Dr Hanoi | 20.03.2014 19:31 | FRST:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Andy (administrator) on AST500 on 20-03-2014 19:00:23
Running from C:\Users\Andy\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
() C:\Windows\system32\DTS.exe
(Lenovo.) C:\Windows\system32\ibmpmsvc.exe
(AuthenTec, Inc.) C:\Windows\system32\ATService.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(SafeNet Inc.) C:\Windows\system32\hasplms.exe
(Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
( ) C:\Windows\system32\lxeccoms.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\shtctky.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Zoom\TpScrex.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecmon.exe
() C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\ezprint.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel Corporation) C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\AMT\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [FingerPrintSoftware] - C:\Program Files\Lenovo Fingerprint Software\fpapp.exe [1582400 2010-02-05] (AuthenTec)
HKLM\...\Run: [FingerPrintSoftwareSplashScreen] - C:\Program Files\Lenovo Fingerprint Software\SplashScreen.exe [107520 2010-02-05] (AuthenTec, Inc.)
HKLM\...\Run: [picon] - C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PIconStartup.exe [111640 2010-02-04] ()
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] ()
HKLM\...\Run: [TpShocks] - C:\Windows\system32\TpShocks.exe [382248 2013-06-20] (Lenovo.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-05-29] (Synaptics Incorporated)
HKLM\...\Run: [lxecmon.exe] - C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecmon.exe [772712 2013-01-23] ()
HKLM\...\Run: [EzPrint] - C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\ezprint.exe [150264 2013-01-23] ()
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2012-05-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [703888 2013-06-19] (Cisco Systems, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-2411893241-2426368810-492649712-1000\...\Run: [Facebook Update] - "C:\Users\Andy\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-2411893241-2426368810-492649712-1000\...\Policies\Explorer: [DisallowCpl] 1
HKU\S-1-5-21-2411893241-2426368810-492649712-1000\...\MountPoints2: {397c8788-33e2-11e2-ae11-002268e277f9} - E:\LaunchU3.exe -a
HKU\S-1-5-21-2411893241-2426368810-492649712-1000\...\MountPoints2: {fb5e03cf-76a7-11e1-b8cb-002268e277f9} - F:\Startme.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x292AFE15D8B9CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
DPF: HKLM {816BE035-1450-40D0-8A3B-BA7825A83A77} hxxp://support.lenovo.com/Resources/Lenovo/AutoDetect/Lenovo_AutoDetect2.cab
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - No File
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWow64\urlmon.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{4FF68166-9F5C-4734-B35B-A347ECDDBEF1}: [NameServer]8.8.8.8
FireFox:
========
FF ProfilePath: C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\v0xlfwww.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files (x64)\PDF-XChange\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin - C:\Program Files\Java\jre6\bin\npDeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files (x64)\PDF-XChange\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @graphisoft.com/GDL Web Plug-in - C:\Program Files (x86)\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll (Graphisoft SE)
FF Plugin-x32: @java.com/DTPlugin - C:\Program Files (x86)\Java\jre6\bin\dtplugin\npDeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\v0xlfwww.default\searchplugins\leo-ger-eng.xml
FF SearchPlugin: C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\v0xlfwww.default\searchplugins\ponseu--englisch--deutsch.xml
FF SearchPlugin: C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\v0xlfwww.default\searchplugins\ponseu--trkisch--deutsch.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\v0xlfwww.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-03-21]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} [2014-02-15]
==================== Services (Whitelisted) =================
S3 ADMonitor; C:\Windows\system32\ADMonitor.exe [130048 2010-02-05] ()
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 ATService; C:\Windows\system32\ATService.exe [2713920 2010-02-05] (AuthenTec, Inc.)
R2 dtsvc; C:\Windows\system32\DTS.exe [117760 2010-02-05] ()
R2 hasplms; C:\Windows\system32\hasplms.exe [4412872 2012-08-22] (SafeNet Inc.)
R2 LMS; C:\Program Files (x86)\Intel\AMT\LMS.exe [174616 2010-02-04] (Intel Corporation)
S2 lxecCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\lxecserv.exe [45736 2010-04-14] (Lexmark International, Inc.)
R2 lxec_device; C:\Windows\system32\lxeccoms.exe [1052328 2010-04-14] ( )
R2 lxec_device; C:\Windows\SysWOW64\lxeccoms.exe [598696 2010-04-14] ( )
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22376 2013-06-26] ()
R2 UNS; C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2058776 2010-02-04] (Intel Corporation)
S2 ExpatShieldService; C:\Program Files (x86)\Expat Shield\bin\openvpnas.exe [X]
S2 ExpatSrv; C:\Program Files (x86)\Expat Shield\HssWPR\hsssrv.exe [X]
S3 ExpatTrayService; C:\Program Files (x86)\Expat Shield\bin\ExpatTrayService.EXE [X]
S2 ExpatWd; C:\Program Files (x86)\Expat Shield\bin\hsswd.exe -product Expat [X]
==================== Drivers (Whitelisted) ====================
S3 akshhl; C:\Windows\System32\DRIVERS\akshhl.sys [57088 2012-06-15] (SafeNet Inc.)
S3 aksusb; C:\Windows\System32\DRIVERS\aksusb.sys [296576 2012-06-15] (SafeNet Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [321536 2011-09-28] (SafeNet Inc.)
