Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   JollyWallet, Coupon Werbung und unsichtbare Links in Chrome (https://www.trojaner-board.de/169056-jollywallet-coupon-werbung-unsichtbare-links-chrome.html)

RVD85 31.07.2015 06:57

addition.txt:

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:30-07-2015
durchgeführt von Admin (2015-07-31 07:52:18)
Gestartet von C:\Users\Admin\Desktop
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Admin (S-1-5-21-500210103-394823293-4185795276-1000 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-500210103-394823293-4185795276-500 - Administrator - Disabled)
Dori (S-1-5-21-500210103-394823293-4185795276-1002 - Limited - Enabled) => C:\Users\Dori
Gast (S-1-5-21-500210103-394823293-4185795276-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-500210103-394823293-4185795276-1012 - Limited - Enabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: AVG Internet Security 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Internet Security 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
FW: AVG Internet Security 2015 (Enabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

7-PDF Split & Merge Version 2.0.3 (Build 264) (HKLM-x32\...\7-PDF Split & Merge_is1) (Version: 7-PDF Split & Merge - Version 2.0.3 (Build 264) - 7-PDF, Germany - Thorsten Hodes)
ABBYY PDF Transformer+ (HKLM\...\{FA400000-0001-6400-0000-074957833700}) (Version: 4.1.241 - ABBYY Production LLC)
abgx360 v1.0.6 (HKLM-x32\...\abgx360) (Version:  - )
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.144 - Adobe Systems Incorporated)
Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
AI Suite II (HKLM-x32\...\{34D3688E-A737-44C5-9E2A-FF73618728E1}) (Version: 1.02.03 - ASUSTeK Computer Inc.)
AMD Catalyst Install Manager (HKLM\...\{14D58A97-B60E-A858-34D8-95469C02F7EC}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AnyDVD (HKLM-x32\...\AnyDVD) (Version: 7.0.0.0 - SlySoft)
Apple Application Support (HKLM-x32\...\{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}) (Version: 2.1.7 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}) (Version: 5.1.1.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Verifier (x64) (HKLM\...\{361A49FA-59B3-49FB-8C3E-08AF3EA5791A}) (Version: 4.0.917 - Microsoft Corporation)
ARIS Express (HKLM-x32\...\{1252F398-5142-4D81-AD31-8B0204C26E8C}) (Version: 1.00 - Ihr Firmenname)
Ashampoo Burning Studio 14 v.14.0.1 (HKLM-x32\...\{91B33C97-7BCF-CDFE-4321-58EBF3E8641C}_is1) (Version: 14.0.1 - Ashampoo GmbH & Co. KG)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.1.0 - Asmedia Technology)
Audacity 2.0.6 (HKLM-x32\...\Audacity_is1) (Version: 2.0.6 - Audacity Team)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6086 - AVG Technologies)
AVG 2015 (Version: 15.0.4401 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.6086 - AVG Technologies) Hidden
AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.1.5.143 - AVG Technologies)
Avidemux 2.5 (HKLM-x32\...\Avidemux 2.5 (64-bit)) (Version: 2.5.6.7716 - )
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Axure RP Pro 7.0 (HKLM-x32\...\Axure RP Pro 7.0) (Version: 7.0.0.3174 - Axure Software Solutions, Inc.)
Axure RP Pro 7.0 (x32 Version: 7.0.0.3174 - Axure Software Solutions, Inc.) Hidden
Balsamiq Mockups For Desktop (HKLM-x32\...\BalsamiqMockupsForDesktop.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1) (Version: 2.2.6 - Balsamiq, SRL)
Balsamiq Mockups For Desktop (x32 Version: 2.2.6 - Balsamiq, SRL) Hidden
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.6.2 - EA Digital Illusions CE AB)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version:  - )
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version:  - )
Canon IJ Network Scan Utility (HKLM-x32\...\Canon_IJ_Network_Scan_UTILITY) (Version:  - )
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version:  - )
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version:  - )
Canon MG5200 series Benutzerregistrierung (HKLM-x32\...\Canon MG5200 series Benutzerregistrierung) (Version:  - )
Canon MG5200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series) (Version:  - )
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version:  - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version:  - )
Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version:  - )
CD-LabelPrint (HKLM-x32\...\MediaNavigation.CDLabelPrint) (Version:  - )
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.08009 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.08009 - Cisco Systems, Inc.) Hidden
CloneCD (HKLM-x32\...\CloneCD) (Version:  - SlySoft)
CloneDVD2 (HKLM-x32\...\CloneDVD2) (Version: 2.9.2.8 - Elaborate Bytes)
Corel PaintShop Pro X7  (HKLM-x32\...\_{176F50D6-6857-49CE-B731-65F757EE3F0D}) (Version: 17.0.0.199 - Corel Corporation)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
Crysis® 2 (HKLM-x32\...\{6033673D-2530-4587-8AD0-EB059FC263F9}) (Version: 1.0.0.0 - Electronic Arts)
Crystal Reports for Visual Studio (x32 Version: 12.51.0.240 - SAP) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.2.0287 - DT Soft Ltd)
DATA BECKER BewerbungsGenie 7 (HKLM-x32\...\BewerbungsGenie 7_is1) (Version: 6.0.10.49 - DATA BECKER GmbH & Co. KG)
Dear Esther (HKLM-x32\...\Dear Esther_is1) (Version:  - )
Debugging Tools for Windows (x64) (HKLM\...\{7F2E5C3B-DBDF-469D-AD8D-F686D3B71176}) (Version: 6.11.1.404 - Microsoft Corporation)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.84 - DivX, LLC)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve )
Dropbox (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\Dropbox) (Version: 3.8.5 - Dropbox, Inc.)
EA Sports FIFA World (HKLM-x32\...\{8F9AC744-EEF6-43DB-A4B6-FA1A18F1C640}) (Version: 7.0.0.47449 - Electronic Arts, Inc.)
FINAL FANTASY VII (HKLM-x32\...\Steam App 39140) (Version:  - Square Enix)
FINAL FANTASY VIII (HKLM-x32\...\Steam App 39150) (Version:  - SQUARE ENIX)
foobar2000 v1.1.10 (HKLM-x32\...\foobar2000) (Version: 1.1.10 - Peter Pawlowski)
Football Manager 2014 version 14.1.4 (HKLM-x32\...\Football Manager 2014_is1) (Version: 14.1.4 - Sega)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Free YouTube to MP3 Converter version 3.12.50.1122 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.50.1122 - DVDVideoSoft Ltd.)
GanttProject (HKLM-x32\...\GanttProject) (Version:  - )
Geometry Wars 3 Dimensions (HKLM-x32\...\Geometry Wars 3 Dimensions_is1) (Version:  - )
Google Chrome (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\Google Chrome) (Version: 44.0.2403.125 - Google Inc.)
Google Drive (HKLM-x32\...\{6EA8B94E-D869-4D96-88DF-5E1ECE1D6876}) (Version: 1.23.9648.8824 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
HashCheck Shell Extension (x86-32) (HKLM-x32\...\HashCheck Shell Extension) (Version: 2.1.11.1 - Kai Liu)
HashCheck Shell Extension (x86-64) (HKLM\...\HashCheck Shell Extension) (Version: 2.1.11.1 - Kai Liu)
Hotfix für Microsoft Team Foundation Server 2010-Objektmodell - DEU (KB2890573) (HKLM-x32\...\{A1F50E06-E514-393D-AAEB-2F989F0B7C68}.KB2890573) (Version: 1 - Microsoft Corporation)
Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2529927) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2529927) (Version: 1 - Microsoft Corporation)
Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2548139) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2548139) (Version: 1 - Microsoft Corporation)
Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2549864) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2549864) (Version: 1 - Microsoft Corporation)
Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2635973) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2635973) (Version: 1 - Microsoft Corporation)
Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2890573) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2890573) (Version: 1 - Microsoft Corporation)
Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB3002340) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB3002340) (Version: 1 - Microsoft Corporation)
ICA (x32 Version: 17.0.0.199 - Corel Corporation) Hidden
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.6.0 - LIGHTNING UK!)
IPM_PSP_COM64 (Version: 17.0.0.199 - Corel Corporation) Hidden
iTunes (HKLM\...\{CF8FFD12-602B-422D-AF1D-511B411E7632}) (Version: 10.6.1.7 - Apple Inc.)
Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
JDownloader Packages (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\JDownloader Packages) (Version:  - ) <==== ACHTUNG
KeyMan V4.0 Build 5 (HKLM-x32\...\{DC627AE5-A2B1-4D16-AF56-178D10EC3E81}) (Version: 4.0.0.5 - ZF Electronics GmbH)
K-Lite Codec Pack 8.1.0 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 8.1.0 - )
KProbe 2.5.2 (HKLM-x32\...\KProbe) (Version:  - )
Launchy 2.5 (HKLM-x32\...\Launchy_21344213_is1) (Version:  - Code Jelly)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
Logitech Gaming Software 8.40 (HKLM\...\Logitech Gaming Software) (Version: 8.40.83 - Logitech Inc.)
Logitech Vid (HKLM-x32\...\{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}) (Version: 1.10.1009 - Logitech Inc.)
Logitech Webcam Software (HKLM\...\{987FE247-4E69-4A2E-A961-D14F901FDBF6}) (Version: 12.10.1113 - Logitech Inc.)
Logitech Webcam Software-Treiberpaket (HKLM\...\lvdrivers_12.10) (Version: 12.10.1110 - Logitech Inc.)
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 - DEU (HKLM-x32\...\{E4E9CBC9-1CF5-48E3-AF6F-1AB44A856346}) (Version: 2.0.50331.0 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools - DEU (HKLM-x32\...\{31C3C6EA-E991-405F-A3AA-2C070CCCC47C}) (Version: 2.0.50331.0 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools (HKLM-x32\...\{40416836-56CC-4C0E-A6AF-5C34BADCE483}) (Version: 2.0.50217.0 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 (HKLM-x32\...\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation)
Microsoft Help Viewer 1.0 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.0 Language Pack - DEU) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation)
Microsoft Help Viewer 1.1 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.1 Language Pack - DEU) (Version: 1.1.40219 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Silverlight 3 SDK - Deutsch (HKLM-x32\...\{91F54E1D-804A-46D8-A56C-53EA9C4B3177}) (Version: 3.0.40818.0 - Microsoft Corporation)
Microsoft Silverlight 4 SDK - Deutsch (HKLM-x32\...\{803910CC-3A39-45E3-A594-0D5512A60A86}) (Version: 4.0.50826.0 - Microsoft Corporation)
Microsoft SQL Server 2005 (HKLM-x32\...\Microsoft SQL Server 2005) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2008 (64-bit) (HKLM\...\Microsoft SQL Server 10 Release) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2008 Browser (HKLM-x32\...\{4AF2248C-B3DF-46FB-9596-87F5DB193689}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Native Client (HKLM\...\{8325FD0C-2FDB-46C3-921A-3A78385EA972}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{E9089B6A-1FDE-47F3-8D29-175F5B7A0722}) (Version: 10.50.1750.9 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (x64) (HKLM\...\{5ADA62BD-2FC0-4ECE-93AA-C933E69B2AB5}) (Version: 10.50.1750.9 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Transact-SQL-Sprachdienst (HKLM-x32\...\{BB1E119E-CF4B-4183-910E-A8C2B379F2C6}) (Version: 10.50.1752.9 - Microsoft Corporation)
Microsoft SQL Server 2008 R2-Datenebenenanwendungs-Framework (HKLM-x32\...\{919E5477-D20B-4F64-AE8B-8199469F7817}) (Version: 10.50.1750.9 - Microsoft Corporation)
Microsoft SQL Server 2008 R2-Datenebenenanwendungs-Projekt (HKLM-x32\...\{103A5E44-DD5B-46D5-AD1E-9DF2260CA023}) (Version: 10.50.1750.9 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{0125D081-30D0-4A97-82A8-C28D444B6256}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 DEU (HKLM\...\{C3EAE456-7E7A-451F-80EF-F34C7A13C558}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Database Publishing Wizard 1.4 (HKLM-x32\...\{ACE28263-76A4-4BF5-B6F4-8BD719595969}) (Version: 10.1.2512.8 - Microsoft Corporation)
Microsoft SQL Server Native Client (HKLM\...\{7C39E0D1-E138-42B1-B083-213EC2CF7692}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{C668416A-9213-4058-B7F2-01A42D85559D}) (Version: 10.50.1750.9 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\...\{0D432429-C79C-462D-ABD8-4D82B83A954B}) (Version: 10.50.1750.9 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\...\{28D06854-572C-4A65-83E5-F8CAF26B9FDC}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft Sync Framework Runtime v1.0 SP1 (x64) de (HKLM\...\{7AC5FFA7-6815-4AED-B16D-8E0D7CC4B221}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Framework SDK v1.0 SP1 de (HKLM-x32\...\{08DA8E46-ED67-451A-9246-50E0FF6959C9}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Framework Services v1.0 SP1 (x64) de (HKLM\...\{EF9A1373-9238-4E11-8FF8-7B83996F5BE5}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) de (HKLM\...\{11EB3D68-A5BE-43EA-8D31-43B08ADB0DA4}) (Version: 2.0.3010.0 - Microsoft Corporation)
Microsoft Team Foundation Server 2010-Objektmodell - DEU (HKLM\...\Microsoft Team Foundation Server 2010 Object Model - DEU) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Designtime - 10.0.30319 (HKLM\...\{95A2AD24-BD44-3E39-A31F-CE928276577E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Runtime - 10.0.40219 (HKLM\...\{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ Compilers 2008 Standard Edition - enu - x64 (HKLM\...\{965DF723-5688-359E-84D2-417CAFE644B5}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ Compilers 2008 Standard Edition - enu - x86 (HKLM-x32\...\{44D9A2CB-0692-3180-B5E2-26F4E807D067}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual F# 2.0 Runtime (HKLM-x32\...\{85467CBC-7A39-33C9-8940-D72D9269B84F}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual F# 2.0 Runtime Language Pack - DEU (HKLM-x32\...\{681F4E9F-34E0-36BD-BF2C-100554E403A5}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{616C6F39-4CE1-3434-A665-2F6A04C09A7F}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 IntelliTrace Collection (x64) (HKLM\...\{E1C1D175-C23E-38F4-9AC1-ABE5167022CF}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Service Pack 1 (HKLM-x32\...\Microsoft Visual Studio 2010 Service Pack 1) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010 Ultimate - DEU (HKLM-x32\...\Microsoft Visual Studio 2010 Ultimate - DEU) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio Macro Tools - DEU Language Pack (HKLM-x32\...\Microsoft Visual Studio Macro Tools - DEU Language Pack) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Macro Tools (HKLM-x32\...\Microsoft Visual Studio Macro Tools) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Windows SDK for Windows 7 (7.0) (HKLM\...\SDKSetup_7.0.7600.16385.40715) (Version: 7.0.7600.16385.40715 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Middle Earth Shadow of Mordor (HKLM-x32\...\Middle Earth Shadow of Mordor_is1) (Version:  - )
Might & Magic Heroes VI (HKLM-x32\...\{745D37C2-26F4-4B65-BA13-F9840EBFA75B}) (Version: 1.1 - Ubisoft)
MKVToolNix 6.2.0 (HKLM-x32\...\MKVToolNix) (Version: 6.2.0 - Moritz Bunkus)
Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0.2 - Mozilla)
MyFreeCodec (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\MyFreeCodec) (Version:  - )
