| Teronius |  14.06.2013 07:08 |        Hallo :)  
läuft alles super soweit. Hier sind die beiden TXTs:    Code:  
 OTL logfile created on: 14.06.2013 07:51:40 - Run 1 
OTL by OldTimer - Version 3.2.69.0     Folder = D:\Downloads 
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation 
Internet Explorer (Version = 9.10.9200.16614) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
3,74 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 63,23% Memory free 
7,48 Gb Paging File | 5,80 Gb Available in Paging File | 77,56% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 97,66 Gb Total Space | 10,21 Gb Free Space | 10,45% Space Free | Partition Type: NTFS 
Drive D: | 356,01 Gb Total Space | 215,45 Gb Free Space | 60,52% Space Free | Partition Type: NTFS 
  
Computer Name: MARCITO | User Name: Marco | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans 
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Processes (SafeList) ========== 
  
PRC -  File not found 
PRC - D:\Downloads\OTL.exe (OldTimer Tools) 
PRC - C:\Users\Marco\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) 
PRC - C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH) 
PRC - C:\Program Files (x86)\PDF Architect\ConversionService.exe (pdfforge GmbH) 
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) 
PRC - C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) 
PRC - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) 
PRC - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) 
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) 
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) 
  
   ========== Modules (No Company Name) ========== 
  
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll () 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\716959df79685a1eae0fc14275a32b0f\WindowsBase.ni.dll () 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll () 
MOD - C:\Users\Marco\AppData\Roaming\Dropbox\bin\libcef.dll () 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll () 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll () 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll () 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll () 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll () 
MOD - C:\Users\Marco\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll () 
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll () 
  
   ========== Services (SafeList) ========== 
  
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD) 
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
SRV - (4game-service) -- C:\Program Files (x86)\4game\4game-service.exe (Innova Co S.a r.l.) 
SRV - (PDF Architect Helper Service) -- C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH) 
SRV - (PDF Architect Service) -- C:\Program Files (x86)\PDF Architect\ConversionService.exe (pdfforge GmbH) 
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) 
SRV - (AVGIDSAgent) -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) 
SRV - (npggsvc) -- C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.) 
SRV - (avgwd) -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) 
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) 
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) 
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) 
SRV - (EvtEng) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) 
SRV - (RegSrvc) -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation) 
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV:64bit: - (Avgmfx64) -- C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.) 
DRV:64bit: - (AVGIDSDriver) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. ) 
DRV:64bit: - (AVGIDSHA) -- C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. ) 
DRV:64bit: - (Avgldx64) -- C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.) 
DRV:64bit: - (Avgtdia) -- C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.) 
DRV:64bit: - (Avgloga) -- C:\Windows\SysNative\drivers\avgloga.sys (AVG Technologies CZ, s.r.o.) 
DRV:64bit: - (Avgrkx64) -- C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.) 
DRV:64bit: - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr)) 
DRV:64bit: - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr)) 
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) 
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.) 
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.) 
DRV:64bit: - (intelkmd) -- C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation) 
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) 
DRV:64bit: - (Impcd) -- C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation) 
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation) 
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.) 
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices) 
DRV:64bit: - (Netaapl) -- C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.) 
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) 
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) 
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation) 
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) 
DRV:64bit: - (tsusbhub) -- C:\Windows\SysNative\drivers\tsusbhub.sys (Microsoft Corporation) 
DRV:64bit: - (Synth3dVsc) -- C:\Windows\SysNative\drivers\Synth3dVsc.sys (Microsoft Corporation) 
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation) 
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation) 
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) 
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation) 
DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.) 
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) 
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated) 
DRV:64bit: - (HECIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation) 
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) 
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) 
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) 
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) 
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) 
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) 
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) 
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) 
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =  
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm 
IE - HKLM\..\SearchScopes,DefaultScope =  
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC 
  
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = D:\Downloads 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7F 69 6D BA 0B ED CC 01  [binary data] 
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} 
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
   ========== FireFox ========== 
  
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) 
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@4game.com/plugin: C:\Program Files (x86)\4game\npplugin4game.dll (Innova Co S.a r.l.) 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll File not found 
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) 
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) 
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) 
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon) 
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) 
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) 
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Marco\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) 
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Marco\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) 
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) 
  
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.02.17 02:42:16 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\FFPDFArchitectConverter@pdfarchitect.com: C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013.05.16 03:17:07 | 000,000,000 | ---D | M] 
  
   ========== Chrome  ========== 
  
CHR - default_search_provider: Google (Enabled) 
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} 
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} 
CHR - homepage: hxxp://www.google.com/ 
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Marco\AppData\Local\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll 
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer 
CHR - plugin: Native Client (Enabled) = C:\Users\Marco\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll 
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Marco\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll 
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll 
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll 
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll 
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll 
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll 
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll 
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll 
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll 
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll 
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonEU\NGM\npNxGameeu.dll 
CHR - plugin: Google Update (Enabled) = C:\Users\Marco\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll 
CHR - Extension: YouTube = C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ 
CHR - Extension: Google-Suche = C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\ 
CHR - Extension: DVDVideoSoft Browser Extension = C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\ 
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\ 
CHR - Extension: Google Mail = C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ 
  
