Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Browser Highjacker (https://www.trojaner-board.de/132132-browser-highjacker.html)

Linschko 12.03.2013 17:53

Browser Highjacker
 
Also ich hab mir wie es scheint einige (viele) Browser Highjacker eingefangen. Darunter das gute alte monstermarketplace (+safersurf4free). Auf jeden Fall schickt mich das Virus nicht automatisch auf die Seite, sondern wenn ich nach etwas suche erscheint oben z.b. "looking for ......?" von monstermarketplace. Aber auch das nicht IMMER. :wtf: Und wenn ich speciel für Viren bezogene Sachen suche kommen seit 2 tagen auch avira, antivirus.fsecure und seit heute fake Norton und Kaspary seiten. Es gibt auch noch einige mehr :heulen: . Gott sei dank aber werden diese Gelb eingekastelt, so das ich weis das das Virus mich fehlleiten will. Mein problem ist aber, ich werde die Dinger einfach nicht mehr los. Ich benutze Chrome.
Norton findet nichts. (2013, im Laden gekauft und kompleter Systemscan)
Ich hab auch die schritte bei http://www.trojaner-board.de/129825-...anfaenger.html (sorry, aber irgendwie krieg ich keinen externen Link her) befolgt. Jetzt hab ich gelesen das man das nicht machen sollte, aber jetzt sind die Informationen die ich vorhin bei diesen ganzen Programmen erhalten habe weg....
Aber ich glaube ich weis wo einige Viren sind. Wenn ich auf meinen C:/ Ordner geh sind die ersten Ergebnis folgende Ordner;
C:\0ff57a5930f400f0c8d2cf7b33ce5a12
C:\1a7b77b06d99019d190e61
C:\1a7b77b06d99019d190e61 (mit mrtstub)
C:\8c39e961136a2721fbb77b5032
und C:\890281e2f5e911f3940d
Löschen hilft da nichts.
Ich denke das dass eigentliche Problem war das ich Norton während den Scanns an hatte...
Außerdem hab ich dieses "Malewarebites-Anti Maleware" Programm benutzt und drei Sachen löschen/isolieren lassen. Hab gelesen das man auch das nicht sollte.
Was soll ich jetzt machen? Kann man diese Drecksdinger noch irgendwie loswerden? Oder muss ich den PC neu aufsetzen? Ich denke nämlich das dass eigentliche Problem war das ich Norton während den Scanns an hatte... Könnte mir da bitte irgendwer helfen? Ich kenne mich nicht aus, und bin schon total am verzweifeln.


Ach ja, hier noch die logfiles vom ZWEITEN mal durchscannen;
ADWCleaner
Code:

# AdwCleaner v2.114 - Datei am 11/03/2013 um 18:47:14 erstellt
# Aktualisiert am 05/03/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Lino - LINOS-HP-SCHATZ
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Lino\Downloads\AdwCleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v8.0.7601.17514

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v [Version kann nicht ermittelt werden]

Datei : C:\Users\Lino\AppData\Roaming\Mozilla\Firefox\Profiles\jq11owgg.default\prefs.js

[OK] Die Datei ist sauber.

-\\ Google Chrome v25.0.1364.152

Datei : C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

-\\ Opera v [Version kann nicht ermittelt werden]

Datei : C:\Users\Lino\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] Die Datei ist sauber.

*************************

AdwCleaner[S1].txt - [1058 octets] - [11/03/2013 18:47:14]

########## EOF - C:\AdwCleaner[S1].txt - [1118 octets] ##########

Checkup
Code:

Results of screen317's Security Check version 0.99.61 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 8 Out of date!
``````````````Antivirus/Firewall Check:``````````````
Norton Internet Security 
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 Java(TM) 6 Update 22 
 Java(TM) 6 Update 31 
 Java 7 Update 9 
 Java version out of Date!
 Adobe Flash Player 11.6.602.171 
 Adobe Reader 10.1.6 Adobe Reader out of Date! 
 Google Chrome 25.0.1364.152 
 Google Chrome 25.0.1364.97 
````````Process Check: objlist.exe by Laurent```````` 
 Norton ccSvcHst.exe
 Symantec Norton Online Backup NOBuAgent.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````

attach
Code:

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 19.03.2011 19:22:54
System Uptime: 11.03.2013 18:57:20 (1 hours ago)
.
Motherboard: MSI |  | 2A9C
Processor: Intel(R) Core(TM) i7 CPU        870  @ 2.93GHz | CPU 1 | 2376/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 1384 GiB total, 805,294 GiB free.
D: is FIXED (NTFS) - 14 GiB total, 1,673 GiB free.
E: is CDROM (CDFS)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1504: 11.03.2013 17:54:57 - Ende der Bereinigung
RP1505: 11.03.2013 18:07:00 - Removed Java(TM) 7 (64-bit)
RP1506: 11.03.2013 18:08:29 - Removed Java(TM) 6 Update 31
RP1507: 11.03.2013 18:09:28 - Removed Java(TM) 6 Update 22
RP1508: 11.03.2013 18:10:28 - Removed Java 7 Update 9
RP1509: 11.03.2013 18:13:05 - Removed Skype™ 5.10
RP1510: 11.03.2013 18:15:37 - Konfiguriert Power2Go
RP1511: 11.03.2013 18:28:31 - Removed DisplayLink Core Software
RP1512: 11.03.2013 18:32:18 - Removed DisplayLink Core Software
RP1513: 11.03.2013 18:36:03 - Removed Skype™ 5.10
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Download Assistant
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Flash Professional CS6
Adobe Help Manager
Adobe Reader X (10.1.6) - Deutsch
Agatha Christie - Death on the Nile
Amnesia: The Dark Descent
aonFTP
aonUpdate
ARMA 2
Arma 2 Army of The Czech Republic (LITE) Uninstall
ARMA 2: British Armed Forces
ARMA 2: British Armed Forces - Data cache removal
ARMA 2: Operation Arrowhead
ARMA 2: Operation Arrowhead Beta
ARMA 2: Private Military Company
ARMA 2: Private Military Company - Data cache removal
µTorrent
AVS Screen Capture version 2.0.1
AVS Update Manager 1.0
AVS Video Editor 6
AVS Video Recorder 2.4
AVS4YOU Software Navigator 1.4
Battle Mages: Sign of Darkness
Battlefield 1918
Battlefield 1942
Battlefield 1942: Secret Weapons of WWII
Battlefield 2(TM)
Battlefield Heroes (Lino)
BattlEye (A2Free) Uninstall
BattlEye for OA Uninstall
Bejeweled 2 Deluxe
CDBurnerXP
Chivalry: Medieval Warfare
Chuzzle Deluxe
Controller
Corel Graphics - Windows Shell Extension
Corel Graphics - Windows Shell Extension 64 Bit
CorelDRAW Graphics Suite X6
CorelDRAW Graphics Suite X6 - Capture
CorelDRAW Graphics Suite X6 - Common
CorelDRAW Graphics Suite X6 - Connect
CorelDRAW Graphics Suite X6 - Custom Data
CorelDRAW Graphics Suite X6 - DE
CorelDRAW Graphics Suite X6 - Draw
CorelDRAW Graphics Suite X6 - Filters
CorelDRAW Graphics Suite X6 - FontNav
CorelDRAW Graphics Suite X6 - IPM
CorelDRAW Graphics Suite X6 - PHOTO-PAINT
CorelDRAW Graphics Suite X6 - Photozoom Plugin
CorelDRAW Graphics Suite X6 - Redist
CorelDRAW Graphics Suite X6 - Setup Files
CorelDRAW Graphics Suite X6 - VBA
CorelDRAW Graphics Suite X6 - VideoBrowser
CorelDRAW Graphics Suite X6 - VSTA
CorelDRAW Graphics Suite X6 - Writing Tools
Counter-Strike: Source
Creation Kit
CyberLink DVD Suite Deluxe
D3DX10
DayZ Commander
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
DesertCombat  0.7
Die Gilde 2 - Gold Edition
Die Schlacht um Mittelerde™ II
Die Sims™ 3
Die Sims™ 3 "Erstelle eine Welt"-Tool - Beta
Die Sims™ 3 Einfach tierisch
Die Sims™ 3 Erstelle ein Muster-Tool
Die Sims™ 3 Jahreszeiten
Die Sims™ 3 Late Night
Die Sims™ 3 Lebensfreude
Die Sims™ 3 Traumkarrieren
Diner Dash 2 Restaurant Rescue
DVD Menu Pack for HP MediaSmart Video
FATE
Fire Department
Flight Simulator X
Flight Simulator X Service Pack 1
Fraps (remove only)
Free YouTube Download version 3.1.42.1212
GameSpy Arcade
GIMP 2.8.4
Google Chrome
Google Update Helper
Grand Ages Rome 1.11
Grand Theft Auto IV
Grand Theft Auto San Andreas
Grand Theft Auto: Episodes from Liberty City
Half-Life 2
Half-Life 2: Episode One
Half-Life 2: Episode Two
Haunt 1.0 64bit
Hewlett-Packard ACLM.NET v1.2.1.1
Hi-Rez Studios Authenticate and Update Service
Highspeed-Internet-Installation
Hotfix für Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946040)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946308)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946344)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947540)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789)
HP Advisor
HP Customer Experience Enhancements
HP Game Console
HP Games
HP MediaSmart DVD
HP MediaSmart Music
HP MediaSmart Photo
HP MediaSmart SmartMenu
HP MediaSmart Video
HP Odometer
HP Setup
HP Support Assistant
HP Support Information
HP Update
HP Vision Hardware Diagnostics
Hunting Unlimited 2010
Imperium Romanum 1.04 Gold Edition
Insaniquarium Deluxe
Intel(R) Management Engine Components
Jewel Quest II
Jewel Quest Solitaire
John Deere Drive Green
Junk Mail filter update
Just Cause 2
LabelPrint
Left 4 Dead 2
LEGO® Star Wars™: Die Komplette Saga
LEGO® Star Wars™: The Complete Saga
LightScribe System Software
LIMBO
LIMBO Demo
Mafia
Mafia II
Magic Desktop
Mesh Runtime
Messenger Companion
Metro 2033
Microsoft .NET Framework 1.1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile DEU Language Pack
Microsoft .NET Framework 4 Extended
Microsoft .NET Framework 4 Extended DEU Language Pack
Microsoft Application Error Reporting
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170)
Microsoft Flight Simulator X
Microsoft Flight Simulator X: Acceleration
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2010
Microsoft Office Excel MUI (German) 2010
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2010
Microsoft Office Office 64-bit Components 2010
Microsoft Office OneNote MUI (German) 2010
Microsoft Office Outlook MUI (German) 2010
Microsoft Office PowerPoint MUI (German) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (German) 2010
Microsoft Office Proof (Italian) 2010
Microsoft Office Proofing (German) 2010
Microsoft Office Publisher MUI (German) 2010
Microsoft Office Shared 64-bit MUI (German) 2010
Microsoft Office Shared MUI (German) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (German) 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual Basic for Applications 7.1 (x86)
Microsoft Visual Basic for Applications 7.1 (x86) German
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Microsoft Visual Studio Tools for Applications 2.0 - ENU
Microsoft Visual Studio Tools for Applications 2.0 Language Pack - DEU
Microsoft Visual Studio Tools for Applications 2.0 Runtime
Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - DEU
Microsoft WSE 3.0 Runtime
Microsoft_VC80_CRT_x86
Microsoft_VC90_CRT_x86
Mirror's Edge™
Morrowind
Movie Theme Pack for HP MediaSmart Video
MSVCRT
MSVCRT Redists
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MyTools
NehrimUninstaller
Nexus Mod Manager
Norton Internet Security
Norton Online Backup
NVIDIA 3D Vision Controller-Treiber 306.97
NVIDIA 3D Vision Treiber 306.97
NVIDIA Display Control Panel
NVIDIA Grafiktreiber 306.97
NVIDIA HD-Audiotreiber 1.3.18.0
NVIDIA Install Application
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
NVIDIA Systemsteuerung 306.97
NVIDIA Update 1.10.8
NVIDIA Update Components
Oblivion
OpenAL
Origin
Pando Media Booster
PARANORMAL - BETA 4
PAYDAY: The Heist
PDF Complete Special Edition
PDF Settings CS6
Penguins!
Penumbra
PhotoNow!
PlanetSide 2
Plants vs. Zombies
Play withSIX
PlayReady PC Runtime amd64
Polar Bowler
POSTAL 2 Complete
Postal 2 Demo
Power2Go
PowerDirector
PunkBuster Services
Realtek High Definition Audio Driver
Recovery Manager
Red Orchestra 2: Heroes of Stalingrad
Republic at War - Deutsch 1.1
Republic at War 1.1
RollerCoaster Tycoon 3
S.T.A.L.K.E.R.: Shadow of Chernobyl
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition
Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition
Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition
Slingo Deluxe
SPORE™
Star Wars Empire at War
Star Wars Empire at War Forces of Corruption
Star Wars: Knights of the Old Republic
Steam
Stronghold 2 Deluxe
TeamSpeak 3 Client
TES Construction Set
The Elder Scrolls V: Skyrim
The Simpsons Hit & Run(TM)
The Ultimate DOOM
Thief: Deadly Shadows
Tropico 4 1.00
Universe Sandbox
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
Vegas Pro 10.0
Virtual Villagers - The Secret City
Wedding Dash
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Fotogalerie
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX control for remote connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinRAR 4.11 (64-Bit)
WinZip 16.0
Xfire (remove only)
Zuma Deluxe
.
==== End Of File ===========================

dds
Code:

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.7601.17514
Run by Lino at 19:07:07 on 2013-03-11
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.43.1031.18.12247.9822 [GMT 1:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
C:\Windows\system32\taskhost.exe
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Norton Internet Security\Engine\20.1.0.24\ccSvcHst.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
C:\Program Files (x86)\PDF Complete\pdfsvc.exe
C:\Windows\SysWOW64\PnkBstrA.exe
c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Norton Internet Security\Engine\20.1.0.24\ccSvcHst.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uWindow Title = A1 Telekom Austria TA AG
uSearch Page = hxxp://www.telekom.at/suche
mStart Page = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
uURLSearchHooks: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - <orphaned>
mWinlogon: Userinit = userinit.exe
BHO: {0931BD3F-547E-45C1-B133-D0E995645DBA} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.1.0.24\CoIEPlg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.1.0.24\IPS\IPSBHO.dll
BHO: Windows Live ID-Anmelde-Hilfsprogramm: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.1.0.24\CoIEPlg.dll
uRun: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
uRun: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Steam] "C:\Program Files (x86)\Stam\steam.exe" -silent
uRun: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
uRun: [AdobeBridge] <no file>
mRun: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
StartupFolder: C:\Users\Lino\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: EnableShellExecuteHooks = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: HideFastUserSwitching = dword:0
mPolicies-System: EnableSecureUIAPath = dword:1
IE: An OneNote s&enden - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Free YouTube Download - C:\Users\Lino\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Nach Microsoft E&xcel exportieren - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - <no file>
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.110.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} - hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.53.2.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
TCP: NameServer = 10.0.0.138
TCP: Interfaces\{7D5A217E-9DD0-4168-BBE9-01BEE99BA879} : DHCPNameServer = 10.0.0.138
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs=   
SSODL: WebCheck - <orphaned>
SEH: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} -
x64-Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
x64-Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 SMR210;Symantec SMR Utility Service 2.1.0;C:\Windows\System32\drivers\SMR210.SYS [2011-9-15 96376]
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1401000.018\SymDS64.sys [2013-3-10 493216]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1401000.018\SymEFA64.sys [2013-3-10 1132192]
R1 acedrv09;acedrv09;C:\Windows\System32\drivers\acedrv09.sys [2011-4-1 134880]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130301.001\BHDrvx64.sys [2013-3-1 1388120]
R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\System32\drivers\NISx64\1401000.018\ccSetx64.sys [2013-3-10 168096]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130308.001\IDSviA64.sys [2013-3-8 513184]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1401000.018\Ironx64.sys [2013-3-10 224416]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1401000.018\symnets.sys [2013-3-10 432800]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2012-7-15 8704]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\20.1.0.24\ccSvcHst.exe [2013-3-10 143928]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-2 2804568]
R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2010-11-17 635416]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-11-17 2320920]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-3-9 138912]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-11-17 56344]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2012-1-29 250984]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-1-29 413800]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 ezSharedSvc;Easybits Services for Windows; [x]
S3 BEService;BattlEye Service;C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2013-1-16 45056]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-5-29 48488]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-28 59392]
S3 WatAdminSvc;Windows-Aktivierungstechnologieservice;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-3-23 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2013-03-11 16:51:51        --------        d-----w-        C:\Windows\ERUNT
2013-03-11 15:53:41        --------        d-----w-        C:\Users\Lino\AppData\Local\{5C9DE9FB-2E16-422A-A4E7-ECA448DC5651}
2013-03-10 18:18:42        776352        ----a-r-        C:\Windows\System32\drivers\NISx64\1401000.018\srtsp64.sys
2013-03-10 18:18:42        493216        ----a-r-        C:\Windows\System32\drivers\NISx64\1401000.018\SymDS64.sys
2013-03-10 18:18:42        432800        ----a-r-        C:\Windows\System32\drivers\NISx64\1401000.018\symnets.sys
2013-03-10 18:18:42        37496        ----a-r-        C:\Windows\System32\drivers\NISx64\1401000.018\srtspx64.sys
2013-03-10 18:18:42        23448        ----a-r-        C:\Windows\System32\drivers\NISx64\1401000.018\SymELAM.sys
2013-03-10 18:18:42        1132192        ----a-r-        C:\Windows\System32\drivers\NISx64\1401000.018\SymEFA64.sys
2013-03-10 18:18:41        224416        ----a-r-        C:\Windows\System32\drivers\NISx64\1401000.018\Ironx64.sys
2013-03-10 18:18:41        168096        ----a-r-        C:\Windows\System32\drivers\NISx64\1401000.018\ccSetx64.sys
2013-03-10 18:18:09        --------        d-----w-        C:\Windows\System32\drivers\NISx64\1401000.018
2013-03-09 18:51:48        --------        d-----w-        C:\Users\Lino\AppData\Roaming\Canneverbe Limited
2013-03-09 18:51:48        --------        d-----w-        C:\ProgramData\Canneverbe Limited
2013-03-09 18:27:16        --------        d-----w-        C:\Users\Lino\AppData\Local\{B1DEADA7-E94A-441F-A68D-30173C3A784E}
2013-03-08 17:23:44        --------        d-----w-        C:\Windows\System32\MpEngineStore
2013-03-08 17:22:43        --------        d-----w-        C:\4c3afa1d91612de34882800ac3
2013-03-08 14:54:52        --------        d-----w-        C:\Program Files\Enigma Software Group
2013-03-08 12:30:44        --------        d-----w-        C:\Users\Lino\AppData\Local\{149EA161-2A33-4314-AC1B-81AAAF070AE0}
2013-03-07 14:12:18        --------        d-----w-        C:\Users\Lino\AppData\Local\{85C8BF14-428F-478E-8B3F-B52BD4F0C234}
2013-03-06 12:16:22        --------        d-----w-        C:\Users\Lino\AppData\Local\{7058F9E1-F903-4530-ADC5-75E11F447050}
2013-03-05 11:48:25        --------        d-----w-        C:\Users\Lino\AppData\Local\{B4D70CB2-ED6D-4140-9D98-72030A45CAB8}
2013-03-04 13:53:05        --------        d-----w-        C:\Users\Lino\AppData\Local\fontconfig
2013-03-04 13:53:04        --------        d-----w-        C:\Users\Lino\.gimp-2.8
2013-03-04 13:53:03        --------        d-----w-        C:\Users\Lino\AppData\Local\gegl-0.2
2013-03-04 13:52:05        --------        d-----w-        C:\Program Files\GIMP 2
2013-03-04 12:20:32        --------        d-----w-        C:\Users\Lino\AppData\Local\{66FF07BC-D205-4BA7-80C4-8B09FD86DBAD}
2013-03-03 15:38:40        --------        d-----w-        C:\Users\Lino\AppData\Roaming\SPORE
2013-03-03 15:26:38        --------        d-----w-        C:\Users\Lino\AppData\Local\{B76E4004-006B-4336-97B5-ABE7C24A223F}
2013-03-01 11:58:18        --------        d-----w-        C:\Users\Lino\AppData\Local\{24AFC32A-7E3D-4982-9D7C-0CA2B8E3DA84}
2013-02-28 20:38:58        --------        d-----w-        C:\ProgramData\Bohemia Interactive Studio
2013-02-28 16:53:47        --------        d-----w-        C:\Users\Lino\AppData\Local\{12A5F638-08D9-41F9-AA7D-2299FA91DE0F}
2013-02-27 14:52:14        --------        d-----w-        C:\Users\Lino\AppData\Local\{4864A5B0-9F3F-48A8-9A00-4B36A3C85D25}
2013-02-26 16:54:11        --------        d-----w-        C:\Users\Lino\AppData\Local\{8057300A-0F4D-45D2-A8E9-BB2449B0D05B}
2013-02-25 16:12:00        --------        d-----w-        C:\Users\Lino\AppData\Local\{E9C8E65D-CF1C-45CA-BAA8-E64510E48A45}
2013-02-22 06:24:18        --------        d-----w-        C:\Users\Lino\AppData\Local\{0D73410A-6760-4166-9895-F95A5208F285}
2013-02-21 06:25:29        --------        d-----w-        C:\Users\Lino\AppData\Local\{6CDEA75C-7CE4-49AC-A92D-F5E01D9BC959}
2013-02-20 12:02:23        --------        d-----w-        C:\Users\Lino\AppData\Local\{08F1B97E-2DC3-4B5C-9AF1-A44EF6D14213}
2013-02-20 06:20:26        --------        d-----w-        C:\Users\Lino\AppData\Local\{B6F1BCC8-7925-471A-AD88-DE5089BF3E93}
2013-02-19 16:36:33        --------        d-----w-        C:\Users\Lino\AppData\Local\Programs
2013-02-19 16:23:25        --------        d-----w-        C:\Users\Lino\AppData\Local\{C61C8DD9-2876-4C9C-A25C-E3240A5E268A}
2013-02-17 12:21:20        --------        d-----w-        C:\Users\Lino\AppData\Local\{423ECC5B-3AE2-4380-BC6D-59E9A025A3CA}
2013-02-14 20:07:01        --------        d-----w-        C:\Users\Lino\AppData\Local\{35943C4E-4601-49F1-A501-9FAA047F9721}
2013-02-14 11:48:39        --------        d-----w-        C:\Users\Lino\AppData\Local\{A1BDC52E-CF53-4A48-88B2-95AF06227116}
2013-02-13 11:55:48        7680        ----a-w-        C:\Windows\SysWow64\instnm.exe
2013-02-13 11:55:48        5120        ----a-w-        C:\Windows\SysWow64\wow32.dll
2013-02-13 11:55:48        25600        ----a-w-        C:\Windows\SysWow64\setup16.exe
2013-02-13 11:55:48        215040        ----a-w-        C:\Windows\System32\winsrv.dll
2013-02-13 11:55:48        2048        ----a-w-        C:\Windows\SysWow64\user.exe
2013-02-13 11:55:48        14336        ----a-w-        C:\Windows\SysWow64\ntvdm64.dll
2013-02-13 11:55:47        288088        ----a-w-        C:\Windows\System32\drivers\FWPKCLNT.SYS
2013-02-13 11:55:47        1913192        ----a-w-        C:\Windows\System32\drivers\tcpip.sys
2013-02-13 11:55:46        760320        ----a-w-        C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-13 11:55:46        1111040        ----a-w-        C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-13 11:43:39        --------        d-----w-        C:\Users\Lino\AppData\Local\{6D886194-3B14-481B-B0BA-A593A6625E37}
2013-02-12 11:06:22        --------        d-----w-        C:\Users\Lino\AppData\Local\{C7E06E8B-A378-432B-837F-5B126EC28CC2}
2013-02-10 12:13:22        --------        d-----w-        C:\Users\Lino\AppData\Local\{C1A5C915-7B6B-4889-AD27-9D3D924E673A}
.
==================== Find3M  ====================
.
2013-03-10 18:22:36        177312        ----a-w-        C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2013-02-27 20:45:09        71024        ----a-w-        C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-27 20:45:09        691568        ----a-w-        C:\Windows\SysWow64\FlashPlayerApp.exe
2013-02-24 11:02:35        280792        ----a-w-        C:\Windows\SysWow64\PnkBstrB.xtr
2013-02-24 11:02:35        280792        ----a-w-        C:\Windows\SysWow64\PnkBstrB.exe
2013-02-24 11:01:09        281032        ----a-w-        C:\Windows\SysWow64\PnkBstrB.ex0
2013-01-13 21:17:03        9728        ---ha-w-        C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 21:17:02        2560        ---ha-w-        C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 21:16:42        10752        ---ha-w-        C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 21:12:46        3584        ---ha-w-        C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 21:11:21        4096        ---ha-w-        C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 21:11:08        5632        ---ha-w-        C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 21:11:07        5632        ---ha-w-        C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 21:11:07        3072        ---ha-w-        C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 21:11:07        3072        ---ha-w-        C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:35:31        9728        ---ha-w-        C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 20:35:31        2560        ---ha-w-        C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 20:35:18        10752        ---ha-w-        C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 20:32:07        3584        ---ha-w-        C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 20:31:48        4096        ---ha-w-        C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 20:31:41        5632        ---ha-w-        C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 20:31:40        5632        ---ha-w-        C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 20:31:40        3072        ---ha-w-        C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 20:31:40        3072        ---ha-w-        C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:31:00        1247744        ----a-w-        C:\Windows\SysWow64\DWrite.dll
2013-01-13 20:22:22        1988096        ----a-w-        C:\Windows\SysWow64\d3d10warp.dll
2013-01-13 20:20:31        293376        ----a-w-        C:\Windows\SysWow64\dxgi.dll
2013-01-13 20:09:00        249856        ----a-w-        C:\Windows\SysWow64\d3d10_1core.dll
2013-01-13 20:08:43        220160        ----a-w-        C:\Windows\SysWow64\d3d10core.dll
2013-01-13 20:08:35        1504768        ----a-w-        C:\Windows\SysWow64\d3d11.dll
2013-01-13 19:59:04        1643520        ----a-w-        C:\Windows\System32\DWrite.dll
2013-01-13 19:58:28        1175552        ----a-w-        C:\Windows\System32\FntCache.dll
2013-01-13 19:54:01        604160        ----a-w-        C:\Windows\SysWow64\d3d10level9.dll
2013-01-13 19:53:58        207872        ----a-w-        C:\Windows\SysWow64\WindowsCodecsExt.dll
2013-01-13 19:53:14        187392        ----a-w-        C:\Windows\SysWow64\UIAnimation.dll
2013-01-13 19:51:30        2565120        ----a-w-        C:\Windows\System32\d3d10warp.dll
2013-01-13 19:49:17        363008        ----a-w-        C:\Windows\System32\dxgi.dll
2013-01-13 19:48:47        161792        ----a-w-        C:\Windows\SysWow64\d3d10_1.dll
2013-01-13 19:46:25        1080832        ----a-w-        C:\Windows\SysWow64\d3d10.dll
2013-01-13 19:43:21        1230336        ----a-w-        C:\Windows\SysWow64\WindowsCodecs.dll
2013-01-13 19:38:39        333312        ----a-w-        C:\Windows\System32\d3d10_1core.dll
2013-01-13 19:38:32        1887232        ----a-w-        C:\Windows\System32\d3d11.dll
2013-01-13 19:38:21        296960        ----a-w-        C:\Windows\System32\d3d10core.dll
2013-01-13 19:37:57        3419136        ----a-w-        C:\Windows\SysWow64\d2d1.dll
2013-01-13 19:25:04        245248        ----a-w-        C:\Windows\System32\WindowsCodecsExt.dll
2013-01-13 19:24:33        648192        ----a-w-        C:\Windows\System32\d3d10level9.dll
2013-01-13 19:24:30        221184        ----a-w-        C:\Windows\System32\UIAnimation.dll
2013-01-13 19:20:42        194560        ----a-w-        C:\Windows\System32\d3d10_1.dll
2013-01-13 19:20:04        1238528        ----a-w-        C:\Windows\System32\d3d10.dll
2013-01-13 19:15:40        1424384        ----a-w-        C:\Windows\System32\WindowsCodecs.dll
2013-01-13 19:10:36        3928064        ----a-w-        C:\Windows\System32\d2d1.dll
2013-01-13 19:02:06        417792        ----a-w-        C:\Windows\SysWow64\WMPhoto.dll
2013-01-13 18:34:58        364544        ----a-w-        C:\Windows\SysWow64\XpsGdiConverter.dll
2013-01-13 18:32:43        465920        ----a-w-        C:\Windows\System32\WMPhoto.dll
2013-01-13 18:09:52        522752        ----a-w-        C:\Windows\System32\XpsGdiConverter.dll
2013-01-13 17:26:42        1158144        ----a-w-        C:\Windows\SysWow64\XpsPrint.dll
2013-01-13 17:05:09        1682432        ----a-w-        C:\Windows\System32\XpsPrint.dll
2013-01-05 05:53:43        5553512        ----a-w-        C:\Windows\System32\ntoskrnl.exe
2013-01-05 05:00:15        3967848        ----a-w-        C:\Windows\SysWow64\ntkrnlpa.exe
2013-01-05 05:00:11        3913064        ----a-w-        C:\Windows\SysWow64\ntoskrnl.exe
2013-01-04 06:11:21        2284544        ----a-w-        C:\Windows\SysWow64\msmpeg2vdec.dll
2013-01-04 06:11:13        2776576        ----a-w-        C:\Windows\System32\msmpeg2vdec.dll
2013-01-04 04:43:21        44032        ----a-w-        C:\Windows\apppatch\acwow64.dll
2013-01-04 03:26:48        3153408        ----a-w-        C:\Windows\System32\win32k.sys
2012-12-20 13:59:36        1188864        ----a-w-        C:\Windows\System32\wininet.dll
2012-12-20 12:53:51        981504        ----a-w-        C:\Windows\SysWow64\wininet.dll
2012-12-20 12:02:26        1638912        ----a-w-        C:\Windows\System32\mshtml.tlb
2012-12-20 11:20:29        1638912        ----a-w-        C:\Windows\SysWow64\mshtml.tlb
2012-12-16 17:11:22        46080        ----a-w-        C:\Windows\System32\atmlib.dll
2012-12-16 14:45:03        367616        ----a-w-        C:\Windows\System32\atmfd.dll
2012-12-16 14:13:28        295424        ----a-w-        C:\Windows\SysWow64\atmfd.dll
2012-12-16 14:13:20        34304        ----a-w-        C:\Windows\SysWow64\atmlib.dll
.
============= FINISH: 19:08:56,11 ===============


