Und hier die beiden Logdateien von OTL: Code:
OTL logfile created on: 15.01.2013 15:54:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Besitzer\Desktop\TrojanerBoard
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,28 Gb Available Physical Memory | 57,09% Memory free
8,00 Gb Paging File | 6,05 Gb Available in Paging File | 75,63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 186,21 Gb Total Space | 73,27 Gb Free Space | 39,35% Space Free | Partition Type: NTFS
Drive D: | 28,63 Gb Total Space | 28,40 Gb Free Space | 99,19% Space Free | Partition Type: NTFS
Computer Name: FLO | User Name: Besitzer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Besitzer\Desktop\TrojanerBoard\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\ROCCAT\Isku Keyboard\IskuMonitor.exe (ROCCAT GmbH)
PRC - C:\Users\Besitzer\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (AVM Berlin)
PRC - C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (AVM Berlin)
PRC - C:\Program Files (x86)\Logitech\G35\G35.exe (Logitech(c))
PRC - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY)
PRC - C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
PRC - C:\Program Files (x86)\FRITZ!DSL\StCenter.exe (AVM Berlin)
========== Modules (No Company Name) ==========
MOD - C:\Users\Besitzer\AppData\Local\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll ()
MOD - C:\Users\Besitzer\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\Besitzer\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll ()
MOD - C:\Users\Besitzer\AppData\Local\Google\Chrome\Application\23.0.1271.97\libglesv2.dll ()
MOD - C:\Users\Besitzer\AppData\Local\Google\Chrome\Application\23.0.1271.97\libegl.dll ()
MOD - C:\Users\Besitzer\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll ()
MOD - C:\Users\Besitzer\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll ()
MOD - C:\Users\Besitzer\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll ()
MOD - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\ROCCAT\Isku Keyboard\hiddriver.dll ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (Hamachi2Svc) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Akamai) -- c:\program files (x86)\common files\akamai/netsession_win_ce5ba24.dll ()
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Skype C2C Service) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (Futuremark SystemInfo Service) -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (OverwolfUpdaterService) -- C:\Program Files (x86)\Overwolf\\OverwolfUpdater.exe ()
SRV - (npggsvc) -- C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (WAS) -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (W3SVC) -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (AppHostSvc) -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV - (AVM WLAN Connection Service) -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (AVM Berlin)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ABBYY.Licensing.FineReader.Sprint.9.0) -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY)
SRV - (AVM IGD CTRL Service) -- C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (de_serv) -- C:\Program Files (x86)\Common Files\AVM\de_serv.exe (AVM Berlin)
========== Driver Services (SafeList) ==========
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (MotioninJoyXFilter) -- C:\Windows\SysNative\drivers\MijXfilt.sys (MotioninJoy)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (atksgt) -- C:\Windows\SysNative\drivers\atksgt.sys ()
DRV:64bit: - (lirsgt) -- C:\Windows\SysNative\drivers\lirsgt.sys ()
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (FWLANUSB) -- C:\Windows\SysNative\drivers\fwlanusb.sys (AVM GmbH)
DRV:64bit: - (avmeject) -- C:\Windows\SysNative\drivers\avmeject.sys (AVM Berlin)
DRV:64bit: - (LADF_SBVM) -- C:\Windows\SysNative\drivers\ladfSBVMamd64.sys (Logitech)
DRV:64bit: - (LADF_DHP2) -- C:\Windows\SysNative\drivers\ladfDHP2amd64.sys (Logitech)
DRV:64bit: - (NVNET) -- C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (xusb21) -- C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (WinRing0_1_2_0) -- C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys (OpenLibSys.org)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (NPPTNT2) -- C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = fritz.box;*.local;<local>
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = fritz.box;*.local;<local>
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://s22.sfgame.de/
IE - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8D C8 14 0A 57 6E CC 01 [binary data]
IE - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\..\URLSearchHook: {64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - No CLSID value found
IE - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\..\URLSearchHook: {7e111a5c-3d11-4f56-9463-5310c3c69025} - No CLSID value found
IE - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
========== FireFox ==========
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..extensions.enabledAddons: clickclean%40hotcleaner.com:4.0
FF - prefs.js..extensions.enabledAddons: %7BEEE6C361-6118-11DC-9C72-001320C79847%7D:1.9.0.0
FF - prefs.js..extensions.enabledAddons: bbrs_002%40blabbers.com:1.0.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Besitzer\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Besitzer\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Besitzer\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Besitzer\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Besitzer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.02.06 15:25:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.11 17:44:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012.05.27 10:58:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Besitzer\AppData\Roaming\mozilla\Extensions
[2011.12.26 21:23:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Besitzer\AppData\Roaming\mozilla\Firefox\extensions
[2011.12.26 21:23:40 | 000,000,000 | ---D | M] (BittorrentBar_DE Community Toolbar) -- C:\Users\Besitzer\AppData\Roaming\mozilla\Firefox\extensions\{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}
[2013.01.15 15:46:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Besitzer\AppData\Roaming\mozilla\Firefox\Profiles\myck6z23.default\extensions
[2012.06.04 14:06:20 | 000,000,000 | ---D | M] (Click&Clean) -- C:\Users\Besitzer\AppData\Roaming\mozilla\Firefox\Profiles\myck6z23.default\extensions\clickclean@hotcleaner.com
[2012.11.14 17:59:55 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Besitzer\AppData\Roaming\mozilla\Firefox\Profiles\myck6z23.default\extensions\ich@maltegoetz.de
[2013.01.07 20:19:22 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\Besitzer\AppData\Roaming\mozilla\firefox\profiles\myck6z23.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.01.11 17:44:21 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013.01.11 17:44:21 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) -- C:\USERS\BESITZER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MYCK6Z23.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}.XPI
