9A09-F25828CFD964}" = rport=137 | protocol=17 | dir=out | app=system |
"{B5433370-EEDE-4411-91EC-E58EE78380CE}" = lport=139 | protocol=6 | dir=in | app=system |
"{BA06E99F-6A55-4161-911C-8CCE820EDA4F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{BDF3C143-97C1-4EB7-A347-855D2A0EA65C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BE809C92-4C5B-42A1-9112-58FFD24F893A}" = lport=138 | protocol=17 | dir=in | app=system |
"{BF61394D-1C5F-4A08-BD4A-9041BC7C2256}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C66A866D-BB89-4E2F-9C53-18B51C45E1BE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C8B36F94-E8D6-46D6-92AF-A40492357485}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D03F2716-B1F5-4549-8379-BB70C8471B44}" = lport=9100 | protocol=6 | dir=in | name=advanced tcp/ip printer port |
"{D1AFEDC9-6CA3-41CA-AB69-B415643E55BB}" = lport=9100 | protocol=6 | dir=in | name=advanced tcp/ip printer port |
"{D4B32C4F-6E06-499B-AAAE-BCAA1F872981}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{DBA75F84-4644-4605-A385-BEE2BC0C70FF}" = lport=427 | protocol=6 | dir=in | name=advanced tcp/ip slp port |
"{E24D6E83-EBF7-4E63-9009-6A9D1A0E292F}" = lport=161 | protocol=6 | dir=in | name=advanced tcp/ip snmp port |
"{EB11BB99-A39D-4236-B66C-AEE5C23C5880}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{ED0C8042-39E8-45ED-B855-32199B9D0832}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{F6CA969D-1145-4009-A8A0-8C931A4E4BDB}" = lport=137 | protocol=17 | dir=in | app=system |
"{FA30ECA0-0A05-40AA-A4C8-C75030EA9F5F}" = rport=138 | protocol=17 | dir=out | app=system |
"{FD44DD2B-7896-44DA-94C6-32CA5C668AEE}" = lport=2869 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{008ACDBA-88B5-4D17-AAC9-29054E8370BF}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\#\day of defeat\hl.exe |
"{0273E1A5-66B9-42F4-B6DA-18047C97D9D7}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsvsvr.exe |
"{04D21294-467F-4804-A162-D655271CEA96}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{08587AE2-B4B3-4698-9613-99544FCA108F}" = protocol=6 | dir=in | app=c:\users\#\appdata\local\temp\7zsb84a.tmp\easyinst64.exe |
"{0A0C1522-5C2D-4760-B6C9-2A1A4B984F7B}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\saints row the third\game_launcher.exe |
"{0D1F492E-4E8E-4113-BA17-EFB15E06C9D6}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{0D1FD4E2-252F-4581-AC8D-D7F514F18057}" = protocol=17 | dir=in | app=c:\program files\autodesk\3ds max design 2013\3dsmax.exe |
"{0E8ED250-E191-4562-9C35-0F0A3599C38E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{0F534902-B6BA-4687-BD5E-0B6E7A083680}" = protocol=17 | dir=in | app=d:\games\company of heroes\relicdownloader\relicdownloader.exe |
"{1471792F-06FE-4DB8-AAD2-0D6E709447DC}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{14C1486A-C563-4C42-ACC7-43AD77C8EAC1}" = protocol=17 | dir=in | app=c:\users\#\appdata\roaming\dropbox\bin\dropbox.exe |
"{14CCF4B8-2635-45F1-A2BC-2E1311EAD80C}" = protocol=17 | dir=in | app=d:\games\call of duty 4 - modern warfare\iw3mp.exe |
"{17265453-7562-4D64-86B2-7D76B4F62B2E}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\metro 2033\metro2033.exe |
"{1B011913-3F88-4B83-A18A-0F43C4710B90}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{202418C7-1F28-49AF-BBE9-8177117805AA}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{24647528-88D9-4303-BD9A-C7B428D0B024}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsasvr.exe |
"{24DA4BB3-BA47-4CFA-995C-7FD36DFF0CFC}" = protocol=6 | dir=in | app=d:\games\battlefield play4free\bfp4f.exe |
"{2AB162F8-FDF8-4EF3-B3BB-19A3712D6203}" = protocol=6 | dir=out | app=system |
"{2DCC1DF7-6486-4704-B8AC-9F881E8F732E}" = protocol=17 | dir=in | app=c:\program files\autodesk\3ds max design 2013\nvidia\raysat_3dsmax2013_64server.exe |
"{2E317F64-EF51-4975-82BD-606150BE3DDF}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{307E64E0-AE5D-4692-B964-8232240CCB97}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{30CFD0E0-2D26-45DA-83C4-5D15F8A3DB71}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{33DEDD79-F8CA-44DB-8A24-69E02824CCB2}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsasvr.exe |
"{354E3674-5F84-4A9B-A536-791DD5810B78}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{38DC5B54-F37F-434B-A952-CDEBA0D866E8}" = protocol=6 | dir=in | app=c:\program files\artlantis render 4\qtsocketserver.exe |
"{3921FDDA-35B3-4136-A79D-FBD4C9EB753C}" = protocol=6 | dir=in | app=c:\users\#\appdata\local\temp\7zsa1b3.tmp\easyinst64.exe |
"{3BB126A5-D7C0-429B-840B-B5ADE1265E9B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{3BC466C5-67E9-4420-98AD-059CD6B339CC}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{3D42F190-5939-457A-8A7C-AD9588C5FF64}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3F76814D-82C5-495E-8FCC-48B7086398AD}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\#\team fortress 2\hl2.exe |