O1 HOSTS File: ([2013.06.11 21:20:38 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts 
O1 - Hosts: 127.0.0.1       localhost 
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) 
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) 
O2 - BHO: (PDF Architect Helper) - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) 
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) 
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.) 
O4:64bit: - HKLM..\Run: [CNAP2 Launcher] C:\Windows\SysNative\spool\drivers\x64\3\CNAP2LAK.EXE (CANON INC.) 
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) 
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) 
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) 
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) 
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) 
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) 
O4 - HKCU..\Run: [CNAP2 Launcher] C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE File not found 
O4 - HKCU..\Run: [NCsoft Launcher] C:\Program Files (x86)\NCSoft\Launcher\NCLauncher.exe (NCSOFT) 
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe (Adobe Systems, Inc.) 
O4 - Startup: C:\Users\Marco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Marco\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) 
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present 
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Marco\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm File not found 
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Marco\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found 
O8 - Extra context menu item: Free YouTube Download - C:\Users\Marco\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm File not found 
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Marco\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found 
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) 
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) 
O13 - gopher Prefix: missing 
O15 - HKCU\..Trusted Domains: 4game.com ([]https in Trusted sites) 
O15 - HKCU\..Trusted Ranges: Range1 ([https] in Trusted sites) 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) 
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4D7A493D-A685-4F47-B6CC-31249886D4F2}: DhcpNameServer = 192.168.0.1 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{53CA3E99-806F-4A13-8C18-5E7C03514239}: DhcpNameServer = 192.168.0.1 
O18:64bit: - Protocol\Handler\linkscanner - No CLSID value found 
O18:64bit: - Protocol\Handler\livecall - No CLSID value found 
O18:64bit: - Protocol\Handler\msnim - No CLSID value found 
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found 
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found 
O18 - Protocol\Handler\linkscanner - No CLSID value found 
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) 
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) 
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. 
O32 - HKLM CDRom: AutoRun - 1 
O34 - HKLM BootExecute: (autocheck autochk *) 
O35:64bit: - HKLM\..comfile [open] -- "%1" %* 
O35:64bit: - HKLM\..exefile [open] -- "%1" %* 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* 
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* 
O37 - HKLM\...com [@ = ComFile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) 
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) 
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2013.06.13 01:51:31 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll 
[2013.06.13 01:51:31 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll 
[2013.06.13 01:51:30 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll 
[2013.06.13 01:51:30 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll 
[2013.06.13 01:51:29 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll 
[2013.06.13 01:51:29 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll 
[2013.06.13 01:51:29 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe 
[2013.06.13 01:51:29 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe 
[2013.06.13 01:51:29 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe 
[2013.06.13 01:51:29 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll 
[2013.06.13 01:51:29 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll 
[2013.06.13 01:51:28 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll 
[2013.06.13 01:51:28 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll 
[2013.06.13 01:51:28 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll 
[2013.06.13 01:51:27 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll 
[2013.06.12 13:58:50 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll 
[2013.06.12 13:58:49 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll 
[2013.06.12 13:58:49 | 000,492,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll 
[2013.06.12 13:58:42 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptdlg.dll 
[2013.06.12 13:58:42 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptdlg.dll 
[2013.06.12 13:58:36 | 001,464,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll 
[2013.06.12 13:58:36 | 001,192,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certutil.exe 
[2013.06.12 13:58:36 | 000,903,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certutil.exe 
[2013.06.12 13:58:36 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll 
[2013.06.12 13:58:36 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certenc.dll 
[2013.06.12 13:58:36 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certenc.dll 
[2013.06.12 13:58:31 | 001,887,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll 
[2013.06.12 13:58:31 | 001,505,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll 
[2013.06.11 21:25:23 | 000,000,000 | ---D | C] -- C:\Windows\temp 
[2013.06.11 21:20:43 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN 
[2013.06.11 21:07:25 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe 
[2013.06.11 21:07:25 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe 
[2013.06.11 21:07:25 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe 
[2013.06.11 21:06:22 | 000,000,000 | ---D | C] -- C:\Qoobox 
[2013.06.11 21:06:01 | 000,000,000 | ---D | C] -- C:\Windows\erdnt 
[2013.06.11 20:58:47 | 000,000,000 | ---D | C] -- C:\found.001 
[2013.06.11 20:11:09 | 000,000,000 | ---D | C] -- C:\FRST 
[2013.06.11 02:59:45 | 004,702,568 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\SysWow64\GameMon.des 
[2013.06.11 02:59:23 | 000,004,682 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\SysWow64\npptNT2.sys 
[2013.06.11 02:58:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\INCA Shared 
[2013.06.11 00:44:20 | 000,000,000 | ---D | C] -- C:\Users\Marco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCsoft 
[2013.06.11 00:39:59 | 000,000,000 | ---D | C] -- C:\Users\Marco\AppData\Local\assembly 
[2013.06.11 00:39:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCsoft 
[2013.06.11 00:39:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NCSoft 
[2013.06.11 00:10:36 | 000,000,000 | ---D | C] -- C:\Users\Marco\AppData\Local\{1C0CF29B-EAEC-403C-A5BB-779E17310447} 
[2013.06.10 22:14:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4game 
[2013.06.10 22:14:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\4game 
[2013.06.03 22:51:43 | 000,000,000 | ---D | C] -- C:\Users\Marco\AppData\Roaming\WinRAR 
[2013.05.23 23:44:00 | 000,000,000 | ---D | C] -- C:\Users\Marco\AppData\Roaming\TS3Client 
[2013.05.23 23:43:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamSpeak 3 Client 
[2013.05.16 03:17:15 | 000,000,000 | ---D | C] -- C:\Users\Marco\Documents\PDF Architect Files 
[2013.05.16 03:17:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 
[2013.05.16 03:17:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDF Architect 
[2013.05.16 03:16:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator 
[2013.05.16 03:16:25 | 001,070,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCOMCTL.OCX 
[2013.05.16 03:16:25 | 000,662,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCOMCT2.OCX 
[2013.05.16 03:16:25 | 000,137,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSMAPI32.OCX 
[2013.05.16 03:16:25 | 000,110,264 | ---- | C] (pdfforge GmbH) -- C:\Windows\SysNative\pdfcmon.dll 
[2013.05.16 03:16:22 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCMCDE.DLL 
[2013.05.16 03:16:22 | 000,125,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VB6DE.DLL 
[2013.05.16 03:16:22 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCC2DE.DLL 
[2013.05.16 03:16:22 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSMPIDE.DLL 
[2013.05.15 15:56:03 | 000,265,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys 
[2013.05.15 15:56:03 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll 
[2013.05.15 15:55:51 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll 
[2013.05.15 15:55:51 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll 
[2013.05.15 15:55:51 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll 
[2013.05.15 15:55:51 | 000,111,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe 
[2013.05.15 15:55:43 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanprotdim.dll 
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] 
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] 
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] 
   ========== Files - Modified Within 30 Days ========== 
  