cosinus 13.03.2013 13:38

Hallo und :hallo:

Zitat:

Außerdem hab ich dieses "Malewarebites-Anti Maleware" Programm benutzt und drei Sachen löschen/isolieren lassen.
Schön und wo sind die Logs dazu? :glaskugel:

Solche Angaben reichen nicht, bitte poste die vollständigen Angaben/Logs der Virenscanner siehe http://www.trojaner-board.de/125889-...tml#post941520


Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Linschko 15.03.2013 15:51

Hallo cosinus, und danke für die schnelle Antwort.
Entschuldige das die Antwort so lang gedauert hat.
Zu den CODE-Tags, ich hab doch CODE-Tags gepostet, oder zumindest genau das gemacht was dort angegeben wird. :balla:

So, ich hab jetzt Malewarebytes noch 2 mal nen Komplettscan machen lassen, bei beiden malen ist der PC in diesem Blauen Bildschirm abgestürtz.
Dann hab ich das alte log gefunden, also von meinem ersten mal durchscannen. Ein zweites mal gibt es nicht.

Code:

Malwarebytes Anti-Malware (Test) 1.70.0.1100
www.malwarebytes.org

Datenbank Version: v2013.03.11.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Lino :: LINOS-HP-SCHATZ [Administrator]

Schutz: Aktiviert

11.03.2013 19:16:27
mbam-log-2013-03-11 (19-16-27).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 270075
Laufzeit: 6 Minute(n), 1 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\AppID\{186E19A3-B909-4F48-B687-BB81EB8BC7CE} (Trojan.BHO) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 6
C:\Users\Lino\Downloads\installer_call_of_duty_black_ops (3).exe (PUP.BundleInstaller.BEN) -> Keine Aktion durchgeführt.
C:\Users\Lino\Downloads\installer_call_of_duty_black_ops.exe (PUP.BundleInstaller.BEN) -> Keine Aktion durchgeführt.
C:\Users\Lino\Downloads\ADLSoft_UnCompressor_v2.exe (PUP.Adware.InstallCore) -> Keine Aktion durchgeführt.
C:\Users\Lino\Downloads\installer_call_of_duty_black_ops (2).exe (PUP.BundleInstaller.BEN) -> Keine Aktion durchgeführt.
C:\Users\Lino\Downloads\DownloadSetup.exe (PUP.Offerware) -> Keine Aktion durchgeführt.
C:\Users\Lino\Downloads\installer_call_of_duty_black_ops (1).exe (PUP.BundleInstaller.BEN) -> Keine Aktion durchgeführt.

(Ende)

So, und hier hab ich noch mal Norton einen Kompletscann durchgehen lassen. 3 Cookies wurden entdeckt. Typischerweise waren genau diese drei Dinger nicht der Ursprung meines problems.

Code:

Scan-Informationen:
  Version der Virendefinitionen: 2013.03.14.004
  Sequ.-ID der Virendefinitionen: 142519

Scanstatistiken:
  Scanstart:
  Lokal: 14.03.2013 18:03
  UTC: 14.03.2013 17:03
  Scanzeit: 11.665 Sekunden
  Scanziele: Gesamter Computer
  Zähler:
Gescannte Elemente insgesamt: 1.292.655
– Dateien und Laufwerke: 1.285.910
– Registrierungseinträge: 780
– Prozesse und Elemente beim Start: 5.133
– Netzwerk- und Browser-Elemente: 822
– Sonstiges: 5
– Vertrauenswürdige Dateien: 0
– Übersprungene Dateien: 0

Erkannte Sicherheitsrisiken insgesamt: 3
Behobene Elemente insgesamt: 3
Elemente insgesamt, die Aufmerksamkeit erfordern: 0

Behobene Bedrohungen:
3 Tracking Cookies
 Typ: Anomalie
 Risiko: Gering (Gering Verbergen, Gering Entfernen, Gering Leistung, Gering Datenschutz) 
 Kategorien: Tracking Cookies
 Status: Vollständig behoben
 -----------
 3 Tracking Cookies
Cookie:lino@atdmt.com/ - Gelöscht
Cookie:lino@atdmt.com/ - Gelöscht
 - Gelöscht




Nicht behobene Bedrohungen:
Keine nicht behobenen Risiken

Das ist alles was ich noch habe.

Wenn du noch etwas brauchst, lass es mich bitte wissen.

cosinus 15.03.2013 17:24

Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
  • Lies dir meine Anleitungen, die ich im Laufe dieses Strangs hier posten werde, aufmerksam durch. Frag umgehend nach, wenn dir irgendetwas unklar sein sollte, bevor du anfängst meine Anleitungen umzusetzen.

  • Solltest du bei einem Schritt Probleme haben, stoppe dort und beschreib mir das Problem so gut du kannst. Manchmal erfordert ein Schritt den vorhergehenden.

  • Bitte nur Scans durchführen zu denen du von einem Helfer aufgefordert wurdest! Installiere / Deinstalliere keine Software ohne Aufforderung!

  • Poste die Logfiles direkt in deinen Thread (bitte in CODE-Tags) und nicht als Anhang, ausser du wurdest dazu aufgefordert. Logs in Anhängen erschweren mir das Auswerten!

  • Die Logs der aufgegebenen Tools wie zB Malwarebytes sind immer zu posten - egal ob ein Fund dabei war oder nicht!

  • Beachte bitte auch => Löschen von Logfiles und andere Anfragen

Note:
Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread.
Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards.


Rootkitscan mit GMER

Bitte lade dir GMER Rootkit Scanner GMER herunter: (Dateiname zufällig)
  • Schließe alle anderen Programme, deaktiviere deinen Virenscanner und trenne den Rechner vom Internet bevor du GMER startest.
  • Sollte sich nach dem Start ein Fenster mit folgender Warnung öffnen:
    WARNING !!!
    GMER has found system modification, which might have been caused by ROOTKIT activity.
    Do you want to fully scan your system ?
    Unbedingt auf "No" klicken.
  • Entferne rechts den Haken bei: IAT/EAT und Show All
  • Setze den Haken bei Quickscan und entferne ihn bei allen anderen Laufwerken.
  • Starte den Scan mit "Scan".
  • Mache nichts am Computer während der Scan läuft.
  • Wenn der Scan fertig ist klicke auf Save und speichere die Logfile unter Gmer.txt auf deinem Desktop. Mit "Ok" wird GMER beendet.
Antiviren-Programm und sonstige Scanner wieder einschalten, bevor Du ins Netz gehst!


Tauchen Probleme auf?
  • Probiere alternativ den abgesicherten Modus.
  • Erhältst du einen Bluescreen, dann entferne den Haken vor Devices.


Anschließend bitte MBAR ausführen:

Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Linschko 16.03.2013 16:44

Ok, das mit dem GMAR scan hab ich jetzt gemacht.

Code:

GMER 2.1.19155 - hxxp://www.gmer.net
Rootkit scan 2013-03-16 12:38:54
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD15 rev.01.0 1397,27GB
Running: tgmdu7dm.exe; Driver: C:\Users\Lino\AppData\Local\Temp\pxairfob.sys


---- Kernel code sections - GMER 2.1 ----

.text  C:\Windows\system32\drivers\USBPORT.SYS!DllUnload                                                                                                              fffff88005228d64 12 bytes {MOV RAX, 0xfffffa800e1fb2a0; JMP RAX}

