|
Plagegeister aller Art und deren Bekämpfung: Windows 7 mit GVU 2.07Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
28.07.2012, 01:30 | #1 |
| Windows 7 mit GVU 2.07 Hallo, Mich hats auch erwischt : ich habe den bka trojaner : gvu 2.07 wie kann ich ihn entfernen und mit otl fixen ? Kann mir jamand den code schreiben es ist sehr dringent ich muss das laptop von meinen papa bis morgen fertig haben oder er käuft sich von meinem geld ein neuen ( morgen 28.07.2012 12:00 uhr ) OTL : OTL logfile created on: 28.07.2012 01:36:40 - Run 1 OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\touran\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Alemania | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 59,13% Memory free 7,99 Gb Paging File | 6,17 Gb Available in Paging File | 77,15% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 74,53 Gb Total Space | 0,63 Gb Free Space | 0,85% Space Free | Partition Type: NTFS Drive D: | 202,07 Gb Total Space | 194,99 Gb Free Space | 96,49% Space Free | Partition Type: NTFS Drive F: | 3,73 Gb Total Space | 3,73 Gb Free Space | 99,98% Space Free | Partition Type: FAT32 Computer Name: TOURAN-PC | User Name: touran | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.07.28 00:10:02 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\touran\Desktop\OTL.exe PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012.02.10 11:28:06 | 000,193,816 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe PRC - [2012.02.07 14:18:30 | 001,987,976 | ---- | M] (LogMeIn Inc.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011.12.27 12:19:25 | 001,693,112 | ---- | M] (MusicLab, LLC) -- C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\datamngrUI.exe PRC - [2011.12.14 13:59:20 | 002,984,832 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe PRC - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe PRC - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe PRC - [2011.07.17 14:56:29 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe PRC - [2011.04.21 07:52:51 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe PRC - [2011.04.21 07:52:36 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe PRC - [2011.03.14 17:31:03 | 000,025,472 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files (x86)\Uniblue\RegistryBooster\rbmonitor.exe PRC - [2010.12.18 14:02:28 | 003,054,136 | ---- | M] (ASUS) -- C:\Windows\AsScrPro.exe PRC - [2010.07.19 22:26:00 | 000,370,480 | ---- | M] (syncables, LLC) -- C:\Program Files (x86)\syncables\syncables desktop\syncables.exe PRC - [2010.07.19 22:26:00 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe PRC - [2010.07.02 23:36:26 | 001,597,440 | ---- | M] () -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe PRC - [2010.06.09 19:55:54 | 001,080,448 | ---- | M] (asus) -- C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe PRC - [2010.02.05 20:05:08 | 000,182,912 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe PRC - [2010.02.05 00:05:32 | 007,350,912 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe PRC - [2010.01.05 23:59:12 | 000,170,624 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe PRC - [2009.11.03 00:21:26 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe PRC - [2009.09.23 11:11:54 | 001,160,320 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe PRC - [2009.09.17 13:55:06 | 000,663,552 | ---- | M] (Nokia) -- C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe PRC - [2009.07.31 20:38:24 | 000,305,720 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe PRC - [2009.07.07 17:29:58 | 000,282,624 | ---- | M] (BlazeVideo Company) -- C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe PRC - [2009.06.19 20:29:42 | 000,105,016 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe PRC - [2009.06.19 20:29:26 | 002,488,888 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe PRC - [2009.06.16 03:30:42 | 000,084,536 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe PRC - [2008.12.23 03:15:34 | 000,174,648 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe PRC - [2008.09.23 08:20:16 | 000,575,488 | ---- | M] (Nokia.) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe PRC - [2007.11.30 21:20:44 | 000,051,768 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe PRC - [2007.08.03 13:24:54 | 000,125,496 | ---- | M] () -- C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe ========== Modules (No Company Name) ========== MOD - [2012.07.26 11:24:11 | 000,222,120 | ---- | M] () -- C:\Users\touran\AppData\Local\Temp\rty0_7z.exe MOD - [2012.06.13 14:36:18 | 014,340,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll MOD - [2012.06.13 14:35:50 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll MOD - [2012.05.11 15:38:43 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll MOD - [2012.05.11 15:38:31 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll MOD - [2012.05.11 15:38:25 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll MOD - [2010.07.02 23:36:26 | 001,597,440 | ---- | M] () -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe MOD - [2009.11.03 00:23:36 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll MOD - [2009.09.15 11:47:10 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\ASUS\Net4Switch\ResItf.dll MOD - [2009.09.14 18:07:16 | 000,024,576 | ---- | M] () -- C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\RemoteControl\abilisRC.dll MOD - [2009.09.11 17:40:20 | 000,084,992 | ---- | M] () -- C:\Program Files (x86)\ASUS\Net4Switch\cxcmrt.dll MOD - [2009.04.16 17:31:14 | 004,210,688 | ---- | M] () -- C:\Program Files (x86)\Nokia\PC Internet Access\GraphicsResources.ngr MOD - [2008.12.30 13:40:30 | 000,073,728 | ---- | M] () -- C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\VersionInfo.dll MOD - [2008.12.30 13:40:26 | 000,106,496 | ---- | M] () -- C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\mlutil.dll MOD - [2008.12.30 13:40:26 | 000,032,768 | ---- | M] () -- C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MMKeyboardHook.dll MOD - [2008.11.12 11:17:54 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\Nokia\PC Internet Access\TextResources_ger.nlr MOD - [2007.11.30 21:20:44 | 000,051,768 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe ========== Win32 Services (SafeList) ========== SRV:64bit: - [2011.12.13 10:29:20 | 000,036,160 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp) SRV:64bit: - [2010.10.09 11:00:14 | 000,859,712 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe -- (SfCtlCom) SRV:64bit: - [2010.09.23 04:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:64bit: - [2010.03.30 16:12:23 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2009.12.08 02:16:34 | 000,379,520 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Windows\SysNative\FBAgent.exe -- (AFBAgent) SRV:64bit: - [2009.09.29 18:32:32 | 000,570,632 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe -- (TMBMServer) SRV:64bit: - [2009.09.29 18:32:30 | 000,917,768 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe -- (TmProxy) SRV:64bit: - [2009.09.29 18:32:06 | 000,595,960 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe -- (TmPfw) SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV:64bit: - [2007.08.03 13:24:54 | 000,125,496 | ---- | M] () [On_Demand | Running] -- C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe -- (spmgr) SRV - [2012.07.14 02:13:54 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012.02.10 11:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe -- (BBUpdate) SRV - [2012.02.10 11:28:06 | 000,193,816 | ---- | M] (Microsoft Corporation.) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe -- (BBSvc) SRV - [2012.02.07 14:18:30 | 002,343,816 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011.12.14 13:59:20 | 002,984,832 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7) SRV - [2011.12.13 10:34:52 | 002,028,864 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc) SRV - [2011.12.13 10:29:16 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp) SRV - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa) SRV - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist) SRV - [2011.07.17 14:56:29 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.04.21 07:52:51 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009.12.15 20:39:38 | 000,096,896 | ---- | M] (ASUS) [Auto | Stopped] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv) SRV - [2009.06.16 03:30:42 | 000,084,536 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe -- (ASLDRService) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008.09.23 08:20:16 | 000,575,488 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) ========== Driver Services (SafeList) ========== DRV:64bit: - [2012.07.27 23:52:10 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2012.02.18 11:46:09 | 000,082,816 | ---- | M] (VSO Software) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\pcouffin.sys -- (pcouffin) DRV:64bit: - [2011.10.01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol) DRV:64bit: - [2011.10.01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay) DRV:64bit: - [2011.10.01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir) DRV:64bit: - [2011.10.01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs) DRV:64bit: - [2011.08.17 09:58:26 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt) DRV:64bit: - [2011.08.17 09:58:22 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev) DRV:64bit: - [2011.08.17 09:58:20 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc) DRV:64bit: - [2011.08.17 09:58:16 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd) DRV:64bit: - [2011.07.17 14:56:29 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb) DRV:64bit: - [2011.07.17 14:56:29 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt) DRV:64bit: - [2011.07.12 12:56:50 | 000,342,288 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\tmxpflt.sys -- (tmxpflt) DRV:64bit: - [2011.07.12 12:56:36 | 000,042,768 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\tmpreflt.sys -- (tmpreflt) DRV:64bit: - [2011.07.12 12:47:06 | 002,077,456 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vsapint.sys -- (vsapint) DRV:64bit: - [2011.02.28 17:38:07 | 000,507,392 | ---- | M] (ITETech ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AF15BDA.sys -- (AF15BDA) DRV:64bit: - [2011.02.16 22:36:37 | 000,046,112 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tbhsd.sys -- (tbhsd) DRV:64bit: - [2011.02.16 22:36:37 | 000,045,160 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rsvcdwdr.sys -- (rsvcdwdr) DRV:64bit: - [2010.12.17 00:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO) DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010.11.20 12:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser) DRV:64bit: - [2010.09.23 10:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr) DRV:64bit: - [2010.07.21 07:33:49 | 000,129,024 | ---- | M] (ELAN Microelectronic Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD) DRV:64bit: - [2010.04.08 10:11:59 | 000,124,944 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV:64bit: - [2010.03.30 16:46:01 | 006,657,536 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2010.03.30 15:23:33 | 000,195,584 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2010.03.04 11:53:01 | 000,075,816 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) DRV:64bit: - [2010.02.09 12:19:13 | 001,586,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:64bit: - [2009.12.28 08:16:45 | 000,044,032 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor) DRV:64bit: - [2009.12.22 12:26:36 | 000,038,456 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter) DRV:64bit: - [2009.12.07 19:53:26 | 000,117,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard) DRV:64bit: - [2009.10.07 09:13:33 | 000,070,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2009.10.07 09:13:33 | 000,028,728 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2009.09.29 18:33:18 | 000,339,984 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tmwfp.sys -- (tmwfp) DRV:64bit: - [2009.09.29 18:33:18 | 000,201,232 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tmlwf.sys -- (tmlwf) DRV:64bit: - [2009.09.29 18:33:18 | 000,107,536 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tmtdi.sys -- (tmtdi) DRV:64bit: - [2009.08.20 04:41:37 | 001,800,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\snp2uvc.sys -- (SNP2UVC) DRV:64bit: - [2009.07.20 11:29:39 | 000,015,416 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr) DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.06.10 22:35:57 | 000,056,832 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SiSG664.sys -- (SiSGbeLH) DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009.05.13 19:07:20 | 000,015,928 | ---- | M] (ASUS) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ATK64AMD.sys -- (MTsensor) DRV:64bit: - [2009.05.05 04:00:27 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) DRV:64bit: - [2009.03.18 18:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi) DRV:64bit: - [2008.08.28 12:44:42 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd) DRV:64bit: - [2008.05.24 03:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr) DRV:64bit: - [2007.08.03 06:26:47 | 000,017,464 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys -- (ghaio) DRV - [2010.11.29 19:27:40 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv) DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) DRV - [2005.09.20 18:27:20 | 000,010,368 | ---- | M] (InterVideo, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\iviaspi.sys -- (Iviaspi) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://downloads.phpnuke.org/de/index.php?rvs=hompag IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://downloads.phpnuke.org/de/index.php?rvs=hompag IE - HKLM\..\URLSearchHook: {48405d3d-2674-4cd8-b1ef-9a719443bd3f} - SOFTWARE\Classes\CLSID\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}\InprocServer32 File not found IE - HKLM\..\URLSearchHook: {8c925777-22df-4587-86f7-7ddd6d2ad1eb} - C:\Program Files (x86)\radio_de\prxtbradi.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {937f343c-c9c2-4235-b544-7fc4da2f2594} - C:\Program Files (x86)\Suche_Deutschland\tbSuc1.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {c9508125-4747-4733-b048-e4b82dc9716d} - C:\Program Files (x86)\PHPNukeDE\prxtbPHP0.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {fe0383f0-af43-4832-a481-0555470194d1} - SOFTWARE\Classes\CLSID\{fe0383f0-af43-4832-a481-0555470194d1}\InprocServer32 File not found IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox IE - HKLM\..\SearchScopes\{5BFE8C19-77F1-4E08-9CB2-B03C51A8E9A7}: "URL" = hxxp://downloads.phpnuke.org/de/index.php?rvs=hompag IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{8C212CF2-7194-4FD3-87FF-75A3C0737546}: "URL" = hxxp://downloads.phpnuke.org/de/index.php?rvs=hompag IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2303923 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://downloads.phpnuke.org/de/index.php?rvs=hompag IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\InprocServer32 File not found IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\URLSearchHook: {48405d3d-2674-4cd8-b1ef-9a719443bd3f} - SOFTWARE\Classes\CLSID\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}\InprocServer32 File not found IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\URLSearchHook: {937f343c-c9c2-4235-b544-7fc4da2f2594} - C:\Program Files (x86)\Suche_Deutschland\tbSuc1.dll (Conduit Ltd.) IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\URLSearchHook: {c9508125-4747-4733-b048-e4b82dc9716d} - C:\Program Files (x86)\PHPNukeDE\prxtbPHP0.dll (Conduit Ltd.) IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\URLSearchHook: {fe0383f0-af43-4832-a481-0555470194d1} - SOFTWARE\Classes\CLSID\{fe0383f0-af43-4832-a481-0555470194d1}\InprocServer32 File not found IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=LMW2&o=16050&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=OF&apn_dtid=VIN009YYDE&apn_uid=78EA5E28-326D-4606-B1CF-F13024F64027&apn_sauid=8AE93DAC-ED95-4E26-B104-706D53EEDA8B IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{5BFE8C19-77F1-4E08-9CB2-B03C51A8E9A7}: "URL" = hxxp://downloads.phpnuke.org/de/index.php?rvs=hompag IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{8C212CF2-7194-4FD3-87FF-75A3C0737546}: "URL" = hxxp://downloads.phpnuke.org/de/index.php?rvs=hompag IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms} IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{C5CB8DCA-1352-4C5C-8F47-3C21D7CCE375}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1147646 IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://search.bearshare.com" FF - prefs.js..keyword.URL: "hxxp://dts.search-results.com/sr?src=ffb&appid=20&systemid=2&sr=0&q=" FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll File not found FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\msntoolbar@msn.com: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.27 18:47:24 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.04.30 06:46:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\touran\AppData\Roaming\mozilla\Extensions [2011.04.30 06:46:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\touran\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org [2012.07.27 18:47:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2012.07.14 02:15:45 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012.07.14 02:45:08 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.07.14 02:45:08 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012.07.14 02:45:08 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012.07.14 02:45:08 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012.07.14 02:45:08 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012.07.14 02:45:07 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - homepage: hxxp://search.bearshare.com O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll File not found O2:64bit: - BHO: (DataMngr) - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\x64\BROWSE~1.DLL (MusicLab, LLC) O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll File not found O2 - BHO: (Discover USA Toolbar) - {48405d3d-2674-4cd8-b1ef-9a719443bd3f} - C:\Program Files (x86)\Search_USA\prxtbSea0.dll File not found O2 - BHO: (radio de Toolbar) - {8c925777-22df-4587-86f7-7ddd6d2ad1eb} - C:\Program Files (x86)\radio_de\prxtbradi.dll (Conduit Ltd.) O2 - BHO: (Suche Deutschland Toolbar) - {937f343c-c9c2-4235-b544-7fc4da2f2594} - C:\Program Files (x86)\Suche_Deutschland\tbSuc1.dll (Conduit Ltd.) O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll File not found O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll File not found O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (DataMngr) - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\BROWSE~1.DLL (MusicLab, LLC) O2 - BHO: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll () O2 - BHO: (PHPNukeDE Toolbar) - {c9508125-4747-4733-b048-e4b82dc9716d} - C:\Program Files (x86)\PHPNukeDE\prxtbPHP0.dll (Conduit Ltd.) O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll File not found O2 - BHO: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found O2 - BHO: (DEUTSCHLAND version Toolbar) - {fe0383f0-af43-4832-a481-0555470194d1} - C:\Program Files (x86)\DEUTSCHLAND_version\prxtbDEUT.dll File not found O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll File not found O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (Deutschland Radio Toolbar) - {2069a8c8-fad1-424b-b76c-d7f33d77dc4c} - C:\Program Files (x86)\Deutschland_Radio\tbDeut.dll File not found O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll File not found O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll File not found O3 - HKLM\..\Toolbar: (Discover USA Toolbar) - {48405d3d-2674-4cd8-b1ef-9a719443bd3f} - C:\Program Files (x86)\Search_USA\prxtbSea0.dll File not found O3 - HKLM\..\Toolbar: (radio de Toolbar) - {8c925777-22df-4587-86f7-7ddd6d2ad1eb} - C:\Program Files (x86)\radio_de\prxtbradi.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll File not found O3 - HKLM\..\Toolbar: (Suche Deutschland Toolbar) - {937f343c-c9c2-4235-b544-7fc4da2f2594} - C:\Program Files (x86)\Suche_Deutschland\tbSuc1.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll () O3 - HKLM\..\Toolbar: (PHPNukeDE Toolbar) - {c9508125-4747-4733-b048-e4b82dc9716d} - C:\Program Files (x86)\PHPNukeDE\prxtbPHP0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found O3 - HKLM\..