File not found (No name found) -- C:\USERS\BESITZER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MYCK6Z23.DEFAULT\EXTENSIONS\BBRS_002@BLABBERS.COM
[2013.01.11 17:44:29 | 000,262,704 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.10.24 23:03:12 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.10.24 23:03:11 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.10.24 23:03:12 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.10.24 23:03:12 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.10.24 23:03:12 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.10.24 23:03:11 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - homepage: hxxp://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Besitzer\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Besitzer\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Besitzer\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Mixesoft Click&Clean Plug-In (Enabled) = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.9_0\plugin/npccch32.dll
CHR - plugin: Bitdefender QuickScan (Enabled) = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.9_0\plugin/npqscan.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Besitzer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - Extension: Click to activate/deactivate ProxTube = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.1.8_0\
CHR - Extension: Magic Actions for YouTube\u2122 = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif\5.7_0\
CHR - Extension: Angry Birds = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: TV = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh\1.0.11_0\
CHR - Extension: YouTube = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google-Suche = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Battlefield Play4Free = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.66.2_0\
CHR - Extension: Click&Clean = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\8.0.1_0\
CHR - Extension: AdBlock = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.55_0\
CHR - Extension: Cut the Rope = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkddaofiamhgfjmaccfcfpfolpgbeomj\14_0\
CHR - Extension: Battlefield Heroes = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdfjahpadlpfnfheehpddpcllihfkmm\5.0.127.0_0\
CHR - Extension: Don't Starve = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiledapehlkhdehbhppgmekfalnlfajc\1.0.0.37_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Deezer = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\npfkoakaabdallkcdbpkkhfilkkngakh\1.3.2_0\
CHR - Extension: NotScripts = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\odjhifogjcknibkahlpidmdajjpkkcfn\0.9.6_0\
CHR - Extension: Flow Free = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbnmelddedlommnmllmfhoephaidddmk\1.1_0\
CHR - Extension: Click&Clean App = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp\8.0_0\
CHR - Extension: Late Night = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgbdhkpacgdhfabeceekiafonfkipohm\1.0_0\
CHR - Extension: Google Mail = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: Click to activate/deactivate ProxTube = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.1.8_0\
CHR - Extension: Magic Actions for YouTube\u2122 = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif\5.7_0\
CHR - Extension: Angry Birds = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: TV = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh\1.0.11_0\
CHR - Extension: YouTube = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google-Suche = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Battlefield Play4Free = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.66.2_0\
CHR - Extension: Click&Clean = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\8.0.1_0\
CHR - Extension: AdBlock = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.55_0\
CHR - Extension: Cut the Rope = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkddaofiamhgfjmaccfcfpfolpgbeomj\14_0\
CHR - Extension: Battlefield Heroes = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdfjahpadlpfnfheehpddpcllihfkmm\5.0.127.0_0\
CHR - Extension: Don't Starve = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiledapehlkhdehbhppgmekfalnlfajc\1.0.0.37_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Deezer = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\npfkoakaabdallkcdbpkkhfilkkngakh\1.3.2_0\
CHR - Extension: NotScripts = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\odjhifogjcknibkahlpidmdajjpkkcfn\0.9.6_0\
CHR - Extension: Flow Free = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbnmelddedlommnmllmfhoephaidddmk\1.1_0\
CHR - Extension: Click&Clean App = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp\8.0_0\
CHR - Extension: Late Night = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgbdhkpacgdhfabeceekiafonfkipohm\1.0_0\
CHR - Extension: Google Mail = C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O4:64bit: - HKLM..\Run: [VIAAUD] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VIAAUD.exe File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVMWlanClient] C:\Program Files (x86)\avmwlanstick\wlangui.exe (AVM Berlin)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Logitech G35] C:\Program Files (x86)\Logitech\G35\G35.exe (Logitech(c))
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [RoccatIsku] C:\Program Files (x86)\ROCCAT\Isku Keyboard\IskuMonitor.EXE (ROCCAT GmbH)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000..\Run: [Akamai NetSession Interface] C:\Users\Besitzer\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000..\Run: [EPSON SX420W Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGCE.EXE /FU "C:\Windows\TEMP\E_S97E1.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O4 - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000..\Run: [PCSpeedUp] C:\Program Files (x86)\PC Beschleunigen\PCSpeedUp.lnk ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Startcenter.lnk = C:\Program Files (x86)\FRITZ!DSL\StCenter.exe (AVM Berlin)
O4 - Startup: C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech blank Produktregistrierung.lnk = C:\Program Files (x86)\Logitech\G35\eReg.exe (Leader Technologies/Logitech)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-1104156866-1664582838-3195057256-1000\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 10.0.0)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.122.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.5.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{99A39ED2-3BDC-4FC8-91F8-22F7AEDB5D9C}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A0978246-1DD7-46EC-8EFF-1F3DDB963A6D}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2d7fa468-dbac-11e0-8434-00040ec9a883}\Shell - "" = AutoRun
