NuclearShot | 01.07.2013 13:44 | Hallo,
Ich wollte Sie nicht anschreien und es tut mir leid, wenn es bei Ihnen so angekommen ist.
OTL.txt:OTL Logfile: Code:
OTL logfile created on: 01.07.2013 14:18:19 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\ahmet\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16599)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,82 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 62,20% Memory free
9,55 Gb Paging File | 7,61 Gb Available in Paging File | 79,66% Paging File free
Paging file location(s): C:\pagefile.sys 5868 5868 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 441,95 Gb Total Space | 377,89 Gb Free Space | 85,50% Space Free | Partition Type: NTFS
Computer Name: WINDOWS8 | User Name: ahmet | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.07.01 14:11:29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ahmet\Desktop\OTL.exe
PRC - [2013.06.20 23:06:11 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013.06.19 15:12:23 | 000,216,968 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
PRC - [2013.06.15 03:28:44 | 000,825,808 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013.06.07 22:55:30 | 000,047,896 | ---- | M] (WebCake LLC) -- C:\Users\ahmet\AppData\Roaming\WebCake\WebCakeDesktop.exe
PRC - [2013.06.07 18:28:06 | 001,302,336 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe
PRC - [2013.06.07 17:10:22 | 000,806,776 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
PRC - [2013.05.23 15:16:56 | 000,311,152 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
PRC - [2013.05.23 15:16:52 | 001,561,968 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe
PRC - [2013.05.23 11:09:59 | 002,827,728 | ---- | M] () -- C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe
PRC - [2013.05.02 21:21:44 | 000,109,064 | ---- | M] (Wajam) -- C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe
PRC - [2013.02.09 12:43:02 | 000,067,904 | ---- | M] (OrdinarySoft) -- C:\Program Files\Start Menu X\StartMenuXService.exe
PRC - [2012.08.24 07:24:38 | 002,435,728 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
PRC - [2012.08.23 08:24:38 | 000,259,136 | ---- | M] (NTI Corporation) -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
PRC - [2012.08.23 08:24:10 | 000,533,568 | ---- | M] (NTI Corporation) -- C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
PRC - [2012.08.23 00:04:22 | 000,025,232 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
PRC - [2012.08.23 00:04:20 | 000,044,176 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
PRC - [2012.08.21 12:36:54 | 000,473,712 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LMutilps32.exe
PRC - [2012.08.21 12:36:52 | 001,176,176 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2012.08.21 12:36:52 | 000,348,784 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2012.08.01 10:08:36 | 000,081,536 | ---- | M] (Atheros) -- C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe
PRC - [2012.07.17 11:10:32 | 000,364,416 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2012.07.17 11:10:30 | 000,276,864 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2012.07.17 11:10:16 | 000,165,760 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
PRC - [2012.07.04 19:57:44 | 000,990,320 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
========== Modules (No Company Name) ==========
MOD - [2013.06.15 03:28:42 | 000,393,168 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll
MOD - [2013.06.15 03:28:41 | 013,140,432 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
MOD - [2013.06.15 03:28:40 | 004,051,408 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll
MOD - [2013.06.15 03:27:51 | 000,599,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\libglesv2.dll
MOD - [2013.06.15 03:27:50 | 000,124,368 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\libegl.dll
MOD - [2013.06.15 03:27:48 | 001,597,392 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ffmpegsumo.dll
MOD - [2013.05.23 11:09:59 | 002,827,728 | ---- | M] () -- C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe
MOD - [2013.05.23 11:09:01 | 002,521,040 | ---- | M] () -- C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll
MOD - [2013.05.21 20:35:49 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7f8a97dd3bd029b406e8c552f441eb12\System.Configuration.ni.dll
MOD - [2013.05.20 20:01:50 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d981792ebf85627e57c7d95594aa7092\System.Xml.ni.dll
MOD - [2013.05.20 20:01:46 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f95cd925503fa9fef4b50d511917a580\System.Windows.Forms.ni.dll
MOD - [2013.05.20 20:01:40 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\97e24281000ae702b067281f3a01878a\System.Drawing.ni.dll
MOD - [2013.05.20 20:01:06 | 007,989,248 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\0b80769ba127fce3221c1fd47e87c4a7\System.ni.dll
MOD - [2013.05.20 20:01:00 | 011,494,912 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8d2929ad589e1092eb62a43424361465\mscorlib.ni.dll
MOD - [2013.05.20 20:00:52 | 007,561,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\e1ec8b9a6d4f9af9d6065c4187fb1b5f\System.Xml.ni.dll
MOD - [2013.05.20 20:00:47 | 001,880,576 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\f641b786d36d1cc5a5531a746c96ce1b\System.Xaml.ni.dll
MOD - [2013.05.20 20:00:35 | 000,220,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\1f3dbc5b0a874bf49a4559e71274f8ba\System.ServiceProcess.ni.dll
MOD - [2013.05.20 20:00:14 | 000,786,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\bbebe831e3b0761ad47dcc09231cbc29\System.Runtime.Remoting.ni.dll
MOD - [2013.05.20 19:59:58 | 000,958,464 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\aa29c7539bd729147a7d1f1ae0ce5670\System.Configuration.ni.dll
MOD - [2013.05.20 19:59:56 | 018,542,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\7de1487a84cd8b173129065729f9f465\PresentationFramework.ni.dll
MOD - [2013.05.20 19:59:42 | 010,926,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\242e86930542076b424887d674d21d10\PresentationCore.ni.dll
MOD - [2013.05.20 19:59:34 | 003,910,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\1058660861056b038fbc9274994c8b75\WindowsBase.ni.dll
MOD - [2013.05.20 19:59:29 | 006,998,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\024a883cc8b0013f72a77d594c278f4d\System.Core.ni.dll
MOD - [2013.05.20 19:59:23 | 009,937,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\a7811936e59aaee26b1d9d467174d6d4\System.ni.dll
MOD - [2013.05.20 19:59:15 | 016,544,768 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\374a0cc6603f58864831897ef723bd4a\mscorlib.ni.dll
MOD - [2012.10.09 04:23:11 | 003,198,976 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2012.09.14 00:04:06 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2012.08.23 08:26:10 | 000,465,384 | ---- | M] () -- C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
MOD - [2012.08.23 00:04:22 | 000,025,232 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
MOD - [2012.08.23 00:04:20 | 000,044,176 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
========== Services (SafeList) ==========
SRV - [2013.06.20 23:06:11 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2013.06.17 00:24:48 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.06.14 18:15:06 | 000,148,000 | ---- | M] (DealPly Technologies Ltd) [On_Demand | Stopped] -- C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe -- (dealplylivem)
SRV - [2013.06.14 18:15:06 | 000,148,000 | ---- | M] (DealPly Technologies Ltd) [Auto | Running] -- C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe -- (dealplylive)
SRV - [2013.06.07 17:10:22 | 000,806,776 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2013.06.03 16:21:54 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.05.23 11:09:59 | 002,827,728 | ---- | M] () [Auto | Running] -- C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe -- (BrowserDefendert)
SRV - [2013.05.15 15:23:00 | 000,885,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe -- (WO_LiveService)
SRV - [2013.05.02 21:21:44 | 000,109,064 | ---- | M] (Wajam) [Auto | Running] -- C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe -- (WajamUpdater)
SRV - [2013.04.12 12:37:24 | 000,032,256 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe -- (SrvUpdater)
SRV - [2012.11.15 06:25:24 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012.11.15 05:53:57 | 000,093,296 | ---- | M] (Dritek System INC.) [Auto | Running] -- C:\Windows\RfBtnSvc64.exe -- (RfButtonDriverService)