\Toolbar: (DEUTSCHLAND version Toolbar) - {fe0383f0-af43-4832-a481-0555470194d1} - C:\Program Files (x86)\DEUTSCHLAND_version\prxtbDEUT.dll File not found O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Deutschland Radio Toolbar) - {2069A8C8-FAD1-424B-B76C-D7F33D77DC4C} - C:\Program Files (x86)\Deutschland_Radio\tbDeut.dll File not found O3:64bit: - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll File not found O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll File not found O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll File not found O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Discover USA Toolbar) - {48405D3D-2674-4CD8-B1EF-9A719443BD3F} - C:\Program Files (x86)\Search_USA\prxtbSea0.dll File not found O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (radio de Toolbar) - {8C925777-22DF-4587-86F7-7DDD6D2AD1EB} - C:\Program Files (x86)\radio_de\prxtbradi.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Suche Deutschland Toolbar) - {937F343C-C9C2-4235-B544-7FC4DA2F2594} - C:\Program Files (x86)\Suche_Deutschland\tbSuc1.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (PHPNukeDE Toolbar) - {C9508125-4747-4733-B048-E4B82DC9716D} - C:\Program Files (x86)\PHPNukeDE\prxtbPHP0.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (DEUTSCHLAND version Toolbar) - {FE0383F0-AF43-4832-A481-0555470194D1} - C:\Program Files (x86)\DEUTSCHLAND_version\prxtbDEUT.dll File not found O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.) O4:64bit: - HKLM..\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe () O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.) O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.) O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [DATAMNGR] C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\DATAMN~1.EXE (MusicLab, LLC) O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" File not found O4 - HKLM..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" File not found O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe () O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001..\Run: [BlazeServoTool] C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe (BlazeVideo Company) O4 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler File not found O4 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001..\Run: [NokiaPCInternetAccess] C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe (Nokia) O4 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001..\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe (syncables, LLC) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 16 O7 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll File not found O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll File not found O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll File not found O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll File not found O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll File not found O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\x64\datamngr.dll) - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\x64\datamngr.dll (MusicLab, LLC) O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\x64\IEBHO.dll) - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\x64\IEBHO.dll (MusicLab, LLC) O20 - AppInit_DLLs: (C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\datamngr.dll) - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\datamngr.dll (MusicLab, LLC) O20 - AppInit_DLLs: (C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\IEBHO.dll) - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\IEBHO.dll (MusicLab, LLC) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - Unable to obtain root file information for disk F:\ O33 - MountPoints2\{1cc67dec-cb1c-11e0-be56-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{1cc67dec-cb1c-11e0-be56-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{1cc67def-cb1c-11e0-be56-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{1cc67def-cb1c-11e0-be56-485b399c40dd}\Shell\AutoRun\command - "" = H:\AutoRun.exe O33 - MountPoints2\{1d2f2070-008a-11e1-be20-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{1d2f2070-008a-11e1-be20-485b399c40dd}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{40cc190d-06cf-11e1-a637-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{40cc190d-06cf-11e1-a637-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{5323a049-f8ba-11e0-b448-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{5323a049-f8ba-11e0-b448-485b399c40dd}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{5323a04c-f8ba-11e0-b448-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{5323a04c-f8ba-11e0-b448-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{5d69f865-c822-11e0-aae2-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{5d69f865-c822-11e0-aae2-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{5d69f869-c822-11e0-aae2-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{5d69f869-c822-11e0-aae2-485b399c40dd}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{5d69f87d-c822-11e0-aae2-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{5d69f87d-c822-11e0-aae2-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{625c6797-c179-11e1-8e7a-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{625c6797-c179-11e1-8e7a-485b399c40dd}\Shell\AutoRun\command - "" = F:\NokiaPCIA_Autorun.exe O33 - MountPoints2\{99e55ee7-cf31-11e0-b80f-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{99e55ee7-cf31-11e0-b80f-485b399c40dd}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{99e55eea-cf31-11e0-b80f-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{99e55eea-cf31-11e0-b80f-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{a5e28d84-e881-11e0-89b8-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{a5e28d84-e881-11e0-89b8-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{a5e28d87-e881-11e0-89b8-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{a5e28d87-e881-11e0-89b8-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{a5e28db3-e881-11e0-89b8-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{a5e28db3-e881-11e0-89b8-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{a5e28db5-e881-11e0-89b8-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{a5e28db5-e881-11e0-89b8-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{c757008c-4530-11e1-9f53-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{c757008c-4530-11e1-9f53-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{d6cc960f-8a42-11e1-b533-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{d6cc960f-8a42-11e1-b533-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{d6cc9611-8a42-11e1-b533-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{d6cc9611-8a42-11e1-b533-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\F\Shell - "" = AutoRun O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.07.28 01:35:35 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Users\touran\Desktop\OTL.exe [2012.07.27 23:53:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite [2012.07.27 23:52:10 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys [2012.07.27 23:52:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite [2012.07.27 19:50:55 | 000,000,000 | ---D | C] -- C:\Users\touran\AppData\Roaming\Malwarebytes [2012.07.27 19:50:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.07.27 19:50:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.07.27 19:50:46 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012.07.27 19:50:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2012.07.27 18:48:20 | 000,000,000 | ---D | C] -- C:\Users\touran\AppData\Local\Mozilla [2012.07.27 18:47:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service [2012.07.27 18:47:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2012.07.27 18:47:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2012.07.24 11:36:06 | 000,000,000 | ---D | C] -- C:\ProgramData\61C3 [2012.07.11 12:30:28 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2012.07.11 12:30:28 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2012.07.11 12:30:28 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2012.07.11 12:30:28 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2012.07.11 12:30:27 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2012.07.11 12:30:27 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2012.07.11 12:30:26 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2012.07.11 12:30:26 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2012.07.11 12:30:25 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2012.07.11 12:30:25 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2012.07.11 12:30:24 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2012.07.11 12:30:24 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2012.07.11 12:30:24 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2012.07.11 12:10:40 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll [2012.07.11 12:10:40 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll [2012.07.11 12:10:29 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll [2012.07.11 12:10:25 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdosys.dll [2012.07.11 12:10:24 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdosys.dll [2012.06.29 05:11:37 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Suite [2012.06.29 05:11:08 | 000,000,000 | ---D | C] -- C:\Users\touran\AppData\Roaming\PC Suite [2012.06.29 05:11:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia PC-Internetzugang [2012.06.29 05:11:01 | 000,025,600 | ---- | C] (Nokia) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys [2012.06.29 05:10:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Connectivity Solution [2012.06.29 03:52:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Installations [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.07.28 01:42:42 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.07.28 01:42:42 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.07.28 01:40:17 | 000,740,224 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2012.07.28 01:40:17 | 000,650,416 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012.07.28 01:40:17 | 000,157,866 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2012.07.28 01:40:17 | 000,131,918 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012.07.28 