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.2 - F.J. Wechselberger)
Nmap 5.51 (HKLM-x32\...\Nmap) (Version:  - )
No23 Recorder (HKLM-x32\...\No23 Recorder) (Version: 2.1.0.3 - No23)
No23 Recorder (x32 Version: 2.1.0.3 - No23) Hidden
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.3 - Notepad++ Team)
O&O Defrag Professional (HKLM\...\{C34D47BA-7A0E-4AFE-954B-254CCABCC032}) (Version: 17.0.490 - O&O Software GmbH)
One Finger Death Punch (HKLM-x32\...\Steam App 264200) (Version:  - Silver Dollar Games)
Ontrack EasyRecovery Professional (HKLM-x32\...\InstallShield_{268723B7-A994-4286-9F85-B974D5CAFC7B}) (Version: 6.22.01 - Kroll Ontrack Inc.)
Ontrack EasyRecovery Professional (x32 Version: 6.22.01 - Kroll Ontrack Inc.) Hidden
Origin (HKLM-x32\...\Origin) (Version: 9.3.10.4710 - Electronic Arts, Inc.)
Pesgalaxy.com Patch 2015 (HKLM-x32\...\Pesgalaxy.com Patch 2015 4.00) (Version: 4.00 - Pesgalaxy)
Pesgalaxy.com Patch 2015 DLC Installer (HKLM-x32\...\Pesgalaxy.com Patch 2015 DLC Installer 4.00) (Version: 4.00 - Pesgalaxy)
Pflanzen gegen Zombies™ (HKLM-x32\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.)
Phase 5 HTML-Editor (HKLM-x32\...\{20B1B020-DEAE-48D1-9960-D4C3185D758B}) (Version: 5.6.2.3 - Systemberatung Schommer)
Power Manager (HKLM-x32\...\{CA2CE23E-6751-4828-AF8B-66EA06E697F6}) (Version: 4.0.2.1 - Gembird Electronics Ltd.)
Pro Evolution Soccer 2015 (HKLM-x32\...\Steam App 287680) (Version:  - KONAMI Digital Entertainment)
Project CARS (HKLM-x32\...\UHJvamVjdENBUlM=_is1) (Version: 1 - )
Protect Disc License Helper 1.0.125 (IE) (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\Protect Disc License Helper) (Version: 1.0.125 - Protect Disc)
ProtectDisc Driver, Version 11 (HKLM-x32\...\ProtectDisc Driver 11) (Version: 11.0.0.14 - ProtectDisc Software GmbH)
PSPPContent (x32 Version: 17.0.0.199 - Corel Corporation) Hidden
PSPPHelp (x32 Version: 17.0.0.199 - Corel Corporation) Hidden
PSPPro64 (Version: 17.0.0.199 - Corel Corporation) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QIP 2012 4.0.7058 (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\QIP 2012) (Version: 4.0.7058 - )
Quake Live (HKLM-x32\...\Steam App 282440) (Version:  - id Software)
QuickMark (HKLM-x32\...\{53B0213C-CC0C-4340-90BF-BFC7D3FE5BB4}) (Version: 3.8.0 - SimpleAct)
Raptr (HKLM-x32\...\Raptr) (Version:  - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.43.321.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6526 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.42 - Piriform)
Rogue Legacy (HKLM-x32\...\Steam App 241600) (Version:  - Cellar Door Games)
Rosetta Stone Version 3 (HKLM-x32\...\{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}) (Version: 3.4.7.0 - Rosetta Stone Ltd.)
SABnzbd 0.7.20 (HKLM-x32\...\SABnzbd) (Version: 0.7.20 - The SABnzbd Team)
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.2.0.12014_18 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.2.0.12014_18 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.43.0 - SAMSUNG Electronics Co., Ltd.)
Seagate Dashboard 2.0 (HKLM-x32\...\{43C423D9-E6D6-4607-ADC9-EBB54F690C57}) (Version: 2.0.3602.0 - Seagate)
Service Pack 1 für SQL Server 2008 (KB 968369) (64-bit) (HKLM\...\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Setup (x32 Version: 17.0.0.199 - Ihr Firmenname) Hidden
Shrew Soft VPN Client (HKLM\...\Shrew Soft VPN Client) (Version:  - )
Sicherheitsupdate für Microsoft Visual Studio 2010 Ultimate - DEU (KB2645410) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2645410) (Version: 1 - Microsoft Corporation)
Sid Meiers Civilization Beyond Earth (HKLM-x32\...\U2lkTWVpZXJzQ2l2aWxpemF0aW9uQmV5b25kRWFydGg=_is1) (Version: 1 - )
SiSoftware Sandra Business 2012.SP1 (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2296}_is1) (Version: 18.24.2012.1 - SiSoftware)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.6 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
SnapaShot Pro 4.0.5.0 (HKLM-x32\...\{CC4A651E-C818-4089-8307-6764AFF04D2E}) (Version: 4.0.50 - NiceKit)
SopCast 3.4.8 (HKLM-x32\...\SopCast) (Version: 3.4.8 - www.sopcast.com)
Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Sweet Home 3D version 4.3 (HKLM\...\Sweet Home 3D_is1) (Version:  - eTeks)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.41110 - TeamViewer)
The Elder Scrolls V - Skyrim (HKLM-x32\...\The Elder Scrolls V - Skyrim_is1) (Version:  - )
The Elder Scrolls V Skyrim - High Resolution Texture Pack (HKLM-x32\...\The Elder Scrolls V Skyrim - High Resolution Texture Pack_is1) (Version:  - )
The Witcher 2 (HKLM-x32\...\{F0A209B7-7F85-4BDD-8F1F-B98EEAD9E04B}) (Version: 1.00.0000 - CD Projekt Red)
The Witcher 3 Wild Hunt Version 1.02 (HKLM-x32\...\{0E0E1973-8765-48CD-8CB8-5F3C050A3404}_is1) (Version: 1.02 - Rapid Games)
TomTom HOME 2.8.4.2596 (HKLM-x32\...\TomTom HOME) (Version: 2.8.4.2596 - TomTom)
TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
Tor 0.2.3.25 (HKLM-x32\...\Tor) (Version:  - )
TreeSize Professional V5.5.3 (HKLM-x32\...\TreeSize Professional_is1) (Version: 5.5.3 - JAM Software)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Unified Remote (HKLM-x32\...\{415B4714-4F8C-49C6-B310-881EAF892CFB}_is1) (Version: 3.2.4 - Unified Intents AB)
Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (HKLM-x32\...\{07629207-FAA0-4F1A-8092-BF5085BE511F}) (Version: 9.00.5000.00 - Microsoft Corporation)
Unterstützungsdateien für Microsoft SQL Server 2008-Setup  (HKLM\...\{6AF73222-EE90-434C-AE7E-B96F70A68D89}) (Version: 10.1.2731.0 - Microsoft Corporation)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Veetle TV (HKLM-x32\...\Veetle TV) (Version: 0.9.19 - Veetle, Inc)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 Prerequisites - English (HKLM\...\{53952792-BF16-300E-ADF2-E7E4367E00CF}) (Version: 10.0.40219 - Microsoft Corporation)
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{CFCB8616-A5D1-4281-80E8-389F685BFAE2}) (Version: 4.0.8080.0 - Microsoft Corporation)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.6 (HKLM-x32\...\VLC media player) (Version: 2.0.6 - VideoLAN)
VMware Workstation (HKLM-x32\...\VMware_Workstation) (Version: 10.0.4 - VMware, Inc)
VMware Workstation (Version: 10.0.4 - VMware, Inc.) Hidden
WCF RIA Services V1.0 SP1 (HKLM-x32\...\{D9E6001A-5DC3-4620-AF7A-80B6CD48645D}) (Version: 4.1.60114.0 - Microsoft Corporation)
Web Deployment Tool (HKLM\...\{0F37D969-1260-419E-B308-EF7D29ABDE20}) (Version: 1.1.0618 - Microsoft Corporation)
WhoCrashed 4.01 (HKLM\...\WhoCrashed_is1) (Version:  - Resplendence Software Projects Sp.)
Wichtiges Update für Microsoft Visual Studio 2010 Ultimate - DEU (KB2938807) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2938807) (Version: 1 - Microsoft Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 5.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)
XAMPP (HKLM-x32\...\xampp) (Version: 5.6.3-0 - Bitnami)
Zotero Standalone 4.0.20 (x86 en-US) (HKLM-x32\...\Zotero Standalone 4.0.20 (x86 en-US)) (Version: 4.0.20 - Zotero)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll Keine Datei
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll Keine Datei
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll Keine Datei
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll Keine Datei
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll Keine Datei
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll Keine Datei
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{DDD5A6D8-BC35-305A-CDA1-5139EBA1CE52}\InprocServer32 -> C:\Windows\system32\ole32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll Keine Datei