---- User code sections - GMER 2.1 ----

.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                      000000007786fc90 5 bytes JMP 00000001001c091c
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                    000000007786fdf4 5 bytes JMP 00000001001c0048
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                            000000007786fe88 5 bytes JMP 00000001001c02ee
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                          000000007786ffe4 5 bytes JMP 00000001001c04b2
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                  0000000077870018 5 bytes JMP 00000001001c09fe
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                          0000000077870048 5 bytes JMP 00000001001c0ae0
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                      0000000077870064 5 bytes JMP 000000010002004c
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                          000000007787077c 5 bytes JMP 00000001001c012a
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                              000000007787086c 5 bytes JMP 00000001001c0758
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                        0000000077870884 5 bytes JMP 00000001001c0676
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                            0000000077870dd4 5 bytes JMP 00000001001c03d0
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                      0000000077871900 5 bytes JMP 00000001001c0594
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                  0000000077871bc4 5 bytes JMP 00000001001c083a
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                        0000000077871d50 5 bytes JMP 00000001001c020c
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                        000000007696524f 7 bytes JMP 00000001001c0f52
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                            00000000769653d0 7 bytes JMP 00000001001d0210
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                          0000000076965677 1 byte JMP 00000001001d0048
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                          0000000076965679 5 bytes {JMP 0xffffffff8986a9d1}
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                  000000007696589a 7 bytes JMP 00000001001c0ca6
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                  0000000076965a1d 7 bytes JMP 00000001001d03d8
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                            0000000076965c9b 7 bytes JMP 00000001001d012c
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                              0000000076965d87 7 bytes JMP 00000001001d02f4
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123              0000000076967240 7 bytes JMP 00000001001c0e6e
.text  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[964] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                            0000000075471492 7 bytes JMP 00000001001d04bc
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                            000000007786fc90 5 bytes JMP 00000001000e091c
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                          000000007786fdf4 5 bytes JMP 00000001000e0048
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                                  000000007786fe88 5 bytes JMP 00000001000e02ee
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                000000007786ffe4 5 bytes JMP 00000001000e04b2
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                        0000000077870018 5 bytes JMP 00000001000e09fe
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                                0000000077870048 5 bytes JMP 00000001000e0ae0
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                            0000000077870064 5 bytes JMP 000000010002004c
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                000000007787077c 5 bytes JMP 00000001000e012a
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                    000000007787086c 5 bytes JMP 00000001000e0758
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                              0000000077870884 5 bytes JMP 00000001000e0676
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                  0000000077870dd4 5 bytes JMP 00000001000e03d0
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                            0000000077871900 5 bytes JMP 00000001000e0594
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                        0000000077871bc4 5 bytes JMP 00000001000e083a
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                              0000000077871d50 5 bytes JMP 00000001000e020c
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                                  0000000075471492 7 bytes JMP 00000001000f059e
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                              000000007696524f 7 bytes JMP 00000001000e0f52
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                                  00000000769653d0 7 bytes JMP 00000001000f0210
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                                0000000076965677 1 byte JMP 00000001000f0048
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                                0000000076965679 5 bytes {JMP 0xffffffff8978a9d1}
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                        000000007696589a 7 bytes JMP 00000001000e0ca6
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                        0000000076965a1d 7 bytes JMP 00000001000f03d8
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                                  0000000076965c9b 7 bytes JMP 00000001000f012c
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                                    0000000076965d87 7 bytes JMP 00000001000f02f4
.text  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1916] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123                    0000000076967240 7 bytes JMP 00000001000e0e6e
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                              000000007786fc90 5 bytes JMP 000000010026091c
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                            000000007786fdf4 5 bytes JMP 0000000100260048
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                                    000000007786fe88 5 bytes JMP 00000001002602ee
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                  000000007786ffe4 5 bytes JMP 00000001002604b2
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                          0000000077870018 5 bytes JMP 00000001002609fe
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                                  0000000077870048 5 bytes JMP 0000000100260ae0
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                              0000000077870064 5 bytes JMP 000000010024004c
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                  000000007787077c 5 bytes JMP 000000010026012a
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                      000000007787086c 5 bytes JMP 0000000100260758
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                0000000077870884 5 bytes JMP 0000000100260676
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                    0000000077870dd4 5 bytes JMP 00000001002603d0
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                              0000000077871900 5 bytes JMP 0000000100260594
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                          0000000077871bc4 5 bytes JMP 000000010026083a
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                                0000000077871d50 5 bytes JMP 000000010026020c
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                                000000007696524f 7 bytes JMP 0000000100260f52
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                                    00000000769653d0 7 bytes JMP 00000001003c0210
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                                  0000000076965677 1 byte JMP 00000001003c0048
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                                  0000000076965679 5 bytes {JMP 0xffffffff89a5a9d1}
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                          000000007696589a 7 bytes JMP 0000000100260ca6
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                          0000000076965a1d 7 bytes JMP 00000001003c03d8
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                                    0000000076965c9b 7 bytes JMP 00000001003c012c
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                                      0000000076965d87 7 bytes JMP 00000001003c02f4
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123                      0000000076967240 7 bytes JMP 0000000100260e6e
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                                    0000000075471492 7 bytes JMP 00000001003c059e
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                      0000000076b71465 2 bytes [B7, 76]
.text  c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1236] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                      0000000076b714bb 2 bytes [B7, 76]
.text  ...                                                                                                                                                            * 2
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                          000000007786fc90 5 bytes JMP 000000010028091c
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                        000000007786fdf4 5 bytes JMP 0000000100280048
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                000000007786fe88 5 bytes JMP 00000001002802ee
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                              000000007786ffe4 5 bytes JMP 00000001002804b2
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                      0000000077870018 5 bytes JMP 00000001002809fe
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                              0000000077870048 5 bytes JMP 0000000100280ae0
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                          0000000077870064 5 bytes JMP 000000010002004c
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                              000000007787077c 5 bytes JMP 000000010028012a
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                  000000007787086c 5 bytes JMP 0000000100280758
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                            0000000077870884 5 bytes JMP 0000000100280676
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                0000000077870dd4 5 bytes JMP 00000001002803d0
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                          0000000077871900 5 bytes JMP 0000000100280594
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                      0000000077871bc4 5 bytes JMP 000000010028083a
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                            0000000077871d50 5 bytes JMP 000000010028020c
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206            000000007696524f 7 bytes JMP 0000000100280f52
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                00000000769653d0 7 bytes JMP 0000000100290210
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149              0000000076965677 1 byte JMP 0000000100290048
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151              0000000076965679 5 bytes {JMP 0xffffffff8992a9d1}
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                      000000007696589a 7 bytes JMP 0000000100280ca6
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                      0000000076965a1d 7 bytes JMP 00000001002903d8
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                0000000076965c9b 7 bytes JMP 000000010029012c
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                  0000000076965d87 7 bytes JMP 00000001002902f4
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123  0000000076967240 7 bytes JMP 0000000100280e6e
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                0000000075471492 7 bytes JMP 00000001002904bc
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                  0000000076b71465 2 bytes [B7, 76]
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[1376] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                  0000000076b714bb 2 bytes [B7, 76]
.text  ...                                                                                                                                                            * 2
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                    000000007786fc90 5 bytes JMP 00000001000f091c
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                  000000007786fdf4 5 bytes JMP 00000001000f0048
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                            000000007786fe88 5 bytes JMP 00000001000f02ee
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                        000000007786ffe4 5 bytes JMP 00000001000f04b2
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                0000000077870018 5 bytes JMP 00000001000f09fe
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                        0000000077870048 5 bytes JMP 00000001000f0ae0
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                      0000000077870064 5 bytes JMP 000000010009004c
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                        000000007787077c 5 bytes JMP 00000001000f012a
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                            000000007787086c 5 bytes JMP 00000001000f0758
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                      0000000077870884 5 bytes JMP 00000001000f0676
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                          0000000077870dd4 5 bytes JMP 00000001000f03d0
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                    0000000077871900 5 bytes JMP 00000001000f0594
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                0000000077871bc4 5 bytes JMP 00000001000f083a
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                        0000000077871d50 5 bytes JMP 00000001000f020c
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                            0000000075471492 7 bytes JMP 000000010010059e
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                      000000007696524f 7 bytes JMP 00000001000f0f52
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                          00000000769653d0 7 bytes JMP 0000000100100210
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                          0000000076965677 1 byte JMP 0000000100100048
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                          0000000076965679 5 bytes {JMP 0xffffffff8979a9d1}
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                000000007696589a 7 bytes JMP 00000001000f0ca6
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                0000000076965a1d 7 bytes JMP 00000001001003d8
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                            0000000076965c9b 7 bytes JMP 000000010010012c
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                              0000000076965d87 7 bytes JMP 00000001001002f4
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe[1436] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123            0000000076967240 7 bytes JMP 00000001000f0e6e
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                      000000007786fc90 5 bytes JMP 000000010017091c
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                    000000007786fdf4 5 bytes JMP 0000000100170048
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                              000000007786fe88 5 bytes JMP 00000001001702ee
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                          000000007786ffe4 5 bytes JMP 00000001001704b2
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                  0000000077870018 5 bytes JMP 00000001001709fe
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                          0000000077870048 5 bytes JMP 0000000100170ae0
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                        0000000077870064 5 bytes JMP 000000010015004c
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                          000000007787077c 5 bytes JMP 000000010017012a
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                              000000007787086c 5 bytes JMP 0000000100170758
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                        0000000077870884 5 bytes JMP 0000000100170676
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                            0000000077870dd4 5 bytes JMP 00000001001703d0
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                      0000000077871900 5 bytes JMP 0000000100170594
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                  0000000077871bc4 5 bytes JMP 000000010017083a
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                          0000000077871d50 5 bytes JMP 000000010017020c
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[1384] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                              0000000075471492 7 bytes JMP 000000010018059e
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                          000000007786fc90 5 bytes JMP 00000001004c091c
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                                        000000007786fdf4 5 bytes JMP 00000001004c0048
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                                                000000007786fe88 5 bytes JMP 00000001004c02ee
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                              000000007786ffe4 5 bytes JMP 00000001004c04b2
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                                      0000000077870018 5 bytes JMP 00000001004c09fe
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                                              0000000077870048 5 bytes JMP 00000001004c0ae0
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                          0000000077870064 5 bytes JMP 000000010002004c
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                              000000007787077c 5 bytes JMP 00000001004c012a
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                  000000007787086c 5 bytes JMP 00000001004c0758
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                            0000000077870884 5 bytes JMP 00000001004c0676
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                0000000077870dd4 5 bytes JMP 00000001004c03d0
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                                          0000000077871900 5 bytes JMP 00000001004c0594
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                      0000000077871bc4 5 bytes JMP 00000001004c083a
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                                            0000000077871d50 5 bytes JMP 00000001004c020c
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\syswow64\user32.dll!RecordShutdownReason + 882                                                0000000075471492 7 bytes JMP 00000001004d059e
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                                            000000007696524f 7 bytes JMP 00000001004c0f52
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                                                00000000769653d0 7 bytes JMP 00000001004d0210
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                                              0000000076965677 1 byte JMP 00000001004d0048
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                                              0000000076965679 5 bytes {JMP 0xffffffff89b6a9d1}
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                                      000000007696589a 7 bytes JMP 00000001004c0ca6
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                                      0000000076965a1d 7 bytes JMP 00000001004d03d8
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                                                0000000076965c9b 7 bytes JMP 00000001004d012c
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                                                  0000000076965d87 7 bytes JMP 00000001004d02f4
.text  C:\Program Files (x86)\PDF Complete\pdfsvc.exe[1928] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123                                  0000000076967240 7 bytes JMP 00000001004c0e6e
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                                        000000007786fc90 5 bytes JMP 000000010027091c
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                                                      000000007786fdf4 5 bytes JMP 0000000100270048
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                                                              000000007786fe88 5 bytes JMP 00000001002702ee
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                                            000000007786ffe4 5 bytes JMP 00000001002704b2
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                                                    0000000077870018 5 bytes JMP 00000001002709fe
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                                                            0000000077870048 5 bytes JMP 0000000100270ae0
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                                        0000000077870064 5 bytes JMP 000000010002004c
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                                            000000007787077c 5 bytes JMP 000000010027012a
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                                000000007787086c 5 bytes JMP 0000000100270758
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                                          0000000077870884 5 bytes JMP 0000000100270676
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                              0000000077870dd4 5 bytes JMP 00000001002703d0
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                                                        0000000077871900 5 bytes JMP 0000000100270594
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                                    0000000077871bc4 5 bytes JMP 000000010027083a
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                                                          0000000077871d50 5 bytes JMP 000000010027020c
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                                                              0000000075471492 7 bytes JMP 000000010028059e
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                                                          000000007696524f 7 bytes JMP 0000000100270f52
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                                                              00000000769653d0 7 bytes JMP 0000000100280210
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                                                            0000000076965677 1 byte JMP 0000000100280048
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                                                            0000000076965679 5 bytes {JMP 0xffffffff8991a9d1}
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                                                    000000007696589a 7 bytes JMP 0000000100270ca6
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                                                    0000000076965a1d 7 bytes JMP 00000001002803d8
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                                                              0000000076965c9b 7 bytes JMP 000000010028012c
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                                                                0000000076965d87 7 bytes JMP 00000001002802f4
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123                                                0000000076967240 7 bytes JMP 0000000100270e6e
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322                                                                        0000000071d91a22 2 bytes [D9, 71]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496                                                                        0000000071d91ad0 2 bytes [D9, 71]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552                                                                        0000000071d91b08 2 bytes [D9, 71]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730                                                                        0000000071d91bba 2 bytes [D9, 71]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762                                                                        0000000071d91bda 2 bytes [D9, 71]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                0000000076b71465 2 bytes [B7, 76]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                0000000076b714bb 2 bytes [B7, 76]
.text  ...                                                                                                                                                            * 2
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                          000000007786fc90 5 bytes JMP 000000010021091c
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                        000000007786fdf4 5 bytes JMP 0000000100210048
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                  000000007786fe88 5 bytes JMP 00000001002102ee
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                              000000007786ffe4 5 bytes JMP 00000001002104b2
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                      0000000077870018 5 bytes JMP 00000001002109fe
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                              0000000077870048 5 bytes JMP 0000000100210ae0
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                            0000000077870064 5 bytes JMP 000000010002004c
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                              000000007787077c 5 bytes JMP 000000010021012a
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                  000000007787086c 5 bytes JMP 0000000100210758
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                            0000000077870884 5 bytes JMP 0000000100210676
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                0000000077870dd4 5 bytes JMP 00000001002103d0
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                          0000000077871900 5 bytes JMP 0000000100210594
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                      0000000077871bc4 5 bytes JMP 000000010021083a
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                              0000000077871d50 5 bytes JMP 000000010021020c
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206            000000007696524f 7 bytes JMP 0000000100210f52
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                00000000769653d0 7 bytes JMP 00000001002a0210
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                0000000076965677 1 byte JMP 00000001002a0048
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                0000000076965679 5 bytes {JMP 0xffffffff8993a9d1}
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                      000000007696589a 7 bytes JMP 0000000100210ca6
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                      0000000076965a1d 7 bytes JMP 00000001002a03d8
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                  0000000076965c9b 7 bytes JMP 00000001002a012c
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                    0000000076965d87 7 bytes JMP 00000001002a02f4
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123  0000000076967240 7 bytes JMP 0000000100210e6e
.text  c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2116] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                  0000000075471492 7 bytes JMP 00000001002a04bc
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                          000000007786fc90 5 bytes JMP 000000010016091c
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                        000000007786fdf4 5 bytes JMP 0000000100160048
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                                  000000007786fe88 5 bytes JMP 00000001001602ee
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                              000000007786ffe4 5 bytes JMP 00000001001604b2
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                      0000000077870018 5 bytes JMP 00000001001609fe
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                              0000000077870048 5 bytes JMP 0000000100160ae0
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                            0000000077870064 5 bytes JMP 000000010014004c
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                              000000007787077c 5 bytes JMP 000000010016012a
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                  000000007787086c 5 bytes JMP 0000000100160758
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                            0000000077870884 5 bytes JMP 0000000100160676
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                0000000077870dd4 5 bytes JMP 00000001001603d0
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                          0000000077871900 5 bytes JMP 0000000100160594
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                      0000000077871bc4 5 bytes JMP 000000010016083a
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                              0000000077871d50 5 bytes JMP 000000010016020c
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                                  0000000075471492 7 bytes JMP 0000000100b0059e
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                            000000007696524f 7 bytes JMP 0000000100160f52
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                                00000000769653d0 7 bytes JMP 0000000100b00210
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                                0000000076965677 1 byte JMP 0000000100b00048
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                                0000000076965679 5 bytes {JMP 0xffffffff8a19a9d1}
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                      000000007696589a 7 bytes JMP 0000000100160ca6
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                      0000000076965a1d 7 bytes JMP 0000000100b003d8
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                                  0000000076965c9b 7 bytes JMP 0000000100b0012c
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                                    0000000076965d87 7 bytes JMP 0000000100b002f4
.text  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe[3744] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123                  0000000076967240 7 bytes JMP 0000000100160e6e
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                        000000007786fc90 5 bytes JMP 00000001001d091c
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                      000000007786fdf4 5 bytes JMP 00000001001d0048
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                                000000007786fe88 5 bytes JMP 00000001001d02ee
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                            000000007786ffe4 5 bytes JMP 00000001001d04b2
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                    0000000077870018 5 bytes JMP 00000001001d09fe
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                            0000000077870048 5 bytes JMP 00000001001d0ae0
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                          0000000077870064 5 bytes JMP 000000010002004c
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                            000000007787077c 5 bytes JMP 00000001001d012a
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                000000007787086c 5 bytes JMP 00000001001d0758
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                          0000000077870884 5 bytes JMP 00000001001d0676
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                              0000000077870dd4 5 bytes JMP 00000001001d03d0
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                        0000000077871900 5 bytes JMP 00000001001d0594
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                    0000000077871bc4 5 bytes JMP 00000001001d083a
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                            0000000077871d50 5 bytes JMP 00000001001d020c
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                                0000000075471492 7 bytes JMP 00000001001e04bc
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                          000000007696524f 7 bytes JMP 00000001001d0f52
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                              00000000769653d0 7 bytes JMP 00000001001e0210
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                              0000000076965677 1 byte JMP 00000001001e0048
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                              0000000076965679 5 bytes {JMP 0xffffffff8987a9d1}
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                    000000007696589a 7 bytes JMP 00000001001d0ca6
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                    0000000076965a1d 7 bytes JMP 00000001001e03d8
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                                0000000076965c9b 7 bytes JMP 00000001001e012c
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                                  0000000076965d87 7 bytes JMP 00000001001e02f4
.text  C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe[3108] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123                0000000076967240 7 bytes JMP 00000001001d0e6e
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                            000000007786fc90 5 bytes JMP 000000010010091c
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                          000000007786fdf4 5 bytes JMP 0000000100100048
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                                  000000007786fe88 5 bytes JMP 00000001001002ee
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                000000007786ffe4 5 bytes JMP 00000001001004b2
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                        0000000077870018 5 bytes JMP 00000001001009fe
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                                0000000077870048 5 bytes JMP 0000000100100ae0
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                            0000000077870064 5 bytes JMP 000000010002004c
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                000000007787077c 5 bytes JMP 000000010010012a
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                    000000007787086c 5 bytes JMP 0000000100100758
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                              0000000077870884 5 bytes JMP 0000000100100676
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                  0000000077870dd4 5 bytes JMP 00000001001003d0
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                            0000000077871900 5 bytes JMP 0000000100100594
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                        0000000077871bc4 5 bytes JMP 000000010010083a
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                              0000000077871d50 5 bytes JMP 000000010010020c
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                                  0000000075471492 7 bytes JMP 000000010011059e
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                              000000007696524f 7 bytes JMP 0000000100100f52
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                                  00000000769653d0 7 bytes JMP 0000000100110210
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                                0000000076965677 1 byte JMP 0000000100110048
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                                0000000076965679 5 bytes {JMP 0xffffffff897aa9d1}
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                        000000007696589a 7 bytes JMP 0000000100100ca6
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                        0000000076965a1d 7 bytes JMP 00000001001103d8
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                                  0000000076965c9b 7 bytes JMP 000000010011012c
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                                    0000000076965d87 7 bytes JMP 00000001001102f4
.text  C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe[2488] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123                    0000000076967240 7 bytes JMP 0000000100100e6e
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                                  000000007786fc90 5 bytes JMP 000000010014091c
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                                                000000007786fdf4 5 bytes JMP 0000000100140048
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                                                          000000007786fe88 5 bytes JMP 00000001001402ee
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                                      000000007786ffe4 5 bytes JMP 00000001001404b2
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                                              0000000077870018 5 bytes JMP 00000001001409fe
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                                                      0000000077870048 5 bytes JMP 0000000100140ae0
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                                    0000000077870064 5 bytes JMP 000000010002004c
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                                      000000007787077c 5 bytes JMP 000000010014012a
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                          000000007787086c 5 bytes JMP 0000000100140758
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                                    0000000077870884 5 bytes JMP 0000000100140676
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                        0000000077870dd4 5 bytes JMP 00000001001403d0
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                                                  0000000077871900 5 bytes JMP 0000000100140594
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                              0000000077871bc4 5 bytes JMP 000000010014083a
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                                                      0000000077871d50 5 bytes JMP 000000010014020c
.text  C:\Program Files (x86)\Stam\steam.exe[1068] C:\Windows\syswow64\KERNELBASE.dll!HeapCreate                                                                      000000007579549c 5 bytes JMP 0000000100210800
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                              000000007786fc90 5 bytes JMP 000000010028091c
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                            000000007786fdf4 5 bytes JMP 0000000100280048
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                                    000000007786fe88 5 bytes JMP 00000001002802ee
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                  000000007786ffe4 5 bytes JMP 00000001002804b2
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                          0000000077870018 5 bytes JMP 00000001002809fe
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                                  0000000077870048 5 bytes JMP 0000000100280ae0
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                              0000000077870064 5 bytes JMP 000000010002004c
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                  000000007787077c 5 bytes JMP 000000010028012a
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                      000000007787086c 5 bytes JMP 0000000100280758
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                0000000077870884 5 bytes JMP 0000000100280676
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                    0000000077870dd4 5 bytes JMP 00000001002803d0
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                              0000000077871900 5 bytes JMP 0000000100280594
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                          0000000077871bc4 5 bytes JMP 000000010028083a
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                                0000000077871d50 5 bytes JMP 000000010028020c
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                                    0000000075471492 7 bytes JMP 000000010029059e
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                                000000007696524f 7 bytes JMP 0000000100280f52
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                                    00000000769653d0 7 bytes JMP 0000000100290210
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                                  0000000076965677 1 byte JMP 0000000100290048
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                                  0000000076965679 5 bytes {JMP 0xffffffff8992a9d1}
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                          000000007696589a 7 bytes JMP 0000000100280ca6
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                          0000000076965a1d 7 bytes JMP 00000001002903d8
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                                    0000000076965c9b 7 bytes JMP 000000010029012c
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                                      0000000076965d87 7 bytes JMP 00000001002902f4
.text  C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe[2644] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123                      0000000076967240 7 bytes JMP 0000000100280e6e
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                              000000007786fc90 5 bytes JMP 000000010010091c
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                            000000007786fdf4 5 bytes JMP 0000000100100048
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                                    000000007786fe88 5 bytes JMP 00000001001002ee
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                  000000007786ffe4 5 bytes JMP 00000001001004b2
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                          0000000077870018 5 bytes JMP 00000001001009fe
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                                  0000000077870048 5 bytes JMP 0000000100100ae0
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                              0000000077870064 5 bytes JMP 000000010002004c
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                  000000007787077c 5 bytes JMP 000000010010012a
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                      000000007787086c 5 bytes JMP 0000000100100758
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                0000000077870884 5 bytes JMP 0000000100100676
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                    0000000077870dd4 5 bytes JMP 00000001001003d0
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                              0000000077871900 5 bytes JMP 0000000100100594
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                          0000000077871bc4 5 bytes JMP 000000010010083a
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                                0000000077871d50 5 bytes JMP 000000010010020c
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\syswow64\KERNELBASE.dll!HeapCreate                                                000000007579549c 5 bytes JMP 00000001001c0800
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                                    0000000075471492 7 bytes JMP 000000010011059e
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                                000000007696524f 7 bytes JMP 0000000100100f52
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                                    00000000769653d0 7 bytes JMP 0000000100110210
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                                  0000000076965677 1 byte JMP 0000000100110048
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                                  0000000076965679 5 bytes {JMP 0xffffffff897aa9d1}
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                          000000007696589a 7 bytes JMP 0000000100100ca6
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                          0000000076965a1d 7 bytes JMP 00000001001103d8
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                                    0000000076965c9b 7 bytes JMP 000000010011012c
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                                      0000000076965d87 7 bytes JMP 00000001001102f4
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123                      0000000076967240 7 bytes JMP 0000000100100e6e
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                      0000000076b71465 2 bytes [B7, 76]
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                      0000000076b714bb 2 bytes [B7, 76]
.text  ...                                                                                                                                                            * 2
.text  C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3436] C:\Windows\syswow64\urlmon.dll!URLOpenPullStreamW + 69                                        00000000773a6acb 7 bytes JMP 0000000100110680
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                          000000007786fc90 5 bytes JMP 000000010028091c
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                        000000007786fdf4 5 bytes JMP 0000000100280048
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                000000007786fe88 5 bytes JMP 00000001002802ee
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                              000000007786ffe4 5 bytes JMP 00000001002804b2
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                      0000000077870018 5 bytes JMP 00000001002809fe
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                              0000000077870048 5 bytes JMP 0000000100280ae0
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                          0000000077870064 5 bytes JMP 000000010026004c
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                              000000007787077c 5 bytes JMP 000000010028012a
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                  000000007787086c 5 bytes JMP 0000000100280758
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                            0000000077870884 5 bytes JMP 0000000100280676
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                0000000077870dd4 5 bytes JMP 00000001002803d0
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                          0000000077871900 5 bytes JMP 0000000100280594
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                      0000000077871bc4 5 bytes JMP 000000010028083a
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                            0000000077871d50 5 bytes JMP 000000010028020c
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206            000000007696524f 7 bytes JMP 0000000100280f52
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                00000000769653d0 7 bytes JMP 0000000100290210
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149              0000000076965677 1 byte JMP 0000000100290048
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151              0000000076965679 5 bytes {JMP 0xffffffff8992a9d1}
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                      000000007696589a 7 bytes JMP 0000000100280ca6
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                      0000000076965a1d 7 bytes JMP 00000001002903d8
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                0000000076965c9b 7 bytes JMP 000000010029012c
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                  0000000076965d87 7 bytes JMP 00000001002902f4
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123  0000000076967240 7 bytes JMP 0000000100280e6e
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                0000000075471492 7 bytes JMP 000000010029059e
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                  0000000076b71465 2 bytes [B7, 76]
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                  0000000076b714bb 2 bytes [B7, 76]
.text  ...                                                                                                                                                            * 2
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                                    000000007786fc90 5 bytes JMP 000000010028091c
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory                                                                  000000007786fdf4 5 bytes JMP 0000000100280048
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtOpenEvent                                                                          000000007786fe88 5 bytes JMP 00000001002802ee
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                                        000000007786ffe4 5 bytes JMP 00000001002804b2
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                                                0000000077870018 5 bytes JMP 00000001002809fe
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                                                        0000000077870048 5 bytes JMP 0000000100280ae0
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                                    0000000077870064 5 bytes JMP 000000010002004c
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                                        000000007787077c 5 bytes JMP 000000010028012a
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                            000000007787086c 5 bytes JMP 0000000100280758
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                                      0000000077870884 5 bytes JMP 0000000100280676
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                          0000000077870dd4 5 bytes JMP 00000001002803d0
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                                                    0000000077871900 5 bytes JMP 0000000100280594
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                                0000000077871bc4 5 bytes JMP 000000010028083a
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\ntdll.dll!NtSuspendThread                                                                      0000000077871d50 5 bytes JMP 000000010028020c
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206                                                      000000007696524f 7 bytes JMP 0000000100280f52
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380                                                          00000000769653d0 7 bytes JMP 0000000100290210
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149                                                        0000000076965677 1 byte JMP 0000000100290048
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 151                                                        0000000076965679 5 bytes {JMP 0xffffffff8992a9d1}
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\sechost.dll!CreateServiceA + 542                                                                000000007696589a 7 bytes JMP 0000000100280ca6
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\sechost.dll!CreateServiceW + 382                                                                0000000076965a1d 7 bytes JMP 00000001002903d8
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370                                                          0000000076965c9b 7 bytes JMP 000000010029012c
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\sechost.dll!ControlServiceExA + 231                                                            0000000076965d87 7 bytes JMP 00000001002902f4
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123                                            0000000076967240 7 bytes JMP 0000000100280e6e
.text  C:\Users\Lino\Downloads\tgmdu7dm.exe[4384] C:\Windows\syswow64\USER32.dll!RecordShutdownReason + 882                                                          0000000075471492 7 bytes JMP 00000001002904bc

---- Devices - GMER 2.1 ----

Device  \FileSystem\Ntfs \Ntfs                                                                                                                                        fffffa800a6912c0
Device  \Driver\NetBT \Device\NetBT_Tcpip_{7D5A217E-9DD0-4168-BBE9-01BEE99BA879}                                                                                      fffffa800d5972c0
Device  \Driver\usbehci \Device\USBPDO-1                                                                                                                              fffffa80099fb2c0
Device  \Driver\cdrom \Device\CdRom0                                                                                                                                  fffffa800abb82c0
Device  \Driver\usbehci \Device\USBFDO-0                                                                                                                              fffffa80099fb2c0
Device  \Driver\NAVENG \Device\NAVENG                                                                                                                                  fffff88009634bb8
Device  \Driver\usbehci \Device\USBFDO-1                                                                                                                              fffffa80099fb2c0
Device  \Driver\IDSVia64 \Device\SymIDSCo                                                                                                                              fffff8800966c060
Device  \Driver\NetBT \Device\NetBt_Wins_Export                                                                                                                        fffffa800d5972c0
Device  \Driver\usbehci \Device\USBPDO-0                                                                                                                              fffffa80099fb2c0

---- Threads - GMER 2.1 ----

Thread  C:\Program Files\Windows Media Player\wmpnetwk.exe [4380:5072]                                                                                                000007fefb6d2a7c
Thread  C:\Program Files\Windows Media Player\wmpnetwk.exe [4380:5000]                                                                                                000007fef6205124
Thread  C:\Program Files\Windows Media Player\wmpnetwk.exe [4380:948]                                                                                                  000007feed5fd618

---- Registry - GMER 2.1 ----

Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                                             
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                            0x00 0x00 0x00 0x00 ...
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                            0
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                                        0xB6 0xDB 0xC9 0xF2 ...
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                                                         
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                                0x00 0x00 0x00 0x00 ...
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                                0
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                                            0xB6 0xDB 0xC9 0xF2 ...

---- Disk sectors - GMER 2.1 ----

Disk    \Device\Harddisk0\DR0                                                                                                                                          unknown MBR code

---- EOF - GMER 2.1 ----


Muss ich für den Anti-Rootkitscan aber auch alle Antivirus Programme ausschalten?

cosinus 17.03.2013 00:01

Ja wäre gut :)

Linschko 17.03.2013 15:41

So, ich hab jetzt auch das Anti Rootkit teil durchgehen lassen. Jedoch wollte er beim Clean up nicht neustarten, sondern er hat es einfach ohne Neustart "ge-clean-uped", also hab ich nach dem Abschluss einfach Manuel einen Neustart gemacht.

Hier sind die logs

Code:

Malwarebytes Anti-Rootkit BETA 1.01.0.1021
www.malwarebytes.org

Database version: v2013.03.17.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Lino :: LINOS-HP-SCHATZ [administrator]

17.03.2013 15:10:48
mbar-log-2013-03-17 (15-10-48).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 33643
Time elapsed: 10 minute(s), 41 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 4
HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550055225558} (Adware.GamePlayLab) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\TypeLib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLab) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660066226658} (Adware.GamePlayLab) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\INTERFACE\{77777777-7777-7777-7777-770077227758} (Adware.GamePlayLab) -> Delete on reboot.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Beim 2. Mal hat es nichts mehr entdeckt.

cosinus 17.03.2013 17:01

aswMBR

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).




TDSS-Killer

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Linschko 18.03.2013 13:02

Also nur um ganz sicher zu gehen: NIEMALS das Programm die Probleme fixen lassen, außer du schreibst es und bei den Scans immer Norton ausschalten?!

cosinus 18.03.2013 13:10

ja genau so :)

Linschko 19.03.2013 14:50

Der aseMBR scan hängt sich jedes mal auf, weil es ein Problem gibt. Nur welches wird nicht geschrieben

cosinus 19.03.2013 15:33

Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

Linschko 19.03.2013 21:19

Das aswMBR Programm hängt sich während dem Scan auf. Es gibt ein "Problem". Welches, wird natürlich nicht gesagt.

cosinus 20.03.2013 13:10

Und das obwohl du avscan auf none gestellt hast? :wtf:

Linschko 20.03.2013 13:45

OOps, ich hab nicht gesehen das eine 2. Seite erstellt wurde und hab deshalb ausversehen 2 mal gepostet :crazy:

Hier sind die logs;
(Ich weiß das der PC-name kake ist, aber mir ist einfach kein besserer PC-name eingefallen)

aswMBR

Code:

aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-03-20 13:24:46
-----------------------------
13:24:46.972    OS Version: Windows x64 6.1.7601 Service Pack 1
13:24:46.972    Number of processors: 8 586 0x1E05
13:24:46.973    ComputerName: LINOS-HP-SCHATZ  UserName: Lino
13:24:51.824    Initialize success
13:25:02.699    AVAST engine defs: 13031900
13:26:04.885    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
13:26:04.889    Disk 0 Vendor: WDC_WD15 01.0 Size: 1430799MB BusType: 8
13:26:05.012    Disk 0 MBR read successfully
13:26:05.016    Disk 0 MBR scan
13:26:05.024    Disk 0 unknown MBR code
13:26:05.029    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
13:26:05.048    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      1416783 MB offset 206848
13:26:05.087    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        13914 MB offset 2901778432
13:26:05.150    Disk 0 scanning C:\Windows\system32\drivers
13:26:16.675    Service scanning
13:26:40.249    Modules scanning
13:26:40.263    Disk 0 trace - called modules:
13:26:40.280    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys sptd.sys hal.dll
13:26:40.290    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800aa95790]
13:26:40.299    3 CLASSPNP.SYS[fffff8800120143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800a7a0050]
13:26:40.305    Scan finished successfully
13:27:19.327    Disk 0 MBR has been saved successfully to "C:\Users\Lino\Desktop\MBR.dat"
13:27:19.330    The log file has been saved successfully to "C:\Users\Lino\Desktop\aswMBR.txt"

Tdsskiller (Hier musste ich Version 2.8.16.0 von Chip downloaden, weil Kaspary "umzieht")

Das Log ist zu lang... So ungefähr 1000 Zeichen.

cosinus 20.03.2013 14:14

Das Log bitte zippen und hier anhängen

Linschko 21.03.2013 22:45

Wie zippt man etwas mit WinRar?
Auserdem muss ich jetzt für ne Woche auf die Slowakei, also kann ich da nichts an meinem PC machen.

cosinus 22.03.2013 12:41

http://www.trojaner-board.de/69886-a...tml#post566999

Linschko 31.03.2013 17:58

Da bin ich wieder. Ich habs jetzt hingekriegt ^^

cosinus 01.04.2013 17:59

Dann bitte jetzt Combofix ausführen:

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Linschko 03.04.2013 13:05

Ich habe keine Fehlermeldung während dem Scan erhalten.

Code:

ComboFix 13-04-02.01 - Lino 03.04.2013  13:16:04.1.8 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.43.1031.18.12247.9337 [GMT 2:00]
ausgeführt von:: c:\users\Lino\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\100
c:\users\Lino\AppData\Roaming\691fa7b1.dat
c:\windows\iun6002.exe
c:\windows\SysWow64\URTTemp
c:\windows\SysWow64\URTTemp\regtlib.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-03-03 bis 2013-04-03  ))))))))))))))))))))))))))))))
.
.
2013-04-03 11:34 . 2013-04-03 11:34        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp
2013-04-03 11:34 . 2013-04-03 11:34        --------        d-----w-        c:\users\UpdatusUser.Linos-HP-Schatz\AppData\Local\temp
2013-04-03 11:34 . 2013-04-03 11:34        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-04-01 11:41 . 2013-04-02 18:25        --------        d-----w-        c:\users\Lino\AppData\Local\Arma 3 Alpha Lite
2013-03-31 16:57 . 2013-02-12 04:12        19968        ----a-w-        c:\windows\system32\drivers\usb8023x.sys
2013-03-31 16:57 . 2013-02-12 04:12        19968        ----a-w-        c:\windows\system32\drivers\usb8023.sys
2013-03-31 16:47 . 2013-03-31 16:47        --------        d-----w-        c:\program files (x86)\7-Zip
2013-03-21 16:58 . 2013-03-21 16:59        --------        d-----w-        c:\users\Lino\AppData\Roaming\Play withSIX
2013-03-21 14:41 . 2013-03-21 14:41        --------        d-----w-        c:\windows\SysWow64\SuperMUI
2013-03-18 15:34 . 2013-03-18 15:34        --------        d-----w-        c:\program files (x86)\1C Company
2013-03-16 23:01 . 2013-03-16 23:01        --------        d-----w-        c:\program files (x86)\BlueStacks
2013-03-16 23:00 . 2013-03-16 23:01        --------        d-----w-        c:\programdata\BlueStacks
2013-03-16 15:26 . 2013-03-17 14:35        --------        d-----w-        C:\mbar
2013-03-15 15:04 . 2013-03-15 15:04        --------        d-----w-        c:\program files (x86)\ProtectDisc Driver Installer
2013-03-15 15:04 . 2013-03-15 15:04        --------        d-----w-        c:\users\Lino\AppData\Roaming\ProtectDISC
2013-03-15 14:57 . 2013-03-18 20:40        --------        d-----w-        c:\program files (x86)\Theatre of War 3
2013-03-13 22:00 . 2013-03-13 22:00        --------        d-----w-        c:\program files\Microsoft Silverlight
2013-03-13 17:46 . 2013-03-13 20:49        --------        d-----w-        c:\windows\system32\drivers\NISx64\1403000.024
2013-03-13 16:09 . 2013-03-13 16:09        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2013-03-13 16:09 . 2012-12-14 15:49        24176        ----a-w-        c:\windows\system32\drivers\mbam.sys
2013-03-12 16:14 . 2013-03-12 16:14        --------        d-----w-        c:\users\Lino\AppData\Local\HP MediaSmart Video
2013-03-11 18:15 . 2013-03-11 18:15        --------        d-----w-        c:\users\Lino\AppData\Roaming\Malwarebytes
2013-03-11 18:15 . 2013-03-11 18:15        --------        d-----w-        c:\programdata\Malwarebytes
2013-03-11 16:51 . 2013-03-11 16:51        --------        d-----w-        c:\windows\ERUNT
2013-03-09 18:51 . 2013-03-09 18:51        --------        d-----w-        c:\users\Lino\AppData\Roaming\Canneverbe Limited
2013-03-09 18:51 . 2013-03-09 18:51        --------        d-----w-        c:\programdata\Canneverbe Limited
2013-03-09 18:51 . 2013-03-09 18:51        --------        d-----w-        c:\program files (x86)\CDBurnerXP
2013-03-08 17:22 . 2013-03-10 03:20        --------        d-----w-        C:\4c3afa1d91612de34882800ac3
2013-03-08 14:54 . 2013-03-08 14:54        --------        d-----w-        c:\program files\Enigma Software Group
2013-03-04 13:53 . 2013-03-04 13:53        --------        d-----w-        c:\users\Lino\AppData\Local\fontconfig
2013-03-04 13:53 . 2013-03-04 13:53        --------        d-----w-        c:\users\Lino\AppData\Local\gegl-0.2
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-13 22:02 . 2011-03-28 20:08        72013344        ----a-w-        c:\windows\system32\MRT.exe
2013-03-13 13:44 . 2012-04-05 11:23        693976        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-13 13:44 . 2011-05-19 12:33        73432        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-10 18:22 . 2011-04-01 17:53        177312        ----a-w-        c:\windows\system32\drivers\SYMEVENT64x86.SYS
2013-02-24 11:02 . 2012-04-18 13:07        280792        ----a-w-        c:\windows\SysWow64\PnkBstrB.exe
2013-02-24 11:02 . 2011-03-23 14:43        280792        ----a-w-        c:\windows\SysWow64\PnkBstrB.xtr
2013-02-24 11:01 . 2011-03-23 14:39        281032        ----a-w-        c:\windows\SysWow64\PnkBstrB.ex0
2013-02-12 05:45 . 2013-03-14 12:00        135168        ----a-w-        c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-14 12:00        308736        ----a-w-        c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-14 12:00        350208        ----a-w-        c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45 . 2013-03-14 12:00        111104        ----a-w-        c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48 . 2013-03-14 12:00        474112        ----a-w-        c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-14 12:00        2176512        ----a-w-        c:\windows\apppatch\AcGenral.dll
2013-01-13 21:17 . 2013-02-27 21:38        9728        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 21:17 . 2013-02-27 21:38        2560        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 21:16 . 2013-02-27 21:38        10752        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 21:12 . 2013-02-27 21:38        3584        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:38        4096        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:38        5632        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:38        3072        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:38        5632        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:38        3072        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:35 . 2013-02-27 21:38        9728        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 20:35 . 2013-02-27 21:38        2560        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 20:35 . 2013-02-27 21:38        10752        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 20:32 . 2013-02-27 21:38        3584        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:38        4096        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:38        5632        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:38        3072        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:38        3072        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:38        5632        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:38        1247744        ----a-w-        c:\windows\SysWow64\DWrite.dll
2013-01-13 20:22 . 2013-02-27 21:38        1988096        ----a-w-        c:\windows\SysWow64\d3d10warp.dll
2013-01-13 20:20 . 2013-02-27 21:38        293376        ----a-w-        c:\windows\SysWow64\dxgi.dll
2013-01-13 20:09 . 2013-02-27 21:38        249856        ----a-w-        c:\windows\SysWow64\d3d10_1core.dll
2013-01-13 20:08 . 2013-02-27 21:38        220160        ----a-w-        c:\windows\SysWow64\d3d10core.dll
2013-01-13 20:08 . 2013-02-27 21:38        1504768        ----a-w-        c:\windows\SysWow64\d3d11.dll
2013-01-13 19:59 . 2013-02-27 21:38        1643520        ----a-w-        c:\windows\system32\DWrite.dll
2013-01-13 19:58 . 2013-02-27 21:38        1175552        ----a-w-        c:\windows\system32\FntCache.dll
2013-01-13 19:54 . 2013-02-27 21:38        604160        ----a-w-        c:\windows\SysWow64\d3d10level9.dll
2013-01-13 19:53 . 2013-02-27 21:38        207872        ----a-w-        c:\windows\SysWow64\WindowsCodecsExt.dll
2013-01-13 19:53 . 2013-02-27 21:38        187392        ----a-w-        c:\windows\SysWow64\UIAnimation.dll
2013-01-13 19:51 . 2013-02-27 21:38        2565120        ----a-w-        c:\windows\system32\d3d10warp.dll
2013-01-13 19:49 . 2013-02-27 21:38        363008        ----a-w-        c:\windows\system32\dxgi.dll
2013-01-13 19:48 . 2013-02-27 21:38        161792        ----a-w-        c:\windows\SysWow64\d3d10_1.dll
2013-01-13 19:46 . 2013-02-27 21:38        1080832        ----a-w-        c:\windows\SysWow64\d3d10.dll
2013-01-13 19:43 . 2013-02-27 21:38        1230336        ----a-w-        c:\windows\SysWow64\WindowsCodecs.dll
2013-01-13 19:38 . 2013-02-27 21:38        333312        ----a-w-        c:\windows\system32\d3d10_1core.dll
2013-01-13 19:38 . 2013-02-27 21:38        1887232        ----a-w-        c:\windows\system32\d3d11.dll
2013-01-13 19:38 . 2013-02-27 21:38        296960        ----a-w-        c:\windows\system32\d3d10core.dll
2013-01-13 19:37 . 2013-02-27 21:38        3419136        ----a-w-        c:\windows\SysWow64\d2d1.dll
2013-01-13 19:25 . 2013-02-27 21:38        245248        ----a-w-        c:\windows\system32\WindowsCodecsExt.dll
2013-01-13 19:24 . 2013-02-27 21:38        648192        ----a-w-        c:\windows\system32\d3d10level9.dll
2013-01-13 19:24 . 2013-02-27 21:38        221184        ----a-w-        c:\windows\system32\UIAnimation.dll
2013-01-13 19:20 . 2013-02-27 21:38        194560        ----a-w-        c:\windows\system32\d3d10_1.dll
2013-01-13 19:20 . 2013-02-27 21:38        1238528        ----a-w-        c:\windows\system32\d3d10.dll
2013-01-13 19:15 . 2013-02-27 21:38        1424384        ----a-w-        c:\windows\system32\WindowsCodecs.dll
2013-01-13 19:10 . 2013-02-27 21:38        3928064        ----a-w-        c:\windows\system32\d2d1.dll
2013-01-13 19:02 . 2013-02-27 21:38        417792        ----a-w-        c:\windows\SysWow64\WMPhoto.dll
2013-01-13 18:34 . 2013-02-27 21:38        364544        ----a-w-        c:\windows\SysWow64\XpsGdiConverter.dll
2013-01-13 18:32 . 2013-02-27 21:38        465920        ----a-w-        c:\windows\system32\WMPhoto.dll
2013-01-13 18:09 . 2013-02-27 21:38        522752        ----a-w-        c:\windows\system32\XpsGdiConverter.dll
2013-01-13 17:26 . 2013-02-27 21:38        1158144        ----a-w-        c:\windows\SysWow64\XpsPrint.dll
2013-01-13 17:05 . 2013-02-27 21:38        1682432        ----a-w-        c:\windows\system32\XpsPrint.dll
2013-01-05 05:53 . 2013-02-13 11:56        5553512        ----a-w-        c:\windows\system32\ntoskrnl.exe
2013-01-05 05:00 . 2013-02-13 11:56        3967848        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2013-01-05 05:00 . 2013-02-13 11:56        3913064        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2013-01-04 06:11 . 2013-02-27 21:38        2284544        ----a-w-        c:\windows\SysWow64\msmpeg2vdec.dll
2013-01-04 06:11 . 2013-02-27 21:38        2776576        ----a-w-        c:\windows\system32\msmpeg2vdec.dll
2013-01-04 05:46 . 2013-02-13 11:55        215040        ----a-w-        c:\windows\system32\winsrv.dll
2013-01-04 04:51 . 2013-02-13 11:55        5120        ----a-w-        c:\windows\SysWow64\wow32.dll
2013-01-04 04:43 . 2013-02-13 11:55        44032        ----a-w-        c:\windows\apppatch\acwow64.dll
2013-01-04 03:26 . 2013-02-13 11:56        3153408        ----a-w-        c:\windows\system32\win32k.sys
2013-01-04 02:47 . 2013-02-13 11:55        25600        ----a-w-        c:\windows\SysWow64\setup16.exe
2013-01-04 02:47 . 2013-02-13 11:55        7680        ----a-w-        c:\windows\SysWow64\instnm.exe
2013-01-04 02:47 . 2013-02-13 11:55        2048        ----a-w-        c:\windows\SysWow64\user.exe
2013-01-04 02:47 . 2013-02-13 11:55        14336        ----a-w-        c:\windows\SysWow64\ntvdm64.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisorDock"="c:\program files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe" [2010-09-28 1715768]
"Steam"="c:\program files (x86)\Stam\steam.exe" [2013-03-29 1631144]
"GoogleChromeAutoLaunch_3A790C4566138A29127FA69389D34642"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2013-03-21 1312720]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2009-10-14 563736]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2010-04-25 61112]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"BlueStacks Agent"="c:\program files (x86)\BlueStacks\HD-Agent.exe" [2013-02-15 601976]
.
c:\users\Lino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2013-1-8 228448]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
"EnableSecureUIAPath"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 ezSharedSvc;Easybits Services for Windows; [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe [2013-01-16 45056]
R3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\DRIVERS\DisplayLinkUsbPort_5.6.31854.0.sys [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2011-03-22 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 SMR210;Symantec SMR Utility Service 2.1.0;c:\windows\System32\drivers\SMR210.SYS [2011-09-15 96376]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1403000.024\SYMDS64.SYS [2013-01-22 493656]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1403000.024\SYMEFA64.SYS [2013-01-31 1139800]
S1 acedrv09;acedrv09;c:\windows\system32\drivers\acedrv09.sys [2011-04-01 134880]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130322.001\BHDrvx64.sys [2013-03-22 1387608]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1403000.024\ccSetx64.sys [2012-11-16 168096]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130402.001\IDSvia64.sys [2013-03-08 513184]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1403000.024\Ironx64.SYS [2012-11-16 224416]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1403000.024\SYMNETS.SYS [2013-01-31 432800]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 191616]
S2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2013-02-15 71032]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [2013-02-15 384888]
S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2012-07-12 8704]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\20.3.0.36\ccSvcHst.exe [2012-12-24 144520]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2009-10-14 635416]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2320920]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-18 138912]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2012-01-29 250984]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-01-29 413800]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-01 17:48        1642448        ----a-w-        c:\program files (x86)\Google\Chrome\Application\26.0.1410.43\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-04-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 13:44]
.
2013-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-01 18:35]
.
2013-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-01 18:35]
.
2013-03-21 c:\windows\Tasks\HPCeeScheduleForLino.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 11:53]
.
2013-03-18 c:\windows\Tasks\HPCeeScheduleForLINOS-HP-SCHATZ$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 11:53]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2010-01-18 568888]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - LocalService
FontCache
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearchAssistant = hxxp://www.google.com
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Free YouTube Download - c:\users\Lino\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 10.0.0.138
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{5e5ab302-7f65-44cd-8211-c1d4caaccea3} - (no file)
BHO-{0931BD3F-547E-45C1-B133-D0E995645DBA} - (no file)
Toolbar-!{40c3cc16-7269-4b32-9531-17f2950fb06f} - (no file)
Toolbar-!{c840e246-6b95-475e-9bd7-caa1c7eca9f2} - (no file)
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Toolbar-!{40c3cc16-7269-4b32-9531-17f2950fb06f} - (no file)
Toolbar-!{c840e246-6b95-475e-9bd7-caa1c7eca9f2} - (no file)
WebBrowser-{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - (no file)
AddRemove-BattlEye A2 Free - c:\program files (x86)\stam\steamapps\common\arma 2 freeBattlEye\UnInstallBE.exe
AddRemove-DesertCombat - c:\windows\iun6002.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
AddRemove-PunkBusterSvc - c:\program files (x86)\Origin Games\Battlefield 3\pbsvc.exe
AddRemove-Republic at War - Deutsch 1.1 - c:\program files (x86)\LucasArts\Star Wars Empire at War Forces of Corruption\Uninstall.exe
AddRemove-Republic at War 1.1 - c:\program files (x86)\LucasArts\Star Wars Empire at War Forces of Corruption\Data\Uninstall_2.exe
AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\20.3.0.36\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\20.3.0.36\diMaster.dll\" /prefetch:1"
--
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3419521695-173782897-1149873748-1000\Software\SecuROM\License information*]
"datasecu"=hex:f0,65,e9,15,ef,2a,de,63,0a,b3,13,13,7c,7a,10,eb,85,f8,ac,8e,6d,
  27,e4,e4,6e,dd,0f,9c,01,80,22,50,ed,48,2b,6d,70,ee,83,9c,c6,57,99,33,f3,9a,\
"rkeysecu"=hex:7c,6e,58,87,a6,f1,0d,f1,0b,17,da,11,5a,67,77,cc
.
[HKEY_LOCAL_MACHINE\software\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-04-03  13:45:42
ComboFix-quarantined-files.txt  2013-04-03 11:45
.
Vor Suchlauf: 22 Verzeichnis(se), 947.744.890.880 Bytes frei
Nach Suchlauf: 35 Verzeichnis(se), 947.491.368.960 Bytes frei
.
- - End Of File - - 3FC1FC6F32F69F6F087F6894577066A5


cosinus 03.04.2013 15:34

JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




Im Anschluss:

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).


Danach eine Kontrolle mit OTL bitte:
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles in CODE-Tags hier in den Thread.

Linschko 05.04.2013 13:01

Es gab keine Probleme.

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.8.2 (04.04.2013:1)
OS: Windows 7 Home Premium x64
Ran by Lino on 05.04.2013 at 13:08:53,79
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_current_user\software\sweetim
Successfully deleted: [Registry Key] hkey_local_machine\software\sweetim
Successfully deleted: [Registry Key] hkey_current_user\software\systweak