SRV - [2012.10.23 05:37:58 | 000,277,024 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2012.09.20 10:18:03 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2012.08.24 07:24:38 | 002,435,728 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe -- (CCDMonitorService)
SRV - [2012.08.23 08:24:38 | 000,259,136 | ---- | M] (NTI Corporation) [Auto | Running] -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2012.08.21 12:36:52 | 000,348,784 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2012.08.11 04:28:14 | 000,211,584 | ---- | M] (Qualcomm Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe -- (AtherosSvc)
SRV - [2012.08.01 10:08:36 | 000,081,536 | ---- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe -- (ZAtheros Wlan Agent)
SRV - [2012.07.26 05:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2012.07.17 11:10:32 | 000,364,416 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2012.07.17 11:10:30 | 000,276,864 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2012.07.17 11:10:16 | 000,165,760 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service)
SRV - [2012.07.13 11:02:16 | 002,451,456 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)
SRV - [2012.07.12 05:10:24 | 000,174,160 | ---- | M] (Egis Technology Inc. ) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe -- (EgisTec Ticket Service)
SRV - [2012.01.26 23:19:18 | 000,332,080 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\PROGRA~1\mcafee\msc\mcawfwk.exe -- (McAWFwk)
SRV - [2010.10.12 19:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2009.08.24 22:16:12 | 000,544,768 | ---- | M] (mst software GmbH, Germany) [On_Demand | Stopped] -- C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\DfsdkS64.exe -- (DfSdkS)
========== Driver Services (SafeList) ==========
DRV - [2012.08.01 15:44:04 | 000,014,544 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys -- (WinRing0_1_2_0)
DRV - [2011.03.08 06:01:06 | 000,012,824 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerProcessMonitor64.sys -- (LiveTunerPM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {FA056DB0-82DE-45BF-9BC2-5676E3675F09}
IE - HKLM\..\SearchScopes\{FA056DB0-82DE-45BF-9BC2-5676E3675F09}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = Delta Search
IE - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
IE - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Babylon Search
IE - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001\..\URLSearchHook: {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\7.2\iobitappsToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001\..\SearchScopes,DefaultScope = {A9F4122A-8325-4D29-BD47-21D5FC78249D}
IE - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A8E912689DABB75E&affID=119357&tt=250613_gr3&tsp=4927
IE - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001\..\SearchScopes\{A9F4122A-8325-4D29-BD47-21D5FC78249D}: "URL" = hxxp://ch.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=114576&p={searchTerms}
IE - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B25A1388B-6B18-46c3-BEBA-A81915D0DE8F%7D:1.7.8.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..keyword.URL: "hxxp://search.yahoo.com/search?ei=utf-8&fr=greentree_ff1&type=114576&ilc=12&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=114576"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=3: C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd)
FF - HKLM\Software\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=9: C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2013.06.26 14:07:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2013.05.16 16:47:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK [2013.05.13 20:49:30 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\70A404B1-BEF2-461E-A753-A3227EB40C64: C:\Program Files (x86)\FunkLyrics\116.xpi [2013.06.25 19:15:25 | 000,004,468 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}: C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi [2013.05.02 21:21:44 | 000,037,909 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\LyricsArt@SternoC.co: C:\Program Files (x86)\LyricsArt\116.xpi [2013.06.30 13:13:18 | 000,005,014 | ---- | M] ()
[2013.06.17 00:09:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ahmet\AppData\Roaming\mozilla\Extensions
[2013.06.30 13:13:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ahmet\AppData\Roaming\mozilla\Firefox\Profiles\k6sf7ehn.default\extensions
[2013.06.30 13:13:19 | 000,000,000 | ---D | M] (LyricsArt) -- C:\Users\ahmet\AppData\Roaming\mozilla\Firefox\Profiles\k6sf7ehn.default\extensions\116
[2013.06.28 17:43:30 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Users\ahmet\AppData\Roaming\mozilla\Firefox\Profiles\k6sf7ehn.default\extensions\ffxtlbr@delta.com
[2013.06.17 00:25:15 | 000,334,744 | ---- | M] () (No name found) -- C:\Users\ahmet\AppData\Roaming\mozilla\firefox\profiles\k6sf7ehn.default\extensions\langpack-de@firefox.mozilla.org.xpi
[2013.06.17 00:22:04 | 000,360,364 | ---- | M] () (No name found) -- C:\Users\ahmet\AppData\Roaming\mozilla\firefox\profiles\k6sf7ehn.default\extensions\langpack-ga-IE@firefox.mozilla.org.xpi
[2013.06.17 00:22:16 | 000,359,496 | ---- | M] () (No name found) -- C:\Users\ahmet\AppData\Roaming\mozilla\firefox\profiles\k6sf7ehn.default\extensions\langpack-gd@firefox.mozilla.org.xpi
[2013.06.17 00:22:30 | 000,382,471 | ---- | M] () (No name found) -- C:\Users\ahmet\AppData\Roaming\mozilla\firefox\profiles\k6sf7ehn.default\extensions\langpack-gu-IN@firefox.mozilla.org.xpi
[2013.06.17 00:10:13 | 000,504,298 | ---- | M] () (No name found) -- C:\Users\ahmet\AppData\Roaming\mozilla\firefox\profiles\k6sf7ehn.default\extensions\{25A1388B-6B18-46c3-BEBA-A81915D0DE8F}.xpi
[2013.06.17 16:28:29 | 000,870,680 | ---- | M] () (No name found) -- C:\Users\ahmet\AppData\Roaming\mozilla\firefox\profiles\k6sf7ehn.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.06.28 17:43:22 | 000,006,545 | ---- | M] () -- C:\Users\ahmet\AppData\Roaming\mozilla\firefox\profiles\k6sf7ehn.default\searchplugins\babylon.xml
[2013.06.28 17:43:22 | 000,006,545 | ---- | M] () -- C:\Users\ahmet\AppData\Roaming\mozilla\firefox\profiles\k6sf7ehn.default\searchplugins\BrowserDefender.xml
[2013.06.28 17:43:31 | 000,001,294 | ---- | M] () -- C:\Users\ahmet\AppData\Roaming\mozilla\firefox\profiles\k6sf7ehn.default\searchplugins\delta.xml
[2013.06.15 21:30:42 | 000,000,904 | ---- | M] () -- C:\Users\ahmet\AppData\Roaming\mozilla\firefox\profiles\k6sf7ehn.default\searchplugins\yahoo.xml
========== Chrome ==========
CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url = hxxp://ch.search.yahoo.com/search?fr=chr-greentree_gc&ei=utf-8&ilc=12&type=114576&p={searchTerms}
CHR - default_search_provider: suggest_url = hxxp://ff.search.yahoo.com/gossip?output=fxjson&command={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll
CHR - plugin: DealPlyLive Update (Enabled) = C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Java(TM) Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Microsoft Office 2013 (Enabled) = C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - Extension: LyricsArt = C:\Users\ahmet\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajcghoegamlabppilamagaddfdfamden\1.116_0\
CHR - Extension: Delta Toolbar = C:\Users\ahmet\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.4_0\
CHR - Extension: SiteAdvisor = C:\Users\ahmet\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.2.1341_0\
CHR - Extension: WebCake = C:\Users\ahmet\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh\1.0.3_0\
CHR - Extension: Ebay Shopping Assistant by Spigot = C:\Users\ahmet\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.0_0\
CHR - Extension: Domain Error Assistant = C:\Users\ahmet\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.1_0\
CHR - Extension: Wajam = C:\Users\ahmet\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: Slick Savings = C:\Users\ahmet\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.4_0\
CHR - Extension: DealPly Shopping = C:\Users\ahmet\AppData\Local\Google\Chrome\User Data\Default\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf\3.5.0.0_0\
CHR - Extension: FunkLyrics = C:\Users\ahmet\AppData\Local\Google\Chrome\User Data\Default\Extensions\napkhbcjepnfkbghigljkegibkdpddhc\1.116_0\
CHR - Extension: Amazon Shopping Assistant by Spigot = C:\Users\ahmet\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp\1.0_0\
O1 HOSTS File: ([2013.07.01 00:13:20 | 000,010,493 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O1 - Hosts: 37.221.160.35 iMeetzu - Meet a stranger. Chatroulette, Omegle, and Camzap alternative with a social network and free online dating site!