01:40:17 | 000,005,438 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012.07.28 01:33:29 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job [2012.07.28 01:33:27 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.07.28 01:33:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.07.28 01:32:59 | 3219,513,344 | -HS- | M] () -- C:\hiberfil.sys [2012.07.28 00:30:00 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.07.28 00:10:02 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\touran\Desktop\OTL.exe [2012.07.27 23:53:52 | 000,001,952 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk [2012.07.27 23:52:10 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys [2012.07.27 20:31:43 | 004,503,728 | ---- | M] () -- C:\ProgramData\z7_0ytr.pad [2012.07.27 20:01:56 | 000,002,322 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini [2012.07.27 20:01:46 | 000,001,311 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini [2012.07.27 19:53:25 | 000,013,277 | ---- | M] () -- C:\Users\touran\Desktop\Ausgeführte Prozesse mit dem Task-Manager anzeigen - Verknüpfung.lnk [2012.07.27 19:50:49 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.07.27 18:47:29 | 000,001,132 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2012.07.26 11:24:12 | 000,001,883 | ---- | M] () -- C:\Users\touran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk [2012.07.16 15:00:49 | 000,004,608 | ---- | M] () -- C:\6XSourceFilter.grf [2012.07.11 14:34:38 | 000,275,208 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012.07.01 12:48:45 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ccdcmbx64_01009.Wdf [2012.06.29 05:11:07 | 000,002,106 | ---- | M] () -- C:\Users\Public\Desktop\Nokia PC-Internetzugang.lnk [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.07.27 23:53:52 | 000,001,952 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk [2012.07.27 19:53:25 | 000,013,277 | ---- | C] () -- C:\Users\touran\Desktop\Ausgeführte Prozesse mit dem Task-Manager anzeigen - Verknüpfung.lnk [2012.07.27 19:50:49 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.07.27 18:47:28 | 000,001,144 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2012.07.27 18:47:28 | 000,001,132 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2012.07.26 11:24:12 | 004,503,728 | ---- | C] () -- C:\ProgramData\z7_0ytr.pad [2012.07.26 11:24:12 | 000,001,883 | ---- | C] () -- C:\Users\touran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk [2012.07.01 12:48:45 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ccdcmbx64_01009.Wdf [2012.06.29 05:11:07 | 000,002,106 | ---- | C] () -- C:\Users\Public\Desktop\Nokia PC-Internetzugang.lnk [2012.03.04 15:59:46 | 000,005,120 | ---- | C] () -- C:\Users\touran\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.02.18 11:41:54 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib [2012.02.12 14:02:49 | 000,000,261 | ---- | C] () -- C:\Windows\Clony2.ini [2011.02.28 17:41:39 | 000,000,014 | ---- | C] () -- C:\Windows\SysWow64\systeminfo.dll [2011.02.19 11:01:03 | 001,558,876 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011.02.12 10:49:09 | 000,000,024 | ---- | C] () -- C:\Windows\ATKPF.ini [2010.12.18 13:56:30 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2010.12.18 13:53:26 | 000,001,035 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2010.12.18 13:47:41 | 000,131,472 | ---- | C] () -- C:\ProgramData\FullRemove.exe ========== LOP Check ========== [2011.02.12 00:36:23 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\Asus WebStorage [2012.02.21 23:24:07 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\Canneverbe Limited [2012.02.21 23:19:44 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\DAEMON Tools Lite [2011.03.26 13:51:22 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\EeeStorageUploader [2011.09.23 21:36:01 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\LimeWire [2011.04.09 14:42:49 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\map&guide [2012.02.24 20:15:47 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\minecraft [2012.02.21 23:18:03 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\OpenCandy [2011.12.14 13:01:46 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\Orsiy [2012.06.29 05:11:08 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\PC Suite [2011.12.14 00:26:52 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\Qygo [2011.05.18 08:26:00 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\Reviversoft [2012.03.11 14:41:08 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\saves [2012.03.11 14:41:08 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\screenshots [2011.11.20 22:02:54 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\SoftGrid Client [2012.03.11 14:41:09 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\stats [2012.01.03 20:24:14 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\TeamViewer [2012.03.11 14:41:09 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\Texturepacks [2011.02.19 11:02:10 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\TP [2011.04.09 09:06:00 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\TuneUp Software [2011.04.09 09:01:00 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\Uniblue [2012.02.18 11:47:06 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\Vso [2012.03.11 14:31:31 | 000,000,000 | ---D | M] -- C:\Users\touran\AppData\Roaming\xrecode2 [2012.07.28 01:33:29 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\RegistryBooster.job [2012.06.28 20:32:34 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:981884E7 @Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:3E7393FC < End of report > Extra: OTL Extras logfile created on: 28.07.2012 01:36:40 - Run 1 OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\touran\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Alemania | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 59,13% Memory free 7,99 Gb Paging File | 6,17 Gb Available in Paging File | 77,15% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 74,53 Gb Total Space | 0,63 Gb Free Space | 0,85% Space Free | Partition Type: NTFS Drive D: | 202,07 Gb Total Space | 194,99 Gb Free Space | 96,49% Space Free | Partition Type: NTFS Drive F: | 3,73 Gb Total Space | 3,73 Gb Free Space | 99,98% Space Free | Partition Type: FAT32 Computer Name: TOURAN-PC | User Name: touran | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1157160496-1306487556-184762800-1001\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "AutoUpdateDisableNotify" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04A2499D-A6A5-492C-A764-E85E971B5F79}" = lport=138 | protocol=17 | dir=in | app=system | "{0E2DE8CD-7144-4BC6-9B9B-029D47626F1F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{129857D6-086A-4413-BCE2-E605EB51D321}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{134BFD74-8404-4342-A724-AF28A6D30E2F}" = lport=5353 | protocol=17 | dir=in | name=java(tm) platform se binary | "{1C09D110-2B18-417C-8BDF-DA3DC0D8ABA0}" = rport=137 | protocol=17 | dir=out | app=system | "{2A675D97-DB15-47B9-BBFE-8B84BD1D5670}" = rport=10243 | protocol=6 | dir=out | app=system | "{35B66ED1-5F6C-4CB2-A817-A6EA9953BCB5}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{3E61D34B-FD68-480F-8B04-C61E5792B24A}" = lport=8182 | protocol=6 | dir=in | name=java(tm) platform se binary | "{4F51AED6-B8F0-4DD1-A37E-A9DEFDAC5A83}" = lport=10243 | protocol=6 | dir=in | app=system | "{51A1E7D0-CE1F-4CB6-856A-8FF8448FC34B}" = lport=2869 | protocol=6 | dir=in | app=system | "{56E8575D-C35B-4205-B8D2-DFD81C3EE9AE}" = lport=445 | protocol=6 | dir=in | app=system | "{5ACB27C0-B503-41DA-A498-5B1D2AF31D4C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{70339C2C-06C4-462B-A6E3-332AB7AE86F8}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{767D1D2D-04E5-413A-A2A0-AD059671B53B}" = rport=445 | protocol=6 | dir=out | app=system | "{861DB5C5-0A9A-44B2-AD03-363CBE01678D}" = lport=5353 | protocol=17 | dir=in | name=java(tm) platform se binary | "{8BB07C53-F2A0-45D7-9DC2-F7E96DE99D77}" = rport=139 | protocol=6 | dir=out | app=system | "{92D97D74-8714-48F5-8D00-312D6040CC1F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{AC44DB55-7F97-48BE-B2EB-C978646455BA}" = lport=137 | protocol=17 | dir=in | app=system | "{AC954B18-4FB0-4F5A-AF91-618898402D4A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{B615F8E2-5594-4530-9993-59853AF40411}" = lport=8182 | protocol=6 | dir=in | name=java(tm) platform se binary | "{BB2F7DF0-0F00-41E6-BCBC-B29FBA69629F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{BD11C042-FBE0-48FD-A309-90327826BE53}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CA75124B-E355-4944-9A31-1A830801DD09}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{CC50A9F0-9788-4351-AA40-5C7DEBC3F8D7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D445C768-5CC9-497D-97A7-861BBE7D76E1}" = lport=139 | protocol=6 | dir=in | app=system | "{EE0163BE-3336-4FD8-B694-D8F11B0E4249}" = rport=138 | protocol=17 | dir=out | app=system | "{F48945EC-85A9-442F-96DA-B05C8AA0441D}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{F49AD1A1-94E8-4FBD-BFA3-F793411EA5D6}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FF27864A-3259-4002-A126-CCD043584434}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{017E4134-0F62-4B6D-B202-4296B81A9FA2}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "{02488468-05BA-4C6C-812C-B763399D56DB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{0334C64A-54DA-4090-82BB-7FF2D7025E13}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{0B84F1AC-5991-424E-80AE-2B40B2115414}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "{130954E0-5928-40D2-A6BD-B2781C05E70F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{1B54F57A-B379-4780-BB69-4D165C4E9B84}" = protocol=6 | dir=out | app=system | "{29596667-F393-4130-816D-3B5DBDEBA335}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{32232947-B202-4ABE-BCE8-140B224E8CD9}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{358359BE-FD57-46D9-AF6D-B25117D35A3F}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer.exe | "{35C972DC-E35D-46EF-8884-FAF6A26E0310}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{39567BB9-5BE1-42E9-AE27-0A43382909A9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{3E4A40DC-A34C-48D7-B07D-C5D8739833A6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{4078D3A0-1C8C-406F-A2DB-BC349BD1F14F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{412B395E-BEE2-4E51-9363-32D8F8BA3ACE}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{443E35FB-065E-4CA9-A481-4535143ABFC1}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{447A79DB-A97D-4684-B087-93B96A99845E}" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe | "{45DCD0B6-C0BF-44AD-97B7-5F21EC6D14B0}" = protocol=17 | dir=in | app=c:\program files (x86)\bearshare applications\bearshare\bearshare.exe | "{5F844A55-E1AC-4300-856A-FE63BFABFD71}" = protocol=6 | dir=in | app=c:\program files (x86)\bearshare applications\bearshare\bearshare.exe | "{6867D680-48FC-40CE-951F-3294033F558D}" = protocol=6 | dir=in | app=c:\program files (x86)\syncables\syncables desktop\jre\bin\javaw.exe | "{6D2C0416-FE13-4D02-8A5F-AF52C46A27B9}" = protocol=17 | dir=in | app=c:\program files (x86)\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe | "{6F658294-F537-4840-819F-CD35761D684B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{72F8C50C-9C7F-4BA7-A40E-50242477402E}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer_service.exe | "{75536F48-AD23-49DB-BAF6-CFFE342B0E39}" = protocol=6 | dir=in | app=c:\program files (x86)\bearshare applications\bearshare\bearshare.exe | "{7DF99EDD-D0A0-4978-B7F3-A9C0F02D6D4E}" = protocol=17 | dir=in | app=c:\program files (x86)\syncables\syncables desktop\jre\bin\javaw.exe | "{888434AE-7974-499D-96D2-BBCDB236DF00}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{8A4CEBEF-B76A-432B-8A40-7D3147359323}" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe | "{8B48ED56-6A3D-4C51-A269-54B0C3CDA1F8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{918D1CB5-7630-4B68-B97B-A51A112DA7FD}" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe | "{995DEB47-7E6D-4273-B43A-3AF19B7DAC31}" = protocol=17 | dir=in | app=c:\program files (x86)\bearshare applications\bearshare\bearshare.exe | "{AF56FE83-FD01-45A3-9C42-F823AD847B08}" = protocol=17 | dir=in | app=c:\program files (x86)\syncables\syncables desktop\jre\bin\javaw.exe | "{B624C60D-E1CA-4F46-B714-224E9506FBA6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{B8871288-998E-4389-9B3F-9159762E7D64}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{BA36CFC5-1BD8-487B-8E54-9AF08C4B1DAF}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer_service.exe | "{C3666541-E100-4869-9ADE-B1A004306827}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{C9C219F0-0D5C-483E-B44A-311C8CA5E16D}" = protocol=6 | dir=in | app=c:\program files (x86)\syncables\syncables desktop\jre\bin\javaw.exe | "{D22BDF51-0DA1-4F8F-879E-D7A6BD929F3D}" = protocol=17 | dir=in | app=c:\program files (x86)\bearshare applications\bearshare\bearshare.exe | "{D2F169F7-4D16-4764-8A03-95EA30AA786B}" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe | "{D7F1B056-5537-4C65-8973-B30479B37D35}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{D8F3E038-C774-4537-99B9-C87396DEA4B3}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{E85F50D4-DEAB-472E-BCA9-8E043F041CF2}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer.exe | "{E8D1677E-8E58-4079-9CD5-7050237B02EB}" = protocol=6 | dir=in | app=c:\program files (x86)\bearshare applications\bearshare\bearshare.exe | "{EDD620B1-EDC0-439F-B2BA-DA18A6232230}" = protocol=6 | dir=in | app=c:\program files (x86)\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe | "{F5660FCB-7B75-4CA0-9B06-F5703D3FD776}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{F7B30B61-C0B1-4776-A58B-50E9C1BDC9C4}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{FB14E503-6A0D-4A89-8E18-6194D5F05126}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "TCP Query User{26D263FF-E5A1-4DF8-A470-2EC9D5A83096}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "TCP Query User{6C9514BE-2271-40C5-9688-DACE0713E3A8}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "TCP Query User{80CE3EF9-5249-4444-A4BC-F6ACF15587A3}C:\program files (x86)\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files (x86)\emule\emule.exe | "TCP Query User{BF6EB32D-8C8A-4E2E-A632-0E2F22929442}C:\program files (x86)\map&guide\map&guide base\bin\mgbase.exe" = protocol=6 | dir=in | app=c:\program files (x86)\map&guide\map&guide base\bin\mgbase.exe | "UDP Query User{06B00468-FE50-4E9F-9AE8-DB06C6ED29BD}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "UDP Query User{19355862-4DE1-4285-9711-B950B149A955}C:\program files (x86)\map&guide\map&guide base\bin\mgbase.exe" = protocol=17 | dir=in | app=c:\program files (x86)\map&guide\map&guide base\bin\mgbase.exe | "UDP Query User{AF2D0FDB-5F88-41B7-B235-E1765C0BB249}C:\program files (x86)\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files (x86)\emule\emule.exe | "UDP Query User{CAC9AAF9-EFC0-4583-A37B-5D1497EC7D50}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0919C44F-F18A-4E3B-A737-03685272CE72}" = Windows Live Remote Service Resources "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot "{169C77B7-69C9-4648-9DD0-72B152AF269F}" = Windows Live Family Safety "{19F09425-3C20-4730-9E2A-FC2E17C9F362}" = Windows Live Remote Service Resources "{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{1C55470A-7C9E-4C63-B466-6AFFC69E94E9}" = Windows Live Family Safety "{1EB2CFC3-E1C5-4FC4-B1F8-549DD6242C67}" = Windows Live Remote Service Resources "{266058E0-8FB1-8487-C833-3697A3484E01}" = ccc-utility64 "{289809B1-078A-49F3-83D0-7E51715B3915}" = Windows Live Family Safety "{3946328A-5B3A-434C-A22B-64CF6652FBAD}" = Windows Live Family Safety "{401C50F6-B443-43EE-8F27-A80DB19B03FD}" = Windows Live Family Safety "{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources "{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{5FEAD3E5-A158-4B66-B92B-0C959D7CF838}" = Windows Live Remote Service Resources "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{692CCE55-9EAE-4F57-A834-092882E7FE0B}" = Windows Live Remote Client Resources "{6CBFDC3C-CF21-4C02-A6DC-A5A2707FAF55}" = Windows Live Remote Service Resources "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security "{825C7D3F-D0B3-49D5-A42B-CBB0FBE85E99}" = Windows Live Remote Client Resources "{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{8970AE69-40BE-4058-9916-0ACB1B974A3D}" = Windows Live Remote Client Resources "{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources "{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010 "{91EFE3A1-585E-4F66-B5F6-F118F56C4C47}" = ASUS Power4Gear Hybrid "{9210D7A2-DC28-43F6-92F9-E6CD4C729F7B}" = Windows Live Family Safety "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9D2B0322-44AE-460E-9283-4D2D7A9205AE}" = Trend Micro Internet Security "{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources "{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B0BF8602-EA52-4B0A-A2BD-EDABB0977030}" = Windows Live Remote Client Resources "{B22C8566-D522-4B40-A7AF-525F5A70D832}" = Windows Live Family Safety "{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 "{C42CA929-C55C-4435-F6B2-160C10FD301E}" = ATI Catalyst Install Manager "{C9F05151-95A9-4B9B-B534-1760E2D014A5}" = Windows Live Remote Client Resources "{CB7935EF-43EE-4C0F-AC02-B0E4DD5DAC17}" = Windows Live Family Safety "{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources "{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DBEDAF67-C5A3-4C91-951D-31F3FE63AF3F}" = Windows Live Remote Client Resources "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}" = SRS Premium Sound Control Panel "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FAA3933C-6F0D-4350-B66B-9D7F7031343E}" = Windows Live Remote Service Resources "{FE4BE0BD-1EDB-4D24-9614-847B3C472887}" = Windows Live Family Safety "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit "Elantech" = ETDWare PS/2-x64 7.0.5.13_WHQL "FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "USB2.0 UVC VGA WebCam" = USB2.0 UVC VGA WebCam "ZDFmediathek_is1" = ZDFmediathek Version 2.1.5 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{04668DF2-D32F-4555-9C7E-35523DCD6544}" = Control ActiveX de Windows Live Mesh para conexiones remotas "{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion "{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}" = ASUS AI Recovery "{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar "{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology "{09F56A49-A7B1-4AAB-95B9-D13094254AD1}" = Windows Live UX Platform Language Pack "{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA}" = Uniblue RegistryBooster "{0A9256E0-C924-46DE-921B-F6C4548A1C64}" = Windows Live Messenger "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0BE5C4DB-8EA2-483D-BD71-D7EB09040CDE}" = Windows Live UX Platform Language Pack "{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail "{0EC0B576-90F9-43C3-8FAD-A4902DF4B8F4}" = Galeria de Fotografias do Windows Live "{13FAE3E3-283E-4BF4-8FE5-17D256EDDD77}" = Windows Live UX Platform Language Pack "{14B441B7-774D-4170-98EA-A13667AE6218}" = Windows Live Writer Resources "{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{198EA334-8A3F-4CB2-9D61-6C10B8168A6F}" = Windows Live Writer "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1BAAF2F6-C688-ACB4-89C3-3D0D074CE59F}" = CCC Help Russian "{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3 "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}" = Wireless Console 3 "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011 "{2511AAD7-82DF-4B97-B0B3-E1B933317010}" = Windows Live Writer Resources "{25A381E1-0AB9-4E7A-ACCE-BA49D519CF4E}" = Windows Live Mail "{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 18 "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in "{29373E24-AC72-424E-8F2A-FB0F9436F21F}" = Windows Live Photo Common "{2997ABF5-E5F6-4E9C-9717-26F208D9ED5E}" = PC Connectivity Solution Lite "{2A07C35B-8384-4DA4-9A95-442B6C89A073}" = Windows Live Essentials "{2AD2DD70-27F7-4343-BB4E-DE50A32D854B}" = Windows Live Messenger "{2B81872B-A054-48DA-BE3B-FA5C164C303A}" = ASUS FancyStart "{2C865FB0-051E-4D22-AC62-428E035AEAF0}" = Windows Live Mesh "{2CA575D0-4A39-13B7-C3F6-C12DCECB5BE4}" = CCC Help Finnish "{2D12DFC6-4C5E-2734-5979-2D94798738F1}" = CCC Help Italian "{32C01DD0-3260-4D2B-BDB2-36CEC3E5B27A}" = Windows Live