Verdacht auf ZeuS/ZBot aufgrund von Telekom-Mail Hi, wir haben heute eine Email vom Telekom-Abuse Dienst erhalten, in dem deren Sicherheitsexperten "zuverlässige Hinweise" haben, dass auf einem unserer Rechner ein Zeus/ZBot sein Unwesen treiben soll.
Natürlich habe ich das Problem in dem Forum schon gefunden, aber man soll ja sein eigenes Thema aufmachen, da es keine generellen Lösungen gibt =)
Habe die drei Punkte aus dem "Für alle Hilfesuchenden" getätigt, weiter unten stehen die Logs. Ein Problem kann ich leider nicht beschreiben, der Rechner läuft flüssig, es kommen keine dubiosen Meldungen (außer der komische "Web-Player", der ohne Icon, also ein leeres Icon, im System-Tray rumlungert und man weder mit links noch mit rechtsklick ansprechen kann, das schließen per Taskmanager funktioniert allerdings einwandfrei :D keine Ahnung warum ich mir den mal runtergeladen habe ;) )
Ich hoffe ich werde die Hinweise sorgfältig lesen und beantworten ;P
Cracks oder ähnliches sollten auf dem Rechner nicht vorhanden sein, wobei ich zugeben muss, dass ich diese mal verwendet habe, das war aber zu einer anderen Zeit :pfeiff: (neuer Rechner ^^)
zu guter Letzt, die schon getanen Schritte sollten aus den Logs hervorgehen, hab 3-5 Scanner runtergeladen und mit Schnellauf drüberlaufen lassen, haben alle nichts gefunden =/
Grüße und Vielen Dank für die Antworten
Ethanil
OTL: Code:
OTL logfile created on: 21.05.2013 23:33:04 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\***\Desktop
64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16580)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,87 Gb Available Physical Memory | 71,85% Memory free
9,99 Gb Paging File | 8,79 Gb Available in Paging File | 87,99% Paging File free
Paging file location(s): C:\pagefile.sys 6139 6139H:\pagef [Binary data over 200 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 488,28 Gb Total Space | 171,15 Gb Free Space | 35,05% Space Free | Partition Type: NTFS
Drive D: | 443,22 Gb Total Space | 441,95 Gb Free Space | 99,71% Space Free | Partition Type: NTFS
Computer Name: ***| User Name: ***| Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.05.21 23:27:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
PRC - [2013.05.12 00:34:55 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013.03.07 01:32:44 | 004,767,304 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe
PRC - [2013.02.02 10:40:58 | 000,375,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
PRC - [2013.01.18 16:25:32 | 000,026,448 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files (x86)\Uniblue\MaxiDisk\mdmonitor.exe
PRC - [2012.11.22 20:44:00 | 000,026,008 | ---- | M] (Uniblue Systems Ltd) -- C:\Program Files (x86)\Uniblue\SpeedUpMyPC\spmonitor.exe
PRC - [2010.11.17 03:53:16 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV:64bit: - [2013.04.09 06:48:42 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2013.03.02 04:45:07 | 000,171,008 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:64bit: - [2013.03.02 04:45:05 | 000,180,224 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:64bit: - [2013.02.02 10:21:45 | 000,467,456 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:64bit: - [2013.01.10 01:23:16 | 001,964,544 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:64bit: - [2013.01.10 01:22:35 | 000,438,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:64bit: - [2012.12.19 21:56:00 | 000,240,640 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2012.12.19 16:32:12 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2012.11.06 06:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:64bit: - [2012.09.20 11:10:47 | 002,367,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:64bit: - [2012.09.20 08:31:18 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:64bit: - [2012.09.20 08:30:41 | 000,179,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:64bit: - [2012.07.26 05:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:64bit: - [2012.07.26 05:07:42 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:64bit: - [2012.07.26 05:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:64bit: - [2012.07.26 05:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:64bit: - [2012.07.26 05:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:64bit: - [2012.07.26 05:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:64bit: - [2012.07.26 05:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:64bit: - [2012.07.26 05:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:64bit: - [2012.07.26 05:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:64bit: - [2012.07.26 05:05:28 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:64bit: - [2012.07.26 05:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:64bit: - [2012.07.26 05:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent)
SRV:64bit: - [2012.07.26 05:05:04 | 000,187,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV - [2013.05.12 00:34:55 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2013.05.04 01:35:30 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013.04.23 14:48:24 | 000,009,216 | ---- | M] (Hi-Rez Studios) [Auto | Paused] -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2013.03.07 01:32:44 | 000,045,248 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013.02.28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.01.18 16:25:34 | 000,030,032 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Uniblue\MaxiDisk\service.exe -- (Uniblue.MaxiDiskSvc)
SRV - [2012.12.16 13:25:38 | 000,123,664 | ---- | M] (SANDBOXIE L.T.D) [Auto | Stopped] -- C:\Programme\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2012.12.10 17:29:46 | 002,465,712 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2012.11.06 06:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2012.07.26 05:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013.05.21 22:37:15 | 000,032,000 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hitmanpro37.sys -- (hitmanpro37)
DRV:64bit: - [2013.04.09 07:27:43 | 000,284,424 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport)
DRV:64bit: - [2013.03.07 01:33:21 | 001,025,808 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2013.03.07 01:33:21 | 000,377,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2013.03.07 01:33:21 | 000,178,624 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2013.03.07 01:33:21 | 000,070,992 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2013.03.07 01:33:21 | 000,068,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2013.03.07 01:33:21 | 000,065,336 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2013.03.07 01:33:20 | 000,080,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\Drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2013.03.07 01:33:20 | 000,033,400 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2013.03.02 12:57:48 | 000,337,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI)
DRV:64bit: - [2013.03.02 12:57:46 | 000,077,544 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\storahci.sys -- (storahci)
DRV:64bit: - [2013.03.02 12:45:20 | 000,148,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\tpm.sys -- (TPM)
DRV:64bit: - [2013.03.02 12:45:19 | 000,194,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2013.03.02 12:39:38 | 000,069,864 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\pdc.sys -- (pdc)
DRV:64bit: - [2013.02.02 13:19:44 | 000,446,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3)
DRV:64bit: - [2013.02.02 09:25:23 | 000,037,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:64bit: - [2013.01.29 03:57:05 | 000,035,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot)
DRV:64bit: - [2013.01.29 01:08:22 | 000,230,904 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter)
DRV:64bit: - [2013.01.10 03:53:32 | 000,028,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:64bit: - [2012.12.21 08:46:02 | 000,104,184 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\AtihdW86.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.12.19 22:48:48 | 011,278,336 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.12.19 21:32:54 | 000,552,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.11.27 05:55:44 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid)
DRV:64bit: - [2012.11.20 06:54:31 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c)
DRV:64bit: - [2012.11.06 05:55:44 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM)
DRV:64bit: - [2012.10.12 10:08:01 | 000,027,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.10.11 09:25:48 | 000,056,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor)
DRV:64bit: - [2012.10.11 09:13:49 | 000,058,088 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\Drivers\dam.sys -- (dam)
DRV:64bit: - [2012.09.20 09:55:33 | 000,212,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000)
DRV:64bit: - [2012.09.20 09:55:30 | 000,120,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:64bit: - [2012.09.20 09:55:27 | 003,265,256 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2012.09.20 09:55:24 | 000,533,224 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2012.07.26 07:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.07.26 07:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\condrv.sys -- (condrv)