"{4089B4F3-ED8B-4265-BEF0-7D40FBF2361C}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\saints row the third\game_launcher.exe |
"{40D4700C-615E-4AF9-9DC5-691332EC7445}" = protocol=6 | dir=in | app=c:\program files\autodesk\3ds max design 2013\nvidia\raysat_3dsmax2013_64server.exe |
"{4678ED75-63D8-42E0-BE03-38268EF2E1EF}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{47381E2B-A33D-4228-9F36-5160F161E4F0}" = protocol=17 | dir=in | app=c:\xampp\apache\bin\httpd.exe |
"{479210D6-F5C3-486C-9291-1F2F5EF507EA}" = protocol=6 | dir=in | app=c:\program files\autodesk\3ds max design 2013\3dsmax.exe |
"{4850C64F-13EF-4050-84D6-593C43E8803A}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\#\team fortress 2\hl2.exe |
"{4B27C719-600F-42FD-8ED0-159ACF1E3AAE}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{522F6EC9-D3B3-4BD6-8E06-C393C6FEB167}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{52B4805A-CCF8-43D4-A104-FB233BB619C8}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{53651DE3-3B36-4A5A-BF53-32E6923A7922}" = protocol=6 | dir=in | app=c:\xampp\mysql\bin\mysqld.exe |
"{54A00F0C-BCF1-4648-BEB2-6E03F1F63D5E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{57F29136-5611-4BDB-B6AC-D3DC53675413}" = protocol=17 | dir=in | app=d:\games\anno 1404\anno4.exe |
"{58F0DD74-296F-4C05-9C8F-60B28794E9BB}" = protocol=6 | dir=in | app=c:\users\#\appdata\local\temp\7zsab4b.tmp\easyinst64.exe |
"{5BF62E22-FCE9-49ED-9817-ED3382683AA7}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe |
"{5EBEF418-BB9B-4A41-818E-8BA740CBE9AC}" = protocol=6 | dir=in | app=d:\games\company of heroes\reliccoh.exe |
"{5F07D6B2-734C-4177-A427-DCDE094931ED}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{62DD6C29-0D1F-4FE7-B146-88CE23B3DE24}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{64E6648F-56AC-4E6D-9838-58B952AC07EF}" = protocol=17 | dir=in | app=c:\xampp\mysql\bin\mysqld.exe |
"{67834B56-C184-406F-B9A1-E7DF4094D94F}" = protocol=6 | dir=in | app=d:\games\call of duty 4 - modern warfare\iw3mp.exe |
"{691A2DCB-48C6-406C-8FF8-A8C9ADFDC416}" = protocol=17 | dir=in | app=c:\users\#\appdata\local\temp\7zsab4b.tmp\easyinst64.exe |
"{6C1A30FC-DB27-4F3E-835B-8B5078750A85}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{714DF4B8-AC7E-41E8-A3FF-6B566E97EA54}" = protocol=6 | dir=in | app=c:\users\#\appdata\roaming\spotify\spotify.exe |
"{7CB0721F-9012-4CC9-AB40-B05B77E42245}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7D344152-7988-4027-8556-89595681EE6B}" = protocol=17 | dir=in | app=c:\users\#\appdata\roaming\spotify\spotify.exe |
"{849F955C-C3A2-4ACA-BCAF-444F6D72D53F}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\saints row the third\saintsrowthethird.exe |
"{87D2B8B6-1C14-4313-B3E4-D6D02E5CFABE}" = protocol=17 | dir=in | app=d:\games\anno 1404\tools\anno4web.exe |
"{8AE8EF8D-C143-4665-9CFB-2219562EBB18}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\company of heroes\reliccoh.exe |
"{8B9FFC9D-4267-40D4-914B-6224060EB629}" = protocol=17 | dir=in | app=c:\users\#\appdata\roaming\spotify\spotify.exe |
"{8ED72352-6236-4E56-ABD3-2C7F994EB410}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{92CEE5B8-B093-43BC-8002-26166AF43652}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{94AD9E56-FEEE-4934-A951-8B051EB2DEB9}" = protocol=17 | dir=in | app=d:\games\defcon\defcon.exe |
"{9606871B-B672-4E39-843F-5B75D588BFCB}" = protocol=6 | dir=in | app=c:\users\#\appdata\roaming\spotify\spotify.exe |
"{960D14CD-A166-4E50-A5DF-2A9523A14335}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{963CE535-9F5E-4801-A8AF-3671EDC1DB0D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{96439218-3446-416C-A023-8192156C3D23}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{96A7554E-4193-48A6-9135-794AD34E15CD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{988D3E00-F8A8-4957-8341-55B5F28AEC29}" = protocol=6 | dir=in | app=d:\games\defcon\defcon.exe |
"{9ADFADC3-611F-4226-82DD-1933962D5CB6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9C554F64-7867-44BD-926A-5350FB5F23E3}" = protocol=17 | dir=in | app=c:\users\#\appdata\local\temp\7zsa1b3.tmp\easyinst64.exe |
"{9C8D52FD-D5D1-4ED9-9A45-A8A635B104A4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9D3D0348-B76A-43C3-90FB-2828C053A673}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\metro 2033\metro2033.exe |
"{A0B333D9-79D8-40A5-BB5B-7F7CE7E4B986}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A3193B29-6673-44D6-8AD0-AB4F8B9BBA99}" = protocol=17 | dir=in | app=c:\program files\artlantis render 4\qtsocketserver.exe |
"{AB6F3F14-AFB3-4537-AE42-D6EDE977E499}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{AC42405A-534E-4B97-9BA0-D82906845AC0}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{AD762EEF-39AE-480F-B1D1-2AEF0767A4D1}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{AECFA2FC-6653-4B33-85EB-8E1737AB2FFF}" = protocol=17 | dir=in | app=d:\games\steam\steam.exe |