==================== Wiederherstellungspunkte =========================

27-07-2015 13:00:14 LavasoftWeCompanion
27-07-2015 13:17:57 Removed Adobe Reader X (10.1.15) - Deutsch.
27-07-2015 13:59:41 Installed AVG 2015
28-07-2015 14:57:48 AA11
29-07-2015 03:00:11 Windows Update
30-07-2015 10:07:58 JRT Pre-Junkware Removal

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2015-07-28 16:00 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {09B9908D-D194-4062-BB17-CCC08ACFFA71} - System32\Tasks\ASUS\USB 3.0 Boost Service => C:\Users\Admin\ASUS\AI Suite\AI Suite II\USB 3.0 Boost\U3BoostSvr.exe [2011-09-10] ()
Task: {2139FE22-776F-49BA-9F18-B9BE87211895} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2015-01-19] ()
Task: {263CB289-3979-4C47-ABE3-D6C71ABD2B0B} - System32\Tasks\Admin Merge => I:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\NBCore.exe [2012-07-02] (Seagate Technology LLC)
Task: {3681667D-0AAF-4DA0-A1A9-D1AF1116F664} - System32\Tasks\Admin DBAgent 2 0 => I:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [2012-07-02] (Seagate Technology LLC)
Task: {560509F5-4ECB-4FD3-9413-49A9FFD716A8} - System32\Tasks\Admin => I:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\NBCore.exe [2012-07-02] (Seagate Technology LLC)
Task: {5BBDA84B-B6B2-4904-BB1D-CA75E17968AE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-14] (Google Inc.)
Task: {62AFA439-8983-4AC8-80E3-74307111040C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {87CDCEA4-96CC-4E23-B459-E79786CE5865} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-06-08] (Oracle Corporation)
Task: {9BF13928-B45D-4102-954F-212A6CFCAF17} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000UA => C:\Users\Admin\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
Task: {9FE20538-AF2E-43B7-BC62-E4FF8C1375F9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-14] (Google Inc.)
Task: {A108CDCA-2014-446B-A1C3-A491BF7E6674} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000Core => C:\Users\Admin\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
Task: {DD5AFC66-F422-4A21-9334-F00676F16DAE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-30] (Adobe Systems Incorporated)
Task: {E2820C24-A83B-49E2-A05E-0DBF50EB303F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000Core => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.)
Task: {EFEAFE41-75F4-48DF-9ADF-6B6752EC9528} - System32\Tasks\{BBD87979-BAB0-4CD4-A69B-D1BA0B897D68} => Chrome.exe hxxp://ui.skype.com/ui/0/7.2.0.103/de/abandoninstall?page=tsMain
Task: {F3D994EE-1EB3-48F9-A952-C99F0EFFF69C} - System32\Tasks\elbyExecuteWithUAC => I:\Program Files (x86)\Elaborate Bytes\CloneDVD2\ExecuteWithUAC.exe [2008-06-27] ()
Task: {FD8D8F91-0314-4AE8-8EDC-3B0FDC02A92F} - System32\Tasks\ASUS\ASUS AI Suite II Execute => C:\Users\Admin\ASUS\AI Suite\AI Suite II\AsRoutineController.exe [2010-11-26] (ASUSTeK Computer Inc.)
Task: {FF0DD1DB-6294-45E6-9493-1D8E036FD7D1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000UA => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000Core.job => C:\Users\Admin\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000UA.job => C:\Users\Admin\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000Core.job => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000UA.job => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-06-23 00:24 - 2015-07-23 13:26 - 01195920 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
2015-06-22 21:37 - 2015-06-22 21:37 - 00214528 _____ () I:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 00817152 _____ () I:\Program Files\AMD\ATI.ACE\Fuel\Device.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 03650560 _____ () I:\Program Files\AMD\ATI.ACE\Fuel\Platform.dll
2012-01-24 21:42 - 2011-10-07 12:34 - 00922240 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe
2012-01-24 21:42 - 2011-10-07 12:34 - 00915584 _____ () C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
2012-01-24 21:43 - 2011-10-07 12:35 - 00586880 _____ () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
2010-10-08 07:18 - 2010-10-08 07:18 - 00056592 _____ () I:\Program Files\ShrewSoft\VPN Client\dtpd.exe
2010-09-02 09:24 - 2010-09-02 09:24 - 00017920 _____ () I:\Program Files\ShrewSoft\VPN Client\libith.dll
2010-09-02 09:24 - 2010-09-02 09:24 - 00019456 _____ () I:\Program Files\ShrewSoft\VPN Client\libdtp.dll
2010-09-02 09:24 - 2010-09-02 09:24 - 00026624 _____ () I:\Program Files\ShrewSoft\VPN Client\libidb.dll
2010-09-02 09:24 - 2010-09-02 09:24 - 00013312 _____ () I:\Program Files\ShrewSoft\VPN Client\liblog.dll
2010-09-02 09:24 - 2010-09-02 09:24 - 00035328 _____ () I:\Program Files\ShrewSoft\VPN Client\libvflt.dll
2010-09-02 09:24 - 2010-09-02 09:24 - 00119296 _____ () I:\Program Files\ShrewSoft\VPN Client\libip.dll
2012-01-31 20:06 - 2010-04-05 12:55 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2010-10-08 07:18 - 2010-10-08 07:18 - 00957712 _____ () I:\Program Files\ShrewSoft\VPN Client\iked.exe
2010-09-02 09:24 - 2010-09-02 09:24 - 00028160 _____ () I:\Program Files\ShrewSoft\VPN Client\libike.dll
2010-09-02 09:25 - 2010-09-02 09:25 - 00040448 _____ () I:\Program Files\ShrewSoft\VPN Client\libvnet.dll
2010-09-02 09:24 - 2010-09-02 09:24 - 00030720 _____ () I:\Program Files\ShrewSoft\VPN Client\libpfk.dll
2010-10-08 07:18 - 2010-10-08 07:18 - 00697616 _____ () I:\Program Files\ShrewSoft\VPN Client\ipsecd.exe
2014-05-29 02:54 - 2014-05-29 02:54 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-05-12 11:49 - 2014-05-12 11:49 - 00222720 _____ () I:\Program Files (x86)\Notepad++\NppShell_06.dll
2012-01-15 00:15 - 2010-11-10 20:38 - 00380928 _____ () I:\Program Files (x86)\Launchy\Launchy.exe
2013-08-29 02:23 - 2013-08-29 02:23 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2015-06-22 21:37 - 2015-06-22 21:37 - 00102400 _____ () I:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2015-04-20 17:46 - 2015-04-20 17:46 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2012-02-20 21:29 - 2012-02-20 21:29 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-02-20 21:28 - 2012-02-20 21:28 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-01-24 21:42 - 2015-07-31 07:48 - 00033280 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.14\PEbiosinterface32.dll
2012-01-24 21:42 - 2011-10-07 12:34 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.14\ATKEX.dll
2014-10-29 16:01 - 2014-10-29 16:01 - 01261272 _____ () C:\Program Files (x86)\VMware\VMware Workstation\libxml2.dll
2015-07-31 07:49 - 2015-07-31 07:49 - 00098816 _____ () G:\Temp\_MEI68162\win32api.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00110080 _____ () G:\Temp\_MEI68162\pywintypes27.dll
2015-07-31 07:49 - 2015-07-31 07:49 - 00364544 _____ () G:\Temp\_MEI68162\pythoncom27.dll
2015-07-31 07:49 - 2015-07-31 07:49 - 00045568 _____ () G:\Temp\_MEI68162\_socket.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 01161216 _____ () G:\Temp\_MEI68162\_ssl.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00320512 _____ () G:\Temp\_MEI68162\win32com.shell.shell.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00713216 _____ () G:\Temp\_MEI68162\_hashlib.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 01175040 _____ () G:\Temp\_MEI68162\wx._core_.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00805888 _____ () G:\Temp\_MEI68162\wx._gdi_.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00811008 _____ () G:\Temp\_MEI68162\wx._windows_.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 01062400 _____ () G:\Temp\_MEI68162\wx._controls_.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00735232 _____ () G:\Temp\_MEI68162\wx._misc_.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00682496 _____ () G:\Temp\_MEI68162\pysqlite2._sqlite.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00087552 _____ () G:\Temp\_MEI68162\_ctypes.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00119808 _____ () G:\Temp\_MEI68162\win32file.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00108544 _____ () G:\Temp\_MEI68162\win32security.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00007168 _____ () G:\Temp\_MEI68162\hashobjs_ext.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00068096 _____ () G:\Temp\_MEI68162\usb_ext.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00167936 _____ () G:\Temp\_MEI68162\win32gui.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00018432 _____ () G:\Temp\_MEI68162\win32event.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00128512 _____ () G:\Temp\_MEI68162\_elementtree.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00127488 _____ () G:\Temp\_MEI68162\pyexpat.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00013824 _____ () G:\Temp\_MEI68162\common.time34.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00036864 _____ () G:\Temp\_MEI68162\_psutil_windows.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00038912 _____ () G:\Temp\_MEI68162\win32inet.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00011264 _____ () G:\Temp\_MEI68162\win32crypt.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00070656 _____ () G:\Temp\_MEI68162\wx._html2.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00027136 _____ () G:\Temp\_MEI68162\_multiprocessing.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00020480 _____ () G:\Temp\_MEI68162\_yappi.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00035840 _____ () G:\Temp\_MEI68162\win32process.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00686080 _____ () G:\Temp\_MEI68162\unicodedata.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00122368 _____ () G:\Temp\_MEI68162\wx._wizard.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00024064 _____ () G:\Temp\_MEI68162\win32pipe.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00010240 _____ () G:\Temp\_MEI68162\select.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00025600 _____ () G:\Temp\_MEI68162\win32pdh.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00525640 _____ () G:\Temp\_MEI68162\windows._lib_cacheinvalidation.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00017408 _____ () G:\Temp\_MEI68162\win32profile.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00022528 _____ () G:\Temp\_MEI68162\win32ts.pyd
2015-07-31 07:49 - 2015-07-31 07:49 - 00078336 _____ () G:\Temp\_MEI68162\wx._animate.pyd
2012-01-15 00:15 - 2009-12-16 23:13 - 08314880 _____ () I:\Program Files (x86)\Launchy\QtGui4.dll
2012-01-15 00:15 - 2009-12-16 22:54 - 02236416 _____ () I:\Program Files (x86)\Launchy\QtCore4.dll
2012-01-15 00:15 - 2009-12-16 22:56 - 00712704 _____ () I:\Program Files (x86)\Launchy\QtNetwork4.dll
2012-01-15 00:15 - 2009-12-17 01:18 - 00233472 _____ () I:\Program Files (x86)\Launchy\imageformats\qmng4.dll
2012-01-15 00:15 - 2010-11-10 20:39 - 00081920 _____ () I:\Program Files (x86)\Launchy\plugins\calcy.dll
2012-01-15 00:15 - 2010-11-10 20:39 - 00090112 _____ () I:\Program Files (x86)\Launchy\plugins\controly.dll
2012-01-15 00:15 - 2010-11-10 20:38 - 00024064 _____ () I:\Program Files (x86)\Launchy\plugins\gcalc.dll
2012-01-15 00:15 - 2010-11-10 20:38 - 00094208 _____ () I:\Program Files (x86)\Launchy\plugins\runner.dll
2012-01-15 00:15 - 2010-11-10 20:38 - 00057344 _____ () I:\Program Files (x86)\Launchy\plugins\verby.dll
2012-01-15 00:15 - 2010-11-10 20:38 - 00122880 _____ () I:\Program Files (x86)\Launchy\plugins\weby.dll
2015-07-31 07:49 - 2015-07-31 07:49 - 00071168 _____ () g:\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpl3wavg.dll
2015-03-04 23:45 - 2015-07-17 02:31 - 00012800 _____ () C:\Users\Admin\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll
2015-03-04 23:45 - 2015-07-17 02:31 - 00779776 _____ () C:\Users\Admin\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-07-30 09:22 - 2015-07-17 02:31 - 00056320 _____ () C:\Users\Admin\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-03-04 23:45 - 2015-07-17 02:31 - 00012288 _____ () C:\Users\Admin\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll
2012-01-24 21:43 - 2011-07-12 20:14 - 00147456 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\AssistFunc.dll
2012-01-24 21:43 - 2010-10-05 09:22 - 00253952 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\pngio.dll
2012-01-24 21:43 - 2011-08-12 16:48 - 00985088 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\BarGadget\BarGadget.dll
2012-01-24 21:43 - 2011-07-26 17:16 - 00880128 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\Sensor\Sensor.dll
2012-01-24 21:43 - 2011-07-29 12:44 - 01611776 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\Sensor Graph\SensorGraph.dll
2012-01-24 21:43 - 2011-08-09 13:15 - 01242624 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\Settings\Settings.dll
2012-01-24 21:43 - 2011-07-21 10:06 - 00846848 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\Splitter\Splitter.dll
2012-01-24 21:43 - 2011-07-21 21:33 - 00885760 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\TabGadget\TabGadget.dll
2012-01-24 21:42 - 2011-10-07 12:34 - 00662016 _____ () C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMLib.dll
2012-01-24 21:43 - 2010-10-05 09:22 - 00208896 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\ImageHelper.dll
2012-01-24 21:43 - 2010-06-21 16:21 - 00208896 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\Sensor\AlertHelper\ImageHelper.dll
2006-02-22 16:47 - 2006-02-22 16:47 - 00073728 ____R () I:\Program Files (x86)\Cherry\KeyMan\zlib1.dll
2006-02-22 16:47 - 2006-02-22 16:47 - 00114688 ____R () I:\Program Files (x86)\Cherry\KeyMan\libpng13.dll
2013-08-29 02:25 - 2013-08-29 02:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2015-07-29 21:28 - 2015-07-25 10:46 - 01405768 _____ () C:\Users\Admin\AppData\Local\Google\Chrome\Application\44.0.2403.125\libglesv2.dll
2015-07-29 21:28 - 2015-07-25 10:46 - 00081224 _____ () C:\Users\Admin\AppData\Local\Google\Chrome\Application\44.0.2403.125\libegl.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer trusted/restricted ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\webcompanion.com -> hxxp://webcompanion.com