DRV:64bit: - [2012.07.26 07:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:64bit: - [2012.07.26 07:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt)
DRV:64bit: - [2012.07.26 07:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor)
DRV:64bit: - [2012.07.26 07:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex)
DRV:64bit: - [2012.07.26 07:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis)
DRV:64bit: - [2012.07.26 07:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2012.07.26 07:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2012.07.26 07:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS)
DRV:64bit: - [2012.07.26 07:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2012.07.26 07:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:64bit: - [2012.07.26 07:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass)
DRV:64bit: - [2012.07.26 07:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2012.07.26 07:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\3ware.sys -- (3ware)
DRV:64bit: - [2012.07.26 07:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2012.07.26 07:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2012.07.26 06:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\clfs.sys -- (CLFS)
DRV:64bit: - [2012.07.26 06:54:34 | 000,096,496 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS)
DRV:64bit: - [2012.07.26 06:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpci.sys -- (vpci)
DRV:64bit: - [2012.07.26 05:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2012.07.26 04:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf)
DRV:64bit: - [2012.07.26 04:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:64bit: - [2012.07.26 04:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo)
DRV:64bit: - [2012.07.26 04:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender)
DRV:64bit: - [2012.07.26 04:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter)
DRV:64bit: - [2012.07.26 04:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic)
DRV:64bit: - [2012.07.26 04:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime)
DRV:64bit: - [2012.07.26 04:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig)
DRV:64bit: - [2012.07.26 04:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:64bit: - [2012.07.26 04:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr)
DRV:64bit: - [2012.07.26 04:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd)
DRV:64bit: - [2012.07.26 04:26:57 | 000,089,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\xusb22.sys -- (xusb22)
DRV:64bit: - [2012.07.26 04:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx)
DRV:64bit: - [2012.07.26 04:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx)
DRV:64bit: - [2012.07.26 04:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012.07.26 04:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum)
DRV:64bit: - [2012.07.26 04:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2012.07.26 04:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.07.26 04:25:26 | 000,203,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\Vid.sys -- (Vid)
DRV:64bit: - [2012.07.26 04:25:22 | 000,067,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\storvsp.sys -- (storvsp)
DRV:64bit: - [2012.07.26 04:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr)
DRV:64bit: - [2012.07.26 04:25:12 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmbusr.sys -- (vmbusr)
DRV:64bit: - [2012.07.26 04:25:12 | 000,066,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpcivsp.sys -- (vpcivsp)
DRV:64bit: - [2012.07.26 04:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:64bit: - [2012.07.26 04:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp)
DRV:64bit: - [2012.07.26 04:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu)
DRV:64bit: - [2012.06.05 07:45:16 | 000,237,968 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2012.06.02 16:31:56 | 000,589,824 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\Rt630x64.sys -- (RTL8168)
DRV:64bit: - [2010.11.19 04:34:26 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010.11.19 04:34:26 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2009.03.18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\hamachi.sys -- (hamachi)
DRV - [2012.12.16 13:25:34 | 000,202,632 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- C:\Programme\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2012.04.09 10:13:58 | 000,057,472 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Programme\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C4 AB 23 BA 43 48 CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@raidcall.en/RCplugin: C:\Users\***\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ocr@babylon.com: C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\ocr@babylon.com
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
CHR - Extension: Google Docs = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: TV = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh\1.0.12_0\
CHR - Extension: YouTube = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Kalender = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.5.3_0\
CHR - Extension: AdBlock = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.63_0\
CHR - Extension: Stealthy = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieaebnkibonmpbhdaanjkmedikadnoje\3.0.1_0\
CHR - Extension: SmartVideo For YouTube\u2122 = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnkdbjbjpnpjeciipoaflmpcddinpjjp\0.9926_0\
CHR - Extension: FastestChrome \u2013 Schneller browsen = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmffncokckfccddfenhkhnllmlobdahm\7.1.1_0\
CHR - Extension: Google Mail = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012.07.26 07:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKCU..\Run: [Exetender_148] "C:\Program Files (x86)\FreeRide Games\GPlayer.exe" /runonstartup File not found
O4 - HKCU..\Run: [Online Weather] C:\Users\***\AppData\Local\WebPlayer\Online Weather\WebPlayer.exe ()
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKLM..\RunOnce: [Z1] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk = C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1EDBDD86-7D55-4D42-A48F-D0758BFB0A3E}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.05.21 23:27:20 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
[2013.05.21 22:43:46 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes
[2013.05.21 22:43:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.05.21 22:43:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.05.21 22:43:30 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.05.21 22:43:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.05.21 22:23:54 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2013.05.21 22:20:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013.05.17 22:42:27 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\vlc
[2013.05.17 21:53:31 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\bilder
[2013.05.12 00:34:40 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Chromium
[2013.05.12 00:34:39 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\PunkBuster
[2013.05.12 00:07:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2013.05.11 00:46:06 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\raidcall
[2013.05.11 00:45:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaidCall
[2013.05.11 00:45:38 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RaidCall
[2013.05.11 00:45:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RaidCall
[2013.05.10 01:49:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Chart Controls
[2013.05.10 01:44:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
[2013.05.10 01:44:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Hi-Rez Studios
[2013.05.10 01:43:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hi-Rez Studios
[2013.04.29 06:33:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2013.04.27 12:32:35 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\TERA
[2013.04.24 20:06:43 | 000,033,856 | -H-- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\hamachi.sys
[2013.04.24 20:06:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2013.04.24 20:06:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
[2013.04.24 20:06:26 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\LogMeIn Hamachi
[2013.04.23 16:51:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grinding Gear Games
[2013.04.23 16:51:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Grinding Gear Games
========== Files - Modified Within 30 Days ==========
[2013.05.21 23:27:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
[2013.05.21 23:27:15 | 000,000,000 | ---- | M] () -- C:\Users\***\defogger_reenable
[2013.05.21 23:00:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.05.21 22:59:50 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.05.21 22:59:17 | 000,000,348 | ---- | M] () -- C:\Windows\tasks\spmonitor.job