"{B282007A-EA46-44E9-99C6-9E08273EA956}" = dir=in | app=c:\program files (x86)\vmware\vmware player\vmware-authd.exe |
"{B60A709C-0ED9-428F-9B95-32D0A7FB4AEF}" = protocol=17 | dir=in | app=c:\program files\autodesk\3ds max design 2013\nvidia\raysat_3dsmax2013_64.exe |
"{B84772ED-0A28-49DB-9F27-64B8AAD05D95}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{B85DBAA0-A521-48BE-99EA-B61E2719FD5E}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{BD5A55E4-43D5-4F1A-9799-0D78FA99F926}" = protocol=6 | dir=in | app=d:\games\anno 1404\tools\anno4web.exe |
"{C5EC9DD2-2969-47B4-8C6A-6F46194017E7}" = protocol=17 | dir=in | app=d:\games\company of heroes\reliccoh.exe |
"{C6E75C2C-BC16-4229-A8CC-CABA66ACE89F}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{C6EE8D3C-A079-4159-BE81-8EB0DC96FE96}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe |
"{C764A5B0-142A-4B28-AB4A-EC9B9F5D05FB}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\company of heroes\reliccoh.exe |
"{C850C463-82BD-48DE-B857-2DC77FE5AF7B}" = protocol=6 | dir=in | app=c:\users\#\appdata\roaming\dropbox\bin\dropbox.exe |
"{CD592509-F0F4-43C4-B8E0-66FA2FE2CDF9}" = protocol=6 | dir=in | app=d:\games\steam\steam.exe |
"{CE310789-75EF-4E4C-84EA-5B0892460971}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{CFBBD1CC-63B0-49A3-ACDF-98761B3E1E7C}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\half-life\hl.exe |
"{D0E42CF9-8B1D-47AC-9A1F-D742E63D36E2}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{D1671D62-7AD8-4530-A7FE-448BF07B7E27}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\half-life\hl.exe |
"{D2FE1F8F-534F-488B-BB5A-ACE83E0B4EE4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D53834C4-2AC6-4799-80DF-CE3F59B9EBF4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{D5E22FFE-8CC3-45F1-A36D-550FFD5838BF}" = protocol=6 | dir=in | app=d:\games\anno 1404\anno4.exe |
"{DA7545A6-D927-4CE2-BF93-A0D18CDD6E14}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{DC187D1E-4147-4E37-BD5C-AA64658EB229}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{DC772A82-9870-474F-AB96-C53DA0481B11}" = dir=in | app=c:\program files (x86)\vmware\vmware player\vmware-authd.exe |
"{DD559201-F0D0-44C7-8C87-E1EC64B8EC6E}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{DF1A0FFD-9B72-49AB-9872-18012B5A10D4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E1A8FF4A-15A6-406A-B6F1-55244AF24ABD}" = protocol=17 | dir=in | app=d:\games\battlefield play4free\bfp4f.exe |
"{E1FADC08-F115-498A-88AB-F39E36126787}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{E222F174-D8FE-4A2D-BCAD-915ED6693124}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E3B45BE5-C099-4262-92DB-9E31ED54E302}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\saints row the third\saintsrowthethird.exe |
"{E46C155C-82AC-4725-BAB3-43075E43192D}" = protocol=6 | dir=in | app=d:\games\company of heroes\relicdownloader\relicdownloader.exe |
"{E6CB7C86-15EB-47A9-B213-CDD2D3158CC5}" = protocol=17 | dir=in | app=c:\users\#\appdata\local\temp\7zsb84a.tmp\easyinst64.exe |
"{E7832A39-BD8B-49C4-AAE5-A0FB6CD7A176}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsvsvr.exe |
"{EE8677E8-B497-4840-B7DB-4EEEEB245093}" = protocol=6 | dir=in | app=c:\xampp\apache\bin\httpd.exe |
"{F395AA01-E884-4179-91C0-946657807AE5}" = dir=in | app=c:\program files (x86)\the bit studio\synctunes desktop\synctunes.exe |
"{F984BF96-6ADC-4439-95F3-F87B57A1A2E3}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{F9C65BBF-D139-4F3B-B08B-9ADFC9875313}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\#\day of defeat\hl.exe |
"{FBC10221-5BDA-4B38-AF50-18C7432D9DA9}" = protocol=6 | dir=in | app=c:\program files\autodesk\3ds max design 2013\nvidia\raysat_3dsmax2013_64.exe |
"TCP Query User{021209B3-BFD8-417B-B973-474742589A8F}D:\games\left4dead 2\left4dead2.exe" = protocol=6 | dir=in | app=d:\games\left4dead 2\left4dead2.exe |
"TCP Query User{03DC74EF-8E20-494B-A10C-43BD878B9E0F}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"TCP Query User{0759ED40-BC4E-4D50-AC5A-1BD710DB16F8}D:\games\battlefield play4free\bfp4f.exe" = protocol=6 | dir=in | app=d:\games\battlefield play4free\bfp4f.exe |
"TCP Query User{0C80CCCD-F122-4B01-90B8-0F2A16F3748D}D:\games\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |
"TCP Query User{0CD36FCD-77C5-40A3-BF3E-A7805EA9EB99}D:\games\call of duty 4 - modern warfare\iw3mp.exe" = protocol=6 | dir=in | app=d:\games\call of duty 4 - modern warfare\iw3mp.exe |
"TCP Query User{1CCB2C0D-11D5-47CE-8A95-3BEC56D36505}D:\games\steam\steamapps\#\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=d:\games\steam\steamapps\#\team fortress 2\hl2.exe |
"TCP Query User{3A979192-D99B-4BF1-8143-71729ACB2C46}C:\xampp\apache\bin\httpd.exe" = protocol=6 | dir=in | app=c:\xampp\apache\bin\httpd.exe |
"TCP Query User{4294A731-9E8D-4F6A-8EDE-8FF6B7E1F96D}D:\games\day of defeat source\hl2.exe" = protocol=6 | dir=in | app=d:\games\day of defeat source\hl2.exe |