O1 - Hosts: 37.221.160.35 imeetzu.com
O1 - Hosts: 37.221.160.35 Omegle: Talk to strangers!
O1 - Hosts: 37.221.160.35 omegle.com
O1 - Hosts: 37.221.160.35 RuneScape – MMORPG – Free Online Fantasy Adventure Game | Strategy Games
O1 - Hosts: 37.221.160.35 runescape.com
O1 - Hosts: 37.221.160.35 google.com
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 37.221.160.35 Google
O1 - Hosts: 337 more lines...
O2 - BHO: (FunkLyrics) - {03BD65B8-D810-48BC-8116-597671666B30} - C:\Program Files (x86)\FunkLyrics\116.dll (MNST corp)
O2 - BHO: (IObit Apps Toolbar) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\7.2\iobitappsToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (WebCake) - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files (x86)\WebCake\WebCakeIEClient.dll (WebCake LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20130515180900.dll (McAfee, Inc.)
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (DealPly Shopping) - {ae48ed75-5a56-4c5f-bbce-6f1ac3875f66} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (LyricsArt) - {E8A6EA19-52BB-42F9-8AA4-1769E5199EBF} - C:\Program Files (x86)\LyricsArt\116.dll (SternoC LTD)
O2 - BHO: (PricePeep) - {FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} - C:\Program Files (x86)\PricePeep\pricepeep.dll (PricePeep)
O3 - HKLM\..\Toolbar: (IObit Apps Toolbar) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\7.2\iobitappsToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll (Delta-search.com)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Dolby Home Theater v4] C:\Dolby PCEE4\pcee4.exe (Dolby Laboratories Inc.)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LManager] File not found
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001..\Run: [StartMenuX] C:\Program Files\Start Menu X\StartMenuX.exe (OrdinarySoft)
O4 - HKU\S-1-5-21-3745752851-2045490827-2738593552-1001..\Run: [WebCake Desktop] C:\Users\ahmet\AppData\Roaming\WebCake\WebCakeDesktop.exe (WebCake LLC)
O4 - HKU\.DEFAULT..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} File not found
O4 - HKU\S-1-5-18..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} File not found
O4 - HKU\S-1-5-19..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} File not found
O4 - HKU\S-1-5-20..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{01F6010D-61DD-445D-B824-F69FFC3100C6}: DhcpNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 85.119.136.140
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F3D2E2A4-16CB-454F-823C-349644703C3B}: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll (McAfee, Inc.)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20 - HKLM Winlogon: UserInit - (userinit.exe) - File not found
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29 - HKLM SecurityProviders - (credssp.dll) - File not found
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013.07.01 14:08:04 | 000,002,550 | ---- | M] () - C:\autoupdate.log -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.07.01 14:12:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013.07.01 14:11:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\ahmet\Desktop\OTL.exe
[2013.06.30 21:24:14 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CrashDump
[2013.06.30 20:48:28 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\NativeFus_Log
[2013.06.30 20:48:23 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Local\Samsung
[2013.06.30 20:48:20 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\Samsung
[2013.06.30 20:48:13 | 000,000,000 | ---D | C] -- C:\Users\ahmet\Documents\samsung
[2013.06.30 20:45:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec
[2013.06.30 20:45:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MyFree Codec
[2013.06.30 20:44:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2013.06.30 20:43:58 | 004,659,712 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\SysWow64\Redemption.dll
[2013.06.30 20:43:51 | 000,821,824 | ---- | C] (Devguru Co., Ltd.) -- C:\Windows\SysWow64\dgderapi.dll
[2013.06.30 20:42:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
[2013.06.30 20:42:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung
[2013.06.30 20:41:32 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Local\Downloaded Installations
[2013.06.30 19:18:46 | 010,788,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2013.06.30 19:18:36 | 008,857,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.dll
[2013.06.30 19:18:33 | 002,035,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2013.06.30 19:18:33 | 000,014,848 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\rars.rs
[2013.06.30 19:18:31 | 000,621,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll
[2013.06.30 19:18:31 | 000,247,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ubpm.dll
[2013.06.30 19:18:29 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netplwiz.dll
[2013.06.30 19:18:27 | 000,758,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Magnify.exe
[2013.06.30 19:18:26 | 000,449,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DevicePairing.dll
[2013.06.30 19:18:25 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\biwinrt.dll
[2013.06.30 19:18:24 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\intl.cpl
[2013.06.30 19:18:23 | 000,411,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfmp4srcsnk.dll
[2013.06.30 19:18:23 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll
[2013.06.30 19:18:22 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\BCP47Langs.dll
[2013.06.30 19:18:22 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll
[2013.06.30 19:18:21 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe
[2013.06.30 19:18:21 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\muifontsetup.dll
[2013.06.30 19:17:39 | 001,013,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certutil.exe
[2013.06.30 19:17:08 | 000,793,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autochk.exe
[2013.06.30 19:17:08 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\untfs.dll
[2013.06.30 14:13:21 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\.minecraft
[2013.06.30 14:10:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013.06.30 14:10:51 | 000,263,592 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013.06.30 14:10:49 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013.06.30 14:10:49 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013.06.30 14:10:49 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.06.30 13:13:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LyricsArt
[2013.06.29 23:48:55 | 000,695,296 | ---- | C] (AnjoCaido) -- C:\Users\ahmet\Desktop\MinecraftSP.exe
[2013.06.29 23:48:06 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.06.29 23:48:05 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UXInit.dll
[2013.06.28 17:43:47 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
[2013.06.28 17:43:37 | 000,000,000 | ---D | C] -- C:\ProgramData\BrowserDefender
[2013.06.28 17:43:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Delta
[2013.06.28 17:43:29 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\Delta
[2013.06.28 17:43:29 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\BabSolution
[2013.06.28 17:43:16 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
[2013.06.28 17:43:15 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Local\Wajam
[2013.06.28 17:43:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wajam
[2013.06.28 17:43:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2013.06.28 17:43:04 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\Babylon
[2013.06.28 15:20:20 | 000,000,000 | ---D | C] -- C:\DV
[2013.06.26 16:09:40 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\TechSmith
[2013.06.26 16:09:26 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Local\TechSmith
[2013.06.26 16:00:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
[2013.06.26 15:43:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LyricsFinder
[2013.06.26 15:42:20 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\QuickTime
