|
Plagegeister aller Art und deren Bekämpfung: Claro Search eingfangen :(Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
17.11.2012, 23:03 | #1 |
| Claro Search eingfangen :( Hallo, ich habe mir das Claro Search eingefangen dass ich nicht mehr wegbekommen und mein PC ist jetzt auch total lahm. Und ich hab jetzt gelesen dass es für jeden eine individuelle lösung gibt deshalb hoffe ich hier auf hilfe Lg Marci Ich bräuchte echt dringend hilfe hier aufm meine Pc geht fast nichts mehr 2-5min ladezeit für die Internetseite bei einer 16000er leitung Weiß niemand was? Habe einen Beitrag gefunden hier ist das vom ADWcleaner: # AdwCleaner v2.007 - Datei am 17/11/2012 um 23:33:58 erstellt # Aktualisiert am 06/11/2012 von Xplode # Betriebssystem : Windows 8 Pro (64 bits) # Benutzer : Marci´s - MARCI´S-LAPTOP # Bootmodus : Normal # Ausgeführt unter : C:\Users\Marci´s\Downloads\adwcleaner_2.0.0.7.exe # Option [Löschen] **** [Dienste] **** Gestoppt & Gelöscht : PC Performer Manager ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml Datei Gelöscht : C:\Users\Marci´s\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tbhcn.lnk Gelöscht mit Neustart : C:\ProgramData\pc performer manager Ordner Gelöscht : C:\Program Files (x86)\BrowserCompanion Ordner Gelöscht : C:\Program Files (x86)\Conduit Ordner Gelöscht : C:\Program Files (x86)\SweetIM Ordner Gelöscht : C:\Program Files (x86)\Yontoo Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\IBUpdaterService Ordner Gelöscht : C:\ProgramData\SweetIM Ordner Gelöscht : C:\ProgramData\Tarma Installer Ordner Gelöscht : C:\Users\Marci´s\AppData\Local\Conduit Ordner Gelöscht : C:\Users\Marci´s\AppData\Local\Smartbar Ordner Gelöscht : C:\Users\Marci´s\AppData\Local\TempDir Ordner Gelöscht : C:\Users\Marci´s\AppData\LocalLow\bbrs_002.tb Ordner Gelöscht : C:\Users\Marci´s\AppData\LocalLow\BVD_ToolKit Ordner Gelöscht : C:\Users\Marci´s\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Marci´s\AppData\LocalLow\incredibar.com Ordner Gelöscht : C:\Users\Marci´s\AppData\LocalLow\PriceGong Ordner Gelöscht : C:\Users\Marci´s\AppData\LocalLow\SweetIM Ordner Gelöscht : C:\Users\Marci´s\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\Marci´s\AppData\Roaming\BrowserCompanion Ordner Gelöscht : C:\Users\Marci´s\AppData\Roaming\loadtbs Ordner Gelöscht : C:\Users\Marci´s\AppData\Roaming\OpenCandy ***** [Registrierungsdatenbank] ***** Daten Gelöscht : HKLM\..\Windows [AppInit_DLLs] = c:\progra~3\pcperf~1\24897~1.175\{61d8b~1\pcpmngr.dll Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\BVD_ToolKit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\DataMngr Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\ImInstaller Schlüssel Gelöscht : HKCU\Software\incredibar.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Web-Suche Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DFEFCDEE-CF1A-4FC8-88AD-129872198372} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEFCDEE-CF1A-4FC8-88AD-129872198372} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{4327FABE-3C22-4689-8DBF-D226CF777FE9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\Software\BrowserCompanion Schlüssel Gelöscht : HKLM\Software\BVD_ToolKit Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\tdataprotocol.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\updatebho.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\wit4ie.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\I Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Incredibar.dskBnd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Incredibar.dskBnd.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IncredibarApp.appCore Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IncredibarApp.appCore.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\base64 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\chrome Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\prox Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sim-packages Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\tdataprotocol.CTData Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\tdataprotocol.CTData.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2319825 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3147923 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{8830DDF0-3042-404D-A62C-384A85E34833} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\updatebho.TimerBHO Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\updatebho.TimerBHO.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wit4ie.WitBHO Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wit4ie.WitBHO.2 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\incredibar.com Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{03E0EF5B-DDBB-489C-A0D0-16287429CEAF} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00CBB66B-1D3B-46D3-9577-323A336ACB50} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C01315C7-B4E2-4864-B43D-5FAFC414D179} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{ED0E67AD-926C-4008-87E5-03CF72AA2A7E} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F0356CB6-4AB7-425B-A31C-0369E0CB5E81} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03E45F6A-8BEE-44EA-BE89-2B5E726DB080} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74C36554-31F0-49DD-8857-ED6A64DF45BE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8CE183B-C52B-455A-8512-2F21822F923D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2F603A45-D956-496B-81B5-50D782424976} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B85C4CB2-B352-4BD8-818C-BCE353599107} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F0356CB6-4AB7-425B-A31C-0369E0CB5E81} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Schlüssel Gelöscht : HKLM\SOFTWARE\Tarma Installer Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E49D8D56-543D-4B71-BA78-150D6DD38374}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{E49D8D56-543D-4B71-BA78-150D6DD38374}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{E49D8D56-543D-4B71-BA78-150D6DD38374}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{9E131A93-EED7-4BEB-B015-A0ADB30B5646}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{DFEFCDEE-CF1A-4FC8-88AD-129872198372}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{E49D8D56-543D-4B71-BA78-150D6DD38374}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{F9639E4A-801B-4843-AEE3-03D9DA199E77}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.10.9200.16420 Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.claro-search.com/?affID=114506&tt=4512_2&babsrc=HP_clro&mntrId=4202e4b400000000000002f1a1ff2b87 --> hxxp://www.google.com Gelöscht : [HKCU\Software\Microsoft\Internet Explorer\Main - bProtector Start Page] -\\ Mozilla Firefox v16.0.2 (de) Profilname : default Datei : C:\Users\Marci´s\AppData\Roaming\Mozilla\Firefox\Profiles\irjptrd8.default\prefs.js C:\Users\Marci´s\AppData\Roaming\Mozilla\Firefox\Profiles\irjptrd8.default\user.js ... Gelöscht ! Gelöscht : user_pref("avg.install.userHPSettings", "hxxp://www.claro-search.com/?affID=114506&tt=4512_2&babsrc=[...] Gelöscht : user_pref("avg.install.userSPSettings", "Claro Search"); Gelöscht : user_pref("browser.search.selectedEngine", "Claro Search"); Gelöscht : user_pref("browser.startup.homepage", "hxxp://www.claro-search.com/?affID=114506&tt=4512_2&babsrc=HP[...] Gelöscht : user_pref("extensions.BabylonToolbar_i.newTab", true); Gelöscht : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.claro-search.com/?affID=114506&tt=451[...] Gelöscht : user_pref("extensions.claro.admin", false); Gelöscht : user_pref("extensions.claro.aflt", "babsst"); Gelöscht : user_pref("extensions.claro.appId", "{C3110516-8EFC-49D6-8B72-69354F332062}"); Gelöscht : user_pref("extensions.claro.dfltLng", "en"); Gelöscht : user_pref("extensions.claro.excTlbr", false); Gelöscht : user_pref("extensions.claro.id", "4202e4b400000000000002f1a1ff2b87"); Gelöscht : user_pref("extensions.claro.instlDay", "15652"); Gelöscht : user_pref("extensions.claro.instlRef", "sst"); Gelöscht : user_pref("extensions.claro.prdct", "claro"); Gelöscht : user_pref("extensions.claro.prtnrId", "claro"); Gelöscht : user_pref("extensions.claro.tlbrId", "claro"); Gelöscht : user_pref("extensions.claro.tlbrSrchUrl", ""); Gelöscht : user_pref("extensions.claro.vrsn", "1.8.3.10"); Gelöscht : user_pref("extensions.claro.vrsni", "1.8.3.10"); Gelöscht : user_pref("extensions.claro_i.smplGrp", "none"); Gelöscht : user_pref("extensions.claro_i.vrsnTs", "1.8.3.1021:26:03"); -\\ Google Chrome v23.0.1271.64 Datei : C:\Users\Marci´s\AppData\Local\Google\Chrome\User Data\Default\Preferences Gelöscht [l.20] : urls_to_restore_on_startup = [ "hxxp://www.google.com/", "hxxp://www.claro-search.com/?affID=114506&tt=4512_2&babsrc=HP_clro&mntrId=4202e4b400000000000002f1a1ff2b87" ] Gelöscht [l.3143] : urls_to_restore_on_startup = [ "hxxp://www.google.com/", "hxxp://www.claro-search.com/?affID=114506&tt=4512_2&babsrc=HP_clro&mntrId=4202e4b400000000000002f1a1ff2b87" ] ************************* AdwCleaner[R1].txt - [22868 octets] - [17/11/2012 23:33:35] AdwCleaner[S1].txt - [22431 octets] - [17/11/2012 23:33:58] ########## EOF - C:\AdwCleaner[S1].txt - [22492 octets] ########## |
18.11.2012, 23:11 | #2 | |
/// TB-Ausbilder | Claro Search eingfangen :( Hallo brauchst du noch Hilfe?
__________________Ich werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich. Customscan mit OTL
__________________ |
19.11.2012, 15:53 | #3 |
| Claro Search eingfangen :( Ich habe es ein paar mal gemacht aber es ist immer wieder nach einem neustart da gewesen. Aber jetzt gerade hält es toi toi toi
__________________ |
19.11.2012, 16:44 | #4 |
/// TB-Ausbilder | Claro Search eingfangen :( Es wird immer wieder da sein, wenn wir es nicht entfernen.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
19.11.2012, 18:18 | #5 |
| Claro Search eingfangen :( So das hab ich jetzt gemacht Teil1: OTL logfile created on: 19.11.2012 17:57:51 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marci´s\Desktop 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16433) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,86 Gb Total Physical Memory | 2,75 Gb Available Physical Memory | 71,20% Memory free 7,74 Gb Paging File | 6,17 Gb Available in Paging File | 79,67% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 223,94 Gb Total Space | 122,87 Gb Free Space | 54,87% Space Free | Partition Type: NTFS Drive D: | 224,14 Gb Total Space | 190,75 Gb Free Space | 85,10% Space Free | Partition Type: NTFS Computer Name: MARCI´S-LAPTOP | User Name: Marci´s | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Marci´s\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Windows\SysWOW64\PnkBstrA.exe () PRC - C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler.exe (Google Inc.) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\AVAST Software\Avast\AvastUI.exe (AVAST Software) PRC - C:\Programme\AVAST Software\Avast\AvastSvc.exe (AVAST Software) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe () PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files (x86)\Freemium\SystemStore\Freemium.SystemStore.WindowsService.exe () PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Goeasily\GameMouse\GameMouse.exe () PRC - C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe (Acer Incorporated) PRC - c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated) PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) ========== Modules (No Company Name) ========== MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll () MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll () MOD - C:\Program Files (x86)\Goeasily\GameMouse\GameMouse.exe () MOD - C:\Program Files (x86)\Launch Manager\CdDirIo.dll () ========== Services (SafeList) ========== SRV:64bit: - (AudioEndpointBuilder) -- C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation) SRV:64bit: - (WSService) -- C:\Windows\SysNative\WSService.dll (Microsoft Corporation) SRV:64bit: - (PrintNotify) -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation) SRV:64bit: - (TimeBroker) -- C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation) SRV:64bit: - (SystemEventsBroker) -- C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation) SRV:64bit: - (fhsvc) -- C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation) SRV:64bit: - (BrokerInfrastructure) -- C:\Windows\SysNative\bisrv.dll (Microsoft Corporation) SRV:64bit: - (MSMQ) -- C:\Windows\SysNative\mqsvc.exe (Microsoft Corporation) SRV:64bit: - (wlidsvc) -- C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation) SRV:64bit: - (WiaRpc) -- C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation) SRV:64bit: - (Wcmsvc) -- C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation) SRV:64bit: - (VaultSvc) -- C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation) SRV:64bit: - (svsvc) -- C:\Windows\SysNative\svsvc.dll (Microsoft Corporation) SRV:64bit: - (netprofm) -- C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation) SRV:64bit: - (Netlogon) -- C:\Windows\SysNative\netlogon.dll (Microsoft Corporation) SRV:64bit: - (NcaSvc) -- C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation) SRV:64bit: - (NcdAutoSetup) -- C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation) SRV:64bit: - (LSM) -- C:\Windows\SysNative\lsm.dll (Microsoft Corporation) SRV:64bit: - (KeyIso) -- C:\Windows\SysNative\keyiso.dll (Microsoft Corporation) SRV:64bit: - (EFS) -- C:\Windows\SysNative\efssvc.dll (Microsoft Corporation) SRV:64bit: - (DsmSvc) -- C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation) SRV:64bit: - (DeviceAssociationService) -- C:\Windows\SysNative\das.dll (Microsoft Corporation) SRV:64bit: - (AllUserInstallAgent) -- C:\Windows\SysNative\AUInstallAgent.dll (Microsoft Corporation) SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SRV:64bit: - (vmicvss) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation) SRV:64bit: - (vmictimesync) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation) SRV:64bit: - (vmicshutdown) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation) SRV:64bit: - (vmicrdv) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation) SRV:64bit: - (vmickvpexchange) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation) SRV:64bit: - (vmicheartbeat) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation) SRV:64bit: - (UxTuneUp) -- C:\Windows\SysNative\uxtuneup.dll (TuneUp Software) SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe () SRV - (SelfUpdateService) -- C:\Program Files (x86)\SelfUpdater\SelfUpdate.exe () SRV - (SystemStoreService) -- C:\Program Files (x86)\SelfUpdater\SystemStore.exe () SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (avast! Antivirus) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe (AVAST Software) SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (PrintNotify) -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll (Microsoft Corporation) SRV - (Desura Install Service) -- C:\Program Files (x86)\Common Files\Desura\desura_service.exe (Desura Pty Ltd) SRV - (Mobile Partner. RunOuc) -- C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe () SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (StorSvc) -- C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation) SRV - (WAS) -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll (Microsoft Corporation) SRV - (W3SVC) -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll (Microsoft Corporation) SRV - (AppHostSvc) -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll (Microsoft Corporation) SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies) SRV - (SystemStore) -- C:\Program Files (x86)\Freemium\SystemStore\Freemium.SystemStore.WindowsService.exe () SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (TuneUp Software) SRV - (UxTuneUp) -- C:\Windows\SysWOW64\uxtuneup.dll (TuneUp Software) SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) SRV - (Live Updater Service) -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe (Acer Incorporated) SRV - (ePowerSvc) -- C:\Programme\Packard Bell\Packard Bell Power Management\ePowerSvc.exe (Acer Incorporated) SRV - (HWDeviceService64.exe) -- C:\ProgramData\DatacardService\HWDeviceService64.exe () SRV - (GamesAppService) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.) SRV - (AdobeActiveFileMonitor9.0) -- c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated) SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation) SRV - (DsiWMIService) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.) SRV - (NTI IScheduleSvc) -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.) SRV - (NOBU) -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation) SRV - (NAUpdate) -- c:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG) SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) SRV - (osppsvc) -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) SRV - (GREGService) -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe (Acer Incorporated) ========== Driver Services (SafeList) ========== DRV:64bit: - (avipbb) -- C:\Windows\SysNative\Drivers\avipbb.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\Drivers\avgntflt.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (aswSnx) -- C:\WINDOWS\SysNative\drivers\aswSnx.sys (AVAST Software) DRV:64bit: - (aswSP) -- C:\WINDOWS\SysNative\drivers\aswSP.sys (AVAST Software) DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\Drivers\aswMonFlt.sys (AVAST Software) DRV:64bit: - (aswFsBlk) -- C:\WINDOWS\SysNative\drivers\aswFsBlk.sys (AVAST Software) DRV:64bit: - (pdc) -- C:\Windows\SysNative\Drivers\pdc.sys (Microsoft Corporation) DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys (Microsoft Corporation) DRV:64bit: - (sdstor) -- C:\Windows\SysNative\Drivers\sdstor.sys (Microsoft Corporation) DRV:64bit: - (sdbus) -- C:\Windows\SysNative\Drivers\sdbus.sys (Microsoft Corporation) DRV:64bit: - (dam) -- C:\Windows\SysNative\Drivers\dam.sys (Microsoft Corporation) DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\Drivers\avkmgr.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (USBHUB3) -- C:\Windows\SysNative\Drivers\USBHUB3.SYS (Microsoft Corporation) DRV:64bit: - (USBXHCI) -- C:\Windows\SysNative\Drivers\USBXHCI.SYS (Microsoft Corporation) DRV:64bit: - (UCX01000) -- C:\Windows\SysNative\Drivers\UCX01000.SYS (Microsoft Corporation) DRV:64bit: - (GPIOClx0101) -- C:\Windows\SysNative\Drivers\msgpioclx.sys (Microsoft Corporation) DRV:64bit: - (msgpiowin32) -- C:\Windows\SysNative\Drivers\msgpiowin32.sys (Microsoft Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\Drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\Drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (TPM) -- C:\Windows\SysNative\Drivers\tpm.sys (Microsoft Corporation) DRV:64bit: - (BthAvrcpTg) -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys (Microsoft Corporation) DRV:64bit: - (bthhfhid) -- C:\Windows\SysNative\Drivers\BthhfHid.sys (Microsoft Corporation) DRV:64bit: - (SynTP) -- C:\Windows\SysNative\Drivers\SynTP.sys (Synaptics Incorporated) DRV:64bit: - (SmbDrvI) -- C:\Windows\SysNative\Drivers\Smb_driver_Intel.sys (Synaptics Incorporated) DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\Drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV:64bit: - (Fs_Rec) -- C:\WINDOWS\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (condrv) -- C:\Windows\SysNative\Drivers\condrv.sys (Microsoft Corporation) DRV:64bit: - (VSTXRAID) -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS (VIA Corporation) DRV:64bit: - (VerifierExt) -- C:\Windows\SysNative\Drivers\VerifierExt.sys (Microsoft Corporation) DRV:64bit: - (UASPStor) -- C:\Windows\SysNative\Drivers\uaspstor.sys (Microsoft Corporation) DRV:64bit: - (acpiex) -- C:\Windows\SysNative\Drivers\acpiex.sys (Microsoft Corporation) DRV:64bit: - (spaceport) -- C:\Windows\SysNative\Drivers\spaceport.sys (Microsoft Corporation) DRV:64bit: - (storahci) -- C:\Windows\SysNative\Drivers\storahci.sys (Microsoft Corporation) DRV:64bit: - (mvumis) -- C:\Windows\SysNative\Drivers\mvumis.sys (Marvell Semiconductor, Inc.) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\Drivers\stexstor.sys (Promise Technology, Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\Drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (LSI_SSS) -- C:\Windows\SysNative\Drivers\lsi_sss.sys (LSI Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\Drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (EhStorTcgDrv) -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys (Microsoft Corporation) DRV:64bit: - (EhStorClass) -- C:\Windows\SysNative\Drivers\EhStorClass.sys (Microsoft Corporation) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\Drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (3ware) -- C:\Windows\SysNative\Drivers\3ware.sys (LSI) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\Drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\Drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (CLFS) -- C:\Windows\SysNative\Drivers\clfs.sys (Microsoft Corporation) DRV:64bit: - (WFPLWFS) -- C:\Windows\SysNative\Drivers\wfplwfs.sys (Microsoft Corporation) DRV:64bit: - (vpci) -- C:\Windows\SysNative\Drivers\vpci.sys (Microsoft Corporation) DRV:64bit: - (WdFilter) -- C:\Windows\SysNative\Drivers\WdFilter.sys (Microsoft Corporation) DRV:64bit: - (WdBoot) -- C:\Windows\SysNative\Drivers\WdBoot.sys (Microsoft Corporation) DRV:64bit: - (terminpt) -- C:\Windows\SysNative\Drivers\terminpt.sys (Microsoft Corporation) DRV:64bit: - (MQAC) -- C:\Windows\SysNative\Drivers\mqac.sys (Microsoft Corporation) DRV:64bit: - (mshidumdf) -- C:\Windows\SysNative\Drivers\mshidumdf.sys (Microsoft Corporation) DRV:64bit: - (BasicDisplay) -- C:\Windows\SysNative\Drivers\BasicDisplay.sys (Microsoft Corporation) DRV:64bit: - (HyperVideo) -- C:\Windows\SysNative\Drivers\HyperVideo.sys (Microsoft Corporation) DRV:64bit: - (BasicRender) -- C:\Windows\SysNative\Drivers\BasicRender.sys (Microsoft Corporation) DRV:64bit: - (FxPPM) -- C:\Windows\SysNative\Drivers\fxppm.sys (Microsoft Corporation) DRV:64bit: - (gencounter) -- C:\Windows\SysNative\Drivers\vmgencounter.sys (Microsoft Corporation) DRV:64bit: - (kdnic) -- C:\Windows\SysNative\Drivers\kdnic.sys (Microsoft Corporation) DRV:64bit: - (acpitime) -- C:\Windows\SysNative\Drivers\acpitime.sys (Microsoft Corporation) DRV:64bit: - (npsvctrig) -- C:\Windows\SysNative\Drivers\npsvctrig.sys (Microsoft Corporation) DRV:64bit: - (WpdUpFltr) -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys (Microsoft Corporation) DRV:64bit: - (acpipagr) -- C:\Windows\SysNative\Drivers\acpipagr.sys (Microsoft Corporation) DRV:64bit: - (hyperkbd) -- C:\Windows\SysNative\Drivers\hyperkbd.sys (Microsoft Corporation) DRV:64bit: - (SerCx) -- C:\Windows\SysNative\Drivers\SerCx.sys (Microsoft Corporation) DRV:64bit: - (SpbCx) -- C:\Windows\SysNative\Drivers\SpbCx.sys (Microsoft Corporation) DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\Drivers\TsUsbGD.sys (Microsoft Corporation) DRV:64bit: - (BthHFEnum) -- C:\Windows\SysNative\Drivers\bthhfenum.sys (Microsoft Corporation) DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\Drivers\dmvsc.sys (Microsoft Corporation) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (hidi2c) -- C:\Windows\SysNative\Drivers\hidi2c.sys (Microsoft Corporation) DRV:64bit: - (Vid) -- C:\Windows\SysNative\Drivers\Vid.sys (Microsoft Corporation) DRV:64bit: - (storvsp) -- C:\Windows\SysNative\Drivers\storvsp.sys (Microsoft Corporation) DRV:64bit: - (wpcfltr) -- C:\Windows\SysNative\Drivers\wpcfltr.sys (Microsoft Corporation) DRV:64bit: - (vmbusr) -- C:\Windows\SysNative\Drivers\vmbusr.sys (Microsoft Corporation) DRV:64bit: - (vpcivsp) -- C:\Windows\SysNative\Drivers\vpcivsp.sys (Microsoft Corporation) DRV:64bit: - (NdisImPlatform) -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys (Microsoft Corporation) DRV:64bit: - (MsLldp) -- C:\Windows\SysNative\Drivers\mslldp.sys (Microsoft Corporation) DRV:64bit: - (Ndu) -- C:\Windows\SysNative\Drivers\Ndu.sys (Microsoft Corporation) DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\Drivers\atikmdag.sys (Advanced Micro Devices, Inc.) DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.) DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\Drivers\atikmpag.sys (Advanced Micro Devices, Inc.) DRV:64bit: - (k57nd60a) -- C:\Windows\SysNative\Drivers\k57nd60a.sys (Broadcom Corporation) DRV:64bit: - (athr) -- C:\Windows\SysNative\Drivers\athrx.sys (Qualcomm Atheros Communications, Inc.) DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\Drivers\Sftvollh.sys (Microsoft Corporation) DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\Drivers\Sftplaylh.sys (Microsoft Corporation) DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\Drivers\Sftredirlh.sys (Microsoft Corporation) DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\Drivers\Sftfslh.sys (Microsoft Corporation) DRV:64bit: - (GameMouseFilter) -- C:\Windows\SysNative\Drivers\QXKJGameMouse.sys () DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\Drivers\iaStor.sys (Intel Corporation) DRV:64bit: - (kbdfdo) -- C:\Windows\SysNative\Drivers\qxkjvk.sys () DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\Drivers\AtiHdmi.sys (ATI Technologies, Inc.) DRV:64bit: - (HECIx64) -- C:\Windows\SysNative\Drivers\HECIx64.sys (Intel Corporation) DRV:64bit: - (NTIDrvr) -- C:\Windows\SysNative\Drivers\NTIDrvr.sys (NewTech Infosystems, Inc.) DRV:64bit: - (UBHelper) -- C:\Windows\SysNative\Drivers\UBHelper.sys (NewTech Infosystems Corporation) DRV:64bit: - (hamachi) -- C:\Windows\SysNative\Drivers\hamachi.sys (LogMeIn, Inc.) DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys (TuneUp Software) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-84541473-987749336-3452602534-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-84541473-987749336-3452602534-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-84541473-987749336-3452602534-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\S-1-5-21-84541473-987749336-3452602534-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F6 94 E6 4B 9F C1 CC 01 [binary data] IE - HKU\S-1-5-21-84541473-987749336-3452602534-1000\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - No CLSID value found IE - HKU\S-1-5-21-84541473-987749336-3452602534-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-84541473-987749336-3452602534-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-84541473-987749336-3452602534-1000\..