[2013.06.14 07:37:19 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
[2013.06.14 07:37:19 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
[2013.06.14 07:34:17 | 003,610,200 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat 
[2013.06.14 07:34:17 | 001,506,082 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat 
[2013.06.14 07:34:17 | 001,074,872 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat 
[2013.06.14 07:34:17 | 000,958,062 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat 
[2013.06.14 07:34:17 | 000,005,194 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI 
[2013.06.14 07:29:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat 
[2013.06.14 07:29:19 | 3010,842,624 | -HS- | M] () -- C:\hiberfil.sys 
[2013.06.13 17:08:01 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1894934171-1551603685-868937202-1000UA.job 
[2013.06.11 21:20:38 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts 
[2013.06.11 02:27:55 | 000,002,094 | ---- | M] () -- C:\Users\Marco\Desktop\Lineage II.lnk 
[2013.06.11 00:39:40 | 000,002,028 | ---- | M] () -- C:\Users\Public\Desktop\NCsoft Launcher.lnk 
[2013.06.09 22:07:07 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1894934171-1551603685-868937202-1000Core.job 
[2013.06.06 12:10:29 | 000,002,363 | ---- | M] () -- C:\Users\Marco\Desktop\Google Chrome.lnk 
[2013.06.01 22:12:54 | 000,001,048 | ---- | M] () -- C:\Users\Marco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 
[2013.06.01 22:12:42 | 000,001,016 | ---- | M] () -- C:\Users\Marco\Desktop\Dropbox.lnk 
[2013.05.29 20:16:40 | 001,317,706 | ---- | M] () -- C:\Users\Public\Documents\Stundenzettel.pdf 
[2013.05.28 13:35:24 | 000,470,058 | ---- | M] () -- C:\Users\Marco\Desktop\Mickey-Mouse-hd-wallpapers.jpg 
[2013.05.28 13:14:21 | 001,910,847 | ---- | M] () -- C:\Users\Marco\Desktop\23724_3d_3d_transparent_pokeball (1).jpg 
[2013.05.23 23:43:21 | 000,001,162 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 
[2013.05.17 03:25:27 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll 
[2013.05.17 03:25:26 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll 
[2013.05.17 03:25:26 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll 
[2013.05.17 03:25:26 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll 
[2013.05.17 03:25:26 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll 
[2013.05.17 02:59:12 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe 
[2013.05.17 02:58:20 | 000,603,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll 
[2013.05.17 02:58:10 | 003,958,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll 
[2013.05.17 02:58:10 | 000,855,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll 
[2013.05.17 02:58:08 | 000,526,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll 
[2013.05.17 02:58:08 | 000,136,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll 
[2013.05.17 02:58:08 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll 
[2013.05.17 02:58:08 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll 
[2013.05.16 06:13:27 | 000,294,344 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT 
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] 
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] 
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] 
   ========== Files Created - No Company Name ========== 
  
[2013.06.11 21:07:25 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe 
[2013.06.11 21:07:25 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe 
[2013.06.11 21:07:25 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe 
[2013.06.11 21:07:25 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe 
[2013.06.11 21:07:25 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe 
[2013.06.11 02:59:22 | 000,005,174 | ---- | C] () -- C:\Windows\SysWow64\nppt9x.vxd 
[2013.06.11 02:27:55 | 000,002,094 | ---- | C] () -- C:\Users\Marco\Desktop\Lineage II.lnk 
[2013.06.11 00:39:40 | 000,002,028 | ---- | C] () -- C:\Users\Public\Desktop\NCsoft Launcher.lnk 
[2013.06.03 22:39:41 | 000,000,670 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk 
[2013.06.03 22:39:41 | 000,000,630 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk 
[2013.06.03 22:39:41 | 000,000,615 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk 
[2013.05.29 20:16:53 | 001,317,706 | ---- | C] () -- C:\Users\Public\Documents\Stundenzettel.pdf 
[2013.05.28 13:35:24 | 000,470,058 | ---- | C] () -- C:\Users\Marco\Desktop\Mickey-Mouse-hd-wallpapers.jpg 
[2013.05.28 13:14:21 | 001,910,847 | ---- | C] () -- C:\Users\Marco\Desktop\23724_3d_3d_transparent_pokeball (1).jpg 
[2013.02.15 13:36:36 | 000,086,857 | ---- | C] () -- C:\Users\Marco\425745_549096938453821_492524886_n.jpg 
[2013.01.30 02:11:37 | 000,034,890 | ---- | C] () -- C:\Users\Marco\66407_501073603264182_714443056_n.jpg 
[2012.12.11 12:45:19 | 000,000,016 | ---- | C] () -- C:\Users\Marco\AppData\Roaming\blckdom.res 
[2012.06.26 16:02:40 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe 
[2012.06.26 16:02:38 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll 
[2012.06.26 16:02:38 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll 
[2012.06.26 16:02:38 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll 
[2012.06.26 16:02:38 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll 
[2012.06.15 20:55:00 | 000,000,110 | ---- | C] () -- C:\Windows\clientshell.INI 
[2012.02.17 17:06:39 | 001,639,104 | ---- | C] () -- C:\Users\Marco\AppData\Roaming\UserTile.png 
[2012.02.17 04:03:49 | 000,002,189 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat 
[2012.02.17 03:39:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin 
[2012.02.17 02:42:18 | 000,001,571 | ---- | C] () -- C:\Users\Marco\DivX Movies.lnk 
[2011.12.06 04:35:10 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat 
[2011.12.06 04:35:10 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat 
[2011.12.05 23:04:00 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll 
[2011.12.05 23:03:52 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll 
   ========== ZeroAccess Check ========== 
  
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 
  
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 
  
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Apartment 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Apartment 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Free 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] 
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Free 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Both 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] 
   ========== LOP Check ========== 
  
[2013.03.29 16:00:36 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\Audacity 
[2013.04.11 16:26:45 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\AVG 
[2012.09.28 18:19:28 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\AVG2013 
[2012.03.23 20:42:05 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\DAEMON Tools Lite 
[2013.06.14 07:47:50 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\Dropbox 
[2012.12.21 15:04:23 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\DVDVideoSoft 
[2012.12.11 12:45:11 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\kock 
[2012.08.02 17:00:55 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\OpenOffice.org 
[2012.11.30 20:31:11 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\Samsung 
[2013.06.13 01:48:50 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\Spotify 
[2012.11.26 22:52:56 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\TeamViewer 
[2013.04.24 22:41:20 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\TERA 
[2013.05.24 01:42:08 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\TS3Client 
[2012.08.28 16:21:07 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\TuneUp Software 
[2012.12.11 12:48:09 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\UAs 
[2012.02.23 21:14:55 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\uTorrent 
[2012.04.03 21:56:13 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\Windows Live Writer 
[2012.03.10 10:45:14 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\Windows SideBar 
[2012.12.11 12:48:20 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\xmldm 
   ========== Purity Check ========== 
  