[2013.05.21 22:59:17 | 000,000,342 | ---- | M] () -- C:\Windows\tasks\mdmonitor.job
[2013.05.21 22:58:43 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2013.05.21 22:58:22 | 3433,918,464 | -HS- | M] () -- C:\hiberfil.sys
[2013.05.21 22:43:32 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.05.21 22:41:01 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.05.21 22:37:15 | 000,032,000 | ---- | M] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys
[2013.05.21 22:37:06 | 000,304,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.05.21 22:32:53 | 000,001,298 | ---- | M] () -- C:\Windows\SysNative\.crusader
[2013.05.17 21:52:43 | 000,001,027 | ---- | M] () -- C:\Users***\Desktop\SciLor's grooveshark(tm).com Downloader.lnk
[2013.05.17 21:52:43 | 000,001,020 | ---- | M] () -- C:\Users***\Desktop\Sandboxed Web Browser.lnk
[2013.05.17 17:33:30 | 009,784,854 | ---- | M] () -- C:\Users***\Desktop\Neue Bitmap (2).bmp
[2013.05.17 15:34:49 | 000,061,978 | ---- | M] () -- C:\Users***\Desktop\mdl2.jpg
[2013.05.17 15:34:38 | 000,070,422 | ---- | M] () -- C:\Users***\Desktop\mdl1.jpg
[2013.05.12 19:57:27 | 000,000,000 | ---- | M] () -- C:\Users***\Desktop\Neue Bitmap.bmp
[2013.05.12 00:34:55 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.05.12 00:34:44 | 000,283,032 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.05.12 00:34:44 | 000,283,032 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.05.12 00:07:24 | 000,189,248 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.05.12 00:01:45 | 003,130,440 | ---- | M] () -- C:\Windows\SysWow64\pbsvc_blr.exe
[2013.05.11 20:07:26 | 001,745,416 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.05.11 20:07:26 | 000,751,892 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.05.11 20:07:26 | 000,710,046 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.05.11 20:07:26 | 000,155,620 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.05.11 20:07:26 | 000,132,416 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.05.11 00:45:38 | 000,001,011 | ---- | M] () -- C:\Users***\Desktop\RaidCall.lnk
[2013.04.28 01:14:18 | 000,001,235 | ---- | M] () -- C:\Users***\Desktop\Neverwinter.lnk
[2013.04.23 16:51:19 | 000,002,106 | ---- | M] () -- C:\Users\Public\Desktop\Path of Exile.lnk
========== Files Created - No Company Name ==========
[2013.05.21 23:27:15 | 000,000,000 | ---- | C] () -- C:\Users***\defogger_reenable
[2013.05.21 22:43:32 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.05.21 22:36:55 | 000,304,464 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.05.21 22:32:53 | 000,001,298 | ---- | C] () -- C:\Windows\SysNative\.crusader
[2013.05.21 22:24:22 | 000,032,000 | ---- | C] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys
[2013.05.17 21:11:07 | 000,387,688 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml
[2013.05.17 17:33:20 | 009,784,854 | ---- | C] () -- C:\Users***\Desktop\Neue Bitmap (2).bmp
[2013.05.17 15:34:49 | 000,061,978 | ---- | C] () -- C:\Users***\Desktop\mdl2.jpg
[2013.05.17 15:34:37 | 000,070,422 | ---- | C] () -- C:\Users***\Desktop\mdl1.jpg
[2013.05.12 19:57:27 | 000,000,000 | ---- | C] () -- C:\Users***\Desktop\Neue Bitmap.bmp
[2013.05.12 00:34:44 | 000,283,032 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.05.12 00:07:20 | 000,283,032 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.05.12 00:07:20 | 000,189,248 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.05.12 00:07:17 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.05.12 00:07:16 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe
[2013.05.11 00:45:38 | 000,001,011 | ---- | C] () -- C:\Users***\Desktop\RaidCall.lnk
[2013.05.06 20:52:15 | 000,132,623 | ---- | C] () -- C:\Probeprüfungen.PDF
[2013.04.28 01:14:18 | 000,001,235 | ---- | C] () -- C:\Users***\Desktop\Neverwinter.lnk
[2013.04.23 16:51:19 | 000,002,106 | ---- | C] () -- C:\Users\Public\Desktop\Path of Exile.lnk
[2013.04.13 12:11:01 | 000,004,514 | ---- | C] () -- C:\Users***\AppData\Local\recently-used.xbel
[2013.03.29 00:59:32 | 000,001,532 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2013.03.24 23:16:41 | 000,609,772 | ---- | C] () -- C:\Users***\Fil.pdf
[2013.03.24 23:16:41 | 000,581,797 | ---- | C] () -- C:\Users***\Lemak.pdf
[2013.03.03 16:12:58 | 000,005,444 | ---- | C] () -- C:\Users***\.prolog_console_history
[2013.02.03 07:03:13 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2013.01.31 20:06:58 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2013.01.31 20:06:58 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2013.01.29 16:18:24 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013.01.27 18:53:54 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.01.27 18:53:54 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.01.27 18:53:53 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2012.07.26 10:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2012.07.26 10:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2012.07.26 09:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2012.07.26 03:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2012.07.25 22:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2012.07.25 22:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2012.06.02 16:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2012.05.02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
========== ZeroAccess Check ==========
[2013.02.02 23:33:28 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.03.06 08:31:28 | 019,758,592 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.03.06 07:03:37 | 017,561,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012.07.26 05:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012.07.26 05:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012.07.26 05:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.05.19 19:28:20 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\.minecraft
[2013.02.27 22:19:02 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\Carbon
[2013.02.28 19:53:36 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\com.stoicstudio.TheBannerSagaFactions
[2013.03.09 23:20:16 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\Dwarfs
[2013.03.03 02:27:52 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\Fatshark
[2013.03.27 03:28:45 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\fltk.org
[2013.05.21 23:31:26 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\foobar2000
[2013.03.14 22:17:06 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\Foxit Software
[2013.03.24 02:42:37 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\Freeplane
[2013.01.29 22:18:35 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\ftblauncher
[2013.01.29 22:30:34 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\LolClient
[2013.04.09 18:24:35 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\Notepad++
[2013.01.31 20:01:48 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\OpenOffice.org
[2013.05.11 00:46:07 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\raidcall
[2013.01.29 17:16:00 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\SWI-Prolog
[2013.04.27 12:32:35 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\TERA
[2013.02.05 00:05:40 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\Trillian
[2013.05.20 00:20:03 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\TS3Client
[2013.03.09 17:02:05 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\Ubisoft
[2013.03.12 21:26:43 | 000,000,000 | ---D | M] -- C:\Users***\AppData\Roaming\Uniblue
========== Purity Check ==========
< End of report > Extras: Code:
OTL Extras logfile created on: 21.05.2013 23:33:04 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\***\Desktop
64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16580)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,87 Gb Available Physical Memory | 71,85% Memory free
9,99 Gb Paging File | 8,79 Gb Available in Paging File | 87,99% Paging File free
Paging file location(s): C:\pagefile.sys 6139 6139H:\pagef [Binary data over 200 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 488,28 Gb Total Space | 171,15 Gb Free Space | 35,05% Space Free | Partition Type: NTFS
Drive D: | 443,22 Gb Total Space | 441,95 Gb Free Space | 99,71% Space Free | Partition Type: NTFS
Computer Name: *** | User Name: ***| Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{030DE039-291F-4911-903C-EBA3210B50C9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{077A6DD7-7286-4EB2-8A67-92FB70A4DF0A}" = rport=138 | protocol=17 | dir=out | app=system |
"{15ACFE88-B5DC-4927-8F4D-34FB9A0E6969}" = lport=137 | protocol=17 | dir=in | app=system |
"{18F23D46-6351-4AB0-B9B4-044CBB4B5D65}" = lport=139 | protocol=6 | dir=in | app=system |
"{23E675CE-049C-432F-8A17-D44B0138612D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5922F5EA-38CE-467B-A6BB-52C0A912627C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5D08C594-1BD8-4C8B-A3D9-64EF04F286B4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5DBAA488-19FA-4507-B5EA-11CB62C2F358}" = rport=445 | protocol=6 | dir=out | app=system |