[2013.06.26 15:42:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Camtasia Studio 7
[2013.06.26 15:42:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2013.06.26 15:42:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\TechSmith Shared
[2013.06.26 15:39:30 | 000,000,000 | ---D | C] -- C:\Users\ahmet\Documents\Camtasia Studio
[2013.06.26 15:38:57 | 000,000,000 | ---D | C] -- C:\ProgramData\TechSmith
[2013.06.26 15:38:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TechSmith
[2013.06.26 15:06:11 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Local\gegl-0.2
[2013.06.26 15:06:11 | 000,000,000 | ---D | C] -- C:\Users\ahmet\.gimp-2.8
[2013.06.26 14:18:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013.06.25 21:47:07 | 000,000,000 | ---D | C] -- C:\Users\ahmet\Documents\Video deluxe 2013
[2013.06.25 21:47:07 | 000,000,000 | ---D | C] -- C:\Users\ahmet\Documents\MAGIX Downloads
[2013.06.25 21:47:07 | 000,000,000 | ---D | C] -- C:\Users\ahmet\Documents\MAGIX
[2013.06.25 21:47:07 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\MAGIX
[2013.06.25 21:46:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\MAGIX Shared
[2013.06.25 21:44:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MAGIX
[2013.06.25 21:44:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\MAGIX Services
[2013.06.25 21:44:43 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX
[2013.06.25 21:44:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2013.06.25 20:33:55 | 000,000,000 | ---D | C] -- C:\Users\ahmet\Desktop\Videos
[2013.06.25 20:32:24 | 000,000,000 | ---D | C] -- C:\ProgramData\APN
[2013.06.25 20:32:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
[2013.06.25 20:31:59 | 000,489,392 | ---- | C] (Ask Partner Network) -- C:\Users\ahmet\Documents\APNSetup.exe
[2013.06.25 19:15:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FunkLyrics
[2013.06.23 15:33:37 | 000,000,000 | ---D | C] -- C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
[2013.06.23 14:36:51 | 000,000,000 | ---D | C] -- C:\ProgramData\StarApp
[2013.06.23 14:36:42 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallMate
[2013.06.22 19:07:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Intenium
[2013.06.20 17:53:25 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2013.06.20 17:27:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
[2013.06.20 13:25:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2013.06.20 13:20:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Activision
[2013.06.19 23:42:07 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Local\PunkBuster
[2013.06.19 23:41:03 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_8.dll
[2013.06.19 23:41:03 | 000,018,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_2.dll
[2013.06.19 23:41:01 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_34.dll
[2013.06.19 23:41:01 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_34.dll
[2013.06.19 23:41:01 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_34.dll
[2013.06.19 23:41:00 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_3.dll
[2013.06.19 23:40:59 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_7.dll
[2013.06.19 23:40:58 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_33.dll
[2013.06.19 23:40:58 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_33.dll
[2013.06.19 23:40:58 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_33.dll
[2013.06.19 23:40:57 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_6.dll
[2013.06.19 23:40:56 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_5.dll
[2013.06.19 23:40:55 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_32.dll
[2013.06.19 23:40:55 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10.dll
[2013.06.19 23:40:54 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_31.dll
[2013.06.19 23:40:54 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_4.dll
[2013.06.19 23:40:54 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_1.dll
[2013.06.19 23:40:53 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_3.dll
[2013.06.19 23:40:53 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_2.dll
[2013.06.19 23:40:52 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_2.dll
[2013.06.19 23:40:51 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_1.dll
[2013.06.19 23:40:50 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_1.dll
[2013.06.19 23:40:45 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_30.dll
[2013.06.19 23:40:43 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_0.dll
[2013.06.19 23:40:43 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_0.dll
[2013.06.19 23:40:42 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_29.dll
[2013.06.19 23:40:42 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_28.dll
[2013.06.19 23:40:41 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_27.dll
[2013.06.19 23:40:40 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_26.dll
[2013.06.19 23:40:39 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_25.dll
[2013.06.19 23:40:38 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_24.dll
[2013.06.19 19:37:15 | 000,000,000 | ---D | C] -- C:\Users\ahmet\Desktop\Lebenslauf
[2013.06.19 15:56:06 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\Nico Mak Computing
[2013.06.19 15:55:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinZip Registry Optimizer
[2013.06.19 15:53:54 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\uTorrent
[2013.06.19 15:13:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013.06.17 00:26:19 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Local\Macromedia
[2013.06.17 00:09:13 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\Mozilla
[2013.06.17 00:09:13 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Local\Mozilla
[2013.06.17 00:09:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2013.06.15 21:30:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit Apps Toolbar
[2013.06.15 21:30:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Updater
[2013.06.14 19:07:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elcomsoft Password Recovery
[2013.06.14 19:07:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Elcomsoft Password Recovery
[2013.06.14 19:07:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Elcomsoft Password Recovery
[2013.06.14 19:07:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Elcomsoft
[2013.06.14 18:15:58 | 000,000,000 | ---D | C] -- C:\Users\ahmet\Documents\My Cheat Tables
[2013.06.14 18:15:48 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\OpenCandy
[2013.06.14 18:15:12 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\WebCake
[2013.06.14 18:15:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WebCake
[2013.06.14 18:15:07 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Local\DealPlyLive
[2013.06.14 18:15:07 | 000,000,000 | ---D | C] -- C:\ProgramData\DealPlyLive
[2013.06.14 18:15:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DealPlyLive
[2013.06.14 18:15:04 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\Dealply
[2013.06.14 18:15:03 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
[2013.06.14 18:15:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DealPly
[2013.06.14 18:15:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer
[2013.06.09 18:10:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013.06.09 18:09:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2013.06.09 18:07:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DsNET Corp
[2013.06.07 19:50:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
[2013.06.07 19:50:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Ashampoo
[2013.06.07 19:50:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ashampoo
[2013.06.02 18:17:25 | 000,000,000 | ---D | C] -- C:\Fraps
[2013.06.01 20:46:27 | 000,000,000 | ---D | C] -- C:\Users\ahmet\Documents\Razer
[2013.06.01 20:43:50 | 000,000,000 | ---D | C] -- C:\Users\ahmet\AppData\Local\Razer
[2013.06.01 20:43:34 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll
[2013.06.01 20:43:34 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_43.dll
[2013.06.01 20:43:34 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_43.dll
[2013.06.01 20:43:34 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_43.dll
[2013.06.01 20:43:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Razer
[2013.06.01 20:43:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Razer
========== Files - Modified Within 30 Days ==========
[2013.07.01 14:23:02 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.07.01 14:20:11 | 000,000,922 | ---- | M] () -- C:\Windows\tasks\DealPlyLiveUpdateTaskMachineUA.job
[2013.07.01 14:17:00 | 000,001,126 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.07.01 14:15:00 | 000,000,308 | ---- | M] () -- C:\Windows\tasks\Dealply.job
[2013.07.01 14:12:59 | 000,001,832 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Internet Security Suite.lnk
[2013.07.01 14:11:29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ahmet\Desktop\OTL.exe
[2013.07.01 14:09:14 | 000,067,584 | -H-- | M] () -- C:\Windows\bootstat.dat
[2013.07.01 14:07:45 | 000,000,402 | ---- | M] () -- C:\Windows\tasks\FunkLyrics Update.job
[2013.07.01 14:07:45 | 000,000,398 | ---- | M] () -- C:\Windows\tasks\LyricsArt Update.job
[2013.07.01 14:07:40 | 000,001,122 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.07.01 14:07:40 | 000,000,918 | ---- | M] () -- C:\Windows\tasks\DealPlyLiveUpdateTaskMachineCore.job
[2013.07.01 14:06:51 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2013.07.01 14:06:48 | 3281,846,272 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.30 23:58:34 | 000,281,768 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.06.30 23:58:34 | 000,281,768 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.06.30 20:01:07 | 000,000,826 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013.06.30 19:27:10 | 000,000,000 | ---- | M] () -- C:\END
[2013.06.30 14:10:39 | 000,867,240 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013.06.30 14:10:39 | 000,789,416 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2013.06.30 14:10:39 | 000,263,592 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013.06.30 14:10:39 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013.06.30 14:10:39 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013.06.30 14:10:39 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.06.29 20:44:44 | 000,005,120 | ---- | M] () -- C:\Users\ahmet\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.06.29 19:01:24 | 000,281,768 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.06.26 16:00:44 | 000,001,172 | ---- | M] () -- C:\Users\Public\Desktop\Camtasia Studio 8.lnk
[2013.06.26 15:09:01 | 000,001,509 | ---- | M] () -- C:\Users\ahmet\AppData\Local\recently-used.xbel
[2013.06.25 21:46:40 | 000,120,200 | ---- | M] () -- C:\Windows\SysWow64\DLLDEV32i.dll
[2013.06.25 20:32:24 | 000,001,194 | ---- | M] () -- C:\Users\ahmet\Desktop\aTube Catcher.lnk
[2013.06.23 16:25:57 | 000,004,542 | ---- | M] () -- C:\Users\ahmet\AppData\Roaming\CamStudio.cfg
[2013.06.23 16:25:57 | 000,000,408 | ---- | M] () -- C:\Users\ahmet\AppData\Roaming\CamShapes.ini
[2013.06.23 16:25:57 | 000,000,408 | ---- | M] () -- C:\Users\ahmet\AppData\Roaming\CamLayout.ini
[2013.06.23 16:25:57 | 000,000,096 | ---- | M] () -- C:\Users\ahmet\AppData\Roaming\Camdata.ini
[2013.06.20 23:06:11 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.06.20 17:29:05 | 000,001,206 | ---- | M] () -- C:\Users\Public\Desktop\Razer Game Booster.lnk
[2013.06.20 13:26:04 | 000,002,014 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk
[2013.06.20 13:26:04 | 000,002,014 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk
[2013.06.20 13:25:35 | 000,000,331 | ---- | M] () -- C:\Windows\game.ini
[2013.06.19 15:13:18 | 000,002,263 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013.06.15 21:30:45 | 000,000,000 | ---- | M] () -- C:\search.sqlite
[2013.06.15 21:30:45 | 000,000,000 | ---- | M] () -- C:\prefs.js
[2013.06.13 21:32:53 | 000,001,484 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2013.06.07 19:50:51 | 000,001,234 | ---- | M] () -- C:\Users\Public\Desktop\Ashampoo WinOptimizer 10.lnk
[2013.06.06 22:41:04 | 000,489,392 | ---- | M] (Ask Partner Network) -- C:\Users\ahmet\Documents\APNSetup.exe
[2013.06.05 00:09:22 | 000,693,112 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.06.05 00:09:22 | 000,078,200 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.06.03 18:54:47 | 000,000,017 | ---- | M] () -- C:\Users\ahmet\AppData\Local\resmon.resmoncfg
========== Files Created - No Company Name ==========
[2013.06.30 13:13:18 | 000,000,398 | ---- | C] () -- C:\Windows\tasks\LyricsArt Update.job
[2013.06.28 17:43:10 | 000,000,000 | ---- | C] () -- C:\END
[2013.06.26 16:10:26 | 000,005,120 | ---- | C] () -- C:\Users\ahmet\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.06.26 16:00:44 | 000,001,172 | ---- | C] () -- C:\Users\Public\Desktop\Camtasia Studio 8.lnk
[2013.06.26 15:09:01 | 000,001,509 | ---- | C] () -- C:\Users\ahmet\AppData\Local\recently-used.xbel
[2013.06.26 15:03:40 | 000,000,896 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
[2013.06.25 20:32:24 | 000,001,194 | ---- | C] () -- C:\Users\ahmet\Desktop\aTube Catcher.lnk
[2013.06.25 19:15:25 | 000,000,402 | ---- | C] () -- C:\Windows\tasks\FunkLyrics Update.job
[2013.06.23 15:48:25 | 000,004,542 | ---- | C] () -- C:\Users\ahmet\AppData\Roaming\CamStudio.cfg
[2013.06.23 15:48:25 | 000,000,408 | ---- | C] () -- C:\Users\ahmet\AppData\Roaming\CamShapes.ini
[2013.06.23 15:48:25 | 000,000,408 | ---- | C] () -- C:\Users\ahmet\AppData\Roaming\CamLayout.ini
[2013.06.23 15:48:25 | 000,000,096 | ---- | C] () -- C:\Users\ahmet\AppData\Roaming\Camdata.ini
[2013.06.20 23:10:35 | 000,281,768 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.06.20 17:27:53 | 000,001,206 | ---- | C] () -- C:\Users\Public\Desktop\Razer Game Booster.lnk
[2013.06.20 13:26:04 | 000,002,014 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk
[2013.06.20 13:26:04 | 000,002,014 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk
[2013.06.19 23:39:13 | 000,281,768 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.06.19 23:39:13 | 000,281,768 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.06.19 23:39:08 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.06.19 23:39:05 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini
[2013.06.19 15:13:18 | 000,002,263 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013.06.19 15:12:29 | 000,001,126 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.06.19 15:12:28 | 000,001,122 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.06.17 00:24:49 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.06.15 21:30:45 | 000,000,000 | ---- | C] () -- C:\search.sqlite
[2013.06.15 21:30:45 | 000,000,000 | ---- | C] () -- C:\prefs.js
[2013.06.14 18:15:22 | 000,000,922 | ---- | C] () -- C:\Windows\tasks\DealPlyLiveUpdateTaskMachineUA.job
[2013.06.14 18:15:20 | 000,000,918 | ---- | C] () -- C:\Windows\tasks\DealPlyLiveUpdateTaskMachineCore.job
[2013.06.14 18:15:04 | 000,000,308 | ---- | C] () -- C:\Windows\tasks\Dealply.job
[2013.06.07 19:50:51 | 000,001,234 | ---- | C] () -- C:\Users\Public\Desktop\Ashampoo WinOptimizer 10.lnk
[2013.06.03 18:54:47 | 000,000,017 | ---- | C] () -- C:\Users\ahmet\AppData\Local\resmon.resmoncfg
[2013.05.22 20:43:52 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2013.05.22 20:43:48 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2013.05.22 20:43:48 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013.05.22 20:43:48 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013.05.22 20:43:48 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013.05.21 23:15:37 | 000,001,484 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2012.11.15 05:57:43 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2012.10.29 06:17:03 | 000,272,928 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng600.bin
[2012.10.29 06:16:59 | 000,963,452 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng600.bin