  
   ========== Files - Unicode (All) ========== 
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360安全中心   
< End of report >    Code:  
 OTL Extras logfile created on: 14.06.2013 07:51:40 - Run 1 
OTL by OldTimer - Version 3.2.69.0     Folder = D:\Downloads 
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation 
Internet Explorer (Version = 9.10.9200.16614) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
3,74 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 63,23% Memory free 
7,48 Gb Paging File | 5,80 Gb Available in Paging File | 77,56% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 97,66 Gb Total Space | 10,21 Gb Free Space | 10,45% Space Free | Partition Type: NTFS 
Drive D: | 356,01 Gb Total Space | 215,45 Gb Free Space | 60,52% Space Free | Partition Type: NTFS 
  
Computer Name: MARCITO | User Name: Marco | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans 
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) 
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) 
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) 
   ========== Shell Spawning ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
htafile [open] -- "%1" %* 
htmlfile [edit] -- Reg Error: Key error. 
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) 
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) 
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
htafile [open] -- "%1" %* 
htmlfile [edit] -- Reg Error: Key error. 
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. 
   ========== Security Center Settings ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"cval" = 1 
"FirewallDisableNotify" = 0 
"AntiVirusDisableNotify" = 0 
"UpdatesDisableNotify" = 0 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data] 
"AntiVirusOverride" = 0 
"AntiSpywareOverride" = 0 
"FirewallOverride" = 0 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
   ========== System Restore Settings ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] 
"DisableSR" = 0 
   ========== Firewall Settings ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
"EnableFirewall" = 1 
"DisableNotifications" = 0 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"EnableFirewall" = 1 
"DisableNotifications" = 0 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] 
"EnableFirewall" = 1 
"DisableNotifications" = 0 
   ========== Authorized Applications List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 
  