"{622D81DB-1CAA-4707-A8AE-780D075EAC91}" = lport=10243 | protocol=6 | dir=in | app=system |
"{639EFE58-4023-479E-9A09-4590A909A75F}" = lport=445 | protocol=6 | dir=in | app=system |
"{650B48E0-693E-4C61-9ABD-89C884DDB950}" = rport=137 | protocol=17 | dir=out | app=system |
"{695BCD6C-358E-45E1-AB86-3D4F78BCABB8}" = rport=10243 | protocol=6 | dir=out | app=system |
"{725D272A-DFF7-4479-A715-33007951B034}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A5B06BBA-9215-45D0-A63D-BBCAB8747718}" = lport=138 | protocol=17 | dir=in | app=system |
"{A8929CBF-100F-44A3-8C82-3DDD558743FC}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B6CB2C8D-D3C8-42D6-8C8E-4D62AEB88962}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C8B40E0C-4F76-431D-8419-CFD5B9266C47}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{CBAEB5B8-CC51-4127-BD9C-751F48A89BB3}" = rport=139 | protocol=6 | dir=out | app=system |
"{CD1E2064-E638-4A0C-8775-5208EFB445E9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D2398BE9-C364-4ACC-907A-E2D04618F301}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{E5A66B18-FE57-4789-9F9B-E2D17892E502}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00A6F3C3-5D5F-4592-A4D8-F657B79090AE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 3\bin\sam3_unrestricted.exe |
"{00CB0EAF-ED75-4825-B22B-9CCC342C1EE6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\supercratebox\supercratebox.exe |
"{0119D483-E0F9-4FE7-AFCF-2DA3B2656101}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lord of the rings online\turbineinvoker.exe |
"{015BDE77-9C8D-4076-BFF3-834D8A65BBE6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gnomoria\gnomoria.exe |
"{021658C6-BFC4-429E-86AA-E1F10A64BBC8}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{03422241-0091-442C-B923-7A7501997714}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hitman absolution\hma.exe |
"{0381A856-DBB5-499D-947C-5B03CCFDDD7B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mirrors edge\binaries\mirrorsedge.exe |
"{03857195-B502-45A0-A91F-952F6525A434}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{04ECC309-61F7-425D-BCFA-846FF03C38D6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\poxnora\launchpad.exe |
"{05D7589E-F924-40C1-ADE0-69BFA209265C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gnomoria\gnomoria.exe |
"{09A11ED2-E7A8-423E-AC20-00940B89103E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe |
"{0AB05247-E8FE-4CA0-88F9-830B4B31FB2D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\hirezbridge.exe |
"{0AC7288F-DF12-4E28-9EE5-1542C1ADC1A8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia two thrones\princeofpersia.exe |
"{0B78485A-3B5E-4F80-8541-9A99BBC57501}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serioussamdoubled\ssgame.exe |
"{0BA2EB68-3E8A-44FE-A866-DC47DE905648}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{0BC5294F-77FA-4EE6-836B-DF09AF6F45D9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lord of the rings online\turbineinvoker.exe |
"{0C12BB13-B99E-4C32-AC66-75EB3E4397DD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0C1504D9-130B-416A-83CC-2AE1D463145C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{0CE1E0DA-E77D-44D6-BAAC-5B1DDDFAEBE0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe |
"{10E811B3-DEC0-4553-9348-65BBE1640748}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\renaissance heroes\bridealauncher.exe |
"{1129F389-B41E-40E7-B25B-B0837DF010A5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia two thrones\princeofpersia.exe |
"{123F0D5E-ABF8-4407-AB2E-526719F2F63C}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{12EA61BC-B396-46EF-B7E0-4E31A5ACE933}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amnesia the dark descent\launcher.exe |
"{149F21F8-B68F-4ED7-87BE-757A13E3F4B4}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404 - königsedition\tools\benchmark.exe |
"{17C964DB-3637-4421-B040-FC5E09A76C72}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{195F1D02-37E6-4369-952B-99FC8C37E5BB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unmechanical\binaries\win32\udk.exe |
"{1CE19A9B-AF80-45E7-B738-443763970783}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bulletstorm demo\binaries\win32\shippingpc-stormgame.exe |
"{1F21D5A8-6EBD-4AE0-9BEF-19C0C91A507E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{204EDB5A-C5CF-4E16-9473-4D9BE15E45C0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe |
"{217D3E1A-BCCF-49F4-BB08-0046377609F7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia\launcher\launcher.exe |
"{21FAF734-7661-4DC6-9799-627D55878C84}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2 demo\trine2_launcher.exe |
"{22E36769-636E-4CCD-869A-50CFC56F1E02}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
"{238223A4-E3D3-42A2-B6A0-214B2B0CB19D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dins curse demo\dinscurse.exe |
"{241A2AE4-9903-4E1E-AB7C-F48454F10FC1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dwarfs - f2p\dwarfs.exe |
"{2512A40B-5A8A-4341-9F7F-8363E90FAAFC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia the sands of time\princeofpersia.exe |
"{291464B4-79E4-454A-BB91-9D777C74D402}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{2921AAE0-4CFA-407E-BB45-93C0F156D371}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dwarfs - f2p\dwarfs.exe |
"{29CB9C73-4284-4298-BC98-BC08AA078839}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age2hd\launcher.exe |
"{2C1CF26A-44DC-4C7C-B0E1-2E095BE4E5CB}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2C8FD086-3112-427D-9749-DB079FF7B64B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 3\bin\sam3.exe |
"{2DB85094-29F5-4FB2-95B8-B5318783903E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia the sands of time\princeofpersia.exe |
"{2DE42095-F3A4-47E5-8BDE-07D5E1BB1CCF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\hirezbridge.exe |
"{2E6274FB-5D5C-4514-8B62-7CD52369AFF3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gnomoria\gnomoria.exe |
"{2F47B232-C0FC-4F46-AAEC-96AE6E700A02}" = protocol=6 | dir=out | app=system |
"{2F6F7432-311A-4C77-A26A-73D09C3CB903}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sleepingdogs\hkship.exe |
"{3047EB3B-58A3-430F-9D51-852705BBE1BD}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{322097CA-FD8A-4B8A-BF3A-4ACFF0A526DD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe |
"{3291D7FD-3008-4021-8CC2-A90F64FC880D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\renaissance heroes\binaries\win32\dvgame.exe |
"{354AD701-6B0B-4BD8-A219-C2D89D15C185}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\castlecrashers\castle.exe |
"{381774E5-9234-4853-8444-3571B4FEF4DD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 2\bin\sam2.exe |
"{3CFBE06D-FDD0-4104-9C36-6E17DFBD9F2A}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404 - königsedition\tools\addonweb.exe |
"{3D0D6175-0D08-4EC3-927C-6F7DE0C40049}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{3E204284-1C3B-4020-BC5A-71376EF85DFC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia forgotten sands\prince of persia.exe |
"{3EC767F2-53DA-42F2-8DDD-28C806290837}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} |
"{3EDFC091-8713-4A6C-B21F-015B72CB8360}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3FE0CFBD-A36B-45B2-BF44-573668FDCF84}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{4163DEED-647A-46C2-AF00-24B9CE8E34A0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia\launcher\launcher.exe |
"{416CA105-B6E3-4366-AFA7-1DE485EA6B10}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia the sands of time\princeofpersia.exe |
"{44EC039D-C432-485C-8E89-BA4ECAAF4CAB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{46D2402F-E003-45C7-9CCA-35BF428D8229}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the banner saga factions\win32\the banner saga factions.exe |
"{483F6B9C-C064-433D-A0FF-911569C8722E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\poxnora\launchpad.exe |
"{4979904D-5559-41CF-9C3C-67FAD420BE43}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{4A53497B-1B25-4688-A81E-AF36A14FB428}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{4BC0733C-C718-4189-A3E4-8C7B6D7E8C77}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 2\bin\sam2.exe |
"{4DE6A156-16B7-4486-A848-A62EB874D06B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2\trine2_launcher.exe |
"{4ED55D69-EAD1-4615-91D0-2DDD0347E0DB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lord of the rings online\turbineinvoker.exe |
"{4F027637-1B54-412F-B487-C08774E1090E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dins curse demo\dinscurse.exe |
"{4F347490-1BB1-48C8-8C42-81BCC73370F9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2 demo\trine2_launcher.exe |
"{501EA033-C46B-4FB4-B1E6-D0338AAF6FFA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\castlecrashers\castle.exe |
"{50762242-49AF-4149-BFD3-290C851CDB18}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
"{50FD1AE6-5516-40C1-BAB2-B4641F200844}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hitman absolution\hma.exe |