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-500210103-394823293-4185795276-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 0) (EnableLUA: 0)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk => C:\Windows\pss\Logitech . Produktregistrierung.lnk.Startup
MSCONFIG\startupreg: AdAwareTray => "C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.7.485.8398\AdAwareTray.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BCSSync => "I:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
MSCONFIG\startupreg: CloneCDTray => "I:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
MSCONFIG\startupreg: DAEMON Tools Lite => "I:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: DBAgent => "I:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe" /WinStart
MSCONFIG\startupreg: Google Update => "C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: iLivid => "C:\Program Files (x86)\iLivid\iLivid.exe" -autorun
MSCONFIG\startupreg: Infium => "I:\Program Files (x86)\QIP 2012\qip.exe" /autorun
MSCONFIG\startupreg: iTunesHelper => "I:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: KiesHelper => I:\Program Files (x86)\Kies\KiesHelper.exe /s
MSCONFIG\startupreg: KiesPDLR => I:\Program Files (x86)\Kies\External\FirmwareUpdate\KiesPDLR.exe
MSCONFIG\startupreg: KiesTrayAgent => I:\Program Files (x86)\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: Logitech Vid => "I:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
MSCONFIG\startupreg: LogitechQuickCamRibbon => "I:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
MSCONFIG\startupreg: Raptr => C:\PROGRA~2\Raptr\raptrstub.exe --startup
MSCONFIG\startupreg: Steam => "I:\Spiele\Shogun2\Steam.exe" -silent
MSCONFIG\startupreg: TomTomHOME.exe => "I:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
MSCONFIG\startupreg: Uploader => I:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
MSCONFIG\startupreg: vmware-tray.exe => "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
MSCONFIG\startupreg: vProt => "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe"
MSCONFIG\startupreg: Web Companion => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [TCP Query User{DA8B16C5-BE90-40EA-827E-2EB7C52B0EA8}I:\program files (x86)\qip 2012\qip.exe] => (Allow) I:\program files (x86)\qip 2012\qip.exe
FirewallRules: [UDP Query User{BBFB236B-3C59-411B-9BA8-13E22649E395}I:\program files (x86)\qip 2012\qip.exe] => (Allow) I:\program files (x86)\qip 2012\qip.exe
FirewallRules: [{8BC7C635-B55F-4EF5-8438-6223B40D4A80}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{F4D2F6EF-B0BB-47EE-961A-37C7B153E8F0}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{AFE7696E-2626-4CE4-AB98-864DFF54B436}] => (Allow) I:\Program Files\SiSoftware\SiSoftware Sandra Business 2012.SP1\RpcAgentSrv.exe
FirewallRules: [{362EE47C-9839-45F0-B2B5-2BAB03546E58}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2012\pes2012.exe
FirewallRules: [{19FA7D7D-FCE5-4133-9E56-A505077BE123}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2012\pes2012.exe
FirewallRules: [{FEAA08D5-1F62-4746-8502-6C8E35AD3AD4}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{89D83809-0329-4E93-9BBC-8F29947A1F6C}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{7E8D0281-4E3D-42E6-8C8B-CBCE14158C15}] => (Allow) I:\Spiele\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe
FirewallRules: [{D2940AD0-EC65-4E66-82FE-5993E30F4857}] => (Allow) I:\Spiele\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe
FirewallRules: [{5955373F-CE8A-4702-B083-83FE94F2CF0C}] => (Allow) I:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe
FirewallRules: [{C74EA9EC-C3E1-478D-9D8D-4121CD67F358}] => (Allow) I:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe
FirewallRules: [{A4B35129-520A-4D22-9439-E769F6464314}] => (Allow) I:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe
FirewallRules: [{EDE36322-5FEB-4116-A24C-0A8E37EBE3F7}] => (Allow) I:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe
FirewallRules: [{0401DEE8-6C56-46D7-BD3D-68C3DD114DC8}] => (Allow) C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{96B950BC-63B4-4374-AD70-0490E0DA7948}] => (Allow) C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{07845E60-9CD3-42AF-9DCA-A6493B8D815E}] => (Allow) I:\Program Files (x86)\MirandaFusion\miranda32.exe
FirewallRules: [{5ABB16A8-F1E4-4662-94A8-C2218E58E695}] => (Allow) I:\Program Files (x86)\MirandaFusion\miranda32.exe
FirewallRules: [{63D7AAF9-70F3-4274-98E8-F1469964D069}] => (Allow) I:\Program Files (x86)\MirandaFusion\fusiontools\updater.exe
FirewallRules: [{344C8FB4-5E3B-493C-9EEB-F4E3A503E934}] => (Allow) I:\Program Files (x86)\MirandaFusion\fusiontools\updater.exe
FirewallRules: [{0E1CFE8E-8E51-4BAB-BDC6-1F55B40B4BDC}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{60156986-F05F-4B44-B56A-1B6296FFCA4F}] => (Allow) I:\Program Files (x86)\Veetle\Player\VeetleNet.exe
FirewallRules: [{0E5E8547-8C1C-4FF2-A6CD-04BE4BDD0BB3}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{D6494379-CA32-419C-9161-11CF8F0CB2E7}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{1C07C517-3B5D-440E-8E59-B9ED88FCE7FF}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{8EB90E80-4711-408D-9B52-85382808D083}] => (Allow) LPort=2869
FirewallRules: [{E592F7EA-5498-4FD8-84F9-403CAE992B2A}] => (Allow) LPort=1900
FirewallRules: [{3328D48A-C369-48D9-A0DA-BAA29331C542}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{67E46703-985D-4D43-80DC-6D6BE9C1D8B5}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
FirewallRules: [{429B5E54-A9D8-4DDD-81FE-3F7B05676ACD}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
FirewallRules: [{7C722773-66FB-4F9A-89EC-BACA2FFC0C83}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{643EEACE-F60F-4B95-9A5D-6E93AA9AD08C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C25BBC8C-1F24-4F79-B3EC-5493341A9E8D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1D1C9799-404B-40B7-8F23-58DA1C06B7A6}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{F057F700-6E39-4191-8C76-8466AD3A371B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{D64842BC-1FB7-4B7B-9570-06536E65C93C}] => (Allow) I:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{3A72BC0D-0D37-4F3D-B862-BDEDE8A06E10}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2012\pes2012.exe
FirewallRules: [{37722471-2BE3-4C12-8B7C-322EF6D3204E}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2012\pes2012.exe
FirewallRules: [{4398A648-238B-4A09-9C0A-FB54437DB8E5}] => (Allow) C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2013\pes2013.exe
FirewallRules: [{CA9385B3-F70A-4C01-A51A-D6AF1A5F8B72}] => (Allow) C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2013\pes2013.exe
FirewallRules: [{E109636D-820D-4439-B85F-EDF9C1E8D15E}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\pes2013.exe
FirewallRules: [{AD9987BD-1C12-4441-9B11-2CA40DDFAF81}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\pes2013.exe
FirewallRules: [{662B62DD-ECC8-4B0C-8C77-0DE526D49089}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\Pesgalaxy.com Patch 2013\pes2013.exe
FirewallRules: [{7AE125AE-51A1-49AB-8D30-0EC90E410EC7}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\Pesgalaxy.com Patch 2013\pes2013.exe
FirewallRules: [{DBBA6DE9-9593-4D21-AC2B-AA001DF6DE6F}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\pes2013.exe
FirewallRules: [{53EBF171-B2ED-4236-8462-CD4985D151B7}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\pes2013.exe
FirewallRules: [{CF8EBDF8-2147-4186-AC19-DB5F620935CC}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\Pesgalaxy.com Patch 2013\pes2013.exe
FirewallRules: [{EC84D4B5-2BDA-4C21-8981-F76E120EF62F}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\Pesgalaxy.com Patch 2013\pes2013.exe
FirewallRules: [{D925962D-FC57-429B-A000-482E648FB0F8}] => (Allow) I:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{724A9BCD-7B6A-46C7-AA37-0458EB6B52CF}] => (Allow) I:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{99905495-7B1E-4A75-AF05-55A63D82FD4B}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{7B456905-3203-44B8-8BD2-444A12450C89}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{7CB416A5-05FE-4A3E-B75C-B6409113D941}] => (Allow) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
FirewallRules: [{3C22040D-E846-4702-A26C-61390E0BE1A1}] => (Allow) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
FirewallRules: [{C5D49E73-F4DE-4AFB-9E11-1A7AFC9664D4}] => (Allow) C:\Users\Admin\AppData\Roaming\TorrentStream\engine\tsengine.exe
FirewallRules: [{0A8E48F2-035F-4B03-A9E3-42F995851267}] => (Allow) C:\Users\Admin\AppData\Roaming\TorrentStream\engine\tsengine.exe
FirewallRules: [{8B9EDA0D-15D2-4C54-A967-6514CD0AE0FF}] => (Allow) I:\Program Files\Logitech\Logitech Vid\Vid.exe
FirewallRules: [{F68ADFC3-0BCC-43E1-B299-97708A087050}] => (Allow) I:\Program Files\Logitech\Logitech Vid\Vid.exe
FirewallRules: [{B7DA221D-BBE0-45C0-8510-AC6ED56BD1D8}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{ADEA4D7E-67C4-41AF-B654-5CC08427F36B}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [TCP Query User{63EC74B4-EB18-4D2F-9AAF-8D7C44BD8D05}I:\program files (x86)\gembird\power manager\pm.exe] => (Allow) I:\program files (x86)\gembird\power manager\pm.exe
FirewallRules: [UDP Query User{E690A155-70F6-401D-9D82-5A331677DD59}I:\program files (x86)\gembird\power manager\pm.exe] => (Allow) I:\program files (x86)\gembird\power manager\pm.exe
FirewallRules: [TCP Query User{A402614A-8B59-4625-AD98-8961ABDE1A48}I:\program files (x86)\gembird\power manager\pm.exe] => (Allow) I:\program files (x86)\gembird\power manager\pm.exe
FirewallRules: [UDP Query User{E1E875BB-7831-43BB-B61B-18414486DE94}I:\program files (x86)\gembird\power manager\pm.exe] => (Allow) I:\program files (x86)\gembird\power manager\pm.exe