\SearchScopes\{C17FE121-70C8-4338-9C80-98633E896532}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3147923 IE - HKU\S-1-5-21-84541473-987749336-3452602534-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-84541473-987749336-3452602534-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKU\S-1-5-21-84541473-987749336-3452602534-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 121.254.133.150:3128 IE - HKU\S-1-5-21-84541473-987749336-3452602534-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.11 FF - prefs.js..extensions.enabledAddons: {dfefbe51-ca52-484b-adf0-6b158b05262d}:2.4.897.175 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Marci´s\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.12.07 13:44:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012.11.01 11:19:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.08 18:05:21 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.12.07 13:44:27 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{dfefbe51-ca52-484b-adf0-6b158b05262d}: C:\ProgramData\PC Performer Manager\2.4.897.175\{61d8b74e-8d89-46ff-afa6-33382c54ac73}\FirefoxExtension [2012.11.08 18:05:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marci´s\AppData\Roaming\mozilla\Extensions [2011.10.22 15:36:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marci´s\AppData\Roaming\mozilla\Extensions-BackupByFirefoxPortable [2012.11.08 21:26:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marci´s\AppData\Roaming\mozilla\Firefox\Profiles\irjptrd8.default\extensions [2012.11.08 18:06:42 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Marci´s\AppData\Roaming\mozilla\Firefox\Profiles\irjptrd8.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2012.11.08 18:05:21 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2012.10.31 19:12:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} File not found (No name found) -- C:\PROGRAMDATA\PC PERFORMER MANAGER\2.4.897.175\{61D8B74E-8D89-46FF-AFA6-33382C54AC73}\FIREFOXEXTENSION File not found (No name found) -- C:\USERS\MARCI´S\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IRJPTRD8.DEFAULT\EXTENSIONS\{B9DB16A4-6EDC-47EC-A1F4-B86292ED211D} [2012.10.24 18:50:04 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012.10.24 23:03:12 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.10.24 23:03:11 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012.10.24 23:03:12 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012.10.24 23:03:12 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012.10.24 23:03:12 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012.10.24 23:03:11 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = hxxp://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&aq=t CHR - default_search_provider: suggest_url = hxxp://suggestqueries.google.com/complete/search?q={searchTerms} CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll CHR - plugin: Java(TM) Platform SE 6 U37 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Unity Player (Enabled) = C:\Users\Marci\u00B4s\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll CHR - Extension: Adblock Plus = C:\Users\Marci´s\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.1_0\ CHR - Extension: Ocean Pacific = C:\Users\Marci´s\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecaabliejjdikjnkahhikeelbblahgoi\3_0\ CHR - Extension: avast! WebRep = C:\Users\Marci´s\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\ CHR - Extension: Adblock Plus = C:\Users\Marci´s\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.1_0\ CHR - Extension: Ocean Pacific = C:\Users\Marci´s\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecaabliejjdikjnkahhikeelbblahgoi\3_0\ CHR - Extension: avast! WebRep = C:\Users\Marci´s\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\ O1 HOSTS File: ([2012.07.26 06:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKU\S-1-5-21-84541473-987749336-3452602534-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Programme\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated) O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.) O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKU\S-1-5-21-84541473-987749336-3452602534-1000..\Run: [Akamai NetSession Interface] C:\Users\Marci´s\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc) O4 - Startup: C:\Users\Marci´s\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () O4 - Startup: C:\Users\Marci´s\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-84541473-987749336-3452602534-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-84541473-987749336-3452602534-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Marci´s\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Marci´s\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{183AAF52-CAAC-4B03-B8C7-C9024BD6559A}: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6CF8A887-0A0D-466B-87DB-DA1DFB7E861B}: DhcpNameServer = 10.57.1.1 O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O30 - LSA: Security Packages - (livessp) - File not found O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:64bit: {74166507-F39E-305E-A972-2C3478E47350} - .NET Framework ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U %SystemRoot%\System32\shell32.dll ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {3A8403F3-90B5-35DC-8926-EB9B907209F9} - .NET Framework ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP NetSvcs:64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation) NetSvcs:64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation) NetSvcs:64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation) NetSvcs:64bit: SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation) NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) MsConfig:64bit - State: "services" - Reg Error: Key error. Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L) Drivers32:64bit: VIDC.XFR1 - xfcodec64.dll () Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: vidc.cvid - C:\WINDOWS\SysWow64\iccvid.dll (Radius Inc.) Drivers32: VIDC.FPS1 - C:\WINDOWS\SysWow64\frapsvid.dll (Beepa P/L) Drivers32: vidc.i420 - C:\WINDOWS\SysWow64\i420vfw.dll (www.helixcommunity.org) Drivers32: VIDC.XFR1 - C:\WINDOWS\SysWow64\xfcodec.dll () Drivers32: vidc.yv12 - C:\WINDOWS\SysWow64\yv12vfw.dll (www.helixcommunity.org) SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SafeBootMin:64bit: Base - Driver Group SafeBootMin:64bit: BasicDisplay.sys - C:\Windows\SysNative\Drivers\BasicDisplay.sys (Microsoft Corporation) SafeBootMin:64bit: BasicRender.sys - C:\Windows\SysNative\Drivers\BasicRender.sys (Microsoft Corporation) SafeBootMin:64bit: Boot Bus Extender - Driver Group SafeBootMin:64bit: Boot file system - Driver Group SafeBootMin:64bit: BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation) SafeBootMin:64bit: EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation) SafeBootMin:64bit: File system - Driver Group SafeBootMin:64bit: Filter - Driver Group SafeBootMin:64bit: HelpSvc - Service SafeBootMin:64bit: KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation) SafeBootMin:64bit: LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation) SafeBootMin:64bit: Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation) SafeBootMin:64bit: PCI Configuration - Driver Group SafeBootMin:64bit: PNP Filter - Driver Group SafeBootMin:64bit: Primary disk - Driver Group SafeBootMin:64bit: sacsvr - Service SafeBootMin:64bit: SCSI Class - Driver Group SafeBootMin:64bit: System Bus Extender - Driver Group SafeBootMin:64bit: TBS - Service SafeBootMin:64bit: vmms - Service SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin:64bit: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices SafeBootMin:64bit: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: TBS - Service SafeBootMin: vmms - Service SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices SafeBootMin: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SafeBootNet:64bit: Base - Driver Group SafeBootNet:64bit: BasicDisplay.sys - C:\Windows\SysNative\Drivers\BasicDisplay.sys (Microsoft Corporation) SafeBootNet:64bit: BasicRender.sys - C:\Windows\SysNative\Drivers\BasicRender.sys (Microsoft Corporation) SafeBootNet:64bit: Boot Bus Extender - Driver Group SafeBootNet:64bit: Boot file system - Driver Group SafeBootNet:64bit: BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation) SafeBootNet:64bit: EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation) SafeBootNet:64bit: File system - Driver Group SafeBootNet:64bit: Filter - Driver Group SafeBootNet:64bit: HelpSvc - Service SafeBootNet:64bit: KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation) SafeBootNet:64bit: LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation) SafeBootNet:64bit: Messenger - Service SafeBootNet:64bit: NDIS Wrapper - Driver Group SafeBootNet:64bit: NetBIOSGroup - Driver Group SafeBootNet:64bit: NetDDEGroup - Driver Group SafeBootNet:64bit: Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation) SafeBootNet:64bit: netprofm - C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation) SafeBootNet:64bit: Network - Driver Group SafeBootNet:64bit: NetworkProvider - Driver Group SafeBootNet:64bit: PCI Configuration - Driver Group SafeBootNet:64bit: PNP Filter - Driver Group SafeBootNet:64bit: PNP_TDI - Driver Group SafeBootNet:64bit: Primary disk - Driver Group SafeBootNet:64bit: rdpencdd.sys - Driver SafeBootNet:64bit: rdsessmgr - Service SafeBootNet:64bit: sacsvr - Service SafeBootNet:64bit: SCSI Class - Driver Group SafeBootNet:64bit: SmartcardSimulator - Driver SafeBootNet:64bit: Streams Drivers - Driver Group SafeBootNet:64bit: System Bus Extender - Driver Group SafeBootNet:64bit: TBS - Service SafeBootNet:64bit: TDI - Driver Group SafeBootNet:64bit: VaultSvc - C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation) SafeBootNet:64bit: VirtualSmartcardReader - Driver SafeBootNet:64bit: vmms - Service SafeBootNet:64bit: Wcmsvc - C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation) SafeBootNet:64bit: WudfUsbccidDriver - Driver SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet:64bit: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices SafeBootNet:64bit: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdpencdd.sys - Driver SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: SmartcardSimulator - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TBS - Service SafeBootNet: TDI - Driver Group SafeBootNet: VirtualSmartcardReader - Driver SafeBootNet: vmms - Service SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices SafeBootNet: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.11.19 16:19:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameMouse Software [2012.11.18 17:57:52 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Marci´s\Desktop\OTL.exe [2012.11.18 12:46:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EA Games [2012.11.18 12:41:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome [2012.11.18 12:40:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google [2012.11.18 12:17:57 | 000,017,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msvcr100_clr0400.dll [2012.11.18 12:17:48 | 000,017,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msvcr100_clr0400.dll [2012.11.18 12:16:24 | 001,619,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll [2012.11.18 12:16:24 | 000,767,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll [2012.11.18 12:16:24 | 000,621,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll [2012.11.18 12:16:24 | 000,318,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ubpm.dll [2012.11.18 12:16:24 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll [2012.11.18 12:16:24 | 000,246,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ubpm.dll [2012.11.18 12:16:24 | 000,141,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll [2012.11.18 12:16:24 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll [2012.11.18 12:16:24 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wushareduxresources.dll [2012.11.18 12:16:24 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll [2012.11.18 12:16:24 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll [2012.11.18 12:16:24 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskhost.exe [2012.11.18 12:16:24 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskhostex.exe [2012.11.18 12:16:24 | 000,058,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe [2012.11.18 12:16:24 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll [2012.11.18 12:16:24 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll [2012.11.18 12:16:24 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe [2012.11.18 12:16:24 | 000,034,304 | ---- | C] (Microsoft Corporation) -- |
19.11.2012, 18:18 | #6 |
| Claro Search eingfangen :( Teil 2 : C:\WINDOWS\SysWow64\wuapp.exe [2012.11.18 12:16:24 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wups.dll [2012.11.18 12:16:24 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll [2012.11.18 12:16:17 | 001,526,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll [2012.11.18 12:16:17 | 001,451,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll [2012.11.18 12:16:16 | 000,522,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AUDIOKSE.dll [2012.11.18 12:16:16 | 000,490,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll [2012.11.18 12:16:16 | 000,463,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AUDIOKSE.dll [2012.11.18 12:16:16 | 000,447,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll [2012.11.18 12:16:16 | 000,267,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EncDump.dll [2012.11.18 12:16:16 | 000,253,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\audiodg.exe [2012.11.18 12:16:16 | 000,169,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll [2012.11.18 12:16:12 | 003,244,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll [2012.11.18 12:16:12 | 000,987,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srmclient.dll [2012.11.18 12:16:12 | 000,487,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srmscan.dll [2012.11.18 12:16:12 | 000,274,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srmstormod.dll [2012.11.18 12:16:12 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srmstormod.dll [2012.11.18 12:16:12 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dskquota.dll [2012.11.18 12:16:12 | 000,027,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys [2012.11.18 12:16:11 | 001,347,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srmclient.dll [2012.11.18 12:16:11 | 000,652,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srmscan.dll [2012.11.18 12:16:11 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dskquota.dll [2012.11.18 12:16:10 | 000,279,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srm.dll [2012.11.18 12:16:10 | 000,278,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srm.dll [2012.11.18 12:16:10 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll [2012.11.18 12:16:10 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srmshell.dll [2012.11.18 12:16:10 | 000,134,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adrclient.dll [2012.11.18 12:16:10 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srmshell.dll [2012.11.18 12:16:10 | 000,104,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\adrclient.dll [2012.11.18 12:16:10 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srmtrace.dll [2012.11.18 12:16:10 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srmtrace.dll [2012.11.18 12:16:10 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rfxvmt.dll [2012.11.18 12:16:10 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srm_ps.dll [2012.11.18 12:16:10 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srm_ps.dll [2012.11.18 12:15:59 | 006,972,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe [2012.11.18 12:15:59 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll [2012.11.18 12:15:59 | 000,396,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll [2012.11.18 12:15:57 | 010,096,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll [2012.11.18 12:15:56 | 008,856,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll [2012.11.18 12:15:55 | 002,302,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll [2012.11.18 12:15:55 | 002,146,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll [2012.11.18 12:15:55 | 002,033,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll [2012.11.18 12:15:55 | 000,069,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\pdc.sys [2012.11.18 12:15:37 | 001,172,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfnetsrc.dll [2012.11.18 12:15:37 | 000,929,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfnetsrc.dll [2012.11.18 12:15:37 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfasfsrcsnk.dll [2012.11.18 12:15:37 | 000,677,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfnetcore.dll [2012.11.18 12:15:37 | 000,673,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmpeg2srcsnk.dll [2012.11.18 12:15:37 | 000,568,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfnetcore.dll [2012.11.18 12:15:37 | 000,513,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmpeg2srcsnk.dll [2012.11.18 12:15:36 | 001,048,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfasfsrcsnk.dll [2012.11.18 12:14:42 | 003,554,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tquery.dll [2012.11.18 12:14:38 | 002,116,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssrch.dll [2012.11.18 12:14:36 | 002,380,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [2012.11.18 12:14:36 | 002,206,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll [2012.11.18 12:14:34 | 002,115,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe [2012.11.18 12:14:34 | 001,610,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssrch.dll [2012.11.18 12:14:34 | 001,395,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Immersive.dll [2012.11.18 12:14:33 | 001,265,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll [2012.11.18 12:14:33 | 001,226,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Immersive.dll [2012.11.18 12:14:33 | 000,793,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfplat.dll [2012.11.18 12:14:33 | 000,579,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StructuredQuery.dll [2012.11.18 12:14:32 | 001,841,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll [2012.11.18 12:14:31 | 000,590,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SHCore.dll [2012.11.18 12:14:30 | 001,403,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi [2012.11.18 12:14:30 | 000,612,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfplat.dll [2012.11.18 12:14:30 | 000,373,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchProtocolHost.exe [2012.11.18 12:14:29 | 000,594,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.dll [2012.11.18 12:14:29 | 000,517,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winlogon.exe [2012.11.18 12:14:29 | 000,441,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\netio.sys [2012.11.18 12:14:28 | 000,561,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmp4srcsnk.dll [2012.11.18 12:14:27 | 000,410,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.dll [2012.11.18 12:14:27 | 000,336,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\Classpnp.sys [2012.11.18 12:14:27 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\portcls.sys [2012.11.18 12:14:27 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Storage.Compression.dll [2012.11.18 12:14:26 | 002,764,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tquery.dll [2012.11.18 12:14:26 | 001,045,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usercpl.dll [2012.11.18 12:14:26 | 000,503,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll [2012.11.18 12:14:25 | 000,962,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\usercpl.dll [2012.11.18 12:14:25 | 000,411,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll [2012.11.18 12:14:25 | 000,244,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dhcpcore6.dll [2012.11.18 12:14:25 | 000,058,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dam.sys [2012.11.18 12:14:23 | 000,907,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uxtheme.dll [2012.11.18 12:14:23 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SpaceControl.dll [2012.11.18 12:14:23 | 000,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dhcpcore6.dll [2012.11.18 12:14:23 | 000,194,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\sdbus.sys [2012.11.18 12:14:23 | 000,124,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpsd.sys [2012.11.18 12:14:23 | 000,056,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\sdstor.sys [2012.11.18 12:14:23 | 000,033,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\battc.sys [2012.11.18 12:14:22 | 001,267,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe [2012.11.18 12:14:22 | 001,217,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi [2012.11.18 12:14:22 | 001,093,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe [2012.11.18 12:14:22 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanmsm.dll [2012.11.18 12:14:22 | 000,386,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanmsm.dll [2012.11.18 12:14:21 | 000,460,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SHCore.dll [2012.11.18 12:14:21 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\input.dll [2012.11.18 12:14:21 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFCaptureEngine.dll [2012.11.18 12:14:21 | 000,116,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Storage.Compression.dll [2012.11.18 12:14:20 | 000,945,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\resetengmig.dll [2012.11.18 12:14:20 | 000,259,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\input.dll [2012.11.18 12:14:19 | 001,009,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\reseteng.dll [2012.11.18 12:14:19 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dhcpcsvc6.dll [2012.11.18 12:14:18 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesysprep.dll [2012.11.18 12:14:17 | 000,658,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssvp.dll [2012.11.18 12:14:16 | 000,745,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssvp.dll [2012.11.18 12:14:16 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\microsoft-windows-pdc.dll [2012.11.18 12:14:15 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFCaptureEngine.dll [2012.11.18 12:14:15 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PCPKsp.dll [2012.11.18 12:14:14 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesysprep.dll [2012.11.18 12:14:13 | 003,966,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll [2012.11.18 12:14:13 | 001,294,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll [2012.11.18 12:14:13 | 000,757,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FirewallAPI.dll [2012.11.18 12:14:12 | 000,854,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll [2012.11.18 12:14:12 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll [2012.11.18 12:14:12 | 000,435,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssph.dll [2012.11.18 12:14:12 | 000,408,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssph.dll [2012.11.18 12:14:12 | 000,370,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SysFxUI.dll [2012.11.18 12:14:12 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSip.dll [2012.11.18 12:14:12 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxSip.dll [2012.11.18 12:14:11 | 001,836,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll [2012.11.18 12:14:11 | 000,446,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlansec.dll [2012.11.18 12:14:11 | 000,375,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlansec.dll [2012.11.18 12:14:11 | 000,273,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanapi.dll [2012.11.18 12:14:11 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssphtb.dll [2012.11.18 12:14:11 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanapi.dll [2012.11.18 12:14:11 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFilterHost.exe [2012.11.18 12:14:11 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sysreset.exe [2012.11.18 12:14:11 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\icfupgd.dll [2012.11.18 12:14:11 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PCPKsp.dll [2012.11.18 12:14:11 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UXInit.dll [2012.11.18 12:14:11 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe [2012.11.18 12:14:11 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BdeUISrv.exe [2012.11.18 12:14:11 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UXInit.dll [2012.11.18 12:14:11 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iernonce.dll [2012.11.18 12:14:11 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iernonce.dll [2012.11.18 12:14:10 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssitlb.dll [2012.11.18 12:14:10 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssprxy.dll [2012.11.18 12:14:10 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssitlb.dll [2012.11.18 12:14:10 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msscntrs.dll [2012.11.18 12:14:10 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wfdprov.dll [2012.11.18 12:14:09 