"{5110E520-FB6A-48EC-B339-97FC624BF174}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amnesia the dark descent\launcher.exe |
"{514737AF-7CBF-4A6F-B32B-53A6D31E2294}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{51489347-620D-413C-B2AC-FB5319BD5B88}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bulletstorm demo\binaries\win32\shippingpc-stormgame.exe |
"{521375CA-A53E-4726-8722-1E7D1219098E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia the warrior within\princeofpersia.exe |
"{53938F51-BAD5-4B7B-9955-E185392070EA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{548A492A-439A-4EC6-A2B9-2828959AC28B}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} |
"{54E1A330-0296-4D1D-B177-1D675803CEAD}" = protocol=17 | dir=in | app=c:\users\ruben\downloads\neverwinter_nw.1.20130416a.6.exe |
"{56C65758-FD81-423F-9449-3997CCDF1ABF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mirrors edge\binaries\mirrorsedge.exe |
"{59D59AC0-7A85-4C11-B522-AF03A97C6DF4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{5A240E37-5A9B-4E5B-BB2D-45925BA9C66B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\poxnora\launchpad.exe |
"{5A7A9564-F860-43CA-8FA0-09E91D76059E}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{5DA49107-F401-470E-9F72-74FBD96269B2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{5E923814-8A02-49AD-9EF2-874A35BE4844}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mirrors edge\support\ea help\electronic_arts_technical_support.htm |
"{5EE4C46C-A80D-4117-A93A-18302F7DA7BE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcs must die 2\build\release\orcsmustdie2.exe |
"{614B8265-677F-448D-9E5E-962B4DEADE06}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mirrors edge\support\ea help\electronic_arts_technical_support.htm |
"{6313D2AC-49AD-4DA9-88E4-F47707FB0F6E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia the warrior within\princeofpersia.exe |
"{63526DF7-ECD0-48CB-8EDD-86AC8A1EB331}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\supercratebox\supercratebox.exe |
"{63D28A66-4157-4F75-8FB1-15A698D2B19B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{6BE9DC98-1745-4549-9D94-80451117C17A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{6C215412-BBCC-490E-AE47-EBED3EA50394}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6C2D4517-E78A-4EF1-A6A9-463C8CC0D152}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\renaissance heroes\binaries\win32\dvgame.exe |
"{6C94CD1A-3477-49A6-8F5A-D9740D901888}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{6D25FB67-DC63-4BF0-926C-411A399EC3F7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{6ECEEA95-8C4C-407C-8068-0E01F8596956}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{7285C984-4AB6-4C8D-83DE-AA57BAAE2540}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\archeblade\binaries\win32\archeblade.exe |
"{759CED39-6B8B-48B9-9B57-0D8FAE9BD43B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dins curse demo\dinscurse.exe |
"{76A5CE02-7680-44D7-9667-C91693B91EF6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dwarfs - f2p\dwarfs.exe |
"{78645FCB-CF39-439C-BE7B-48D1D298AFB6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcs must die 2\build\release\orcsmustdie2.exe |
"{7AED8428-37D7-4B55-9CE2-96DB4E5CA0D7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gnomoria\gnomoria.exe |
"{7B0EF11E-446E-48DB-BAC2-F55EC0DABC64}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7C2B26C3-B73D-41C8-9725-093375E1C00F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
"{7D3B83DB-6DE3-40A2-B44E-9FCBA9926697}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\castlecrashers\castle.exe |
"{7FE36847-95DB-4A35-95AB-6B5BC5D07974}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dins curse demo\dinscurse.exe |
"{807C8A48-C0DD-4D45-AFA0-D5D76FAC9169}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404 - königsedition\addon.exe |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{8233DCBC-B971-4484-BCF3-1EC90A6D0C35}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amnesia the dark descent\launcher.exe |
"{824EA552-51E6-4C12-B01A-7B1E01D8D8CC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lord of the rings online\turbineinvoker.exe |
"{8251F26E-11BA-4E37-B01C-CDB1569F9BB2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{830F0FEA-1BCF-406E-BB3E-C5D5C68EA2F0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2\trine2_launcher.exe |
"{84D5A8D8-6C36-4FF7-98F4-639F0636ABA4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\archeblade\binaries\win32\archeblade.exe |
"{85C20383-1BEF-4175-87AA-539E65FE27BD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2\trine2_launcher.exe |
"{873AEA4F-D6D4-45F1-A85C-084599236B65}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia forgotten sands\prince of persia.exe |
"{8742A7E1-6B76-4FA6-8731-578FF67F635A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{87C75011-0748-40C4-AAC5-CBB3336E6FCF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{883C5D06-3018-49AE-99F0-E8D084A3A06E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia the sands of time\princeofpersia.exe |
"{891B9891-5B47-4C06-A390-267B606B0B2D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\renaissance heroes\bridealauncher.exe |
"{895F13D1-0911-4836-9AF4-5B06A64F99A6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age2hd\launcher.exe |
"{89B954E3-AD13-42F1-9CC0-39C6CDD3006F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia two thrones\princeofpersia.exe |
"{8ACC1E38-E8B7-4B94-BBB6-6A71E92D3B81}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{8ADA0186-E0B4-4198-887F-A7A2FF9376FE}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{8B2E988A-26F1-43A0-9102-2A955C8EE51E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age2hd\launcher.exe |
"{8EC105F0-4D3F-4E24-9892-C096D7870DBB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age2hd\launcher.exe |
"{8FD7EDA3-A797-4255-92A2-D23D0A1E7B9F}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{9021A217-5C58-43E2-92AF-7282ADE96D1F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sleepingdogs\hkship.exe |
"{91A13D59-9EE8-4848-B131-E907E4C513E1}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{93D67CB1-E82C-49F4-922A-CB93434AF55F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{93E5ED86-5FC4-4F4D-95EA-308FC9122DBB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 2\bin\sam2.exe |
"{945AE1C3-8A01-45A4-B60F-AD7F7D177FDC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{94894C3A-F1BB-4BF5-9FC7-96031A69EE41}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\airmech\airmech.exe |
"{97D8B6BA-F5DD-4888-917E-3E1980021719}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mirrors edge\binaries\mirrorsedge.exe |
"{98A894DA-8A07-456B-930F-7552AD98CDF3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 2\bin\dedicatedserver.exe |
"{9AD40217-701B-4D30-B3FE-C8BD8F05D5B3}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{9BD128E0-65C1-4FEA-91F1-55069D424F8C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the banner saga factions\win32\the banner saga factions.exe |
"{9C765FD4-2E85-48F2-BB12-2EADFF3A66F6}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{9C85EBDA-9A5F-4269-985B-2E6482404D1E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amnesia the dark descent\launcher.exe |
"{9DBC2A36-8051-402B-AB1C-DDD30CCCC528}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{9DCE65E3-AC68-4D4B-A15C-34BFDD3FBA8A}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404 - königsedition\anno4.exe |
"{9DF46A4D-06B8-49D0-A1D7-8F637D206DCB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\krater demo\run_game.exe |
"{A02DBBFE-EA57-4DBC-BA4A-C5DCCCE1F731}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\supercratebox\supercratebox.exe |
"{A099B61D-A1CC-4987-AB65-6A4A46EF6034}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\supercratebox\supercratebox.exe |
"{A0AAEBC8-3F6B-48D2-9508-68B8E4D5589D}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404 - königsedition\tools\anno4web.exe |
"{A40EF0D7-9F93-418A-8010-ED69FF3B8242}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
"{A43781E5-6A2A-406E-A288-7B96D58B8CAE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serioussamdoubled\ssgame.exe |
"{A5FECC44-1498-4A13-8C60-3F864ED3879E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\poxnora\launchpad.exe |
"{A6629400-2CF2-42D1-ABAF-8E91EF1396B4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcs must die 2\build\release\orcsmustdie2.exe |
"{A825661B-5684-4273-9F5E-7E95FE2EDD5A}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404 - königsedition\tools\addonweb.exe |
"{A89398BE-8619-4A98-BAC6-F1CFA7498A54}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{AB5F6420-25DA-4562-8CCF-6D6A26633B6D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 3\bin\sam3_unrestricted.exe |
"{AC55B685-03D8-4B5D-96B3-12A14D2DA80E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
"{ACA33D29-7F2C-48E3-95CE-4F841A1F3A74}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\krater demo\run_game.exe |