   ========== Vista Active Open Ports Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
"{07E70A13-69D0-496C-BDFB-D3212DA76E66}" = lport=138 | protocol=17 | dir=in | app=system |  
"{0D443283-8ECE-403E-B58F-9EB302A71ACB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |  
"{144876C4-F7F6-4F27-A663-14CB39EB097F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{1DD3195D-28DC-400D-BAFF-D3D47FCD168B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |  
"{2636A2EB-010A-4440-9892-E1E129DA964D}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{310414DE-81B4-4CB5-9FD0-173F214E3956}" = lport=445 | protocol=6 | dir=in | app=system |  
"{34B9E7F4-A175-4952-B545-102EAEE139F3}" = lport=56748 | protocol=17 | dir=in | name=pando media booster |  
"{3BDC49A1-041E-44B7-8B4D-CE51029206C4}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |  
"{43A43B03-3181-4C49-B027-C228528CDF2B}" = rport=137 | protocol=17 | dir=out | app=system |  
"{4AADFB40-E3A3-4C42-8DED-C88457C7DE11}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{519554AD-D67A-4970-908F-451893234617}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{5B072B4C-9B5F-44CA-9C5F-A9F9A3D86018}" = lport=56748 | protocol=17 | dir=in | name=pando media booster |  
"{5E951BF2-BE76-452D-BF42-B46748A6AFD1}" = lport=2869 | protocol=6 | dir=in | app=system |  
"{79214FB2-E72B-45F1-9CDB-64924ECC1CDD}" = lport=139 | protocol=6 | dir=in | app=system |  
"{818E061E-FC76-45AF-B266-8F7B0D6B4498}" = rport=139 | protocol=6 | dir=out | app=system |  
"{8DD086F8-7A59-43A1-9438-0D64015E88BC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{9736BE52-271E-403D-A646-BB1EF4939D16}" = lport=56748 | protocol=6 | dir=in | name=pando media booster |  
"{A1A22668-C0E7-4CDF-966A-925E899513E6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |  
"{B41B6D46-CE30-40C3-B5B1-EEB2570F9479}" = rport=10243 | protocol=6 | dir=out | app=system |  
"{B422036E-BDBD-4135-9C13-0670657C9CF2}" = rport=138 | protocol=17 | dir=out | app=system |  
"{BF7141C8-32A7-4ACA-93E8-F6D4377A4BA1}" = rport=445 | protocol=6 | dir=out | app=system |  
"{C070EA34-A920-4714-B415-62FA548DF249}" = lport=56748 | protocol=6 | dir=in | name=pando media booster |  
"{D116EDE2-FD8E-44FB-BD85-6878ADE4F8EB}" = lport=10243 | protocol=6 | dir=in | app=system |  
"{D3818E70-80B9-45D0-8D35-C936F8A36A2B}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |  
"{ED6C2018-A8AF-4E6B-B39C-65F4377E3C9C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |  
"{F78CAD9B-C211-4D44-A514-DFC614389DD1}" = lport=137 | protocol=17 | dir=in | app=system |  
"{F7BF5259-5D59-49F2-A1E6-9457179FB94F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |  
   ========== Vista Active Application Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
"{01ACCDC1-FE98-4DCB-B5E0-FCD2218A87E0}" = protocol=6 | dir=out | app=system |  
"{023C6BA2-60EF-49EA-BE26-FD43BED68FD5}" = protocol=17 | dir=in | app=d:\world of warcraft\launcher.patch.exe |  
"{0287B56D-1B1F-4A06-9D1E-99E71691F217}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |  
"{0FFAEAFA-752A-4C9C-BF8C-3DC5C9B03192}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |  
"{158E62FC-6D25-4A6C-A909-39C17726555B}" = protocol=17 | dir=in | app=d:\tera\tera\tera-launcher.exe |  
"{279B6FD5-F83D-4440-BA88-9053E4555958}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |  
"{304A1E58-8D1B-4C0E-916C-7F0E95C7E115}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |  
"{37B032C0-B5E6-4EFC-8B43-E8E15932D812}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe |  
"{3E587FF7-74A8-4B7E-915E-6BA5853E8A20}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |  
"{4AC87044-46A3-4B5F-80BD-BF6B8CCA03CE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |  
"{5095756F-BBD9-4318-8138-5879C56B9B1F}" = protocol=6 | dir=in | app=d:\tera\tera\tera-launcher.exe |  
"{545B531D-75A4-49D1-9BD6-3247ED49FF45}" = protocol=6 | dir=in | app=d:\vindictus eu\en-eu\nmservice.exe |  
"{5563B817-BA90-493F-B029-52E4BC7EEC01}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |  
"{5FFF8BD1-E035-475D-8A73-372863A66F46}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |  
"{629DC71D-D078-4B62-8D19-BAE10831B54D}" = protocol=17 | dir=in | app=d:\world of warcraft\launcher.exe |  
"{6BFE0657-A6ED-4027-8D42-C04566A5C72D}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgdiagex.exe |  
"{70765DCC-657A-4E71-94F7-C9BB2506BF2D}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgnsa.exe |  
"{7143DC2A-4287-4700-9F9A-03A1C620C0B5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{76F202DC-0654-47EE-AF6D-B14FBC3F20D9}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{7E8E52F0-8488-4FFB-BD42-C08C92DACF53}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |  
"{82B8ADBA-D541-40C7-9B6E-9F0F85EE7D10}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |  
"{9426EEF6-D757-46B8-97BD-499B0F076A33}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |  
"{96272A1D-3F35-4693-A052-EFF646860382}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{96912EEA-F0DC-4614-A9F4-8089C010E287}" = protocol=17 | dir=in | app=d:\vindictus eu\en-eu\nmservice.exe |  
"{96F00020-D6EF-413B-9D60-2074E93731E6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{A0979D12-3363-4B66-A10E-83BB9A2193A3}" = protocol=6 | dir=in | app=c:\users\marco\appdata\roaming\dropbox\bin\dropbox.exe |  
"{A485A523-0CCB-49F6-999C-24FF33C3A804}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgdiagex.exe |  
"{A5E79ED0-AF60-4AAB-A55F-F6B35FE9999A}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe |  
"{A84F8976-FD1F-495F-B241-B47D6C864689}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |  
"{AAB634F7-3B4B-4B1D-91A0-2DD1C9EB43DA}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe |  
"{ACA36180-61C8-40E5-91E8-B5AEC4F4223C}" = protocol=6 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |  
"{AD4DCEFD-87C9-4B2F-85B2-9EFA74F3C545}" = protocol=6 | dir=in | app=d:\world of warcraft\launcher.patch.exe |  
"{B0EC52FE-4046-4DAD-8203-F12E85992C0F}" = protocol=17 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |  
"{B28D9830-D65E-4842-92BD-8FF2607D9C20}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{B4FB3DA5-B507-48EC-8A01-0BA77941A2D7}" = protocol=6 | dir=in | app=d:\world of warcraft\launcher.exe |  
"{B6901312-E899-409E-A37F-C13C49311250}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{BE6156D0-8A95-4FED-B9EF-62BCC8385CBC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |  
"{BFBF573E-CC6E-4882-82C4-2294AFFD5344}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{C83CF95B-C466-4694-9276-492BD9DA92E4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |  
"{C9D325F1-CDCF-44E3-BC32-991E6AE110EE}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe |  
"{CBA55A18-B16D-4B87-B344-4D500307F019}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |  
"{D15E51E5-4693-4FE1-9E58-71848157BFFD}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgnsa.exe |  
"{D1EB0973-B6B6-43AF-BE3A-D5A4EA1E9A71}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |  
"{D3151FB4-64A9-40CB-8A3B-EB6F1BCFA94E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{D3D44AE1-7F26-4968-95EF-F7CF9B8736CC}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |  
"{D3F22EF1-F2A0-45C3-B185-F512193D49D8}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |  
"{DA064AAA-A65B-41E1-85A8-6644916452B9}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |  
"{DBAC01A5-3BAF-4DC1-89F1-F0CECBA15C9C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |  
"{E6FAAF33-C91D-419F-BE2C-82080094DD65}" = protocol=6 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |  