R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [44784 2013-05-29] (Synaptics Incorporated)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-04-29] ()
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52080 2013-06-19] (Cisco Systems, Inc.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-19 20:59 - 2014-03-19 20:45 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-03-19 20:47 - 2014-03-19 21:01 - 00010358 _____ () C:\zoek-results.log
2014-03-19 20:45 - 2014-03-19 20:56 - 00000000 ____D () C:\zoek_backup
2014-03-19 20:44 - 2014-03-19 20:44 - 01285120 _____ () C:\Users\Andy\Desktop\zoek.exe
2014-03-19 20:26 - 2014-03-19 20:26 - 00001109 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-19 20:26 - 2014-03-19 20:26 - 00000000 ____D () C:\Users\Andy\AppData\Roaming\Malwarebytes
2014-03-19 20:26 - 2014-03-19 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-19 20:26 - 2014-03-19 20:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-19 20:26 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-19 20:25 - 2014-03-19 20:25 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andy\Desktop\mbam-setup-1.75.0.1300.exe
2014-03-19 20:18 - 2014-03-19 20:18 - 00001159 _____ () C:\Users\Andy\Desktop\JRT.txt
2014-03-19 20:12 - 2014-03-19 20:12 - 00000000 ____D () C:\Windows\ERUNT
2014-03-19 20:10 - 2014-03-19 20:10 - 01037734 _____ (Thisisu) C:\Users\Andy\Desktop\JRT.exe
2014-03-19 20:03 - 2014-03-19 20:04 - 00000000 ____D () C:\AdwCleaner
2014-03-19 20:01 - 2014-03-19 20:01 - 01950720 _____ () C:\Users\Andy\Desktop\adwcleaner.exe
2014-03-19 20:00 - 2014-03-19 20:01 - 01950720 _____ () C:\Users\Andy\Downloads\adwcleaner.exe
2014-03-16 14:54 - 2014-03-16 15:04 - 00541874 _____ () C:\Users\Andy\Desktop\Addition.txt
2014-03-16 14:53 - 2014-03-20 19:00 - 00015325 _____ () C:\Users\Andy\Desktop\FRST.txt
2014-03-16 14:53 - 2014-03-20 19:00 - 00000000 ____D () C:\FRST
2014-03-16 14:52 - 2014-03-16 14:52 - 02157056 _____ (Farbar) C:\Users\Andy\Desktop\FRST64.exe
2014-03-13 19:01 - 2014-03-13 19:01 - 00001002 _____ () C:\Users\Andy\Desktop\IrfanView.lnk
2014-03-13 19:01 - 2014-03-13 19:01 - 00000000 ____D () C:\Users\Andy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2014-03-13 19:01 - 2014-03-13 19:01 - 00000000 ____D () C:\Users\Andy\AppData\Roaming\IrfanView
2014-03-13 19:01 - 2014-03-13 19:01 - 00000000 ____D () C:\Program Files (x86)\IrfanView
2014-03-13 18:59 - 2014-03-13 18:59 - 02179728 _____ (Irfan Skiljan) C:\Users\Andy\Downloads\iview437g_setup.exe
2014-03-07 14:25 - 2014-03-07 14:25 - 27474118 _____ () C:\Users\Andy\Downloads\capoeira training 1.avi
2014-03-07 14:24 - 2014-03-07 14:24 - 20166367 _____ () C:\Users\Andy\Downloads\capoeira training 1.mp4
2014-03-06 19:48 - 2014-03-06 19:48 - 00000002 _____ () C:\Users\Andy\Documents\Rz1.rzf
2014-02-24 19:18 - 2014-02-24 19:18 - 01587612 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-24 19:13 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-02-24 19:13 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-02-24 19:13 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-02-24 19:13 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-02-24 19:13 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-02-24 19:13 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-02-24 19:13 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-02-24 19:13 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-02-24 19:13 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-02-24 19:13 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-02-24 19:13 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-02-24 19:13 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-02-24 19:13 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-02-24 19:13 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-02-24 19:13 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-02-24 19:13 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-02-24 19:13 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-02-24 19:13 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-02-24 19:11 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-02-24 19:11 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-02-18 20:35 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-18 20:35 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-18 20:35 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-18 20:35 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-18 20:35 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-18 20:35 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-18 20:35 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-18 20:35 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-18 20:35 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-18 20:35 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-18 20:35 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-18 20:35 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-18 20:35 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-18 20:35 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-18 20:35 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-18 20:35 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-18 20:35 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-18 20:35 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-18 20:35 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-18 20:35 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-18 20:35 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-18 20:35 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-18 20:35 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-18 20:35 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-18 20:35 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-18 20:35 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-18 20:35 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-02-18 20:35 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-02-18 20:35 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-02-18 20:35 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-02-18 20:35 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-02-18 20:35 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-02-18 20:35 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-02-18 20:35 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-18 20:35 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-18 20:34 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-02-18 20:34 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
==================== One Month Modified Files and Folders =======
2014-03-20 19:00 - 2014-03-16 14:53 - 00015325 _____ () C:\Users\Andy\Desktop\FRST.txt
2014-03-20 19:00 - 2014-03-16 14:53 - 00000000 ____D () C:\FRST
2014-03-20 18:57 - 2013-11-18 12:07 - 00000646 _____ () C:\Windows\Tasks\WebContent AutoUpdate 2013.job
2014-03-20 18:52 - 2012-03-21 07:31 - 01815803 _____ () C:\Windows\WindowsUpdate.log
2014-03-20 18:33 - 2013-04-28 18:06 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2411893241-2426368810-492649712-1000UA.job
2014-03-20 18:31 - 2012-08-20 07:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-20 18:29 - 2013-12-08 18:13 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-20 18:29 - 2013-12-08 18:13 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-20 18:23 - 2009-07-14 05:45 - 00021808 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-20 18:23 - 2009-07-14 05:45 - 00021808 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-20 18:16 - 2012-04-02 10:30 - 00258310 _____ () C:\ProgramData\lxecscan.log
2014-03-20 18:15 - 2010-11-21 04:47 - 00585308 _____ () C:\Windows\PFRO.log
2014-03-20 18:15 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-20 18:15 - 2009-07-14 05:51 - 00127268 _____ () C:\Windows\setupact.log