"{AD01EB2F-BA52-4066-9C97-A40EAB0840C0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{AD788440-AC87-478F-925D-635D8911979F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unmechanical\binaries\win32\udk.exe |
"{AD8854F8-AB84-4FB2-9512-1BE733A5B190}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{AE030391-3B01-4E2F-AB94-1FAE94D1DEF1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unmechanical\binaries\win32\udk.exe |
"{B1ACBCF5-E71B-45DF-91D6-4CBE25F5788D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 2\bin\dedicatedserver.exe |
"{B1CF0F4C-5D89-4E7E-A25B-F755163EE597}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B32C0B51-AF9C-4171-A70E-D159689EFA45}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B3492401-C777-48A5-875F-B6AACB2E4263}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe |
"{B50FBD68-13AF-4738-A153-BCC282ED9382}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2 demo\trine2_launcher.exe |
"{B5618049-5203-4817-A9F0-5DF1CE98CBB2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{B6696433-02FE-4525-8DBD-093AC1E8B269}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia the warrior within\princeofpersia.exe |
"{B76F9DAE-DC23-42B2-84D6-4C535473F97C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sleepingdogs\hkship.exe |
"{BA3CB8F6-D8D3-4DA7-89B9-29E7646B2BBB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 2\bin\sam2.exe |
"{BA6F34A4-D11E-46AA-8999-D08963B5F534}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe |
"{BB15458B-270C-4A9B-A034-63DF61C185EE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 3\bin\sam3.exe |
"{BB5AE134-C6AC-4301-A1FB-D8D051E5CFC1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the banner saga factions\win32\the banner saga factions.exe |
"{BBEFC994-2841-4255-A617-BF6EDF553756}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{BCC23A6D-8FF6-46A0-A913-844E8D27729E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{BD7A7ABE-8053-4FB4-9034-8065A56C3F98}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serioussamdoubled\ssgame.exe |
"{BDBB54CF-9BA1-431F-A890-57291EDE96B1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 2\bin\dedicatedserver.exe |
"{BF3E1588-3987-4D4A-81D2-105C4D8BE928}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hitman absolution\hma.exe |
"{BF4BAA04-2270-429C-8D88-9E96C55AEE9F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{C01126E0-D014-470F-AB57-E49491A1048E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia two thrones\princeofpersia.exe |
"{C0E369D6-0B60-4181-8CCF-731DD64DF58D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dwarfs - f2p\dwarfs.exe |
"{C116234F-AF8C-4A3E-BE20-241D507E121D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 3\bin\sam3.exe |
"{C1352AF5-A79A-4AD3-A738-8B0F38D990C1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 3\bin\sam3_unrestricted.exe |
"{C19B2F89-1B9F-40D0-B111-828F7FAA4999}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\castlecrashers\castle.exe |
"{C29DBB19-A68E-41B4-BE04-CB0CAF310339}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sleepingdogs\hkship.exe |
"{C32A81A5-C0F0-4A9D-ABA0-4DE1979AFD68}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{C3BAE191-1B73-4603-91D0-80FDA11ED53B}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{C40FB18B-EF35-422B-9E57-1BF0AD42CC48}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the banner saga factions\win32\the banner saga factions.exe |
"{C43E68CF-B230-4F15-9BAD-3E7BB435A4C3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{C47940A6-0FA7-4BCF-8C42-FC5D34B22A03}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcs must die 2\build\release\orcsmustdie2.exe |
"{C4C056EA-41F6-4D12-AB26-70B9801B5258}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia\launcher\launcher.exe |
"{C5A1D004-8FDF-4735-9949-398C4AB514D6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam the random encounter\sstre.exe |
"{C5F6868A-CB22-49B8-A218-690D9C1F2816}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{C649E1AD-F030-438F-ACD3-CF563F85B73E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\archeblade\binaries\win32\archeblade.exe |
"{C7296419-B8C3-414B-AF24-F194161743BC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mirrors edge\support\ea help\electronic_arts_technical_support.htm |
"{C8485611-C72E-4CC2-8B75-51D5F43FD539}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{C85ACC3D-08FA-4A71-9604-1A5CC4314C4B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bulletstorm demo\binaries\win32\shippingpc-stormgame.exe |
"{C88DA139-ADC4-4D82-B634-8737EF24ADD8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C8FD4908-E14C-4296-A52F-6D02E3E2D37E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia the warrior within\princeofpersia.exe |
"{CA362FA1-C85D-4927-B827-BB1654F5EB5E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
"{CAE6A77E-A0B5-4DF8-B5CC-77A330E7F978}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam the random encounter\sstre.exe |
"{CB848A52-5EFC-4278-B063-9C3F8BC32FF8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
"{CD974D10-11BE-4326-81A0-AB8FCDE58D6A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe |
"{CE91B9CA-C795-44B6-BDA8-D6258BEC32BA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2 demo\trine2_launcher.exe |
"{D12EB5BD-AE92-438E-A2A4-5E8C4269AFC1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\krater demo\run_game.exe |
"{D1EE4449-7F0B-4028-A2DE-E4DC4ED91B06}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 2\bin\dedicatedserver.exe |
"{D32ED3AA-0824-4F85-8168-C61367877D2F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\airmech\airmech.exe |
"{D365CF95-568B-4563-A838-6033D6AAC4B8}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{D5BB726F-2175-42B6-9921-754E749A7BED}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} |
"{D63DEAEB-4CF3-4F9B-A70B-BE571894DB2B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\krater demo\run_game.exe |
"{D698CFB8-3624-45D6-BF4D-CBC9E917C350}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404 - königsedition\addon.exe |
"{D749BEA0-AFCE-411F-8F26-2CB1799075E2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam the random encounter\sstre.exe |
"{D7BE538F-844E-412D-8AE2-2D459E2D1670}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{D8254036-25B8-4F92-95AA-586759F6C488}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404 - königsedition\tools\anno4web.exe |
"{D93ED920-1469-421C-98DB-3865E978D5C8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam the random encounter\sstre.exe |
"{D9E984F5-AB7E-4EBB-8B9E-E8AF89964906}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\airmech\airmech.exe |
"{DA6ECFA6-AFA1-44AB-BD2F-0A81C96A1CB6}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{DC314223-0A28-4E62-A66C-DD7F377EA479}" = protocol=17 | dir=in | app=c:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe |
"{DCEBDC65-F076-4DDD-A70F-C25A2F0337AD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe |
"{DE5A8B8D-1367-40CA-BE12-64E6D6CEBCCA}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{DEC442C1-0753-4FDA-A7FC-6877F0F6C654}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2\trine2_launcher.exe |
"{E09304D3-0FAB-496C-BB17-4ADDB107CBEA}" = protocol=6 | dir=in | app=c:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe |
"{E0DA97FA-2B72-4033-B350-1F0CD8EC039E}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{E509CE4E-FEB8-4812-AC0C-C9BFEC8735F1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{E59BCEC3-5BB1-47A1-A631-1FF7295479DE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bulletstorm demo\binaries\win32\shippingpc-stormgame.exe |
"{E64721DD-4B07-49D9-9CB4-D30897BF0622}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia\launcher\launcher.exe |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{E8FC40A4-886F-4741-BEB0-527A653D4CA0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mirrors edge\binaries\mirrorsedge.exe |
"{E915E54C-72D9-4E77-8F03-EC03D2A0D502}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia forgotten sands\prince of persia.exe |
"{E94431A2-BF36-47DB-AF99-D5DE983BC1A1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{EC7F2695-8870-4BAE-81CA-0BB3AAB182DF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\airmech\airmech.exe |
"{ECA139EF-67B5-42E0-B749-06E1E971EAF6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 3\bin\sam3_unrestricted.exe |
"{ED68315B-5E8B-4A74-8256-DFF6092D2B82}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404 - königsedition\anno4.exe |
"{F1F657E2-5A86-410E-95C5-4BCB86D20A89}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hitman absolution\hma.exe |
"{F32A405E-CD37-43FA-B8F2-FFABDC647BC9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unmechanical\binaries\win32\udk.exe |
"{F4287F1C-A50C-4D49-90BD-EE2F95856070}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{F5DE0A25-0435-4E91-8748-E8D8166242B8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{F5FB94E3-E3F3-4242-9DCF-48DCA21EDEB9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serioussamdoubled\ssgame.exe |
"{F5FCABD1-0FAC-4484-BCEC-584E548CD0B3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{F636C8FD-6445-40A2-8D40-89CA4ACDF7F8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mirrors edge\support\ea help\electronic_arts_technical_support.htm |