O33 - MountPoints2\{2d7fa468-dbac-11e0-8434-00040ec9a883}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{359e2645-da28-11e0-9b9b-002522718d17}\Shell - "" = AutoRun
O33 - MountPoints2\{359e2645-da28-11e0-9b9b-002522718d17}\Shell\AutoRun\command - "" = F:\pushinst.exe
O33 - MountPoints2\{e0507473-12a8-11e1-bc1b-00040ec9a883}\Shell - "" = AutoRun
O33 - MountPoints2\{e0507473-12a8-11e1-bc1b-00040ec9a883}\Shell\AutoRun\command - "" = H:\Setup.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\pushinst.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.01.14 22:14:34 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\Desktop\TrojanerBoard
[2013.01.13 18:34:07 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\Desktop\League of Legends Support Ticket
[2013.01.13 18:01:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.01.13 18:01:42 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.01.13 18:01:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.01.13 18:01:28 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\AppData\Local\Programs
[2013.01.11 18:21:25 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\Documents\BIS Core Engine
[2013.01.11 17:44:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.01.10 10:15:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2013.01.10 10:15:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2013.01.10 10:15:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2013.01.10 10:15:41 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\AppData\Local\Adobe
[2013.01.10 10:07:28 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\BestPractices
[2013.01.10 10:07:23 | 000,000,000 | ---D | C] -- C:\inetpub
[2013.01.10 10:07:23 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\BestPractices
[2013.01.08 17:21:52 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\AppData\Roaming\Leadertech
[2013.01.08 17:21:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
[2013.01.08 17:21:23 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
[2013.01.08 17:21:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Logitech
[2013.01.08 17:18:16 | 000,000,000 | ---D | C] -- C:\ProgramData\LogiShrd
[2012.12.30 16:49:48 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\Documents\LOLReplay
[2012.12.30 16:49:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LOLReplay
[2012.12.25 11:44:10 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\Desktop\Sounds
[2012.12.24 14:36:39 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\Desktop\LootAlert 1.0.6 Meine versuchung
[2012.12.24 14:00:49 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\Desktop\LootAlert 1.0.6
[2012.12.24 06:25:48 | 000,000,000 | ---D | C] -- C:\dev
[2012.12.24 06:24:42 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\AppData\Local\Neutrino_inc
[2012.12.24 06:17:01 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\AppData\Local\LootAlert
[2012.12.21 17:41:11 | 000,000,000 | ---D | C] -- C:\ProgramData\ROCCAT
[2012.12.21 17:40:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ROCCAT
[2012.12.21 17:40:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ROCCAT
[2012.12.21 17:38:51 | 000,000,000 | ---D | C] -- C:\Users\Besitzer\Desktop\ROCCAT_Isku_DRV1.20_FW1.25
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.01.15 15:55:12 | 000,028,720 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.01.15 15:55:12 | 000,028,720 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.01.15 15:53:02 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1104156866-1664582838-3195057256-1000UA.job
[2013.01.15 15:47:43 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.01.15 15:47:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.01.15 15:47:25 | 3220,676,608 | -HS- | M] () -- C:\hiberfil.sys
[2013.01.14 21:53:01 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1104156866-1664582838-3195057256-1000Core.job
[2013.01.14 21:38:00 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.01.14 21:16:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.01.13 18:01:43 | 000,001,117 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.01.11 14:17:51 | 000,001,189 | ---- | M] () -- C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech blank Produktregistrierung.lnk
[2013.01.10 10:09:07 | 001,845,894 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.01.10 10:09:07 | 000,799,698 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.01.10 10:09:07 | 000,729,622 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.01.10 10:09:07 | 000,184,932 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.01.10 10:09:07 | 000,151,028 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.01.10 10:08:48 | 001,750,180 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.01.09 21:27:11 | 000,697,864 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.01.09 21:27:11 | 000,074,248 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.01.07 15:40:23 | 000,001,414 | ---- | M] () -- C:\Users\Public\Desktop\DayZ Commander.lnk
[2012.12.30 16:49:34 | 000,001,909 | ---- | M] () -- C:\Users\Public\Desktop\LOL Recorder.lnk
[2012.12.23 00:07:34 | 000,000,108 | ---- | M] () -- C:\Users\Besitzer\Desktop\10Mash Up Germany - Meine Zeit (Die Young Gangnam... von trmlol.url
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.01.13 18:01:43 | 000,001,117 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.01.11 14:17:51 | 000,001,189 | ---- | C] () -- C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech blank Produktregistrierung.lnk
[2012.12.30 16:49:34 | 000,001,909 | ---- | C] () -- C:\Users\Public\Desktop\LOL Recorder.lnk
[2012.12.23 00:07:34 | 000,000,108 | ---- | C] () -- C:\Users\Besitzer\Desktop\10Mash Up Germany - Meine Zeit (Die Young Gangnam... von trmlol.url
[2012.04.01 02:47:32 | 000,000,000 | ---- | C] () -- C:\Windows\EEventManager.INI
[2012.03.26 13:11:48 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2011.12.08 15:23:42 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2011.10.01 12:53:53 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2011.09.22 16:37:32 | 000,007,600 | ---- | C] () -- C:\Users\Besitzer\AppData\Local\Resmon.ResmonCfg
[2011.09.11 09:42:34 | 000,281,120 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011.09.11 09:42:33 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011.09.09 15:04:11 | 001,750,180 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012.11.19 16:22:17 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\.minecraft
[2012.03.29 17:52:32 | 000,000,000 | RHSD | M] -- C:\Users\Besitzer\AppData\Roaming\.share
[2011.10.22 17:01:58 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\Azureus