FirewallRules: [{7A4F5E0B-F7F6-413E-A12D-92A3EBA60213}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{44D41D10-29CC-4163-B2D9-0E3A06E90392}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{009A8772-ED14-4BD7-A60F-08E58C4C84BB}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{98117CFE-02E4-48BE-85E1-01C30A3DBE37}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{4A5727EB-16BD-4B3F-9D7A-93044872A2B0}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{6AE47FEE-E88E-4A59-9F42-2D31017B3378}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{1A11A178-C737-4B29-AB2B-9E48AE7FE104}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe
FirewallRules: [{671EAD44-A446-45D5-BBFA-663054284BA5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe
FirewallRules: [{DE4BA6E6-ADC4-4C8D-B3C2-C8AF7AD801E3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{C479E420-FD02-4CA6-AC75-DF80AF559421}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{A355DD9E-1308-489B-9C88-DEC05B478FFB}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{39F53DFE-6304-46CC-B2B8-1907E770DD92}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{D71831B4-90C7-4B1A-83AE-74F8BCC1F677}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{B4B0A17C-CA89-48D4-A332-36063BD4EA67}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{9FDE980F-979E-4989-A226-E1A50203EF64}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{A172864A-5B49-48BE-B3F0-F9316BB9968F}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{B56B05E3-22DD-4E46-B0AC-D8140356E25A}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{9C861C18-776C-416E-A65C-B27AF2BC4209}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{B87C9DD5-5FB0-495F-BA17-8717C92DF98E}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\Rogue Legacy\RogueLegacy.exe
FirewallRules: [{220A5D30-C98A-4FD8-B0E4-A51F13C9649D}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\Rogue Legacy\RogueLegacy.exe
FirewallRules: [{6A31F993-39B0-477D-95F5-57FB037FF7B2}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\FINAL FANTASY VIII\FF8_Launcher.exe
FirewallRules: [{11486E23-BCDA-47CA-9A48-D744951F54FC}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\FINAL FANTASY VIII\FF8_Launcher.exe
FirewallRules: [{3EEF7F57-68BB-4A18-9366-CE65958D55FD}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{0A3759DE-0340-44AB-BB75-D8891789E014}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [TCP Query User{6B7E7A41-8B0B-4E1C-94F4-6A2F4D56D43A}I:\program files (x86)\libreoffice 4\program\soffice.bin] => (Allow) I:\program files (x86)\libreoffice 4\program\soffice.bin
FirewallRules: [UDP Query User{5852FD27-A7C2-4B4E-B036-AFD2F263361B}I:\program files (x86)\libreoffice 4\program\soffice.bin] => (Allow) I:\program files (x86)\libreoffice 4\program\soffice.bin
FirewallRules: [TCP Query User{545628FC-9C6E-4D8C-90D6-F4B9EFF6C0B3}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{C680CB0D-FFD9-4CCA-93E5-081244976B4B}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{307D98F2-08D4-4950-BDCE-F2CCEB1650F4}I:\program files (x86)\sopcast\sopcast.exe] => (Allow) I:\program files (x86)\sopcast\sopcast.exe
FirewallRules: [UDP Query User{EA45DD32-5B84-4D74-9AF5-F50BF777EEA5}I:\program files (x86)\sopcast\sopcast.exe] => (Allow) I:\program files (x86)\sopcast\sopcast.exe
FirewallRules: [{1EDF1FB2-4890-4401-88E5-37D3DC463639}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe
FirewallRules: [{1BF7DA1B-A913-495E-8D98-3BE627EA07A0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe
FirewallRules: [{65D5665E-4A5F-488F-9588-8BBF2DF04991}] => (Allow) I:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{E9BB800C-4E34-44C4-BBDF-879F7C72D334}] => (Allow) I:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [TCP Query User{40774BCD-EBF3-4DBB-82FF-0661E7F415BC}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{C623C620-2E9B-48C0-8978-88D24940F63C}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [TCP Query User{6F617A60-D3CE-473A-B6DF-6D99BE718553}I:\program files (x86)\sopcast\sopcast.exe] => (Allow) I:\program files (x86)\sopcast\sopcast.exe
FirewallRules: [UDP Query User{34CFEEF9-08F7-447D-B03F-3B5FB10811E9}I:\program files (x86)\sopcast\sopcast.exe] => (Allow) I:\program files (x86)\sopcast\sopcast.exe
FirewallRules: [TCP Query User{24F2A94C-85DE-4FAD-A84F-97E53F1253CC}I:\spiele\pro evolution soccer 2014\pes2014.exe] => (Allow) I:\spiele\pro evolution soccer 2014\pes2014.exe
FirewallRules: [UDP Query User{BFA2FC11-613A-42C0-B65E-3C1A8C923DC6}I:\spiele\pro evolution soccer 2014\pes2014.exe] => (Allow) I:\spiele\pro evolution soccer 2014\pes2014.exe
FirewallRules: [{3EFE3C44-E51A-466C-96BE-EF6AFB82E693}] => (Allow) C:\Users\Admin\AppData\Roaming\ACEStream\engine\ace_engine.exe
FirewallRules: [{3A1609E6-DFE5-4351-A464-F32D3D0380F7}] => (Allow) C:\Users\Admin\AppData\Roaming\ACEStream\engine\ace_engine.exe
FirewallRules: [{6F7FDED0-235E-477D-B7E7-9E3A3CBE4D7D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{2FFCDB85-C562-4715-A56B-6EB4A6ACAB93}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{6221A8D9-C192-4605-B9DC-626D8D97B77C}] => (Allow) G:\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{F279A456-E9E0-430D-BDBB-BF17577BBE95}] => (Allow) G:\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{63EF3EFF-3EBA-49FF-B88C-9DEF3947813F}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{2AB36BAA-E192-4477-AA91-2D0D5AC6CB4B}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{D7762DF8-BFC1-402B-8B33-FA0F0154D8D7}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{E144CEBA-2EAE-44F7-B9AC-E84754133A70}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{FD6A79F4-6AAF-4A40-A1AD-0F9E26721706}] => (Allow) G:\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{0AC8CCAC-4208-438E-883E-97825AB5AC7D}] => (Allow) G:\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{3FF7376C-70FA-41F9-B0DE-86FEDC096268}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{C8CC5276-DABB-4B14-A206-B3E881439B48}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{74881FD2-5264-4BD4-92A6-C8CE47D701FD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [{31EA935D-9C24-433F-9617-62DE00A87C88}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [TCP Query User{98CF1771-0E6C-4F52-BF56-29AB4E5D2A92}I:\spiele\divinity original sin\shipping\eocapp.exe] => (Block) I:\spiele\divinity original sin\shipping\eocapp.exe
FirewallRules: [UDP Query User{47807778-B09B-4256-B568-86D4DD197A74}I:\spiele\divinity original sin\shipping\eocapp.exe] => (Block) I:\spiele\divinity original sin\shipping\eocapp.exe
FirewallRules: [{7E4FBE01-30EE-482F-92D8-438D4179DB1C}] => (Allow) I:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{67AA91B7-07CB-4545-946D-E4B72F9AD57D}] => (Allow) I:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{546527AB-0121-4826-A9B7-2C7ECD5CF209}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe
FirewallRules: [{A6EFCFEB-2C91-4FE6-B1C2-4582B05FC7E9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe
FirewallRules: [{0644E69B-2437-4DFD-A3A5-83F987C2C4B2}] => (Allow) I:\Program Files (x86)\Origin Games\FIFA World\fifaworld.exe
FirewallRules: [{B0E016FB-8173-449F-B4CE-EE19F5008545}] => (Allow) I:\Program Files (x86)\Origin Games\FIFA World\fifaworld.exe
FirewallRules: [{20B834F7-169E-4B2A-928D-427DA0C24727}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{DA16898C-69E6-4E29-B779-D1B8DE179DB0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{177E0E07-33DC-4066-B195-F3D169C66AFE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3286\Agent.exe
FirewallRules: [{05238314-5001-4210-AC93-76678CF4B46E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3286\Agent.exe
FirewallRules: [{6CFAA827-F9B0-49EE-9BC3-55B7906A3EFD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3346\Agent.exe
FirewallRules: [{5AD4F365-C0CB-43A9-B446-9E8613459E11}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3346\Agent.exe
FirewallRules: [{1BD42C09-FCC0-4478-8177-F566200EC1AB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [{BFD697F0-5884-45D5-97DA-6073C3C82AED}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [{AAB3A8FC-D53D-49ED-9531-9898F701143B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe
FirewallRules: [{55719414-C766-414B-A666-BEF2582BDE7B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe
FirewallRules: [{11C97E03-8523-4A87-8682-53D2DBED28AD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe
FirewallRules: [{60E525EF-38B7-4A32-9871-2224D7550405}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe
FirewallRules: [{CEF3BA47-48EB-44F9-AF94-5B320B8D7CD5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe
FirewallRules: [{DA7D1730-8FC9-4C91-8690-996034BB1C4D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe
FirewallRules: [{D214B8B2-13E0-4880-9205-DC5490BD2C41}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
FirewallRules: [{63D286EA-1EA1-446F-AD8C-11062C04E028}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
FirewallRules: [{067961E8-23AA-4AD7-9911-C8EB95D4FF4D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe
FirewallRules: [{85ED6F17-5E2F-4D3E-8E62-81D68D2DAFAE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe
FirewallRules: [{FE681703-1045-428D-9CFB-818BA8E07967}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{C76EC2B7-CA42-4C24-8FDF-E7D78D02753B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{88D4F973-FD87-4D3B-8067-DCB8BBD8A337}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{6E51B1CA-57A9-4765-8D59-C3BAAEA903DF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [TCP Query User{9BE1AE84-9D13-4C43-B424-7D6A9B7A9F3B}I:\spiele\pro evolution soccer 2015\pes2015.exe] => (Allow) I:\spiele\pro evolution soccer 2015\pes2015.exe
FirewallRules: [UDP Query User{D0AC4E49-CCF8-4CAC-B607-6DF7399BF3E8}I:\spiele\pro evolution soccer 2015\pes2015.exe] => (Allow) I:\spiele\pro evolution soccer 2015\pes2015.exe
FirewallRules: [{7122C35C-B6C6-4E6E-86A2-AACBDEF834EE}] => (Allow) G:\SteamLibrary\SteamApps\common\Pro Evolution Soccer 2015\PES2015.exe
FirewallRules: [{29462748-3F10-4424-9DEF-90AAB302C1D0}] => (Allow) G:\SteamLibrary\SteamApps\common\Pro Evolution Soccer 2015\PES2015.exe
FirewallRules: [{8E8957D1-C55C-4E31-B900-9B46379E6C3A}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
FirewallRules: [{0F26E076-AF8F-4402-865A-A397FBE47234}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