"{F7460FE7-0E8A-41D1-8D19-E2F912101D84}" = protocol=6 | dir=in | app=c:\users\ruben\downloads\neverwinter_nw.1.20130416a.6.exe |
"{F7EA8D92-7880-48E7-8781-D081F9DCC9CC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{FA46D5FA-1000-4E66-B212-905F9D51D186}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prince of persia forgotten sands\prince of persia.exe |
"{FADEFD79-F63F-4DC5-8C08-99118CF28A69}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{FBFA6CB2-47D6-42BE-850F-9EE5BD9BFB02}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam 3\bin\sam3.exe |
"{FC425A59-D983-419C-BF46-ABF4996F1444}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FD2B6429-D763-4F81-825A-EF3F21ECB805}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FD8B206A-29AE-427A-B47E-4629811869E0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
"{FF0C77F4-783E-4BCB-9DB5-A502FC9E488D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\archeblade\binaries\win32\archeblade.exe |
"{FF154D5E-A1B9-4774-B01B-53F793160F0A}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404 - königsedition\tools\benchmark.exe |
"TCP Query User{026364E4-7006-4E66-9631-686B3D4C8A20}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{1CB9480E-C55B-425E-9BC2-1966705C47FE}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{2C55C218-DD30-4D9B-9A21-13A88536E6FE}C:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe" = protocol=6 | dir=in | app=c:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe |
"TCP Query User{394986A9-0BE6-4B39-BB25-A43824DE6082}C:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe |
"TCP Query User{46F9DA95-9B0C-46E8-A2E3-A76EBB9F4D91}C:\users\ruben\downloads\neverwinter_nw.1.20130416a.6.exe" = protocol=6 | dir=in | app=c:\users\ruben\downloads\neverwinter_nw.1.20130416a.6.exe |
"TCP Query User{5961AACF-FF95-45EE-B080-2924AFD05EA0}C:\program files (x86)\trillian\trillian.exe" = protocol=6 | dir=in | app=c:\program files (x86)\trillian\trillian.exe |
"TCP Query User{6A65D3E4-637C-4AE8-BFCB-7F05B1649BEE}C:\program files (x86)\swipl\bin\swipl-win.exe" = protocol=6 | dir=in | app=c:\program files (x86)\swipl\bin\swipl-win.exe |
"TCP Query User{6BDA9C38-7721-45D7-B038-4B0834DB6DFF}C:\program files (x86)\steam\steamapps\common\krater demo\krater.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\krater demo\krater.exe |
"TCP Query User{6E552EAB-0183-4234-AA17-62B858991CCF}C:\windows\system32\javaw.exe" = protocol=6 | dir=in | app=c:\windows\system32\javaw.exe |
"TCP Query User{8140D65A-269C-42ED-8338-8670D8695FD0}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |
"TCP Query User{A3224889-6C1C-4FCE-B441-B1195F9A22C9}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe |
"TCP Query User{F85448DF-3945-417F-82B5-2892D42E137D}C:\program files (x86)\tera\tera-launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |
"UDP Query User{0EEA1BB7-0F16-4420-A4CC-7F253483A71F}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{57DC5C36-4E4B-4358-8EC9-1FBCDD86B489}C:\program files (x86)\trillian\trillian.exe" = protocol=17 | dir=in | app=c:\program files (x86)\trillian\trillian.exe |
"UDP Query User{71150DDA-C985-426E-BF75-11E6BE7E4B61}C:\program files (x86)\tera\tera-launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |
"UDP Query User{73E2A1B9-66A9-40D1-85F9-FE8CC7429985}C:\windows\system32\javaw.exe" = protocol=17 | dir=in | app=c:\windows\system32\javaw.exe |
"UDP Query User{747FF1B6-280A-447E-B41E-75A783CCFB81}C:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe" = protocol=17 | dir=in | app=c:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe |
"UDP Query User{992CABD0-3394-4A16-8F55-7CCC795A43EF}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{9D5C915C-34ED-4C87-A4DE-64B8D4EB4B1C}C:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe |
"UDP Query User{A7D5ADC4-53AA-49C1-AD40-AF28F18EAACC}C:\users\ruben\downloads\neverwinter_nw.1.20130416a.6.exe" = protocol=17 | dir=in | app=c:\users\ruben\downloads\neverwinter_nw.1.20130416a.6.exe |
"UDP Query User{B4284386-1581-40BF-B464-37C8F46A712E}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe |
"UDP Query User{D53C273C-FE8E-4383-9420-E5087879DDE2}C:\program files (x86)\steam\steamapps\common\krater demo\krater.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\krater demo\krater.exe |
"UDP Query User{ECB8C36A-B2BA-4648-9ECD-44F9CFFE6B84}C:\program files (x86)\swipl\bin\swipl-win.exe" = protocol=17 | dir=in | app=c:\program files (x86)\swipl\bin\swipl-win.exe |
"UDP Query User{FB727FC6-B65F-4E52-BBF3-38C2423303FF}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417017FF}" = Java 7 Update 17 (64-bit)
"{3145731D-C578-70ED-899F-7A670D2A6662}" = AMD Fuel
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{3C28BFD4-90C7-3138-87EF-418DC16E9598}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5AF4E09F-5C9B-3AAF-B731-544D3DC821DD}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106
"{5E03A267-415E-5383-FA8F-3CE4145663B9}" = AMD Catalyst Install Manager
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{64A3A4F4-B792-11D6-A78A-00B0D0170110}" = Java SE Development Kit 7 Update 11 (64-bit)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89EE4A30-080F-2C95-6F78-C98D18FBD74D}" = AMD Accelerated Video Transcoding
"{9CF11D16-ECEB-90A5-A028-CA9E068D848B}" = ccc-utility64
"{D3941722-C4DD-4509-88C4-0E87F675A859}_is1" = Freeplane
"GIMP-2_is1" = GIMP 2.8.4
"Sandboxie" = Sandboxie 3.76 (64-bit)
"SWI-Prolog" = SWI-Prolog (remove only)
"TeamSpeak 3 Client" = TeamSpeak 3 Client
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{017F8447-2A1D-0DDB-B5D7-CA2BFACE2886}" = CCC Help French
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{054E9A1C-3EA2-C657-E787-FD8DCF5C3D3B}" = CCC Help Czech
"{106B4413-ACBB-4CDE-8707-587DB9BD77EC}" = LogMeIn Hamachi
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1DE2BD51-0300-772D-5E18-F337D95D5687}" = CCC Help German
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{224E8FEB-5C1F-077F-6FC5-602AC1AE644D}" = CCC Help Danish
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21
"{275E9C49-C72F-D754-DEB7-77F10A9C00D8}" = CCC Help Japanese
"{30049739-BE95-6591-B504-E6D7057D49CC}" = CCC Help Spanish
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}" = ANNO 1404 - Königsedition
"{3F1EB155-F96E-EB7B-2EF2-7375490E0FA9}" = CCC Help English
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{41785C66-90F2-40CE-8CB5-1C94BFC97280}" = Microsoft Chart Controls for Microsoft .NET Framework 3.5
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B023D7B-9E67-795D-FB31-B5E1F6DCA451}" = CCC Help Italian
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{55F6C486-8C75-2A72-DAFE-CE78A624C9F7}" = CCC Help Russian
"{5AF23993-7152-1620-E43F-1B4542FB4F84}" = CCC Help Thai
"{5C1130F5-F955-4319-BFF6-AFE4A42BC3A8}_is1" = MaxiDisk
"{63326924-3CAF-C858-3A8F-8598C87019D7}" = AMD VISION Engine Control Center
"{63822E89-11AA-F8EC-D433-F72A85799EC0}" = CCC Help Greek
"{66361420-4905-AEB8-17AE-172FDD164A7E}" = CCC Help Polish
"{6C772996-BFF3-3C8C-860B-B3D48FF05D65}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106
"{6e8f74e0-43bd-4dce-8477-6ff6828acc07}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{769F2A4B-84A3-9486-ADD2-9E5AB4B4E1E3}" = Catalyst Control Center InstallProxy
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8773DD1C-5FB2-95B5-5A93-0EFEAC900A4D}" = CCC Help Norwegian
"{8CCBB0BF-9CC1-1A65-BB93-56012A460EE6}" = CCC Help Portuguese
"{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2
"{8e70e4e1-06d7-470b-9f74-a51bef21088e}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{90A4562F-D4A1-4B65-906D-41F236CF6902}" = Path of Exile
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0A3CE05-96CB-52E9-434E-074F3BB7807E}" = CCC Help Turkish
"{A2S166A0-F031-4E27-A057-C69733219434}_is1" = TERA
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9C64319-932F-D02B-B14C-FFFC3EC49E77}" = CCC Help Chinese Standard
"{C09DB932-7619-7B56-30E3-C0454811D6D7}" = CCC Help Korean
"{C22A4697-BD77-ACB1-744F-1FD0A0BFF798}" = CCC Help Swedish
"{D4B457B2-260F-C561-CA87-703BD3B724CA}" = Catalyst Control Center Graphics Previews Common
"{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh
"{D6CDB506-297D-AE70-0EF6-DE5185F961BE}" = CCC Help Chinese Traditional
"{DB833EF9-A198-49BE-970A-BD46F30BFBB4}" = ANNO 1503 GOLD
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106
"{ECFD508E-68A2-91B2-46DD-1D03D783D94B}" = Catalyst Control Center Localization All
"{EDE361D5-35A5-DA7D-3462-C3DABD24029B}" = CCC Help Hungarian
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E7DD6A-AE2D-D706-BEB3-937F76CA6AE9}" = CCC Help Finnish
"{F56F54DD-BCB2-1221-2CB7-E983A5CF9D15}" = CCC Help Dutch
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"5513-1208-7298-9440" = JDownloader 0.9
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"avast" = avast! Free Antivirus
"foobar2000" = foobar2000 v1.2.2
"Foxit Reader_is1" = Foxit Reader
"Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 7.2
"Google Chrome" = Google Chrome