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader"
Successfully deleted: [Folder] "C:\Users\Lino\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Users\Lino\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Program Files (x86)\imesh applications"
Successfully deleted: [Folder] "C:\Program Files (x86)\mytools"
Successfully deleted: [Folder] "C:\Program Files (x86)\ytd toolbar"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader"
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{000BB735-975F-4EA6-B9EE-58B411F9F25F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{01EDE236-8997-40D4-AD5F-1A85EE0475A2}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{0217D984-6CC1-49C5-8D03-0D8EFFC69309}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{0217DC3A-B886-40B0-A8D5-63594929A2F5}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{040FA44D-AC00-45C9-BC1F-8178230C9746}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{04EEDF4D-F198-4FBC-AD81-AF5A0E7B5666}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{05352367-EDFC-4FFD-B3BD-0649452E2141}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{06CC8B07-586E-4DA2-B7CB-DD470BD1235D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{06D1A616-D570-4088-802B-E6419B3A1EF9}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{076E1BA1-F5E2-4D89-8F6B-502491FF0B08}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{085CDE0A-C04F-463C-B13F-8F422F4E75FF}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{08F1B97E-2DC3-4B5C-9AF1-A44EF6D14213}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{0989D525-B6B4-4355-BE5D-0B3475FF2CF1}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{0A18ABED-52B1-4B43-8C2F-712B5A8D0503}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{0B2930E0-0E33-43D5-9B25-691731882F51}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{0D072B93-AAF5-423D-A650-CABEF7ABAF7B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{0D73410A-6760-4166-9895-F95A5208F285}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{0D8A07F0-428F-4141-8171-56047D9B5568}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{0F7BD39F-EF81-4DC3-8410-F1F8D63CDB10}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{11DEBED6-67B3-49FA-976E-393B22CB89DC}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{12A5F638-08D9-41F9-AA7D-2299FA91DE0F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{12C4D8A2-71B9-44A0-B6DF-6648D4FDCA95}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{1311EA26-ECF4-4084-8D5B-E1B68E963D8D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{13C63266-6E1F-4D6E-B982-1859F0894ABD}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{149EA161-2A33-4314-AC1B-81AAAF070AE0}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{15311C4C-7604-4539-A3AA-902C74746CDF}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{155CDFD8-E50F-4084-84CC-C74AD065168F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{15CA0FED-E3E6-4D9F-A324-0D81518C171A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{163B6EF4-E37F-4ED2-AD49-72144F00B2C6}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{175174EB-415C-4744-8657-7D13492425B6}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{17EA1A56-CA20-4AD8-9F78-67D340E75A76}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{1AF07E4D-4A51-4E9E-BAE1-11D8B0C71672}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{1C076F44-BD49-422F-9CD0-193A69F40573}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{1C92B179-1D18-46D1-A5AD-9004D4E96E41}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{1FFB392A-B688-410D-A86C-CD391E4CE9B4}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{212E35EE-DB00-4A88-BFBB-B94746C41835}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2158A3D4-30DC-4412-9C91-36C9303E4353}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2217AA81-BB03-4361-9C08-8C8D24639025}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{242D7953-5E12-454B-AD29-C840332945D8}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{24AFC32A-7E3D-4982-9D7C-0CA2B8E3DA84}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{275F69F1-855A-4DE9-8C4E-238034187E2A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{27623A7F-AF38-4D5F-9BBC-985A6B979F4D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2822F003-2CC2-4DAE-8C37-533098714C91}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2A314D4D-C1C9-43B7-A417-417FFCF1370D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2A6ABDFF-8808-4D33-A01F-BF8B1718B67F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2D1B311F-E026-41B0-BB89-BA3568E15FDC}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2DCC4DC3-F26A-41AB-BB42-CBD2318FBD23}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2DE0A59B-13DC-4FF1-9647-F2D68C0F0C04}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2E1DF33B-901A-4E9D-B38A-C206AD54BC5D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2E870BB0-7518-4DBF-8B19-0BD28B4EB9AA}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2EA1F3E5-3BC5-40F2-8D8E-D84442D2C487}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2F5625BD-FBED-47CE-8919-068A05EA99D3}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{2F757285-9C58-4545-8306-BC71762C3387}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{308AF2D8-C6F0-4337-BC8D-42E33A9C7B24}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{30EA8857-C0F0-4E23-83C9-72959F076EC1}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{32C8833C-7913-451B-99B2-0343CB2D8377}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{3313E212-0CAA-4419-A7FA-5ACA84296204}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{335B4FE8-13E6-4982-8E4D-501BEBA27152}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{34EBA25A-D7E5-4A26-B193-14EC8B41012C}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{35027440-48E0-4B14-A21F-80B269FC9769}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{35943C4E-4601-49F1-A501-9FAA047F9721}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{36A87AC6-2ECA-494B-B744-A5DFC2267C60}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{37F4AE76-3588-456C-B84C-27C46FD649DF}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{382B1965-6B7F-4240-B79B-DAC46ADA720A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{38A0C145-528D-4ED9-8476-16005A547C53}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{393C9A98-2A07-4922-A9E5-E530462EB779}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{3A2C1699-27BA-4FDF-AAC9-15BF28921202}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{3AFAD901-513B-4F85-A4A0-708FC8AF0746}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{3B48017A-E9CE-41AF-9243-7F867E1372C3}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{3D474704-B867-4B35-A24F-B2B96503BFAB}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{3E5DAAC6-4627-46EE-83D3-26C7E6F38CF2}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{3E626B7C-5BF5-44A1-8AE6-11F184797F56}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{40B0549D-6C3C-44E9-B780-A97D70B4536D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{423ECC5B-3AE2-4380-BC6D-59E9A025A3CA}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{427054D5-C9F9-4E2E-B631-1BA9F6FECE4F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{42A2CCF0-BEA6-4657-B544-3F687F530146}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{435961D8-CBCA-45C8-85AE-019E28405BD4}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{449010FC-2D5C-4867-B379-27B77534A723}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{450C050C-67A8-4DCA-8BCF-284C44F893F6}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{46B61456-C57D-44F4-AB18-B4ECB588C270}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{4742637E-425F-4F80-B5A5-5247CB1D949D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{4864A5B0-9F3F-48A8-9A00-4B36A3C85D25}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{48ECA927-C89F-4CBD-93BE-A424B1000F64}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{48F64D7D-5488-45EB-8B98-506E83F3706B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{49CA6603-4B06-43F7-93CC-7F509AA0B14B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{4A35B0F9-FFD8-46E5-83B3-0D0065248EA6}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{4AC99C6C-727A-4CC7-A3E7-06F53870045B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{4AF34ACC-404E-4560-9D11-B5A520435873}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{4C75F63E-7C1D-43F6-881F-D43EE5EE3558}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{4CA86F00-D3A7-4F91-AD1A-C3F54826EB9F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{4DFE7F77-55A3-4E38-84B7-18FD77995823}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{4ED675B3-6534-45B7-8C90-EEE401F32190}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{4F0B7540-347F-422F-BEF0-F4EE709BD56D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{4FDBB83D-15F3-4C41-B0BB-3D1113586DA4}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{52C7CB03-640B-4BB1-BC96-7CD649B36DB6}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5397D135-D778-48AA-82C9-B215A0FFEC32}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{53B2A777-2A09-4C36-A507-B0382BB2A7BC}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{547268E7-3853-41D0-9678-E4693D855F3A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5481CDFF-E24D-4D96-9F8E-A6931577CA71}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{54F03E02-902A-47C1-A760-EC47AA5D8713}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5619AC61-00D8-4EC1-80FF-A4F66E233CFC}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{579B04B6-4C84-46EC-B951-712900D73DD4}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5801A05B-FD78-4F54-9897-DAF7D672B142}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{587C472D-FE80-4443-B351-D9C78E677B80}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5A981503-1369-4C11-8858-5A7009508597}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5C2D2AC0-F252-4FE2-BADA-CA361F512251}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5C9DE9FB-2E16-422A-A4E7-ECA448DC5651}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5D1AA39F-C197-4E44-96F5-11E072602F83}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5DCBF02A-A2A4-4AB2-BBD7-ED5D6FA119BD}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5E0D9BEF-823A-41D7-94EF-123E4A4C4956}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5E462F7B-7219-4F41-957A-E5B01C98C488}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{5F5816CA-989B-4C25-BFC9-37F2396F8AC0}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{6417500B-1A18-4007-B7BB-10A83D0B3A4D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{641E9FD3-17AE-4930-BA28-F5605832046C}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{64C1C5AF-D379-4231-B25D-633D9C945362}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{65D9607A-62E8-4670-8F92-54920B98FB3C}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{65FC8DCF-1B7D-4E1C-9E06-059A96E71329}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{66AC898A-CB64-45E4-AE67-5F884DEDDE5F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{66FF07BC-D205-4BA7-80C4-8B09FD86DBAD}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{6728F49A-C688-4893-86B0-28395EC0CBEE}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{676A0EFE-05BA-459A-8EFB-5C3ABEC86E55}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{68421D5C-E3E3-42FE-85DE-324C3EE74AB8}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{692799A1-FF7D-40AB-BA4F-4E00FC0E4491}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{6B52D98B-56BC-4DC1-9682-6E57F9D27754}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{6BB79FBA-8955-4BBC-BABE-3874F8F42DD8}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{6C219D1B-E128-4199-8B9B-F84DFDC67F3C}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{6CB8050D-E3F5-400D-8A53-45BD0F29BE37}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{6CDEA75C-7CE4-49AC-A92D-F5E01D9BC959}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{6CF08475-FF8C-4695-9B2F-2E71DA549CDD}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{6D886194-3B14-481B-B0BA-A593A6625E37}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{6EAC1FF4-5F8D-4E69-9CA3-86DDC4F10B4C}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{6F860688-A032-4E14-AEEB-AD324C8B85C1}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{7058F9E1-F903-4530-ADC5-75E11F447050}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{70EC602A-4C99-4FD3-B124-F32423017D19}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{7249E7D9-2B66-4FB0-B631-07B1A3746C70}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{72C72597-C2DC-4F44-AE68-284C479675D5}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{73B83067-F9C7-4B6E-80C0-DA2A3B26D0AB}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{7530092C-ABF9-4F6B-AD05-61793775E87D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{754D1F93-AC00-4D21-8295-432C72046212}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{790A4D6C-3BAE-41B0-A7B6-8122908A9873}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{797EF8C8-9437-44AD-8F6E-6803D81EB26B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{7BD23484-191A-49D3-843F-B61CBACE7BDD}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{7C3C96F4-2DB9-4FB2-B2D6-D7030CB5558C}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{7C3FDC52-8C87-4123-B8B0-5E1BC02BD6EE}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{7CE7F54F-7DD5-4751-8E1C-11E960863236}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8057300A-0F4D-45D2-A8E9-BB2449B0D05B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{81068020-8843-4F46-BE1A-CDF9AFDE14F0}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{81A48999-33F1-47B7-9E49-99EDB8CDFC90}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{81DFB9D5-F9DE-479E-BA8D-AF27FC81CCCC}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{81E5610C-1B1B-40C5-94A0-0F241EFE144C}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{823D4BC0-F8B6-4C08-B7EB-D08E8F575FD1}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{83D306C7-23E0-4DD2-A498-6D04AF06A52E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{85C8BF14-428F-478E-8B3F-B52BD4F0C234}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{86385E40-D71E-49F7-B9BE-1531A4B12219}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{869F2F7A-707E-4A98-A7A1-1DCC5DBB67F4}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{874B196C-9757-4041-95D7-D3A8979A8D95}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8785CDFF-ADDE-4A19-B4F5-3470BC74A642}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{87C95B88-20D9-43A7-889F-DB1D97AABB11}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8848603A-1087-4473-8177-62DFA4DD057E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8894A3FE-1D7F-41EE-882C-B6E0C1ED076B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8A8F6FE4-3CF9-4C49-BC9B-12A73868C6F5}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8ACBD6B9-1795-48D0-AC1D-EF97F98054C6}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8B0095FB-BE75-4804-B48A-197742954182}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8B0737A4-1DAB-4E7E-BEA1-49AF7B5B69E9}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8B90C27F-56E6-4F20-94E7-BA038C33D3A9}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8D43A0FD-2BDC-4932-8916-ACF7EB72FB70}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8D477B63-3356-482B-81C3-9790C5FB6DFD}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8DB000DC-005A-4016-A094-A0AB679160AD}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8EC9ADF5-772E-4F92-B984-144BA58C1DE0}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8F21A756-18A6-4EF5-A765-AD39CD64CC4A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8F29D0F2-1028-44CF-8065-1F8E891B0E12}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{8F3C1521-6E3A-4286-AF3F-1255FBA0B223}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{90D632BF-EDF5-4799-8F89-1A4E67C549D9}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{91C13F20-EDE1-41FA-93F3-712BB6C43C85}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{927C6279-346E-480B-83FE-F6D5E923BEB0}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{92F19CFA-FB9C-4995-9988-915B4AE1E5E4}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{93171AFE-DD0F-4A4F-A5CE-6AFCD81A8717}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{93F7D7D4-F105-4B9F-92EA-736DC1093024}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{94403663-254E-4ECF-A7B2-B52808337022}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{94896994-1486-440E-BCDE-1ED91EF41229}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{96DAA2E5-72C8-4DD0-AB9D-E246A8FDDDA6}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{97458181-F8E7-493C-941B-F3B44BF9151E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{97F85FBE-5017-47C5-AEBB-A4341D711E18}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{98737C54-5D7B-4A08-AF8E-D97F16CB0CD9}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{98861538-D0F7-4245-AE5B-A8D29644CFD0}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{9961BB39-659F-4AE1-B18A-B9D1D1A42C7E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{9A2F5B78-B922-4A62-AD4E-9134592FDEA1}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{9B108885-C765-4E1A-9FDE-B6450FE11AA4}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{9BAE5CB8-DB54-4364-B51C-239EDD1FFDBA}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{9BD4044E-1586-44C7-8440-0554665EB7DF}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{9D0BBBD0-DF55-4C46-9422-2A96082CDD4A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{9F246BFA-1AD0-4469-97BE-1D9468E769D3}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{9F73D744-9FB0-4DEA-9D47-5BA79F46BBCC}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A0C1B257-8F63-4AF9-BD54-190382A557E1}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A1A40BB8-C10D-487F-8D8A-9DF356A784C7}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A1BDC52E-CF53-4A48-88B2-95AF06227116}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A4197452-E492-4515-B375-9595C3DDB83B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A43BA7EF-4F8C-4A95-A5F9-FDAACAC3780E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A5B7C1CC-FA77-44B6-B5B2-B987D07C2386}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A642952F-E0A1-44BD-8A64-BC34A6CE4D13}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A75E0E56-54AE-496F-A5E6-23033F13BF7F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A7DD020E-1E2F-4F79-87BD-29825A71A00C}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A8511714-C155-45A8-B84B-C0E085EDCE76}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A88EEED1-B166-4EB4-8A80-B549350D49FC}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A8ABE907-7F14-4CDC-B2E0-AB3D41859CE9}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A9613773-EB82-417B-9C2A-A84FCE3F7A97}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{A9B6E70C-35CF-4C67-A76D-20F67112EAF6}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{AAC6AAB0-2D2B-4146-8012-039718B3119A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{AAE1823B-0AEA-4134-AC00-4D8CAC339AB9}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{AB8B2C21-4FCF-416E-9D5A-654B773B2B57}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{ABEBF509-B707-48A3-B972-C831AD263077}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{AD5C9B1E-3373-4B93-A486-3C62DA555AB6}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{AF25B6C7-DF5B-4EA0-8A45-7BA12836C4B0}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{AF5531E6-2A96-4F38-BEF9-19D8BC6F5345}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{AF5B93C6-9D86-4F6F-8365-5F441F8219CE}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B1C509D1-8E93-4E0D-BB1D-23FDC3B4AB2B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B1DEADA7-E94A-441F-A68D-30173C3A784E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B417F954-BD44-4DD2-95B5-2D9E07B86307}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B45B7052-21BD-471F-A043-CB0B7D4B1182}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B4898428-9E59-43A1-AD77-3A91FBB2357F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B4D70CB2-ED6D-4140-9D98-72030A45CAB8}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B5A7CB37-DF0F-4ADE-819E-335EF2EEB967}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B5CFC67D-2265-41C6-BE68-A6470465CA31}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B6F1BCC8-7925-471A-AD88-DE5089BF3E93}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B717E136-1BC7-4FC6-AB8B-2A167FEC0200}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B76E4004-006B-4336-97B5-ABE7C24A223F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B8335D41-270F-47C3-9259-113C1AA96F3F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B8CC286A-4DD6-4C71-AB4B-3C893953FB27}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B904FDB1-F015-4576-BA3D-C6827CA798C7}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B90E6B69-0FF0-49E8-A263-F6C3832DD164}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{B995757A-4709-4237-8470-590BBCE74319}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{BA35E7F8-080E-4EE8-AE0A-E888395508D4}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{BBF75156-D606-40BF-A61C-DC37B1117029}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{BCCC5949-C192-4309-927D-ED9F2155B681}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{BCF0E1B0-4C85-42FE-9F36-C483F26DC584}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{BE574EAC-2B32-4434-AD91-C1245F57CA6E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{BF16288F-83A6-4686-9E41-73BF2140055B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{BFA9E451-75F1-4BBA-A54A-DC649084DC50}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C0747A3C-2F63-4D49-9164-3EA53A3A7564}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C15D4ECE-5336-488A-9441-A95C33FB2E3F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C1A5C915-7B6B-4889-AD27-9D3D924E673A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C1C2C94A-E2F3-439F-BE4E-E3CEC42CE69A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C1E8A681-F288-4CB0-90FC-3BA3C7FCE2F2}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C38B6303-47D1-42FB-9041-2207657C20D3}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C436C827-9832-4C98-8857-9953A7095F50}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C5181594-5521-46C6-B273-0638D0340632}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C61C8DD9-2876-4C9C-A25C-E3240A5E268A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C6B18D37-7E49-484A-9FF2-71C095A93EC0}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C71843EC-F7AA-4FCB-A0C6-070577A1D15D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C741AD41-23BE-4ECA-8D82-DC2E97D2DF1B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C7E06E8B-A378-432B-837F-5B126EC28CC2}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C9652BB0-8D4F-4318-8D41-C24C4B1883F6}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{C9AE8318-5B5F-49AA-BFEF-C001EF9F54AD}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{CA83238C-2688-4424-8883-E5022E26BAEF}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{CAA3933A-6880-47F8-80FC-89166422CDD0}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{CBEEB8FC-9E9D-4FAF-B029-65A523E3D61F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{CEA85548-C4B7-4801-ACD6-872D07D833D8}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{CEB01675-1E7C-4139-8E00-F4C24AEFB65E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{CF156163-30AD-4683-90F1-2503E8A07EAD}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{CF3F921A-6925-4986-B069-0E3F7B108908}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{CF503B5C-7AE7-4D11-A5D8-06970CC00643}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{CFC6465A-B513-481C-A996-1EEADE487A6E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{D05DEEC7-F3D2-4944-9EC1-3A3A4B48D6F8}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{D07AD564-F246-43FC-A51B-B64085251C76}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{D1958631-5532-41A1-91AA-B51A56B33503}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{D273F5C7-F7AF-4FB9-9FA6-D3480568E087}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{D2F18B6D-663C-47D2-8246-5AC84423A780}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{D4CBFEFC-EACE-4BA3-9595-346DDED2DF39}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{D599A642-18BB-48E9-BEAE-1B2660693485}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{D6B9C562-9440-48CE-8CEB-4C85F1FDBAE5}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{D6C380D8-B57D-4A66-993C-6126933EEF3F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{D7828D62-11AE-44CB-90A2-AFE94F193F6A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{DE6CEE9E-9AE8-47B2-A1EA-CB74461B46DD}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{DF336616-6B39-4CBA-BFE4-57C534DA9A3E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{DFA71FDC-D380-4D9D-872A-98A237B23E8F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{E03348F0-29F7-4549-AC80-17A29A625219}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{E2C5AF0E-4220-4971-B77A-A3E97BD1C409}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{E2ED0FC3-F4BE-40EA-8AB4-44C91B21100F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{E4958A52-48B7-46E3-B011-D0F9BF6A290D}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{E70B2A0D-AD46-4EB4-833B-E2A80713B1DE}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{E9BEBD67-0DB1-44AB-B9D4-AE6095ABCC07}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{E9C8E65D-CF1C-45CA-BAA8-E64510E48A45}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{EA793F18-57B0-4A7F-BF5A-DB6F0834C34E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{EBE2704E-9FF4-4117-8A83-0B2528DD0193}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{EDC5187E-1036-4397-9138-318A37250A2F}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{EE9F0968-05E0-4B44-B4CE-E3556FDF95B2}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F0C935CA-32EF-461B-8241-04971E1127C8}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F29BD4CF-9CBB-470E-B9B1-EA2129308AD9}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F2B7C032-1582-4AE4-A6E0-CF2F8200674A}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F43201C7-9EDA-4A51-8DD1-6F90D2222B4C}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F4C12E0E-A513-4E6D-8AB8-9046EF585038}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F4D14D9E-E8F3-48D0-A6B4-BE52AF8E7844}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F5AC26A1-CC9E-4A3A-9B60-81BDD5962945}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F631A496-E562-4D0A-908E-404E795779FF}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F6E24F3D-507E-4323-863F-E1FEDC6BCE5E}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F766EEC2-EFEF-4C10-BA45-5445EE3C1EF1}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F89CE759-8403-4D06-838B-429CCA8BBAD6}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{F98F5591-DB38-405E-8CA3-B1E595220F63}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{FA390325-FB48-42F9-9935-052251DC6CBF}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{FA3A93A8-A914-4C27-987B-988D75EA0A43}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{FAF45AA9-7256-4682-BF42-88B6660E3789}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{FB3FE671-9F9F-4479-AA5C-7672AAA3EF88}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{FBA42C17-275E-4CF1-A3BF-6F1C7B0615FC}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{FC04FF23-AA8D-43FE-9E30-22310B5B78A0}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{FDAE739F-F9A8-4BF9-A6B3-0371CEAD766B}
Successfully deleted: [Empty Folder] C:\Users\Lino\appdata\local\{FF74C13C-01F0-4C79-AECD-45DC72A92FCD}



~~~ Chrome

Successfully deleted: [Folder] C:\Users\Lino\appdata\local\Google\Chrome\User Data\Default\Extensions\pgmfkblbflahhponhjmkcnpjinenhlnc



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.04.2013 at 13:14:29,67
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Code:

# AdwCleaner v2.200 - Datei am 05/04/2013 um 13:28:48 erstellt
# Aktualisiert am 02/04/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Lino - LINOS-HP-SCHATZ
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Lino\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\Users\Lino\AppData\Local\PackageAware

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{6536801B-F50C-449B-9476-093DFD3789E3}

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.7601.17514

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v [Version kann nicht ermittelt werden]

Datei : C:\Users\Lino\AppData\Roaming\Mozilla\Firefox\Profiles\jq11owgg.default\prefs.js

[OK] Die Datei ist sauber.

-\\ Google Chrome v26.0.1410.43

Datei : C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

-\\ Opera v [Version kann nicht ermittelt werden]

Datei : C:\Users\Lino\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] Die Datei ist sauber.

*************************

AdwCleaner[S2].txt - [1204 octets] - [05/04/2013 13:28:48]

########## EOF - C:\AdwCleaner[S2].txt - [1264 octets] ##########

Hier noch der Rest von OTL
OTL.txt

Code:

OTL logfile created on: 4/5/2013 1:40:56 PM - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Lino\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
11.96 Gb Total Physical Memory | 9.46 Gb Available Physical Memory | 79.11% Memory free
23.92 Gb Paging File | 21.34 Gb Available in Paging File | 89.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1383.58 Gb Total Space | 878.51 Gb Free Space | 63.50% Space Free | Partition Type: NTFS
Drive D: | 13.59 Gb Total Space | 1.67 Gb Free Space | 12.31% Space Free | Partition Type: NTFS
 
Computer Name: LINOS-HP-SCHATZ | User Name: Lino | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Lino\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\BlueStacks\HD-Service.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\BlueStacks\HD-SharedFolder.exe (BlueStack Systems)
PRC - C:\Program Files (x86)\BlueStacks\HD-BlockDevice.exe (BlueStack Systems)
PRC - C:\Program Files (x86)\BlueStacks\HD-Network.exe (BlueStack Systems)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\20.3.0.36\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
PRC - C:\Program Files (x86)\PDF Complete\pdfsvc.exe (PDF Complete Inc)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\HD-Agent\8ab2ef26e0f12a948693309f478b2412\HD-Agent.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\JSON\567a91db0da200e86e2bd801cbec56d5\JSON.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\302207b4fa3083899fd8ab4db98cecc5\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\dd20416f723ee13ffb4173ec1afc4ec4\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\HP.ActiveSupportLibrary\2.0.0.1__01a974bc1760f423\HP.ActiveSupportLibrary.dll ()
MOD - C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.3.0.36\wincfi39.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\ECenter\ECLibrary.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (BstHdLogRotatorSvc) -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
SRV - (BstHdAndroidSvc) -- C:\Program Files (x86)\BlueStacks\HD-Service.exe (BlueStack Systems, Inc.)
SRV - (BEService) -- C:\Program Files (x86)\Common Files\BattlEye\BEService.exe ()
SRV - (NIS) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.3.0.36\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (HP Support Assistant Service) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (HiPatchService) -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Hi-Rez Studios)
SRV - (NOBU) -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (GameConsoleService) -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (pdfcDispatcher) -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe (PDF Complete Inc)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (esgiguard) -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys File not found
DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\NISx64\1403000.024\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\NISx64\1403000.024\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\NISx64\1403000.024\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) -- C:\Windows\SysNative\drivers\NISx64\1403000.024\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) -- C:\Windows\SysNative\drivers\NISx64\1403000.024\symds64.sys (Symantec Corporation)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\NISx64\1403000.024\ironx64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NIS) -- C:\Windows\SysNative\drivers\NISx64\1403000.024\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (SMR210) -- C:\Windows\SysNative\drivers\SMR210.SYS (Symantec Corporation)
DRV:64bit: - (acedrv09) -- C:\Windows\SysNative\drivers\acedrv09.sys ()
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (acedrv11) -- C:\Windows\SysNative\drivers\acedrv11.sys (Protect Software GmbH)
DRV:64bit: - (HECIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BHDrvx64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130322.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130404.024\ex64.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130404.024\eng64.sys (Symantec Corporation)
DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130404.001\IDSviA64.sys (Symantec Corporation)
DRV - (BstHdDrv) -- C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys (BlueStack Systems)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCON/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{2ED8B296-BAB9-416C-A9EF-35CEA4A3BDAE}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
IE:64bit: - HKLM\..\SearchScopes\{4DBDB2AB-E55C-4F3C-88F0-FC101EB626C8}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{BE068418-4F0B-42FC-8601-7C894EAFAEA5}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCON/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{2ED8B296-BAB9-416C-A9EF-35CEA4A3BDAE}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
IE - HKLM\..\SearchScopes\{4DBDB2AB-E55C-4F3C-88F0-FC101EB626C8}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
IE - HKLM\..\SearchScopes\{BE068418-4F0B-42FC-8601-7C894EAFAEA5}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\..\SearchScopes\{06788F9B-8CFA-49CE-B630-3AD0844FFE33}: "URL" = hxxp://at.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
IE - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\..\SearchScopes\{18004914-DE5C-4661-B8C9-94CF23D89580}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=de_US&apn_ptnrs=U3&apn_dtid=YYYYYYYYAT&apn_uid=70071C2E-C882-45B3-8D47-837AA0B3BF97&apn_sauid=EFE5B83C-A339-4F79-A488-069FE304DEE6
IE - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=937811"
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0:  File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.110.0: C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.138.0: C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn\ [2013/04/05 13:34:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFFPlgn\ [2013/03/10 20:37:16 | 000,000,000 | ---D | M]
 
[2012/07/19 04:19:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lino\AppData\Roaming\Mozilla\Extensions
[2011/04/15 17:15:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lino\AppData\Roaming\Mozilla\Firefox\extensions
[2011/04/15 17:15:12 | 000,000,000 | ---D | M] (XfireXO) -- C:\Users\Lino\AppData\Roaming\Mozilla\Firefox\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
[2013/03/11 18:01:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lino\AppData\Roaming\Mozilla\Firefox\Profiles\jq11owgg.default\extensions
[2011/08/26 00:37:49 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\Lino\AppData\Roaming\Mozilla\Firefox\Profiles\jq11owgg.default\extensions\battlefieldheroespatcher@ea.com
[2012/05/17 22:21:28 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Lino\AppData\Roaming\Mozilla\Firefox\Profiles\jq11owgg.default\extensions\ich@maltegoetz.de
[2012/02/11 16:10:00 | 000,000,000 | ---D | M] (MyTools extension) -- C:\Users\Lino\AppData\Roaming\Mozilla\Firefox\Profiles\jq11owgg.default\extensions\info@my-tools-app.com
[2013/03/08 16:40:59 | 000,213,444 | ---- | M] () (No name found) -- C:\Users\Lino\AppData\Roaming\Mozilla\Firefox\Profiles\jq11owgg.default\extensions\torntv@torntv.com.xpi
[2012/05/09 14:40:55 | 000,004,404 | ---- | M] () (No name found) -- C:\Users\Lino\AppData\Roaming\Mozilla\Firefox\Profiles\jq11owgg.default\extensions\youtubeunblocker@unblocker.yt.xpi
[2012/02/11 16:05:51 | 000,000,544 | ---- | M] () -- C:\Users\Lino\AppData\Roaming\Mozilla\Firefox\Profiles\jq11owgg.default\searchplugins\MyTools.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\pdf.dll
CHR - plugin:  (Enabled) = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\chromeNPAPI.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.4.6_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Adblock Plus = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\
CHR - Extension: Google-Suche = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Norton Identity Protection = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.3.2.10_0\
CHR - Extension: DVDVideoSoft Browser Extension = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\
CHR - Extension: Google Mail = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: YouTube = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Adblock Plus = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\
CHR - Extension: Google-Suche = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Norton Identity Protection = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.3.2.10_0\
CHR - Extension: DVDVideoSoft Browser Extension = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\
CHR - Extension: Google Mail = C:\Users\Lino\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2013/04/03 13:34:07 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll File not found
O2 - BHO: (no name) - {0931BD3F-547E-45C1-B133-D0E995645DBA} - No CLSID value found.
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.3.0.36\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.3.0.36\IPS\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3:64bit: - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - !{BDE58274-7A2A-4682-8C47-A379DD9E36CB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{40c3cc16-7269-4b32-9531-17f2950fb06f} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{BDE58274-7A2A-4682-8C47-A379DD9E36CB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{c840e246-6b95-475e-9bd7-caa1c7eca9f2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.3.0.36\coIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000..\Run: [GoogleChromeAutoLaunch_3A790C4566138A29127FA69389D34642] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe (Hewlett-Packard)
O4 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000..\Run: [Steam] C:\Program Files (x86)\Stam\steam.exe (Valve Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPath = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Lino\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - Reg Error: Value error. File not found
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Lino\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - Reg Error: Value error. File not found
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\..Trusted Domains: blank ([]about in Local intranet)
O15 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3419521695-173782897-1149873748-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.110.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.53.2.cab (Battlefield Play4Free Updater)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7D5A217E-9DD0-4168-BBE9-01BEE99BA879}: DhcpNameServer = 10.0.0.138
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\gopher - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013/04/05 13:38:56 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Lino\Desktop\OTL.exe
[2013/04/05 13:08:30 | 000,000,000 | ---D | C] -- C:\JRT
[2013/04/05 13:06:29 | 000,551,171 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Lino\Desktop\JRT.exe
[2013/04/03 15:10:29 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/04/03 13:45:55 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013/04/03 13:12:38 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/04/03 13:12:38 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/04/03 13:12:38 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/04/03 13:10:28 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/04/03 13:03:27 | 005,046,606 | R--- | C] (Swearware) -- C:\Users\Lino\Desktop\ComboFix.exe
[2013/04/03 12:55:31 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/04/02 21:59:24 | 000,000,000 | ---D | C] -- C:\Users\Lino\Desktop\scripts
[2013/04/02 21:59:24 | 000,000,000 | ---D | C] -- C:\Users\Lino\Desktop\Data
[2013/04/01 13:41:31 | 000,000,000 | ---D | C] -- C:\Users\Lino\Documents\Arma 3 Alpha Lite
[2013/04/01 13:41:30 | 000,000,000 | ---D | C] -- C:\Users\Lino\AppData\Local\Arma 3 Alpha Lite
[2013/04/01 01:55:50 | 000,000,000 | ---D | C] -- C:\Users\Lino\Desktop\FORTRAN_A10_CAMOPACK
[2013/03/31 18:57:14 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023x.sys
[2013/03/31 18:57:14 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023.sys
[2013/03/31 18:47:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2013/03/31 18:47:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
[2013/03/21 18:58:24 | 000,000,000 | ---D | C] -- C:\Users\Lino\AppData\Roaming\Play withSIX
[2013/03/21 18:57:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIX Networks
[2013/03/21 16:41:16 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\SuperMUI
[2013/03/19 13:59:11 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\Lino\Desktop\aswMBR.exe
[2013/03/18 23:20:14 | 000,000,000 | ---D | C] -- C:\Users\Lino\Desktop\SCP - Containment Breach v0.6.5
[2013/03/18 17:38:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1C Company
[2013/03/18 17:34:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\1C Company
[2013/03/17 01:01:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
[2013/03/17 01:01:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BlueStacks
[2013/03/17 01:00:23 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueStacksSetup
[2013/03/17 01:00:23 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueStacks
[2013/03/16 17:26:51 | 000,000,000 | ---D | C] -- C:\mbar
[2013/03/15 17:04:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ProtectDisc Driver Installer
[2013/03/15 17:04:02 | 000,000,000 | ---D | C] -- C:\Users\Lino\AppData\Roaming\ProtectDISC
[2013/03/15 16:57:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Theatre of War 3
[2013/03/14 00:00:10 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2013/03/13 18:09:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/03/13 18:09:33 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013/03/13 18:09:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/03/13 15:09:10 | 000,735,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/03/13 15:09:08 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013/03/13 15:09:07 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/03/13 15:09:07 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/03/13 15:09:07 | 000,134,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013/03/13 15:09:07 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/03/13 15:09:07 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/03/12 18:14:54 | 000,000,000 | ---D | C] -- C:\Users\Lino\AppData\Local\HP MediaSmart Video
[2013/03/11 20:15:30 | 000,000,000 | ---D | C] -- C:\Users\Lino\AppData\Roaming\Malwarebytes
[2013/03/11 20:15:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/03/11 18:51:51 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/03/09 20:51:48 | 000,000,000 | ---D | C] -- C:\Users\Lino\AppData\Roaming\Canneverbe Limited
[2013/03/09 20:51:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
[2013/03/09 20:51:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDBurnerXP
[2013/03/08 19:22:43 | 000,000,000 | ---D | C] -- C:\4c3afa1d91612de34882800ac3
[2013/03/08 19:19:46 | 067,823,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MRT.exe
[2013/03/08 16:54:52 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2013/03/06 14:37:01 | 000,398,600 | ---- | C] (Electronic Arts Inc.) -- C:\Users\Lino\Desktop\Spore.exe
 
========== Files - Modified Within 30 Days ==========
 
[2013/04/05 13:43:02 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/04/05 13:42:31 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/05 13:42:30 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/05 13:39:14 | 001,641,292 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/04/05 13:39:14 | 000,707,088 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013/04/05 13:39:14 | 000,660,706 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/04/05 13:39:14 | 000,152,680 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013/04/05 13:39:14 | 000,124,896 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/04/05 13:38:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Lino\Desktop\OTL.exe
[2013/04/05 13:32:35 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/05 13:31:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/04/05 13:30:32 | 1041,559,550 | -HS- | M] () -- C:\hiberfil.sys
[2013/04/05 13:27:12 | 000,613,083 | ---- | M] () -- C:\Users\Lino\Desktop\adwcleaner.exe
[2013/04/05 13:06:23 | 000,551,171 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Lino\Desktop\JRT.exe
[2013/04/05 12:45:09 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/03 13:34:07 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/04/03 13:03:16 | 005,046,606 | R--- | M] (Swearware) -- C:\Users\Lino\Desktop\ComboFix.exe
[2013/04/02 13:14:45 | 000,000,892 | ---- | M] () -- C:\Users\Public\Desktop\Nexus Mod Manager.lnk
[2013/04/01 19:48:42 | 000,002,185 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/04/01 07:28:24 | 002,481,110 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1403000.024\Cat.DB
[2013/03/31 19:01:36 | 000,000,221 | ---- | M] () -- C:\Users\Lino\Desktop\Arma 3 Alpha Lite.url
[2013/03/21 16:17:56 | 000,000,328 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForLino.job
[2013/03/20 15:31:03 | 000,030,247 | ---- | M] () -- C:\Users\Lino\Desktop\TDSSKiller.2.8.16.0_20.03.2013_13.33.00_log.rar
[2013/03/20 14:27:19 | 000,000,512 | ---- | M] () -- C:\Users\Lino\Desktop\MBR.dat
[2013/03/19 13:59:01 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\Lino\Desktop\aswMBR.exe
[2013/03/18 22:08:01 | 000,000,356 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForLINOS-HP-SCHATZ$.job
[2013/03/18 17:39:01 | 000,002,274 | ---- | M] () -- C:\Users\Lino\Desktop\Men of War. Assault Squad.lnk
[2013/03/17 01:01:37 | 000,001,789 | ---- | M] () -- C:\Users\Public\Desktop\Apps.lnk
[2013/03/17 01:01:35 | 000,001,809 | ---- | M] () -- C:\Users\Public\Desktop\Start BlueStacks.lnk
[2013/03/16 20:11:33 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\000030A5.LCS
[2013/03/16 14:06:57 | 000,002,521 | ---- | M] () -- C:\Users\Lino\Desktop\Norton Internet Security.lnk
[2013/03/13 18:09:34 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/13 15:44:57 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/03/13 15:44:57 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/03/10 20:22:36 | 000,177,312 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/03/10 20:22:36 | 000,007,466 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/03/10 20:22:36 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/03/09 20:51:39 | 000,001,951 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2013/03/08 18:50:37 | 000,000,017 | ---- | M] () -- C:\Users\Lino\AppData\Local\resmon.resmoncfg
[2013/03/08 16:57:38 | 000,001,539 | ---- | M] () -- C:\Users\Lino\Desktop\_Endless.lua - Verknüpfung.lnk
 
========== Files Created - No Company Name ==========
 
[2013/04/05 13:27:19 | 000,613,083 | ---- | C] () -- C:\Users\Lino\Desktop\adwcleaner.exe
[2013/04/03 13:12:38 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/04/03 13:12:38 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/04/03 13:12:38 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/04/03 13:12:38 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/04/03 13:12:38 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/03/31 19:01:36 | 000,000,221 | ---- | C] () -- C:\Users\Lino\Desktop\Arma 3 Alpha Lite.url
[2013/03/20 15:30:11 | 000,030,247 | ---- | C] () -- C:\Users\Lino\Desktop\TDSSKiller.2.8.16.0_20.03.2013_13.33.00_log.rar
[2013/03/20 14:27:19 | 000,000,512 | ---- | C] () -- C:\Users\Lino\Desktop\MBR.dat
[2013/03/18 17:39:00 | 000,002,274 | ---- | C] () -- C:\Users\Lino\Desktop\Men of War. Assault Squad.lnk
[2013/03/17 01:01:37 | 000,001,789 | ---- | C] () -- C:\Users\Public\Desktop\Apps.lnk
[2013/03/17 01:01:35 | 000,001,809 | ---- | C] () -- C:\Users\Public\Desktop\Start BlueStacks.lnk
[2013/03/16 14:06:57 | 000,002,521 | ---- | C] () -- C:\Users\Lino\Desktop\Norton Internet Security.lnk
[2013/03/15 17:04:04 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\000030A5.LCS
[2013/03/13 18:09:34 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/09 20:51:39 | 000,001,951 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2013/03/09 20:51:39 | 000,001,901 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
[2013/03/08 18:50:37 | 000,000,017 | ---- | C] () -- C:\Users\Lino\AppData\Local\resmon.resmoncfg
[2012/07/28 17:16:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2012/05/03 04:55:52 | 000,042,392 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2012/04/18 15:07:47 | 000,280,792 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/04/18 15:07:47 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/02/14 19:21:01 | 000,000,092 | ---- | C] () -- C:\Users\Lino\AppData\Local\fusioncache.dat
[2012/02/02 19:40:13 | 000,000,043 | ---- | C] () -- C:\Windows\gswin32.ini
[2012/01/10 23:11:04 | 000,000,000 | ---- | C] () -- C:\Users\Lino\AppData\Local\{A739A7A1-0946-4D4A-8BBF-FC4D7C5EBC93}
[2011/09/28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/09/15 15:16:38 | 000,000,839 | ---- | C] () -- C:\Users\Lino\AppData\Local\recently-used.xbel
[2011/09/15 14:56:16 | 000,000,741 | ---- | C] () -- C:\Users\Lino\AppData\Roaming\SMRBackup210.dat
[2011/09/10 15:36:31 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2011/04/20 03:39:16 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2011/04/10 14:42:18 | 000,000,936 | ---- | C] () -- C:\Windows\eReg.dat
[2004/01/26 17:15:29 | 000,233,472 | R--- | C] () -- C:\Users\Lino\AppData\Roaming\MafiaSetup.exe
 
========== ZeroAccess Check ==========
 
[2009/07/14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >


Linschko 05.04.2013 13:08

Und extra.txt weil das ganze 242 Zeichen zu lang war.

Code:

OTL Extras logfile created on: 4/5/2013 1:40:56 PM - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Lino\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
11.96 Gb Total Physical Memory | 9.46 Gb Available Physical Memory | 79.11% Memory free
23.92 Gb Paging File | 21.34 Gb Available in Paging File | 89.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1383.58 Gb Total Space | 878.51 Gb Free Space | 63.50% Space Free | Partition Type: NTFS
Drive D: | 13.59 Gb Total Space | 1.67 Gb Free Space | 12.31% Space Free | Partition Type: NTFS
 
Computer Name: LINOS-HP-SCHATZ | User Name: Lino | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
 
[HKEY_USERS\S-1-5-21-3419521695-173782897-1149873748-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{10CFEEBB-3092-42C8-9468-09788A278121}" = lport=445 | protocol=6 | dir=in | app=system |
"{12DA0150-1859-4DAC-AB3C-AE9A8C73CC9F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{28F74F72-B461-486B-A851-765945E7B493}" = rport=445 | protocol=6 | dir=out | app=system |
"{2D1FB208-2512-497A-8F7D-53FB75B1CE7C}" = lport=139 | protocol=6 | dir=in | app=system |
"{3417F545-BC65-433B-BE11-B9C64076BD2D}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{443FF496-A39E-4100-97D8-3D1F648F695E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{473AA302-595C-4E88-9127-6825C7C72C76}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{5384AC5F-7950-4D74-9B33-C6DA83E52CD8}" = rport=138 | protocol=17 | dir=out | app=system |
"{5827A281-0250-444A-AC8C-35CAE13DCBD7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9F79F531-FC61-4937-A1A1-5A1AC898E176}" = lport=138 | protocol=17 | dir=in | app=system |
"{A7959854-43E7-432E-A171-2A02DD622747}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AA8CC2C9-4587-489D-A238-B2CACFE0F82F}" = rport=137 | protocol=17 | dir=out | app=system |
"{AC0ECD69-383F-40F7-A4DB-C92496896DD2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B736461C-AB8B-4E4C-80E3-C8E82D828843}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CAF55A21-DC61-4603-9B62-2F27B15984D2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{CB3E1113-116E-4A13-9AE3-8BE289F927E9}" = rport=139 | protocol=6 | dir=out | app=system |
"{CC6AEB8A-1BF3-4FDF-BAB9-9490A8360E96}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{DD34B041-51D2-4F5F-B1FA-A68CE7D0CFD2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DD4784E0-4B01-423E-8DC0-65653FC233F8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E434A6CD-C1D8-452F-AFFB-26BFAB664744}" = lport=137 | protocol=17 | dir=in | app=system |
"{E59194DA-E40A-4935-9F33-3F73096C64F0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E66697BE-AE0F-4A7F-91DF-664FDE7F1821}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{EB41E0BE-002B-4678-B5B7-39A876CDB0B7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EDC2DDFA-90EF-46F8-A752-D47ABFFA8A23}" = rport=10243 | protocol=6 | dir=out | app=system |
"{EE222143-EFD1-4F3D-B5F0-3CA5B3DA8428}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F0DD5DDE-3437-48DF-AB11-5EE85BDD451D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FE92B2C7-CFBE-4AC7-A143-01746B4E75CE}" = lport=10243 | protocol=6 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{041E265A-BCFC-4D90-A7CA-69B0C5C59885}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\bully scholarship edition\bully.exe |
"{042427B1-7731-4D80-AC76-D9ECDA854B68}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{05CA74FE-7EC5-4200-AF78-99E1F85132E9}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\counter-strike source\hl2.exe |
"{05EB65D8-E128-4D2B-9BE7-4DBDA9DF12E2}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{0617C06B-79B3-42BE-9E26-8421F1447296}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\die schlacht um mittelerde ii\game.dat |
"{07191776-E6DA-480B-8066-F77521308919}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{0752F3E1-81B7-42DE-BF02-3C6F28CFA2DC}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\counter-strike source\hl2.exe |
"{08ABCB71-7C1F-472E-B4E9-1462A3598BE9}" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{08D1F74B-3F2F-436C-8A39-E3BA4D778FF2}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\dlcsetup\pmc\datacachepreprocessor.exe |
"{0968DACC-6820-463E-9505-212164087981}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\red orchestra 2\binaries\win32\rogame.exe |
"{09A71FDA-7C03-44AD-8CE8-4A0AFA4FC42B}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{09AD963E-8290-4360-BD8E-8EA95E7579E6}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{0BB0604C-0D79-47FF-8F46-99FCE328373B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{0CC8E6C3-D8DC-47DC-ACFB-BF7B766E69B7}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 3 alpha lite\arma3demo.exe |
"{107AE318-9CE5-4F38-A096-109FC601FFFB}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{12BEEC44-8AF9-464B-9BE7-72235CAB9433}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{183EF4AD-54C6-4DE2-AB41-8D2E8A39BE33}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{190A1842-60BD-47CC-8EF1-4396A19EE709}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{197BEF60-159F-4B08-8D86-6A3D2D04D7C5}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1AA2C705-3D1C-4FD9-A498-EE9C24369E1B}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd |
"{215872D7-DC17-483E-9DC0-1935ADA94651}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{21FB602D-DF07-461A-8BD4-5A032957FFE0}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{22396E9B-9D86-4117-8DB0-0A7F54ABBB83}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\eflc\launcheflc.exe |
"{2249CBDD-BD95-4990-B424-CA8B16F6C8DB}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{22F0EB39-E8EE-493B-9E9B-154630EB6964}" = protocol=17 | dir=in | app=c:\program files (x86)\firefly studios\stronghold 2\stronghold2.exe |
"{231A5875-B5FF-4206-AAA5-1A9AA14AB1A6}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{24704394-639D-42E7-94BC-26B419CD4474}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{277BB473-5C5C-4A2B-ADFC-5B3B4820201A}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\dlcsetup\pmc\datacachepreprocessor.exe |
"{2794B230-7027-4A0E-915E-F0AC1E2F420C}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\team fortress classic\hl.exe |
"{279F4741-37AC-4919-B558-862BAB76FD3D}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\apocalypseweekend\system\apocalypseweekend.exe |
"{2A5D31CF-2109-42A0-A5A4-F0AE897573C7}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\photo\hpmediasmartphoto.exe |
"{2A6ABC56-4DB5-46A7-8FC9-1AEC01B6732E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2AC2C2CD-2633-48F0-BE96-0D3DA41383B6}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"{2C0DF6EA-75D4-431D-9646-3B1334B0C2A1}" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe |
"{2C1E090B-4AED-4550-B374-830CEF9B393C}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\music\hptouchsmartmusic.exe |
"{2DC51445-523D-4144-AEE2-2BFA43FD673F}" = protocol=6 | dir=in | app=c:\program files (x86)\windows ilivid toolbar\toolbar\dtuser.exe |
"{2EA9B41C-25B0-4A28-98D8-EBFFC8EBA4D8}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\mafia ii\pc\mafia2.exe |
"{2FF8424F-3215-4754-9E48-FC0BDF985688}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\just cause 2\justcause2.exe |
"{316EF4C6-C9F6-440A-B869-2CADCFD1A432}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{34089D4F-955E-4C8C-8861-DDFFDBCE61B9}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{36CE20FD-2841-47A0-A805-FA495B384406}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\universe sandbox\universe sandbox.exe |
"{37528C66-A982-4BC8-9BAC-EBB37AC04700}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{391A13E8-05BB-4E7C-8EF1-9221B9C74CBA}" = protocol=17 | dir=in | app=c:\program files (x86)\a1 telekom austria\breitband-internet-installation\fixnet installer\installer.exe |
"{39C153D8-021C-46C6-BF54-8F9B44648778}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr8.exe |
"{3EC3F485-E0CA-461E-920B-B614EF34F518}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{3EC4E62E-8D68-4FF8-844D-B3282996CEEB}" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{3F96BF6E-CF5B-45EE-A301-7DA952DE9778}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{3FFE020A-6DA3-41ED-A621-19B6A6FD9350}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{40153583-D606-43FA-9F4A-AF908C94C28F}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{405A5353-7991-4B01-A0B7-827E63FA0F99}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{411003DF-9782-4210-BF1E-2095C7CF891B}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{4145046B-6B08-4D92-A83B-3139D9AADD1D}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\ultimate doom\base\dosbox.exe |
"{4181DF07-239B-4EDE-AEF0-68389B4BB1F0}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\red orchestra 2\binaries\win32\rogame.exe |
"{439633E8-107F-42C0-94DA-0801A2EC6B93}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{4402BBEB-F562-4F04-9A54-17825140D18E}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\thief deadly shadows\system\runme.exe |
"{448B6541-CA88-4B1B-A33A-C59526F3636D}" = protocol=17 | dir=in | app=c:\program files (x86)\a1 telekom austria\breitband-internet-installation\fixnet installer\installer.exe |
"{4906AE23-14BF-4F47-A3D5-0EDCF3B6D069}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{49A5097D-9FB5-41FC-95E5-AB4F9DFAF3DF}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{49FB398E-239B-4C3D-B9CC-72578D3419F3}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\dlcsetup\baf\datacachepreprocessor.exe |
"{4AE16098-9EE6-4F4B-A78C-F7F6888040F7}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 3 alpha lite\arma3demo.exe |
"{4C9D2B10-947E-45C5-B542-EF4158197052}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\dlcsetup\baf\datacachepreprocessor.exe |
"{4CFB497C-F082-4041-AF25-4CF86ED28EE4}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\bully scholarship edition\bully.exe |
"{4D7DA73F-940A-4EEA-9DE1-E368B9D40E5E}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\half-life\hl.exe |
"{5013FFF4-0370-4E07-A2DE-1B0C821E241C}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{515220B3-C373-4E23-829D-321C40A4D9DF}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\sharethepain\system\postal2mp.exe |
"{51CBB35A-A925-4E2B-9EBE-86E03A1DF3B3}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\half-life\hl.exe |
"{52694DC5-6801-4CF5-A9C0-9C13373BF346}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\system\postal2.exe |
"{547C9901-4BAF-4FA6-A2B4-C7C0DE192620}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\die schlacht um mittelerde ii\game.dat |
"{569D1A6F-8B82-4EB9-A08D-B72A244E21D1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{59792F67-3546-44D9-AC24-4EAA88FF47A0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5B62A528-EEB7-4393-B6F5-987B74C21228}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\video\hpmediasmartvideo.exe |
"{5C30D5F6-280B-4713-8A5F-822F0CFF43DC}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{5C501B2D-BAC2-4982-A582-8E201A0D4FF5}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{5CA74262-D1E9-41A0-ADFF-D52AFBC6AF78}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\apb reloaded\binaries\vivoxvoiceservice.exe |
"{5D6D944F-0ADB-4C8F-A025-7EC7358677EB}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\planetside 2\launchpad.exe |
"{5F8FBB4D-BB57-4481-BD63-33A02B2C2668}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\apb reloaded\binaries\vivoxvoiceservice.exe |
"{6762E77A-27AA-4722-8DAF-0132025ACD05}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{67B7333D-AD22-4CE6-B040-1BA7A85DC755}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{69A23C0E-4FAC-443D-AC8B-E59805E35543}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd |
"{6C960376-7E6F-4DF1-9F7B-C342FAF8D085}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"{6D5CB057-1BD1-4451-B495-BE439F244C20}" = protocol=6 | dir=in | app=c:\program files (x86)\lucasarts\star wars empire at war\gamedata\sweaw.exe |
"{6DCB77D4-685B-4F05-ADC7-78F389FC754E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6E86AD9B-36C0-4574-99A9-E7090CEC4380}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\system\postal2.exe |
"{6F46088A-BA29-437C-B245-158B050005A1}" = protocol=17 | dir=in | app=c:\program files (x86)\lucasarts\star wars empire at war\gamedata\sweaw.exe |
"{70600CBA-795D-4B14-BF77-826E45DB0566}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\stalker shadow of chernobyl\bin\xr_3da.exe |
"{708C15D1-FB97-484C-A0D2-5B9B3D381E66}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\amnesia the dark descent\launcher.exe |
"{727F6855-1159-4A01-9038-05CCED15E51A}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\sharethepain\system\postal2mp.exe |