2014-03-19 21:01 - 2014-03-19 20:47 - 00010358 _____ () C:\zoek-results.log
2014-03-19 20:56 - 2014-03-19 20:45 - 00000000 ____D () C:\zoek_backup
2014-03-19 20:56 - 2012-03-21 08:12 - 00000000 ____D () C:\Users\Andy
2014-03-19 20:45 - 2014-03-19 20:59 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-03-19 20:44 - 2014-03-19 20:44 - 01285120 _____ () C:\Users\Andy\Desktop\zoek.exe
2014-03-19 20:26 - 2014-03-19 20:26 - 00001109 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-19 20:26 - 2014-03-19 20:26 - 00000000 ____D () C:\Users\Andy\AppData\Roaming\Malwarebytes
2014-03-19 20:26 - 2014-03-19 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-19 20:26 - 2014-03-19 20:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-19 20:25 - 2014-03-19 20:25 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andy\Desktop\mbam-setup-1.75.0.1300.exe
2014-03-19 20:18 - 2014-03-19 20:18 - 00001159 _____ () C:\Users\Andy\Desktop\JRT.txt
2014-03-19 20:12 - 2014-03-19 20:12 - 00000000 ____D () C:\Windows\ERUNT
2014-03-19 20:11 - 2011-04-12 08:43 - 00699682 _____ () C:\Windows\system32\perfh007.dat
2014-03-19 20:11 - 2011-04-12 08:43 - 00149790 _____ () C:\Windows\system32\perfc007.dat
2014-03-19 20:11 - 2009-07-14 06:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-19 20:10 - 2014-03-19 20:10 - 01037734 _____ (Thisisu) C:\Users\Andy\Desktop\JRT.exe
2014-03-19 20:04 - 2014-03-19 20:03 - 00000000 ____D () C:\AdwCleaner
2014-03-19 20:01 - 2014-03-19 20:01 - 01950720 _____ () C:\Users\Andy\Desktop\adwcleaner.exe
2014-03-19 20:01 - 2014-03-19 20:00 - 01950720 _____ () C:\Users\Andy\Downloads\adwcleaner.exe
2014-03-19 19:42 - 2013-11-25 08:12 - 00000000 ____D () C:\Users\Andy\Desktop\Fotos
2014-03-19 19:42 - 2012-05-10 09:46 - 00000000 ____D () C:\Users\Andy\Desktop\Stuff
2014-03-18 19:33 - 2012-06-21 09:15 - 13209088 ___SH () C:\Users\Andy\Desktop\Thumbs.db
2014-03-16 15:33 - 2013-04-28 18:06 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2411893241-2426368810-492649712-1000Core.job
2014-03-16 15:04 - 2014-03-16 14:54 - 00541874 _____ () C:\Users\Andy\Desktop\Addition.txt
2014-03-16 14:52 - 2014-03-16 14:52 - 02157056 _____ (Farbar) C:\Users\Andy\Desktop\FRST64.exe
2014-03-13 19:31 - 2012-08-20 07:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-13 19:31 - 2012-07-16 06:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-13 19:31 - 2012-03-23 10:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-13 19:01 - 2014-03-13 19:01 - 00001002 _____ () C:\Users\Andy\Desktop\IrfanView.lnk
2014-03-13 19:01 - 2014-03-13 19:01 - 00000000 ____D () C:\Users\Andy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2014-03-13 19:01 - 2014-03-13 19:01 - 00000000 ____D () C:\Users\Andy\AppData\Roaming\IrfanView
2014-03-13 19:01 - 2014-03-13 19:01 - 00000000 ____D () C:\Program Files (x86)\IrfanView
2014-03-13 18:59 - 2014-03-13 18:59 - 02179728 _____ (Irfan Skiljan) C:\Users\Andy\Downloads\iview437g_setup.exe
2014-03-07 14:25 - 2014-03-07 14:25 - 27474118 _____ () C:\Users\Andy\Downloads\capoeira training 1.avi
2014-03-07 14:24 - 2014-03-07 14:24 - 20166367 _____ () C:\Users\Andy\Downloads\capoeira training 1.mp4
2014-03-06 19:48 - 2014-03-06 19:48 - 00000002 _____ () C:\Users\Andy\Documents\Rz1.rzf
2014-02-25 18:15 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-02-24 19:22 - 2012-03-21 10:36 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-24 19:18 - 2014-02-24 19:18 - 01587612 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-24 19:11 - 2012-12-11 11:00 - 00000000 ____D () C:\Program Files (x86)\Java
2014-02-24 19:08 - 2012-03-28 18:11 - 00000000 ____D () C:\Program Files\Java
2014-02-20 18:24 - 2013-12-08 18:13 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-20 18:24 - 2013-12-08 18:13 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-20 17:28 - 2009-07-14 05:45 - 00417440 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-18 20:46 - 2013-08-15 07:21 - 00000000 ____D () C:\Windows\system32\MRT
Some content of TEMP:
====================
C:\Users\Andy\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-15 10:57
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014
Ran by Andy at 2014-03-20 19:01:16
Running from C:\Users\Andy\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Ahnenblatt 2.74 (HKLM-x32\...\Ahnenblatt_is1) (Version: 2.74.0.1 - Dirk Boettcher)
AMD Catalyst Install Manager (HKLM\...\{353D1262-B2D2-AD87-EB5E-6B1395AF9FAE}) (Version: 3.0.868.0 - Advanced Micro Devices, Inc.)
Anzeige am Bildschirm (HKLM\...\OnScreenDisplay) (Version: 6.70.00 - )
ATI Uninstaller (HKLM\...\ATI Uninstaller) (Version: 8.792.5.2-120504a-138564C-Lenovo - ATI Technologies, Inc.)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2012.0504.2334.40448 - ATI) Hidden
Catalyst Control Center Localization All (x32 Version: 2012.0504.2334.40448 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
CCC Help Dutch (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
CCC Help English (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
CCC Help French (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
CCC Help German (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
CCC Help Italian (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
CCC Help Japanese (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
CCC Help Korean (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
CCC Help Spanish (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
CCC Help Swedish (x32 Version: 2012.0504.2333.40448 - ATI) Hidden
ccc-core-static (x32 Version: 2012.0504.2334.40448 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2012.0504.2334.40448 - ATI) Hidden
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4478 - CDBurnerXP)
Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.04059 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.04059 - Cisco Systems, Inc.) Hidden
Conexant 20561 SmartAudio HD (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.92.12.0 - Conexant)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{81FB7C60-565A-4869-9D90-3BE1D270E8B7}) (Version: - Microsoft)
Dropbox (HKCU\...\Dropbox) (Version: 2.0.22 - Dropbox, Inc.)
ESS Energie Indikator (HKLM-x32\...\{6E83470B-5EE2-407D-ABFC-CC87E070ED8C}) (Version: 20.13.0 - Nemetschek Allplan GmbH)
Expat Shield 2.25 (HKLM-x32\...\ExpatShield) (Version: 2.25 - AnchorFree)
General Runtime Files for Allplan 2013-1-5 (x32 Version: 1.7.0.0 - Nemetschek Allplan Systems GmbH) Hidden
General Runtime Files for Allplan 2013-1-5 x64 (Version: 1.4.0.0 - Nemetschek Allplan Systems GmbH) Hidden
General Runtime Files for Nemetschek Softlock 2006 64 (Version: 1.2.0.0 - Nemetschek) Hidden
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden
Hotfix für Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) (HKLM-x32\...\{8E87B944-4815-3C5E-947F-5035C9F64362}.KB947789) (Version: 1 - Microsoft Corporation)
Intel PROSet Wireless (Version: - ) Hidden
Intel PROSet Wireless (x32 Version: - ) Hidden
Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
Intel(R) Management Engine Interface (HKLM\...\HECI) (Version: - Intel Corporation)
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 16.1 - Intel)
Intel(R) PROSet/Wireless WiFi-Software (HKLM\...\{D61E4101-9E15-4D0E-ABD1-1ABD36B43330}) (Version: 14.03.0000 - Intel Corporation)
Intel® Active-Management-Technologie (HKLM\...\MESOL) (Version: - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 31 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416031FF}) (Version: 6.0.310 - Oracle)
Java(TM) 6 Update 39 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216032FF}) (Version: 6.0.390 - Oracle)
Lenovo Fingerprint Software (HKLM\...\{2ED326C9-A4E6-4884-B3F0-9A6CFB0A1141}) (Version: 3.3.2.27 - AuthenTec, Inc.)