"TCP Query User{4760A9F5-0D84-4F67-9684-D58C3FEB151C}C:\program files (x86)\miranda im\miranda32.exe" = protocol=6 | dir=in | app=c:\program files (x86)\miranda im\miranda32.exe |
"TCP Query User{4F6F1FDD-4B34-49AA-A94A-2E692E400F46}C:\xampp\mysql\bin\mysqld.exe" = protocol=6 | dir=in | app=c:\xampp\mysql\bin\mysqld.exe |
"TCP Query User{6CC32321-CDC6-403C-9E75-1B10C5ACC1E0}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{74E50359-CAC1-4049-AE1F-98329F8D9CFF}D:\games\flatout 2\flatout2.exe" = protocol=6 | dir=in | app=d:\games\flatout 2\flatout2.exe |
"TCP Query User{7B3CA050-97ED-43E7-8E1F-AA7AFFABA0CC}D:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=d:\games\world_of_tanks\wotlauncher.exe |
"TCP Query User{7CF4D801-26B3-4393-A940-09AF0991E5FC}D:\games\left4dead\left4dead.exe" = protocol=6 | dir=in | app=d:\games\left4dead\left4dead.exe |
"TCP Query User{90D6DCDE-9052-488E-92B5-6962C6EB6A35}C:\program files (x86)\miranda im\miranda32.exe" = protocol=6 | dir=in | app=c:\program files (x86)\miranda im\miranda32.exe |
"TCP Query User{A22722A1-7BD6-4CDB-B620-19FEC6312C1E}D:\games\anno 1701\anno1701.exe" = protocol=6 | dir=in | app=d:\games\anno 1701\anno1701.exe |
"TCP Query User{A7AAEA6F-0F85-4B2A-AD09-60F994BB11E6}D:\games\counter-strike 1.6\counter-strike 1.6\hl.exe" = protocol=6 | dir=in | app=d:\games\counter-strike 1.6\counter-strike 1.6\hl.exe |
"TCP Query User{A7E88A75-316A-49B0-AFF0-23A6C2549288}C:\program files\artlantis render 4\qtsocketserver.exe" = protocol=6 | dir=in | app=c:\program files\artlantis render 4\qtsocketserver.exe |
"TCP Query User{B47C65F0-AB82-4355-ABC1-E37A3872B308}D:\games\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=d:\games\counter-strike source\hl2.exe |
"TCP Query User{CEE7552F-C5B7-4140-ACDE-A2B2C1686DE9}D:\games\defcon\defcon.exe" = protocol=6 | dir=in | app=d:\games\defcon\defcon.exe |
"UDP Query User{0667B88E-AF60-40BA-B050-3CBEB7BA4468}C:\xampp\mysql\bin\mysqld.exe" = protocol=17 | dir=in | app=c:\xampp\mysql\bin\mysqld.exe |
"UDP Query User{1B72F74A-9489-46FB-9F5E-85E0ADF77324}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"UDP Query User{23EC61A1-570C-43BE-B801-0B05A2C37884}C:\program files\artlantis render 4\qtsocketserver.exe" = protocol=17 | dir=in | app=c:\program files\artlantis render 4\qtsocketserver.exe |
"UDP Query User{2B8488C0-DA09-431C-A672-5CFCC9B2C6A4}D:\games\battlefield play4free\bfp4f.exe" = protocol=17 | dir=in | app=d:\games\battlefield play4free\bfp4f.exe |
"UDP Query User{3C63EE2B-EA97-414C-98AD-24856EBF95CA}D:\games\flatout 2\flatout2.exe" = protocol=17 | dir=in | app=d:\games\flatout 2\flatout2.exe |
"UDP Query User{530F1923-BCC3-4184-9072-F7F667260EAC}C:\xampp\apache\bin\httpd.exe" = protocol=17 | dir=in | app=c:\xampp\apache\bin\httpd.exe |
"UDP Query User{5B73F878-B429-40DE-BCFD-199152A5812B}D:\games\defcon\defcon.exe" = protocol=17 | dir=in | app=d:\games\defcon\defcon.exe |
"UDP Query User{5F40CF64-D7C5-4B44-8C1C-3A81AC160AE1}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{6D320456-BBBF-4F99-B05D-D695AA762C66}D:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=d:\games\world_of_tanks\wotlauncher.exe |
"UDP Query User{7CF4B7FC-7B95-4881-9937-510E6CCAFDB1}D:\games\counter-strike 1.6\counter-strike 1.6\hl.exe" = protocol=17 | dir=in | app=d:\games\counter-strike 1.6\counter-strike 1.6\hl.exe |
"UDP Query User{80651B89-1395-4AF1-BEF4-1179171EF159}D:\games\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |
"UDP Query User{A7245F21-AC03-47B4-877D-959AAF679E31}C:\program files (x86)\miranda im\miranda32.exe" = protocol=17 | dir=in | app=c:\program files (x86)\miranda im\miranda32.exe |
"UDP Query User{AA8C0DEA-E343-45BA-A848-D8BA1A242926}D:\games\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=d:\games\counter-strike source\hl2.exe |
"UDP Query User{AC1FA569-5776-444D-8452-1DE11CA27C61}D:\games\call of duty 4 - modern warfare\iw3mp.exe" = protocol=17 | dir=in | app=d:\games\call of duty 4 - modern warfare\iw3mp.exe |
"UDP Query User{AFDDB22E-6510-4D21-9481-40D7C41B43A1}D:\games\day of defeat source\hl2.exe" = protocol=17 | dir=in | app=d:\games\day of defeat source\hl2.exe |
"UDP Query User{B2AA9C71-485B-4237-9D9C-AF77450DBA31}D:\games\left4dead 2\left4dead2.exe" = protocol=17 | dir=in | app=d:\games\left4dead 2\left4dead2.exe |
"UDP Query User{C455D1C6-3ED8-4889-914C-727F30E92E38}D:\games\steam\steamapps\#\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=d:\games\steam\steamapps\#\team fortress 2\hl2.exe |
"UDP Query User{D1968150-E083-457B-95C9-B76AEDD73ED8}C:\program files (x86)\miranda im\miranda32.exe" = protocol=17 | dir=in | app=c:\program files (x86)\miranda im\miranda32.exe |
"UDP Query User{D5646934-5CC4-4DBF-819B-66514A11E6D7}D:\games\left4dead\left4dead.exe" = protocol=17 | dir=in | app=d:\games\left4dead\left4dead.exe |
"UDP Query User{EB9A34B9-45B6-4DED-A25E-0D3980CD45D2}D:\games\anno 1701\anno1701.exe" = protocol=17 | dir=in | app=d:\games\anno 1701\anno1701.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes
"{06E18300-BB64-1664-8E6A-2593FC67BB74}" = Autodesk Revit Interoperability for 3ds Max and 3ds Max Design 2013 64-bit
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86416031FF}" = Java(TM) 6 Update 31 (64-bit)
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{2F808931-D235-4FC7-90CD-F8A890C97B2F}" = Composite 2013 64-bit
"{324297F8-2898-454B-9AC4-07050AEB35B3}" = Autodesk DirectConnect 2013 64-bit
"{4975DE61-6BF6-B9BC-1FDE-C04C5EC78E4C}" = AMD Media Foundation Decoders
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4FF5C7C9-86CC-41ED-B93B-0B51AB4FED24}" = VmciSockets
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5783F2D7-B001-0000-0102-0060B0CE6BBA}" = AutoCAD 2013 - English
"{5783F2D7-B001-0409-1102-0060B0CE6BBA}" = AutoCAD 2013 Language Pack - English
"{5783F2D7-B001-0409-2102-0060B0CE6BBA}" = AutoCAD 2013 - English
"{5E03A267-415E-5383-FA8F-3CE4145663B9}" = AMD Catalyst Install Manager
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{62CBE596-1BB8-4D7B-A056-103287BAD1C4}" = Autodesk Essential Skills Movies for 3ds Max Design 2013 64-bit
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7346B4A0-1200-0111-0407-705C0D862004}" = Revit Architecture 2012 Language Pack - Deutsch
"{7346B4A0-1300-0510-0407-705C0D862004}" = Revit 2013
"{7346B4A0-1300-0511-0407-705C0D862004}" = Revit 2013 Language Pack - Deutsch
"{7D65612F-53B4-0409-85AA-21DF5A8E9455}" = Autodesk 3ds Max Design 2013 64-bit
"{82C1E6E4-6718-4EFD-9DCC-E276D690EF46}" = Autodesk Inventor Fusion plug-in for AutoCAD 2013
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{89EE4A30-080F-2C95-6F78-C98D18FBD74D}" = AMD Accelerated Video Transcoding
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90A80D89-A0E4-33C1-B13D-B93CB3496867}" = Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{9CF11D16-ECEB-90A5-A028-CA9E068D848B}" = ccc-utility64
"{9E6BB4E4-0B20-4922-AA37-260FA5ACFBA5}" = Autodesk Maya 2012 64-bit
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64
"{B69A7CBA-9139-7ACB-7564-4CD5D8C36E26}" = AMD Drag and Drop Transcoding
"{BC66B242-DF13-1664-851B-00123612ED98}" = Autodesk Inventor Server Engine for 3ds Max Design 2013 64-bit
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{E6420CCB-92BE-3ACB-BDC3-69FBDD319C94}" = Microsoft Visual Studio 2008 Remote Debugger Light (x64) - DEU
"{EE5F74BC-5CD5-4EF2-86BA-81E6CF46A18F}" = Autodesk Sync
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FC4AD39F-9DCE-4BD0-B7D0-7C81CEB9F04B}" = NVIDIA PhysX Plug-in for Autodesk Maya 2012 64 bit
"{FE2F4875-095C-427C-9A97-4F8DE05ACF22}" = Autodesk Inventor Fusion plug-in language pack for AutoCAD 2013
"AutoCAD 2013 - English" = AutoCAD 2013 - English
"Autodesk 3ds Max Design 2013 64-bit" = Autodesk 3ds Max Design 2013 64-bit
"Autodesk DirectConnect 2013 64-bit" = Autodesk DirectConnect 2013 64-bit
"Autodesk FBX Plug-in 2013.1 - 3ds Max Design 2013 64-bit" = Autodesk FBX Plug-in 2013.1 - 3ds Max Design 2013 64-bit
"Autodesk Inventor Fusion plug-in for AutoCAD 2013" = Autodesk Inventor Fusion plug-in for AutoCAD 2013
"Autodesk Maya 2012 64-bit" = Autodesk Maya 2012 64-bit
"Autodesk Revit 2013" = Autodesk Revit 2013
"HP LaserJet Professional P1100-P1560-P1600 Series" = HP LaserJet Professional P1100-P1560-P1600 Series
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Visual Studio 2008 Remote Debugger Light (x64) - DEU" = Microsoft Visual Studio 2008 Remote Debugger Light (x64) - DEU
"Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU" = Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU
"Wacom Tablet Driver" = Wacom Tablett
"WinRAR archiver" = WinRAR 4.01 (64-Bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{017F8447-2A1D-0DDB-B5D7-CA2BFACE2886}" = CCC Help French
"{03534DA5-2F88-4B8E-A978-849B979E1B8F}" = TuxGuitar
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}" = Microsoft Visual C++ 2008 x86 ATL Runtime 9.0.30729
"{0513EE35-E0FB-4166-B663-BD1AE3A803DE}" = Anno 1404
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054E9A1C-3EA2-C657-E787-FD8DCF5C3D3B}" = CCC Help Czech
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{117EBEEB-5DB0-43C8-9FD6-DD583DB152DD}" = Autodesk Material Library 2013
"{14866AAD-1F23-39AC-A62B-7091ED1ADE64}" = Microsoft Visual C++ 2008 x86 CRT Runtime 9.0.30729
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1DE2BD51-0300-772D-5E18-F337D95D5687}" = CCC Help German
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1" = World of Tanks
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{224E8FEB-5C1F-077F-6FC5-602AC1AE644D}" = CCC Help Danish
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17
"{275E9C49-C72F-D754-DEB7-77F10A9C00D8}" = CCC Help Japanese
"{27C6C0A2-2EC9-4FEA-BE2B-659EAAC2C68C}" = Autodesk Material Library Low Resolution Image Library 2013
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{30049739-BE95-6591-B504-E6D7057D49CC}" = CCC Help Spanish