"{73773B41-30A4-4FB2-9864-16E3219EAFCA}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{73DE6D44-EB69-4B3E-8CE5-B9F63F5D3B69}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{7542D122-1C41-4D43-BEBD-B99B1EB65A7A}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\red orchestra 2\binaries\win32\rogame.exe |
"{7578A1EC-EA62-4BC3-8FCD-A1D288A58CE8}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2\arma2.exe |
"{786B29BA-D5B0-454A-9693-89FD671E8B31}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\skyrimlauncher.exe |
"{797423E8-D163-49ED-9447-946C4337D177}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{79FC98EF-67D5-4526-8EBA-9F6A6AE802CA}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\ultimate doom\base\dosbox.exe |
"{7C72A588-C40C-4661-A355-91E900892F69}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{7DFA5081-9DB5-4B5F-982E-41909D11EAC2}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{80E3ABD7-9023-4DF2-AD82-860C07784E72}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{8148C999-2D57-4531-ABD0-631D7CF02A1F}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\amnesia the dark descent\launcher.exe |
"{82655D6C-7266-45EE-B9A7-BCC7C202C8D3}" = protocol=17 | dir=in | app=c:\program files (x86)\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{87737410-920E-4FCA-B0EC-5C5B6B4066DD}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{88A3C632-1613-4233-8DBE-E6E9A9467674}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2\arma2.exe |
"{8B42A354-D1D9-43BD-B6C3-1317C8E511B4}" = protocol=6 | dir=in | app=c:\program files (x86)\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{8C60F231-E354-482C-A168-279942FC4D8D}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\team fortress classic\hl.exe |
"{8D784637-4D26-4C35-B1DD-8894030504C4}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{8FE43E82-6765-41B0-A2C5-CF4ABDB5DC5B}" = protocol=6 | dir=in | app=c:\program files (x86)\a1 telekom austria\breitband-internet-installation\fixnet installer\installer.exe |
"{959CE94B-43C8-488D-BF05-4E247F1B55E2}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{96491AC7-2427-4256-98DD-D5EF855D4F67}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\universe sandbox\universe sandbox.exe |
"{9A709FE0-F833-48A6-9EEA-561DE3D15396}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\stalker shadow of chernobyl\bin\xr_3da.exe |
"{9D9ACECE-D462-44E4-8F24-B3B1EB89C989}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\die schlacht um mittelerde ii\game.dat |
"{9DA44E29-4D97-4DAE-B773-9D9E0E34B6C7}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\just cause 2\justcause2.exe |
"{A03377C5-252E-4E7B-B8A6-46BA783F8F58}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\thief deadly shadows\system\runme.exe |
"{A0D544F5-BC3B-4F83-9309-CF7320DDF630}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\opposing force\hl.exe |
"{A5D9F0A9-12DE-47F4-AFD4-BB2B20A7DC2E}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\red orchestra 2\binaries\win32\rogame.exe |
"{A9FCEEA1-D95B-4EC0-9A0C-A27740E6DC32}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\metro 2033\metro2033.exe |
"{ABD6AF2A-222E-40B8-83A2-5697C5BC4EE8}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{ABE4E7E6-BA0B-44C1-A86D-63BF1317069E}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{AFBA30B3-180A-4BC2-850D-06AA061C83D6}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"{B0799AB4-5631-4C37-9D39-8B14E83B2E8C}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{B100E9E8-3357-4D4C-A5AF-E47696308234}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{B59851EB-496B-4392-81D4-EDDD07FE3403}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\planetside 2\launchpad.exe |
"{B7471AE4-AF86-49CE-8EAA-5DD4253B3767}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{B76964E4-1340-46D6-ACD4-94CD5A06E5AA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BAD6D84B-34F5-4458-9A1A-8F1A0F71E294}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\skyrimlauncher.exe |
"{C8CC817E-F8EB-433F-B9A9-672FD6C02FE5}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{C8EA2508-D29B-4087-9D43-5E607EADF845}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{CB3BDA8F-F0EC-4E2A-905E-1CCF1267A34B}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"{CB51E8A4-D941-4CA8-A7A5-3CF64C978E68}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\opposing force\hl.exe |
"{CCD944B7-BDB4-462F-9EEF-C517796F826A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{CDF059F2-866C-4A4D-8FD7-851D0F5DE9A5}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\die schlacht um mittelerde ii\game.dat |
"{CE884939-3BD9-4C18-AC96-1ACD3FAB1A6F}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\payday the heist\payday_win32_release.exe |
"{D1410297-B02B-49FB-A9A3-61735D900B8A}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{D2CB4996-BC51-4D1E-8C91-B7B12D59E7D1}" = protocol=6 | dir=in | app=c:\program files (x86)\firefly studios\stronghold 2\stronghold2.exe |
"{D3E2573C-6B52-45C9-8ADE-DDE207930279}" = protocol=6 | dir=out | app=system |
"{D47C6539-983D-4B5D-A218-15ED3FDEF06C}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\mafia ii\pc\mafia2.exe |
"{D603BC43-76BC-47E8-98E7-C4E2ADD5FD12}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D940BED9-2C23-4509-8999-450D46330F6C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DA86669E-CEBF-45B8-B079-7E18C9BCD4BE}" = protocol=6 | dir=in | app=c:\program files (x86)\easybits for kids\programs\my first browser\myfirstbrowser.exe |
"{DABB9F36-0222-45E4-84CF-96F294CD8849}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\payday the heist\payday_win32_release.exe |
"{DBA0BEE4-07A8-4AAB-BCD5-27528B3ED30C}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{DD0DF7C4-289D-4BE6-8B0B-98A3892575B1}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{DD596F3A-9601-4369-90BA-300939E61E3F}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\creationkit.exe |
"{DEDE2CFB-4E53-4C81-848B-79EFFF1C69B3}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\apb reloaded\binaries\apb.exe |
"{E2E1550A-77BF-40CC-856E-D88257715CE1}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 free\arma2free.exe |
"{E3066BCB-5819-4CB4-AD1B-02F0917E05BD}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\creationkit.exe |
"{E36021BD-D5AE-4A5C-A959-C7A57EBDE4AA}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{E39A3913-E981-4942-BA52-75B87BE89818}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{E4B455E6-750F-418D-B3BD-704AE6B0D33A}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E5B56675-2D2C-49F0-806C-8E36A04F878F}" = protocol=6 | dir=in | app=c:\program files (x86)\a1 telekom austria\breitband-internet-installation\fixnet installer\installer.exe |
"{E5CE8015-BB93-40F7-B7B0-67A7F13EA763}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\eflc\launcheflc.exe |
"{E71FA8F9-31BD-40D2-A2A3-C601C28311C8}" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe |
"{E8384A92-297A-4835-8C2D-FB1E3FB855ED}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steam.exe |
"{E909C2F9-6541-4302-803E-B6DC09C9ED6E}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 free\arma2free.exe |
"{ED858269-CD82-4E17-B977-516BC85EAD96}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\creationkit.exe |
"{ED9215B5-AE64-464C-93FA-70F9BB9684F5}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\apocalypseweekend\system\apocalypseweekend.exe |
"{EEF4B42C-2629-496B-AB12-AA7FB59546A0}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\skyrimlauncher.exe |
"{F021A178-EB8A-4535-B4D7-476AAC91B4A3}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\skyrimlauncher.exe |
"{F1232109-D860-4DFD-A41D-5087A2FBE469}" = protocol=17 | dir=in | app=c:\program files (x86)\windows ilivid toolbar\toolbar\dtuser.exe |
"{F5607BF0-FC4A-475A-B7DC-0A7CC6A6DAAB}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{F57E47E0-3402-4439-8485-46856E9EC9C8}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\creationkit.exe |
"{F713E0E0-D9B1-458A-855C-705967A8FD4B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{F731D8F3-8541-4671-AB89-8A6917AEF3D5}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{F8A0ED63-36D8-472D-A8BE-B12B25B7F1DA}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F9DEC007-2874-42CC-A5CB-DA54E012F6C2}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\apb reloaded\binaries\apb.exe |
"{FA2E3388-D4C6-42E3-94CC-B2E806A6A70A}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\metro 2033\metro2033.exe |
"{FB5617ED-B2BC-49FF-8C19-CD3B6E253C80}" = protocol=17 | dir=in | app=c:\program files (x86)\easybits for kids\programs\my first browser\myfirstbrowser.exe |
"{FBDC5E8A-0C5E-4D03-B0D1-8FC3ABC70E20}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steam.exe |
"{FC083DBE-E8C1-49B2-8989-CF0562BCF2DC}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{FD2C3003-5F3C-40A7-A4BE-E19814E6CE4F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{1B8FC019-4D86-45AB-814D-9DBB741C5BEF}C:\program files (x86)\rockstar games\eflc\eflc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\eflc\eflc.exe |
"UDP Query User{A9B47F8A-4468-406A-B8E7-1CE44D0977C6}C:\program files (x86)\rockstar games\eflc\eflc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\eflc\eflc.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{2128559D-BBCD-4744-87F0-7C0CD5CFB464}" = Windows Live Family Safety
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5B08AF35-B699-4A44-BB89-3E51E70611E8}" = HP MediaSmart SmartMenu
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6281459C-49C7-49C6-A9FE-50293675B4B2}" = Corel Graphics - Windows Shell Extension 64 Bit
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240CD}" = WinZip 16.0
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D79A02E9-6713-4335-9668-AAC7474C0C0E}" = HP Vision Hardware Diagnostics
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"6af12c54-643b-4752-87d0-8335503010de_is1" = Nexus Mod Manager
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"UDK-f24ec637-dde0-4842-ae14-a26395f54452" = PARANORMAL - BETA 4
"WinRAR archiver" = WinRAR 4.11 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{511DE7EA-AA68-4D7A-A2E3-0E7B5186B822}" = CorelDRAW Graphics Suite X6
"_{B92076C0-C5FE-4DB1-AA8D-855430CDF098}" = Corel Graphics - Windows Shell Extension
"{0084B0C3-F376-42E3-804A-885D249282BD}" = CorelDRAW Graphics Suite X6 - IPM
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2(TM)
"{05B1529B-C423-42AA-B981-4ECA247E9FC0}" = DayZ Commander
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{086BADF8-9B1F-4E89-B207-2EDA520972D6}" = Grand Theft Auto San Andreas
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{169ADA4A-8079-4CD8-8E20-030B1A54E552}" = CorelDRAW Graphics Suite X6 - DE
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1D108D70-E7D1-4089-9A0A-99629C4D0CB8}" = Morrowind
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1ED31028-6D65-4CFD-AD03-8E484A052FE7}" = aonUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{25D69CEE-3EE2-47FD-9A0E-5013240EC953}" = CorelDRAW Graphics Suite X6 - Common
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{318FF3D7-0C40-483B-AF92-AF36416B0AC6}" = CorelDRAW Graphics Suite X6 - Writing Tools
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{3DE92282-CB49-434F-81BF-94E5B380E889}" = Die Sims™ 3 Jahreszeiten
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{42DCB650-F003-4535-A5CD-32AD815CD2DD}" = Play withSIX
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{44EAFE3D-09A9-4478-A2BF-0EED22F4E49F}" = Die Sims™ 3 Erstelle ein Muster-Tool
"{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = Die Sims™ 3 Late Night
"{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}" = LightScribe System Software
"{4767A89A-F6A5-41B1-903C-734483739882}" = Highspeed-Internet-Installation
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{511DE7EA-AA68-4D7A-A2E3-0E7B5186B822}" = CorelDRAW Graphics Suite X6 - Setup Files
"{5454083B-1308-4485-BF17-111000038701}" = Grand Theft Auto: Episodes from Liberty City
"{5454083B-1308-4485-BF17-1110000D8301}" = Grand Theft Auto IV
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{579CA850-B2C3-43F3-A3F6-3A0AE42E8225}" = CorelDRAW Graphics Suite X6 - FontNav
"{58D68DF0-4E8B-4E9E-B425-670F9E37C1A8}" = TES Construction Set
"{5B9C7C4F-A1CB-11E0-9E40-0013D3D69929}" = Vegas Pro 10.0
"{5DF7AA5E-A1CB-11E0-A7D6-0013D3D69929}" = MSVCRT Redists
"{603C6570-2BA1-4FC6-8735-7EFA6D1F6F61}" = CorelDRAW Graphics Suite X6 - Custom Data
"{61B8B2F9-D8DA-4B24-89A9-DB09F38A4899}" = Grand Theft Auto: Episodes From Liberty City
"{62BEC144-7029-4BF4-B3F2-FA231FB9F84B}" = CorelDRAW Graphics Suite X6 - Redist
"{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}" = NVIDIA PhysX
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65761BAE-11E8-48FE-B30F-1F01011AB906}" = Die Sims™ 3 "Erstelle eine Welt"-Tool - Beta
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1
"{6F53FB68-6620-423E-B7CD-B8205655B421}" = CorelDRAW Graphics Suite X6 - PHOTO-PAINT
"{7032B400-11EC-11E0-A9BF-0013D3D69929}" = MSVCRT Redists
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72D90DB3-A16A-4545-B555-868471101833}" = HP Setup
"{74FA94F1-9566-4252-9372-E7EAFFEFE209}" = CorelDRAW Graphics Suite X6 - Capture
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{76DAEC83-AF7B-333C-8A53-83D7C7D39199}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - DEU
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7A2FF332-E4F6-4D87-9EBD-EDFF1216490F}" = CorelDRAW Graphics Suite X6 - Filters
"{7CCD75BD-5528-4FE1-90D2-392D661A2BF1}" = CorelDRAW Graphics Suite X6 - VSTA
"{7D606567-5047-451A-B49E-29FCB6012B4E}" = Microsoft Flight Simulator X: Acceleration
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7F9F6864-8CAB-440C-AF44-030D0135666D}" = CorelDRAW Graphics Suite X6
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{879E2460-18F9-48F2-B736-4E814A699504}" = CorelDRAW Graphics Suite X6 - VBA
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E87B944-4815-3C5E-947F-5035C9F64362}" = Microsoft Visual Studio Tools for Applications 2.0 Language Pack - DEU
"{90120000-0070-0000-0000-4000000FF1CE}" = Microsoft Visual Basic for Applications 7.1 (x86)
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0407-1000-0000000FF1CE}_Office14.SingleImage_{594128C9-2CDF-43CE-8103-DC100CF013B6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{904B64C4-49D8-4941-A2B6-D13D06C5CD8B}" = Controller
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = Die Sims™ 3 Traumkarrieren
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{9ED06229-1F1B-4AE2-970D-5F731E8C8C35}" = Hunting Unlimited 2010
"{9EF200A3-1CAC-462E-990B-EC902279BAAA}" = Microsoft Visual Basic for Applications 7.1 (x86) German
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AF37176A-78CA-545B-34EF-8B6A21514DD1}" = Adobe Help Manager
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B5554F9E-702A-49A7-BD52-680AA21E0032}" = Fire Department
"{B73B4A99-4173-4747-BBEC-0F05E966F9D2}" = Battlefield 1942: Secret Weapons of WWII
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B92076C0-C5FE-4DB1-AA8D-855430CDF098}" = Corel Graphics - Windows Shell Extension
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{BD5669B5-49FF-4490-B956-E9D7CB9B0ADC}" = Adobe Flash Professional CS6
"{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die Sims™ 3
"{C12631C6-804D-4B32-B0DD-8A496462F106}" = Die Sims™ 3 Einfach tierisch
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5262276-0075-498B-B80F-7D997482E4DB}" = CorelDRAW Graphics Suite X6 - Draw
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C66BF9FD-D367-4E13-8EB8-385FFEA20DB3}" = Oblivion
"{C8773FDB-D0DB-BE52-D536-F48F9886B57B}" = Adobe Download Assistant
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD9D0827-A6D6-4E2C-B31E-23F01577E27B}" = BlueStacks Notification Center
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4A17D31-2F7B-4682-AD57-467021452909}" = CorelDRAW Graphics Suite X6 - Photozoom Plugin
"{D4EFC6B7-3DA5-400D-9682-9BE287A5440E}" = CorelDRAW Graphics Suite X6 - Connect
"{D8B5C1BB-5951-422D-A4D5-451675614956}_is1" = Men of War: Assault Squad (Nur entfernen)
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDFEB503-D662-4224-82C9-37A5698FDC25}" = CorelDRAW Graphics Suite X6 - VideoBrowser
"{DE77FE3F-A33D-499A-87AD-5FC406617B40}" = HP Update
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}" = Die Sims™ 3 Lebensfreude
"{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F535B2CF-C9BB-4162-B03A-02D6971F32CC}" = Microsoft Flight Simulator X
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"7-Zip" = 7-Zip 9.20
"A2BAF Data cache removal" = ARMA 2: British Armed Forces - Data cache removal
"A2PMC Data cache removal" = ARMA 2: Private Military Company - Data cache removal
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"aonUpdate" = aonUpdate
"Arma 2 Army of The Czech Republic (LITE)" = Arma 2 Army of The Czech Republic (LITE) Uninstall
"AVS Screen Capture_is1" = AVS Screen Capture version 2.0.1
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS Video Editor_is1" = AVS Video Editor 6
"AVS Video Recorder_is1" = AVS Video Recorder 2.4
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"Battlefield 1918" = Battlefield 1918
"BattlEye A2 Free" = BattlEye (A2Free) Uninstall
"BattlEye for OA" = BattlEye for OA Uninstall
"BlueStacks App Player" = BlueStacks App Player
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Help Manager
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Controller" = Controller
"DesertCombat" = DesertCombat  0.7
"Die Gilde 2 - Gold Edition" = Die Gilde 2 - Gold Edition
"EasyBits Magic Desktop" = Magic Desktop
"FlightSim_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Microsoft Flight Simulator X: Acceleration
"Fraps" = Fraps (remove only)
"Free YouTube Download_is1" = Free YouTube Download version 3.1.42.1212
"Google Chrome" = Google Chrome
"Highspeed-Internet-Installation" = Highspeed-Internet-Installation
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{F535B2CF-C9BB-4162-B03A-02D6971F32CC}" = Microsoft Flight Simulator X
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"Mafia" = Mafia
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"My HP Game Console" = HP Game Console
"MyTools" = MyTools
"Nehrim - Am Rande des Schicksals_is1" = NehrimUninstaller
"NIS" = Norton Internet Security
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"OpenAL" = OpenAL
"PDF Complete" = PDF Complete Special Edition
"Postal 2 Demo" = Postal 2 Demo
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"PunkBusterSvc" = PunkBuster Services
"Republic at War - Deutsch 1.1" = Republic at War - Deutsch 1.1
"Republic at War 1.1" = Republic at War 1.1
"RollerCoaster Tycoon 3_is1" = RollerCoaster Tycoon 3
"RTMshadow_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Flight Simulator X
"SP1shadow_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Flight Simulator X Service Pack 1
"Steam App 202480" = Creation Kit
"Steam App 218230" = PlanetSide 2
"Steam App 219540" = ARMA 2: Operation Arrowhead Beta
"Steam App 220" = Half-Life 2
"Steam App 223470" = POSTAL 2 Complete
"Steam App 2280" = The Ultimate DOOM
"Steam App 228800" = Arma 3 Alpha Lite
"Steam App 240" = Counter-Strike: Source
"Steam App 24240" = PAYDAY: The Heist
"Steam App 33910" = ARMA 2
"Steam App 33930" = ARMA 2: Operation Arrowhead
"Steam App 35450" = Red Orchestra 2: Heroes of Stalingrad
"Steam App 380" = Half-Life 2: Episode One
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 43110" = Metro 2033
"Steam App 4500" = S.T.A.L.K.E.R.: Shadow of Chernobyl
"Steam App 48010" = LIMBO Demo
"Steam App 50130" = Mafia II
"Steam App 550" = Left 4 Dead 2
"Steam App 65700" = ARMA 2: British Armed Forces
"Steam App 65720" = ARMA 2: Private Military Company
"Steam App 6980" = Thief: Deadly Shadows
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 8190" = Just Cause 2
"Universe Sandbox" = Universe Sandbox
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WT087361" = FATE
"WT087380" = John Deere Drive Green
"WT087394" = Penguins!
"WT087396" = Polar Bowler
"WT087420" = Agatha Christie - Death on the Nile
"WT087428" = Bejeweled 2 Deluxe
"WT087453" = Chuzzle Deluxe
"WT087480" = Insaniquarium Deluxe
"WT087485" = Jewel Quest II
"WT087490" = Jewel Quest Solitaire
"WT087501" = Plants vs. Zombies
"WT087510" = Slingo Deluxe
"WT087513" = Virtual Villagers - The Secret City
"WT087519" = Wedding Dash
"WT087533" = Zuma Deluxe
"WT087536" = Diner Dash 2 Restaurant Rescue
"Xfire" = Xfire (remove only)
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3419521695-173782897-1149873748-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Haunt 1.0 64bit" = Haunt 1.0 64bit
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Tropico 4" = Tropico 4 1.00
 
========== Last 20 Event Log Errors ==========
 
[ Hewlett-Packard Events ]
Error - 10/10/2012 12:46:31 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 40  TargetSite: Void UpdateAndDetect() 
 
Error - 10/17/2012 12:02:51 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization:  TargetSite: Void UpdateAndDetect() 
 
Error - 10/24/2012 12:02:34 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 40  TargetSite: Void UpdateAndDetect() 
 
Error - 11/7/2012 1:59:23 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 20  TargetSite: Void UpdateAndDetect() 
 
Error - 11/14/2012 2:00:45 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 30  TargetSite: Void UpdateAndDetect() 
 
Error - 11/21/2012 1:03:01 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 30  TargetSite: Void UpdateAndDetect() 
 
Error - 11/21/2012 10:02:42 PM | Computer Name = Linos-HP-Schatz | Source = HPSF.exe | ID = 4000
Description =
 
Error - 11/22/2012 2:32:33 AM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088hpsa_service.exe  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 10  TargetSite: Void UpdateAndDetect() 
 
Error - 11/22/2012 7:37:56 AM | Computer Name = Linos-HP-Schatz | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261  bei HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Message:
 Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt.  StackTrace:  bei
 HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Source:
 HP.SupportFramework.Utilities    Name: HPSF.exe  Version: 07.00.01.01  Path: C:\Program
 Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe  Format: de-DE  RAM: 12247
Ram
 Utilization: 20  TargetSite: HP.SupportFramework.HPSFReporting._Property[] AddNavigationProperties()

 
Error - 11/22/2012 11:40:58 AM | Computer Name = Linos-HP-Schatz | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261  bei HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Message:
 Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt.  StackTrace:  bei
 HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Source:
 HP.SupportFramework.Utilities    Name: HPSF.exe  Version: 07.00.01.01  Path: C:\Program
 Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe  Format: de-DE  RAM: 12247
Ram
 Utilization: 10  TargetSite: HP.SupportFramework.HPSFReporting._Property[] AddNavigationProperties()

 
[ System Events ]
Error - 4/5/2013 7:31:59 AM | Computer Name = Linos-HP-Schatz | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Easybits Services for Windows" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%3
 
Error - 4/5/2013 7:35:13 AM | Computer Name = Linos-HP-Schatz | Source = Service Control Manager | ID = 7038
Description = Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser"
 mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:  %%1330    Vergewissern
 Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
 Management Console (MMC).
 
Error - 4/5/2013 7:35:13 AM | Computer Name = Linos-HP-Schatz | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%1069
 
 
< End of report >


Linschko 05.04.2013 13:09

Und extra.txt weil das ganze 242 Zeichen zu lang war.

Code:

OTL Extras logfile created on: 4/5/2013 1:40:56 PM - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Lino\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
11.96 Gb Total Physical Memory | 9.46 Gb Available Physical Memory | 79.11% Memory free
23.92 Gb Paging File | 21.34 Gb Available in Paging File | 89.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1383.58 Gb Total Space | 878.51 Gb Free Space | 63.50% Space Free | Partition Type: NTFS
Drive D: | 13.59 Gb Total Space | 1.67 Gb Free Space | 12.31% Space Free | Partition Type: NTFS
 
Computer Name: LINOS-HP-SCHATZ | User Name: Lino | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
 
[HKEY_USERS\S-1-5-21-3419521695-173782897-1149873748-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{10CFEEBB-3092-42C8-9468-09788A278121}" = lport=445 | protocol=6 | dir=in | app=system |
"{12DA0150-1859-4DAC-AB3C-AE9A8C73CC9F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{28F74F72-B461-486B-A851-765945E7B493}" = rport=445 | protocol=6 | dir=out | app=system |
"{2D1FB208-2512-497A-8F7D-53FB75B1CE7C}" = lport=139 | protocol=6 | dir=in | app=system |
"{3417F545-BC65-433B-BE11-B9C64076BD2D}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{443FF496-A39E-4100-97D8-3D1F648F695E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{473AA302-595C-4E88-9127-6825C7C72C76}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{5384AC5F-7950-4D74-9B33-C6DA83E52CD8}" = rport=138 | protocol=17 | dir=out | app=system |
"{5827A281-0250-444A-AC8C-35CAE13DCBD7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9F79F531-FC61-4937-A1A1-5A1AC898E176}" = lport=138 | protocol=17 | dir=in | app=system |
"{A7959854-43E7-432E-A171-2A02DD622747}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AA8CC2C9-4587-489D-A238-B2CACFE0F82F}" = rport=137 | protocol=17 | dir=out | app=system |
"{AC0ECD69-383F-40F7-A4DB-C92496896DD2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B736461C-AB8B-4E4C-80E3-C8E82D828843}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CAF55A21-DC61-4603-9B62-2F27B15984D2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{CB3E1113-116E-4A13-9AE3-8BE289F927E9}" = rport=139 | protocol=6 | dir=out | app=system |
"{CC6AEB8A-1BF3-4FDF-BAB9-9490A8360E96}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{DD34B041-51D2-4F5F-B1FA-A68CE7D0CFD2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DD4784E0-4B01-423E-8DC0-65653FC233F8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E434A6CD-C1D8-452F-AFFB-26BFAB664744}" = lport=137 | protocol=17 | dir=in | app=system |
"{E59194DA-E40A-4935-9F33-3F73096C64F0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E66697BE-AE0F-4A7F-91DF-664FDE7F1821}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{EB41E0BE-002B-4678-B5B7-39A876CDB0B7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EDC2DDFA-90EF-46F8-A752-D47ABFFA8A23}" = rport=10243 | protocol=6 | dir=out | app=system |
"{EE222143-EFD1-4F3D-B5F0-3CA5B3DA8428}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F0DD5DDE-3437-48DF-AB11-5EE85BDD451D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FE92B2C7-CFBE-4AC7-A143-01746B4E75CE}" = lport=10243 | protocol=6 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{041E265A-BCFC-4D90-A7CA-69B0C5C59885}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\bully scholarship edition\bully.exe |
"{042427B1-7731-4D80-AC76-D9ECDA854B68}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{05CA74FE-7EC5-4200-AF78-99E1F85132E9}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\counter-strike source\hl2.exe |
"{05EB65D8-E128-4D2B-9BE7-4DBDA9DF12E2}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{0617C06B-79B3-42BE-9E26-8421F1447296}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\die schlacht um mittelerde ii\game.dat |
"{07191776-E6DA-480B-8066-F77521308919}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{0752F3E1-81B7-42DE-BF02-3C6F28CFA2DC}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\counter-strike source\hl2.exe |
"{08ABCB71-7C1F-472E-B4E9-1462A3598BE9}" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{08D1F74B-3F2F-436C-8A39-E3BA4D778FF2}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\dlcsetup\pmc\datacachepreprocessor.exe |
"{0968DACC-6820-463E-9505-212164087981}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\red orchestra 2\binaries\win32\rogame.exe |
"{09A71FDA-7C03-44AD-8CE8-4A0AFA4FC42B}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{09AD963E-8290-4360-BD8E-8EA95E7579E6}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{0BB0604C-0D79-47FF-8F46-99FCE328373B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{0CC8E6C3-D8DC-47DC-ACFB-BF7B766E69B7}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 3 alpha lite\arma3demo.exe |
"{107AE318-9CE5-4F38-A096-109FC601FFFB}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{12BEEC44-8AF9-464B-9BE7-72235CAB9433}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{183EF4AD-54C6-4DE2-AB41-8D2E8A39BE33}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{190A1842-60BD-47CC-8EF1-4396A19EE709}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{197BEF60-159F-4B08-8D86-6A3D2D04D7C5}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1AA2C705-3D1C-4FD9-A498-EE9C24369E1B}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd |
"{215872D7-DC17-483E-9DC0-1935ADA94651}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{21FB602D-DF07-461A-8BD4-5A032957FFE0}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{22396E9B-9D86-4117-8DB0-0A7F54ABBB83}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\eflc\launcheflc.exe |
"{2249CBDD-BD95-4990-B424-CA8B16F6C8DB}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{22F0EB39-E8EE-493B-9E9B-154630EB6964}" = protocol=17 | dir=in | app=c:\program files (x86)\firefly studios\stronghold 2\stronghold2.exe |
"{231A5875-B5FF-4206-AAA5-1A9AA14AB1A6}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{24704394-639D-42E7-94BC-26B419CD4474}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{277BB473-5C5C-4A2B-ADFC-5B3B4820201A}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\dlcsetup\pmc\datacachepreprocessor.exe |
"{2794B230-7027-4A0E-915E-F0AC1E2F420C}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\team fortress classic\hl.exe |
"{279F4741-37AC-4919-B558-862BAB76FD3D}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\apocalypseweekend\system\apocalypseweekend.exe |
"{2A5D31CF-2109-42A0-A5A4-F0AE897573C7}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\photo\hpmediasmartphoto.exe |
"{2A6ABC56-4DB5-46A7-8FC9-1AEC01B6732E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2AC2C2CD-2633-48F0-BE96-0D3DA41383B6}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"{2C0DF6EA-75D4-431D-9646-3B1334B0C2A1}" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe |
"{2C1E090B-4AED-4550-B374-830CEF9B393C}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\music\hptouchsmartmusic.exe |
"{2DC51445-523D-4144-AEE2-2BFA43FD673F}" = protocol=6 | dir=in | app=c:\program files (x86)\windows ilivid toolbar\toolbar\dtuser.exe |
"{2EA9B41C-25B0-4A28-98D8-EBFFC8EBA4D8}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\mafia ii\pc\mafia2.exe |
"{2FF8424F-3215-4754-9E48-FC0BDF985688}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\just cause 2\justcause2.exe |
"{316EF4C6-C9F6-440A-B869-2CADCFD1A432}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{34089D4F-955E-4C8C-8861-DDFFDBCE61B9}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{36CE20FD-2841-47A0-A805-FA495B384406}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\universe sandbox\universe sandbox.exe |
"{37528C66-A982-4BC8-9BAC-EBB37AC04700}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{391A13E8-05BB-4E7C-8EF1-9221B9C74CBA}" = protocol=17 | dir=in | app=c:\program files (x86)\a1 telekom austria\breitband-internet-installation\fixnet installer\installer.exe |
"{39C153D8-021C-46C6-BF54-8F9B44648778}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr8.exe |