Lenovo Patch Utility (HKLM-x32\...\{AD32F5E9-6BDD-480A-8B7B-95571D04691C}) (Version: 1.3.1.1 - Lenovo Group Limited)
Lenovo Patch Utility 64 bit (HKLM\...\{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}) (Version: 1.3.1.1 - Lenovo Group Limited)
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.00.02 - )
Lenovo System Interface Driver (HKLM\...\LENOVO.SMIIF) (Version: 1.05 - )
Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.02.0018 - Lenovo)
Lexmark Pro800-Pro900 Series (HKLM\...\Lexmark Pro800-Pro900 Series) (Version: - Lexmark International, Inc.)
Logitech Vid (HKLM-x32\...\{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}) (Version: 1.10.1009 - Logitech Inc.)
Logitech Webcam Software (HKLM\...\{987FE247-4E69-4A2E-A961-D14F901FDBF6}) (Version: 12.10.1113 - Logitech Inc.)
Logitech Webcam Software-Treiberpaket (HKLM\...\lvdrivers_12.10) (Version: 12.10.1110 - Logitech Inc.)
Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version: - Microsoft)
Microsoft Office 2010 Service Pack 1 (SP1) (x32 Version: - Microsoft) Hidden
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Report Viewer Redistributable 2008 (KB971119) (HKLM-x32\...\Microsoft Report Viewer Redistributable 2008 (KB971119)) (Version: - Microsoft Corporation)
Microsoft Report Viewer Redistributable 2008 (KB971119) (x32 Version: 9.0.30731 - Microsoft Corporation) Hidden
Microsoft ReportViewer 2010 SP1 Redistributable (KB2549864) (HKLM-x32\...\{1282C0BC-3B22-33D4-B72E-62922415DDCA}) (Version: 10.0.40220 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Language Pack - DEU (HKLM-x32\...\{8E87B944-4815-3C5E-947F-5035C9F64362}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - DEU (HKLM-x32\...\{76DAEC83-AF7B-333C-8A53-83D7C7D39199}) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 27.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla)
Mozilla Thunderbird 24.3.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.3.0 (x86 de)) (Version: 24.3.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nemetschek Allplan 2013 (HKLM-x32\...\{FA47FBFD-2F6C-439A-B88C-2FFD6F4AE291}) (Version: 2013.0 - Nemetschek Allplan Systems GmbH)
Nemetschek SoftLock 2006 (HKLM-x32\...\{7262D0C8-41CC-4F75-8383-A6C7C61D7FC6}) (Version: 1.26.55 - Nemetschek Allplan Systems GmbH)
PDF24 Creator 5.4.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PDF-XChange Viewer (HKLM\...\{9ED333F8-3E6C-4A38-BAFA-728454121CDA}) (Version: 2.5.201.0 - Tracker Software Products Ltd.)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
RICOH R5U8xx Media Driver ver.3.64.02 (HKLM-x32\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.64.02 - RICOH)
RuckZuck 4.0 (HKLM-x32\...\RuckZuck 4.0) (Version: - )
Sentinel Runtime (HKLM-x32\...\{2A414CBE-CDF3-48C6-A91B-D3D4522F8EB5}) (Version: 6.3.1.28367 - SafeNet Inc.)
Skype™ 6.3 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.3.107 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
ThinkPad Bluetooth with Enhanced Data Rate Software (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.3100 - Broadcom Corporation)
ThinkPad FullScreen Magnifier (HKLM\...\ThinkPad FullScreen Magnifier) (Version: 2.40 - )
ThinkPad Modem Adapter (HKLM\...\CNXT_MODEM_HDA_HSF) (Version: 7.80.5.0 - Conexant Systems)
ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.19.9 - )
ThinkVantage System für aktiven Festplattenschutz (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.77.0.26 - Lenovo)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{001E8BF3-EDC3-4D5E-9C11-1D0E599B6497}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{001E8BF3-EDC3-4D5E-9C11-1D0E599B6497}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553065) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{A8686D24-1E89-43A1-973E-05A258D2B3F8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{18B3CF2A-73F7-4716-B1AE-86D68726D408}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (HKLM-x32\...\{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{32E700B9-1A94-48B4-99E1-CB8BD5F7340A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2566458) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFB525A0-E1C0-4E32-9968-FE401BC87363}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ED31DE9A-3E13-4E2C-9106-E0D8AFFB9FA6}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B1FA5E8C-2342-45AF-8A62-5E860042F8DF}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9CFD026D-EB1C-48C2-9DD2-8E8875F251B2}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2837583) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{E21274CE-CA0C-49FA-93F4-DC292A052264}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{B5C70C99-B109-42FD-B219-FF12CA543F19}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (HKLM-x32\...\{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{0C175ED0-26B9-4B09-AFA9-3F16A03A29B9}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{3EFF1957-7DEA-4C7A-8E9C-2D6D58E4B2ED}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3EFF1957-7DEA-4C7A-8E9C-2D6D58E4B2ED}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{651EE0E5-C789-48D8-8B91-F79352B783C9}) (Version: - Microsoft)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{81CA2EFA-7250-4B1E-B3A6-E0595224E2CD}) (Version: - Microsoft)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{BC6DFBFD-16DD-47E1-A7EF-2C062930FA4F}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{81812245-FC84-426A-BC02-6659C88CC7B2}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2775360) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{80F56E3F-1D47-4E45-B6E0-FEF4E919F4F9}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{5DA2D071-A54C-47C0-83E5-43C63DBFD936}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}) (Version: - Microsoft)
VLC media player 2.0.1 (HKLM-x32\...\VLC media player) (Version: 2.0.1 - VideoLAN)
Windows Driver Package - Broadcom (BTHUSB) Bluetooth (04/08/2010 6.3.5.430) (HKLM\...\DE7217D2A8B057F15EC6E52329FDAB84231521E8) (Version: 04/08/2010 6.3.5.430 - Broadcom)
Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\3BA80AB4C7E9F8497C115C844953A3D4BEB84D21) (Version: 07/28/2009 6.2.0.9800 - Broadcom)
Windows-Treiberpaket - AuthenTec Inc. (ATSwpWDF) Biometric (01/14/2010 8.6.0.13) (HKLM\...\0481B164C8D1D26C560D6A5E717C5920D4362D60) (Version: 01/14/2010 8.6.0.13 - AuthenTec Inc.)
==================== Restore Points =========================
24-02-2014 18:06:51 Removed Java 7 Update 51 (64-bit)
24-02-2014 18:08:28 Removed Java 7 Update 51
24-02-2014 18:11:58 Windows Update
09-03-2014 15:21:24 Geplanter Prüfpunkt
18-03-2014 19:06:59 Geplanter Prüfpunkt
19-03-2014 19:47:56 zoek.exe restore point
==================== Hosts content: ==========================
2009-07-14 03:34 - 2013-10-08 10:23 - 00475479 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0B128A8F-A156-495F-8FBA-C47D2328E7F1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-08] (Google Inc.)