"{342F5437-C87D-4BB5-89B9-B23E16C6A395}" = Microsoft Visual C++ 8.0 Support DLLs
"{34B32B70-8081-11E2-89AF-B8AC6F98CCE3}" = Google Earth Plug-in
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3AB65E95-37D6-4DD7-8862-29AED3AFD54B}" = Google SketchUp Pro 8
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3D347E6D-5A03-4342-B5BA-6A771885F379}" = Autodesk Backburner 2013.0.0
"{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}" = ANNO 1404
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3F0D0ABE-CDAF-431A-00BC-CBBE018EA74E}" = SimCity 4 Deluxe
"{3F1EB155-F96E-EB7B-2EF2-7375490E0FA9}" = CCC Help English
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple Application Support
"{47C6F987-685A-41AE-B092-E75B277AEE39}" = Adobe Flash CS4 Extension - Flash Lite STI others
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{4B023D7B-9E67-795D-FB31-B5E1F6DCA451}" = CCC Help Italian
"{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}" = Microsoft Visual C++ 2008 x86 OpenMP Runtime 9.0.30729
"{4D96D2F0-8FB4-45C2-9B80-2DCB88016316}_is1" = Machinarium
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{55F6C486-8C75-2A72-DAFE-CE78A624C9F7}" = CCC Help Russian
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{58760EEC-8B6A-43F4-81AA-696E381DFADD}" = Autodesk Material Library Medium Resolution Image Library 2013
"{5AF23993-7152-1620-E43F-1B4542FB4F84}" = CCC Help Thai
"{606E12B9-641F-4644-A22A-FF38AE980AFD}" = Autodesk Material Library Base Resolution Image Library 2013
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{62F029AB-85F2-0000-866A-9FC0DD99DDBC}" = Autodesk Content Service
"{62F029AB-85F2-0001-866A-9FC0DD99DDBC}" = Autodesk Content Service Language Pack
"{63326924-3CAF-C858-3A8F-8598C87019D7}" = Catalyst Control Center
"{63822E89-11AA-F8EC-D433-F72A85799EC0}" = CCC Help Greek
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{66361420-4905-AEB8-17AE-172FDD164A7E}" = CCC Help Polish
"{66FDDF31-084D-49D7-99C2-0D3FE8A27763}_is1" = Dungeon Keeper Complete Collection
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6DA2B636-698A-3294-BF4A-B5E11B238CDD}" = Microsoft Visual C++ 2008 x64 MFC Runtime 9.0.30729
"{6DC61284-C3F6-4628-96E2-9B07DDEAD672}_is1" = The Secret Of Monkey Island Special Edition
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}" = RollerCoaster Tycoon 2
"{769F2A4B-84A3-9486-ADD2-9E5AB4B4E1E3}" = Catalyst Control Center InstallProxy
"{76DAEC83-AF7B-333C-8A53-83D7C7D39199}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - DEU
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{8773DD1C-5FB2-95B5-5A93-0EFEAC900A4D}" = CCC Help Norwegian
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{885843E7-6CAC-4791-B7BF-1CD516017954}_is1" = DLL Suite 2013
"{8CCBB0BF-9CC1-1A65-BB93-56012A460EE6}" = CCC Help Portuguese
"{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}" = Microsoft Visual C++ 2008 x64 OpenMP Runtime 9.0.30729
"{8E87B944-4815-3C5E-947F-5035C9F64362}" = Microsoft Visual Studio Tools for Applications 2.0 Language Pack - DEU
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT2860 Wireless LAN Card
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon® 3
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0A3CE05-96CB-52E9-434E-074F3BB7807E}" = CCC Help Turkish
"{A2433A63-5F5D-40E5-B529-9123C2B3E734}" = Anno 1701
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9C64319-932F-D02B-B14C-FFFC3EC49E77}" = CCC Help Chinese Standard
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}_954" = Adobe Acrobat 9.5.4 - CPSID_83708
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B1AD83A0-DC92-41E3-B111-E9472349768C}" = RollerCoaster Tycoon 2: Wacky Worlds
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}" = Microsoft Visual C++ 2008 x86 MFC Runtime 9.0.30729
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BCE46757-7674-4416-BEDB-68205A60409E}" = CanoScan Toolbox Ver4.1
"{BD3374D3-C2E6-42B7-A80B-E850B6886246}" = Adobe Flash CS4 STI-other
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C09DB932-7619-7B56-30E3-C0454811D6D7}" = CCC Help Korean
"{C22A4697-BD77-ACB1-744F-1FD0A0BFF798}" = CCC Help Swedish
"{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}" = Microsoft Visual C++ 2008 x64 ATL Runtime 9.0.30729
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{D4B457B2-260F-C561-CA87-703BD3B724CA}" = Catalyst Control Center Graphics Previews Common
"{D6CDB506-297D-AE70-0EF6-DE5185F961BE}" = CCC Help Chinese Traditional
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E3355E5C-965C-4f67-8A8C-E9A0FA9FD80F}" = Rhinoceros 4.0 Evaluation
"{E452E727-86B8-4233-8CC3-41FD817AFAFF}" = VMware Player
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{EA926717-CE5A-4CB4-AB21-9E6E9565A458}" = RCT3 Soaked
"{ECFD508E-68A2-91B2-46DD-1D03D783D94B}" = Catalyst Control Center Localization All