"{3EC3F485-E0CA-461E-920B-B614EF34F518}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{3EC4E62E-8D68-4FF8-844D-B3282996CEEB}" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{3F96BF6E-CF5B-45EE-A301-7DA952DE9778}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{3FFE020A-6DA3-41ED-A621-19B6A6FD9350}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{40153583-D606-43FA-9F4A-AF908C94C28F}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{405A5353-7991-4B01-A0B7-827E63FA0F99}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{411003DF-9782-4210-BF1E-2095C7CF891B}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{4145046B-6B08-4D92-A83B-3139D9AADD1D}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\ultimate doom\base\dosbox.exe |
"{4181DF07-239B-4EDE-AEF0-68389B4BB1F0}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\red orchestra 2\binaries\win32\rogame.exe |
"{439633E8-107F-42C0-94DA-0801A2EC6B93}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{4402BBEB-F562-4F04-9A54-17825140D18E}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\thief deadly shadows\system\runme.exe |
"{448B6541-CA88-4B1B-A33A-C59526F3636D}" = protocol=17 | dir=in | app=c:\program files (x86)\a1 telekom austria\breitband-internet-installation\fixnet installer\installer.exe |
"{4906AE23-14BF-4F47-A3D5-0EDCF3B6D069}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{49A5097D-9FB5-41FC-95E5-AB4F9DFAF3DF}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{49FB398E-239B-4C3D-B9CC-72578D3419F3}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\dlcsetup\baf\datacachepreprocessor.exe |
"{4AE16098-9EE6-4F4B-A78C-F7F6888040F7}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 3 alpha lite\arma3demo.exe |
"{4C9D2B10-947E-45C5-B542-EF4158197052}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\dlcsetup\baf\datacachepreprocessor.exe |
"{4CFB497C-F082-4041-AF25-4CF86ED28EE4}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\bully scholarship edition\bully.exe |
"{4D7DA73F-940A-4EEA-9DE1-E368B9D40E5E}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\half-life\hl.exe |
"{5013FFF4-0370-4E07-A2DE-1B0C821E241C}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{515220B3-C373-4E23-829D-321C40A4D9DF}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\sharethepain\system\postal2mp.exe |
"{51CBB35A-A925-4E2B-9EBE-86E03A1DF3B3}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\half-life\hl.exe |
"{52694DC5-6801-4CF5-A9C0-9C13373BF346}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\system\postal2.exe |
"{547C9901-4BAF-4FA6-A2B4-C7C0DE192620}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\die schlacht um mittelerde ii\game.dat |
"{569D1A6F-8B82-4EB9-A08D-B72A244E21D1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{59792F67-3546-44D9-AC24-4EAA88FF47A0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5B62A528-EEB7-4393-B6F5-987B74C21228}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\video\hpmediasmartvideo.exe |
"{5C30D5F6-280B-4713-8A5F-822F0CFF43DC}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{5C501B2D-BAC2-4982-A582-8E201A0D4FF5}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{5CA74262-D1E9-41A0-ADFF-D52AFBC6AF78}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\apb reloaded\binaries\vivoxvoiceservice.exe |
"{5D6D944F-0ADB-4C8F-A025-7EC7358677EB}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\planetside 2\launchpad.exe |
"{5F8FBB4D-BB57-4481-BD63-33A02B2C2668}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\apb reloaded\binaries\vivoxvoiceservice.exe |
"{6762E77A-27AA-4722-8DAF-0132025ACD05}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{67B7333D-AD22-4CE6-B040-1BA7A85DC755}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{69A23C0E-4FAC-443D-AC8B-E59805E35543}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd |
"{6C960376-7E6F-4DF1-9F7B-C342FAF8D085}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"{6D5CB057-1BD1-4451-B495-BE439F244C20}" = protocol=6 | dir=in | app=c:\program files (x86)\lucasarts\star wars empire at war\gamedata\sweaw.exe |
"{6DCB77D4-685B-4F05-ADC7-78F389FC754E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6E86AD9B-36C0-4574-99A9-E7090CEC4380}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\system\postal2.exe |
"{6F46088A-BA29-437C-B245-158B050005A1}" = protocol=17 | dir=in | app=c:\program files (x86)\lucasarts\star wars empire at war\gamedata\sweaw.exe |
"{70600CBA-795D-4B14-BF77-826E45DB0566}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\stalker shadow of chernobyl\bin\xr_3da.exe |
"{708C15D1-FB97-484C-A0D2-5B9B3D381E66}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\amnesia the dark descent\launcher.exe |
"{727F6855-1159-4A01-9038-05CCED15E51A}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\sharethepain\system\postal2mp.exe |
"{73773B41-30A4-4FB2-9864-16E3219EAFCA}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{73DE6D44-EB69-4B3E-8CE5-B9F63F5D3B69}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{7542D122-1C41-4D43-BEBD-B99B1EB65A7A}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\red orchestra 2\binaries\win32\rogame.exe |
"{7578A1EC-EA62-4BC3-8FCD-A1D288A58CE8}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2\arma2.exe |
"{786B29BA-D5B0-454A-9693-89FD671E8B31}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\skyrimlauncher.exe |
"{797423E8-D163-49ED-9447-946C4337D177}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{79FC98EF-67D5-4526-8EBA-9F6A6AE802CA}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\ultimate doom\base\dosbox.exe |
"{7C72A588-C40C-4661-A355-91E900892F69}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{7DFA5081-9DB5-4B5F-982E-41909D11EAC2}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{80E3ABD7-9023-4DF2-AD82-860C07784E72}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{8148C999-2D57-4531-ABD0-631D7CF02A1F}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\amnesia the dark descent\launcher.exe |
"{82655D6C-7266-45EE-B9A7-BCC7C202C8D3}" = protocol=17 | dir=in | app=c:\program files (x86)\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{87737410-920E-4FCA-B0EC-5C5B6B4066DD}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{88A3C632-1613-4233-8DBE-E6E9A9467674}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2\arma2.exe |
"{8B42A354-D1D9-43BD-B6C3-1317C8E511B4}" = protocol=6 | dir=in | app=c:\program files (x86)\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{8C60F231-E354-482C-A168-279942FC4D8D}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\team fortress classic\hl.exe |
"{8D784637-4D26-4C35-B1DD-8894030504C4}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{8FE43E82-6765-41B0-A2C5-CF4ABDB5DC5B}" = protocol=6 | dir=in | app=c:\program files (x86)\a1 telekom austria\breitband-internet-installation\fixnet installer\installer.exe |
"{959CE94B-43C8-488D-BF05-4E247F1B55E2}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{96491AC7-2427-4256-98DD-D5EF855D4F67}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\universe sandbox\universe sandbox.exe |
"{9A709FE0-F833-48A6-9EEA-561DE3D15396}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\stalker shadow of chernobyl\bin\xr_3da.exe |
"{9D9ACECE-D462-44E4-8F24-B3B1EB89C989}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\die schlacht um mittelerde ii\game.dat |
"{9DA44E29-4D97-4DAE-B773-9D9E0E34B6C7}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\just cause 2\justcause2.exe |
"{A03377C5-252E-4E7B-B8A6-46BA783F8F58}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\thief deadly shadows\system\runme.exe |
"{A0D544F5-BC3B-4F83-9309-CF7320DDF630}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\opposing force\hl.exe |
"{A5D9F0A9-12DE-47F4-AFD4-BB2B20A7DC2E}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\red orchestra 2\binaries\win32\rogame.exe |
"{A9FCEEA1-D95B-4EC0-9A0C-A27740E6DC32}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\metro 2033\metro2033.exe |
"{ABD6AF2A-222E-40B8-83A2-5697C5BC4EE8}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{ABE4E7E6-BA0B-44C1-A86D-63BF1317069E}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{AFBA30B3-180A-4BC2-850D-06AA061C83D6}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"{B0799AB4-5631-4C37-9D39-8B14E83B2E8C}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{B100E9E8-3357-4D4C-A5AF-E47696308234}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{B59851EB-496B-4392-81D4-EDDD07FE3403}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\planetside 2\launchpad.exe |
"{B7471AE4-AF86-49CE-8EAA-5DD4253B3767}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{B76964E4-1340-46D6-ACD4-94CD5A06E5AA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BAD6D84B-34F5-4458-9A1A-8F1A0F71E294}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\skyrimlauncher.exe |
"{C8CC817E-F8EB-433F-B9A9-672FD6C02FE5}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{C8EA2508-D29B-4087-9D43-5E607EADF845}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{CB3BDA8F-F0EC-4E2A-905E-1CCF1267A34B}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"{CB51E8A4-D941-4CA8-A7A5-3CF64C978E68}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\f551d464b216807ee95c4d2d8c568d26\opposing force\hl.exe |
"{CCD944B7-BDB4-462F-9EEF-C517796F826A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{CDF059F2-866C-4A4D-8FD7-851D0F5DE9A5}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\die schlacht um mittelerde ii\game.dat |
"{CE884939-3BD9-4C18-AC96-1ACD3FAB1A6F}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\payday the heist\payday_win32_release.exe |
"{D1410297-B02B-49FB-A9A3-61735D900B8A}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{D2CB4996-BC51-4D1E-8C91-B7B12D59E7D1}" = protocol=6 | dir=in | app=c:\program files (x86)\firefly studios\stronghold 2\stronghold2.exe |
"{D3E2573C-6B52-45C9-8ADE-DDE207930279}" = protocol=6 | dir=out | app=system |
"{D47C6539-983D-4B5D-A218-15ED3FDEF06C}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\mafia ii\pc\mafia2.exe |
"{D603BC43-76BC-47E8-98E7-C4E2ADD5FD12}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D940BED9-2C23-4509-8999-450D46330F6C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DA86669E-CEBF-45B8-B079-7E18C9BCD4BE}" = protocol=6 | dir=in | app=c:\program files (x86)\easybits for kids\programs\my first browser\myfirstbrowser.exe |
"{DABB9F36-0222-45E4-84CF-96F294CD8849}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\payday the heist\payday_win32_release.exe |
"{DBA0BEE4-07A8-4AAB-BCD5-27528B3ED30C}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{DD0DF7C4-289D-4BE6-8B0B-98A3892575B1}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{DD596F3A-9601-4369-90BA-300939E61E3F}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\creationkit.exe |
"{DEDE2CFB-4E53-4C81-848B-79EFFF1C69B3}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\apb reloaded\binaries\apb.exe |
"{E2E1550A-77BF-40CC-856E-D88257715CE1}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 free\arma2free.exe |
"{E3066BCB-5819-4CB4-AD1B-02F0917E05BD}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\creationkit.exe |
"{E36021BD-D5AE-4A5C-A959-C7A57EBDE4AA}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{E39A3913-E981-4942-BA52-75B87BE89818}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{E4B455E6-750F-418D-B3BD-704AE6B0D33A}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E5B56675-2D2C-49F0-806C-8E36A04F878F}" = protocol=6 | dir=in | app=c:\program files (x86)\a1 telekom austria\breitband-internet-installation\fixnet installer\installer.exe |
"{E5CE8015-BB93-40F7-B7B0-67A7F13EA763}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\eflc\launcheflc.exe |
"{E71FA8F9-31BD-40D2-A2A3-C601C28311C8}" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe |
"{E8384A92-297A-4835-8C2D-FB1E3FB855ED}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steam.exe |
"{E909C2F9-6541-4302-803E-B6DC09C9ED6E}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\arma 2 free\arma2free.exe |
"{ED858269-CD82-4E17-B977-516BC85EAD96}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\creationkit.exe |
"{ED9215B5-AE64-464C-93FA-70F9BB9684F5}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\postal2complete\apocalypseweekend\system\apocalypseweekend.exe |
"{EEF4B42C-2629-496B-AB12-AA7FB59546A0}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\skyrimlauncher.exe |
"{F021A178-EB8A-4535-B4D7-476AAC91B4A3}" = protocol=17 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\skyrimlauncher.exe |
"{F1232109-D860-4DFD-A41D-5087A2FBE469}" = protocol=17 | dir=in | app=c:\program files (x86)\windows ilivid toolbar\toolbar\dtuser.exe |
"{F5607BF0-FC4A-475A-B7DC-0A7CC6A6DAAB}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{F57E47E0-3402-4439-8485-46856E9EC9C8}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\skyrim\creationkit.exe |
"{F713E0E0-D9B1-458A-855C-705967A8FD4B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{F731D8F3-8541-4671-AB89-8A6917AEF3D5}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{F8A0ED63-36D8-472D-A8BE-B12B25B7F1DA}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F9DEC007-2874-42CC-A5CB-DA54E012F6C2}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\apb reloaded\binaries\apb.exe |
"{FA2E3388-D4C6-42E3-94CC-B2E806A6A70A}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steamapps\common\metro 2033\metro2033.exe |
"{FB5617ED-B2BC-49FF-8C19-CD3B6E253C80}" = protocol=17 | dir=in | app=c:\program files (x86)\easybits for kids\programs\my first browser\myfirstbrowser.exe |
"{FBDC5E8A-0C5E-4D03-B0D1-8FC3ABC70E20}" = protocol=6 | dir=in | app=c:\program files (x86)\stam\steam.exe |
"{FC083DBE-E8C1-49B2-8989-CF0562BCF2DC}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{FD2C3003-5F3C-40A7-A4BE-E19814E6CE4F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{1B8FC019-4D86-45AB-814D-9DBB741C5BEF}C:\program files (x86)\rockstar games\eflc\eflc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\eflc\eflc.exe |
"UDP Query User{A9B47F8A-4468-406A-B8E7-1CE44D0977C6}C:\program files (x86)\rockstar games\eflc\eflc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\eflc\eflc.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{2128559D-BBCD-4744-87F0-7C0CD5CFB464}" = Windows Live Family Safety
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5B08AF35-B699-4A44-BB89-3E51E70611E8}" = HP MediaSmart SmartMenu
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6281459C-49C7-49C6-A9FE-50293675B4B2}" = Corel Graphics - Windows Shell Extension 64 Bit
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240CD}" = WinZip 16.0
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D79A02E9-6713-4335-9668-AAC7474C0C0E}" = HP Vision Hardware Diagnostics
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"6af12c54-643b-4752-87d0-8335503010de_is1" = Nexus Mod Manager
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"UDK-f24ec637-dde0-4842-ae14-a26395f54452" = PARANORMAL - BETA 4
"WinRAR archiver" = WinRAR 4.11 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{511DE7EA-AA68-4D7A-A2E3-0E7B5186B822}" = CorelDRAW Graphics Suite X6
"_{B92076C0-C5FE-4DB1-AA8D-855430CDF098}" = Corel Graphics - Windows Shell Extension
"{0084B0C3-F376-42E3-804A-885D249282BD}" = CorelDRAW Graphics Suite X6 - IPM
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2(TM)
"{05B1529B-C423-42AA-B981-4ECA247E9FC0}" = DayZ Commander
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{086BADF8-9B1F-4E89-B207-2EDA520972D6}" = Grand Theft Auto San Andreas
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{169ADA4A-8079-4CD8-8E20-030B1A54E552}" = CorelDRAW Graphics Suite X6 - DE
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1D108D70-E7D1-4089-9A0A-99629C4D0CB8}" = Morrowind
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1ED31028-6D65-4CFD-AD03-8E484A052FE7}" = aonUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{25D69CEE-3EE2-47FD-9A0E-5013240EC953}" = CorelDRAW Graphics Suite X6 - Common
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{318FF3D7-0C40-483B-AF92-AF36416B0AC6}" = CorelDRAW Graphics Suite X6 - Writing Tools
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{3DE92282-CB49-434F-81BF-94E5B380E889}" = Die Sims™ 3 Jahreszeiten
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{42DCB650-F003-4535-A5CD-32AD815CD2DD}" = Play withSIX
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{44EAFE3D-09A9-4478-A2BF-0EED22F4E49F}" = Die Sims™ 3 Erstelle ein Muster-Tool
"{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = Die Sims™ 3 Late Night
"{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}" = LightScribe System Software
"{4767A89A-F6A5-41B1-903C-734483739882}" = Highspeed-Internet-Installation
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{511DE7EA-AA68-4D7A-A2E3-0E7B5186B822}" = CorelDRAW Graphics Suite X6 - Setup Files
"{5454083B-1308-4485-BF17-111000038701}" = Grand Theft Auto: Episodes from Liberty City
"{5454083B-1308-4485-BF17-1110000D8301}" = Grand Theft Auto IV
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{579CA850-B2C3-43F3-A3F6-3A0AE42E8225}" = CorelDRAW Graphics Suite X6 - FontNav
"{58D68DF0-4E8B-4E9E-B425-670F9E37C1A8}" = TES Construction Set
"{5B9C7C4F-A1CB-11E0-9E40-0013D3D69929}" = Vegas Pro 10.0
"{5DF7AA5E-A1CB-11E0-A7D6-0013D3D69929}" = MSVCRT Redists
"{603C6570-2BA1-4FC6-8735-7EFA6D1F6F61}" = CorelDRAW Graphics Suite X6 - Custom Data
"{61B8B2F9-D8DA-4B24-89A9-DB09F38A4899}" = Grand Theft Auto: Episodes From Liberty City
"{62BEC144-7029-4BF4-B3F2-FA231FB9F84B}" = CorelDRAW Graphics Suite X6 - Redist
"{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}" = NVIDIA PhysX
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65761BAE-11E8-48FE-B30F-1F01011AB906}" = Die Sims™ 3 "Erstelle eine Welt"-Tool - Beta
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1
"{6F53FB68-6620-423E-B7CD-B8205655B421}" = CorelDRAW Graphics Suite X6 - PHOTO-PAINT
"{7032B400-11EC-11E0-A9BF-0013D3D69929}" = MSVCRT Redists
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72D90DB3-A16A-4545-B555-868471101833}" = HP Setup
"{74FA94F1-9566-4252-9372-E7EAFFEFE209}" = CorelDRAW Graphics Suite X6 - Capture
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{76DAEC83-AF7B-333C-8A53-83D7C7D39199}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - DEU
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7A2FF332-E4F6-4D87-9EBD-EDFF1216490F}" = CorelDRAW Graphics Suite X6 - Filters
"{7CCD75BD-5528-4FE1-90D2-392D661A2BF1}" = CorelDRAW Graphics Suite X6 - VSTA
"{7D606567-5047-451A-B49E-29FCB6012B4E}" = Microsoft Flight Simulator X: Acceleration
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7F9F6864-8CAB-440C-AF44-030D0135666D}" = CorelDRAW Graphics Suite X6
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{879E2460-18F9-48F2-B736-4E814A699504}" = CorelDRAW Graphics Suite X6 - VBA
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E87B944-4815-3C5E-947F-5035C9F64362}" = Microsoft Visual Studio Tools for Applications 2.0 Language Pack - DEU
"{90120000-0070-0000-0000-4000000FF1CE}" = Microsoft Visual Basic for Applications 7.1 (x86)
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0407-1000-0000000FF1CE}_Office14.SingleImage_{594128C9-2CDF-43CE-8103-DC100CF013B6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{904B64C4-49D8-4941-A2B6-D13D06C5CD8B}" = Controller
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = Die Sims™ 3 Traumkarrieren
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{9ED06229-1F1B-4AE2-970D-5F731E8C8C35}" = Hunting Unlimited 2010
"{9EF200A3-1CAC-462E-990B-EC902279BAAA}" = Microsoft Visual Basic for Applications 7.1 (x86) German
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AF37176A-78CA-545B-34EF-8B6A21514DD1}" = Adobe Help Manager
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B5554F9E-702A-49A7-BD52-680AA21E0032}" = Fire Department
"{B73B4A99-4173-4747-BBEC-0F05E966F9D2}" = Battlefield 1942: Secret Weapons of WWII
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B92076C0-C5FE-4DB1-AA8D-855430CDF098}" = Corel Graphics - Windows Shell Extension
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{BD5669B5-49FF-4490-B956-E9D7CB9B0ADC}" = Adobe Flash Professional CS6
"{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die Sims™ 3
"{C12631C6-804D-4B32-B0DD-8A496462F106}" = Die Sims™ 3 Einfach tierisch
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5262276-0075-498B-B80F-7D997482E4DB}" = CorelDRAW Graphics Suite X6 - Draw
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C66BF9FD-D367-4E13-8EB8-385FFEA20DB3}" = Oblivion
"{C8773FDB-D0DB-BE52-D536-F48F9886B57B}" = Adobe Download Assistant
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD9D0827-A6D6-4E2C-B31E-23F01577E27B}" = BlueStacks Notification Center
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4A17D31-2F7B-4682-AD57-467021452909}" = CorelDRAW Graphics Suite X6 - Photozoom Plugin
"{D4EFC6B7-3DA5-400D-9682-9BE287A5440E}" = CorelDRAW Graphics Suite X6 - Connect
"{D8B5C1BB-5951-422D-A4D5-451675614956}_is1" = Men of War: Assault Squad (Nur entfernen)
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDFEB503-D662-4224-82C9-37A5698FDC25}" = CorelDRAW Graphics Suite X6 - VideoBrowser
"{DE77FE3F-A33D-499A-87AD-5FC406617B40}" = HP Update
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}" = Die Sims™ 3 Lebensfreude
"{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F535B2CF-C9BB-4162-B03A-02D6971F32CC}" = Microsoft Flight Simulator X
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"7-Zip" = 7-Zip 9.20
"A2BAF Data cache removal" = ARMA 2: British Armed Forces - Data cache removal
"A2PMC Data cache removal" = ARMA 2: Private Military Company - Data cache removal
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"aonUpdate" = aonUpdate
"Arma 2 Army of The Czech Republic (LITE)" = Arma 2 Army of The Czech Republic (LITE) Uninstall
"AVS Screen Capture_is1" = AVS Screen Capture version 2.0.1
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS Video Editor_is1" = AVS Video Editor 6
"AVS Video Recorder_is1" = AVS Video Recorder 2.4
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"Battlefield 1918" = Battlefield 1918
"BattlEye A2 Free" = BattlEye (A2Free) Uninstall
"BattlEye for OA" = BattlEye for OA Uninstall
"BlueStacks App Player" = BlueStacks App Player
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Help Manager
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Controller" = Controller
"DesertCombat" = DesertCombat  0.7
"Die Gilde 2 - Gold Edition" = Die Gilde 2 - Gold Edition
"EasyBits Magic Desktop" = Magic Desktop
"FlightSim_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Microsoft Flight Simulator X: Acceleration
"Fraps" = Fraps (remove only)
"Free YouTube Download_is1" = Free YouTube Download version 3.1.42.1212
"Google Chrome" = Google Chrome
"Highspeed-Internet-Installation" = Highspeed-Internet-Installation
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{F535B2CF-C9BB-4162-B03A-02D6971F32CC}" = Microsoft Flight Simulator X
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"Mafia" = Mafia
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"My HP Game Console" = HP Game Console
"MyTools" = MyTools
"Nehrim - Am Rande des Schicksals_is1" = NehrimUninstaller
"NIS" = Norton Internet Security
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"OpenAL" = OpenAL
"PDF Complete" = PDF Complete Special Edition
"Postal 2 Demo" = Postal 2 Demo
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"PunkBusterSvc" = PunkBuster Services
"Republic at War - Deutsch 1.1" = Republic at War - Deutsch 1.1
"Republic at War 1.1" = Republic at War 1.1
"RollerCoaster Tycoon 3_is1" = RollerCoaster Tycoon 3
"RTMshadow_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Flight Simulator X
"SP1shadow_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Flight Simulator X Service Pack 1
"Steam App 202480" = Creation Kit
"Steam App 218230" = PlanetSide 2
"Steam App 219540" = ARMA 2: Operation Arrowhead Beta
"Steam App 220" = Half-Life 2
"Steam App 223470" = POSTAL 2 Complete
"Steam App 2280" = The Ultimate DOOM
"Steam App 228800" = Arma 3 Alpha Lite
"Steam App 240" = Counter-Strike: Source
"Steam App 24240" = PAYDAY: The Heist
"Steam App 33910" = ARMA 2
"Steam App 33930" = ARMA 2: Operation Arrowhead
"Steam App 35450" = Red Orchestra 2: Heroes of Stalingrad
"Steam App 380" = Half-Life 2: Episode One
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 43110" = Metro 2033
"Steam App 4500" = S.T.A.L.K.E.R.: Shadow of Chernobyl
"Steam App 48010" = LIMBO Demo
"Steam App 50130" = Mafia II
"Steam App 550" = Left 4 Dead 2
"Steam App 65700" = ARMA 2: British Armed Forces
"Steam App 65720" = ARMA 2: Private Military Company
"Steam App 6980" = Thief: Deadly Shadows
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 8190" = Just Cause 2
"Universe Sandbox" = Universe Sandbox
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WT087361" = FATE
"WT087380" = John Deere Drive Green
"WT087394" = Penguins!
"WT087396" = Polar Bowler
"WT087420" = Agatha Christie - Death on the Nile
"WT087428" = Bejeweled 2 Deluxe
"WT087453" = Chuzzle Deluxe
"WT087480" = Insaniquarium Deluxe
"WT087485" = Jewel Quest II
"WT087490" = Jewel Quest Solitaire
"WT087501" = Plants vs. Zombies
"WT087510" = Slingo Deluxe
"WT087513" = Virtual Villagers - The Secret City
"WT087519" = Wedding Dash
"WT087533" = Zuma Deluxe
"WT087536" = Diner Dash 2 Restaurant Rescue
"Xfire" = Xfire (remove only)
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3419521695-173782897-1149873748-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Haunt 1.0 64bit" = Haunt 1.0 64bit
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Tropico 4" = Tropico 4 1.00
 
========== Last 20 Event Log Errors ==========
 
[ Hewlett-Packard Events ]
Error - 10/10/2012 12:46:31 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 40  TargetSite: Void UpdateAndDetect() 
 
Error - 10/17/2012 12:02:51 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization:  TargetSite: Void UpdateAndDetect() 
 
Error - 10/24/2012 12:02:34 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 40  TargetSite: Void UpdateAndDetect() 
 
Error - 11/7/2012 1:59:23 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 20  TargetSite: Void UpdateAndDetect() 
 
Error - 11/14/2012 2:00:45 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 30  TargetSite: Void UpdateAndDetect() 
 
Error - 11/21/2012 1:03:01 PM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 30  TargetSite: Void UpdateAndDetect() 
 
Error - 11/21/2012 10:02:42 PM | Computer Name = Linos-HP-Schatz | Source = HPSF.exe | ID = 4000
Description =
 
Error - 11/22/2012 2:32:33 AM | Computer Name = Linos-HP-Schatz | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088hpsa_service.exe  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Message: One HP Active Check Local Mode job already running.  StackTrace:
  bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

  bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
 Boolean localScan)  Source: HP.ActiveCheckLocalMode.SessionManager    Name: hpsa_service.exe
Version:
 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
 de-DE  RAM: 12247  Ram Utilization: 10  TargetSite: Void UpdateAndDetect() 
 
Error - 11/22/2012 7:37:56 AM | Computer Name = Linos-HP-Schatz | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261  bei HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Message:
 Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt.  StackTrace:  bei
 HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Source:
 HP.SupportFramework.Utilities    Name: HPSF.exe  Version: 07.00.01.01  Path: C:\Program
 Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe  Format: de-DE  RAM: 12247
Ram
 Utilization: 20  TargetSite: HP.SupportFramework.HPSFReporting._Property[] AddNavigationProperties()

 
Error - 11/22/2012 11:40:58 AM | Computer Name = Linos-HP-Schatz | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261  bei HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Message:
 Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt.  StackTrace:  bei
 HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Source:
 HP.SupportFramework.Utilities    Name: HPSF.exe  Version: 07.00.01.01  Path: C:\Program
 Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe  Format: de-DE  RAM: 12247
Ram
 Utilization: 10  TargetSite: HP.SupportFramework.HPSFReporting._Property[] AddNavigationProperties()

 
[ System Events ]
Error - 4/5/2013 7:31:59 AM | Computer Name = Linos-HP-Schatz | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Easybits Services for Windows" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%3
 
Error - 4/5/2013 7:35:13 AM | Computer Name = Linos-HP-Schatz | Source = Service Control Manager | ID = 7038
Description = Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser"
 mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:  %%1330    Vergewissern
 Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
 Management Console (MMC).
 
Error - 4/5/2013 7:35:13 AM | Computer Name = Linos-HP-Schatz | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%1069
 
 
< End of report >


cosinus 05.04.2013 14:46

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes - denk bitte vorher daran, Malwarebytes über den Updatebutton zu aktualisieren

Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Linschko 06.04.2013 12:29

ESEB

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=02639d5e964ad842b2f6e26674442017
# engine=13563
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-04-06 11:25:15
# local_time=2013-04-06 01:25:15 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=3591 16777213 100 91 4547 127844100 0 0
# compatibility_mode=5893 16776574 100 94 31881919 116877365 0 0
# scanned=10796
# found=0
# cleaned=0
# scan_time=1937

mbam

Code:

Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Datenbank Version: v2013.04.06.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Lino :: LINOS-HP-SCHATZ [Administrator]

06.04.2013 12:26:59
mbam-log-2013-04-06 (12-26-59).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 287016
Laufzeit: 4 Minute(n), 26 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 06.04.2013 16:47

Sieht soweit ok aus

Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Linschko 07.04.2013 17:16

Also ich werde bei Google auf nichts mehr verlinkt und sonst läuft der PC auch normal.
Heißt das jetzt also mein PC ist wieder sauber? Wenn ja kann ich dir garnicht genug danken :dankeschoen:
Und deinen Rat werde ich mir natürlich zu herzen nehmen.

cosinus 08.04.2013 00:12

Dann wären wir durch! :daumenhoc

Die Programme, die hier zum Einsatz kamen, können alle wieder runter.

Combofix entfernen (nur relevant wenn es hier benutzt wurde!) : Start/Ausführen (Tastenkombination WIN+R), dort den Befehl combofix /uninstall eintippen und ausführen

Mit Hilfe von OTL kannst du auch viele andere Tools entfernen: Starte dazu einfach OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.

Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate
Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.
Windows Vista/7: Start, Systemsteuerung, Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks findest du hier => Browsers and Plugins - FilePony.de

Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

Linschko 09.04.2013 16:12

Hm ja, aber wie löscht man die ganzen Programme wie JRT? Die werden bei der Systemsteuerung nicht angezeigt...

cosinus 09.04.2013 16:25

Einfach die EXE-Dateien löschen.

Linschko 10.04.2013 13:14

Okay, hab ich gemacht. Ich hab aber noch ne letzt frage.
Ich hab MBAM gelöscht (hab nicht gesehen das ich es drauf lassen sollte), ich hatte aber 4 registry und eine Datei in Quarantäne. Sind die Dinger jetzt wieder ausgebrochen? Ich hab es mittlerweile wieder oben, und hatte heute schon 2 mal diese abstürze mit dem Blauen Textfeld beim Hochfahren.

cosinus 10.04.2013 14:17

Zitat:

Sind die Dinger jetzt wieder ausgebrochen?
Nein....

Linschko 11.04.2013 18:15

Na dann bin ich aber erleichtert.
Vielen dank nochmal für eine Hilfe, keine Ahnung was ich ohne dich gemacht hätte.
Meine Fragen wären jetzt alle beantwortet.


Alle Zeitangaben in WEZ +1. Es ist jetzt 17:45 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19