"{E77A1BED-B380-4479-AC47-84C489E141A1}" = protocol=17 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |  
"{EC055AF1-4B52-442D-9620-BB8C3CEE77D0}" = protocol=17 | dir=in | app=c:\users\marco\appdata\roaming\dropbox\bin\dropbox.exe |  
"{EC0C2E7C-4EF5-46E7-A1F0-097317DF82E0}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |  
"{F4F73956-54F7-41AD-80B9-54484092F644}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe |  
"{F509C1DA-F49E-4AE7-B807-3EFBD1A78306}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe |  
"{F8536DEB-E686-46E6-A069-10B5B40F5AF4}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |  
"{FEB91D53-2635-4240-88ED-A45DBB0C51D3}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |  
"{FF20C6D2-BAD6-45DD-952D-6D62440B63FD}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |  
"TCP Query User{121D86F2-0FA1-4B13-B778-DD9057891C8D}D:\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=6 | dir=in | app=d:\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe |  
"TCP Query User{1782FA85-9281-4A72-B390-5E20390C4312}D:\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=d:\world of warcraft\backgrounddownloader.exe |  
"TCP Query User{258C379D-F242-4E2C-B036-E83968BBB602}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |  
"TCP Query User{2A0FB177-21C1-4DE8-9AC8-9C517C7497A8}C:\windows\syswow64\rundll32.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\rundll32.exe |  
"TCP Query User{3E0F439C-9FCA-45A9-8787-DD42ACD35E4C}D:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=6 | dir=in | app=d:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |  
"TCP Query User{64F03C6D-7C59-45C8-BEBD-D991FF9E041C}C:\program files (x86)\tera\tera-launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |  
"TCP Query User{67BF345A-B5CF-4625-9CD5-B3BB9B71698F}C:\users\marco\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\marco\appdata\roaming\dropbox\bin\dropbox.exe |  
"TCP Query User{77072AAC-7EF1-4B65-A439-CCDF9EF02F5F}C:\users\marco\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\marco\appdata\roaming\spotify\spotify.exe |  
"TCP Query User{899C7D6F-5DF1-419F-9AF1-11E8B92DBF28}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |  
"TCP Query User{8C749016-A61A-44AD-8EDB-9B3AB3729B49}D:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=6 | dir=in | app=d:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |  
"TCP Query User{C267D3C4-36FE-44C4-B455-C979AE54EFCB}D:\tera\tera\tera-launcher.exe" = protocol=6 | dir=in | app=d:\tera\tera\tera-launcher.exe |  
"TCP Query User{DD2F84B1-3704-4CCA-B046-46400F2E4C45}D:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe" = protocol=6 | dir=in | app=d:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe |  
"TCP Query User{E449282F-8283-4981-9455-4FD7F3A7667D}C:\programdata\battle.net\agent\agent.1363\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |  
"TCP Query User{EEDDCDAF-394A-42B4-BB14-C995E4F7C6CD}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |  
"TCP Query User{F3954284-D822-453C-B376-AAC9E9F69907}C:\users\marco\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\marco\appdata\roaming\spotify\spotify.exe |  
"TCP Query User{FE531592-7DF3-4702-9910-7754A01B83ED}D:\tera\tera-launcher.exe" = protocol=6 | dir=in | app=d:\tera\tera-launcher.exe |  
"UDP Query User{00E87455-3FCB-4A71-ACAF-04A045D127D9}C:\users\marco\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\marco\appdata\roaming\dropbox\bin\dropbox.exe |  
"UDP Query User{286F8BE9-4879-475D-B09A-944FB20C6C0C}C:\programdata\battle.net\agent\agent.1363\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |  
"UDP Query User{29A36281-F168-4282-9FBD-4EE7D7F7BBA8}D:\tera\tera-launcher.exe" = protocol=17 | dir=in | app=d:\tera\tera-launcher.exe |  
"UDP Query User{36817ABE-F979-48DB-8F6A-6547832A1752}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |  
"UDP Query User{40669E70-A3D5-4587-A68C-388439674358}D:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=17 | dir=in | app=d:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |  
"UDP Query User{4A2AE6BC-D1ED-4D81-BEB7-905CBCE88CC1}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |  
"UDP Query User{4A316CE3-789F-4366-BD35-EBCF6D3B3929}D:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe" = protocol=17 | dir=in | app=d:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe |  
"UDP Query User{60ADB637-C432-43CB-94ED-5C454FF71087}D:\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=17 | dir=in | app=d:\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe |  
"UDP Query User{64960459-E69A-417E-A2E7-8F67BAA8D105}D:\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=d:\world of warcraft\backgrounddownloader.exe |  
"UDP Query User{9C5C6A62-245F-4192-9DA2-D018CF978950}C:\users\marco\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\marco\appdata\roaming\spotify\spotify.exe |  
"UDP Query User{A2ED390F-1E43-4DA5-A320-B8F806DCB5BE}C:\program files (x86)\tera\tera-launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |  
"UDP Query User{A56F9821-D881-49A7-BFC6-3B48007239F7}D:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=17 | dir=in | app=d:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |  
"UDP Query User{C2A9FAA3-01B3-442F-8EEF-CA4628BA4004}C:\windows\syswow64\rundll32.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\rundll32.exe |  
"UDP Query User{E2A94F40-6AB4-4DD9-9CE2-C98D04E15A0C}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |  
"UDP Query User{E8E920B8-A2A3-4A4D-A978-DCF1318A9618}D:\tera\tera\tera-launcher.exe" = protocol=17 | dir=in | app=d:\tera\tera\tera-launcher.exe |  
"UDP Query User{F726CBE1-9F2F-4013-ABED-44FF12D8F88F}C:\users\marco\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\marco\appdata\roaming\spotify\spotify.exe |  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector 
"{0D98B285-0777-B3B7-7A3D-9C85422203B9}" = ccc-utility64 
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack 
"{119EEB4B-F32F-4D71-B9C0-E42403F91C9A}" = AVG 2013 
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant 
"{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables 
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) 
"{418A8D89-B9AA-B872-5927-3D1A052CEAA8}" = AMD Media Foundation Decoders 
"{45CB0703-D49C-31B2-0DBD-FDD98D7DEF7A}" = AMD Drag and Drop Transcoding 
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime 
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes 
"{8924F1FE-8AC5-C2AE-59EF-C5D65B226933}" = AMD Catalyst Install Manager 
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight 
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting 
"{CCAFF072-4DDB-4846-963D-15F02A8E9472}" = Intel(R) PROSet/Wireless WiFi-Software 
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones 
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter 
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 
"{DFE888DA-79D5-C64A-8439-1B224D330F2F}" = ccc-utility64 
"{F5AA006A-1ABE-4F16-B6E1-FEE1F7D38102}" = AVG 2013 
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile 
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit 
"AVG" = AVG 2013 
"Broadcom 802.11 Network Adapter" = Broadcom 802.11 Network Adapter 
"Canon LBP7010C/7018C" = Canon LBP7010C/7018C 
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile 
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack 
"ProInst" = Intel PROSet Wireless 
"SynTPDeinstKey" = Synaptics Pointing Device Driver 
"TeamSpeak 3 Client" = TeamSpeak 3 Client 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator 
"{064A929A-4DE8-40CF-A901-BD40C14E4D25}" = PDF Architect 
"{06870F63-4D1C-171F-9552-368D3890D92F}" = CCC Help French 