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{EDE361D5-35A5-DA7D-3462-C3DABD24029B}" = CCC Help Hungarian
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F1E7DD6A-AE2D-D706-BEB3-937F76CA6AE9}" = CCC Help Finnish
"{F56F54DD-BCB2-1221-2CB7-E983A5CF9D15}" = CCC Help Dutch
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}" = Microsoft Visual C++ 2008 x64 CRT Runtime 9.0.30729
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FE6DCC8D-427F-405C-A779-C93B6D9F77A5}" = Autodesk Civil View for 3ds Max Design 2013
"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection
"Allway Sync_is1" = Allway Sync version 12.3.3
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE v.6.80
"Autodesk Content Service" = Autodesk Content Service
"Avira AntiVir Desktop" = Avira Free Antivirus
"Bridge Building Game" = Bridge Building Game
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DAEMON Tools Lite" = DAEMON Tools Lite
"Defcon_is1" = Defcon v1.5 de rtl
"Episode 1" = Back to the Future The Game - Episode 1
"FileZilla Client" = FileZilla Client 3.6.0.2
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"IrfanView" = IrfanView (remove only)
"LastFM_is1" = Last.fm Scrobbler 2.1.35
"LDraw2012-01" = LDraw All-In-One-Installer 2012-01
"MiniLyrics" = MiniLyrics
"Miranda IM" = Miranda IM 0.10.11
"MozBackup" = MozBackup 1.5.1
"Mozilla Firefox 19.0.2 (x86 de)" = Mozilla Firefox 19.0.2 (x86 de)
"Mozilla Thunderbird 17.0.4 (x86 de)" = Mozilla Thunderbird 17.0.4 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NoLimits Coasters full" = NoLimits Coasters 1.8 (remove only)
"Notepad++" = Notepad++
"OpenTTD" = OpenTTD 1.2.1
"PunkBusterSvc" = PunkBuster Services
"RollerCoaster Tycoon Setup" = Roll
"Sam & Max - Culture Shock" = Sam & Max - Culture Shock 1.0
"Steam App 10" = Counter-Strike
"Steam App 20540" = Company of Heroes: Tales of Valor
"Steam App 218" = Source SDK Base 2007
"Steam App 219640" = Chivalry: Medieval Warfare
"Steam App 43110" = Metro 2033
"Steam App 440" = Team Fortress 2
"Steam App 4560" = Company of Heroes
"Steam App 55230" = Saints Row: The Third
"Steamless Left4Dead Pack" = Steamless Left4Dead Pack
"Steamless Left4Dead2 Pack" = Steamless Left4Dead2 Pack
"UnPowerItNow_is1" = UnPowerIt Now! 1.06
"VLC media player" = VLC media player 1.1.11
"VMware_Player" = VMware Player
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"xampp" = XAMPP 1.7.7
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Episode 2" = Back to the Future The Game - Episode 2
"Episode 3" = Back to the Future The Game - Episode 3
"Episode 4" = Back to the Future The Game - Episode 4
"Episode 5" = Back to the Future The Game - Episode 5
"Network Addon Mod" = Network Addon Mod 31
"Spotify" = Spotify
"UnityWebPlayer" = Unity Web Player
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 05.03.2013 08:46:14 | Computer Name = #-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 05.03.2013 08:46:14 | Computer Name = #-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 11030
Error - 05.03.2013 08:46:14 | Computer Name = #-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 11030
Error - 05.03.2013 17:17:21 | Computer Name = #-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: firefox.exe, Version: 19.0.0.4794,
Zeitstempel: 0x511ed1c1 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0,
Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x2bf4fb60 ID des fehlerhaften
Prozesses: 0xc88 Startzeit der fehlerhaften Anwendung: 0x01ce19e1fd37806a Pfad der
fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Pfad
des fehlerhaften Moduls: unknown Berichtskennung: 10a04508-85da-11e2-b977-14dae96d8089
Error - 06.03.2013 16:22:18 | Computer Name = #-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\Autodesk\Composite
2013\python\lib\distutils\command\wininst-8_d.exe". Die abhängige Assemblierung
"Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 07.03.2013 07:40:15 | Computer Name = #-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\Autodesk\Composite
2013\python\lib\distutils\command\wininst-8_d.exe". Die abhängige Assemblierung
"Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 07.03.2013 09:38:25 | Computer Name = #-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\Autodesk\Composite
2013\python\lib\distutils\command\wininst-8_d.exe". Die abhängige Assemblierung
"Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 08.03.2013 07:15:22 | Computer Name = #-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\Autodesk\Composite
2013\python\lib\distutils\command\wininst-8_d.exe". Die abhängige Assemblierung
"Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 08.03.2013 12:29:58 | Computer Name = #-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iTunes.exe, Version: 11.0.2.26, Zeitstempel:
0x51253247 Name des fehlerhaften Moduls: itw_scrobbler.dll_unloaded, Version: 0.0.0.0,
Zeitstempel: 0x510036aa Ausnahmecode: 0xc0000005 Fehleroffset: 0x09ac0eeb ID des fehlerhaften