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesetup.dll [2012.11.18 12:14:09 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msscntrs.dll [2012.11.18 12:14:09 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wfdprov.dll [2012.11.18 12:14:09 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wfapigp.dll [2012.11.18 12:14:09 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wfapigp.dll [2012.11.18 12:14:08 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesetup.dll [2012.11.18 12:14:08 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msshooks.dll [2012.11.18 12:14:07 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\drmk.sys [2012.11.18 12:14:07 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msshooks.dll [2012.11.18 12:14:07 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanhlp.dll [2012.11.18 12:14:07 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanhlp.dll [2012.11.18 12:14:07 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kbdhebl3.dll [2012.11.18 12:14:07 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\kbdhebl3.dll [2012.11.17 22:33:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} [2012.11.17 14:29:03 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\Desktop\BORS [2012.11.17 12:47:45 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\AppData\Roaming\Avira [2012.11.17 12:40:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2012.11.17 12:39:52 | 000,129,216 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\SysNative\drivers\avipbb.sys [2012.11.17 12:39:52 | 000,098,888 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\SysNative\drivers\avgntflt.sys [2012.11.17 12:39:52 | 000,027,800 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\SysNative\drivers\avkmgr.sys [2012.11.17 12:39:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2012.11.17 12:39:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira [2012.11.15 22:01:11 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\AppData\Local\Freetec [2012.11.15 22:00:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SelfUpdater [2012.11.14 14:19:36 | 000,371,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgent.dll [2012.11.14 14:19:35 | 000,439,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgent.dll [2012.11.14 14:19:35 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgentc.exe [2012.11.14 14:19:35 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgentc.exe [2012.11.14 13:53:50 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\synceng.dll [2012.11.14 13:53:50 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\synceng.dll [2012.11.11 15:47:30 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\Documents\GameMouseSetting [2012.11.11 15:47:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Goeasily [2012.11.11 01:56:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Synaptics [2012.11.11 01:51:35 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics [2012.11.11 01:22:28 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\AppData\Roaming\Synaptics [2012.11.08 21:25:39 | 000,019,000 | ---- | C] (PerformerSoft LLC) -- C:\WINDOWS\SysNative\roboot64.exe [2012.11.08 21:25:39 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\AppData\Roaming\PerformerSoft [2012.11.08 21:25:15 | 000,327,749 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\SysWow64\drvc.dll [2012.11.08 21:24:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eRightSoft [2012.11.08 18:07:36 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\dwhelper [2012.11.08 18:05:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service [2012.11.07 19:29:29 | 000,695,648 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe [2012.11.07 19:29:29 | 000,080,728 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl [2012.11.07 19:22:30 | 000,000,000 | R--D | C] -- C:\WINDOWS\BrowserChoice [2012.11.05 17:16:40 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\Desktop\Tagesberichte [2012.11.04 19:30:50 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\AppData\Local\Deployment [2012.11.04 17:46:55 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\newdev.dll [2012.11.04 17:46:55 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\newdev.dll [2012.11.04 17:46:55 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\newdev.exe [2012.11.04 17:46:55 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ndadmin.exe [2012.11.04 17:46:55 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\newdev.exe [2012.11.04 17:46:55 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ndadmin.exe [2012.11.04 17:46:54 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wwanprotdim.dll [2012.11.04 17:46:22 | 013,640,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll [2012.11.04 17:46:22 | 002,367,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSService.dll [2012.11.04 17:46:12 | 003,265,256 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\SysNative\drivers\evbda.sys [2012.11.04 17:46:09 | 014,259,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmp.dll [2012.11.04 17:46:08 | 010,791,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll [2012.11.04 17:46:06 | 001,131,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll [2012.11.04 17:46:04 | 002,397,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WpcMon.exe [2012.11.04 17:46:02 | 003,847,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d2d1.dll [2012.11.04 17:46:00 | 003,964,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinSAT.exe [2012.11.04 17:45:59 | 011,875,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wmp.dll [2012.11.04 17:45:57 | 000,533,224 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\SysNative\drivers\bxvbda.sys [2012.11.04 17:45:56 | 001,513,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vssapi.dll [2012.11.04 17:45:54 | 001,825,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll [2012.11.04 17:45:47 | 001,739,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RacEngn.dll [2012.11.04 17:45:47 | 001,019,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MsSpellCheckingFacility.dll [2012.11.04 17:45:46 | 002,219,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d10warp.dll [2012.11.04 17:45:45 | 001,304,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Streaming.dll [2012.11.04 17:45:45 | 001,096,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpmde.dll [2012.11.04 17:45:44 | 000,762,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provcore.dll [2012.11.04 17:45:44 | 000,757,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uDWM.dll [2012.11.04 17:45:44 | 000,389,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MMDevAPI.dll [2012.11.04 17:45:41 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncsi.dll [2012.11.04 17:45:34 | 000,543,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlroamextension.dll [2012.11.04 17:45:33 | 001,145,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmde.dll [2012.11.04 17:45:33 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinSATAPI.dll [2012.11.04 17:45:30 | 000,995,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Streaming.dll [2012.11.04 17:45:30 | 000,488,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbport.sys [2012.11.04 17:45:29 | 001,590,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsCodecs.dll [2012.11.04 17:45:29 | 000,634,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\apphelp.dll [2012.11.04 17:45:29 | 000,468,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFMediaEngine.dll [2012.11.04 17:45:29 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IPHLPAPI.DLL [2012.11.04 17:45:28 | 000,709,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MsSpellCheckingFacility.dll [2012.11.04 17:45:27 | 001,743,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\combase.dll [2012.11.04 17:45:27 | 000,236,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFPlay.dll [2012.11.04 17:45:24 | 000,604,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dnsapi.dll [2012.11.04 17:45:24 | 000,420,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WWAHost.exe [2012.11.04 17:45:23 | 000,866,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinTypes.dll [2012.11.04 17:45:23 | 000,755,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveapi.dll [2012.11.04 17:45:23 | 000,640,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll [2012.11.04 17:45:23 | 000,631,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserLanguagesCpl.dll [2012.11.04 17:45:23 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rascfg.dll [2012.11.04 17:45:22 | 000,702,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drvstore.dll [2012.11.04 17:45:22 | 000,617,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsrcsnk.dll [2012.11.04 17:45:22 | 000,545,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskeng.exe [2012.11.04 17:45:22 | 000,355,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsvr.dll [2012.11.04 17:45:22 | 000,344,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidcredprov.dll [2012.11.04 17:45:22 | 000,180,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdsrv.dll [2012.11.04 17:45:22 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rascfg.dll [2012.11.04 17:45:21 | 001,400,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\propsys.dll [2012.11.04 17:45:21 | 000,337,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBXHCI.SYS [2012.11.04 17:45:21 | 000,332,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wintrust.dll [2012.11.04 17:45:21 | 000,249,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpnprv.dll [2012.11.04 17:45:19 | 000,541,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VAN.dll [2012.11.04 17:45:19 | 000,445,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBHUB3.SYS [2012.11.04 17:45:19 | 000,410,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlroamextension.dll [2012.11.04 17:45:19 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WinSATAPI.dll [2012.11.04 17:45:19 | 000,203,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSClient.dll [2012.11.04 17:45:18 | 000,410,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\services.exe [2012.11.04 17:45:18 | 000,240,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveapibase.dll [2012.11.04 17:45:17 | 000,891,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmde.dll [2012.11.04 17:45:17 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\appwiz.cpl [2012.11.04 17:45:17 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFMediaEngine.dll [2012.11.04 17:45:17 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bisrv.dll [2012.11.04 17:45:17 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\psmsrv.dll [2012.11.04 17:45:16 | 000,707,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.dll [2012.11.04 17:45:16 | 000,291,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.Connectivity.dll [2012.11.04 17:45:16 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vdsutil.dll [2012.11.04 17:45:16 | 000,177,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSSync.dll [2012.11.04 17:45:16 | 000,028,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\msgpiowin32.sys [2012.11.04 17:45:15 | 000,548,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\drvstore.dll [2012.11.04 17:45:15 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll [2012.11.04 17:45:15 | 000,333,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WWAHost.exe [2012.11.04 17:45:15 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhengine.dll [2012.11.04 17:45:15 | 000,166,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSClient.dll [2012.11.04 17:45:15 | 000,120,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\msgpioclx.sys [2012.11.04 17:45:14 | 000,670,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\appwiz.cpl [2012.11.04 17:45:14 | 000,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFPlay.dll [2012.11.04 17:45:14 | 000,154,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSSync.dll [2012.11.04 17:45:14 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PackageStateRoaming.dll [2012.11.04 17:45:13 | 001,369,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\RacEngn.dll [2012.11.04 17:45:13 | 000,457,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpncore.dll [2012.11.04 17:45:13 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmredir.dll [2012.11.04 17:45:12 | 000,390,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.BackgroundTransfer.dll [2012.11.04 17:45:12 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TpmTasks.dll [2012.11.04 17:45:11 | 000,228,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ProximityService.dll [2012.11.04 17:45:10 | 000,533,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\provcore.dll [2012.11.04 17:45:10 | 000,256,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msvproc.dll [2012.11.04 17:45:10 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PackageStateRoaming.dll [2012.11.04 17:45:09 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\setbcdlocale.dll [2012.11.04 17:45:08 | 000,509,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinapi.dll [2012.11.04 17:45:08 | 000,480,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VAN.dll [2012.11.04 17:45:08 | 000,027,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\avrt.dll [2012.11.04 17:45:07 | 001,247,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\combase.dll [2012.11.04 17:45:07 | 000,449,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsrcsnk.dll [2012.11.04 17:45:07 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\microsoft-windows-kernel-power-events.dll [2012.11.04 17:45:07 | 000,062,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpfve.sys [2012.11.04 17:45:06 | 002,016,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\batmeter.dll [2012.11.04 17:45:06 | 002,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\batmeter.dll [2012.11.04 17:45:06 | 000,560,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserLanguagesCpl.dll [2012.11.04 17:45:06 | 000,411,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS [2012.11.04 17:45:06 | 000,148,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\tpm.sys [2012.11.04 17:45:06 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncHost.exe [2012.11.04 17:45:06 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\perfdisk.dll [2012.11.04 17:45:05 | 000,303,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms1.sys [2012.11.04 17:45:04 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WinTypes.dll [2012.11.04 17:45:04 | 000,212,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UCX01000.SYS [2012.11.04 17:45:04 | 000,021,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbd.sys [2012.11.04 17:45:03 | 000,270,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsvr.dll [2012.11.04 17:45:03 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\perfdisk.dll [2012.11.04 17:45:03 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\svchost.exe [2012.11.04 17:45:02 | 000,263,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlidcredprov.dll [2012.11.04 17:45:02 | 000,195,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.Connectivity.dll [2012.11.04 17:45:02 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhevents.dll [2012.11.04 17:45:01 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.BackgroundTransfer.dll [2012.11.04 17:45:00 | 001,342,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\user32.dll [2012.11.04 17:45:00 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storewuauth.dll [2012.11.04 17:44:59 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winsrv.dll [2012.11.04 17:44:58 | 000,437,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfh264enc.dll [2012.11.04 17:44:58 | 000,413,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfh264enc.dll [2012.11.04 17:44:58 | 000,214,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msvproc.dll [2012.11.04 17:44:58 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncHost.exe [2012.11.04 17:44:58 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\perfnet.dll [2012.11.04 17:44:57 | 000,699,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinapi.dll [2012.11.04 17:44:57 | 000,627,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lpksetup.exe [2012.11.04 17:44:57 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DevPropMgr.dll [2012.11.04 17:44:56 | 000,281,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfreadwrite.dll [2012.11.04 17:44:56 | 000,214,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfreadwrite.dll [2012.11.04 17:44:56 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.dll [2012.11.04 17:44:56 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwm.exe [2012.11.04 17:44:56 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\drvinst.exe [2012.11.04 17:44:55 | 000,315,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhcfg.dll [2012.11.04 17:44:54 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drvinst.exe [2012.11.04 17:44:53 | 000,459,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxgi.dll [2012.11.04 17:44:52 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DAFWSD.dll [2012.11.04 17:44:51 | 002,066,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d11.dll [2012.11.04 17:44:51 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhsrchapi.dll [2012.11.04 17:44:51 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\perfnet.dll [2012.11.04 17:44:50 | 001,701,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3d11.dll [2012.11.04 17:44:50 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll [2012.11.04 17:44:49 | 000,588,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\webio.dll [2012.11.04 17:44:49 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\perfos.dll [2012.11.04 17:44:49 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll [2012.11.04 17:44:48 | 000,417,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\webio.dll [2012.11.04 17:44:48 | 000,280,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhcat.dll [2012.11.04 17:44:48 | 000,178,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemEventsBrokerServer.dll [2012.11.04 17:44:48 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CscMig.dll [2012.11.04 17:44:48 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhsvc.dll [2012.11.04 17:44:47 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TimeBrokerServer.dll [2012.11.04 17:44:47 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.dll [2012.11.04 17:44:47 | 000,126,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WcnApi.dll [2012.11.04 17:44:47 | 000,110,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dafWCN.dll [2012.11.04 17:44:47 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WcnApi.dll [2012.11.04 17:44:47 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lpremove.exe [2012.11.04 17:44:46 | 000,163,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sspicli.dll [2012.11.04 17:44:46 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhshl.dll [2012.11.04 17:44:46 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rasdiag.dll [2012.11.04 17:44:46 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cryptdlg.dll [2012.11.04 17:44:45 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhmanagew.exe [2012.11.04 17:44:45 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasdiag.dll [2012.11.04 17:44:45 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhlisten.dll [2012.11.04 17:44:45 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\cryptdlg.dll [2012.11.04 17:44:44 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fdWCN.dll [2012.11.04 17:44:44 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vsstrace.dll [2012.11.04 17:44:44 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhsrchph.dll [2012.11.04 17:44:44 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhcleanup.dll [2012.11.04 17:44:44 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sdbinst.exe [2012.11.04 17:44:43 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasmxs.dll [2012.11.04 17:44:43 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhtask.dll [2012.11.04 17:44:43 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WcnEapAuthProxy.dll [2012.11.04 17:44:43 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sdbinst.exe [2012.11.04 17:44:43 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vdsldr.exe [2012.11.04 17:44:42 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhautoplay.dll [2012.11.04 17:44:42 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ndptsp.tsp [2012.11.04 17:44:42 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rasmxs.dll [2012.11.04 17:44:42 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WcnEapPeerProxy.dll [2012.11.04 17:44:41 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ndptsp.tsp [2012.11.04 17:44:41 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\perfctrs.dll [2012.11.04 17:44:41 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\perfctrs.dll [2012.11.04 17:44:41 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\perfproc.dll [2012.11.04 17:44:41 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasser.dll [2012.11.04 17:44:41 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rasser.dll [2012.11.04 17:44:40 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\perfproc.dll [2012.11.04 17:44:40 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\perfos.dll [2012.11.04 17:44:39 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kmddsp.tsp [2012.11.04 17:44:39 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\kmddsp.tsp [2012.11.04 17:44:39 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sspisrv.dll [2012.11.04 17:44:39 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhsvcctl.dll [2012.11.04 17:44:39 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eventcls.dll [2012.11.04 17:44:39 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eventcls.dll [2012.11.04 17:44:38 | 000,120,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vds_ps.dll [2012.11.04 17:44:38 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\vds_ps.dll [2012.11.04 17:44:38 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LangCleanupSysprepAction.dll [2012.11.04 17:44:36 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MUILanguageCleanup.dll [2012.11.04 17:44:35 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spwmp.dll [2012.11.04 17:44:35 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\spwmp.dll [2012.11.04 17:44:35 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lpksetupproxyserv.dll [2012.11.04 17:44:35 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shimeng.dll [2012.11.04 17:44:35 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msdxm.ocx [2012.11.04 17:44:35 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxmasf.dll [2012.11.04 17:44:34 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cdd.dll [2012.11.04 17:44:34 | 000,031,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\BthAvrcpTg.sys [2012.11.04 17:44:34 | 000,029,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\BthhfHid.sys [2012.11.04 17:44:34 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\BtaMPM.sys [2012.11.04 17:44:34 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msdxm.ocx [2012.11.04 17:44:34 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dxmasf.dll [2012.11.04 17:44:33 | 009,374,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wmploc.DLL [2012.11.04 17:44:33 | 009,374,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmploc.DLL [2012.11.04 17:40:24 | 002,893,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msmpeg2vdec.dll [2012.11.04 17:40:24 | 002,400,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msmpeg2vdec.dll [2012.11.04 15:20:14 | 000,000,000 | ---D | C] -- C:\ProgramData\PRICache [2012.11.04 15:20:14 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\AppData\Local\Packages [2012.11.04 15:11:57 | 000,000,000 | R--D | C] -- C:\Users\Marci´s\Pictures [2012.11.04 15:06:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC [2012.11.04 14:52:24 | 000,000,000 | --SD | C] -- C:\Users\Marci´s\AppData\Roaming\Microsoft [2012.11.04 14:52:24 | 000,000,000 | R--D | C] -- C:\Users\Marci´s\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [2012.11.04 14:52:24 | 000,000,000 | R--D | C] -- C:\Users\Marci´s\Favorites [2012.11.04 14:52:24 | 000,000,000 | R--D | C] -- C:\Users\Marci´s\Desktop [2012.11.04 14:52:24 | 000,000,000 | R--D | C] -- C:\Users\Marci´s\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2012.11.04 14:52:24 | 000,000,000 | R--D | C] -- C:\Users\Marci´s\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Vorlagen [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\AppData\Local\Verlauf [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\AppData\Local\Temporary Internet Files [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Startmenü [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\SendTo [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Recent [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Netzwerkumgebung [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Lokale Einstellungen [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Documents\Eigene Videos [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Documents\Eigene Musik [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Eigene Dateien [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Documents\Eigene Bilder [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Druckumgebung [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Cookies [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\AppData\Local\Anwendungsdaten [2012.11.04 14:52:24 | 000,000,000 | -HSD | C] -- C:\Users\Marci´s\Anwendungsdaten [2012.11.04 14:52:24 | 000,000,000 | -H-D | C] -- C:\Users\Marci´s\AppData [2012.11.04 14:52:24 