FirewallRules: [{A6460428-A9EE-4551-AAB1-9919A8CB9FE7}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgdiagex.exe
FirewallRules: [{A33E8FE9-D05D-4FFE-8822-FC73F3DC550A}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgdiagex.exe
FirewallRules: [{1AC7AE59-22CC-4C22-9325-1B9387438B71}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgemca.exe
FirewallRules: [{86AA2786-26BF-4AB7-A66B-6E5E665FACDF}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgemca.exe
FirewallRules: [TCP Query User{750FD61C-DEBE-412E-9723-59374283BC20}I:\spiele\sierra activision aspyr\geometry wars 3 dimensions\gw3.exe] => (Block) I:\spiele\sierra activision aspyr\geometry wars 3 dimensions\gw3.exe
FirewallRules: [UDP Query User{E1E8AA2F-D28F-46E6-912D-0012C96D29E0}I:\spiele\sierra activision aspyr\geometry wars 3 dimensions\gw3.exe] => (Block) I:\spiele\sierra activision aspyr\geometry wars 3 dimensions\gw3.exe
FirewallRules: [{B4D9749E-B708-4D9D-9DDC-A48E8A4459BD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{C55D1012-3D11-4966-B4BE-07B0171EF8DE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{D7891E90-3D5E-4E71-91E6-74F2470568D6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3632\Agent.exe
FirewallRules: [{19BAF5E7-C630-4E87-BFC9-E875AC3E101F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3632\Agent.exe
FirewallRules: [TCP Query User{934E83F4-23D0-44FF-87C7-0957C34C00B3}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{AFB751F7-169D-440A-BADA-70F25F4545B6}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{97D5122A-DE93-4E9D-94DE-560DDB0A915E}I:\program files\xampp\apache\bin\httpd.exe] => (Allow) I:\program files\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{17F86DA3-A1F5-4BAD-83C4-B630DA509607}I:\program files\xampp\apache\bin\httpd.exe] => (Allow) I:\program files\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{9268B190-BF64-4AF9-BA9F-73477A9597F5}I:\program files\xampp\mysql\bin\mysqld.exe] => (Allow) I:\program files\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{A68F1A97-6293-4687-8C2B-C6F7F0BAF8BF}I:\program files\xampp\mysql\bin\mysqld.exe] => (Allow) I:\program files\xampp\mysql\bin\mysqld.exe
FirewallRules: [{67B5231F-8ADB-4FF5-B36A-FFC60C1F237C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{26B8BF3D-7228-4D1C-83F2-DE5FF771D4BD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{5264E2C9-606F-4009-B7F1-5024B7B5CF2B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe
FirewallRules: [{AA931175-D489-4128-8800-0F69680CD7A3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe
FirewallRules: [{239C8B4D-9F39-41AD-B84F-B4B337CA2D72}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe
FirewallRules: [{5BE02404-C7E9-47D1-86EF-91C9E127B4B2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe
FirewallRules: [{C29A9D4D-8EFB-467C-833B-1BF942E44643}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
FirewallRules: [{66370EA6-F85A-4580-AC31-6AF8A17B72EB}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
FirewallRules: [{392FEB61-2B82-41AF-BCA8-8350B63A0D60}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
FirewallRules: [{93E85BE7-1F1B-4FE5-A119-3E828992E3FA}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
FirewallRules: [{6C8B2C10-6A54-4171-AA94-A2B884369D0C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe
FirewallRules: [{27CD20F3-07EF-400F-99B1-E284BFE05B17}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe
FirewallRules: [{4C385DC4-C490-457A-9FFF-885810C64C9A}] => (Allow) G:\SteamLibrary\SteamApps\common\Quake Live\quakelive_steam.exe
FirewallRules: [{598B1C43-5AC4-46CA-B4CB-0268F622174E}] => (Allow) G:\SteamLibrary\SteamApps\common\Quake Live\quakelive_steam.exe
FirewallRules: [TCP Query User{1559CE4F-EBBC-434F-93D4-CBBD3AC0B908}G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe] => (Allow) G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe
FirewallRules: [UDP Query User{6748B5FC-83AB-49E2-80E3-FF5B2C36DF55}G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe] => (Allow) G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe
FirewallRules: [{55F96811-D542-4AD3-A2FB-1AAE0741376E}] => (Block) G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe
FirewallRules: [{B4A5676B-82D8-4F67-A9F8-860D9696FE8D}] => (Block) G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe
FirewallRules: [{5AFFAF25-4C99-4203-8748-62E29395211C}] => (Allow) I:\Program Files\SiSoftware\SiSoftware Sandra Business 2012.SP1\WNt500x64\RpcSandraSrv.exe
FirewallRules: [{2E8C2002-15B2-4CB1-B0DC-5E9AE99BA086}] => (Allow) I:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe
FirewallRules: [{4D1C1F4D-154B-45CE-BB5F-973BADCEB950}] => (Allow) I:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe
FirewallRules: [{01FCB0B7-D5E9-4179-8020-3D547D91E3CA}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{2323FEB1-3673-4C70-93D5-06706DAF2530}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{A5330042-8A8A-4EFA-BF39-C18DBDFD4D23}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{7178C640-F4BA-45BC-BB03-33F9464587DA}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [TCP Query User{B5A2A9B5-8D58-44B8-9693-0C4D838BF8C2}G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe] => (Allow) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe
FirewallRules: [UDP Query User{BDB94D6A-5650-4EE1-AA64-6085D0B16BAE}G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe] => (Allow) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe
FirewallRules: [{5B635C6E-0C8C-4864-A333-0AB7C8939BDE}] => (Block) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe
FirewallRules: [{FB176797-B9BA-47EE-A426-E8E7CEB16A1A}] => (Block) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe
FirewallRules: [TCP Query User{76D0C968-5490-44BD-B6BE-733CF7C09504}G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe] => (Allow) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe
FirewallRules: [UDP Query User{9414CF60-207B-468E-963F-CB18B8E6BC85}G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe] => (Allow) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe
FirewallRules: [{62800BC7-647B-48D5-A81E-6D264B4FEA39}] => (Block) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe
FirewallRules: [{7B24E092-E864-4D79-8896-79718766A4B4}] => (Block) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe
FirewallRules: [{F92D3E68-0D80-46D4-904E-26645B2B4429}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{760E89FA-6A6E-4026-84AC-7679B006AB6F}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{F0122ABE-D7E4-4882-9DAF-81A5E8B6A7CC}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{2DD7FA52-91FD-4ECB-9953-37FDA3C44AF5}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{67B73862-FB62-474D-8136-1F60B3EE7D96}] => (Allow) G:\SteamLibrary\SteamApps\common\FINAL FANTASY VII\FF7_Launcher.exe
FirewallRules: [{325CD692-B642-48F3-9E67-0F5CA6CB3937}] => (Allow) G:\SteamLibrary\SteamApps\common\FINAL FANTASY VII\FF7_Launcher.exe
FirewallRules: [{6E481CEB-2803-4D24-A8E6-201907F17ED9}] => (Allow) G:\SteamLibrary\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{03F2D851-82F7-46F0-A413-27761EAECEE3}] => (Allow) G:\SteamLibrary\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{3589CD91-E258-4B2E-999B-1029301D2301}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{A30CEBE1-2227-4371-B476-4BC0F3C8BCB8}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{DFCC8903-182A-4040-852E-167AC8D41C97}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{70831CAB-C418-4D43-9700-1E0D8C7C3937}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{3732328F-8CC0-4FF7-AEDC-1EE1AB7C90F9}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{9625A327-9DF4-4CB7-9E9A-4948FCEACAED}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{775A1104-026F-47D2-9777-5F64944C47AE}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{0590F458-0DCD-44C3-BDC7-D138CEA53FA9}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{0DDC93C9-951B-4A06-9513-2C62E6756591}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{6F341878-9A59-40A0-B440-202514C4F814}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{224D9513-CAEC-4D16-9E7A-2A1B75DBFA9D}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{D97AE7D4-2DFA-442E-9404-78FB8B31D5A5}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{33E236AB-D19F-4470-8D62-1FE9651AE148}] => (Allow) C:\Users\Dori\AppData\Local\Mozilla Firefox\firefox.exe
FirewallRules: [{2D294BBE-ED04-4F16-A9E6-7DACDC47DC1D}] => (Allow) C:\Users\Dori\AppData\Local\Mozilla Firefox\firefox.exe
FirewallRules: [{B6030ED4-2A16-4689-B5D0-94B0FFEC7E2D}] => (Allow) C:\Users\Admin\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Shrew Soft Virtual Adapter
Description: Shrew Soft Virtual Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Shrew Soft
Service: vnet
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (07/31/2015 07:49:11 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/30/2015 02:55:28 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/30/2015 10:17:52 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/30/2015 10:01:15 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/30/2015 09:34:51 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/30/2015 09:20:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/29/2015 03:52:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/28/2015 04:02:00 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: AutoKMS.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.ComponentModel.Win32Exception
Stapel:
  bei System.Diagnostics.Process.StartWithCreateProcess(System.Diagnostics.ProcessStartInfo)
  bei System.Diagnostics.Process.Start(System.Diagnostics.ProcessStartInfo)
  bei ..(System.String, Boolean, Boolean)
  bei ..(., System.String, Boolean, System.String, Int32, System.String, System.String, Boolean, Boolean, Boolean, Boolean, Boolean, Boolean, System.String, System.String)
  bei ..(Boolean, System.String, Boolean, Int32, Boolean, Boolean, Boolean, Boolean, System.String, System.String, Boolean, System.String, ., System.String)
  bei ..(.)
  bei ..()