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300
"Neverwinter" = Neverwinter
"Notepad++" = Notepad++
"PunkBusterSvc" = PunkBuster Services
"RaidCall" = RaidCall
"Steam App 105600" = Terraria
"Steam App 111600" = Serious Sam Double D
"Steam App 12900" = Audiosurf
"Steam App 13500" = Prince of Persia: Warrior Within
"Steam App 13530" = Prince of Persia: The Two Thrones
"Steam App 13600" = Prince of Persia: The Sands of Time
"Steam App 17080" = Tribes: Ascend
"Steam App 17410" = Mirror's Edge
"Steam App 19980" = Prince of Persia
"Steam App 201210" = PoxNora
"Steam App 201480" = Serious Sam: The Random Encounter
"Steam App 201790" = Orcs Must Die! 2
"Steam App 202170" = Sleeping Dogs™
"Steam App 203140" = Hitman: Absolution
"Steam App 204260" = Trine 2 Demo
"Steam App 204340" = Serious Sam 2
"Steam App 204360" = Castle Crashers
"Steam App 206500" = AirMech
"Steam App 207230" = Archeblade
"Steam App 209870" = Blacklight: Retribution
"Steam App 211180" = Unmechanical
"Steam App 212500" = The Lord of the Rings Online™
"Steam App 212800" = Super Crate Box
"Steam App 213650" = Dwarfs F2P
"Steam App 214560" = Mark of the Ninja
"Steam App 218110" = Din's Curse Demo
"Steam App 219340" = The Banner Saga: Factions
"Steam App 219740" = Don't Starve
"Steam App 220" = Half-Life 2
"Steam App 221380" = Age of Empires II: HD Edition
"Steam App 221790" = Renaissance Heroes
"Steam App 224500" = Gnomoria
"Steam App 224640" = Krater Demo
"Steam App 33320" = Prince of Persia: The Forgotten Sands
"Steam App 35720" = Trine 2
"Steam App 400" = Portal
"Steam App 41000" = Serious Sam HD: The First Encounter
"Steam App 41010" = Serious Sam HD: The Second Encounter
"Steam App 41070" = Serious Sam 3: BFE
"Steam App 570" = Dota 2
"Steam App 57300" = Amnesia: The Dark Descent
"Steam App 65800" = Dungeon Defenders
"Steam App 8980" = Borderlands
"Steam App 99870" = Bulletstorm Demo
"SWI-Prolog" = SWI-Prolog (remove only)
"Trillian" = Trillian
"VLC media player" = VLC media player 2.0.2
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 10.05.2013 18:33:18 | Computer Name = *** | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: League of Legends.exe, Version: 3.6.0.389,
Zeitstempel: 0x517af769 Name des fehlerhaften Moduls: League of Legends.exe, Version:
3.6.0.389, Zeitstempel: 0x517af769 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00014602
ID
des fehlerhaften Prozesses: 0x4c Startzeit der fehlerhaften Anwendung: 0x01ce4dc8fb330f34
Pfad
der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.229\deploy\League
of Legends.exe Pfad des fehlerhaften Moduls: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.229\deploy\League
of Legends.exe Berichtskennung: 9c1f2f04-b9c1-11e2-be79-1c6f6581e666 Vollständiger
Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket
ist:
Error - 10.05.2013 18:33:21 | Computer Name =*** | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: League of Legends.exe, Version: 3.6.0.389,
Zeitstempel: 0x517af769 Name des fehlerhaften Moduls: rads.dll, Version: 0.0.0.0,
Zeitstempel: 0x510195ce Ausnahmecode: 0xc00001a5 Fehleroffset: 0x00000000 ID des fehlerhaften
Prozesses: 0x4c Startzeit der fehlerhaften Anwendung: 0x01ce4dc8fb330f34 Pfad der
fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.229\deploy\League
of Legends.exe Pfad des fehlerhaften Moduls: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.229\deploy\rads.dll
Berichtskennung:
9e27e139-b9c1-11e2-be79-1c6f6581e666 Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error - 10.05.2013 18:33:27 | Computer Name = ***| Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: League of Legends.exe, Version: 3.6.0.389,
Zeitstempel: 0x517af769 Name des fehlerhaften Moduls: League of Legends.exe, Version:
3.6.0.389, Zeitstempel: 0x517af769 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00014602
ID
des fehlerhaften Prozesses: 0x4c Startzeit der fehlerhaften Anwendung: 0x01ce4dc8fb330f34
Pfad
der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.229\deploy\League
of Legends.exe Pfad des fehlerhaften Moduls: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.229\deploy\League
of Legends.exe Berichtskennung: a1a516de-b9c1-11e2-be79-1c6f6581e666 Vollständiger
Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket
ist:
Error - 12.05.2013 13:03:07 | Computer Name = ***| Source = Application Hang | ID = 1002
Description = Programm League of Legends.exe, Version 3.6.0.389 kann nicht mehr
unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf
in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
zu suchen. Prozess-ID: 9d8 Startzeit: 01ce4f32859237bb Endzeit: 18 Anwendungspfad:
C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.229\deploy\League
of Legends.exe Berichts-ID: c7b93514-bb25-11e2-be79-1c6f6581e666 Vollständiger Name
des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error - 13.05.2013 07:00:36 | Computer Name = ***| Source = Desktop Window Manager | ID = 9020
Description = Der Desktopfenster-Manager hat einen schwerwiegenden Fehler (0x8898008d)
festgestellt.
Error - 13.05.2013 08:25:27 | Computer Name = ***| Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: soffice.bin, Version: 3.2.9498.500,
Zeitstempel: 0x4bf4c207 Name des fehlerhaften Moduls: RPCRT4.dll, Version: 6.2.9200.16384,
Zeitstempel: 0x50108b02 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00010137 ID des fehlerhaften
Prozesses: 0xb30 Startzeit der fehlerhaften Anwendung: 0x01ce4fd0ee38a9b7 Pfad der
fehlerhaften Anwendung: C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
Pfad
des fehlerhaften Moduls: C:\Windows\SYSTEM32\RPCRT4.dll Berichtskennung: 30f5ac35-bbc8-11e2-be79-1c6f6581e666
Vollständiger
Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket
ist:
Error - 13.05.2013 18:53:19 | Computer Name = ***| Source = Application Hang | ID = 1002
Description = Programm League of Legends.exe, Version 3.6.0.389 kann nicht mehr
unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf
in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
zu suchen. Prozess-ID: 1c70 Startzeit: 01ce502ca4a7697e Endzeit: 67 Anwendungspfad:
C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.229\deploy\League
of Legends.exe Berichts-ID: e3cf8ced-bc1f-11e2-be79-1c6f6581e666 Vollständiger Name
des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error - 17.05.2013 08:30:19 | Computer Name = ***| Source = Desktop Window Manager | ID = 9020
Description = Der Desktopfenster-Manager hat einen schwerwiegenden Fehler (0x8898008d)
festgestellt.
Error - 17.05.2013 15:21:36 | Computer Name = ***| Source = Microsoft-Windows-Immersive-Shell | ID = 2486
Description = Die App „microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos“
wurde nicht innerhalb der vorgesehenen Zeit gestartet.
Error - 17.05.2013 16:34:22 | Computer Name = ***| Source = Microsoft-Windows-Immersive-Shell | ID = 2486
Description = Die App „Microsoft.ZuneVideo_8wekyb3d8bbwe!Microsoft.ZuneVideo“ wurde
nicht innerhalb der vorgesehenen Zeit gestartet.
[ System Events ]
Error - 19.05.2013 17:09:33 | Computer Name = ***| Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt
gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende
Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus
lautet: 900.
Error - 19.05.2013 17:34:41 | Computer Name = ***| Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt
gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende
Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus
lautet: 900.
Error - 19.05.2013 17:34:41 | Computer Name = ***| Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt
gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende
Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus
lautet: 900.
Error - 19.05.2013 18:19:36 | Computer Name = ***| Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt
gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende
Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus
lautet: 900.
Error - 19.05.2013 18:19:36 | Computer Name = ***| Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt
gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende
Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus
lautet: 900.
Error - 20.05.2013 00:31:26 | Computer Name = ***| Source = Microsoft-Windows-Kernel-General | ID = 6
Description =
Error - 21.05.2013 16:36:32 | Computer Name = ***| Source = Microsoft-Windows-Kernel-General | ID = 6
Description =
Error - 21.05.2013 16:37:53 | Computer Name = ***| Source = Service Control Manager | ID = 7024
Description = Der Dienst "HitmanPro 3.7 Crusader (Boot)" wurde mit dem folgenden
dienstspezifischen Fehler beendet: %%0
Error - 21.05.2013 16:58:17 | Computer Name = ***| Source = Microsoft-Windows-Kernel-General | ID = 6
Description =
Error - 21.05.2013 17:30:38 | Computer Name = ***| Source = Service Control Manager | ID = 7034
Description = Dienst "Sandboxie Service" wurde unerwartet beendet. Dies ist bereits
1 Mal passiert.
< End of report > GMER: Code:
zu lang :P ist der log nötig, wenn ja hänge ich ihn an
EDIT: Den Webplayer hab ich wegbekommen^^ hatte mich nie mit beschäftigt, hab mir einfach mal mit autoruns die Startenden programme angeschaut und das Verzeichnis gefunden |