Task: {0B313A42-9107-49F4-9BE3-41C798538A46} - System32\Tasks\AutoUpdate Allplan 2013 => C:\Program Files\Nemetschek\Allplan_3\prg\NemDownloadHandler.exe [2013-03-01] (Nemetschek Allplan Systems GmbH)
Task: {1B951354-40B7-43C5-A9C1-34261BDB6D86} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2411893241-2426368810-492649712-1000UA => C:\Users\Andy\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {5E9FD27A-5C70-4A2E-8FED-04F21F1823F3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-13] (Adobe Systems Incorporated)
Task: {6F08E44C-0875-4463-AE71-D91D2ED46BCF} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2013-06-26] ()
Task: {9F08C335-EAB2-40EC-AE59-6634CC8F0358} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-08] (Google Inc.)
Task: {C7323EFC-DDD4-4875-9649-3B349DE88BB6} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2411893241-2426368810-492649712-1000Core => C:\Users\Andy\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {D70CD65E-1AD8-4606-BB10-CDA2DFBEA2FB} - System32\Tasks\WebContent AutoUpdate 2013 => C:\Program Files\Nemetschek\Allplan_3\prg\NemDownloadHandler.exe [2013-03-01] (Nemetschek Allplan Systems GmbH)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AutoUpdate Allplan 2013.job => C:\Program Files\Nemetschek\Allplan_3\prg\NemDownloadHandler.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2411893241-2426368810-492649712-1000Core.job => C:\Users\Andy\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2411893241-2426368810-492649712-1000UA.job => C:\Users\Andy\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\WebContent AutoUpdate 2013.job => C:\Program Files\Nemetschek\Allplan_3\prg\NemDownloadHandler.exe
==================== Loaded Modules (whitelisted) =============
2010-02-05 06:45 - 2010-02-05 06:45 - 00117760 _____ () C:\Windows\system32\DTS.exe
2011-11-01 11:58 - 2011-11-01 11:58 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2012-04-02 10:31 - 2009-11-04 08:17 - 00189440 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxecdrpp.dll
2013-11-08 19:18 - 2013-01-23 13:35 - 00772712 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecmon.exe
2013-11-08 19:18 - 2013-01-23 13:35 - 00150264 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\ezprint.exe
2011-11-09 09:55 - 2011-11-09 09:55 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2012-05-04 22:33 - 2012-05-04 22:33 - 00270336 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2013-06-19 16:00 - 2013-06-19 16:00 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2013-02-12 17:46 - 2012-09-19 18:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2013-11-08 19:18 - 2010-04-01 12:23 - 00389120 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecscw.dll
2013-11-08 19:18 - 2009-05-27 07:16 - 00192512 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecdatr.dll
2013-11-08 19:18 - 2010-04-01 12:24 - 01159168 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecDRS.dll
2013-11-08 19:18 - 2009-03-10 00:43 - 00155648 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxeccaps.dll
2012-04-02 10:23 - 2009-02-20 03:48 - 00381440 _____ () C:\Windows\system32\lxecsm.dll
2012-04-02 10:23 - 2009-04-28 02:56 - 00024064 _____ () C:\Windows\system32\lxecsmr.dll
2013-11-08 19:18 - 2010-04-05 05:56 - 00716954 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Epwizard.DLL
2013-11-08 19:18 - 2010-04-05 05:55 - 00159890 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\customui.dll
2013-11-08 19:18 - 2010-04-05 05:54 - 00123033 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Eputil.DLL
2013-11-08 19:18 - 2010-04-05 05:54 - 00143502 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Imagutil.DLL
2013-11-08 19:18 - 2010-04-05 05:55 - 00061604 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Epfunct.DLL
2013-11-08 19:18 - 2009-06-23 06:09 - 02203648 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\EPWizRes.dll
2013-11-08 19:18 - 2009-06-23 06:10 - 00045056 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\epstring.dll
2013-11-08 19:18 - 2009-06-23 06:11 - 00102400 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\EPOEMDll.dll
2013-11-08 19:18 - 2009-04-07 14:25 - 00409600 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\iptk.dll
2013-11-08 19:18 - 2009-03-02 09:25 - 00151552 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecptp.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Windows:nlsPreferences
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
MSCONFIG\startupreg: Cisco AnyConnect Secure Mobility Agent for Windows => "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
MSCONFIG\startupreg: Logitech Vid => "C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe" -bootmode
MSCONFIG\startupreg: LogitechQuickCamRibbon => "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
==================== Faulty Device Manager Devices =============
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (03/20/2014 06:15:51 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/19/2014 09:06:55 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 27.0.1.5156, Zeitstempel: 0x52fc0faa
Name des fehlerhaften Moduls: xul.dll, Version: 27.0.1.5156, Zeitstempel: 0x52fc0f79
Ausnahmecode: 0xc0000005
Fehleroffset: 0x001560c7
ID des fehlerhaften Prozesses: 0x1018
Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0
Pfad der fehlerhaften Anwendung: firefox.exe1
Pfad des fehlerhaften Moduls: firefox.exe2
Berichtskennung: firefox.exe3
Error: (03/19/2014 09:00:43 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/19/2014 08:48:37 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: LVPrcSrv.exe, Version: 12.10.1110.0, Zeitstempel: 0x4acc50c4
Name des fehlerhaften Moduls: LVPrcSrv.exe, Version: 12.10.1110.0, Zeitstempel: 0x4acc50c4
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000007af2
ID des fehlerhaften Prozesses: 0x940
Startzeit der fehlerhaften Anwendung: 0xLVPrcSrv.exe0
Pfad der fehlerhaften Anwendung: LVPrcSrv.exe1
Pfad des fehlerhaften Moduls: LVPrcSrv.exe2
Berichtskennung: LVPrcSrv.exe3
Error: (03/19/2014 08:40:15 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (03/20/2014 06:17:54 PM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{A9F943D6-F52F-4FA2-B180-6965530F379E}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (03/20/2014 06:15:46 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "lxecCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (03/20/2014 06:15:46 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxecCATSCustConnectService erreicht.
Error: (03/20/2014 06:15:44 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Expat Shield Monitoring Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (03/20/2014 06:15:44 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Expat Shield Routing Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (03/20/2014 06:15:44 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Expat Shield Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (03/19/2014 09:09:34 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Data Transfer Service" hat einen ungültigen aktuellen Status gemeldet: 0
Error: (03/19/2014 09:00:30 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "lxecCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (03/19/2014 09:00:30 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxecCATSCustConnectService erreicht.