Error: (07/28/2015 04:01:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/28/2015 03:46:34 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\wbem\wmiprvse.exe; Beschreibung = ComboFix created restore point; Fehler = 0x8007043c).


Systemfehler:
=============
Error: (07/30/2015 10:08:48 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (07/30/2015 10:08:45 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Software Protection" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (07/30/2015 10:08:45 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Office Software Protection Platform" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (07/30/2015 10:08:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Cherry Device Interface" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (07/30/2015 10:08:44 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (07/30/2015 10:08:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "VMware USB Arbitration Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (07/30/2015 10:08:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "VMware DHCP Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (07/30/2015 10:08:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "VMware Authorization Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (07/30/2015 10:08:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Live ID Sign-in Assistant" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (07/30/2015 10:08:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "VMware NAT Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 1000 Millisekunden durchgeführt: Neustart des Diensts.


Microsoft Office:
=========================
Error: (07/31/2015 07:49:11 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/30/2015 02:55:28 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/30/2015 10:17:52 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/30/2015 10:01:15 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/30/2015 09:34:51 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/30/2015 09:20:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/29/2015 03:52:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/28/2015 04:02:00 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: AutoKMS.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.ComponentModel.Win32Exception
Stapel:
  bei System.Diagnostics.Process.StartWithCreateProcess(System.Diagnostics.ProcessStartInfo)
  bei System.Diagnostics.Process.Start(System.Diagnostics.ProcessStartInfo)
  bei ..(System.String, Boolean, Boolean)
  bei ..(., System.String, Boolean, System.String, Int32, System.String, System.String, Boolean, Boolean, Boolean, Boolean, Boolean, Boolean, System.String, System.String)
  bei ..(Boolean, System.String, Boolean, Int32, Boolean, Boolean, Boolean, Boolean, System.String, System.String, Boolean, System.String, ., System.String)
  bei ..(.)
  bei ..()

Error: (07/28/2015 04:01:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/28/2015 03:46:34 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Windows\system32\wbem\wmiprvse.exeComboFix created restore point0x8007043c


CodeIntegrity:
===================================
  Date: 2015-07-28 15:57:08.984
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-07-28 15:57:08.922
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-06-18 12:27:45.986
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 11:10:05.788
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-14 12:38:19.578
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-23 16:27:02.842
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-13 14:28:44.599
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-09 15:12:03.689
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-09 14:58:44.987
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-09 08:12:57.673
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Speicherinformationen ===========================

Processor: AMD FX(tm)-6100 Six-Core Processor
Percentage of memory in use: 49%
Total physical RAM: 8138.38 MB
Available physical RAM: 4116.63 MB
Total Virtual: 16274.96 MB
Available Virtual: 11744.44 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:119.24 GB) (Free:20.07 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)]
Drive g: (Volume) (Fixed) (Total:1863.01 GB) (Free:371.94 GB) NTFS
Drive i: (Software und Spiele) (Fixed) (Total:232.88 GB) (Free:29.4 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 08D508D5)
Partition 1: (Not Active) - (Size=232.9 GB) - (Type=42)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 7BE21FF1)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: FDA660FB)
Partition 1: (Active) - (Size=119.2 GB) - (Type=07 NTFS)

==================== Ende von log ============================


M-K-D-B 31.07.2015 21:48

Servus,



treten die Probleme nur in Chrome oder auch in Firefox und IE auf?

RVD85 01.08.2015 11:42

die treten nur im chrome auf. firefox nutze ich gerade alternativ und schaue nur nachdem ich deine anweisungen gemacht habe mal im chrome, ob sich etwas geändert hat. hat es aber nicht. hier auf der seite vom trojaner board kommt zb keine werbung, da öffnet sich nur manchmal ein neues tab mit werbung, wenn ich irgendwo hin klicke. auf bild, amazon und solchen seiten ist aber oben ne jollywallet werbeleiste, rechts ist eine für gutscheine bzw coupons, manchmal ist mitten drin noch eine werbebox. die sich öffnenden werbetabs, wenn ich irgendwas anklicke, sind wie gesagt überall, auf jeder seite, wie ein unsichtbarer layer

M-K-D-B 01.08.2015 15:43

Servus,



ok, dann deinstalliere Google Chrome über die Systemsteuerung und setze auch einen Haken bei Alle Browserdaten löschen.

Rechner neu starten.

Google Chrome neu installieren.

CHR:::
Setze Google Chrome nach dieser Anleitung zurück.


Dann nochmal FRST zur Kontrolle sowie Rückmeldung wie es jetzt läuft:
  • Starte die FRST.exe erneut. Setze einen Haken vor Addition.txt und drücke auf Untersuchen.
  • FRST erstellt wieder zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.

M-K-D-B 05.08.2015 22:35

Fehlende Rückmeldung
Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten.
PM an mich falls Du denoch weiter machen willst.

Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen!


Alle Zeitangaben in WEZ +1. Es ist jetzt 08:13 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132