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\AppData\Local\Temp [2012.11.04 14:52:24 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\AppData\Local\Microsoft [2012.11.04 14:52:24 | 000,000,000 | ---D | C] -- C:\Users\Marci´s\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2012.11.04 14:47:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\RTCOM [2012.11.04 14:47:05 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek [2012.11.04 14:46:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch [2012.11.04 14:44:04 | 000,000,000 | ---D | C] -- C:\Windows.old [2012.11.04 14:41:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies [2012.11.04 14:41:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild [2012.11.04 14:41:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\XPSViewer [2012.11.04 14:41:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\BestPractices [2012.11.04 14:41:04 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies [2012.11.04 14:41:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\msmq [2012.11.04 14:41:04 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild [2012.11.04 14:41:04 | 000,000,000 | ---D | C] -- C:\inetpub [2012.11.04 14:41:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\BestPractices [2012.11.04 14:39:58 | 001,166,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationNative_v0300.dll [2012.11.04 14:39:56 | 000,124,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationCFFRasterizerNative_v0300.dll [2012.11.04 14:39:56 | 000,035,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TsWpfWrp.exe [2012.11.04 14:39:54 | 000,102,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationCFFRasterizerNative_v0300.dll [2012.11.04 14:39:54 | 000,035,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TsWpfWrp.exe [2012.11.04 14:39:53 | 000,778,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationNative_v0300.dll [2012.11.04 14:00:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther [2012.11.04 12:48:47 | 000,000,000 | RH-D | C] -- C:\ESD [2012.11.02 12:25:52 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\sun [2012.10.31 19:12:13 | 000,157,680 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\SysWow64\javaws.exe [2012.10.31 19:12:13 | 000,149,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\SysWow64\javaw.exe [2012.10.31 19:12:13 | 000,149,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\SysWow64\java.exe [34 C:\WINDOWS\SysWow64\*.tmp files -> C:\WINDOWS\SysWow64\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.11.19 17:45:00 | 000,001,154 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012.11.19 17:42:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012.11.19 16:19:50 | 000,000,956 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GameMouseLive.lnk [2012.11.19 15:46:06 | 000,001,150 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012.11.19 15:45:33 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012.11.18 18:17:39 | 002,029,610 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI [2012.11.18 18:17:39 | 000,864,720 | ---- | M] () -- C:\WINDOWS\SysNative\perfh007.dat [2012.11.18 18:17:39 | 000,802,780 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat [2012.11.18 18:17:39 | 000,197,242 | ---- | M] () -- C:\WINDOWS\SysNative\perfc007.dat [2012.11.18 18:17:39 | 000,165,598 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat [2012.11.18 18:11:18 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys [2012.11.18 18:11:05 | 3111,460,864 | -HS- | M] () -- C:\hiberfil.sys [2012.11.18 17:57:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Marci´s\Desktop\OTL.exe [2012.11.18 14:05:23 | 000,076,888 | ---- | M] () -- C:\WINDOWS\SysWow64\PnkBstrA.exe [2012.11.18 14:05:16 | 000,282,104 | ---- | M] () -- C:\WINDOWS\SysWow64\PnkBstrB.xtr [2012.11.18 14:05:16 | 000,282,104 | ---- | M] () -- C:\WINDOWS\SysWow64\PnkBstrB.exe [2012.11.18 13:59:04 | 000,002,249 | ---- | M] () -- C:\Users\Marci´s\Desktop\Google Chrome.lnk [2012.11.17 23:36:41 | 000,316,200 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT [2012.11.17 23:33:15 | 000,541,569 | ---- | M] () -- C:\Users\Marci´s\Desktop\adwcleaner_2.0.0.7.exe [2012.11.17 12:40:14 | 000,002,034 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk [2012.11.15 22:00:56 | 000,002,521 | ---- | M] () -- C:\Users\Public\Desktop\Freetec TubeBox.lnk [2012.11.11 15:30:16 | 000,030,160 | ---- | M] () -- C:\Users\Marci´s\Desktop\Textbeschreibung.odt [2012.11.11 01:51:37 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_Smb_driver_Intel_01009.Wdf [2012.11.08 18:05:25 | 000,001,155 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2012.11.07 19:28:51 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf [2012.11.07 16:03:24 | 000,129,216 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\SysNative\drivers\avipbb.sys [2012.11.07 16:03:24 | 000,098,888 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\SysNative\drivers\avgntflt.sys [2012.11.04 15:38:09 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf [2012.11.04 15:12:45 | 000,020,958 | ---- | M] () -- C:\WINDOWS\diagwrn.xml [2012.11.04 15:12:45 | 000,020,958 | ---- | M] () -- C:\WINDOWS\diagerr.xml [2012.11.04 15:12:25 | 000,022,960 | ---- | M] () -- C:\WINDOWS\SysNative\emptyregdb.dat [2012.11.04 14:51:11 | 001,968,878 | ---- | M] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI [2012.11.04 14:47:41 | 000,000,000 | ---- | M] () -- C:\WINDOWS\SysNative\atiicdxx.dat [2012.11.04 14:47:40 | 000,000,000 | ---- | M] () -- C:\WINDOWS\ativpsrm.bin [2012.11.04 14:13:28 | 000,024,656 | -H-- | M] () -- C:\WINDOWS\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.11.04 14:13:28 | 000,024,656 | -H-- | M] () -- C:\WINDOWS\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.11.04 13:41:58 | 000,001,108 | ---- | M] () -- C:\WINDOWS\wininit.ini [2012.11.03 12:14:27 | 000,000,017 | ---- | M] () -- C:\WINDOWS\SysWow64\shortcut_ex.dat [2012.11.02 16:31:49 | 000,000,724 | ---- | M] () -- C:\Users\Marci´s\Desktop\.minecraft.lnk [2012.11.02 12:25:15 | 000,001,203 | ---- | M] () -- C:\Users\Marci´s\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2012.11.02 08:07:58 | 000,058,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe [2012.11.02 06:22:08 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe [2012.11.02 06:21:44 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll [2012.11.02 06:21:44 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll [2012.11.02 06:21:44 | 000,018,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wups.dll [2012.11.02 06:21:43 | 000,621,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll [2012.11.02 06:21:28 | 000,246,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ubpm.dll [2012.11.02 06:20:31 | 000,039,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe [2012.11.02 06:20:28 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskhost.exe [2012.11.02 06:20:28 | 000,072,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskhostex.exe [2012.11.02 06:20:10 | 000,141,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll [2012.11.02 06:20:09 | 001,619,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll [2012.11.02 06:20:09 | 000,767,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll [2012.11.02 06:20:09 | 000,251,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll [2012.11.02 06:20:09 | 000,098,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll [2012.11.02 06:20:09 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll [2012.11.02 06:20:09 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll [2012.11.02 06:20:09 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll [2012.11.02 06:19:50 | 000,318,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ubpm.dll [2012.11.02 06:01:27 | 000,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wushareduxresources.dll [2012.11.01 11:19:56 | 000,000,000 | ---- | M] () -- C:\WINDOWS\SysWow64\config.nt [2012.10.31 19:06:24 | 001,689,625 | ---- | M] () -- C:\Users\Marci´s\Desktop\mcpatcher-2.4.3_02.exe [2012.10.30 23:51:55 | 000,984,144 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSnx.sys [2012.10.30 23:51:55 | 000,370,288 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSP.sys [2012.10.30 23:51:55 | 000,071,600 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswMonFlt.sys [2012.10.30 23:51:53 | 000,025,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswFsBlk.sys [2012.10.30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012.10.30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysWow64\aswBoot.exe [2012.10.30 23:50:30 | 000,285,328 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe [2012.10.29 06:04:47 | 000,522,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AUDIOKSE.dll [2012.10.29 06:04:47 | 000,490,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll [2012.10.29 06:04:47 | 000,447,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll [2012.10.29 06:04:47 | 000,253,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\audiodg.exe [2012.10.29 04:21:53 | 001,526,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll [2012.10.29 04:21:21 | 000,267,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EncDump.dll [2012.10.29 04:20:49 | 000,169,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll [2012.10.29 04:19:08 | 000,463,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AUDIOKSE.dll [2012.10.29 03:46:23 | 001,451,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll [2012.10.26 23:19:09 | 000,695,648 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe [2012.10.26 23:19:09 | 000,080,728 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl [2012.10.24 05:54:06 | 006,972,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe [2012.10.24 05:54:04 | 000,396,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll [2012.10.24 04:25:41 | 000,026,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgentc.exe [2012.10.24 04:24:42 | 000,439,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgent.dll [2012.10.24 04:24:12 | 000,603,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll [2012.10.24 03:48:12 | 000,024,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgentc.exe [2012.10.24 03:47:29 | 000,371,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgent.dll [34 C:\WINDOWS\SysWow64\*.tmp files -> C:\WINDOWS\SysWow64\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.11.19 16:19:50 | 000,000,956 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GameMouseLive.lnk [2012.11.18 13:59:04 | 000,002,249 | ---- | C] () -- C:\Users\Marci´s\Desktop\Google Chrome.lnk [2012.11.18 12:40:13 | 000,001,154 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012.11.18 12:40:12 | 000,001,150 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012.11.17 23:36:24 | 000,316,200 | ---- | C] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT [2012.11.17 23:33:15 | 000,541,569 | ---- | C] () -- C:\Users\Marci´s\Desktop\adwcleaner_2.0.0.7.exe [2012.11.17 12:40:14 | 000,002,034 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk [2012.11.15 22:00:56 | 000,002,521 | ---- | C] () -- C:\Users\Public\Desktop\Freetec TubeBox.lnk [2012.11.13 17:52:16 | 000,000,866 | ---- | C] () -- C:\Users\Marci´s\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\lol.lnk [2012.11.11 15:47:31 | 000,007,680 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\qxkjvk.sys [2012.11.11 01:51:37 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_Smb_driver_Intel_01009.Wdf [2012.11.10 17:34:35 | 000,030,160 | ---- | C] () -- C:\Users\Marci´s\Desktop\Textbeschreibung.odt [2012.11.08 18:05:25 | 000,001,167 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2012.11.08 18:05:25 | 000,001,155 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2012.11.07 19:28:51 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf [2012.11.04 17:45:18 | 000,361,934 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml [2012.11.04 17:44:44 | 000,110,592 | ---- | C] () -- C:\WINDOWS\SysNative\OEMLicense.dll [2012.11.04 17:44:44 | 000,083,968 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll [2012.11.04 15:38:09 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf [2012.11.04 15:21:25 | 000,001,446 | ---- | C] () -- C:\Users\Marci´s\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2012.11.04 15:12:25 | 000,022,960 | ---- | C] () -- C:\WINDOWS\SysNative\emptyregdb.dat [2012.11.04 14:56:44 | 000,020,958 | ---- | C] () -- C:\WINDOWS\diagwrn.xml [2012.11.04 14:56:44 | 000,020,958 | ---- | C] () -- C:\WINDOWS\diagerr.xml [2012.11.04 14:51:11 | 001,968,878 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI [2012.11.04 14:47:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SysNative\atiicdxx.dat [2012.11.04 14:47:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin [2012.11.04 14:45:12 | 268,435,456 | -HS- | C] () -- C:\swapfile.sys [2012.11.03 12:14:27 | 000,000,017 | ---- | C] () -- C:\WINDOWS\SysWow64\shortcut_ex.dat [2012.11.02 12:48:31 | 000,000,724 | ---- | C] () -- C:\Users\Marci´s\Desktop\.minecraft.lnk [2012.11.02 12:25:15 | 000,001,203 | ---- | C] () -- C:\Users\Marci´s\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2012.10.31 19:06:27 | 001,689,625 | ---- | C] () -- C:\Users\Marci´s\Desktop\mcpatcher-2.4.3_02.exe [2012.08.10 19:20:13 | 000,000,034 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2012.07.26 09:13:10 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat [2012.07.26 09:13:09 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT [2012.07.26 08:21:26 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2012.07.26 02:17:42 | 000,043,520 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll [2012.07.25 21:37:29 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin [2012.07.25 21:28:31 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll [2012.06.02 15:31:19 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat [2012.05.19 15:44:11 | 000,000,010 | ---- | C] () -- C:\WINDOWS\popcinfo.dat [2012.04.03 15:03:03 | 000,000,087 | ---- | C] () -- C:\WINDOWS\AutoScreenRecorder.INI [2012.03.24 14:18:36 | 000,282,104 | ---- | C] () -- C:\WINDOWS\SysWow64\PnkBstrB.exe [2012.03.24 14:18:09 | 000,076,888 | ---- | C] () -- C:\WINDOWS\SysWow64\PnkBstrA.exe [2012.02.29 20:26:36 | 000,042,392 | ---- | C] () -- C:\WINDOWS\SysWow64\xfcodec.dll [2012.02.17 00:14:14 | 000,104,552 | -H-- | C] () -- C:\WINDOWS\SysWow64\mlfcache.dat [2012.02.16 14:02:02 | 000,111,104 | ---- | C] () -- C:\WINDOWS\SysWow64\Uharc.exe [2012.02.16 14:02:02 | 000,008,636 | ---- | C] () -- C:\WINDOWS\SysWow64\modifype.exe [2012.02.16 12:27:19 | 000,925,184 | ---- | C] () -- C:\WINDOWS\expstart.exe [2012.02.15 14:06:50 | 000,001,108 | ---- | C] () -- C:\WINDOWS\wininit.ini [2012.01.03 21:29:48 | 000,032,256 | ---- | C] () -- C:\WINDOWS\SysWow64\AVSredirect.dll [2011.12.14 17:53:23 | 000,000,856 | ---- | C] () -- C:\WINDOWS\client.config.ini [2011.12.07 13:53:52 | 000,000,385 | ---- | C] () -- C:\WINDOWS\hpwmdl27.dat.temp [2011.12.07 13:34:42 | 000,197,085 | ---- | C] () -- C:\WINDOWS\hpwins27.dat [2011.10.19 23:43:24 | 000,000,267 | ---- | C] () -- C:\WINDOWS\LaunApp.ini [2011.10.19 23:40:24 | 000,001,461 | ---- | C] () -- C:\WINDOWS\WPatchProgress.ini [2011.08.29 11:35:01 | 000,000,325 | ---- | C] () -- C:\WINDOWS\Prelaunch.ini [2011.08.29 11:35:01 | 000,000,271 | ---- | C] () -- C:\WINDOWS\WisPriority.ini [2011.08.29 11:35:01 | 000,000,119 | ---- | C] () -- C:\WINDOWS\WisLangCode.ini ========== ZeroAccess Check ========== [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.10.11 06:45:39 | 019,789,824 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.10.11 06:07:29 | 017,560,576 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012.07.26 04:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2012.07.26 04:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012.07.26 04:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2012.11.18 12:38:22 | 000,000,000 | ---D | M] -- C:\Users\Administrator.Marci´s-Laptop\AppData\Roaming\Synaptics [2012.11.04 18:09:55 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\.minecraft [2012.04.05 11:42:30 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\.Nitrous [2012.03.31 09:02:53 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\CrystalIdea Software [2012.10.01 15:11:43 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\DVDVideoSoft [2012.10.01 15:11:05 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\DVDVideoSoftIEHelpers [2012.01.06 15:36:40 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Floodlight Games [2012.09.07 13:24:32 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\FOG Downloader [2012.05.10 05:41:12 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Freemium [2012.01.04 22:52:19 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\funkitron [2011.03.10 22:02:50 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\jar files [2011.12.03 16:11:42 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Jens Lorek [2012.01.20 15:06:22 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\LolClient [2012.02.23 17:00:22 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Need for Speed World [2011.11.27 18:51:05 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\OpenOffice.org [2012.09.12 13:08:19 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Origin [2012.11.10 21:19:34 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\PerformerSoft [2011.08.16 18:10:42 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\planes [2011.03.10 22:02:56 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\resource files [2011.11.04 14:15:08 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\runic games [2011.11.10 13:37:36 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\SNS [2012.11.05 18:46:58 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\SoftGrid Client [2012.11.11 01:22:28 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Synaptics [2011.10.31 22:44:48 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Tific [2012.02.29 13:55:54 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\TP [2012.10.10 16:51:35 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\TS3Client [2011.12.27 21:13:34 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\TuneUp Software [2012.09.20 19:30:08 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Unity [2012.08.28 21:27:23 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\WildTangent [2012.01.06 15:30:59 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\WildTangentv1001 [2012.01.24 14:45:31 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Windows Live Writer ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2012.11.18 12:38:23 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2012.11.04 14:43:41 | 000,000,000 | -H-D | M] -- C:\$WINDOWS.~BT [2011.10.19 14:31:10 | 000,000,000 | ---D | M] -- C:\BOOK [2012.11.18 12:45:01 | 000,000,000 | -H-D | M] -- C:\Config.Msi [2012.07.26 08:22:08 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2011.10.22 14:47:47 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2012.11.04 12:48:47 | 000,000,000 | RH-D | M] -- C:\ESD [2012.09.28 15:29:51 | 000,000,000 | ---D | M] -- C:\Fraps [2012.11.04 14:41:04 | 000,000,000 | ---D | M] -- C:\inetpub [2011.10.19 14:03:25 | 000,000,000 | ---D | M] -- C:\Intel [2012.05.22 14:47:46 | 000,000,000 | RH-D | M] -- C:\MSOCache [2011.10.19 14:30:06 | 000,000,000 | -H-D | M] -- C:\OEM [2012.07.26 08:33:46 | 000,000,000 | ---D | M] -- C:\PerfLogs [2012.11.11 01:51:35 | 000,000,000 | R--D | M] -- C:\Program Files [2012.11.18 12:46:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86) [2012.11.17 23:50:10 | 000,000,000 | -H-D | M] -- C:\ProgramData [2011.10.22 14:47:47 | 000,000,000 | -HSD | M] -- C:\Programme [2012.11.04 15:13:26 | 000,000,000 | -HSD | M] -- C:\Recovery [2012.11.19 18:00:50 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2012.11.18 12:35:02 | 000,000,000 | R--D | M] -- C:\Users [2012.11.18 17:40:28 | 000,000,000 | ---D | M] -- C:\Windows [2012.11.04 14:44:04 | 000,000,000 | ---D | M] -- C:\Windows.old < %SYSTEMDRIVE%\*.* > [2012.11.17 23:33:39 | 000,022,868 | ---- | M] () -- C:\AdwCleaner[R1].txt [2012.11.17 23:47:14 | 000,002,277 | ---- | M] () -- C:\AdwCleaner[R2].txt [2012.11.18 17:37:36 | 000,002,296 | ---- | M] () -- C:\AdwCleaner[R3].txt [2012.11.18 19:14:21 | 000,002,126 | ---- | M] () -- C:\AdwCleaner[R4].txt [2012.11.17 23:34:48 | 000,022,510 | ---- | M] () -- C:\AdwCleaner[S1].txt [2012.11.17 23:47:47 | 000,002,345 | ---- | M] () -- C:\AdwCleaner[S2].txt [2012.11.18 17:39:16 | 000,002,358 | ---- | M] () -- C:\AdwCleaner[S4].txt [2012.11.18 18:10:23 | 000,002,416 | ---- | M] () -- C:\AdwCleaner[S5].txt [2010.11.21 04:23:51 | 000,383,786 | RHS- | M] () -- C:\bootmgr [2012.06.02 15:30:55 | 000,000,001 | -HS- | M] () -- C:\BOOTNXT [2011.02.15 01:54:06 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK [2012.10.01 16:09:09 | 000,000,009 | ---- | M] () -- C:\END [2012.11.18 18:11:05 | 3111,460,864 | -HS- | M] () -- C:\hiberfil.sys [2011.12.18 22:30:35 | 000,000,040 | ---- | M] () -- C:\log.txt [2012.11.18 18:11:13 | 4160,749,568 | -HS- | M] () -- C:\pagefile.sys [2011.04.20 04:38:57 | 000,001,575 | RHS- | M] () -- C:\Patch.rev [2011.10.19 23:43:01 | 000,000,230 | RHS- | M] () -- C:\Preload.rev [2011.10.19 14:07:46 | 000,002,142 | ---- | M] () -- C:\RHDSetup.log [2012.11.18 18:11:18 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys < %PROGRAMFILES%\*.exe > < %PROGRAMFILES(X86)%\*.exe > < %systemroot%\*. /mp /s > < %windir%\installer\*. /10 > [2012.11.15 22:00:44 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\MSI4B1B.tmp- [2012.11.15 22:00:56 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{F45BEC1B-DE2A-4F47-81E7-042D0C29CD09} < %appdata%\*. > [2012.11.04 18:09:55 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\.minecraft [2012.04.05 11:42:30 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\.Nitrous [2012.08.16 11:16:23 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Adobe [2012.02.29 17:36:24 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Apple Computer [2011.10.22 14:50:23 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\ATI [2012.11.17 12:47:45 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Avira [2012.03.31 09:02:53 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\CrystalIdea Software [2012.10.01 15:11:43 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\DVDVideoSoft [2012.10.01 15:11:05 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\DVDVideoSoftIEHelpers [2012.01.06 15:36:40 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Floodlight Games [2012.09.07 13:24:32 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\FOG Downloader [2012.05.10 05:41:12 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Freemium [2012.01.04 22:52:19 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\funkitron [2012.01.24 15:13:40 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\HP [2012.06.04 11:54:38 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\HpUpdate [2010.11.21 03:51:08 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Identities [2012.08.07 11:41:04 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Intelli-studio [2011.03.10 22:02:50 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\jar files [2011.12.03 16:11:42 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Jens Lorek [2012.01.20 15:06:22 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\LolClient [2011.08.29 11:24:36 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Macromedia [2012.11.04 15:21:48 | 000,000,000 | --SD | M] -- C:\Users\Marci´s\AppData\Roaming\Microsoft [2012.11.08 18:05:39 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Mozilla [2012.02.23 17:00:22 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Need for Speed World [2011.10.27 17:32:19 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Nero [2011.11.27 18:51:05 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\OpenOffice.org [2012.09.12 13:08:19 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Origin [2012.11.10 21:19:34 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\PerformerSoft [2011.08.16 18:10:42 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\planes [2011.03.10 22:02:56 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\resource files [2011.11.04 14:15:08 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\runic games [2012.11.05 20:03:25 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Skype [2011.11.10 13:37:36 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\SNS [2012.11.05 18:46:58 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\SoftGrid Client [2012.11.11 01:22:28 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Synaptics [2011.10.31 22:44:48 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Tific [2012.02.29 13:55:54 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\TP [2012.10.10 16:51:35 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\TS3Client [2011.12.27 21:13:34 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\TuneUp Software [2012.09.20 19:30:08 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Unity [2012.08.28 21:27:23 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\WildTangent [2012.01.06 15:30:59 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\WildTangentv1001 [2012.01.24 14:45:31 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\Windows Live Writer [2011.10.27 12:39:45 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Roaming\WinRAR < %appdata%\*.