UX Platform Language Pack "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{33A51566-5216-B590-472F-D626C407E332}" = CCC Help Hungarian "{341697D8-9923-445E-B42A-529E5A99CB7A}" = syncables desktop SE "{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{370F888E-42A7-4911-9E34-7D74632E17EB}" = Windows Live Photo Common "{38E5F2CE-F3B8-95C8-E2D2-E668ECF12FB3}" = CCC Help Greek "{3A09ED0F-8DDF-47BB-B53D-841AB9D1D3A7}" = Complemento Messenger "{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer "{3D0C22FA-96D7-4789-BC5B-991A5A99BFFA}" = Windows Live Messenger "{3F4143A1-9C21-4011-8679-3BC1014C6886}" = Windows Live Mesh "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "{41B4578A-520D-375F-0702-51608CFDDA0F}" = CCC Help Norwegian "{43233BDA-5837-0AA5-1624-4746516BCB01}" = CCC Help Dutch "{44FAF589-DA07-039F-A7BF-09A846640A43}" = Catalyst Control Center Graphics Full Existing "{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh "{47CB9C66-D023-34D2-98EB-541D05F89968}" = CCC Help Chinese Standard "{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live "{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A275FD1-2F24-4274-8C01-813F5AD1A92D}" = Windows Live Messenger "{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer "{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform "{4D409740-7A1C-52B4-D7E6-BB6C4F343140}" = CCC Help Spanish "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion "{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance "{5B65EF64-1DFA-414A-8C94-7BB726158E21}" = ControlDeck "{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker "{5D4C60AA-84E6-4E1A-8A68-69970D387BE1}" = TuneUp Utilities Language Pack (de-DE) "{5EFDCD2E-1218-5101-747C-C9AA9443CB85}" = CCC Help Japanese "{5F624839-947D-46EA-BD63-FD847C1AC6F1}" = BearShare "{5F6E678A-7E61-448A-86CB-BC2AD1E04138}" = Windows Live Messenger "{6057E21C-ABE9-4059-AE3E-3BEB9925E660}" = Windows Live Messenger "{619D83DC-710E-203E-29EA-8318FB27C5E4}" = CCC Help Thai "{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer "{622DE1BE-9EDE-49D3-B349-29D64760342A}" = 適用遠端連線的 Windows Live Mesh ActiveX 控制項 "{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources "{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}" = NB Probe "{63AE67AA-1AB1-4565-B4EF-ABBC5C841E8D}" = Windows Live Messenger "{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon "{6703F18D-12B3-7936-2DCA-5D50FD0E3235}" = CCC Help Polish "{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail "{6807427D-8D68-4D30-AF5B-0B38F8F948C8}" = Windows Live Writer Resources "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack "{6A563426-3474-41C6-B847-42B39F1485B2}" = Windows Live Messenger "{6CB36609-E3A6-446C-A3C1-C71E311D2B9C}" = Windows Live Movie Maker "{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker "{6E08F573-FCF7-C933-5BC5-7B14FD5564E3}" = CCC Help Korean "{6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}" = Complément Messenger "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common "{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh "{76046298-768C-492C-8C93-2983C9E3719E}" = Windows Live UX Platform Language Pack "{77C4850C-3592-4A2F-B652-ACB77A1EF77C}" = Bing Bar Platform "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh "{7AC9FA44-609F-8D70-5CC3-9C6A1E59CA4D}" = Catalyst Control Center Graphics Light "{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials "{7E017923-16F8-4E32-94EF-0A150BD196FE}" = Windows Live Writer "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{804DE397-F82C-4867-9085-E0AA539A3294}" = Windows Live Writer "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{8142D25E-028A-4563-86ED-5755783C8029}" = Messenger Companion "{840E2658-DBA1-9A75-7C36-6C6E3F67FAC0}" = ccc-core-static "{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh "{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar "{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8BECCB29-DA5E-4002-B211-C3A148E48D63}" = map&guide base "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash "{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch "{9170B2A2-FC44-4ec2-AEB6-9052626B2A2E}_is1" = Driver Reviver "{924DAFFB-CA84-43a3-8205-A6E94461EC79}_is1" = Registry Reviver "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{939C80FA-96C9-44A6-B318-8E7D8BD8481B}" = Messenger Companion "{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{96403552-88D1-429F-9C92-388B814B885E}" = Messenger Companion "{987B04C4-B5AC-4AD6-A7E9-8D681085B850}" = AMD USB Filter Driver "{9BD262D0-B788-4546-A0A5-F4F56EC3834B}" = Windows Live Photo Common "{9BDD86A7-B184-BB3F-222C-BD24871C0021}" = CCC Help Turkish "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet-TV für Windows Media Center "{9D48531D-2135-49FC-BC29-ACCDA5396A76}" = ASUS MultiFrame "{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}" = פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9D6D7811-43B3-463C-BC79-5D1755269989}" = Net4Switch "{9DB90178-B5B0-45BD-B0A7-D40A6A1DF1CA}" = Windows Live Movie Maker "{9E48FF52-082C-4CC2-BB67-6E10D09C0431}" = Windows Live UX Platform Language Pack "{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail "{A0B91308-6666-4249-8FF6-1E11AFD75FE1}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A1ABB2D1-3A6C-8598-CCCC-684625F4D451}" = CCC Help Swedish "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common "{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}" = Windows Live Photo Gallery "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A7B8A5E9-CA44-44A0-9393-9EA0FFE4C3FB}" = Alcor Micro USB Card Reader "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB5977C5-11AE-4003-BA7D-261C48F2BC35}" = מסייע Messenger "{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package "{ABD534B7-E951-470E-92C2-CD5AF1735726}" = Windows Live Essentials "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch "{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9 "{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh "{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail "{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail "{B2BCA478-EC0F-45EE-A9E9-5EABE87EA72D}" = Windows Live Photo Common "{B30B1C24-863A-B8D3-DB04-7037EE242486}" = CCC Help French "{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{B89F53E2-4461-16D4-66B5-285593D1BE07}" = CCC Help Chinese Traditional "{BBC019AB-8349-42A2-AF5A-A8B759722E2F}" = Windows Live UX Platform Language Pack "{BC3F09E3-E113-1856-855D-E90B073190D1}" = CCC Help Danish "{BE79D33C-6C74-2F72-2160-F0DB4C897B3D}" = Catalyst Control Center InstallProxy "{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker "{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live "{C0A0FA0B-9C4C-1653-0A8D-5F1D92F38D16}" = CCC Help English "{C167A588-87AA-47BF-A88E-5B0F9A14480D}" = InterVideo DVDCopy5 "{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C32CE55C-12BA-4951-8797-0967FDEF556F}" = Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen "{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint "{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}" = Windows Live Mesh ActiveX Control for Remote Connections "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{C7DAD22D-29D4-438F-B986-03B9ED582EA4}" = Messenger Companion "{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common "{C9A00809-0A5A-39DD-C70F-B2CBDD4EA35A}" = Catalyst Control Center Graphics Previews Vista "{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}" = Windows Live Movie Maker "{CE929F09-3853-4180-BD90-30764BFF7136}" = גלריית התמונות של Windows Live "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{CF088261-BC81-4FB9-9BA0-7B5B9602D01A}" = Messenger 分享元件 "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D179B513-AD43-4013-AC50-C16107A0A02D}" = LogMeIn Hamachi "{D2131BFA-A0D6-4FDE-8614-75B07A9B15EE}" = Windows Live UX Platform Language Pack "{D21D5B3B-0BCB-1809-5701-E59EFB4358E8}" = Catalyst Control Center Core Implementation "{D22AFEDF-6A5B-459D-A9EA-D16E422E4C18}" = Nokia Connectivity Cable Driver "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D588365A-AE39-4F27-BDAE-B4E72C8E900C}" = Windows Live Mail "{D619679A-64A9-4677-F2D9-BF2EB2746D61}" = CCC Help Portuguese "{DAEF48AD-89C8-4A93-B1DD-45B7E4FB6071}" = Windows Live Movie Maker "{DBAA2B17-D596-4195-A169-BA2166B0D69B}" = Windows Live Mail "{DCA5FA4B-C9F1-4693-BF7E-A3B2287A3ED5}" = Nokia PC-Internetzugang "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer "{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}" = Controlo ActiveX do Windows Live Mesh para Ligações Remotas "{E62E0550-C098-43A2-B54B-03FB1E634483}" = Windows Live Writer "{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update "{E71E60C1-533E-45A5-8D80-E475E88D2B17}_is1" = Game Park Console "{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources "{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera "{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live "{ED86C4AB-D1E5-42CF-BFA3-56BAAE617D4E}" = Windows Live UX Platform Language Pack "{EEC9A274-AD86-3A16-4F17-22490EF597B4}" = CCC Help German "{EEF99142-3357-402C-B298-DEC303E12D92}" = Windows Live 影像中心 "{EF6ADCD6-C463-24C9-EEE0-6E07F5CC5182}" = CCC Help Czech "{EF7EAB13-46FC-49DD-8E3C-AAF8A286C5BB}" = Windows Live 程式集 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}" = Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις "{F7E80BA7-A09D-4DD1-828B-C4A0274D4720}" = Windows Live Mesh "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{F99BB4A4-5C73-0E3B-59E4-41960860A26E}" = Catalyst Control Center Localization All "{FCDE76CB-989D-4E32-9739-6A272D2B0ED7}" = Windows Live Mesh "{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker "{FF783F26-3A11-FD83-4B2E-7A7C423323C7}" = Catalyst Control Center Graphics Full New "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "ASUS WebStorage" = ASUS WebStorage "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "BearShare" = BearShare "BlazeDTV 6.0_is1" = BlazeDTV 6.0 "Bookworm Deluxe" = Bookworm Deluxe "CloneDVD2" = CloneDVD2 "conduitEngine" = Conduit Engine "Cooking Dash" = Cooking Dash "DAEMON Tools Lite" = DAEMON Tools Lite "Deutschland Radio Toolbar" = Deutschland Radio Toolbar "DEUTSCHLAND_version Toolbar" = DEUTSCHLAND version Toolbar "Google Chrome" = Google Chrome "Governor of Poker" = Governor of Poker "Hotel Dash Suite Success" = Hotel Dash Suite Success "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "InstallShield_{A7B8A5E9-CA44-44A0-9393-9EA0FFE4C3FB}" = Alcor Micro USB Card Reader "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint "Jewel Quest 3" = Jewel Quest 3 "K_Series_ScreenSaver_EN" = K_Series_ScreenSaver_EN "LimeWire" = LimeWire 5.5.13 "LogMeIn Hamachi" = LogMeIn Hamachi "Luxor 3" = Luxor 3 "Magic DVD Copier_is1" = Magic DVD Copier Version 5.0.0 "Mahjongg dimensions" = Mahjongg dimensions "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400 "Mozilla Firefox 14.0.1 (x86 de)" = Mozilla Firefox 14.