[2012.07.13 20:36:35 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\Beat Hazard
[2012.09.09 00:47:47 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\BitTorrent
[2012.01.25 15:16:57 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\DAEMON Tools Lite
[2012.12.19 22:52:51 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\DVDVideoSoft
[2012.03.31 12:40:41 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\Epson
[2012.06.07 15:21:35 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\FOG Downloader
[2011.09.08 16:59:44 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\FRITZ!
[2013.01.08 17:21:52 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\Leadertech
[2011.09.25 13:11:33 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\LolClient
[2012.05.24 17:54:52 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\LolClient2
[2011.10.06 15:31:03 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\MoreTerra
[2012.07.26 16:36:30 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\MotioninJoy
[2011.09.08 20:21:10 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\Notepad++
[2012.03.07 15:49:05 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\OpenOffice.org
[2011.09.11 09:45:49 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\Opera
[2012.06.13 13:05:48 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\Product_RM
[2012.05.13 00:25:34 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\RotMG.Production
[2012.07.14 23:43:44 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\six-zsync
[2012.09.09 00:42:59 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\Software Informer
[2013.01.13 18:36:55 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\TS3Client
[2012.09.14 19:41:19 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\ts3overlay
[2012.09.04 11:27:50 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\TuneUp Software
[2012.03.18 13:54:40 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\Ubisoft
[2011.12.11 22:05:13 | 000,000,000 | ---D | M] -- C:\Users\Besitzer\AppData\Roaming\Unity
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:D1B5B4F1
< End of report > Code:
OTL Extras logfile created on: 15.01.2013 15:54:38 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Besitzer\Desktop\TrojanerBoard
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,28 Gb Available Physical Memory | 57,09% Memory free
8,00 Gb Paging File | 6,05 Gb Available in Paging File | 75,63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 186,21 Gb Total Space | 73,27 Gb Free Space | 39,35% Space Free | Partition Type: NTFS
Drive D: | 28,63 Gb Total Space | 28,40 Gb Free Space | 99,19% Space Free | Partition Type: NTFS
Computer Name: FLO | User Name: Besitzer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{050EF3DF-E05C-4997-9B0A-5DFF7611258D}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{A2D6DA2A-B583-4D96-8052-B106A066C3AF}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C7BA2987-13D3-4544-9568-744FBD4FEC9D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D07B82C5-F3A3-4732-8762-B36AAEA2150B}" = lport=49183 | protocol=6 | dir=in | name=akamai netsession interface |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01F8CB89-9925-4417-8CC1-399280B148E7}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe |
"{02864FC3-1144-4204-ACB6-64D8783182AE}" = protocol=17 | dir=in | app=d:\rom\rom\runes of magic\client.exe |
"{03473123-A1F1-4F80-B66B-4782D8E28943}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{03651E07-A13C-4C44-A267-8B1220AAAD7B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
"{0B521217-C22D-4DC3-A481-6711FB88E848}" = protocol=17 | dir=in | app=c:\users\besitzer\desktop\tesserver1.1\terrariaserver.exe |
"{10568D62-35C0-4F06-A47B-7EC3503F77AB}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{11D0B0AE-D34D-455E-B512-4D60BB506E09}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{12D1A474-7E5F-48E1-A9D6-8824E1053D5C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{13EC2B63-3E5C-4A7A-9105-AA4A921FA827}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"{162877C7-6743-430A-A313-665A48D40486}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{16A6CCC3-C30F-4161-B3E1-C0A8C5B3BF63}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{1727D057-C5EC-4DB7-8A57-0E0F315C9F30}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{17CE23D9-7733-417F-9F7E-5066AA132104}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{184849C3-1973-4027-9E64-36265FA6FD82}" = protocol=6 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |
"{1B1F85DF-3358-46E9-8092-04DD67657F74}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{1BFDEAB6-9E80-48F4-AE17-98CF92A2E9E0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{1E776AFD-B155-414D-8E4C-D29E3FD37176}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{22429BF1-D7C7-4E6D-B834-1DAB0C94CE61}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{229DA288-5C87-46F6-A0C2-15AE73E79F0F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{23DC21C0-BCAF-48E2-96C9-D2496C1AC86A}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{240C4278-A022-466E-8687-5B1EAF731907}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
"{25BC14F0-A321-4172-B868-027A57617244}" = protocol=6 | dir=in | app=c:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.0019_5fcfe8195e974fe8\launcher.exe |
"{28951A55-9D70-4E7B-9173-FE17EE49495F}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{29746B65-65AE-4D6B-87F7-74971E16D5D2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2CABD7E6-A4CD-4210-8F6F-074158BBEDE7}" = protocol=17 | dir=in | app=c:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.0019_5fcfe8195e974fe8\launcher.exe |
"{2DC56185-6422-4515-9E98-56591838C5D5}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{2F6D0CE4-B5E9-4F8A-A964-E442DF354CE9}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{32B0FD17-1B48-494D-9FF3-0DA66591EFF9}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{34221481-537B-42E3-B5BB-F16E58AD79E6}" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"{34DBDA55-F2DB-419C-B5BB-480B31032F9C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{37ECFBBA-0FEE-4FDD-A01E-74FCB66E9899}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{38AE461C-0957-42ED-99ED-30050F1A4AF3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |
"{3FA41E49-BD51-4613-8B37-E91622DB97EB}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{403E96EB-057D-4F67-A839-ACD81BFF8C59}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{41312D0B-7D99-4464-9306-F5C9BDF57E30}" = protocol=17 | dir=in | app=c:\users\besitzer\appdata\local\akamai\netsession_win.exe |
"{418B2B59-A14C-48FE-9AC5-74FE1F4FEBA8}" = protocol=17 | dir=in | app=c:\nexon\combat arms eu\nmservice.exe |