* > [2011.09.21 11:34:58 | 000,000,808 | ---- | M] () -- C:\Users\Marci´s\AppData\Roaming\Readme.txt [2012.02.07 15:19:55 | 000,045,056 | -HS- | M] () -- C:\Users\Marci´s\AppData\Roaming\Thumbs.db < %appdata%\*.exe /s > [2012.03.26 21:56:54 | 001,058,316 | ---- | M] ( ) -- C:\Users\Marci´s\AppData\Roaming\.minecraft\Minecraft Version Changer.exe [2011.08.21 14:19:18 | 000,695,296 | ---- | M] (AnjoCaido) -- C:\Users\Marci´s\AppData\Roaming\.minecraft\MinecraftSP.exe [2011.10.19 14:25:53 | 000,038,784 | ---- | M] () -- C:\Users\Marci´s\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe [2011.10.22 16:33:01 | 000,034,494 | R--- | M] () -- C:\Users\Marci´s\AppData\Roaming\Microsoft\Installer\{24F5BFDD-18E0-41F6-8A68-A22C742FC4A1}\_6FEFF9B68218417F98F549.exe [2012.08.28 21:27:31 | 000,000,181 | ---- | M] () -- C:\Users\Marci´s\AppData\Roaming\WildTangent\WildTangent Games\App\DPConfig\InstallTouchpoints-packardbell.exe_filedata [2012.08.28 21:28:18 | 000,065,535 | ---- | M] () -- C:\Users\Marci´s\AppData\Roaming\WildTangent\WildTangent Games\App\DPConfig\InstallTouchpoints-packardbell.exe_cache [2012.05.22 02:34:34 | 000,571,040 | ---- | M] (WildTangent, Inc.) -- C:\Users\Marci´s\AppData\Roaming\WildTangent\WildTangent Games\App\Update\Updater.exe < %localappdata%\*. > [2012.02.06 20:14:36 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Adobe [2012.10.10 16:51:34 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Akamai [2012.11.04 14:52:24 | 000,000,000 | -HSD | M] -- C:\Users\Marci´s\AppData\Local\Anwendungsdaten [2012.02.07 14:40:09 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Apple [2012.02.17 00:14:10 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Apple Computer [2011.10.22 16:58:18 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Apps [2011.10.22 14:50:23 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\ATI [2012.07.27 01:08:43 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\BlueStacks [2012.06.22 05:30:56 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\BlueStacksSetup [2012.01.21 15:43:43 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Chromium [2012.10.31 22:32:44 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\CrashDumps [2012.10.01 16:09:06 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\CRE [2012.11.04 19:33:27 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Deployment [2012.10.13 18:16:16 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Diagnostics [2012.02.23 15:45:35 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Electronic_Arts_Inc [2012.11.15 22:01:11 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Freetec [2012.11.18 13:59:39 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Google [2011.12.12 12:56:44 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\HP [2012.05.10 05:44:37 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\IsolatedStorage [2012.06.11 14:51:39 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Macromedia [2012.07.26 15:48:13 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Messenger_Plus_Live [2012.11.11 15:47:29 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Microsoft [2012.08.16 10:46:31 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Microsoft Games [2011.10.22 15:36:19 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Mozilla [2012.09.09 20:20:31 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Overwolf [2012.11.17 22:41:17 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Packages [2012.11.19 17:56:32 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\PMB Files [2012.04.16 15:11:03 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\PunkBuster [2012.02.29 13:55:47 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\SoftGrid Client [2011.10.31 22:44:27 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Symantec [2012.08.31 19:53:09 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\TeamSpeak 3 Client [2012.11.19 18:05:35 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Temp [2012.11.04 14:52:24 | 000,000,000 | -HSD | M] -- C:\Users\Marci´s\AppData\Local\Temporary Internet Files [2012.10.01 15:06:10 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\TubeBox [2012.02.17 22:46:27 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Unity [2012.11.04 14:52:24 | 000,000,000 | -HSD | M] -- C:\Users\Marci´s\AppData\Local\Verlauf [2012.02.02 21:32:54 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\VirtualStore [2012.08.17 11:44:03 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Windows Live [2012.01.24 14:45:39 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\Windows Live Writer [2012.08.31 13:38:00 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{065843EA-A1FF-46C8-8C45-85F6BE7C60E8} [2012.08.17 11:45:10 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{0F69C307-6E05-4727-8E64-FC045878A7D0} [2012.07.17 15:38:16 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{289F2FE6-1D61-42A0-8604-8AF9390575BA} [2011.11.15 06:37:16 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{2FDFF52D-633F-4B70-A462-A31BAE26E130} [2012.06.14 19:54:37 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{345849EF-8936-4EA9-B2AB-768ACBDA48E1} [2012.07.18 20:47:13 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{3825CADF-8149-45E1-858C-FBCFC97863D2} [2012.08.15 15:43:19 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{39EAA494-A6DC-447B-A72C-5F6E9457FA58} [2012.05.05 12:56:51 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{3A4BEF6A-B0BD-48C4-BD80-E64027FBB554} [2012.08.15 15:14:01 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{3A902523-6387-4E37-A85E-8873D69E25B3} [2012.08.16 11:31:22 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{42AFA991-DB4F-48E3-B908-DFC83D2D738F} [2012.08.11 21:54:40 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{4889774E-9598-4EF6-998D-FF691A134446} [2011.12.30 01:12:19 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{490930E7-82C0-4CC0-8EEE-DF67B7CB1FFD} [2012.02.20 15:51:30 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{5018166E-E9CE-4A28-A2D9-1708F16874B9} [2012.08.25 21:00:13 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{57A9B45E-A05C-4ECE-969B-BB79BEC0F73E} [2011.12.30 01:12:08 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{5DFCF6C9-9076-414F-8085-34355BA8007C} [2012.08.15 23:43:07 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{6A0A1566-51BD-4AFF-8521-8C058B70FB13} [2012.02.22 17:53:51 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{6D2DC93F-D5FF-4F5D-BF57-3EF35C4305EB} [2012.10.03 11:40:35 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{6E141DCB-D7EC-4ECF-8061-5A31165732AD} [2011.11.15 06:37:16 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{7400419C-7840-4A15-B748-609D712AC10E} [2011.12.12 12:52:39 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{7DD1701B-22EC-4F47-9905-B9000D90ED8D} [2012.09.01 12:53:27 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{917F917F-2A06-4243-AFD7-5E07E75A53EF} [2012.02.09 15:26:54 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{9758C11D-A090-4D2B-A201-11E3C9CDA205} [2012.02.20 15:51:31 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{A2F81368-9CEA-487F-82C6-DB58DFD5F5EB} [2012.05.20 20:55:59 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{B7DB336E-13E5-4558-84AF-8366F20976B1} [2012.01.24 14:46:00 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{C4071F69-CBE0-48FC-97A6-D6A4CBCD556E} [2012.08.16 11:28:15 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{CBC21024-7AAD-4D98-9F31-8F82651BDF79} [2012.08.17 11:41:40 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{CF0FD756-8304-479A-A350-95C8331344F0} [2012.08.15 23:28:58 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{D56C78ED-C581-4BF9-9844-7B1D8607490B} [2012.08.15 14:00:32 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{D6098BB4-C947-47E9-9D64-624F36D071AD} [2011.11.29 14:45:58 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{D6AB3580-831F-4087-BEF9-5D3358C4F78C} [2012.01.14 17:05:07 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{D714A31A-0F2E-43FF-A40F-86B75A0F1021} [2012.08.25 22:50:56 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{DD73CB39-1718-4566-8FDF-80F6454A9832} [2011.12.14 13:19:36 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{DEB7F962-C0C1-40DD-8B91-9A96ADC68B17} [2012.08.21 10:19:41 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{EBA722FA-95DA-440F-B5EE-CDD4A2C1EB89} [2012.08.17 11:38:51 | 000,000,000 | ---D | M] -- C:\Users\Marci´s\AppData\Local\{F0A4C3B6-AEBC-4575-83A9-418CAF811ECA} < %localappdata%\*.* > [2012.11.04 14:05:23 | 000,066,760 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\GDIPFONTCACHEV1.DAT [2012.11.18 19:59:16 | 000,093,719 | -H-- | M] () -- C:\Users\Marci´s\AppData\Local\IconCache.db < %localappdata%\*.exe /s > [2011.12.12 23:04:54 | 001,265,936 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\Akamai\admintool.exe [2011.12.12 23:19:37 | 003,420,440 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\Akamai\ControlPanel.exe [2011.12.12 23:20:56 | 003,859,936 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\Akamai\ControlPanel_Installer.exe [2011.12.20 19:07:05 | 008,449,640 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\Akamai\installer_no_upload_silent.exe [2011.12.12 23:20:56 | 003,305,760 | ---- | M] (Akamai Technologies, Inc) -- C:\Users\Marci´s\AppData\Local\Akamai\netsession_win.exe [2011.12.12 23:20:54 | 005,446,920 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\Akamai\rswinui.exe [2011.12.12 23:20:56 | 001,422,096 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\Akamai\uninstall.exe [2011.10.31 14:43:28 | 000,811,520 | ---- | M] (Infinite Zero) -- C:\Users\Marci´s\AppData\Local\Apps\2.0\KNPA6A9Q.59G\Q41HHPXO.JM0\rom-..tion_cfa43ff289ae6bf6_0001.0006_d5a93549e785d52d\ROM-Runecalc.exe [2012.06.22 05:29:18 | 000,198,144 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\BlueStacks\setup\glInfo.exe [2012.02.22 17:54:14 | 001,287,016 | ---- | M] (Microsoft Corporation) -- C:\Users\Marci´s\AppData\Local\Microsoft\Windows Live\Installer\Catalog\wlsetup.exe [2012.07.11 12:45:11 | 000,005,632 | ---- | M] (Microsoft Corporation) -- C:\Users\Marci´s\AppData\Local\Microsoft\Windows Sidebar\Gadgets\alarmClock.gadget\Sibbl.Gadget.AlarmClock.AlertApp.exe [2012.07.11 12:48:00 | 000,020,480 | ---- | M] (Microsoft) -- C:\Users\Marci´s\AppData\Local\Microsoft\Windows Sidebar\Gadgets\GermanyRain.gadget\RegisterHost.exe [2012.11.08 21:24:24 | 001,633,163 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\61E3WWSU\WORLD_21_target_5830[1].exe [2012.11.10 16:49:47 | 000,233,472 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\Packages\12199Asparion.AsparionCalculator_f89vgcf3qm37t\AC\Microsoft\CLR_v4.0_32\NativeImages\Calc\d80d2a406a48bdb9c164 0f7bc1c0743c\Calc.ni.exe [2012.11.18 14:05:23 | 000,076,888 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\PunkBuster\BFP4F\pb\PnkBstrA.exe [2012.11.18 14:05:13 | 000,282,104 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\PunkBuster\BFP4F\pb\PnkBstrB.exe [2012.06.05 15:24:29 | 000,270,240 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\PunkBuster\HEROES\pb\PnkBstrB.exe [2012.06.21 13:33:28 | 000,110,106 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\TeamSpeak 3 Client\createfileassoc.exe [2012.04.29 10:46:06 | 000,188,912 | ---- | M] (TeamSpeak Systems GmbH) -- C:\Users\Marci´s\AppData\Local\TeamSpeak 3 Client\error_report.exe [2012.07.16 18:41:21 | 000,224,240 | ---- | M] (TeamSpeak Systems GmbH) -- C:\Users\Marci´s\AppData\Local\TeamSpeak 3 Client\package_inst.exe [2012.08.31 19:53:08 | 012,752,880 | ---- | M] (TeamSpeak Systems GmbH) -- C:\Users\Marci´s\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe [2011.10.22 16:50:54 | 000,121,943 | ---- | M] (TeamSpeak Systems GmbH) -- C:\Users\Marci´s\AppData\Local\TeamSpeak 3 Client\Uninstall.exe [2012.08.31 19:53:08 | 000,497,648 | ---- | M] (TeamSpeak Systems GmbH) -- C:\Users\Marci´s\AppData\Local\TeamSpeak 3 Client\update.exe [2012.07.16 18:41:22 | 000,498,160 | ---- | M] (TeamSpeak Systems GmbH) -- C:\Users\Marci´s\AppData\Local\TeamSpeak 3 Client\_old_update.exe [2012.08.31 19:53:08 | 000,011,776 | ---- | M] (Rohrbacher Development) -- C:\Users\Marci´s\AppData\Local\TeamSpeak 3 Client\plugins\ts3overlay\ICCompressorChoose_win32.exe [2012.08.31 19:53:08 | 000,063,488 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\TeamSpeak 3 Client\plugins\ts3overlay\InstallHook.exe [2012.02.16 23:10:56 | 000,136,176 | ---- | M] (Google Inc.) -- C:\Users\Marci´s\AppData\Local\Temp\GoogleUpdate.exe4f0f61 [2012.11.18 19:38:12 | 000,027,411 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\Temp\i4jdel0.exe [2012.11.15 21:59:09 | 001,083,240 | ---- | M] () -- C:\Users\Marci´s\AppData\Local\Temp\tmpCEEA.tmp.exe [137 C:\Users\Marci´s\AppData\Local\Temp\*.tmp files -> C:\Users\Marci´s\AppData\Local\Temp\*.tmp -> ] [2012.06.27 16:40:33 | 001,816,216 | ---- | M] (Babylon Ltd.) -- C:\Users\Marci´s\AppData\Local\Temp\3794F2E5-BAB0-7891-9E9F-E1D654BA4BA9\Setup.exe [2012.10.25 19:51:08 | 000,484,656 | ---- | M] (DealPly) -- C:\Users\Marci´s\AppData\Local\Temp\is2036075176\dp.exe [2012.08.15 14:41:36 | 000,899,224 | ---- | M] (Babylon Ltd.) -- C:\Users\Marci´s\AppData\Local\Temp\is2036075176\MyBabylonTB.exe [2012.11.08 15:56:52 | 015,196,840 | ---- | M] (Freetec) -- C:\Users\Marci´s\AppData\Local\Temp\is2036075176\Tubebox_Update_Setup.exe [2011.07.01 22:20:00 | 002,789,888 | R--- | M] ( ) -- C:\Users\Marci´s\AppData\Local\Temp\Rar$EXa0.097\autorun.exe [2011.06.30 16:00:52 | 000,802,816 | R--- | M] (Acresso Software Inc. ) -- C:\Users\Marci´s\AppData\Local\Temp\Rar$EXa0.097\setup.exe [2011.06.30 00:20:58 | 003,601,707 | R--- | M] (Acresso Software Inc. ) -- C:\Users\Marci´s\AppData\Local\Temp\Rar$EXa0.097\Goeasily_Shock\GameMouseFFDrv.exe < %allusersprofile%\*. > [2012.09.25 12:45:35 | 000,000,000 | ---D | M] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 [2012.11.08 19:10:34 | 000,000,000 | ---D | M] -- C:\ProgramData\Adobe [2011.10.19 14:06:45 | 000,000,000 | ---D | M] -- C:\ProgramData\AmUStor [2011.10.22 14:47:47 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten [2012.02.07 14:39:59 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple [2012.09.25 12:45:06 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple Computer [2012.07.26 08:22:08 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data [2011.10.19 14:06:05 | 000,000,000 | ---D | M] -- C:\ProgramData\ATI [2012.05.11 13:29:29 | 000,000,000 | ---D | M] -- C:\ProgramData\AVAST Software [2012.11.17 12:39:51 | 000,000,000 | ---D | M] -- C:\ProgramData\Avira [2011.08.29 12:02:53 | 000,000,000 | ---D | M] -- C:\ProgramData\BackupManager [2012.03.20 21:50:57 | 000,000,000 | ---D | M] -- C:\ProgramData\Blizzard [2012.03.21 17:25:02 | 000,000,000 | ---D | M] -- C:\ProgramData\Blizzard Entertainment [2012.06.22 05:31:09 | 000,000,000 | ---D | M] -- C:\ProgramData\BlueStacks [2012.11.17 22:33:21 | 000,000,000 | -H-D | M] -- C:\ProgramData\Common Files [2011.11.10 13:37:42 | 000,000,000 | ---D | M] -- C:\ProgramData\CyberLink [2012.01.29 13:13:20 | 000,000,000 | ---D | M] -- C:\ProgramData\DAEMON Tools Pro [2012.08.13 17:46:00 | 000,000,000 | ---D | M] -- C:\ProgramData\DatacardService [2012.07.26 08:22:08 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop [2012.09.07 17:47:24 | 000,000,000 | ---D | M] -- C:\ProgramData\Desura [2012.07.26 08:22:08 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents [2011.10.22 14:47:47 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente [2012.09.12 13:39:32 | 000,000,000 | -HSD | M] -- C:\ProgramData\DSS [2012.11.04 13:43:02 | 000,000,000 | ---D | M] -- C:\ProgramData\Electronic Arts [2011.10.19 14:28:01 | 000,000,000 | ---D | M] -- C:\ProgramData\eSellerate [2011.10.22 14:47:47 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten [2012.01.06 15:36:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Floodlight Games [2011.12.07 17:25:42 | 000,000,000 | ---D | M] -- C:\ProgramData\HP [2011.12.07 13:42:36 | 000,000,000 | ---D | M] -- C:\ProgramData\HP Product Assistant [2012.11.18 12:36:24 | 000,000,000 | --SD | M] -- C:\ProgramData\Microsoft [2012.08.13 17:45:31 | 000,000,000 | ---D | M] -- C:\ProgramData\Mobile Partner [2012.05.09 14:39:56 | 000,000,000 | ---D | M] -- C:\ProgramData\Mozilla [2011.08.29 11:28:17 | 000,000,000 | ---D | M] -- C:\ProgramData\Nero [2011.12.25 21:21:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Norton [2011.12.25 20:51:54 | 000,000,000 | ---D | M] -- C:\ProgramData\NortonInstaller [2011.10.22 14:49:55 | 000,000,000 | ---D | M] -- C:\ProgramData\oem [2012.11.04 13:43:02 | 000,000,000 | ---D | M] -- C:\ProgramData\Origin [2012.11.15 22:00:39 | 000,000,000 | ---D | M] -- C:\ProgramData\Package Cache [2011.08.29 11:34:52 | 000,000,000 | ---D | M] -- C:\ProgramData\Packard Bell [2012.08.19 17:40:27 | 000,000,000 | ---D | M] -- C:\ProgramData\PlayFirst [2012.11.19 17:56:31 | 000,000,000 | ---D | M] -- C:\ProgramData\PMB Files [2012.11.07 19:29:54 | 000,000,000 | ---D | M] -- C:\ProgramData\PRICache [2012.02.05 20:39:12 | 000,000,000 | ---D | M] -- C:\ProgramData\regid.1986-12.com.adobe [2012.07.26 11:29:39 | 000,000,000 | ---D | M] -- C:\ProgramData\regid.1991-06.com.microsoft [2012.09.14 11:32:49 | 000,000,000 | ---D | M] -- C:\ProgramData\Skype [2011.10.19 14:28:28 | 000,000,000 | ---D | M] -- C:\ProgramData\SmartSound Software Inc [2012.07.26 08:22:08 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu [2011.10.22 14:47:47 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü [2011.10.27 12:47:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Sun [2011.08.29 12:06:16 | 000,000,000 | ---D | M] -- C:\ProgramData\Symantec [2012.11.11 01:56:56 | 000,000,000 | ---D | M] -- C:\ProgramData\Synaptics [2011.12.09 12:49:25 | 000,000,000 | ---D | M] -- C:\ProgramData\Temp [2012.07.26 08:22:08 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates [2012.03.22 13:35:05 | 000,000,000 | ---D | M] -- C:\ProgramData\TERA [2011.12.25 21:04:22 | 000,000,000 | ---D | M] -- C:\ProgramData\TuneUp Software [2012.03.01 21:15:07 | 000,000,000 | ---D | M] -- C:\ProgramData\VirtualizedApplications [2011.10.22 14:47:47 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen [2012.01.06 15:40:08 | 000,000,000 | ---D | M] -- C:\ProgramData\Wild Tangent [2012.08.28 21:27:19 | 000,000,000 | ---D | M] -- C:\ProgramData\WildTangent [2012.04.09 11:30:06 | 000,000,000 | ---D | M] -- C:\ProgramData\Xfire [2011.12.25 21:03:13 | 000,000,000 | -HSD | M] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936} [2012.02.07 14:41:03 | 000,000,000 | ---D | M] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} [2012.11.17 22:33:21 | 000,000,000 | -HSD | M] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} < %allusersprofile%\*.* > [2011.12.07 14:00:02 | 000,001,799 | ---- | M] () -- C:\ProgramData\hpzinstall.log < %allusersprofile%\*.exe /s > [2012.08.21 12:01:28 | 001,977,816 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69\GEARDIFx.exe [2012.08.21 12:01:20 | 000,131,544 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DifXInst64.exe [2010.09.30 02:11:38 | 001,586,624 | ---- | M] (Macromedia, Inc.) -- C:\ProgramData\Adobe\Elements Organizer\9.0\Flash Galleries\Dynamic\flashplayer\windows\SAFlashPlayer.exe [2010.09.30 02:15:32 | 000,083,392 | ---- | M] () -- C:\ProgramData\Adobe\Elements Organizer\9.0\Slideshow Templates\yahoomap\resources\AuthSWF.exe [2011.09.05 22:51:05 | 001,560,520 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1031-7B44-AA1000000001}\setup.exe [2012.01.03 18:44:25 | 000,342,984 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1031-7B44-AA1000000001}\RDC\setup.exe [2012.09.10 02:33:52 | 000,073,624 | ---- | M] (Apple Inc.) -- C:\ProgramData\Apple Computer\Installer Cache\iTunes 10.7.0.21\SetupAdmin.exe [2011.11.10 17:53:38 | 000,073,584 | ---- | M] (Apple Inc.) -- C:\ProgramData\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.exe [2010.11.16 14:37:40 | 000,137,216 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe [2010.11.16 14:37:30 | 000,230,912 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe [2010.11.16 14:37:38 | 000,264,704 | ---- | M] () -- C:\ProgramData\DatacardService\HWDeviceService.exe [2010.11.16 14:38:16 | 000,339,456 | ---- | M] () -- C:\ProgramData\DatacardService\HWDeviceService64.exe [2012.02.29 15:18:53 | 010,273,120 | ---- | M] (Electronic Arts) -- C:\ProgramData\Electronic Arts\Need For Speed World\Data\nfsw.exe [2011.12.07 13:59:17 | 000,244,000 | ---- | M] (Igor Pavlov) -- C:\ProgramData\HP\Installer\Temp\DEU-Package.exe [2009.08.01 15:02:10 | 001,710,392 | ---- | M] (Hewlett-Packard) -- C:\ProgramData\HP\Installer\Temp\hpzmsi01.exe [2009.08.01 15:02:25 | 002,410,296 | ---- | M] (Hewlett-Packard) -- C:\ProgramData\HP\Installer\Temp\hpzscr40.EXE [4 C:\ProgramData\HP\Installer\Temp\*.tmp files -> C:\ProgramData\HP\Installer\Temp\*.tmp -> ] [2010.06.25 17:24:23 | 001,100,664 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\Office14\setup.exe [2010.06.18 13:52:31 | 000,838,536 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\Office14\Office.de-de\DW20.EXE [2010.06.18 13:52:35 | 000,519,584 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\Office14\Office.de-de\dwtrig20.exe [2010.06.25 17:24:32 | 000,149,352 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\Office14\SingleImage.WW\ose.exe [2010.02.28 10:33:12 | 005,336,456 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\OStarter\de-de\Office.exe [2010.11.03 04:45:25 | 001,632,144 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\OStarter\de-de\SetupConsumerC2R.exe [2010.11.03 04:45:25 | 001,632,144 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\OStarter\de-de\SetupConsumerC2ROLW.exe [2012.08.13 17:44:39 | 001,057,792 | ---- | M] () -- C:\ProgramData\Mobile Partner\OnlineUpdate\LiveUpd.exe [2012.08.13 17:44:39 | 000,218,624 | ---- | M] () -- C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe [2012.10.01 14:59:55 | 000,429,600 | ---- | M] (Freetec) -- C:\ProgramData\Package Cache\{58a26b11-1507-4461-bb28-9c2be3a0dff1}\TubeBoxSetup.exe [2012.11.15 21:59:56 | 000,429,656 | ---- | M] (Freetec) -- C:\ProgramData\Package Cache\{c5b74464-3a04-417c-9eee-d0dc7d6af196}\TubeBoxSetup_update.exe [2011.10.19 14:10:44 | 000,036,864 | ---- | M] ( ) -- C:\ProgramData\Temp\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\PostBuild.exe [2011.02.25 02:35:36 | 000,316,704 | ---- | M] (Macrovision Corporation ) -- C:\ProgramData\Temp\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\Setup.exe [2011.10.19 14:29:12 | 000,036,864 | ---- | M] ( ) -- C:\ProgramData\Temp\{64EF903E-D00A-414C-94A4-FBA368FFCDC9}\PostBuild.exe [2011.12.09 12:48:47 | 000,036,864 | ---- | M] ( ) -- C:\ProgramData\Temp\{66931EF6-8094-4758-A4A2-EDD3F5FB86BF}\PostBuild.exe [2009.05.22 17:15:42 | 000,316,712 | ---- | M] (Macrovision Corporation ) -- C:\ProgramData\Temp\{66931EF6-8094-4758-A4A2-EDD3F5FB86BF}\Setup.exe [2010.12.01 12:27:54 | 018,298,408 | ---- | M] (WildTangent) -- C:\ProgramData\WildTangent\GameInstalls\WTA-c29c590d-8770-4ad3-878b-0fc5c132326c-extr.exe [2010.11.16 02:49:28 | 000,441,064 | ---- | M] (WildTangent, Inc.) -- C:\ProgramData\WildTangent\WildTangent Games\App\Update\Updater.exe [2012.08.28 08:18:51 | 000,213,560 | ---- | M] (WildTangent, Inc.) -- C:\ProgramData\WildTangent\WTDownloader\fatethecursedking\Download\brandinfo_wildgames_1.0.0.354.exe [2012.08.28 08:18:56 | 000,692,960 | ---- | M] (WildTangent, Inc.) -- C:\ProgramData\WildTangent\WTDownloader\fatethecursedking\Download\brand_1.0.0.558.exe [2012.08.28 08:18:43 | 000,455,888 | ---- | M] (WildTangent, Inc.) -- C:\ProgramData\WildTangent\WTDownloader\fatethecursedking\Download\catalyst_1.0.0.435.exe [2012.08.28 08:18:53 | 000,453,808 | ---- | M] (WildTangent, Inc.) -- C:\ProgramData\WildTangent\WTDownloader\fatethecursedking\Download\installerui_1.0.0.197.exe [2012.08.28 08:18:44 | 000,083,304 | ---- | M] (WildTangent, Inc.) -- C:\ProgramData\WildTangent\WTDownloader\fatethecursedking\Download\pkgtype_1.0.0.65.exe [2012.08.28 08:18:48 | 000,245,701 | ---- | M] (WildTangent, Inc.) -- C:\ProgramData\WildTangent\WTDownloader\fatethecursedking\Download\prodinfo_fatethecursedking_1.0.1.1196.exe [2012.08.28 21:28:47 | 004,340,112 | ---- | M] (WildTangent, Inc.) -- C:\ProgramData\WildTangent\WTDownloader\fatethecursedking\Download\wire_1.0.0.212.exe < End of report > |
19.11.2012, 18:20 | #7 |