Error: (03/19/2014 09:00:28 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Expat Shield Monitoring Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Microsoft Office Sessions:
=========================
Error: (03/20/2014 06:15:51 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/19/2014 09:06:55 PM) (Source: Application Error)(User: )
Description: firefox.exe27.0.1.515652fc0faaxul.dll27.0.1.515652fc0f79c0000005001560c7101801cf43ae180191aeC:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\xul.dll04518e60-afa2-11e3-88a6-002268e277f9
Error: (03/19/2014 09:00:43 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/19/2014 08:48:37 PM) (Source: Application Error)(User: )
Description: LVPrcSrv.exe12.10.1110.04acc50c4LVPrcSrv.exe12.10.1110.04acc50c4c00000050000000000007af294001cf43ab0a1c1430C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exeC:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe76309151-af9f-11e3-b5b7-002268e277f9
Error: (03/19/2014 08:40:15 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Percentage of memory in use: 27%
Total physical RAM: 3992.03 MB
Available physical RAM: 2879.46 MB
Total Pagefile: 7982.23 MB
Available Pagefile: 6278.88 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:232.79 GB) (Free:173.31 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 77777777)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Look: Code:
SystemLook 30.07.11 by jpshortstuff
Log created at 19:23 on 20/03/2014 by Andy
Administrator - Elevation successful
========== filefind ==========
Searching for "*Expat Shield*"
C:\zoek_backup\C_ProgramData_Microsoft_Windows_Start Menu_Programs_Expat Shield\Expat Shield Control Panel.url --a---- 54 bytes [19:55 19/03/2014] [09:17 26/03/2012] 37C77C7F58C925AD50AD0540B3E17EBB
C:\zoek_backup\C_ProgramData_Microsoft_Windows_Start Menu_Programs_Expat Shield\Expat Shield Launch.lnk --a---- 1144 bytes [19:55 19/03/2014] [09:17 26/03/2012] 085423C76E328E922C253F9DCB448197
C:\zoek_backup\C_ProgramData_Microsoft_Windows_Start Menu_Programs_Expat Shield\Uninstall Expat Shield.lnk --a---- 834 bytes [19:56 19/03/2014] [09:17 26/03/2012] C1D2B16B0D83FE9D4FA543B8FD9C9DBE
========== folderfind ==========
Searching for "*Expat Shield*"
C:\Expat Shield d------ [09:17 26/03/2012]
C:\zoek_backup\C_ProgramData_Microsoft_Windows_Start Menu_Programs_Expat Shield d-a---- [19:55 19/03/2014]
C:\zoek_backup\C_PROGRA~2_Expat Shield d-a---- [19:55 19/03/2014]
========== regfind ==========
Searching for "Expat Shield"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e0d0a7cc_0]
@="{0.0.0.00000000}.{265c981d-49f7-4a9c-a245-1f30423dc3e1}|\Device\HarddiskVolume2\Program Files (x86)\Expat Shield\bin\fbw.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ExpatIE.ExpatIEApp]
@="Expat Shield Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ExpatIE.ExpatIEApp.1]
@="Expat Shield Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0]
@="Expat Shield Class 1.0 Type Library"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0\0\win32]
@="C:\Program Files (x86)\Expat Shield\HssIE\ExpatIE.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0\0\win64]
@="C:\Program Files (x86)\Expat Shield\HssIE\ExpatIE_64.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0\HELPDIR]
@="C:\Program Files (x86)\Expat Shield\HssIE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0]
@="Expat Shield Class 1.0 Type Library"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0\0\win32]
@="C:\Program Files (x86)\Expat Shield\HssIE\ExpatIE.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0\0\win64]
@="C:\Program Files (x86)\Expat Shield\HssIE\ExpatIE_64.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0\HELPDIR]
@="C:\Program Files (x86)\Expat Shield\HssIE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
@="C:\Program Files (x86)\Expat Shield"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
"config_dir"="C:\Program Files (x86)\Expat Shield\config"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
"htdocs_dir"="C:\Program Files (x86)\Expat Shield\htdocs"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
"verify_dir"="C:\Program Files (x86)\Expat Shield\log\verify"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
"exe_path"="C:\Program Files (x86)\Expat Shield\bin\openvpn.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
"proxy_path"="C:\Program Files (x86)\Expat Shield\bin\af_proxy_cmd.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
"log_dir"="C:\Program Files (x86)\Expat Shield\log"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
"log_path"="C:\Program Files (x86)\Expat Shield\log\oas.log"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
"hssie_dir"="C:\Program Files (x86)\Expat Shield\HssIE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
"hss_ff_dir"="C:\Program Files (x86)\Expat Shield\HssFF"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
"hss_wd_dir"="C:\Program Files (x86)\Expat Shield\hsswd"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ExpatShield]
"update_dir"="C:\Program Files (x86)\Expat Shield\update"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ExpatShield]
"DisplayName"="Expat Shield 2.25"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ExpatShield]
"UninstallString"="C:\Program Files (x86)\Expat Shield\Uninstall.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ExpatShield]
"DisplayIcon"="C:\Program Files (x86)\Expat Shield\expat.ico"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ExpatShield]
"InstallLocation"="C:\Program Files (x86)\Expat Shield"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0]
@="Expat Shield Class 1.0 Type Library"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0\0\win32]
@="C:\Program Files (x86)\Expat Shield\HssIE\ExpatIE.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0\0\win64]
@="C:\Program Files (x86)\Expat Shield\HssIE\ExpatIE_64.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{F5A29F21-B121-48A0-A317-737AF8BB106A}\1.0\HELPDIR]
@="C:\Program Files (x86)\Expat Shield\HssIE"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0016]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0016]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0017]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0017]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0018]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0018]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0019]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0019]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0020]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0020]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0022]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0022]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0023]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0023]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0027]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0027]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions]
"Expat Shield Routing Miniport"="1 2 3 4 5 6 7 8"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{E2A76D08-408E-440A-8F06-554AA005F205}]
"LocDescription"="@oem23.inf,%hssdrv_desc%;Expat Shield Routing Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{E2A76D08-408E-440A-8F06-554AA005F205}]
"Description"="Expat Shield Routing Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{E2A76D08-408E-440A-8F06-554AA005F205}\Ndi]
"HelpText"="Expat Shield Routing Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0000]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0000]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0000]
"FriendlyName"="Intel(R) WiFi Link 5100 AGN - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0001]
"FriendlyName"="Intel(R) 82567LM Gigabit Network Connection - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0001]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0001]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0002]
"FriendlyName"="WAN-Miniport (IP) - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0002]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0002]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0003]
"FriendlyName"="WAN-Miniport (Netzwerkmonitor) - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0003]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0003]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0004]