[2012.10.29 06:16:59 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012.10.24 06:21:28 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2012.07.26 10:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2012.07.26 10:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2012.07.26 09:21:26 | 000,067,584 | -H-- | C] () -- C:\Windows\bootstat.dat
[2012.07.26 03:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2012.07.25 22:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2012.07.25 22:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2012.07.25 22:22:56 | 000,733,840 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng700.bin
[2012.07.25 22:22:56 | 000,492,340 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng700.bin
[2012.06.02 16:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2012.04.20 23:59:44 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
========== ZeroAccess Check ==========
[2013.06.19 23:40:35 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.03.06 08:31:28 | 019,758,592 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.03.06 07:03:37 | 017,561,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012.07.26 05:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012.07.26 05:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012.07.26 05:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report > --- --- ---
Extras.txt:OTL EXTRAS Logfile: Code:
OTL Extras logfile created on: 01.07.2013 14:18:19 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\ahmet\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16599)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,82 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 62,20% Memory free
9,55 Gb Paging File | 7,61 Gb Available in Paging File | 79,66% Paging File free
Paging file location(s): C:\pagefile.sys 5868 5868 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 441,95 Gb Total Space | 377,89 Gb Free Space | 85,50% Space Free | Partition Type: NTFS
Computer Name: WINDOWS8 | User Name: ahmet | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.reg [@ = regfile] -- regedit.exe "%1"
[HKEY_USERS\S-1-5-21-3745752851-2045490827-2738593552-1001\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [open] -- regedit.exe "%1"
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V"
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0361F9D9-FCD6-4FB1-A8FA-0CAF3133939F}" = rport=445 | protocol=6 | dir=out | app=system |
"{28AF6C0D-DD88-4EA1-93F4-7EC28A898AE8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{28C3C67E-FB02-4397-B9FE-9E3A37241172}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{382ED227-2FB7-4C38-AE1C-03ABC394387C}" = rport=138 | protocol=17 | dir=out | app=system |
"{3A6F018D-1024-4931-B6C2-21877137D154}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3B97140D-55DE-4E8C-A93D-68E6DEF47EA1}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{680D1D30-2CEE-4AC1-BDB0-F8025B07ADEC}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7813093F-A2C8-4224-BF6D-596F188CFEC1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{79EC5AE9-0099-4A35-B0C0-B598EE4E1691}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9C7542E5-4CAF-4FCB-B91D-8E74F79F39A5}" = rport=137 | protocol=17 | dir=out | app=system |
"{A4710A8E-EE72-44CD-9492-E54772400B50}" = lport=139 | protocol=6 | dir=in | app=system |
"{A7A1270F-D181-49DB-9B09-5B46F47C50FB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B8793A99-58B9-4AB7-AB69-67DF2164CD94}" = rport=10243 | protocol=6 | dir=out | app=system |
"{BA281A97-8262-40E6-AB7E-992F1CA103C1}" = lport=445 | protocol=6 | dir=in | app=system |
"{BBEF0F7A-3BAB-490C-8A2D-632EA9CE6D3E}" = rport=139 | protocol=6 | dir=out | app=system |
"{CF019D72-8969-4F4C-9446-CF0532B197B9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D13FB275-D0D2-44E6-9F1A-D34A97840528}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{DEBACEB9-96AB-4054-98FD-1657FFB4BFBC}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EB4DF53C-8DFB-41CE-A597-B3FC6184B3C7}" = lport=137 | protocol=17 | dir=in | app=system |
"{EEA9B931-1D6F-433F-AA82-7F6F8B933F81}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{F090B59A-C766-46F2-B017-80F2F56FB7B7}" = lport=138 | protocol=17 | dir=in | app=system |
"{F1529D3D-CE4A-4B9F-9BA5-A10F5825FF04}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\outlook.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0067D064-31E5-4517-919E-BA543E11D2E1}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{061C0D2F-9B68-46EE-94B3-8A260966F29C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{06C5B32C-DC99-4B0E-ABFE-EBD4EA11DCF4}" = dir=in | app=c:\program files (x86)\nti\acer backup manager\backupmanager.exe |
"{09B6C08A-7B43-4293-9C20-C628EA5CADFA}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe |
"{0DB6EE5B-10E3-403D-80F6-F44E903E9050}" = dir=out | name=social jogger |
"{121BDD1B-4CD0-46F6-A328-4A7621C3B3B7}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{1230895A-59FD-4DA9-9D70-75740EE8DF41}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\video\videoplayer.exe |
"{13F3525B-1B03-4542-A15C-D769794E6D7F}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe |
"{14A0649F-03BC-441B-AAAE-CC8D598D1A7E}" = dir=out | name=taptiles |
"{14AC652B-F1D9-414C-8737-9BFEB93561CD}" = dir=in | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{15E6C838-22C5-4B54-A5E1-F52719B7901D}" = dir=out | name=@{microsoft.zunevideo_1.3.59.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{1AF6263B-CD45-4D8E-9ED6-8B757F6ECF0B}" = dir=out | name=acer explorer |
"{1B9AD04B-C605-4F76-83B9-E382353A2671}" = protocol=6 | dir=out | app=system |
"{1C97B400-B0AA-42BA-AC90-8978AF8FB1E3}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{1FCF93CB-013B-4845-AA9F-2587C52D2DD1}" = dir=out | name=the treasures of montezuma 3 |
"{216BC2EC-4167-485E-802A-B1ABD20D3104}" = dir=out | name=wordament |
"{2AD87B43-B2E0-4D35-A2A3-AA16E8323C6D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{34AE4C9F-9578-4EBA-BA66-FEC3BB07BE5D}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe |
"{360E467C-605C-4077-862D-1E1D24547122}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{39398E48-85AE-46A1-9A3E-68F0258DDAF1}" = dir=out | name=kindle |
"{3BDE02D5-46D8-4D18-8D10-67C15AE1D2EB}" = dir=out | name=evernote touch |
"{3EFD7BA6-25D5-4790-9DC0-E1F2967452C4}" = dir=out | name=7digital music store |
"{44BF919A-108F-48C0-864C-3DECC5FFE60B}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{469D4E21-7826-4536-83DB-AA44BB2079C7}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{48C3894A-2C80-47F2-8925-E620DF28A6DE}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe |
"{4B554E79-6DD2-43F2-951A-F43FC927EF94}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe |
"{4B975AFC-4942-4BE6-ACF9-A7A212372D7D}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{4E15266A-345C-4EBC-BBBF-77660B073958}" = dir=out | name=microsoft mahjong |
"{4EBFD80E-B761-4956-B1D3-89BE8835519B}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{51EC8CB2-FFD7-430D-9012-F0D59FAB17DB}" = dir=out | name=weatherbug |
"{524304CC-7B4A-4DBD-B015-F42BCB0DEC1F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5463EF59-5EF0-4C62-972D-13BD3A95BE24}" = dir=out | name=@{microsoft.bingweather_2.0.0.288_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{550DECF7-6D07-459F-A050-23A4D7B22BFF}" = dir=in | app=c:\users\ahmet\appdata\local\microsoft\skydrive\skydrive.exe |
"{56F7F798-42AF-46A5-8800-2B7574F00427}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{57898F79-E578-429C-B932-4B3960168803}" = dir=in | name=evernote touch |
"{58183785-6B0A-4D18-97D6-62AAC496A598}" = dir=in | name=acer explorer |
"{5BDDA5F9-5D97-483D-B05A-98869B6CC41A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{5BFD587D-7D4E-453D-9058-A35E3CEC6828}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{65B40FAE-4289-4FA1-ACD4-B7D70670B286}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{6827EF7E-3349-44F9-AAC7-140B5992D6D7}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{68386042-F846-4FBA-AAC1-3CB4F5D4824B}" = dir=out | name=@{microsoft.bingfinance_2.0.0.275_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{68E7D49F-730C-4FF0-94AB-E6F64BC4F44B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6D8047D6-B50C-4204-BA54-4723ABEBFFE0}" = dir=out | name=@{microsoft.bingtravel_2.0.0.274_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{6E2301DE-C363-4FE2-B806-C6D225852DAD}" = dir=in | app=c:\program files (x86)\nti\acer backup manager\fileexplorer.exe |