| Claro Search eingfangen :( Hier ist das Extra txt:OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 19.11.2012 17:57:51 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marci´s\Desktop 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16433) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,86 Gb Total Physical Memory | 2,75 Gb Available Physical Memory | 71,20% Memory free 7,74 Gb Paging File | 6,17 Gb Available in Paging File | 79,67% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 223,94 Gb Total Space | 122,87 Gb Free Space | 54,87% Space Free | Partition Type: NTFS Drive D: | 224,14 Gb Total Space | 190,75 Gb Free Space | 85,10% Space Free | Partition Type: NTFS Computer Name: MARCI´S-LAPTOP | User Name: Marci´s | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_USERS\S-1-5-21-84541473-987749336-3452602534-1000\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{7C437346-AC8C-4D52-8E9E-CA0DC5D7A230}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{EE32EFC7-F713-477C-B0CA-A8FCF2C7B96F}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01AB67CC-D2B4-4A5C-8A70-7047D1FACADD}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{06AEAE5D-BE81-4868-B5FE-A9F0CD99088E}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{0802F110-FB13-4C9F-A3BA-25D4BAE1FFB3}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{0B7F5795-D8BD-48D1-84BE-2B27EE5FD2A0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{0D878372-7084-4487-8BEA-AF50B3D1524A}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{0E0425BE-7325-4227-A583-DE5B61DE15D0}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{0F937023-25F5-44D2-A954-BA149ABE4231}" = protocol=6 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "{1050B212-D62D-4689-B319-625FD69044AD}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{119FB347-489A-41AA-80C4-7F73817C230B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe | "{15A5FB94-5028-4831-AAF8-F9AC1E668C65}" = dir=in | name=air soccer fever | "{1854EA34-4C8E-45E0-89C9-5760EA6DFF43}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{19BD2144-0C77-40F1-99D0-160AD149CEB3}" = dir=in | name=@{microsoft.reader_6.2.9200.20523_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{1A018FF5-87A8-4A40-A8CC-D78A74F095B4}" = dir=out | name=@{microsoft.bingsports_1.5.1.249_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{1A42900B-0471-4135-9EB1-8A34A606CF45}" = dir=out | name=@{microsoft.xboxlivegames_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{1C48F737-E411-44AC-B387-3F1A42371B95}" = dir=in | name=pinball fx2 | "{1EF5EB73-75DC-4361-8E66-2E80F983D3FA}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{201C31F1-05D6-4060-9D97-A015036C36F1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{20FD48E5-E91E-4A9D-9C54-E38F12453F75}" = protocol=17 | dir=in | app=c:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe | "{2402ACD8-75D4-4E1E-B082-2B048993B6AA}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{2666A39B-BCF7-409F-8DBC-0E0C20E2F9AF}" = dir=out | name=robotek | "{2A668D37-8387-4ADA-B1D8-CF93A6E425F8}" = dir=out | name=@{microsoft.bing_1.5.1.251_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{2F7FEAAD-BA6C-4536-B5AE-2AEA57B960AC}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{30A9B654-CEA9-4552-B561-1F786F613DE7}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{328E6057-C3DE-4C4D-ABC8-84A015C66847}" = dir=out | name=@{microsoft.reader_6.2.9200.20523_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{3588DE6B-4FB5-416F-91F1-9537D7A21FD8}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{3962A026-750C-4E71-A3ED-736A53CF78C9}" = dir=out | name=windows_ie_ac_001 | "{3C3C1082-BBAE-4286-8A61-7B4804617356}" = dir=out | name=air soccer fever | "{3CA1DC00-25D2-4D88-A521-575C22796862}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe | "{3D78A9A0-4FF4-43A3-9DE9-7952F605EF30}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{40C97067-323E-471E-87D4-7D3C7DA84CB4}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "{41652096-5CF1-4D02-9351-BE8C9BD1A51A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{424B399E-34C2-40FB-949D-BB8124CD8299}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{48B155AD-7B10-42C1-ABB2-4D2EB3692583}" = dir=out | name=@{microsoft.bingfinance_1.5.1.406_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{4F8D5102-CF5C-4E83-BDAE-D826CC866E0D}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{50229B40-25B5-4E3E-B8B2-5036BA67CB72}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{5060FECA-40BF-4A5B-972C-F45C7ACF476A}" = dir=out | name=ebay | "{515C8CCC-442A-48FA-977F-EBC4E6C34606}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{5318C01D-B208-4155-A9E1-CCB54EB4F4FC}" = dir=out | name=@{microsoft.zunevideo_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{54EDFCFB-E9E0-4DC6-A294-9368FA306CCC}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{59D80D86-0C4F-4333-B9CB-386DB5CCFDA9}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe | "{5A1752EA-BD61-4BB9-B3F1-FD45A94628E1}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe | "{5A6B5BFC-3292-4069-B93C-09D6F85FB498}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{5B9DA972-57AD-4A17-B7C0-F00897B643B1}" = protocol=6 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe | "{5C940647-3BE8-4B71-AB58-590A49970BE9}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{6636ECA1-AE1F-4B6B-A030-9C917E4320B0}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{692BEC22-85F0-4D35-996B-F63C6FD674BF}" = dir=in | name=ebay | "{6B990AD9-90C6-4985-A165-7EE69AC89698}" = dir=out | name=jetpack joyride | "{6C889B7F-3587-4858-B85D-53C32CD5A335}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{6E4C1231-41FF-4DF9-8EDA-19527FDB08B9}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{6FDA96C1-B703-4C0E-B2D5-6914279B5189}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{73A8D331-3EDE-4495-84E0-EFD733E7A4B1}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{73DCD575-680C-44A6-B068-3A6F3FA94607}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{7586001D-E2CC-4102-A19C-636C153EE278}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{75F53686-F79F-448E-B9E4-A27D2F05958A}" = protocol=17 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe | "{79AF5E67-D42F-4CBB-831F-85AFBF0FEBCE}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{7CEA5561-792B-4769-80EA-4805B7B20807}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{7D74779D-3F1E-46CC-ACB6-AA3714BDE837}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{7FF60113-2D9F-4AC9-9C76-9BCA5EFCE89F}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{808883F5-1CE4-4885-B0F4-D963CDC4FCE4}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{88AEFA1B-FF88-441B-9E6D-44F6B7D2428E}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "{88E6335A-8411-47B4-94EF-8E86EEDD00A3}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{89548613-629D-49D8-9D29-C553ADC8F8EE}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{89FC59FE-5954-41DA-B458-7D1ADEE0327D}" = dir=in | name=robotek | "{8F32D51F-4E96-4094-873D-61EA61F6026B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe | "{9094AED6-F0E6-4ECC-B16D-84B4360D076D}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{90BD3770-4BE2-42D4-8E58-09F0E647D0DE}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{943E6C86-F2F7-4217-9410-7955C2B5400E}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{9494B231-D3ED-46AD-B878-68339FEEE3E3}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{983F463F-AB9D-4B29-8C1C-C3D6A81F7059}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{9A0EE505-A46E-4B82-87C4-ABBDBD9764BD}" = protocol=6 | dir=in | app=c:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe | "{A149DC0B-C6A8-411C-946F-3CA394C5027C}" = dir=out | name=google search | "{A602FF98-F7A2-4768-B915-37D6AA440357}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{A9791FDB-B353-4003-915B-73B242339868}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{A997550D-46DF-4822-BA52-7EBDFAE52AF8}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{A9DDC3C7-5B34-41CA-9EA9-9CC219DA7F84}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{AA7D5F15-4BE7-4372-B324-D12A8A0217A5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{BEF6308A-434D-4063-9FA5-CD7A7BB426FE}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{C2418CB4-F470-4628-AA3C-8B58099743DF}" = protocol=17 | dir=in | app=c:\users\marci´s\appdata\local\akamai\netsession_win.exe | "{C57A85BF-3B6F-44B9-B0CC-5017ACE7D6E8}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\demo\james cameron's avatar - das spiel (demo)\bin\avatardemo.exe | "{C853355E-3491-404D-8423-4806970CECFE}" = protocol=17 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "{C8AD87E1-CD5D-4C0D-A6F2-136601C7EED5}" = dir=in | name=jetpack joyride | "{CA969AFD-F04D-4510-A2FD-99616AE58338}" = dir=in | name=@{microsoft.skypeapp_1.1.0.25_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{CAC9D7A0-B61F-495E-AEF0-807690EAE3C0}" = protocol=6 | dir=in | app=c:\users\marci´s\appdata\local\akamai\netsession_win.exe | "{CCC076C8-CFDA-462F-8B9E-61D05BFA46A8}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{CD1456F9-7F20-4792-A969-A6D44826DF17}" = dir=out | name=@{microsoft.bingmaps_1.5.1.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{CF17E262-056F-4112-A4C5-7DD63789FEF1}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{D044D3EB-62CD-4852-9F7F-06F86C906B61}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe | "{D324ED89-A251-4623-ADA4-4EB876B9C06B}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{D4DF25AB-0217-4568-A92D-69C3C3287BD2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{D5DC554B-5681-471A-A724-1898261598AB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{DA61C96E-FC70-4423-ABAE-D705DE8AC847}" = dir=out | name=@{microsoft.bingnews_1.5.1.409_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{DD10F14D-58C3-4963-8E5C-9AAE17951377}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{DE23D039-B557-404F-BA6D-E7C18444C85D}" = dir=out | name=@{microsoft.bingweather_1.5.1.245_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{DF8A2E60-7FA7-493C-A960-E88ABBE2A5F4}" = dir=out | name=@{microsoft.zunemusic_1.1.137.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{E2F72C7E-25EF-4DF1-855F-B76A6E194817}" = dir=out | name=windows_ie_ac_001 | "{E31C2E16-B17C-48CC-B5D1-A57085F60D09}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\demo\james cameron's avatar - das spiel (demo)\bin\avatardemo.exe | "{E33816AE-7F88-4450-BC20-2BA3777D8FA0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{E5615AB9-363D-4FB3-8187-C7B67F615CE9}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{E6040050-91FC-430A-BDD3-A85FB243DE4B}" = dir=out | name=@{microsoft.skypeapp_1.1.0.25_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{E7045A8D-EF06-404C-B7FC-B659F77FD2B4}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{E915D9DA-3434-435E-A0B0-B45390CF5A49}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe | "{E927BBDF-D66A-421A-B7BD-5FF4314401D1}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{EA2FB9F2-B2BC-44B6-8B87-1644EA40E65B}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{EA6AA9C9-68AE-4D03-9521-586B9D1CB7DD}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{EFDFB918-48BF-47A7-8012-803D1D0EC3E4}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{F54E1DE1-C090-4841-B6F5-AB74224ECC47}" = dir=out | name=pinball fx2 | "{F90C9439-5E05-4F0C-953B-DEF0FE26E901}" = dir=out | name=@{microsoft.bingtravel_1.5.1.248_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{FC2982BD-09BC-49C7-8638-C40248E11422}" = dir=out | name=wikipedia | "{FF793FC7-05A9-4D91-8522-F99CDDEF89AA}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe | "TCP Query User{1163E211-6BDA-4EB6-93D5-4C0E2CA832F3}C:\aeriagames\wolfteam-de\wolfteam.bin" = protocol=6 | dir=in | app=c:\aeriagames\wolfteam-de\wolfteam.bin | "TCP Query User{2CC8676D-256F-4CE1-B5EA-E29271880E9D}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "TCP Query User{3F8660C3-0459-4FC4-82AB-A500CC353BBC}C:\program files (x86)\runes of magic\client.exe" = protocol=6 | dir=in | app=c:\program files (x86)\runes of magic\client.exe | "TCP Query User{4389B0CE-2BCA-4D25-9410-99598C3329DA}C:\program files (x86)\tera\tera-launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe | "TCP Query User{46EECCF7-B964-4261-BFAF-CD0E16C0FA65}C:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe" = protocol=6 | dir=in | app=c:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe | "TCP Query User{48009E57-D584-4C84-B880-6F986530D898}C:\program files (x86)\runes of magic\launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\runes of magic\launcher.exe | "TCP Query User{4DDF450A-C2AF-47E0-9884-0532CD1C8336}C:\users\marci´s\desktop\blacknight-2011\metin2client.dll" = protocol=6 | dir=in | app=c:\users\marci´s\desktop\blacknight-2011\metin2client.dll | "TCP Query User{B0E06146-ABCB-4DE6-9428-A8A07FE50875}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe | "TCP Query User{BDEAA2F2-0BE0-41AD-B396-54D7DBB8F82D}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "TCP Query User{DDB8C9DC-381C-487B-943D-0B149B0C1A4E}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=6 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "TCP Query User{ECB034F3-CA69-4700-8E2F-6F829BCE091B}C:\users\marci´s\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\marci´s\appdata\local\akamai\netsession_win.exe | "UDP Query User{098B087B-9BF4-4E66-B7D1-C859B18A7C19}C:\program files (x86)\tera\tera-launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe | "UDP Query User{36333577-186E-4730-86FF-F089FBAAAFEA}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "UDP Query User{4D3DA2F5-E9CC-4BFA-8E0B-DB4505705671}C:\program files (x86)\runes of magic\client.exe" = protocol=17 | dir=in | app=c:\program files (x86)\runes of magic\client.exe | "UDP Query User{61475386-59D3-4200-B294-7C9CAE3BFA3C}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=17 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "UDP Query User{7C288DE0-6A30-478F-BB2A-C3CD2418BF3E}C:\aeriagames\wolfteam-de\wolfteam.bin" = protocol=17 | dir=in | app=c:\aeriagames\wolfteam-de\wolfteam.bin | "UDP Query User{9CEC4C21-8B13-498D-A62E-08639E9E5BDE}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe | "UDP Query User{C91518F5-AC11-4A00-B327-F7D60B68DB64}C:\program files (x86)\runes of magic\launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\runes of magic\launcher.exe | "UDP Query User{DB85B86D-3D16-4D77-A530-03449920923E}C:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe" = protocol=17 | dir=in | app=c:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe | "UDP Query User{E41A0F5F-7337-47FA-904A-4E322016049E}C:\users\marci´s\desktop\blacknight-2011\metin2client.dll" = protocol=17 | dir=in | app=c:\users\marci´s\desktop\blacknight-2011\metin2client.dll | "UDP Query User{E59A2101-28A2-47C8-BCF4-B97682778BDF}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "UDP Query User{EFFC9917-B51A-462E-B17E-9E52A4890673}C:\users\marci´s\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\marci´s\appdata\local\akamai\netsession_win.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0919C44F-F18A-4E3B-A737-03685272CE72}" = Windows Live Remote Service Resources "{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes "{1553D712-B35F-4A82-BC72-D6B11A94BE3E}" = Windows Live Remote Service Resources "{1685AE50-97ED-485B-80F6-145071EE14B0}" = Windows Live Remote Service Resources "{17A4FD95-A507-43F1-BC92-D8572AF8340A}" = Windows Live Remote Service Resources "{19F09425-3C20-4730-9E2A-FC2E17C9F362}" = Windows Live Remote Service Resources "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{1EB2CFC3-E1C5-4FC4-B1F8-549DD6242C67}" = Windows Live Remote Service Resources "{22AB5CFD-B3DB-414E-9F99-4D024CCF1DA6}" = Windows Live Remote Client Resources "{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources "{2C1A6191-9804-4FDC-AB01-6F9183C91A13}" = Windows Live Remote Client Resources "{2F304EF4-0C31-47F4-8557-0641AAE4197C}" = Windows Live Remote Client Resources "{34384A2A-2CA2-4446-AB0E-1F360BA2AAC5}" = Windows Live Remote Service Resources "{350FD0E7-175A-4F86-84EF-05B77FCD7161}" = Windows Live Remote Service Resources "{3921492E-82D2-4180-8124-E347AD2F2DB4}" = Windows Live Remote Client Resources "{456FB9B5-AFBC-4761-BBDC-BA6BAFBB818F}" = Windows Live Remote Client Resources "{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{4C2E49C0-9276-4324-841D-774CCCE5DB48}" = Windows Live Remote Client Resources "{5141AA6E-5FAC-4473-BFFB-BEE69DDC7F2B}" = Windows Live Remote Service Resources "{5151E2DB-0748-4FD1-86A2-72E2F94F8BE7}" = Windows Live Remote Service Resources "{57F2BD1C-14A3-4785-8E48-2075B96EB2DF}" = Windows Live Remote Service Resources "{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources "{5F44A3A1-5D24-4708-8776-66B42B174C64}" = Windows Live Remote Client Resources "{5FCD6EFE-C2E7-4D77-8212-4BA223D8DF8E}" = Windows Live Remote Client Resources "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{5FEAD3E5-A158-4B66-B92B-0C959D7CF838}" = Windows Live Remote Service Resources "{61407251-7F7D-4303-810D-226A04D5CFF3}" = Windows Live Remote Service Resources "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{692CCE55-9EAE-4F57-A834-092882E7FE0B}" = Windows Live Remote Client Resources "{6C9D3F1D-DBBE-46F9-96A0-726CC72935AF}" = Windows Live Remote Service Resources "{6CBFDC3C-CF21-4C02-A6DC-A5A2707FAF55}" = Windows Live Remote Service Resources "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{702A632F-99CE-4E2D-B8F2-BF980E9CF62F}" = Windows Live Remote Client Resources "{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support "{7AEC844D-448A-455E-A34E-E1032196BBCD}" = Windows Live Remote Service Resources "{825C7D3F-D0B3-49D5-A42B-CBB0FBE85E99}" = Windows Live Remote Client Resources "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{850B8072-2EA7-4EDC-B930-7FE569495E76}" = Windows Live Remote Client Resources "{8970AE69-40BE-4058-9916-0ACB1B974A3D}" = Windows Live Remote Client Resources "{8B79B3A9-6E49-5FFB-2017-A822BBDC4992}" = ATI Catalyst Install Manager "{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources "{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{97A295A7-8840-4B35-BB61-27A8F4512CA3}" = Windows Live Remote Service Resources "{9E9C960F-7F47-46D5-A95D-950B354DE2B8}" = Windows Live Remote Service Resources "{A060182D-CDBE-4AD6-B9B4-860B435D6CBD}" = Windows Live Remote Client Resources "{A508D5A2-3AC1-4594-A718-A663D6D3CF11}" = Windows Live Remote Service Resources "{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources "{A84DB02B-9C2B-4272-9D2D-A80E00A56513}" = Broadcom Gigabit NetLink Controller "{B0B97CF2-5032-A645-7FFC-BD1E39FC4E3F}" = ccc-utility64 "{B0BF8602-EA52-4B0A-A2BD-EDABB0977030}" = Windows Live Remote Client Resources "{B680A663-1A15-47A5-A07C-7DF9A97558B7}" = Windows Live Remote Client Resources "{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources "{C504EC13-E122-4939-BD6E-EE5A3BAA5FEC}" = Windows Live Remote Client Resources "{C98517B6-DCE9-49B7-B19E-E384178D3986}" = HP Officejet 4500 G510a-f "{C9F05151-95A9-4B9B-B534-1760E2D014A5}" = Windows Live Remote Client Resources "{CFF3C688-2198-4BC3-A399-598226949C39}" = Windows Live Remote Client Resources "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{D1C1556C-7FF3-48A3-A5D6-7126F0FAFB66}" = Windows Live Remote Client Resources "{D3E4F422-7E0F-49C7-8B00-F42490D7A385}" = Windows Live Remote Service Resources "{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources "{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DBEDAF67-C5A3-4C91-951D-31F3FE63AF3F}" = Windows Live Remote Client Resources "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{ED421F97-E1C3-4E78-9F54-A53888215D58}" = Windows Live Remote Client Resources "{EFB20CF5-1A6D-41F3-8895-223346CE6291}" = Windows Live Remote Service Resources "{F6CB2C5F-B2C1-4DF1-BF44-39D0DC06FE6F}" = Windows Live Remote Service Resources "{FAA3933C-6F0D-4350-B66B-9D7F7031343E}" = Windows Live Remote Service Resources "{FAD0EC0B-753B-4A97-AD34-32AC1EC8DB69}" = Windows Live Remote Client Resources "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "HP Document Manager" = HP Document Manager 2.0 "HP Imaging Device Functions" = HP Imaging Device Functions 13.0 "HP Smart Web Printing" = HP Smart Web Printing 4.5 "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0 "HPExtendedCapabilities" = HP Customer Participation Program 13.0 "HPOCR" = OCR Software by I.R.I.S. 13.0 "Shop for HP Supplies" = Shop for HP Supplies "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = WinRAR 4.20 (64-Bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{001EE40D-BB45-4E5C-8A26-233791AAE0E0}" = COMPUTERBILD-Abzockschutz "{007F778D-F15C-4EAB-AE92-071D21FAF632}" = Adobe Photoshop Elements 9 "{00884F14-05BD-4D8E-90E5-1ABF78948CA4}" = Windows Live Mesh "{0125DB4D-98A0-4DBF-B68A-23BF08FFA6A3}" = Windows Live Messenger "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Video Web Camera "{02A414EA-0E5F-CD08-61EF-E155F31DFF76}" = Catalyst Control Center Graphics Previews Vista "{039480EE-6933-4845-88B8-77FD0C3D059D}" = Windows Live Mesh "{0557BBDA-69D3-4FA4-A93C-A5300F7034B4}" = Windows Live Writer "{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack "{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common "{06B05153-97E4-427E-B1A8-E098F6C5E52F}" = Windows Live Essentials "{073F306D-9851-4969-B828-7B6444D07D55}" = Windows Live Photo Common "{0785A0B6-07DF-43CF-B147-E1EB4CEA0345}" = Windows Live Messenger "{08938019-97FA-1C7A-19E0-0C8D56ED7CB2}" = CCC Help Hungarian "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{09922FFE-D153-44AE-8B60-EA3CB8088F93}" = Windows Live UX Platform Language Pack "{0A4C4B29-5A9D-4910-A13C-B920D5758744}" = بريد Windows Live "{0A4D717B-E6E8-11FA-E7D2-385EBB1A4A85}" = CCC Help Japanese "{0A9256E0-C924-46DE-921B-F6C4548A1C64}" = Windows Live Messenger "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack "{0C975FCC-A06E-4CB6-8F54-A9B52CF37781}" = Windows Liven sähköposti "{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail "{0EC0B576-90F9-43C3-8FAD-A4902DF4B8F4}" = Galeria de Fotografias do Windows Live "{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan "{10186F1A-6A14-43DF-A404-F0105D09BB07}" = Windows Live Mail "{110668B7-54C6-47C9-BAC4-1CE77F156AF5}" = Windows Live Mesh "{11417707-1F72-4279-95A3-01E0B898BBF5}" = Windows Live Mesh "{11778DA1-0495-4ED9-972F-F9E0B0367CD5}" = Windows Live Writer "{1203DC60-D9BD-44F9-B372-2B8F227E6094}" = Windows Live Temel Parçalar "{128133D3-037A-4C62-B1B7-55666A10587A}" = Windows Live UX Platform Language Pack "{133D9D67-D475-4407-AC3C-D558087B2453}" = Windows Live Movie Maker "{13BA5548-1065-4DBE-B115-681AFB77263B}" = CCC Help Swedish "{14B441B7-774D-4170-98EA-A13667AE6218}" = Windows Live Writer Resources "{16890D7F-1C77-733B-D8E4-F5D4315A5F93}" = Catalyst Control Center Localization All "{168E7302-890A-4138-9109-A225ACAF7AD1}" = Windows Live Photo Common "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch "{17835B63-8308-427F-8CF5-D76E0D5FE457}" = Windows Live Essentials "{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials "{198EA334-8A3F-4CB2-9D61-6C10B8168A6F}" = Windows Live Writer "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1A72337E-D126-4BAF-AC89-E6122DB71866}" = Windows Liven valokuvavalikoima "{1A82AE99-84D3-486D-BAD6-675982603E14}" = Windows Live Writer "{1CBDB473-E303-EFAE-88D1-6F741ACD5B31}" = CCC Help Czech "{1D6C2068-807F-4B76-A0C2-62ED05656593}" = Windows Live Writer "{1D8912B0-343C-EB1F-28EE-B672D444C192}" = Catalyst Control Center InstallProxy "{1DA6D447-C54D-4833-84D4-3EA31CAECE9B}" = Windows Live UX Platform Language Pack "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FC83EAE-74C8-4C72-8400-2D8E40A017DE}" = Windows Live Writer "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery "{220C7F8C-929D-4F71-9DC7-F7A6823B38E4}" = Windows Live UX Platform Language Pack "{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1 "{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10 "{249EE21B-8EDD-4F36-8A23-E580E9DBE80A}" = Windows Live Mail "{24DF33E0-F924-4D0D-9B96-11F28F0D602D}" = Windows Live UX Platform Language Pack "{2511AAD7-82DF-4B97-B0B3-E1B933317010}" = Windows Live Writer Resources "{25175695-4B20-4298-9F34-C2C57CD277B3}" = Elements STI Installer "{25A381E1-0AB9-4E7A-ACCE-BA49D519CF4E}" = Windows Live Mail "{25CD4B12-8CC5-433E-B723-C9CB41FA8C5A}" = Windows Live Writer "{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java(TM) 6 Update 37 "{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{28B9D2D8-4304-483F-AD71-51890A063A74}" = Windows Live Photo Common "{29373E24-AC72-424E-8F2A-FB0F9436F21F}" = Windows Live Photo Common "{2A07C35B-8384-4DA4-9A95-442B6C89A073}" = Windows Live Essentials "{2AD2DD70-27F7-4343-BB4E-DE50A32D854B}" = Windows Live Messenger "{2BA5FD10-653F-4CAF-9CCD-F685082A1DC1}" = Windows Live Writer "{2C4E06CC-1F04-4C25-8B3C-93A9049EC42C}" = Windows Live UX Platform Language Pack "{2C59BF0E-66A5-681E-60FE-8D18CE6319A1}" = CCC Help German "{2C7E8AA1-9C03-4606-BF34-5D99D07964DA}" = Windows Live Messenger "{2C865FB0-051E-4D22-AC62-428E035AEAF0}" = Windows Live Mesh "{2C9D4FCA-3E7F-9368-6955-EA6D65F7DC78}" = CCC Help English "{2D3E034E-F76B-410A-A169-55755D2637BB}" = Windows Live Mesh "{2E50E321-4747-4EB5-9ECB-BBC6C3AC0F31}" = Windows Live Writer Resources "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update "{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App "{303143DD-1F6D-4BC5-9342-FFC2E19B2DBD}" = Windows Live Messenger "{3125D9DE-8D7A-4987-95F3-8A42389833D8}" = Windows Live Writer Resources "{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012 "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM) "{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live "{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10 "{34C4F5AF-D757-4E6A-ABCA-65AB5A50A1A8}" = Windows Live Messenger "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{370F888E-42A7-4911-9E34-7D74632E17EB}" = Windows Live Photo Common "{3788B9B7-C15F-4C64-D52B-3DD1BA494B7A}" = CCC Help Korean "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{39BDD209-5704-480C-9F4A-B69D0370DDBB}" = Windows Live Messenger "{39F95B0B-A0B7-4FA7-BB6C-197DA2546468}" = Windows Live Mesh "{3B72C1E0-26A1-40F6-8516-D50C651DFB3C}" = Windows Live Essentials "{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer "{3D0C22FA-96D7-4789-BC5B-991A5A99BFFA}" = Windows Live Messenger "{3D200EB9-44FC-432F-1E35-C20AB5FDCD77}" = CCC Help Thai "{3DB0448D-AD82-4923-B305-D001E521A964}" = Packard Bell Power Management "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{3EB6F78A-66E3-434f-BD0E-76C7D078DB5E}" = 4500G510af_Software_Min "{3F4143A1-9C21-4011-8679-3BC1014C6886}" = Windows Live Mesh "{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup "{40BFD84C-64CD-42CC-9909-8734C50429C6}" = Windows Live UX Platform Language Pack "{410DF0AA-882D-450D-9E1B-F5397ACFFA80}" = Windows Live Essentials "{4264C020-850B-4F08-ACBE-98205D9C336C}" = Windows Live Writer "{429DF1A0-3610-4E9E-8ACE-3C8AC1BA8FCA}" = Windows Live Photo Gallery "{433EACD8-4747-4A6A-826A-FFA9F39B0D40}" = Elements 9 Organizer "{43B43577-2514-4CE0-B14A-7E85C17C0453}" = Windows Live Essentials "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg "{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax "{4444F27C-B1A8-464E-9486-4C37BAB39A09}" = Фотогалерия на Windows Live "{44D52071-5077-2839-1AE6-863563AEA269}" = CCC Help Russian "{458F399F-62AC-4747-99F5-499BBF073D29}" = Windows Live Writer Resources "{4664ED39-C80A-48F7-93CD-EBDCAFAB6CC5}" = Windows Live Writer