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Nokia PC Internet Access" = Nokia PC-Internetzugang "Office14.Click2Run" = Microsoft Office Klick-und-Los 2010 "PHPNukeDE Toolbar" = PHPNukeDE Toolbar "Plants vs Zombies" = Plants vs Zombies "radio_de Toolbar" = radio de Toolbar "Search_USA Toolbar" = Search_USA Toolbar "Suche_Deutschland Toolbar" = Suche_Deutschland Toolbar "Surf & E-Mail-Stick" = Surf & E-Mail-Stick "Switch" = Switch Sound File Converter "TeamViewer 7" = TeamViewer 7 "TuneUp Utilities 2011" = TuneUp Utilities 2011 "Uniblue RegistryBooster" = Uniblue RegistryBooster "Wincore MediaBar" = Wincore MediaBar "WinLiveSuite" = Windows Live Essentials "World of Goo" = World of Goo ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 27.07.2012 18:10:45 | Computer Name = touran-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error - 27.07.2012 18:15:29 | Computer Name = touran-PC | Source = CVHSVC | ID = 100 Description = Nur zur Information. (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Error - 27.07.2012 18:15:52 | Computer Name = touran-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error - 27.07.2012 18:15:52 | Computer Name = touran-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error - 27.07.2012 18:15:52 | Computer Name = touran-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error - 27.07.2012 19:38:53 | Computer Name = touran-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: TuneUpUtilitiesService64.exe, Version: 10.0.4600.4, Zeitstempel: 0x4ee70dfd Name des fehlerhaften Moduls: RPCRT4.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c96e Ausnahmecode: 0xc0020043 Fehleroffset: 0x000000000008a973 ID des fehlerhaften Prozesses: 0x8c4 Startzeit der fehlerhaften Anwendung: 0x01cd6c50337c1848 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe Pfad des fehlerhaften Moduls: C:\Windows\system32\RPCRT4.dll Berichtskennung: 3961fe37-d844-11e1-af86-485b399c40dd Error - 27.07.2012 19:40:14 | Computer Name = touran-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error - 27.07.2012 19:40:14 | Computer Name = touran-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error - 27.07.2012 19:40:14 | Computer Name = touran-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error - 27.07.2012 19:43:51 | Computer Name = touran-PC | Source = CVHSVC | ID = 100 Description = Nur zur Information. (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: [ Media Center Events ] Error - 18.05.2011 23:24:23 | Computer Name = touran-PC | Source = MCUpdate | ID = 0 Description = 05:24:23 - Fehler beim Herstellen der Internetverbindung. 05:24:23 - Serververbindung konnte nicht hergestellt werden.. Error - 18.05.2011 23:24:47 | Computer Name = touran-PC | Source = MCUpdate | ID = 0 Description = 05:24:28 - Fehler beim Herstellen der Internetverbindung. 05:24:28 - Serververbindung konnte nicht hergestellt werden.. Error - 23.05.2011 18:03:40 | Computer Name = touran-PC | Source = MCUpdate | ID = 0 Description = 00:03:40 - Fehler beim Herstellen der Internetverbindung. 00:03:40 - Serververbindung konnte nicht hergestellt werden.. Error - 23.05.2011 18:03:55 | Computer Name = touran-PC | Source = MCUpdate | ID = 0 Description = 00:03:45 - Fehler beim Herstellen der Internetverbindung. 00:03:45 - Serververbindung konnte nicht hergestellt werden.. Error - 23.05.2011 19:04:00 | Computer Name = touran-PC | Source = MCUpdate | ID = 0 Description = 01:04:00 - Fehler beim Herstellen der Internetverbindung. 01:04:00 - Serververbindung konnte nicht hergestellt werden.. Error - 23.05.2011 19:04:09 | Computer Name = touran-PC | Source = MCUpdate | ID = 0 Description = 01:04:05 - Fehler beim Herstellen der Internetverbindung. 01:04:05 - Serververbindung konnte nicht hergestellt werden.. Error - 23.05.2011 21:40:01 | Computer Name = touran-PC | Source = MCUpdate | ID = 0 Description = 03:40:01 - Fehler beim Herstellen der Internetverbindung. 03:40:01 - Serververbindung konnte nicht hergestellt werden.. Error - 23.05.2011 21:40:11 | Computer Name = touran-PC | Source = MCUpdate | ID = 0 Description = 03:40:06 - Fehler beim Herstellen der Internetverbindung. 03:40:06 - Serververbindung konnte nicht hergestellt werden.. Error - 23.05.2011 22:40:15 | Computer Name = touran-PC | Source = MCUpdate | ID = 0 Description = 04:40:15 - Fehler beim Herstellen der Internetverbindung. 04:40:15 - Serververbindung konnte nicht hergestellt werden.. Error - 23.05.2011 22:40:24 | Computer Name = touran-PC | Source = MCUpdate | ID = 0 Description = 04:40:20 - Fehler beim Herstellen der Internetverbindung. 04:40:20 - Serververbindung konnte nicht hergestellt werden.. [ System Events ] Error - 27.07.2012 18:04:43 | Computer Name = touran-PC | Source = Application Popup | ID = 1060 Description = Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\iviaspi.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error - 27.07.2012 18:04:51 | Computer Name = touran-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "ASMMAP64" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 27.07.2012 18:04:51 | Computer Name = touran-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "ATKGFNEX Service" ist vom Dienst "ASMMAP64" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%2 Error - 27.07.2012 18:07:36 | Computer Name = touran-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Google Update Service (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 27.07.2012 19:32:59 | Computer Name = touran-PC | Source = Application Popup | ID = 1060 Description = Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\iviaspi.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error - 27.07.2012 19:33:02 | Computer Name = touran-PC | Source = Application Popup | ID = 1060 Description = Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\iviaspi.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error - 27.07.2012 19:33:11 | Computer Name = touran-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "ASMMAP64" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 27.07.2012 19:33:11 | Computer Name = touran-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "ATKGFNEX Service" ist vom Dienst "ASMMAP64" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%2 Error - 27.07.2012 19:35:45 | Computer Name = touran-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Google Update Service (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 27.07.2012 19:39:02 | Computer Name = touran-PC | Source = Service Control Manager | ID = 7034 Description = Dienst "TuneUp Utilities Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. [ TuneUp Events ] Error - 17.02.2012 17:02:48 | Computer Name = touran-PC | Source = TuneUp.UtilitiesSvc | ID = 300 Description = Error - 17.02.2012 17:11:36 | Computer Name = touran-PC | Source = TuneUp.UtilitiesSvc | ID = 300 Description = Error - 17.02.2012 17:11:36 | Computer Name = touran-PC | Source = TuneUp.UtilitiesSvc | ID = 300 Description = Error - 17.02.2012 17:11:36 | Computer Name = touran-PC | Source = TuneUp.UtilitiesSvc | ID = 300 Description = < End of report > |
28.07.2012, 14:32 | #2 |
/// Helfer-Team | Windows 7 mit GVU 2.07Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL MOD - [2012.07.26 11:24:11 | 000,222,120 | ---- | M] () -- C:\Users\touran\AppData\Local\Temp\rty0_7z.exe IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={output Encoding}&sourceid=ie7 IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms} IE - HKLM\..\URLSearchHook: {48405d3d-2674-4cd8-b1ef-9a719443bd3f} - SOFTWARE\Classes\CLSID\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}\InprocServer32 File not found IE - HKLM\..\URLSearchHook: {8c925777-22df-4587-86f7-7ddd6d2ad1eb} - C:\Program Files (x86)\radio_de\prxtbradi.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {937f343c-c9c2-4235-b544-7fc4da2f2594} - C:\Program Files (x86)\Suche_Deutschland\tbSuc1.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {c9508125-4747-4733-b048-e4b82dc9716d} - C:\Program Files (x86)\PHPNukeDE\prxtbPHP0.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {fe0383f0-af43-4832-a481-0555470194d1} - SOFTWARE\Classes\CLSID\{fe0383f0-af43-4832-a481-0555470194d1}\InprocServer32 File not found IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox IE - HKLM\..