"{709C5204-BDCA-4726-AE30-645C00E07096}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{71D9827A-32AA-4769-8A58-EA76768FBC66}" = dir=out | name=pinball fx2 |
"{74349ED7-3A1D-4E73-8716-3AA010CFAF42}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{74BB8609-5EC1-4FF6-B1D9-BD1F2FE59CC8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{77F17863-87AD-49A1-B317-EE02D176A752}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7B94EEBE-EC63-4837-8403-95EA292085B1}" = dir=out | name=skitch touch |
"{7C8F8454-AC0B-4B5B-9C53-A0E41F8C6083}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{850972EA-D5A1-46CB-8E8C-C65C3BAC765C}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{878CEBD2-6123-495E-B6E4-C9908F5E181E}" = dir=in | name=newsxpresso |
"{87C08719-88A0-4498-A9BE-96E22671E0E3}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{893B9F38-4979-45E1-9536-2A1361ACAD3A}" = dir=out | name=@{microsoft.bingnews_2.0.0.273_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{893EA72E-5E6D-47D0-BA4C-398AA594123B}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{8A7008BF-6974-4DD4-8694-E382BF05DCA7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8DA7DF21-4A08-4A12-AA25-AD1CCC195E9F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8FAD364A-BB08-4AB0-9F09-ADD78ED34AD8}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe |
"{95E282B7-44AA-45CB-9A4D-F8D00F40164F}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{97C7658D-2746-4B6A-B3A3-EFED8EBEB963}" = dir=in | name=pinball fx2 |
"{9BB18E18-CF49-4612-84B4-74ED970A26C7}" = dir=out | name=acer crystal eye |
"{9D2AE77F-1F44-4297-9C59-1C89BD5526D4}" = dir=out | name=microsoft solitaire collection |
"{A01F8104-FFB4-4B15-9ED5-7B9D29C34FC8}" = dir=in | app=c:\program files (x86)\nti\acer backup manager\ischedulesvc.exe |
"{A2719930-1044-4873-A1FE-338A5954672A}" = dir=out | name=adera |
"{A5546912-FA60-4D7C-9F85-47AB63BBCC04}" = dir=out | name=cut the rope |
"{A7F2B849-9A23-4A51-81F6-71A2D044C0DE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AA5CE555-56F5-48A0-9C9E-D1F7210EDD46}" = dir=out | name=shark dash |
"{AE1D334A-F2E9-4711-A393-C30F5E4D5E16}" = dir=out | name=@{microsoft.zunemusic_1.3.59.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{AE955DB4-F249-4142-AE02-F518D48B69D4}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe |
"{B23714E8-EE92-4572-BF73-36F3E160DF49}" = dir=out | name=@{microsoft.xboxlivegames_1.3.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{B75E4692-113D-4D88-925D-3FC7C2AA7AE6}" = dir=out | name=@{microsoft.bingsports_2.0.0.273_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{B8EBD0A8-CB84-4A11-A004-052FDD2DCA8C}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} |
"{BD8ED80F-6E47-42D9-B4A1-D0369EE52D22}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe |
"{C493547A-147B-4504-863D-436A9B8E9CD6}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{C8E3003E-9C1F-45C6-BD31-02FF324A6E76}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DAF41B66-68EA-49CD-A429-A94B0D047B36}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{DEFE4578-5323-414D-8CCB-C07633C48B1C}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E458B195-7DC7-4232-85A4-949500521114}" = dir=out | name=windows_ie_ac_001 |
"{E76AC7F1-97C3-4EA6-8FDD-9CB40FA23D4E}" = dir=out | name=newsxpresso |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{E7C1C31F-C0EE-488A-B89C-1E98E8D6EA17}" = dir=out | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{E7D50B7B-9AB3-4897-A51B-1B0224A49DF2}" = dir=out | name=@{microsoft.bingmaps_1.6.1528.2509_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{EA621D5A-2B46-4570-9CC5-B9994CB9AB4D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{EEBCA30E-84D5-4A12-9127-34B79C303383}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe |
"{F2084A9E-E74D-4699-BAD5-7095F86C560A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F50EDD20-5502-440F-BA12-EBAF27930EC3}" = dir=out | name=tunein radio |
"{F9CCD533-D70A-4387-84CB-2E1A43F09B3A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FFE88C82-AEF0-41BF-ACCB-872497FBAF58}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01011662-76A8-41E8-B1A8-4F8821570AC5}" = Advanced Archive Password Recovery
"{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = BrowserDefender
"{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros WiFi Driver Installation
"{2DA4F5D1-A94A-4F4F-A9B8-8EEC8DC87E2C}" = S4 League_EU
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{35DA427D-BB23-49B8-9AFD-CFFCFE3B708D}" = clear.fi SDK- Movie 2
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{39F15B50-A977-4CA6-B1C3-6A8724CDA025}" = MyWinLocker 4
"{3D9CB654-99AD-4301-89C6-0D12A790767C}" = Identity Card
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{4209F371-88D4-AB00-ED2B-D6520C84D9D5}_is1" = Ashampoo WinOptimizer 10 v.10.2.5
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.5
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{6D2BBE1D-E600-4695-BA37-0B0E605542CC}" = Office Addin
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer" = WildTangent Games App
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8AE2B7D4-2BAA-4B9D-A4F4-282D3D30F1D0}" = IObit Apps Toolbar v7.2
"{8F6F7194-0734-4CDA-8C04-6B766F2241A6}" = Camtasia Studio 8
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90150000-008C-0000-0000-0000000FF1CE}" = Office 15 Click-to-Run Extensibility Component
"{90150000-008C-0407-0000-0000000FF1CE}" = Office 15 Click-to-Run Localization Component
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}" = Backup Manager v4
"{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}" = AcerCloud
"{A694AF57-9891-4D62-824C-7E55A1361A14}" = eBay Worldwide
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B26438B4-BF51-49C3-9567-7F14A5E40CB9}" = Dolby Home Theater v4
"{B5AD89F2-03D3-4206-8487-018298007DD0}" = clear.fi Photo
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}" = AcerCloud Docs
"{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"{DE042823-C359-4B87-B66B-308057E8B6AF}" = Camtasia Studio 7
"{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso 6.5
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{E9AF1707-3F3A-49E2-8345-4F2D629D0876}" = clear.fi Media
"{EBA33CAD-E071-48d5-A168-FBA4EEB42E93}" = clear.fi SDK - Video 2
"{EE26E302-876A-48D9-9058-3129E5B99999}" = Live Updater
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"aTube Catcher" = aTube Catcher
"DealPly" = DealPly (remove only)
"delta" = Delta toolbar
"Delta Chrome Toolbar" = Delta Chrome Toolbar
"FunkLyrics@MNSTsoft.net" = FunkLyrics
"Google Chrome" = Google Chrome
"InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}" = Acer Backup Manager
"InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso 6.5
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"LManager" = Launch Manager
"LyricsArt@SternoC.co" = LyricsArt
"MAGIX_{A3A1D6DC-7CB4-4894-8E54-3A48493EF488}" = MAGIX Speed burnR (MSI)
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"MSC" = McAfee Internet Security Suite
"PricePeep" = PricePeep
"Razer Game Booster_is1" = Razer Game Booster
"SoftwareUpdater" = SoftwareUpdater
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"Wajam" = Wajam
"WildTangent wildgames Master Uninstall" = WildTangent Games
"WTA-41be6ab8-0adf-4421-a12d-c39d5d528ed4" = Zuma's Revenge
"WTA-5c0bb165-21b0-43ed-908b-96453764e8ec" = Delicious: Emily's True Love Premium Edition
"WTA-71e38d99-0e77-405b-8869-0688ab5471a4" = Governor of Poker 2 Premium Edition
"WTA-7513b0d7-91ed-4fcd-8ee0-439da2ac4de4" = Aloha TriPeaks
"WTA-78b9a4a7-34f0-436a-8fba-0ff9828bda2b" = Jewel Match 3
"WTA-8a7ffe38-22ec-4597-8c64-930b826c4b8a" = Penguins!