Resources "{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh "{4736B0ED-F6A1-48EC-A1B7-C053027648F1}" = Galeria fotogràfica del Windows Live "{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live "{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer "{48F597DD-D397-4CFA-91A0-4C033A0113BD}" = Windows Live Mail "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A04DB63-8F81-4EF4-9D09-61A2057EF419}" = Windows Live Essentials "{4A275FD1-2F24-4274-8C01-813F5AD1A92D}" = Windows Live Messenger "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter "{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer "{4BCBC4D0-1D88-462D-809E-506F34EA11C0}" = Catalyst Control Center - Branding "{4C378B16-46B7-4DA1-A2CE-2EE676F74680}" = Windows Live UX Platform Language Pack "{4D141929-141B-4605-95D6-2B8650C1C6DA}" = Windows Live UX Platform Language Pack "{4D83F339-5A5C-4B21-8FD3-5D407B981E72}" = Windows Live Photo Common "{50300123-F8FC-4B50-B449-E847D04F1BA2}" = Windows Live Messenger "{506FC723-8E6C-4417-9CFF-351F99130425}" = Windows Live UX Platform Language Pack "{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM) "{523DF2BB-3A85-4047-9898-29DC8AEB7E69}" = Windows Live UX Platform Language Pack "{5275D81E-83AD-4DE4-BC2B-6E6BA3A33244}" = Windows Live Writer Resources "{5495E9A4-501A-4D4C-87C9-E80916CA9478}" = Windows Live UX Platform Language Pack "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5C2F5C1B-9732-4F81-8FBF-6711627DC508}" = Windows Live Fotogalleri "{5C83944D-5319-4AD6-A803-C08446B27596}" = BlueStacks "{5CF5B1A5-CBC3-42F0-8533-5A5090665862}" = Windows Live Mesh "{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker "{5D2E7BD7-4B6F-4086-BA8A-E88484750624}" = Windows Live Writer Resources "{5D90ABE5-8A35-4947-8269-6F40BCE47A95}" = Windows Live Messenger "{5DA7D148-D2D2-4C67-8444-2F0F9BD88A06}" = Windows Live Writer "{5E627606-53B9-42D1-97E1-D03F6229E248}" = Windows Live UX Platform Language Pack "{5F6E678A-7E61-448A-86CB-BC2AD1E04138}" = Windows Live Messenger "{6057E21C-ABE9-4059-AE3E-3BEB9925E660}" = Windows Live Messenger "{60C3C026-DB53-4DAB-8B97-7C1241F9A847}" = Windows Live Movie Maker "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{625D45F0-5DCB-48BF-8770-C240A84DAAEB}" = Windows Live Mesh "{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources "{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}" = Nero Multimedia Suite 10 Essentials "{63AE67AA-1AB1-4565-B4EF-ABBC5C841E8D}" = Windows Live Messenger "{63CF7D0C-B6E7-4EE9-8253-816B613CC437}" = Windows Live Mail "{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2 "{640798A0-A4FB-4C52-AC72-755134767F1E}" = Windows Live Movie Maker "{64376910-1860-4CEF-8B34-AA5D205FC5F1}" = Poczta usługi Windows Live "{644063FA-ABA3-42AC-A8AC-3EDC0706018B}" = Windows Live Mesh "{6491AB99-A11E-41FD-A5E7-32DE8A097B8E}" = Windows Live Essentials "{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}" = Windows Live Movie Maker "{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Packard Bell Social Networks "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update "{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0 "{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail "{6807427D-8D68-4D30-AF5B-0B38F8F948C8}" = Windows Live Writer Resources "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting "{6986737B-F286-40D1-87AF-938339DCF6AB}" = Windows Live Messenger "{69C9C672-400A-43A0-B2DE-9DB38C371282}" = Windows Live Writer "{69CAC24D-B1DC-4B97-A1BE-FE21843108FE}" = Windows Live Writer Resources "{6A4ABCDC-0A49-4132-944E-01FBCCB3465C}" = Windows Live UX Platform Language Pack "{6A563426-3474-41C6-B847-42B39F1485B2}" = Windows Live Messenger "{6ABE832B-A5C7-44C1-B697-3E123B7B4D5B}" = Windows Live Mesh "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply "{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}" = VoiceOver Kit "{6B556C37-8919-4991-AC34-93D018B9EA49}" = Windows Live Photo Common "{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox "{6CB36609-E3A6-446C-A3C1-C71E311D2B9C}" = Windows Live Movie Maker "{6D30E864-46AE-435B-8230-8B5D42B4AE37}" = Windows Live Messenger "{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker "{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10 "{6EE9F44A-B8C7-4CDB-B2A9-441AF2AE315A}" = Windows Live Messenger "{6EF2BE2C-3121-48B7-B7A6-C56046B3A588}" = Windows Live Movie Maker "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0 "{6F37D92B-41AA-44B7-80D2-457ABDE11896}" = Windows Live Photo Common "{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10 "{709E38A9-7F80-4598-96CC-44B0D553FECE}" = Windows Live Messenger "{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-packardbell" = WildTangent Games App (Packard Bell Games) "{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames" = WildTangent Games App "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71527C7C-5289-4CB2-88C9-23344C0FF6C1}" = Windows Live Movie Maker "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser und SDK "{71A81378-79D5-40CC-9BDC-380642D1A87F}" = Windows Live Writer "{71C95134-F6A9-45E7-B7B3-07CA6012BF2A}" = Windows Live Mesh "{7272F232-A7E0-4B2B-A5D2-71B7C5E2379C}" = Windows Live Fotótár "{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic "{7327080F-6673-421F-BBD9-B618F357EEB3}" = Windows Live UX Platform Language Pack "{734104DE-C2BF-412F-BB97-FCCE1EC94229}" = Windows Live Writer Resources "{7373E17D-18E0-44A7-AC3A-6A3BFB85D3B3}" = Windows Live Movie Maker "{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common "{7465A996-0FCA-4D2D-A52C-F833B0829B5B}" = Windows Live Movie Maker "{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh "{74E8A7F6-575D-42C7-9178-E87D1B3BEFE8}" = Windows Live UX Platform Language Pack "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack "{77F69CA1-E53D-4D77-8BA3-FA07606CC851}" = Фотоальбом Windows Live "{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh "{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live "{7ADFA72D-2A9F-4DEC-80A5-2FAA27E23F0F}" = Windows Live Photo Common "{7AF8E500-B349-4A77-8265-9854E9A47925}" = Windows Live Movie Maker "{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World "{7BA19818-F717-4DFB-BC11-FAF17B2B8AEE}" = Pošta Windows Live "{7C2A3479-A5A0-412B-B0E6-6D64CBB9B251}" = Windows Live Photo Common "{7CB529B2-6C74-4878-9C3F-C29C3C3BBDC6}" = Windows Live Writer Resources "{7D0DE76C-874E-4BDE-A204-F4240160693E}" = Windows Live Photo Common "{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials "{7D926AD2-16D6-42C2-8CA1-AB09E96040BA}" = Windows Live Writer Resources "{7E017923-16F8-4E32-94EF-0A150BD196FE}" = Windows Live Writer "{7E566DEC-1C02-44CE-A4D0-B538D7C8A20C}" = shock "{7E90B133-FF47-48BB-91B8-36FC5A548FE9}" = Windows Live Writer Resources "{7F6021AE-E688-4D03-843A-C2260482BA0D}" = Windows Live Messenger "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Packard Bell Recovery Management "{7FF11E53-C002-4F40-8D68-6BE751E5DD62}" = Windows Live Writer Resources "{804DE397-F82C-4867-9085-E0AA539A3294}" = Windows Live Writer "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{80E8C65A-8F70-4585-88A2-ABC54BABD576}" = Windows Live Mesh "{827D3E4A-0186-48B7-9801-7D1E9DD40C07}" = Windows Live Essentials "{82803FF3-563F-414F-A403-8D4C167D4120}" = Windows Live Mail "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh "{84267681-BF16-40B6-9564-27BC57D7D71C}" = Windows Live Photo Common "{84A411F9-40A5-4CDA-BF46-E09FBB2BC313}" = Windows Live Essentials "{85373DA7-834E-4850-8AF5-1D99F7526857}" = Windows Live Photo Common "{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer "{861B1145-7762-4794-B40C-3FF0A389DFE6}" = Windows Live Photo Gallery "{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger "{87686C21-8A15-4b4d-A3F1-11141D9BE094}" = Battlefield Play4Free "{87976D85-DBF6-F263-39B6-500ACB658CE0}" = Catalyst Control Center Graphics Full Existing "{885F1BCD-C344-4758-85BD-09640CF449A5}" = Windows Live Photo Gallery "{8909CFA8-97BF-4077-AC0F-6925243FFE08}" = Windows Liven asennustyökalu "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8B9F50F9-BA6F-47c5-990B-76A74A1C68B0}" = 4500G510af "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8CF5D47D-27B7-49D6-A14F-10550B92749D}" = Windows Live UX Platform Language Pack "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch "{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends "{924B4D82-1B97-48EB-8F1E-55C4353C22DB}" = Windows Live Mail "{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{97F77D62-5110-4FA3-A2D3-410B92D31199}" = Windows Live Fotogaléria "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9932E1E3-9A6F-4C50-B8C1-D8FF01164368}" = GameMouse "{99BE7F5D-AB52-4404-9E03-4240FFAA7DE9}" = Windows Live Mesh "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc "{9BBB29A1-C71D-DD1D-66B1-352AAAB13FC6}" = CCC Help Danish "{9BD262D0-B788-4546-A0A5-F4F56EC3834B}" = Windows Live Photo Common "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9DA3F03B-2CEE-4344-838E-117861E61FAF}" = Windows Live Mail "{9DB90178-B5B0-45BD-B0A7-D40A6A1DF1CA}" = Windows Live Movie Maker "{9F4D1D9E-5542-B572-81A7-9DCB0AEED1BE}" = CCC Help French "{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail "{A0B91308-6666-4249-8FF6-1E11AFD75FE1}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A101F637-2E56-42C0-8E08-F1E9086BFAF3}" = Windows Live Movie Maker "{A199DB88-E22D-4CE7-90AC-B8BE396D7BF4}" = Windows Live Movie Maker "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A3EF3FAD-6ABA-1551-AD3B-D09361C5EEC9}" = CCC Help Polish "{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common "{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection "{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}" = Windows Live Photo Gallery "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A73FBC00-44F8-0ECF-76FB-14CF62120B55}" = ccc-core-static "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AACEAAE9-9CC3-5715-4539-EB13CA3C67BA}" = CCC Help Spanish "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB0B2113-5B96-4B95-8AD1-44613384911F}" = Windows Live Mesh "{AB78C965-5C67-409B-8433-D7B5BDB12073}" = Windows Live Writer Resources "{ABD534B7-E951-470E-92C2-CD5AF1735726}" = Windows Live Essentials "{ABE2F2AA-7ADC-4717-9573-BF3F83C696AC}" = Windows Live Mail "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch "{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh "{AD001A69-88CC-4766-B2DB-3C1DFAB9AC72}" = Windows Live Mesh "{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail "{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common "{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status "{AF01B90A-D25C-4F60-AECD-6EEDF509DC11}" = Windows Live Mesh "{B0AD205F-60D0-4084-AFB8-34D9A706D9A8}" = Windows Live Essentials "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail "{B2463AD3-1334-A30E-A523-D38E8E7B09A2}" = CCC Help Dutch "{B2BCA478-EC0F-45EE-A9E9-5EABE87EA72D}" = Windows Live Photo Common "{B33B61FE-701F-425F-98AB-2B85725CBF68}" = Windows Live Photo Common "{B3BE54A4-8DFE-4593-8E66-56AB7133B812}" = Windows Live Writer "{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials "{B63F0CE3-CCD0-490A-9A9C-E1A3B3A17137}" = Почта Windows Live "{B7B67AA5-12DA-4F01-918D-B1BF66779D8A}" = Windows Live Writer Resources "{BA2AD7F2-55AE-87B5-00DD-9B0C6F087FD0}" = Catalyst Control Center Graphics Light "{BC940CD7-FC71-83C5-2001-CF6FD07BA3D1}" = CCC Help Chinese Traditional "{BD4EBDB5-EB14-4120-BB04-BE0A26C7FB3E}" = Windows Live Photo Common "{BD695C2F-3EA0-4DA4-92D5-154072468721}" = Windows Live Fotoğraf Galerisi "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker "{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh "{BF847A60-119D-6888-B2DA-EC62F1B66BBB}" = CCC Help Chinese Standard "{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live "{C01FCACE-CC3D-49A2-ADC2-583A49857C58}" = Windows Live Essentials "{C08D5964-C42F-48EE-A893-2396F9562A7C}" = Windows Live Mesh "{C175D5B0-ED04-42C9-B23F-D8BD406173E7}" = 4500_G510af_Help "{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM) "{C1C9D199-B4DD-4895-92DD-9A726A2FE341}" = Windows Live Writer "{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant "{C454280F-3C3E-4929-B60E-9E6CED5717E7}" = Windows Live Mail "{c5b74464-3a04-417c-9eee-d0dc7d6af196}" = TubeBox "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{C8421D85-CA0E-4E93-A9A9-B826C4FB88EA}" = Windows Live Mail "{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common "{C97396A9-44BC-C856-0B92-93A6A417D6A8}" = Catalyst Control Center Graphics Full New "{CA10114E-3941-E8ED-70A3-17CAA2226AFC}" = CCC Help Turkish "{CAB89605-7C12-8082-32DF-B419C696BD12}" = Catalyst Control Center Core Implementation "{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live "{CB66242D-12B1-4494-82D2-6F53A7E024A3}" = Galerie foto Windows Live "{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}" = Windows Live Movie Maker "{CD442136-9115-4236-9C14-278F6A9DCB3F}" = Windows Live Movie Maker "{CD7CB1E6-267A-408F-877D-B532AD2C882E}" = Windows Live Photo Common "{CDC39BF2-9697-4959-B893-A2EE05EF6ACB}" = Windows Live Writer "{CE026CFE-73FE-4FED-9D5F-2C8D4DB512B0}" = TuneUp Utilities Language Pack (de-DE) "{CE929F09-3853-4180-BD90-30764BFF7136}" = גלריית התמונות של Windows Live "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{CF671BFE-6BA3-44E7-98C1-500D9C51D947}" = Windows Live Photo Gallery "{D07B1FDA-876B-4914-9E9A-309732B6D44F}" = Windows Live Mail "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86 "{D299197D-CDEA-41A6-A363-F532DE4114FD}" = Windows Live UX Platform Language Pack "{D31169F2-CD71-4337-B783-3E53F29F4CAD}" = Windows Live Mail "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D54A52A8-DF24-4CE8-850B-074CA47DFA74}" = Windows Live Messenger "{D588365A-AE39-4F27-BDAE-B4E72C8E900C}" = Windows Live Mail "{D6CBB3B2-F510-483D-AE0D-1CF3F43CF1EE}" = Windows Live Writer Resources "{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}" = Windows Live UX Platform Language Pack "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86 "{D98C2191-0AE0-4087-9153-018A4810DF45}" = CCC Help Norwegian "{DA29F644-2420-4448-8128-1331BE588999}" = Windows Live Writer "{DAEF48AD-89C8-4A93-B1DD-45B7E4FB6071}" = Windows Live Movie Maker "{DB1208F4-B2FE-44E9-BFE6-8824DBD7891B}" = Windows Live Movie Maker "{DBAA2B17-D596-4195-A169-BA2166B0D69B}" = Windows Live Mail "{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp "{DCAB6BA7-6533-44BF-9235-E5BF33B7431C}" = Windows Live Writer "{DD89CE29-BC88-40C6-A845-E2548682C5D6}" = Alcor Micro USB Card Reader "{DDC1E1BD-7615-4186-89E1-F5F43F9B6491}" = Windows Live Movie Maker "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer "{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials "{DF71ABBB-B834-41C0-BB58-80B0545D754C}" = Windows Live UX Platform Language Pack "{DF7D3C5E-87FC-6AE6-D986-35E0F05FEFD9}" = CCC Help Italian "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E2AE009D-37E5-4724-A6B8-0ED6A6BA4F68}" = Elements STI Installer "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{E5377D46-83C5-445A-A1F1-830336B42A10}" = Windows Live Galerija fotografija "{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer "{E59969EA-3B5B-4B24-8B94-43842A7FBFE9}" = Fotogalerija Windows Live "{E5DD4723-FE0B-436E-A815-DC23CF902A0B}" = Windows Live UX Platform Language Pack "{E62E0550-C098-43A2-B54B-03FB1E634483}" = Windows Live Writer "{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources "{E7688C7D-DE09-4D43-9785-534EDE9BC18E}" = Windows Live Messenger "{E83DC314-C926-4214-AD58-147691D6FE9F}" = Основные компоненты Windows Live "{E8524B28-3BBB-4763-AC83-0E83FE31C350}" = Windows Live Writer "{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live "{E9D98402-21AB-4E9F-BF6B-47AF36EF7E97}" = Windows Live Writer Resources "{EA777812-4905-4C08-8F6E-13BDCC734609}" = Windows Live UX Platform Language Pack "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{EB9955F8-467C-47FC-90F8-12CD5DF684C3}" = Adobe Premiere Elements 9 "{EBA8538C-F0B1-A089-D555-44DBF3A47C9F}" = CCC Help Finnish "{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live "{EE171732-BEB4-4576-887D-CB62727F01CA}" = Packard Bell Updater "{EE492B20-FB15-4A98-883C-3054354A11F8}" = Windows Live Messenger "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{EEF99142-3357-402C-B298-DEC303E12D92}" = Windows Live 影像中心 "{EF7EAB13-46FC-49DD-8E3C-AAF8A286C5BB}" = Windows Live 程式集 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0F5D89A-197C-495B-827E-3E98B811CD2E}" = Windows Live Photo Common "{F0F9505B-3ACF-4158-9311-D0285136AA00}" = Windows Live Essentials "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F22E305E-BD02-5CC1-92D0-BD7170CDFE45}" = CCC Help Portuguese "{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}" = Safari "{F302F4F0-588D-6501-1ACF-BE3FDCC9135D}" = Adobe Community Help "{F45BEC1B-DE2A-4F47-81E7-042D0C29CD09}" = TubeBox "{F4BEA6C1-AAC3-4810-AAEA-588E26E0F237}" = Windows Live UX Platform Language Pack "{F52C5BE7-3F57-464E-8A54-908402E43CE8}" = Windows Live Writer Resources "{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM) "{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10 "{F7A46527-DF1F-4B0F-9637-98547E189442}" = Windows Live Galeria de Fotos "{F7E80BA7-A09D-4DD1-828B-C4A0274D4720}" = Windows Live Mesh "{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{FA6CF94F-DACF-4FE7-959D-55C421B91B17}" = Windows Live Mail "{FB3D07AE-73D0-47A9-AC12-6F50BF8B6202}" = Windows Live Movie Maker "{FB79FDB7-4DE1-453D-99FE-9A880F57380E}" = Windows Live Fotogalerie "{FBCA06D2-4642-4F33-B20A-A7AB3F0D2E69}" = معرض صور Windows Live "{FCDE76CB-989D-4E32-9739-6A272D2B0ED7}" = Windows Live Mesh "{FD4B3108-0915-31E1-5A7C-AC5B3C33846C}" = CCC Help Greek "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials "{FEEF7F78-5876-438B-B554-C4CC426A4302}" = Windows Live Essentials "{FF105207-8423-4E13-B0B1-50753170B245}" = Windows Live Movie Maker "{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker "{FF737490-5A2D-4269-9D82-97DB2F7C0B09}" = Windows Live Movie Maker "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Photoshop Elements 9" = Adobe Photoshop Elements 9 "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "Akamai" = Akamai NetSession Interface Service "avast" = avast! Free Antivirus "Avira AntiVir Desktop" = Avira Free Antivirus "CamStudio" = CamStudio "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help "Desura" = Desura "Fraps" = Fraps (remove only) "Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.22.508 "Google Chrome" = Google Chrome "Identity Card" = Identity Card "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Video Web Camera "InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Packard Bell Social Networks "InstallShield_{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0 "InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Packard Bell MyBackup "InstallShield_{DD89CE29-BC88-40C6-A845-E2548682C5D6}" = Alcor Micro USB Card Reader "LManager" = Launch Manager "loadtbs-2.1" = loadtbs-2.1 "Mobile Partner" = Mobile Partner "Mozilla Firefox 16.0.2 (x86 de)" = Mozilla Firefox 16.0.2 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Office14.Click2Run" = Microsoft Office Klick-und-Los 2010 "Packard Bell Registration" = Packard Bell Registration "Packard Bell Screensaver" = Packard Bell ScreenSaver "Packard Bell Welcome Center" = Welcome Center "PremElem90" = Adobe Premiere Elements 9 "PunkBusterSvc" = PunkBuster Services "TuneUp Utilities 2012" = TuneUp Utilities 2012 "WildTangent packardbell Master Uninstall" = Packard Bell Games "WinLiveSuite" = Windows Live Essentials "Wisdom-soft Set up ASR 3.1 Free" = Wisdom-soft Set up ASR 3.1 Free "WTA-013c4596-5587-4af1-b8a0-93c24c1346c0" = John Deere Drive Green "WTA-1496e8cf-44e8-4c50-b43e-365ec591e2f1" = Mystery P.I. - The London Caper "WTA-1e5cb599-6179-4cdc-8b2f-2e8bd4ae4c97" = Zuma Deluxe "WTA-27609f1c-7c62-49c6-b93b-a7fec02d2cb7" = Jewel Quest Solitaire "WTA-3eb233d8-9e61-4180-8b85-7aceb266eace" = FATE "WTA-4b1ad90f-6c86-4041-9f69-6a011cd0514e" = Wedding Dash "WTA-5da7a7cd-086d-4667-9d85-8bd50f0b631e" = Chuzzle Deluxe "WTA-6cf7b628-cc0f-41f3-b3dc-d15295b4f073" = Slingo Deluxe "WTA-700ce3a6-3227-42fd-9a24-d5fd1118d407" = Polar Bowler "WTA-77107ae0-3289-4ba7-a1af-6010e61fda21" = Virtual Villagers - The Secret City "WTA-7d420375-28d4-4f8b-a115-df3e417c3633" = Agatha Christie - 4:50 from Paddington "WTA-8267faff-fb7c-4f8c-9db5-eff22db555df" = Plants vs. Zombies - Game of the Year "WTA-915558b6-e783-452a-82c7-d0eaa87d26b1" = Crazy Chicken Kart 2 "WTA-af4c16da-72c9-468b-bf04-24d70ab45207" = Diner Dash 2 Restaurant Rescue "WTA-afa6c663-3f95-41dc-89be-d07137f91841" = Penguins! "WTA-b68f3c91-526e-4e6c-82f1-6a0ffa1cecf1" = Torchlight "WTA-c29c590d-8770-4ad3-878b-0fc5c132326c" = Bejeweled 2 Deluxe ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-84541473-987749336-3452602534-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{87686C21-8A15-4b4d-A3F1-11141D9BE094}" = Battlefield Play4Free "876305d134f71bcc" = ROM-Runecalc "Akamai" = Akamai NetSession Interface "TeamSpeak 3 Client" = TeamSpeak 3 Client "UnityWebPlayer" = Unity Web Player ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 13.06.2012 12:33:13 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error - 14.06.2012 07:13:35 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 14.06.2012 07:23:55 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error - 14.06.2012 12:57:10 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 14.06.2012 13:24:47 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 15.06.2012 00:24:40 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 15.06.2012 06:26:09 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 15.06.2012 13:54:11 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 15.06.2012 16:41:06 | Computer Name = Marci´s-Laptop | Source = VSS | ID = 13 Description = Error - 15.06.2012 16:41:06 | Computer Name = Marci´s-Laptop | Source = VSS | ID = 8193 Description = Error - 16.06.2012 04:49:42 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 16.06.2012 07:05:24 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 18.11.2012 12:45:39 | Computer Name = Marci´s-Laptop | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Mobile Partner. OUC erreicht. Error - 18.11.2012 12:45:39 | Computer Name = Marci´s-Laptop | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 18.11.2012 12:48:05 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 18.11.2012 12:48:41 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 18.11.2012 13:11:31 | Computer Name = Marci´s-Laptop | Source = Service Control Manager | ID = 7000 Description = Der Dienst "TuneUp Designerweiterung" wurde aufgrund folgenden Fehlers nicht gestartet: %%1083 Error - 18.11.2012 13:12:03 | Computer Name = Marci´s-Laptop | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Mobile Partner. OUC erreicht. Error - 18.11.2012 13:12:03 | Computer Name = Marci´s-Laptop | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 18.11.2012 13:25:51 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 18.11.2012 14:59:31 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 18.11.2012 17:11:50 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = < End of report > |
19.11.2012, 18:24 | #8 |