"{44993D2F-2B13-4B24-B671-C763FDC6B35D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{4535263F-A96B-441F-AD23-C3AC752BB410}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{4595081D-359C-4289-A6B4-098401ACE629}" = dir=out | app=%programfiles% (x86)\ubisoft\related designs\anno 2070\autopatcher.exe |
"{4893F081-4A96-48CC-B0AF-B2DFB22EF79E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{4A1EF54A-0C78-4AFD-809A-631767B53C5C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{4AA05F57-FBF9-42AD-8C66-E40B3202D060}" = protocol=6 | dir=in | app=c:\program files (x86)\valve\hl.exe |
"{4AC41558-D5A4-4BC4-8C6B-E13BCDBC9317}" = dir=out | app=%programfiles% (x86)\ubisoft\related designs\anno 2070\anno5.exe |
"{4BCF634F-4572-4D0E-A409-611C801940E7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |
"{4DEDA45F-CDE1-4141-BCCF-426A97857982}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe |
"{4E4BEF83-AFA3-453A-A9FE-076E77653062}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |
"{5170EB91-3CFA-4513-AB61-FD9E7B07D431}" = dir=out | app=%programfiles% (x86)\ubisoft\related designs\anno 2070\initengine.exe |
"{5371E77C-EAAB-48FD-8EC5-7A2BCC87C2A7}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{549F4F61-D366-498B-9B33-BD2112A16074}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{578E7819-432C-41F3-B36D-BF004E6014D2}" = protocol=17 | dir=in | app=d:\rom\runes_of_magic_4_0_8_2506_slim_eu.exe |
"{5946423A-BC0E-41C4-B444-136F1247D0C8}" = protocol=17 | dir=in | app=c:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.001a_e12ee8c4a80a8fe8\launcher.exe |
"{59D7BCE0-D1FD-4763-91AB-0759FB87A16D}" = protocol=58 | dir=in | app=system |
"{5B658B2F-176C-4816-8394-71C7167BF1E3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the binding of isaac\isaac.exe |
"{5CD2AC31-ABB2-47F5-A838-F025A83962E1}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{616DD15E-3C50-4626-B3DB-C378337AE3BD}" = protocol=6 | dir=in | app=d:\rom\runes_of_magic_4_0_8_2506_slim_eu.exe |
"{66B63B6B-D245-4545-9CE5-E2832B30AF2C}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
"{6CE6E906-84E9-4BB7-8685-73AA02AE2307}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd |
"{6DE11DF9-B92C-48C4-8EAA-59B9E7EBB430}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd |
"{6DF09CFD-84A7-42AA-8903-AD8216B5B95D}" = protocol=6 | dir=in | app=c:\users\besitzer\appdata\roaming\spotify\spotify.exe |
"{6FA538D2-1339-4038-8955-68C8F46A6B56}" = protocol=6 | dir=in | app=c:\ubisoft\gro\pdc-live\yeti_release.exe |
"{7010A1F0-3685-4ED3-BBE6-1F0810B86107}" = dir=in | app=d:\brickforce\bflauncher.exe |
"{73FFE5D1-40B3-48F3-9FD6-ABD92B5F02B3}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{787C7151-6BFE-4DE0-83BD-1F071F0812CD}" = protocol=6 | dir=in | app=c:\program files (x86)\six projects\six updater\tools\bin\rsync.exe |
"{7ACC5310-1BDB-47A8-B2F3-8BFAAFA59304}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1199\agent.exe |
"{7BF0805D-A667-4275-B520-B476ECD92D12}" = protocol=6 | dir=in | app=d:\rom\rom\runes of magic\client.exe |
"{7E9BB2F1-92A2-4FD7-9D0F-3CDADB61F044}" = protocol=17 | dir=in | app=c:\ubisoft\gro\pdc-live\yeti_release.exe |
"{7FABE24D-450C-48A3-A432-FC7E031A4418}" = dir=out | app=d:\ubisoft\related designs\anno 2070\anno5.exe |
"{804D5DDB-F8AC-4ED6-BDB6-84DF88ECF772}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe |
"{821DB28A-033D-4235-A99B-E4F47B06877B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{83D55E87-E121-4E86-918F-FB18ADCCC2F4}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{85370A7D-196C-4F45-8D3F-7CCA11EEAFD1}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
"{85CD7B7A-8D2B-4501-8BBC-F0CDABD59621}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{86ACF2D5-2D45-4D5B-B47A-E4B09B6A1533}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{8996FDC5-C59E-45C8-9EBC-EC90C918F376}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |
"{89E3B575-77CC-415E-9600-915982D11607}" = protocol=6 | dir=in | app=c:\users\besitzer\desktop\tesserver1.1\terrariaserver.exe |
"{8AF3BCC0-62A3-48B3-B38E-8CAFE73F135D}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{8B408FEA-0ACF-4330-B74B-EF124BF2972F}" = protocol=17 | dir=in | app=c:\program files (x86)\valve\hl.exe |
"{8B426642-3C31-4784-80C4-17E58AB5EEA6}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{911217AC-21C6-4C26-8D46-6FD4F6354C7F}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe |
"{933CB469-EE9A-4171-B9B3-FE5B1B3D5CFF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{94C630D5-65AA-4E1C-BB7F-0F64C08DD4C3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders demo\binaries\win32\dundefgame.exe |
"{96FB7D5B-2DE7-4BF4-B308-B507B07570CD}" = protocol=17 | dir=in | app=c:\users\besitzer\appdata\roaming\spotify\spotify.exe |
"{977204B6-D0E3-4CB9-A17A-7E52B98F3F4B}" = protocol=6 | dir=in | app=d:\assasin'screedbrotherhood\assassins creed brotherhood\acbsp.exe |
"{9A4645C7-556A-4D35-8F1C-AFA2AF960BBA}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"{9B2E2FF2-DAA3-49FE-B483-865B70B873F4}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{9D7E68AA-73F0-4E43-AD42-79B878A7BA9C}" = protocol=6 | dir=in | app=c:\program files (x86)\sony ericsson\sony ericsson media manager\mediamanager.exe |
"{9F3525F0-4868-4B55-88CF-4FD6D5CE9955}" = protocol=17 | dir=in | app=d:\assasin'screedbrotherhood\assassins creed brotherhood\acbsp.exe |
"{A0225EA3-DFDA-447E-8BA6-93AF687F53CC}" = protocol=6 | dir=in | app=c:\users\besitzer\appdata\local\temp\gw2.exe |
"{A053E5CB-76DA-4E03-B0FC-BC00784BC9E2}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{A0A875BB-5452-4576-8D94-09CB0AA28D28}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{A1B6E1F9-21CB-4C1F-8854-48CC9E138AE8}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{A4316B93-D0E3-43C4-8C13-5277DB31A5F7}" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"{A4F7F43B-7136-4825-A3FC-C916FE7955E8}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{A5E340F9-D580-4342-9B73-1FA9F8AB2CCE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"{A99100D2-866A-468C-B23C-697C1B88EC20}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{AB0263C5-3AA0-44D8-A84F-81DE4FFDD78D}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{AF331745-10B4-4C9D-87C8-78B357A364D3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders demo\binaries\win32\dundefgame.exe |
"{AFE9C156-302F-4D06-95D1-DA95551E07AD}" = dir=out | app=%programfiles% (x86)\ubisoft\related designs\anno 2070\awesomiumprocess.exe |
"{B192F951-C148-4933-A927-B7B9A7F95B99}" = protocol=6 | dir=in | app=c:\users\besitzer\guild wars 2\gw2.exe |
"{B4FA03A6-DE29-4FC0-AC77-3B171549E84D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{B8C5ACDB-CF72-4BA5-912A-B19944E2BEF6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe |
"{B997C918-1126-4357-8612-4E95256BFEDF}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{BBE82C00-ACB0-4529-8CE7-460B052C7D2A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{BCCB2C6F-8D7C-4CFF-803B-FDF42029A346}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"{C123E766-BFDE-4CED-BB3C-B676A83E4E35}" = protocol=6 | dir=in | app=c:\nexon\combat arms eu\engine.exe |