Prozesses: 0x1114 Startzeit der fehlerhaften Anwendung: 0x01ce1c1a1b0c393b Pfad der
fehlerhaften Anwendung: C:\Program Files (x86)\iTunes\iTunes.exe Pfad des fehlerhaften
Moduls: itw_scrobbler.dll Berichtskennung: 6a2d00ec-880d-11e2-8ac2-14dae96d8089
Error - 08.03.2013 12:30:16 | Computer Name = #-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iTunes.exe, Version: 11.0.2.26, Zeitstempel:
0x51253247 Name des fehlerhaften Moduls: itw_scrobbler.dll_unloaded, Version: 0.0.0.0,
Zeitstempel: 0x510036aa Ausnahmecode: 0xc0000005 Fehleroffset: 0x09a2cb00 ID des fehlerhaften
Prozesses: 0x1114 Startzeit der fehlerhaften Anwendung: 0x01ce1c1a1b0c393b Pfad der
fehlerhaften Anwendung: C:\Program Files (x86)\iTunes\iTunes.exe Pfad des fehlerhaften
Moduls: itw_scrobbler.dll Berichtskennung: 75227d0e-880d-11e2-8ac2-14dae96d8089
[ System Events ]
Error - 26.03.2013 11:10:10 | Computer Name = #-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "vhdmp Streaming Filter" wurde unerwartet beendet. Dies ist
bereits 1 Mal passiert.
Error - 26.03.2013 18:39:12 | Computer Name = #-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "vhdmp Streaming Filter" wurde unerwartet beendet. Dies ist
bereits 1 Mal passiert.
Error - 27.03.2013 04:50:12 | Computer Name = #-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem
Fehler beendet: %%-2147014847
Error - 27.03.2013 05:35:34 | Computer Name = #-PC | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
Error - 27.03.2013 11:44:48 | Computer Name = #-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "vhdmp Streaming Filter" wurde unerwartet beendet. Dies ist
bereits 1 Mal passiert.
Error - 28.03.2013 06:29:29 | Computer Name = #-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem
Fehler beendet: %%-2147014847
Error - 28.03.2013 20:03:54 | Computer Name = #-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "vhdmp Streaming Filter" wurde unerwartet beendet. Dies ist
bereits 1 Mal passiert.
Error - 02.04.2013 11:09:35 | Computer Name = #-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "vhdmp Streaming Filter" wurde unerwartet beendet. Dies ist
bereits 1 Mal passiert.
Error - 03.04.2013 09:09:33 | Computer Name = #-PC | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
Error - 03.04.2013 15:33:26 | Computer Name = #-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "vhdmp Streaming Filter" wurde unerwartet beendet. Dies ist
bereits 1 Mal passiert.
< End of report > [CODE]
GMER Logfile: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-04-08 11:56:29
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_HD502HJ rev.1AJ10001 465,76GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\#\AppData\Local\Temp\pwtoapod.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[2536] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000076361465 2 bytes [36, 76]
.text C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[2536] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000763614bb 2 bytes [36, 76]
.text ... * 2
.text C:\Windows\SysWOW64\PnkBstrA.exe[2560] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000072ed1a22 2 bytes [ED, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2560] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000072ed1ad0 2 bytes [ED, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2560] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000072ed1b08 2 bytes [ED, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2560] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000072ed1bba 2 bytes [ED, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2560] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000072ed1bda 2 bytes [ED, 72]
.text C:\Windows\SysWOW64\vmnat.exe[3424] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 5 0000000073f513b1 1 byte [73]
.text C:\Windows\SysWOW64\vmnat.exe[3424] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 21 0000000073f513c1 1 byte [73]
.text ... * 20
.text C:\Windows\SysWOW64\vmnat.exe[3424] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 23 0000000073f5153f 1 byte [73]
.text C:\Windows\SysWOW64\vmnat.exe[3424] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 44 0000000073f51554 1 byte [73]
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076361465 2 bytes [36, 76]
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000763614bb 2 bytes [36, 76]
.text ... * 2
.text C:\Users\#\Desktop\I MOG DES NIT\Defogger.exe[5812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076361465 2 bytes [36, 76]
.text C:\Users\#\Desktop\I MOG DES NIT\Defogger.exe[5812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000763614bb 2 bytes [36, 76]
.text ... * 2
---- Registry - GMER 2.1 ----
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\Users\#\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SimCity\x2122\SimCity\x2122 Recovery.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimCity\x2122\SimCity\x2122 Recovery.lnk 1
---- EOF - GMER 2.1 ---- --- --- --- |