"FriendlyName"="WAN-Miniport (IPv6) - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0004]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0004]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0005]
"FriendlyName"="Anchorfree HSS Adapter - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0005]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0005]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0006]
"FriendlyName"="Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0006]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0006]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0007]
"FriendlyName"="Microsoft Virtual WiFi Miniport Adapter - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0007]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_HSSDRVMP\0007]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\ExpatSrv]
"EventMessageFile"="C:\Program Files (x86)\Expat Shield\HssWPR\hsssrv.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\ExpatWd]
"EventMessageFile"="C:\Program Files (x86)\Expat Shield\bin\hsswd.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ExpatShieldService]
"ImagePath"="C:\Program Files (x86)\Expat Shield\bin\openvpnas.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ExpatShieldService]
"DisplayName"="Expat Shield Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ExpatSrv]
"ImagePath"="C:\Program Files (x86)\Expat Shield\HssWPR\hsssrv.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ExpatSrv]
"DisplayName"="Expat Shield Routing Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ExpatTrayService]
"ImagePath"="C:\Program Files (x86)\Expat Shield\bin\ExpatTrayService.EXE"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ExpatTrayService]
"DisplayName"="Expat Shield Tray Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ExpatWd]
"ImagePath"="C:\Program Files (x86)\Expat Shield\bin\hsswd.exe -product Expat"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ExpatWd]
"DisplayName"="Expat Shield Monitoring Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HssDrv]
"DisplayName"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0016]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0016]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0017]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0017]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0018]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0018]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0019]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0019]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0020]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0020]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0022]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0022]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0023]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0023]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0027]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0027]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions]
"Expat Shield Routing Miniport"="1 2 3 4 5 6 7 8"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{E2A76D08-408E-440A-8F06-554AA005F205}]
"LocDescription"="@oem23.inf,%hssdrv_desc%;Expat Shield Routing Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{E2A76D08-408E-440A-8F06-554AA005F205}]
"Description"="Expat Shield Routing Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{E2A76D08-408E-440A-8F06-554AA005F205}\Ndi]
"HelpText"="Expat Shield Routing Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0000]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0000]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0000]
"FriendlyName"="Intel(R) WiFi Link 5100 AGN - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0001]
"FriendlyName"="Intel(R) 82567LM Gigabit Network Connection - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0001]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0001]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0002]
"FriendlyName"="WAN-Miniport (IP) - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0002]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0002]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0003]
"FriendlyName"="WAN-Miniport (Netzwerkmonitor) - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0003]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0003]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0004]
"FriendlyName"="WAN-Miniport (IPv6) - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0004]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0004]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0005]
"FriendlyName"="Anchorfree HSS Adapter - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0005]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0005]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0006]
"FriendlyName"="Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0006]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0006]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0007]
"FriendlyName"="Microsoft Virtual WiFi Miniport Adapter - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0007]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\MS_HSSDRVMP\0007]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\eventlog\Application\ExpatSrv]
"EventMessageFile"="C:\Program Files (x86)\Expat Shield\HssWPR\hsssrv.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\eventlog\Application\ExpatWd]
"EventMessageFile"="C:\Program Files (x86)\Expat Shield\bin\hsswd.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\ExpatShieldService]
"ImagePath"="C:\Program Files (x86)\Expat Shield\bin\openvpnas.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\ExpatShieldService]
"DisplayName"="Expat Shield Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\ExpatSrv]
"ImagePath"="C:\Program Files (x86)\Expat Shield\HssWPR\hsssrv.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\ExpatSrv]
"DisplayName"="Expat Shield Routing Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\ExpatTrayService]
"ImagePath"="C:\Program Files (x86)\Expat Shield\bin\ExpatTrayService.EXE"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\ExpatTrayService]
"DisplayName"="Expat Shield Tray Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\ExpatWd]
"ImagePath"="C:\Program Files (x86)\Expat Shield\bin\hsswd.exe -product Expat"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\ExpatWd]
"DisplayName"="Expat Shield Monitoring Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\HssDrv]
"DisplayName"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0016]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0016]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0017]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0017]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0018]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0018]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0019]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0019]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0020]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0020]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0022]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0022]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0023]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0023]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0027]
"ProviderName"="Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0027]
"DriverDesc"="Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions]
"Expat Shield Routing Miniport"="1 2 3 4 5 6 7 8"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{E2A76D08-408E-440A-8F06-554AA005F205}]
"LocDescription"="@oem23.inf,%hssdrv_desc%;Expat Shield Routing Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{E2A76D08-408E-440A-8F06-554AA005F205}]
"Description"="Expat Shield Routing Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{E2A76D08-408E-440A-8F06-554AA005F205}\Ndi]
"HelpText"="Expat Shield Routing Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0000]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0000]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0000]
"FriendlyName"="Intel(R) WiFi Link 5100 AGN - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0001]
"FriendlyName"="Intel(R) 82567LM Gigabit Network Connection - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0001]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0001]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0002]