"{C188A46E-251A-4D26-A47E-954366247F11}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{C4E9AE67-BA62-4086-87AB-A76A9A994031}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{C5D435F8-C9B1-4794-BF6A-526F39D097F1}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"{C6AA0DE1-5E4C-4A5F-A7F9-7235D534DADC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{C6FFAED2-57AE-4368-BFDB-2D4F7ABECD32}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the binding of isaac\isaac.exe |
"{CA82C701-5DC7-4173-A414-FFDD06B78A07}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{CC368E9F-9947-4338-B10C-4BC1A0343159}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{CC537AC2-AF94-40B2-A85F-3F8D28C42215}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{CCC67F36-B4EA-46E9-83F5-1DCFE8D1C72B}" = protocol=6 | dir=in | app=c:\users\besitzer\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{D0FD572B-97B6-4867-9931-3CFB8CA62D6F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"{D6904E2C-19A2-42F3-BD36-AA34DB23F72B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe |
"{D6B64342-0935-463C-884A-820682543651}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{D8510332-4762-4931-A78B-B8FBD6E665E4}" = dir=out | app=%programfiles% (x86)\ubisoft\related designs\anno 2070\anno5.exe |
"{DAE53E74-DD18-42B9-A5CA-5A3AE53933C6}" = dir=out | app=%programfiles% (x86)\ubisoft\related designs\anno 2070\autopatcher.exe |
"{DE60DE09-5BFF-4607-9075-8A28182F1995}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{DF149FE1-D1DC-467F-9798-DCE37D6858E9}" = protocol=17 | dir=in | app=c:\nexon\combat arms eu\engine.exe |
"{DF2420F4-9D4A-4FA0-8BD2-8359E4B832D2}" = protocol=17 | dir=in | app=c:\users\besitzer\guild wars 2\gw2.exe |
"{E12D0839-D210-4CA8-A0D3-7902DE29E1B1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe |
"{E8C9394E-30EE-44C1-89F1-C6A8922A6CAF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{ECCD8B2B-8752-44E5-A700-85B0751AABD4}" = protocol=17 | dir=in | app=c:\users\besitzer\appdata\local\temp\gw2.exe |
"{ECDA7093-0A70-43DE-935A-AFB6BD429EB8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{EF3DDBF9-B759-4BAC-93A6-C2566086C74B}" = protocol=6 | dir=in | app=c:\users\besitzer\appdata\local\akamai\netsession_win.exe |
"{F141439B-087D-4CA3-9D84-DC8B30CF5556}" = protocol=17 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |
"{F2B85A2E-F6CB-441F-9E61-9716A4EF7919}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe |
"{F2F8C2AC-ECD4-414E-ABF0-9B7DCC98C730}" = protocol=17 | dir=in | app=c:\users\besitzer\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{F32EF293-7C82-403B-9B40-52E02D904BC9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{F335F56E-DA44-4E1E-B505-28F33FA5BAC8}" = protocol=6 | dir=in | app=c:\nexon\combat arms eu\nmservice.exe |
"{F436E3B3-5DF6-4FDD-A7A3-53C6C9160D76}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{F47A5ED1-DFF4-4926-97D0-4F0CCD5F9958}" = protocol=17 | dir=in | app=c:\program files (x86)\six projects\six updater\tools\bin\rsync.exe |
"{F50770E5-662A-439D-97D1-17BA7BDAB0B4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1199\agent.exe |
"{F5E94E06-3240-42DB-9BDB-242E2EE4398D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{F67FDB1E-B075-4375-ABE1-07C47AFB6110}" = protocol=6 | dir=in | app=c:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.001a_e12ee8c4a80a8fe8\launcher.exe |
"{F8085E7E-4235-47A0-A614-9BC03AED6F9D}" = dir=in | app=d:\brickforce\brickforce.exe |
"{F89F0E60-8FF8-4826-8E27-A07CB7A9ACB0}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{FC3D8981-B4D6-4F56-BED5-A1E97CEF53C7}" = protocol=17 | dir=in | app=c:\program files (x86)\sony ericsson\sony ericsson media manager\mediamanager.exe |
"TCP Query User{0957C0DC-B595-4853-951E-96E5BFDA3F0B}D:\assasin'screedbrotherhood\assassins creed brotherhood\acbsp.exe" = protocol=6 | dir=in | app=d:\assasin'screedbrotherhood\assassins creed brotherhood\acbsp.exe |
"TCP Query User{182FF3C7-7356-4D69-9105-F381C746F0AB}C:\users\besitzer\downloads\runes_of_magic_4_0_5_2467_eu_slim.exe" = protocol=6 | dir=in | app=c:\users\besitzer\downloads\runes_of_magic_4_0_5_2467_eu_slim.exe |
"TCP Query User{1B25BE73-A3EB-411A-9D45-7BE86BF36783}C:\program files (x86)\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mirc\mirc.exe |
"TCP Query User{1D329777-A26A-471D-AE02-D9E87E1879FC}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{28A6319E-5E65-482B-B32C-1E5ADEC580F3}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"TCP Query User{382A0352-12D6-488A-8055-D499B28399E7}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"TCP Query User{3C7DF3F8-D9C5-4FC7-8E63-4A9E126881C2}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |
"TCP Query User{4675F57B-FB2D-4E41-B5D0-E6C3A98FB14E}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe |
"TCP Query User{4D2EB836-FFCC-4810-9A71-0203DA869941}C:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"TCP Query User{5D23A988-F566-4739-9195-7DAB09363EF2}C:\users\besitzer\desktop\mw3\krak\iw5mp_server.exe" = protocol=6 | dir=in | app=c:\users\besitzer\desktop\mw3\krak\iw5mp_server.exe |
"TCP Query User{63A4DBB8-FF61-436F-B50A-1C6CD7E90070}C:\ubisoft\gro\pdc-live\yeti_release.exe" = protocol=6 | dir=in | app=c:\ubisoft\gro\pdc-live\yeti_release.exe |
"TCP Query User{6C16D04F-35ED-4263-8529-BF48D1BBFC2B}C:\ygopro\ygopro_vs.exe" = protocol=6 | dir=in | app=c:\ygopro\ygopro_vs.exe |
"TCP Query User{785289EA-B233-46BB-AB7F-B73C2007E18A}C:\program files (x86)\steam\steamapps\fonix171\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\fonix171\team fortress 2\hl2.exe |
"TCP Query User{7A9D1DE4-A661-4B26-8759-4FE43917BFB8}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{7E66C294-4D3B-44F4-A139-C59C17B3CA24}C:\nexon\combat arms eu\engine.exe" = protocol=6 | dir=in | app=c:\nexon\combat arms eu\engine.exe |
"TCP Query User{7F0E3DB1-BCF3-4B93-B85B-E8187C620668}C:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe" = protocol=6 | dir=in | app=c:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe |
"TCP Query User{8E69382D-D3D4-446C-8F2A-4F7FE3BF1D7B}D:\rom\rom\runes of magic\client.exe" = protocol=6 | dir=in | app=d:\rom\rom\runes of magic\client.exe |
"TCP Query User{A827E739-B8AE-4BAA-9D13-D56F474A303A}C:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.001a_e12ee8c4a80a8fe8\launcher.exe" = protocol=6 | dir=in | app=c:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.001a_e12ee8c4a80a8fe8\launcher.exe |
"TCP Query User{A9FC4DAB-E1DD-4B5B-869D-21ADCC71ACAD}C:\program files (x86)\six projects\six updater\tools\bin\rsync.exe" = protocol=6 | dir=in | app=c:\program files (x86)\six projects\six updater\tools\bin\rsync.exe |