"WTA-8b74b8bf-ee5a-4fd7-99c0-ceeae06c3944" = John Deere Drive Green
"WTA-8bb11e0c-0940-4eff-ad22-d09ee156600c" = Tales of Lagoona
"WTA-a1ba48da-5d27-47d0-bf94-2dce2d78b74b" = Agatha Christie - Death on the Nile
"WTA-ad6a1696-cdad-459f-8ff8-43dc61ac2375" = Island Tribe
"WTA-bbbb1cd0-9aac-47dc-89f7-7b1f9ece5f8e" = Magic Academy
"WTA-d1991cd1-f201-4e3c-a345-60b99b562e05" = Bejeweled 3
"WTA-ee3f742e-76bb-4209-b9ce-eaaa678f96d4" = Polar Bowler
"WTA-f3852ed2-d4bf-4a05-a0c5-0fd9af786f68" = Plants vs. Zombies - Game of the Year
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-3745752851-2045490827-2738593552-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dealply" = Dealply
"MyFreeCodec" = MyFreeCodec
"SkyDriveSetup.exe" = Microsoft SkyDrive
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 26.06.2013 09:39:55 | Computer Name = Windows8 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: CamtasiaStudio.exe, Version: 7.0.1.106,
Zeitstempel: 0x4c72f2ec Name des fehlerhaften Moduls: CamtasiaStudio.exe, Version:
7.0.1.106, Zeitstempel: 0x4c72f2ec Ausnahmecode: 0xc0000005 Fehleroffset: 0x001429b5
ID
des fehlerhaften Prozesses: 0xca8 Startzeit der fehlerhaften Anwendung: 0x01ce7272912bf427
Pfad
der fehlerhaften Anwendung: C:\Program Files (x86)\TechSmith\Camtasia Studio 7\CamtasiaStudio.exe
Pfad
des fehlerhaften Moduls: C:\Program Files (x86)\TechSmith\Camtasia Studio 7\CamtasiaStudio.exe
Berichtskennung:
e297d32e-de65-11e2-bebc-7054d23e8554 Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error - 26.06.2013 09:40:07 | Computer Name = Windows8 | Source = MsiInstaller | ID = 11722
Description =
Error - 26.06.2013 10:20:03 | Computer Name = Windows8 | Source = .NET Runtime | ID = 1023
Description =
Error - 26.06.2013 10:20:04 | Computer Name = Windows8 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: CamtasiaStudio.exe, Version: 8.0.4.1060,
Zeitstempel: 0x50c57c2f Name des fehlerhaften Moduls: clr.dll, Version: 4.0.30319.18033,
Zeitstempel: 0x50b5a638 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002ade1 ID des fehlerhaften
Prozesses: 0xee4 Startzeit der fehlerhaften Anwendung: 0x01ce7276ad59cbaf Pfad der
fehlerhaften Anwendung: C:\Program Files (x86)\TechSmith\Camtasia Studio 8\CamtasiaStudio.exe
Pfad
des fehlerhaften Moduls: C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll Berichtskennung:
7e5be3f2-de6b-11e2-bebc-7054d23e8554 Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error - 26.06.2013 12:58:50 | Computer Name = Windows8 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: S4Client.exe, Version: 0.8.32.2091,
Zeitstempel: 0x51b69462 Name des fehlerhaften Moduls: S4Client.exe, Version: 0.8.32.2091,
Zeitstempel: 0x51b69462 Ausnahmecode: 0xc0000005 Fehleroffset: 0x009b7b26 ID des fehlerhaften
Prozesses: 0x10d8 Startzeit der fehlerhaften Anwendung: 0x01ce728e6d269c84 Pfad der
fehlerhaften Anwendung: C:\Program Files (x86)\alaplaya\S4League\S4Client.exe Pfad
des fehlerhaften Moduls: C:\Program Files (x86)\alaplaya\S4League\S4Client.exe Berichtskennung:
ac721277-de81-11e2-bebc-7054d23e8554 Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error - 26.06.2013 13:00:51 | Computer Name = Windows8 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: S4Client.exe, Version: 0.8.32.2091,
Zeitstempel: 0x51b69462 Name des fehlerhaften Moduls: S4Client.exe, Version: 0.8.32.2091,
Zeitstempel: 0x51b69462 Ausnahmecode: 0xc0000005 Fehleroffset: 0x009b7b26 ID des fehlerhaften
Prozesses: 0x15ac Startzeit der fehlerhaften Anwendung: 0x01ce728eb576689f Pfad der
fehlerhaften Anwendung: C:\Program Files (x86)\alaplaya\S4League\S4Client.exe Pfad
des fehlerhaften Moduls: C:\Program Files (x86)\alaplaya\S4League\S4Client.exe Berichtskennung:
f431e2cf-de81-11e2-bebc-7054d23e8554 Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error - 27.06.2013 10:23:57 | Computer Name = Windows8 | Source = ETDService | ID = 0
Description =
Error - 28.06.2013 09:13:36 | Computer Name = Windows8 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: S4Client.exe, Version: 0.8.32.2091,
Zeitstempel: 0x51b69462 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0,
Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x01cb804f ID des fehlerhaften
Prozesses: 0x1ac4 Startzeit der fehlerhaften Anwendung: 0x01ce74014ada06f3 Pfad der
fehlerhaften Anwendung: C:\Program Files (x86)\alaplaya\S4League\S4Client.exe Pfad
des fehlerhaften Moduls: unknown Berichtskennung: 8a0672a9-dff4-11e2-bebd-7054d23e8554
Vollständiger
Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket
ist:
Error - 28.06.2013 09:17:43 | Computer Name = Windows8 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: S4Client.exe, Version: 0.8.32.2091,
Zeitstempel: 0x51b69462 Name des fehlerhaften Moduls: S4Client.exe, Version: 0.8.32.2091,
Zeitstempel: 0x51b69462 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00ab80c5 ID des fehlerhaften
Prozesses: 0x1464 Startzeit der fehlerhaften Anwendung: 0x01ce7401dea9f29f Pfad der
fehlerhaften Anwendung: C:\Program Files (x86)\alaplaya\S4League\S4Client.exe Pfad
des fehlerhaften Moduls: C:\Program Files (x86)\alaplaya\S4League\S4Client.exe Berichtskennung:
1d723919-dff5-11e2-bebd-7054d23e8554 Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error - 28.06.2013 11:53:27 | Computer Name = Windows8 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iw3mp.exe, Version: 0.0.0.0, Zeitstempel:
0x4859a219 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel:
0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x27048fc5 ID des fehlerhaften Prozesses:
0x1b0c Startzeit der fehlerhaften Anwendung: 0x01ce74173b13fab3 Pfad der fehlerhaften
Anwendung: C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
Pfad
des fehlerhaften Moduls: unknown Berichtskennung: de674caa-e00a-11e2-bebd-7054d23e8554
Vollständiger
Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket
ist:
[ System Events ]
Error - 27.06.2013 13:51:35 | Computer Name = Windows8 | Source = DCOM | ID = 10016
Description =
Error - 27.06.2013 13:51:35 | Computer Name = Windows8 | Source = DCOM | ID = 10016
Description =
Error - 27.06.2013 13:51:35 | Computer Name = Windows8 | Source = DCOM | ID = 10016
Description =
Error - 27.06.2013 13:51:35 | Computer Name = Windows8 | Source = DCOM | ID = 10016
Description =
Error - 27.06.2013 13:51:35 | Computer Name = Windows8 | Source = DCOM | ID = 10016
Description =
Error - 27.06.2013 13:51:35 | Computer Name = Windows8 | Source = DCOM | ID = 10016
Description =
Error - 27.06.2013 13:51:35 | Computer Name = Windows8 | Source = DCOM | ID = 10016
Description =
Error - 27.06.2013 13:51:35 | Computer Name = Windows8 | Source = DCOM | ID = 10016
Description =
Error - 27.06.2013 13:51:36 | Computer Name = Windows8 | Source = DCOM | ID = 10016
Description =
Error - 27.06.2013 13:51:36 | Computer Name = Windows8 | Source = DCOM | ID = 10016
Description =
< End of report > --- --- --- |