"{080FA973-1BE0-6E71-C03D-8F6081C3F64B}" = CCC Help Danish 
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer 
"{101B3A2E-D391-52C7-2EEA-744F8B0CD0AC}" = CCC Help Dutch 
"{14A34B7D-E675-8775-5975-987E9193CE8F}" = CCC Help Spanish 
"{14CE04AF-0EBC-B865-382F-1FB466CAC301}" = CCC Help English 
"{18F3394D-1A34-F631-E789-C0BD57DAC2BA}" = CCC Help Finnish 
"{1998C8AE-87D7-E562-51D1-582F6D3CBE50}" = CCC Help Italian 
"{1B192700-C368-49C1-BF81-D2F9BA065534}" = Catalyst Control Center - Branding 
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger 
"{1DBC5882-96E2-3A01-A32C-9B6F6EF6CF25}" = CCC Help Korean 
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources 
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 
"{1F36B20F-7408-EC75-2825-E9FE81B0339D}" = CCC Help Norwegian 
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update 
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions 
"{2442DE08-0947-4A14-8061-219A99F2DFD5}_is1" = World of Qin 2 Version 2100 
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31 
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program 
"{289AC7E0-0AEE-4a7b-913C-709D9803D23E}" = Nexon Game Manager 
"{2E3C5EA7-5034-4673-EC48-0B9F0D108F96}" = CCC Help Japanese 
"{30B533D1-F0AB-2C56-648A-C204C033CB6C}" = ccc-core-static 
"{30DAAF05-3679-C10C-953C-BB422FCDF557}" = CCC Help Swedish 
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver 
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery 
"{34F2DA68-5394-490F-7426-B6BBEF9E9271}" = CCC Help Thai 
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack 
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology 
"{4273A992-97B0-22D1-1E72-2B634E161232}" = CCC Help Chinese Traditional 
"{428536FB-25A0-8531-75EF-D7A7C340B0A4}" = Catalyst Control Center 
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3 
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR 
"{485C9280-B899-4D46-86F3-B3E459636EE5}" = Yu-Gi-Oh! Power of Chaos KAIBA THE REVENGE 
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater 
"{4BA6B7C9-65AE-BE8B-687A-6F1A2D7F9705}" = CCC Help Czech 
"{4C8E1E1B-175F-AF47-8B21-E12C7C8B5D40}" = CCC Help Thai 
"{4E515022-7CE0-2FBF-B65A-0D22B983B3B8}" = CCC Help Korean 
"{4EAF46A2-DB90-6B67-F640-5CC876A2B5C4}" = CCC Help Greek 
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module 
"{571AA09E-720E-5FC0-1A52-39D3959A128E}" = PX Profile Update 
"{5D5B8455-50E0-F94A-4C82-0F9303BB4C0E}" = CCC Help Danish 
"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = NCsoft Launcher 
"{60E20402-AC6B-CA7D-7BB7-F022D74313C6}" = CCC Help Swedish 
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module 
"{65788064-4757-CB23-92A7-9D5D447F32BC}" = CCC Help Hungarian 
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE 
"{6A9EF6CF-7630-4E33-AE22-7D70F3AF4B05}" = AION Free-To-Play 
"{70018574-BBF0-AFF0-E3A4-8B242404CAFD}" = CCC Help Polish 
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable 
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies 
"{7765BB73-D985-42C9-C7EE-AB434D59429F}" = CCC Help Chinese Traditional 
"{7ADFB885-8E98-6AAE-8687-D6EFB5127F6B}" = Catalyst Control Center Graphics Previews Common 
"{7F7C616E-6971-77D9-7D59-82DC35DF81AC}" = CCC Help Russian 
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform 
"{85A12E3C-16F1-6129-F2D6-80016A30ED0D}" = CCC Help Chinese Standard 
"{892F1E79-65C7-EBFA-2D82-D45D53C106C3}" = CCC Help English 
"{89463BCF-A199-8F20-2692-1158A84225BB}" = CCC Help Russian 
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT 
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker 
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster 
"{99913581-07B0-6B84-9528-F65C248AA3D2}" = CCC Help Greek 
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail 
"{9FA5B08F-9162-BCCB-AFAC-28DF1751BEC3}" = Catalyst Control Center Localization All 
"{A11FBE34-2710-EC90-7149-7A78EDC498AB}" = CCC Help Czech 
"{A2S166A0-F031-4E27-A057-C69733219434}_is1" = TERA 
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common 
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer 
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Deutsch 
"{AF859F36-5F97-F6EC-A617-62771A8B4FDC}" = CCC Help Finnish 
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie 
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail 
"{BB095F3E-0A7D-7DD4-B2A8-47CB12E416B0}" = CCC Help Japanese 
"{BC71B06F-BFAE-6A73-091C-F18ACF00A04C}" = CCC Help Italian 
"{BDCBA80C-A3BD-9DA5-E43F-EBBBE779C032}" = CCC Help Hungarian 
"{BF15BE5B-A45E-6312-304F-39475AE9722F}" = CCC Help Turkish 
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common 
"{C9AAF970-4E7E-4C98-AD67-09C74379D345}" = Harry Potter und die Heiligtümer des Todes™ - Teil 1 
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform 
"{CEEA6219-8792-3E40-D361-4FB5F0FBBB0F}" = CCC Help Portuguese 
"{CF053286-7F4C-CAFB-616B-58EC562BB28E}" = CCC Help Chinese Standard 
"{D07BB56A-7DB4-4564-A1F9-EBCE75FBE3C6}" = Catalyst Control Center InstallProxy 
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 
"{D1280DCC-F2CC-BBDF-2E1E-EF8D0A4CD3C3}" = Catalyst Control Center Localization All 
"{D3689EED-3943-9E90-1D65-D2246EB58AD1}" = CCC Help Turkish 
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform 
"{D535632D-624E-0B64-A107-6E3AD09893E3}" = Catalyst Control Center Graphics Previews Vista 
"{D767A1E2-930B-93DC-B0D8-AC6456A19C82}" = CCC Help Norwegian 
"{DAC3C995-8C29-8310-558B-9869CED00978}" = CCC Help Portuguese 
"{DBA5EE42-A143-A658-9F86-C611BFDBEFCA}" = CCC Help Dutch 
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 
"{E17141A6-211D-5854-61D9-69827A430D82}" = EA Download Manager UI 
"{E19490CD-5380-4F37-B0A7-624D635605DC}" = Catalyst Control Center - Branding 
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker 
"{E566097D-791C-C25F-8559-B440021AC7D7}" = CCC Help French 
"{E58DB2CA-1F78-4EBC-B0BC-A38016A19855}" = Ð¶ÔØÌì½¾II 
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger 
"{E5EABF66-F9C4-430C-B97D-3CF28A58D50B}" = Alcor Micro USB Card Reader 
"{EAF0F475-CFE2-9F4D-F26A-875FF09AD40E}" = CCC Help Spanish 
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module 
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] 
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver 
"{F1F1CCD6-34FE-81C6-CE0C-F22695E6409F}" = CCC Help German 
"{F2421108-2F1E-4CD6-AF8F-07AA3BDEE35A}" = Uninstall World of Qin 2 
"{F71A71E1-285C-95CE-A8F7-231E3827138E}" = CCC Help Polish 
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials 
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables 
"{FDCDE331-EEB2-E1EE-8765-B195B2B0B25D}" = CCC Help German 
"4game" = 4game 
"4game_lineage2de" = LineageII DE 
"5513-1208-7298-9440" = JDownloader 0.9 
"Adobe AIR" = Adobe AIR 
"BandiMPEG1" = Bandisoft MPEG-1 Decoder 
"com.ea.Vault.919CACB699904AC5D41B606703500DD39747C02D.1" = EA Download Manager UI 
"DivX Setup" = DivX-Setup 
"EA Download Manager" = EA Download Manager 
"Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 7.0 
"Free YouTube Download_is1" = Free YouTube Download version 3.1.42.1212 
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.37.1212 
"InstallShield_{6A9EF6CF-7630-4E33-AE22-7D70F3AF4B05}" = AION Free-To-Play 
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies 
"InstallShield_{E5EABF66-F9C4-430C-B97D-3CF28A58D50B}" = Alcor Micro USB Card Reader 
"NCLauncher_GameForge" = NC Launcher (GameForge) 
"PS3 Media Server" = PS3 Media Server 
"TeamSpeak 3 Client" = TeamSpeak 3 Client 
"VLC media player" = VLC media player 2.0.0 
"WinLiveSuite" = Windows Live Essentials 
   ========== HKEY_CURRENT_USER Uninstall List ========== 
  