"TCP Query User{AF0E8B8F-6319-4021-B34E-8322CB8281FD}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"TCP Query User{B041F3F7-7E65-492F-8C98-7A7D87D432A8}C:\program files (x86)\valve\hl.exe" = protocol=6 | dir=in | app=c:\program files (x86)\valve\hl.exe |
"TCP Query User{C120E62E-9BC5-4BBE-84A2-C20B514035F0}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
"TCP Query User{C7A4D657-31B6-4822-8129-ECFD1A64D36E}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe |
"TCP Query User{C7E61FBF-0766-4FD2-B2A8-796D4A943ED3}D:\rom\runes_of_magic_4_0_8_2506_slim_eu.exe" = protocol=6 | dir=in | app=d:\rom\runes_of_magic_4_0_8_2506_slim_eu.exe |
"TCP Query User{D032FAA4-93C6-4959-AD17-80B13DE4CB95}C:\program files (x86)\fritz!dsl\fboxupd.exe" = protocol=6 | dir=in | app=c:\program files (x86)\fritz!dsl\fboxupd.exe |
"TCP Query User{D6F26465-E331-41A4-BCAF-B10FB17C8412}C:\users\besitzer\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\users\besitzer\guild wars 2\gw2.exe |
"TCP Query User{E685CF96-A6A9-4B59-8328-362119C269B9}C:\users\besitzer\appdata\local\temp\gw2.exe" = protocol=6 | dir=in | app=c:\users\besitzer\appdata\local\temp\gw2.exe |
"TCP Query User{E9B61A54-E918-4CA8-8D27-B0786241DBF1}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{EE74F671-A7AC-4935-A2E0-069947AEDB86}C:\users\besitzer\desktop\tesserver1.1\terrariaserver.exe" = protocol=6 | dir=in | app=c:\users\besitzer\desktop\tesserver1.1\terrariaserver.exe |
"TCP Query User{F05BFDAA-35EF-4DD2-85C2-1C0C879A7B69}C:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.0019_5fcfe8195e974fe8\launcher.exe" = protocol=6 | dir=in | app=c:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.0019_5fcfe8195e974fe8\launcher.exe |
"TCP Query User{F809CC81-1A4B-464A-A14B-45BE0F8A555F}D:\runesom\runes of magic\client.exe" = protocol=6 | dir=in | app=d:\runesom\runes of magic\client.exe |
"TCP Query User{FE73AFA5-EFD6-4FB7-9045-390B021BDB14}C:\program files (x86)\steam\steamapps\common\dungeon defenders demo\binaries\win32\dundefgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders demo\binaries\win32\dundefgame.exe |
"UDP Query User{022E16A8-7037-4749-8E8D-ABDB1D02BD16}C:\users\besitzer\desktop\mw3\krak\iw5mp_server.exe" = protocol=17 | dir=in | app=c:\users\besitzer\desktop\mw3\krak\iw5mp_server.exe |
"UDP Query User{0C6F3C02-6C34-45D6-8965-75A5D3E1C04F}C:\users\besitzer\desktop\tesserver1.1\terrariaserver.exe" = protocol=17 | dir=in | app=c:\users\besitzer\desktop\tesserver1.1\terrariaserver.exe |
"UDP Query User{0DBEDCD7-72DD-4ED5-957A-360594C4AAF1}C:\ubisoft\gro\pdc-live\yeti_release.exe" = protocol=17 | dir=in | app=c:\ubisoft\gro\pdc-live\yeti_release.exe |
"UDP Query User{12455CB5-E0ED-4253-8BA2-445443BE5A44}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{17DF0768-5617-4062-826A-B62B7A772D79}C:\program files (x86)\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mirc\mirc.exe |
"UDP Query User{1C3EB2E1-4C16-44CB-A689-BC3D3F8FFD8A}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"UDP Query User{2123417A-FE4A-4B58-824B-F25CB7444D98}D:\rom\runes_of_magic_4_0_8_2506_slim_eu.exe" = protocol=17 | dir=in | app=d:\rom\runes_of_magic_4_0_8_2506_slim_eu.exe |
"UDP Query User{23C77277-AE7E-48F1-92D9-C51345676521}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe |
"UDP Query User{2832DAA2-675B-410E-BC30-F9E062189E27}D:\runesom\runes of magic\client.exe" = protocol=17 | dir=in | app=d:\runesom\runes of magic\client.exe |
"UDP Query User{2B0DB03D-6D58-4E32-B5CF-1876B5699F89}C:\ygopro\ygopro_vs.exe" = protocol=17 | dir=in | app=c:\ygopro\ygopro_vs.exe |
"UDP Query User{2C1319C2-79F9-40E7-AEED-4ADA5B6B3C33}D:\rom\rom\runes of magic\client.exe" = protocol=17 | dir=in | app=d:\rom\rom\runes of magic\client.exe |
"UDP Query User{2C62DE7B-A9DF-4FFA-BD78-55B567C85D27}C:\program files (x86)\steam\steamapps\common\dungeon defenders demo\binaries\win32\dundefgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders demo\binaries\win32\dundefgame.exe |
"UDP Query User{3553D48C-744A-400D-B320-9D0431551A6F}C:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.001a_e12ee8c4a80a8fe8\launcher.exe" = protocol=17 | dir=in | app=c:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.001a_e12ee8c4a80a8fe8\launcher.exe |
"UDP Query User{3D043B19-2405-4CF1-8CC8-FE560FB51B59}C:\nexon\combat arms eu\engine.exe" = protocol=17 | dir=in | app=c:\nexon\combat arms eu\engine.exe |
"UDP Query User{4A32756D-8DF3-4507-B8BE-C911ECFAC0AE}C:\users\besitzer\downloads\runes_of_magic_4_0_5_2467_eu_slim.exe" = protocol=17 | dir=in | app=c:\users\besitzer\downloads\runes_of_magic_4_0_5_2467_eu_slim.exe |
"UDP Query User{4CC2194D-1579-46EE-B191-CFB579DED848}C:\program files (x86)\fritz!dsl\fboxupd.exe" = protocol=17 | dir=in | app=c:\program files (x86)\fritz!dsl\fboxupd.exe |
"UDP Query User{51B5B2C0-E215-4FA6-98C5-7B1E68C3D619}C:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe" = protocol=17 | dir=in | app=c:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe |
"UDP Query User{604B32E2-9B0A-4399-B143-B847ADF5ACDA}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{73CC187F-5298-4BD5-ADB2-B74174F86098}C:\program files (x86)\valve\hl.exe" = protocol=17 | dir=in | app=c:\program files (x86)\valve\hl.exe |
"UDP Query User{73D15C20-B873-474B-B6C7-CA75E9395AFF}D:\assasin'screedbrotherhood\assassins creed brotherhood\acbsp.exe" = protocol=17 | dir=in | app=d:\assasin'screedbrotherhood\assassins creed brotherhood\acbsp.exe |
"UDP Query User{7C5BA8B9-4668-406F-9B7F-6A58575E1D27}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"UDP Query User{83BD82C4-1C2F-4B14-94C3-0FC4D681D920}C:\program files (x86)\six projects\six updater\tools\bin\rsync.exe" = protocol=17 | dir=in | app=c:\program files (x86)\six projects\six updater\tools\bin\rsync.exe |
"UDP Query User{8C3C1305-BE34-48A3-AAC3-542B48B41A37}C:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"UDP Query User{9D44C21E-1561-4801-9506-19FF6373D772}C:\users\besitzer\appdata\local\temp\gw2.exe" = protocol=17 | dir=in | app=c:\users\besitzer\appdata\local\temp\gw2.exe |
"UDP Query User{AE3390DA-F242-483A-83BF-66932C2E793D}C:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.0019_5fcfe8195e974fe8\launcher.exe" = protocol=17 | dir=in | app=c:\users\besitzer\appdata\local\apps\2.0\t9yzyzxt.x50\3qt1xg0x.mql\laun...app_59711684aa47878d_0001.0019_5fcfe8195e974fe8\launcher.exe |
"UDP Query User{B098FADB-3C50-40A3-B23A-B699444D85F8}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe |
"UDP Query User{B27A6053-61A5-4204-B8F1-9ACA4D1ECCFF}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |
"UDP Query User{C7268D98-CB46-4F84-96F3-A3354B6BAF9D}C:\users\besitzer\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\users\besitzer\guild wars 2\gw2.exe |
"UDP Query User{D5375D92-9AB1-40D7-992E-A6781DF42B51}C:\program files (x86)\steam\steamapps\fonix171\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\fonix171\team fortress 2\hl2.exe |