"FriendlyName"="WAN-Miniport (IP) - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0002]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0002]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0003]
"FriendlyName"="WAN-Miniport (Netzwerkmonitor) - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0003]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0003]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0004]
"FriendlyName"="WAN-Miniport (IPv6) - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0004]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0004]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0005]
"FriendlyName"="Anchorfree HSS Adapter - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0005]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0005]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0006]
"FriendlyName"="Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0006]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0006]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0007]
"FriendlyName"="Microsoft Virtual WiFi Miniport Adapter - Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0007]
"Mfg"="@oem24.inf,%msft%;Expat Shield"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_HSSDRVMP\0007]
"DeviceDesc"="@oem24.inf,%hssdrvmp_desc%;Expat Shield Routing Miniport"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\ExpatSrv]
"EventMessageFile"="C:\Program Files (x86)\Expat Shield\HssWPR\hsssrv.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\ExpatWd]
"EventMessageFile"="C:\Program Files (x86)\Expat Shield\bin\hsswd.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ExpatShieldService]
"ImagePath"="C:\Program Files (x86)\Expat Shield\bin\openvpnas.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ExpatShieldService]
"DisplayName"="Expat Shield Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ExpatSrv]
"ImagePath"="C:\Program Files (x86)\Expat Shield\HssWPR\hsssrv.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ExpatSrv]
"DisplayName"="Expat Shield Routing Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ExpatTrayService]
"ImagePath"="C:\Program Files (x86)\Expat Shield\bin\ExpatTrayService.EXE"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ExpatTrayService]
"DisplayName"="Expat Shield Tray Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ExpatWd]
"ImagePath"="C:\Program Files (x86)\Expat Shield\bin\hsswd.exe -product Expat"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ExpatWd]
"DisplayName"="Expat Shield Monitoring Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\HssDrv]
"DisplayName"="Expat Shield Routing Miniport"
[HKEY_USERS\S-1-5-21-2411893241-2426368810-492649712-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e0d0a7cc_0]
@="{0.0.0.00000000}.{265c981d-49f7-4a9c-a245-1f30423dc3e1}|\Device\HarddiskVolume2\Program Files (x86)\Expat Shield\bin\fbw.exe%b{00000000-0000-0000-0000-000000000000}"
Searching for "Conduit"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\C:/Program Files/Nemetschek/Allplan_3/Prg/NemAll_Wpf_Geo_CadastralPlanforConduits.dll]
Searching for "Mobogenie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\28573ee7_0]
@="{0.0.0.00000000}.{265c981d-49f7-4a9c-a245-1f30423dc3e1}|\Device\HarddiskVolume2\Program Files (x86)\Mobogenie\Mobogenie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\Mobogenie]
[HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QSqlDriverFactoryInterface:\C:\Program Files (x86)\Mobogenie]
[HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files (x86)\Mobogenie]
[HKEY_USERS\S-1-5-21-2411893241-2426368810-492649712-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\28573ee7_0]
@="{0.0.0.00000000}.{265c981d-49f7-4a9c-a245-1f30423dc3e1}|\Device\HarddiskVolume2\Program Files (x86)\Mobogenie\Mobogenie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-2411893241-2426368810-492649712-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\Mobogenie]
[HKEY_USERS\S-1-5-21-2411893241-2426368810-492649712-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QSqlDriverFactoryInterface:\C:\Program Files (x86)\Mobogenie]
[HKEY_USERS\S-1-5-21-2411893241-2426368810-492649712-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files (x86)\Mobogenie]
Searching for "OpenCandy"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OpenCandyHelperRunOnceCFC232F5AF1443AF961445973E46CB5D]
Searching for " "
[HKEY_CURRENT_USER\Software\LexmarkInkjet\App List Manager v2]
"AppList"=" <DESTINATION>
<APP>
<FRIENDLY_NAME>MS Paint</FRIENDLY_NAME>
<PATH>C:\Windows\system32\mspaint.exe</PATH>
<DEFAULT_FILE_TYPE>JPG</DEFAULT_FILE_TYPE>
</APP>
</DESTINATION>
<DESTINATION>
<APP>
<FRIENDLY_NAME>MS PowerPoint</FRIENDLY_NAME>
<PATH>C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE</PATH>
<DEFAULT_FILE_TYPE>JPG</DEFAULT_FILE_TYPE>
</APP>
</DESTINATION>
"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Lexmark Pro900 Series (USB)]
"PrintCapabilites"="<?xml version="1.0"?>
<psf:PrintCapabilities version="1" xmlns:xsl="hxxp://www.w3.org/1999/XSL/Transform" xmlns:xs="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:cfg="hxxp://schemas.lexmark.com/2006/01/config" xmlns:lps="hxxp://schemas.lexmark.com/2006/01/lexmarkprintschema"><psf:Feature name="psk:JobCollateAllDocuments">
<psf:Option name="psk:Collated">
<psf:Property name="lps:Default"/>
<psf:Property name="lps:DMValue">
<psf:Value xsi:type="xs:integer">1</psf:Value>
</psf:Property>
<psf:Property name="psk:DisplayName"><psf:Value xsi:type="xs:string">Ein</psf:Value></psf:Property></psf
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\Andy\Downloads\lanvia_vt6105.exe"="Squeez Self Extractor "
[HKEY_LOCAL_MACHINE\SOFTWARE\LexmarkInkjet\App List Manager v2]
"AppList"=" <DESTINATION>
<APP>
<FRIENDLY_NAME>MS Paint</FRIENDLY_NAME>
<PATH>C:\Windows\system32\mspaint.exe</PATH>
<DEFAULT_FILE_TYPE>JPG</DEFAULT_FILE_TYPE>
</APP>
</DESTINATION>
<DESTINATION>
<APP>
<FRIENDLY_NAME>MS PowerPoint</FRIENDLY_NAME>
<PATH>C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE</PATH>
<DEFAULT_FILE_TYPE>JPG</DEFAULT_FILE_TYPE>
</APP>
</DESTINATION>
"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell]
"ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32]
"ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/>
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_1.62#000A270015536CDF&0#]
"DeviceDesc"="iPod "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_1.62#000A270015536CDF&0#]
"DeviceDesc"="iPod "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_1.62#000A270015536CDF&0#]
"DeviceDesc"="iPod "
[HKEY_USERS\S-1-5-21-2411893241-2426368810-492649712-1000\Software\LexmarkInkjet\App List Manager v2]
"AppList"=" <DESTINATION>
<APP>
<FRIENDLY_NAME>MS Paint</FRIENDLY_NAME>
<PATH>C:\Windows\system32\mspaint.exe</PATH>
<DEFAULT_FILE_TYPE>JPG</DEFAULT_FILE_TYPE>
</APP>
</DESTINATION>
<DESTINATION>
<APP>
<FRIENDLY_NAME>MS PowerPoint</FRIENDLY_NAME>
<PATH>C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE</PATH>
<DEFAULT_FILE_TYPE>JPG</DEFAULT_FILE_TYPE>
</APP>
</DESTINATION>
"
[HKEY_USERS\S-1-5-21-2411893241-2426368810-492649712-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Lexmark Pro900 Series (USB)]
"PrintCapabilites"="<?xml version="1.0"?>
<psf:PrintCapabilities version="1" xmlns:xsl="hxxp://www.w3.org/1999/XSL/Transform" xmlns:xs="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:cfg="hxxp://schemas.lexmark.com/2006/01/config" xmlns:lps="hxxp://schemas.lexmark.com/2006/01/lexmarkprintschema"><psf:Feature name="psk:JobCollateAllDocuments">
<psf:Option name="psk:Collated">
<psf:Property name="lps:Default"/>
<psf:Property name="lps:DMValue">
<psf:Value xsi:type="xs:integer">1</psf:Value>
</psf:Property>
<psf:Property name="psk:DisplayName"><psf:Value xsi:type="xs:stri
[HKEY_USERS\S-1-5-21-2411893241-2426368810-492649712-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\Andy\Downloads\lanvia_vt6105.exe"="Squeez Self Extractor "
[HKEY_USERS\S-1-5-21-2411893241-2426368810-492649712-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\Andy\Downloads\lanvia_vt6105.exe"="Squeez Self Extractor "
-= EOF =- Naja so richtige Probleme hatte ich sowieso nicht feststellen können. Ich bin nur durch den Fund bei Spybot S&D aufmerksam geworden.
Soll ich Spybot nochmal aktualisieren und drüber laufen lassen? Wann kann ich den TeaTimer und mein Virenprogramm wieder aktivieren? |