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"Dropbox" = Dropbox 
"Google Chrome" = Google Chrome 
"MyFreeCodec" = MyFreeCodec 
"NCsoft-Lineage2" = Lineage II 
"Spotify" = Spotify 
   ========== Last 20 Event Log Errors ========== 
  
[ Application Events ] 
Error - 10.06.2013 18:13:55 | Computer Name = Marcito | Source = WinMgmt | ID = 10 
Description =  
  
Error - 10.06.2013 19:11:49 | Computer Name = Marcito | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: TJ2Client.exe, Version: 2100.1212.1.0, 
 Zeitstempel: 0x475f3f30  Name des fehlerhaften Moduls: TJ2Client.exe, Version: 2100.1212.1.0, 
 Zeitstempel: 0x475f3f30  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000e243f  ID des fehlerhaften 
 Prozesses: 0x173c  Startzeit der fehlerhaften Anwendung: 0x01ce662994f3eb20  Pfad der 
 fehlerhaften Anwendung: C:\Program Files (x86)\World of Qin 2\TJ2Client.exe  Pfad 
 des fehlerhaften Moduls: C:\Program Files (x86)\World of Qin 2\TJ2Client.exe  Berichtskennung: 
 203d8e42-d223-11e2-9e0a-c80aa95f33d8 
  
Error - 10.06.2013 19:11:53 | Computer Name = Marcito | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: TJ2Client.exe, Version: 2100.1212.1.0, 
 Zeitstempel: 0x475f3f30  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, 
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x08383d30  ID des fehlerhaften 
 Prozesses: 0x173c  Startzeit der fehlerhaften Anwendung: 0x01ce662994f3eb20  Pfad der 
 fehlerhaften Anwendung: C:\Program Files (x86)\World of Qin 2\TJ2Client.exe  Pfad 
 des fehlerhaften Moduls: unknown  Berichtskennung: 22b01e0f-d223-11e2-9e0a-c80aa95f33d8 
  
Error - 10.06.2013 19:11:54 | Computer Name = Marcito | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: TJ2Client.exe, Version: 2100.1212.1.0, 
 Zeitstempel: 0x475f3f30  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, 
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x11743d30  ID des fehlerhaften 
 Prozesses: 0x310  Startzeit der fehlerhaften Anwendung: 0x01ce6629c3fb09e0  Pfad der 
 fehlerhaften Anwendung: C:\Program Files (x86)\World of Qin 2\TJ2Client.exe  Pfad 
 des fehlerhaften Moduls: unknown  Berichtskennung: 23725f77-d223-11e2-9e0a-c80aa95f33d8 
  
Error - 11.06.2013 01:06:29 | Computer Name = Marcito | Source = WinMgmt | ID = 10 
Description =  
  
Error - 11.06.2013 08:44:09 | Computer Name = Marcito | Source = WinMgmt | ID = 10 
Description =  
  
Error - 11.06.2013 08:57:53 | Computer Name = Marcito | Source = WinMgmt | ID = 10 
Description =  
  
Error - 11.06.2013 10:40:38 | Computer Name = Marcito | Source = WinMgmt | ID = 10 
Description =  
  
Error - 11.06.2013 10:58:06 | Computer Name = Marcito | Source = SideBySide | ID = 16842785 
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\ATI\CIM\Bin64\SetACL64.exe". 
Die 
 abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" 
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm 
 "sxstrace.exe". 
  
Error - 11.06.2013 13:01:56 | Computer Name = Marcito | Source = WinMgmt | ID = 10 
Description =  
  
[ System Events ] 
Error - 13.06.2013 10:18:50 | Computer Name = Marcito | Source = Service Control Manager | ID = 7009 
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst 
 4game-service erreicht. 
  
Error - 13.06.2013 10:18:50 | Computer Name = Marcito | Source = Service Control Manager | ID = 7000 
Description = Der Dienst "4game-service" wurde aufgrund folgenden Fehlers nicht  
gestartet:   %%1053 
  
Error - 13.06.2013 10:18:51 | Computer Name = Marcito | Source = Service Control Manager | ID = 7006 
Description = Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden 
 Fehlers fehlgeschlagen:   %%5 
  
Error - 13.06.2013 10:19:07 | Computer Name = Marcito | Source = Service Control Manager | ID = 7006 
Description = Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden 
 Fehlers fehlgeschlagen:   %%5 
  
Error - 13.06.2013 11:44:41 | Computer Name = Marcito | Source = DCOM | ID = 10010 
Description =  
  
Error - 13.06.2013 11:44:46 | Computer Name = Marcito | Source = Service Control Manager | ID = 7006 
Description = Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden 
 Fehlers fehlgeschlagen:   %%5 
  
Error - 14.06.2013 01:30:05 | Computer Name = Marcito | Source = Service Control Manager | ID = 7009 
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst 
 4game-service erreicht. 
  
Error - 14.06.2013 01:30:05 | Computer Name = Marcito | Source = Service Control Manager | ID = 7000 
Description = Der Dienst "4game-service" wurde aufgrund folgenden Fehlers nicht  
gestartet:   %%1053 
  
Error - 14.06.2013 01:30:05 | Computer Name = Marcito | Source = Service Control Manager | ID = 7006 
Description = Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden 
 Fehlers fehlgeschlagen:   %%5 
  
Error - 14.06.2013 01:30:06 | Computer Name = Marcito | Source = Service Control Manager | ID = 7006 
Description = Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden 
 Fehlers fehlgeschlagen:   %%5 
  
  
< End of report >      |