\SearchScopes\{5BFE8C19-77F1-4E08-9CB2-B03C51A8E9A7}: "URL" = http://downloads.phpnuke.org/de/index.php?rvs=hompag IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncodin g}&oe={outputEncoding}&rlz=1I7ASUT IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={output Encoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{8C212CF2-7194-4FD3-87FF-75A3C0737546}: "URL" = http://downloads.phpnuke.org/de/index.php?rvs=hompag IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2303923 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\InprocServer32 File not found IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\URLSearchHook: {48405d3d-2674-4cd8-b1ef-9a719443bd3f} - SOFTWARE\Classes\CLSID\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}\InprocServer32 File not found IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\URLSearchHook: {937f343c-c9c2-4235-b544-7fc4da2f2594} - C:\Program Files (x86)\Suche_Deutschland\tbSuc1.dll (Conduit Ltd.) IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\URLSearchHook: {c9508125-4747-4733-b048-e4b82dc9716d} - C:\Program Files (x86)\PHPNukeDE\prxtbPHP0.dll (Conduit Ltd.) IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\URLSearchHook: {fe0383f0-af43-4832-a481-0555470194d1} - SOFTWARE\Classes\CLSID\{fe0383f0-af43-4832-a481-0555470194d1}\InprocServer32 File not found IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=LMW2&o=16050&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=OF&apn_dtid=VIN009Y YDE&apn_uid=78EA5E28-326D-4606-B1CF-F13024F64027&apn_sauid=8AE93DAC-ED95-4E26-B104-706D53EEDA8B IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{5BFE8C19-77F1-4E08-9CB2-B03C51A8E9A7}: "URL" = http://downloads.phpnuke.org/de/index.php?rvs=hompag IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncodin g}&oe={outputEncoding}&rlz=1I7ASUT IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={output Encoding}&sourceid=ie7 IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{8C212CF2-7194-4FD3-87FF-75A3C0737546}: "URL" = http://downloads.phpnuke.org/de/index.php?rvs=hompag IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms} IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\SearchScopes\{C5CB8DCA-1352-4C5C-8F47-3C21D7CCE375}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1147646 IE - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - prefs.js..browser.startup.homepage: "http://search.bearshare.com" FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=20&systemid=2&sr=0&q=" FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll File not found [2011.04.30 06:46:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\touran\AppData\Roaming\mozilla\Extensions [2011.04.30 06:46:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\touran\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll File not found O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll File not found O2 - BHO: (Discover USA Toolbar) - {48405d3d-2674-4cd8-b1ef-9a719443bd3f} - C:\Program Files (x86)\Search_USA\prxtbSea0.dll File not found O2 - BHO: (radio de Toolbar) - {8c925777-22df-4587-86f7-7ddd6d2ad1eb} - C:\Program Files (x86)\radio_de\prxtbradi.dll (Conduit Ltd.) O2 - BHO: (Suche Deutschland Toolbar) - {937f343c-c9c2-4235-b544-7fc4da2f2594} - C:\Program Files (x86)\Suche_Deutschland\tbSuc1.dll (Conduit Ltd.) O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll File not found O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll File not found O2 - BHO: (PHPNukeDE Toolbar) - {c9508125-4747-4733-b048-e4b82dc9716d} - C:\Program Files (x86)\PHPNukeDE\prxtbPHP0.dll (Conduit Ltd.) O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll File not found O2 - BHO: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found O2 - BHO: (DEUTSCHLAND version Toolbar) - {fe0383f0-af43-4832-a481-0555470194d1} - C:\Program Files (x86)\DEUTSCHLAND_version\prxtbDEUT.dll File not found O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll File not found O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (Deutschland Radio Toolbar) - {2069a8c8-fad1-424b-b76c-d7f33d77dc4c} - C:\Program Files (x86)\Deutschland_Radio\tbDeut.dll File not found O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll File not found O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll File not found O3 - HKLM\..\Toolbar: (Discover USA Toolbar) - {48405d3d-2674-4cd8-b1ef-9a719443bd3f} - C:\Program Files (x86)\Search_USA\prxtbSea0.dll File not found O3 - HKLM\..\Toolbar: (radio de Toolbar) - {8c925777-22df-4587-86f7-7ddd6d2ad1eb} - C:\Program Files (x86)\radio_de\prxtbradi.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll File not found O3 - HKLM\..\Toolbar: (Suche Deutschland Toolbar) - {937f343c-c9c2-4235-b544-7fc4da2f2594} - C:\Program Files (x86)\Suche_Deutschland\tbSuc1.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (PHPNukeDE Toolbar) - {c9508125-4747-4733-b048-e4b82dc9716d} - C:\Program Files (x86)\PHPNukeDE\prxtbPHP0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found O3 - HKLM\..\Toolbar: (DEUTSCHLAND version Toolbar) - {fe0383f0-af43-4832-a481-0555470194d1} - C:\Program Files (x86)\DEUTSCHLAND_version\prxtbDEUT.dll File not found O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Deutschland Radio Toolbar) - {2069A8C8-FAD1-424B-B76C-D7F33D77DC4C} - C:\Program Files (x86)\Deutschland_Radio\tbDeut.dll File not found O3:64bit: - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll File not found O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll File not found O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll File not found O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Discover USA Toolbar) - {48405D3D-2674-4CD8-B1EF-9A719443BD3F} - C:\Program Files (x86)\Search_USA\prxtbSea0.dll File not found O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (radio de Toolbar) - {8C925777-22DF-4587-86F7-7DDD6D2AD1EB} - C:\Program Files (x86)\radio_de\prxtbradi.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (Suche Deutschland Toolbar) - {937F343C-C9C2-4235-B544-7FC4DA2F2594} - C:\Program Files (x86)\Suche_Deutschland\tbSuc1.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (PHPNukeDE Toolbar) - {C9508125-4747-4733-B048-E4B82DC9716D} - C:\Program Files (x86)\PHPNukeDE\prxtbPHP0.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found O3 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\..\Toolbar\WebBrowser: (DEUTSCHLAND version Toolbar) - {FE0383F0-AF43-4832-A481-0555470194D1} - C:\Program Files (x86)\DEUTSCHLAND_version\prxtbDEUT.dll File not found O4 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 16 O7 - HKU\S-1-5-21-1157160496-1306487556-184762800-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll File not found O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll File not found O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll File not found O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll File not found O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll File not found O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{1cc67dec-cb1c-11e0-be56-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{1cc67dec-cb1c-11e0-be56-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{1cc67def-cb1c-11e0-be56-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{1cc67def-cb1c-11e0-be56-485b399c40dd}\Shell\AutoRun\command - "" = H:\AutoRun.exe O33 - MountPoints2\{1d2f2070-008a-11e1-be20-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{1d2f2070-008a-11e1-be20-485b399c40dd}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{40cc190d-06cf-11e1-a637-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{40cc190d-06cf-11e1-a637-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{5323a049-f8ba-11e0-b448-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{5323a049-f8ba-11e0-b448-485b399c40dd}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{5323a04c-f8ba-11e0-b448-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{5323a04c-f8ba-11e0-b448-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{5d69f865-c822-11e0-aae2-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{5d69f865-c822-11e0-aae2-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{5d69f869-c822-11e0-aae2-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{5d69f869-c822-11e0-aae2-485b399c40dd}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{5d69f87d-c822-11e0-aae2-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{5d69f87d-c822-11e0-aae2-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{625c6797-c179-11e1-8e7a-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{625c6797-c179-11e1-8e7a-485b399c40dd}\Shell\AutoRun\command - "" = F:\NokiaPCIA_Autorun.exe O33 - MountPoints2\{99e55ee7-cf31-11e0-b80f-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{99e55ee7-cf31-11e0-b80f-485b399c40dd}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{99e55eea-cf31-11e0-b80f-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{99e55eea-cf31-11e0-b80f-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{a5e28d84-e881-11e0-89b8-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{a5e28d84-e881-11e0-89b8-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{a5e28d87-e881-11e0-89b8-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{a5e28d87-e881-11e0-89b8-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{a5e28db3-e881-11e0-89b8-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{a5e28db3-e881-11e0-89b8-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{a5e28db5-e881-11e0-89b8-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{a5e28db5-e881-11e0-89b8-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{c757008c-4530-11e1-9f53-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{c757008c-4530-11e1-9f53-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{d6cc960f-8a42-11e1-b533-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{d6cc960f-8a42-11e1-b533-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{d6cc9611-8a42-11e1-b533-485b399c40dd}\Shell - "" = AutoRun O33 - MountPoints2\{d6cc9611-8a42-11e1-b533-485b399c40dd}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\F\Shell - "" = AutoRun O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe [2012.07.24 11:36:06 | 000,000,000 | ---D | C] -- C:\ProgramData\61C3 [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [2012.07.27 20:31:43 | 004,503,728 | ---- | M] () -- C:\ProgramData\z7_0ytr.pad [[2012.07.26 11:24:12 | 000,001,883 | ---- | M] () -- C:\Users\touran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk @Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:981884E7 @Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:3E7393FC :Files ipconfig /flushdns /c :Commands [purity] [emptytemp] [emptyflash]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
__________________ |
12.08.2012, 04:30 | #3 |
/// Helfer-Team | Windows 7 mit GVU 2.07 Fehlende Rückmeldung
__________________Gibt es Probleme beim Abarbeiten obiger Anleitung? Um Kapazitäten für andere Hilfesuchende freizumachen, lösche ich dieses Thema aus meinen Benachrichtigungen. Solltest Du weitermachen wollen, schreibe mir eine PN oder eröffne ein neues Thema. http://www.trojaner-board.de/69886-a...-beachten.html Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner sauber ist.
__________________ |
Themen zu Windows 7 mit GVU 2.07 |
antivir, avira, bho, bingbar, conduit, entfernen, error, failed, fehler, firefox, flash player, geld, gfnexsrv.exe, google earth, gvu 2.07, gvu 2.07win7, gvu-trojaner, gvu2.07, helper, home, iexplore.exe, install.exe, limewire, logfile, microsoft office starter 2010, mozilla, plug-in, popup, realtek, rundll, scan, searchscopes, security, software, svchost.exe, trojaner, windows |