"UDP Query User{D8CAB247-5FB9-4B7C-BCE4-7310695A0B35}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"UDP Query User{D9AD2340-54C2-4B92-B64A-B172AB31BE53}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{F2F70D96-39EA-4C1B-981F-C907F279FE4B}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{26A24AE4-039D-4CA4-87B4-2F86417000FF}" = Java(TM) 7 (64-bit)
"{27607A94-33AC-4AA7-AACE-95AF6ACA3E30}" = Logitech G35
"{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1" = MotioninJoy ds3 driver version 0.5.0002
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"EPSON SX420W Series" = EPSON SX420W Series Printer Uninstall
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"NVIDIA Drivers" = NVIDIA Drivers
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"WinRAR archiver" = WinRAR 4.01 (64-Bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}" = Epson Event Manager
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{106B4413-ACBB-4CDE-8707-587DB9BD77EC}" = LogMeIn Hamachi
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java(TM) 6 Update 29
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX
"{355CAC3F-0788-4117-B401-3CC4F8367E0A}" = Overwolf
"{39F58DDB-B2B8-4B86-AF20-4706A80EB30D}" = Epson Easy Photo Print 2
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{43D16DA8-BF42-3C62-89D3-3AD47829DC2E}" = Google Talk Plugin
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4ABAF918-A6BD-43D8-AE0B-5292034B14CB}" = ROCCAT Isku Keyboard Driver
"{59E4543A-D49D-4489-B445-473D763C79AF}" = Microsoft Games for Windows - LIVE Redistributable
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{730CFF48-E755-4B5B-994E-E29232DCF565}_is1" = YGOPro Version 1.02D
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7E910FDA-CBBE-4451-8728-235E6A4DE162}" = Sony Ericsson Media Manager 1.1
"{821018E8-68D9-42F0-84FF-C571876B5D33}" = DayZ Commander
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{88F0F4FF-B514-4E32-9C17-CAF96D60EAFC}" = Razer Game Booster
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95140000-00AF-0407-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C9D8A041-2963-4B31-8FFC-1500F3DB9293}" = EpsonNet Setup 3.2
"{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint
"ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AIDA64 Extreme Edition_is1" = AIDA64 Extreme Edition v1.85
"Akamai" = Akamai NetSession Interface Service
"AVMFBox" = AVM FRITZ!Box Dokumentation
"AVMFBoxPrinter" = AVM FRITZ!Box Druckeranschluss
"AVMWLANCLI" = AVM FRITZ!WLAN
"BattlEye for A2" = BattlEye Uninstall
"BattlEye for OA" = BattlEye for OA Uninstall
"Diablo III" = Diablo III
"DivX Setup" = DivX-Setup
"EPSON Scanner" = EPSON Scan
"EPSON SX420W Series Manual" = EPSON SX420W Series Handbuch
"EPSON SX420W Series Network Guide" = EPSON SX420W Series Netzwerk-Handbuch
"FRITZ!DSL" = AVM FRITZ!DSL
"Guild Wars 2" = Guild Wars 2
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Plattform-Geräte-Manager
"LogMeIn Hamachi" = LogMeIn Hamachi
"LOLReplay" = LOLReplay
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100
"MinecraftAlpha" = MinecraftAlpha
"Mozilla Firefox 18.0 (x86 de)" = Mozilla Firefox 18.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Notepad++" = Notepad++
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"PunkBusterSvc" = PunkBuster Services
"Steam App 113200" = The Binding of Isaac
"Steam App 202990" = Call of Duty: Black Ops II - Multiplayer
"Steam App 212910" = Call of Duty: Black Ops II - Zombies
"Steam App 33910" = ARMA 2
"Steam App 33930" = ARMA 2: Operation Arrowhead
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1104156866-1664582838-3195057256-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Google Chrome" = Google Chrome
"UnityWebPlayer" = Unity Web Player
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 13.08.2012 07:59:06 | Computer Name = Flo | Source = WinMgmt | ID = 10
Description =
Error - 13.08.2012 14:14:28 | Computer Name = Flo | Source = WinMgmt | ID = 10
Description =
Error - 14.08.2012 09:44:41 | Computer Name = Flo | Source = WinMgmt | ID = 10
Description =
Error - 14.08.2012 14:22:36 | Computer Name = Flo | Source = WinMgmt | ID = 10
Description =
Error - 15.08.2012 08:58:15 | Computer Name = Flo | Source = WinMgmt | ID = 10
Description =
Error - 15.08.2012 13:00:03 | Computer Name = Flo | Source = Windows Backup | ID = 4103
Description =
Error - 16.08.2012 09:45:17 | Computer Name = Flo | Source = WinMgmt | ID = 10
Description =
Error - 17.08.2012 07:31:19 | Computer Name = Flo | Source = WinMgmt | ID = 10
Description =
Error - 17.08.2012 13:51:27 | Computer Name = Flo | Source = WinMgmt | ID = 10
Description =
Error - 18.08.2012 09:03:43 | Computer Name = Flo | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 14.01.2013 08:40:28 | Computer Name = Flo | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden
Fehlers nicht gestartet: %%1069
Error - 14.01.2013 09:42:28 | Computer Name = Flo | Source = Service Control Manager | ID = 7023
Description = Der Dienst "AMD External Events Utility .NET." wurde mit folgendem
Fehler beendet: %%126
Error - 14.01.2013 09:44:52 | Computer Name = Flo | Source = Service Control Manager | ID = 7038
Description = Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser"
mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern
Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
Management Console (MMC).
Error - 14.01.2013 09:44:52 | Computer Name = Flo | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden
Fehlers nicht gestartet: %%1069
Error - 15.01.2013 10:39:14 | Computer Name = Flo | Source = Service Control Manager | ID = 7023
Description = Der Dienst "AMD External Events Utility .NET." wurde mit folgendem
Fehler beendet: %%126
Error - 15.01.2013 10:41:37 | Computer Name = Flo | Source = Service Control Manager | ID = 7038
Description = Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser"
mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern
Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
Management Console (MMC).
Error - 15.01.2013 10:41:37 | Computer Name = Flo | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden
Fehlers nicht gestartet: %%1069
Error - 15.01.2013 10:47:44 | Computer Name = Flo | Source = Service Control Manager | ID = 7023
Description = Der Dienst "AMD External Events Utility .NET." wurde mit folgendem
Fehler beendet: %%126
Error - 15.01.2013 10:50:04 | Computer Name = Flo | Source = Service Control Manager | ID = 7038
Description = Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser"
mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern
Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
Management Console (MMC).
Error - 15.01.2013 10:50:04 | Computer Name = Flo | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden
Fehlers nicht gestartet: %%1069
< End of report > |