| Claro Search eingfangen :( Hier ist das Extra txt:OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 19.11.2012 17:57:51 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marci´s\Desktop 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16433) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,86 Gb Total Physical Memory | 2,75 Gb Available Physical Memory | 71,20% Memory free 7,74 Gb Paging File | 6,17 Gb Available in Paging File | 79,67% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 223,94 Gb Total Space | 122,87 Gb Free Space | 54,87% Space Free | Partition Type: NTFS Drive D: | 224,14 Gb Total Space | 190,75 Gb Free Space | 85,10% Space Free | Partition Type: NTFS Computer Name: MARCI´S-LAPTOP | User Name: Marci´s | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_USERS\S-1-5-21-84541473-987749336-3452602534-1000\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{7C437346-AC8C-4D52-8E9E-CA0DC5D7A230}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{EE32EFC7-F713-477C-B0CA-A8FCF2C7B96F}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01AB67CC-D2B4-4A5C-8A70-7047D1FACADD}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{06AEAE5D-BE81-4868-B5FE-A9F0CD99088E}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{0802F110-FB13-4C9F-A3BA-25D4BAE1FFB3}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{0B7F5795-D8BD-48D1-84BE-2B27EE5FD2A0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{0D878372-7084-4487-8BEA-AF50B3D1524A}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{0E0425BE-7325-4227-A583-DE5B61DE15D0}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{0F937023-25F5-44D2-A954-BA149ABE4231}" = protocol=6 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "{1050B212-D62D-4689-B319-625FD69044AD}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{119FB347-489A-41AA-80C4-7F73817C230B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe | "{15A5FB94-5028-4831-AAF8-F9AC1E668C65}" = dir=in | name=air soccer fever | "{1854EA34-4C8E-45E0-89C9-5760EA6DFF43}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{19BD2144-0C77-40F1-99D0-160AD149CEB3}" = dir=in | name=@{microsoft.reader_6.2.9200.20523_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{1A018FF5-87A8-4A40-A8CC-D78A74F095B4}" = dir=out | name=@{microsoft.bingsports_1.5.1.249_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{1A42900B-0471-4135-9EB1-8A34A606CF45}" = dir=out | name=@{microsoft.xboxlivegames_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{1C48F737-E411-44AC-B387-3F1A42371B95}" = dir=in | name=pinball fx2 | "{1EF5EB73-75DC-4361-8E66-2E80F983D3FA}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{201C31F1-05D6-4060-9D97-A015036C36F1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{20FD48E5-E91E-4A9D-9C54-E38F12453F75}" = protocol=17 | dir=in | app=c:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe | "{2402ACD8-75D4-4E1E-B082-2B048993B6AA}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{2666A39B-BCF7-409F-8DBC-0E0C20E2F9AF}" = dir=out | name=robotek | "{2A668D37-8387-4ADA-B1D8-CF93A6E425F8}" = dir=out | name=@{microsoft.bing_1.5.1.251_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{2F7FEAAD-BA6C-4536-B5AE-2AEA57B960AC}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{30A9B654-CEA9-4552-B561-1F786F613DE7}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{328E6057-C3DE-4C4D-ABC8-84A015C66847}" = dir=out | name=@{microsoft.reader_6.2.9200.20523_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{3588DE6B-4FB5-416F-91F1-9537D7A21FD8}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{3962A026-750C-4E71-A3ED-736A53CF78C9}" = dir=out | name=windows_ie_ac_001 | "{3C3C1082-BBAE-4286-8A61-7B4804617356}" = dir=out | name=air soccer fever | "{3CA1DC00-25D2-4D88-A521-575C22796862}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe | "{3D78A9A0-4FF4-43A3-9DE9-7952F605EF30}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{40C97067-323E-471E-87D4-7D3C7DA84CB4}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "{41652096-5CF1-4D02-9351-BE8C9BD1A51A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{424B399E-34C2-40FB-949D-BB8124CD8299}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{48B155AD-7B10-42C1-ABB2-4D2EB3692583}" = dir=out | name=@{microsoft.bingfinance_1.5.1.406_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{4F8D5102-CF5C-4E83-BDAE-D826CC866E0D}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{50229B40-25B5-4E3E-B8B2-5036BA67CB72}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{5060FECA-40BF-4A5B-972C-F45C7ACF476A}" = dir=out | name=ebay | "{515C8CCC-442A-48FA-977F-EBC4E6C34606}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{5318C01D-B208-4155-A9E1-CCB54EB4F4FC}" = dir=out | name=@{microsoft.zunevideo_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{54EDFCFB-E9E0-4DC6-A294-9368FA306CCC}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{59D80D86-0C4F-4333-B9CB-386DB5CCFDA9}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe | "{5A1752EA-BD61-4BB9-B3F1-FD45A94628E1}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe | "{5A6B5BFC-3292-4069-B93C-09D6F85FB498}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{5B9DA972-57AD-4A17-B7C0-F00897B643B1}" = protocol=6 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe | "{5C940647-3BE8-4B71-AB58-590A49970BE9}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{6636ECA1-AE1F-4B6B-A030-9C917E4320B0}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{692BEC22-85F0-4D35-996B-F63C6FD674BF}" = dir=in | name=ebay | "{6B990AD9-90C6-4985-A165-7EE69AC89698}" = dir=out | name=jetpack joyride | "{6C889B7F-3587-4858-B85D-53C32CD5A335}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{6E4C1231-41FF-4DF9-8EDA-19527FDB08B9}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{6FDA96C1-B703-4C0E-B2D5-6914279B5189}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{73A8D331-3EDE-4495-84E0-EFD733E7A4B1}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{73DCD575-680C-44A6-B068-3A6F3FA94607}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{7586001D-E2CC-4102-A19C-636C153EE278}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{75F53686-F79F-448E-B9E4-A27D2F05958A}" = protocol=17 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe | "{79AF5E67-D42F-4CBB-831F-85AFBF0FEBCE}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{7CEA5561-792B-4769-80EA-4805B7B20807}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{7D74779D-3F1E-46CC-ACB6-AA3714BDE837}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{7FF60113-2D9F-4AC9-9C76-9BCA5EFCE89F}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{808883F5-1CE4-4885-B0F4-D963CDC4FCE4}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{88AEFA1B-FF88-441B-9E6D-44F6B7D2428E}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "{88E6335A-8411-47B4-94EF-8E86EEDD00A3}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{89548613-629D-49D8-9D29-C553ADC8F8EE}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{89FC59FE-5954-41DA-B458-7D1ADEE0327D}" = dir=in | name=robotek | "{8F32D51F-4E96-4094-873D-61EA61F6026B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe | "{9094AED6-F0E6-4ECC-B16D-84B4360D076D}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{90BD3770-4BE2-42D4-8E58-09F0E647D0DE}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{943E6C86-F2F7-4217-9410-7955C2B5400E}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{9494B231-D3ED-46AD-B878-68339FEEE3E3}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{983F463F-AB9D-4B29-8C1C-C3D6A81F7059}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{9A0EE505-A46E-4B82-87C4-ABBDBD9764BD}" = protocol=6 | dir=in | app=c:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe | "{A149DC0B-C6A8-411C-946F-3CA394C5027C}" = dir=out | name=google search | "{A602FF98-F7A2-4768-B915-37D6AA440357}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{A9791FDB-B353-4003-915B-73B242339868}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{A997550D-46DF-4822-BA52-7EBDFAE52AF8}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{A9DDC3C7-5B34-41CA-9EA9-9CC219DA7F84}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{AA7D5F15-4BE7-4372-B324-D12A8A0217A5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{BEF6308A-434D-4063-9FA5-CD7A7BB426FE}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{C2418CB4-F470-4628-AA3C-8B58099743DF}" = protocol=17 | dir=in | app=c:\users\marci´s\appdata\local\akamai\netsession_win.exe | "{C57A85BF-3B6F-44B9-B0CC-5017ACE7D6E8}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\demo\james cameron's avatar - das spiel (demo)\bin\avatardemo.exe | "{C853355E-3491-404D-8423-4806970CECFE}" = protocol=17 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "{C8AD87E1-CD5D-4C0D-A6F2-136601C7EED5}" = dir=in | name=jetpack joyride | "{CA969AFD-F04D-4510-A2FD-99616AE58338}" = dir=in | name=@{microsoft.skypeapp_1.1.0.25_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{CAC9D7A0-B61F-495E-AEF0-807690EAE3C0}" = protocol=6 | dir=in | app=c:\users\marci´s\appdata\local\akamai\netsession_win.exe | "{CCC076C8-CFDA-462F-8B9E-61D05BFA46A8}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{CD1456F9-7F20-4792-A969-A6D44826DF17}" = dir=out | name=@{microsoft.bingmaps_1.5.1.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{CF17E262-056F-4112-A4C5-7DD63789FEF1}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{D044D3EB-62CD-4852-9F7F-06F86C906B61}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe | "{D324ED89-A251-4623-ADA4-4EB876B9C06B}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{D4DF25AB-0217-4568-A92D-69C3C3287BD2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{D5DC554B-5681-471A-A724-1898261598AB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{DA61C96E-FC70-4423-ABAE-D705DE8AC847}" = dir=out | name=@{microsoft.bingnews_1.5.1.409_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{DD10F14D-58C3-4963-8E5C-9AAE17951377}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{DE23D039-B557-404F-BA6D-E7C18444C85D}" = dir=out | name=@{microsoft.bingweather_1.5.1.245_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{DF8A2E60-7FA7-493C-A960-E88ABBE2A5F4}" = dir=out | name=@{microsoft.zunemusic_1.1.137.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{E2F72C7E-25EF-4DF1-855F-B76A6E194817}" = dir=out | name=windows_ie_ac_001 | "{E31C2E16-B17C-48CC-B5D1-A57085F60D09}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\demo\james cameron's avatar - das spiel (demo)\bin\avatardemo.exe | "{E33816AE-7F88-4450-BC20-2BA3777D8FA0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{E5615AB9-363D-4FB3-8187-C7B67F615CE9}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{E6040050-91FC-430A-BDD3-A85FB243DE4B}" = dir=out | name=@{microsoft.skypeapp_1.1.0.25_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{E7045A8D-EF06-404C-B7FC-B659F77FD2B4}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{E915D9DA-3434-435E-A0B0-B45390CF5A49}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe | "{E927BBDF-D66A-421A-B7BD-5FF4314401D1}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{EA2FB9F2-B2BC-44B6-8B87-1644EA40E65B}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{EA6AA9C9-68AE-4D03-9521-586B9D1CB7DD}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{EFDFB918-48BF-47A7-8012-803D1D0EC3E4}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{F54E1DE1-C090-4841-B6F5-AB74224ECC47}" = dir=out | name=pinball fx2 | "{F90C9439-5E05-4F0C-953B-DEF0FE26E901}" = dir=out | name=@{microsoft.bingtravel_1.5.1.248_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{FC2982BD-09BC-49C7-8638-C40248E11422}" = dir=out | name=wikipedia | "{FF793FC7-05A9-4D91-8522-F99CDDEF89AA}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe | "TCP Query User{1163E211-6BDA-4EB6-93D5-4C0E2CA832F3}C:\aeriagames\wolfteam-de\wolfteam.bin" = protocol=6 | dir=in | app=c:\aeriagames\wolfteam-de\wolfteam.bin | "TCP Query User{2CC8676D-256F-4CE1-B5EA-E29271880E9D}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "TCP Query User{3F8660C3-0459-4FC4-82AB-A500CC353BBC}C:\program files (x86)\runes of magic\client.exe" = protocol=6 | dir=in | app=c:\program files (x86)\runes of magic\client.exe | "TCP Query User{4389B0CE-2BCA-4D25-9410-99598C3329DA}C:\program files (x86)\tera\tera-launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe | "TCP Query User{46EECCF7-B964-4261-BFAF-CD0E16C0FA65}C:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe" = protocol=6 | dir=in | app=c:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe | "TCP Query User{48009E57-D584-4C84-B880-6F986530D898}C:\program files (x86)\runes of magic\launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\runes of magic\launcher.exe | "TCP Query User{4DDF450A-C2AF-47E0-9884-0532CD1C8336}C:\users\marci´s\desktop\blacknight-2011\metin2client.dll" = protocol=6 | dir=in | app=c:\users\marci´s\desktop\blacknight-2011\metin2client.dll | "TCP Query User{B0E06146-ABCB-4DE6-9428-A8A07FE50875}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe | "TCP Query User{BDEAA2F2-0BE0-41AD-B396-54D7DBB8F82D}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "TCP Query User{DDB8C9DC-381C-487B-943D-0B149B0C1A4E}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=6 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "TCP Query User{ECB034F3-CA69-4700-8E2F-6F829BCE091B}C:\users\marci´s\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\marci´s\appdata\local\akamai\netsession_win.exe | "UDP Query User{098B087B-9BF4-4E66-B7D1-C859B18A7C19}C:\program files (x86)\tera\tera-launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe | "UDP Query User{36333577-186E-4730-86FF-F089FBAAAFEA}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "UDP Query User{4D3DA2F5-E9CC-4BFA-8E0B-DB4505705671}C:\program files (x86)\runes of magic\client.exe" = protocol=17 | dir=in | app=c:\program files (x86)\runes of magic\client.exe | "UDP Query User{61475386-59D3-4200-B294-7C9CAE3BFA3C}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=17 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "UDP Query User{7C288DE0-6A30-478F-BB2A-C3CD2418BF3E}C:\aeriagames\wolfteam-de\wolfteam.bin" = protocol=17 | dir=in | app=c:\aeriagames\wolfteam-de\wolfteam.bin | "UDP Query User{9CEC4C21-8B13-498D-A62E-08639E9E5BDE}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe | "UDP Query User{C91518F5-AC11-4A00-B327-F7D60B68DB64}C:\program files (x86)\runes of magic\launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\runes of magic\launcher.exe | "UDP Query User{DB85B86D-3D16-4D77-A530-03449920923E}C:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe" = protocol=17 | dir=in | app=c:\users\marci´s\appdata\roaming\kalydo\kalydoplayer\bin1\kalydoloader.exe | "UDP Query User{E41A0F5F-7337-47FA-904A-4E322016049E}C:\users\marci´s\desktop\blacknight-2011\metin2client.dll" = protocol=17 | dir=in | app=c:\users\marci´s\desktop\blacknight-2011\metin2client.dll | "UDP Query User{E59A2101-28A2-47C8-BCF4-B97682778BDF}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "UDP Query User{EFFC9917-B51A-462E-B17E-9E52A4890673}C:\users\marci´s\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\marci´s\appdata\local\akamai\netsession_win.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0919C44F-F18A-4E3B-A737-03685272CE72}" = Windows Live Remote Service Resources "{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes "{1553D712-B35F-4A82-BC72-D6B11A94BE3E}" = Windows Live Remote Service Resources "{1685AE50-97ED-485B-80F6-145071EE14B0}" = Windows Live Remote Service Resources "{17A4FD95-A507-43F1-BC92-D8572AF8340A}" = Windows Live Remote Service Resources "{19F09425-3C20-4730-9E2A-FC2E17C9F362}" = Windows Live Remote Service Resources "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{1EB2CFC3-E1C5-4FC4-B1F8-549DD6242C67}" = Windows Live Remote Service Resources "{22AB5CFD-B3DB-414E-9F99-4D024CCF1DA6}" = Windows Live Remote Client Resources "{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources "{2C1A6191-9804-4FDC-AB01-6F9183C91A13}" = Windows Live Remote Client Resources "{2F304EF4-0C31-47F4-8557-0641AAE4197C}" = Windows Live Remote Client Resources "{34384A2A-2CA2-4446-AB0E-1F360BA2AAC5}" = Windows Live Remote Service Resources "{350FD0E7-175A-4F86-84EF-05B77FCD7161}" = Windows Live Remote Service Resources "{3921492E-82D2-4180-8124-E347AD2F2DB4}" = Windows Live Remote Client Resources "{456FB9B5-AFBC-4761-BBDC-BA6BAFBB818F}" = Windows Live Remote Client Resources "{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{4C2E49C0-9276-4324-841D-774CCCE5DB48}" = Windows Live Remote Client Resources "{5141AA6E-5FAC-4473-BFFB-BEE69DDC7F2B}" = Windows Live Remote Service Resources "{5151E2DB-0748-4FD1-86A2-72E2F94F8BE7}" = Windows Live Remote Service Resources "{57F2BD1C-14A3-4785-8E48-2075B96EB2DF}" = Windows Live Remote Service Resources "{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources "{5F44A3A1-5D24-4708-8776-66B42B174C64}" = Windows Live Remote Client Resources "{5FCD6EFE-C2E7-4D77-8212-4BA223D8DF8E}" = Windows Live Remote Client Resources "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{5FEAD3E5-A158-4B66-B92B-0C959D7CF838}" = Windows Live Remote Service Resources "{61407251-7F7D-4303-810D-226A04D5CFF3}" = Windows Live Remote Service Resources "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{692CCE55-9EAE-4F57-A834-092882E7FE0B}" = Windows Live Remote Client Resources "{6C9D3F1D-DBBE-46F9-96A0-726CC72935AF}" = Windows Live Remote Service Resources "{6CBFDC3C-CF21-4C02-A6DC-A5A2707FAF55}" = Windows Live Remote Service Resources "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{702A632F-99CE-4E2D-B8F2-BF980E9CF62F}" = Windows Live Remote Client Resources "{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support "{7AEC844D-448A-455E-A34E-E1032196BBCD}" = Windows Live Remote Service Resources "{825C7D3F-D0B3-49D5-A42B-CBB0FBE85E99}" = Windows Live Remote Client Resources "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{850B8072-2EA7-4EDC-B930-7FE569495E76}" = Windows Live Remote Client Resources "{8970AE69-40BE-4058-9916-0ACB1B974A3D}" = Windows Live Remote Client Resources "{8B79B3A9-6E49-5FFB-2017-A822BBDC4992}" = ATI Catalyst Install Manager "{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources "{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{97A295A7-8840-4B35-BB61-27A8F4512CA3}" = Windows Live Remote Service Resources "{9E9C960F-7F47-46D5-A95D-950B354DE2B8}" = Windows Live Remote Service Resources "{A060182D-CDBE-4AD6-B9B4-860B435D6CBD}" = Windows Live Remote Client Resources "{A508D5A2-3AC1-4594-A718-A663D6D3CF11}" = Windows Live Remote Service Resources "{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources "{A84DB02B-9C2B-4272-9D2D-A80E00A56513}" = Broadcom Gigabit NetLink Controller "{B0B97CF2-5032-A645-7FFC-BD1E39FC4E3F}" = ccc-utility64 "{B0BF8602-EA52-4B0A-A2BD-EDABB0977030}" = Windows Live Remote Client Resources "{B680A663-1A15-47A5-A07C-7DF9A97558B7}" = Windows Live Remote Client Resources "{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources "{C504EC13-E122-4939-BD6E-EE5A3BAA5FEC}" = Windows Live Remote Client Resources "{C98517B6-DCE9-49B7-B19E-E384178D3986}" = HP Officejet 4500 G510a-f "{C9F05151-95A9-4B9B-B534-1760E2D014A5}" = Windows Live Remote Client Resources "{CFF3C688-2198-4BC3-A399-598226949C39}" = Windows Live Remote Client Resources "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{D1C1556C-7FF3-48A3-A5D6-7126F0FAFB66}" = Windows Live Remote Client Resources "{D3E4F422-7E0F-49C7-8B00-F42490D7A385}" = Windows Live Remote Service Resources "{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources "{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DBEDAF67-C5A3-4C91-951D-31F3FE63AF3F}" = Windows Live Remote Client Resources "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{ED421F97-E1C3-4E78-9F54-A53888215D58}" = Windows Live Remote Client Resources "{EFB20CF5-1A6D-41F3-8895-223346CE6291}" = Windows Live Remote Service Resources "{F6CB2C5F-B2C1-4DF1-BF44-39D0DC06FE6F}" = Windows Live Remote Service Resources "{FAA3933C-6F0D-4350-B66B-9D7F7031343E}" = Windows Live Remote Service Resources "{FAD0EC0B-753B-4A97-AD34-32AC1EC8DB69}" = Windows Live Remote Client Resources "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "HP Document Manager" = HP Document Manager 2.0 "HP Imaging Device Functions" = HP Imaging Device Functions 13.0 "HP Smart Web Printing" = HP Smart Web Printing 4.5 "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0 "HPExtendedCapabilities" = HP Customer Participation Program 13.0 "HPOCR" = OCR Software by I.R.I.S. 13.0 "Shop for HP Supplies" = Shop for HP Supplies "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = WinRAR 4.20 (64-Bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{001EE40D-BB45-4E5C-8A26-233791AAE0E0}" = COMPUTERBILD-Abzockschutz "{007F778D-F15C-4EAB-AE92-071D21FAF632}" = Adobe Photoshop Elements 9 "{00884F14-05BD-4D8E-90E5-1ABF78948CA4}" = Windows Live Mesh "{0125DB4D-98A0-4DBF-B68A-23BF08FFA6A3}" = Windows Live Messenger "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Video Web Camera "{02A414EA-0E5F-CD08-61EF-E155F31DFF76}" = Catalyst Control Center Graphics Previews Vista "{039480EE-6933-4845-88B8-77FD0C3D059D}" = Windows Live Mesh "{0557BBDA-69D3-4FA4-A93C-A5300F7034B4}" = Windows Live Writer "{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack "{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common "{06B05153-97E4-427E-B1A8-E098F6C5E52F}" = Windows Live Essentials "{073F306D-9851-4969-B828-7B6444D07D55}" = Windows Live Photo Common "{0785A0B6-07DF-43CF-B147-E1EB4CEA0345}" = Windows Live Messenger "{08938019-97FA-1C7A-19E0-0C8D56ED7CB2}" = CCC Help Hungarian "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{09922FFE-D153-44AE-8B60-EA3CB8088F93}" = Windows Live UX Platform Language Pack "{0A4C4B29-5A9D-4910-A13C-B920D5758744}" = بريد Windows Live "{0A4D717B-E6E8-11FA-E7D2-385EBB1A4A85}" = CCC Help Japanese "{0A9256E0-C924-46DE-921B-F6C4548A1C64}" = Windows Live Messenger "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack "{0C975FCC-A06E-4CB6-8F54-A9B52CF37781}" = Windows Liven sähköposti "{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail "{0EC0B576-90F9-43C3-8FAD-A4902DF4B8F4}" = Galeria de Fotografias do Windows Live "{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan "{10186F1A-6A14-43DF-A404-F0105D09BB07}" = Windows Live Mail "{110668B7-54C6-47C9-BAC4-1CE77F156AF5}" = Windows Live Mesh "{11417707-1F72-4279-95A3-01E0B898BBF5}" = Windows Live Mesh "{11778DA1-0495-4ED9-972F-F9E0B0367CD5}" = Windows Live Writer "{1203DC60-D9BD-44F9-B372-2B8F227E6094}" = Windows Live Temel Parçalar "{128133D3-037A-4C62-B1B7-55666A10587A}" = Windows Live UX Platform Language Pack "{133D9D67-D475-4407-AC3C-D558087B2453}" = Windows Live Movie Maker "{13BA5548-1065-4DBE-B115-681AFB77263B}" = CCC Help Swedish "{14B441B7-774D-4170-98EA-A13667AE6218}" = Windows Live Writer Resources "{16890D7F-1C77-733B-D8E4-F5D4315A5F93}" = Catalyst Control Center Localization All "{168E7302-890A-4138-9109-A225ACAF7AD1}" = Windows Live Photo Common "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch "{17835B63-8308-427F-8CF5-D76E0D5FE457}" = Windows Live Essentials "{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials "{198EA334-8A3F-4CB2-9D61-6C10B8168A6F}" = Windows Live Writer "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1A72337E-D126-4BAF-AC89-E6122DB71866}" = Windows Liven valokuvavalikoima "{1A82AE99-84D3-486D-BAD6-675982603E14}" = Windows Live Writer "{1CBDB473-E303-EFAE-88D1-6F741ACD5B31}" = CCC Help Czech "{1D6C2068-807F-4B76-A0C2-62ED05656593}" = Windows Live Writer "{1D8912B0-343C-EB1F-28EE-B672D444C192}" = Catalyst Control Center InstallProxy "{1DA6D447-C54D-4833-84D4-3EA31CAECE9B}" = Windows Live UX Platform Language Pack "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FC83EAE-74C8-4C72-8400-2D8E40A017DE}" = Windows Live Writer "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery "{220C7F8C-929D-4F71-9DC7-F7A6823B38E4}" = Windows Live UX Platform Language Pack "{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1 "{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10 "{249EE21B-8EDD-4F36-8A23-E580E9DBE80A}" = Windows Live Mail "{24DF33E0-F924-4D0D-9B96-11F28F0D602D}" = Windows Live UX Platform Language Pack "{2511AAD7-82DF-4B97-B0B3-E1B933317010}" = Windows Live Writer Resources "{25175695-4B20-4298-9F34-C2C57CD277B3}" = Elements STI Installer "{25A381E1-0AB9-4E7A-ACCE-BA49D519CF4E}" = Windows Live Mail "{25CD4B12-8CC5-433E-B723-C9CB41FA8C5A}" = Windows Live Writer "{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java(TM) 6 Update 37 "{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{28B9D2D8-4304-483F-AD71-51890A063A74}" = Windows Live Photo Common "{29373E24-AC72-424E-8F2A-FB0F9436F21F}" = Windows Live Photo Common "{2A07C35B-8384-4DA4-9A95-442B6C89A073}" = Windows Live Essentials "{2AD2DD70-27F7-4343-BB4E-DE50A32D854B}" = Windows Live Messenger "{2BA5FD10-653F-4CAF-9CCD-F685082A1DC1}" = Windows Live Writer "{2C4E06CC-1F04-4C25-8B3C-93A9049EC42C}" = Windows Live UX Platform Language Pack "{2C59BF0E-66A5-681E-60FE-8D18CE6319A1}" = CCC Help German "{2C7E8AA1-9C03-4606-BF34-5D99D07964DA}" = Windows Live Messenger "{2C865FB0-051E-4D22-AC62-428E035AEAF0}" = Windows Live Mesh "{2C9D4FCA-3E7F-9368-6955-EA6D65F7DC78}" = CCC Help English "{2D3E034E-F76B-410A-A169-55755D2637BB}" = Windows Live Mesh "{2E50E321-4747-4EB5-9ECB-BBC6C3AC0F31}" = Windows Live Writer Resources "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update "{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App "{303143DD-1F6D-4BC5-9342-FFC2E19B2DBD}" = Windows Live Messenger "{3125D9DE-8D7A-4987-95F3-8A42389833D8}" = Windows Live Writer Resources "{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012 "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM) "{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live "{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10 "{34C4F5AF-D757-4E6A-ABCA-65AB5A50A1A8}" = Windows Live Messenger "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{370F888E-42A7-4911-9E34-7D74632E17EB}" = Windows Live Photo Common "{3788B9B7-C15F-4C64-D52B-3DD1BA494B7A}" = CCC Help Korean "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{39BDD209-5704-480C-9F4A-B69D0370DDBB}" = Windows Live Messenger "{39F95B0B-A0B7-4FA7-BB6C-197DA2546468}" = Windows Live Mesh "{3B72C1E0-26A1-40F6-8516-D50C651DFB3C}" = Windows Live Essentials "{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer "{3D0C22FA-96D7-4789-BC5B-991A5A99BFFA}" = Windows Live Messenger "{3D200EB9-44FC-432F-1E35-C20AB5FDCD77}" = CCC Help Thai "{3DB0448D-AD82-4923-B305-D001E521A964}" = Packard Bell Power Management "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{3EB6F78A-66E3-434f-BD0E-76C7D078DB5E}" = 4500G510af_Software_Min "{3F4143A1-9C21-4011-8679-3BC1014C6886}" = Windows Live Mesh "{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup "{40BFD84C-64CD-42CC-9909-8734C50429C6}" = Windows Live UX Platform Language Pack "{410DF0AA-882D-450D-9E1B-F5397ACFFA80}" = Windows Live Essentials "{4264C020-850B-4F08-ACBE-98205D9C336C}" = Windows Live Writer "{429DF1A0-3610-4E9E-8ACE-3C8AC1BA8FCA}" = Windows Live Photo Gallery "{433EACD8-4747-4A6A-826A-FFA9F39B0D40}" = Elements 9 Organizer "{43B43577-2514-4CE0-B14A-7E85C17C0453}" = Windows Live Essentials "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg "{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax "{4444F27C-B1A8-464E-9486-4C37BAB39A09}" = Фотогалерия на Windows Live "{44D52071-5077-2839-1AE6-863563AEA269}" = CCC Help Russian "{458F399F-62AC-4747-99F5-499BBF073D29}" = Windows Live Writer Resources "{4664ED39-C80A-48F7-93CD-EBDCAFAB6CC5}" = Windows Live Writer Resources "{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh "{4736B0ED-F6A1-48EC-A1B7-C053027648F1}" = Galeria fotogràfica del Windows Live "{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live "{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer "{48F597DD-D397-4CFA-91A0-4C033A0113BD}" = Windows Live Mail "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A04DB63-8F81-4EF4-9D09-61A2057EF419}" = Windows Live Essentials "{4A275FD1-2F24-4274-8C01-813F5AD1A92D}" = Windows Live Messenger "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter "{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer "{4BCBC4D0-1D88-462D-809E-506F34EA11C0}" = Catalyst Control Center - Branding "{4C378B16-46B7-4DA1-A2CE-2EE676F74680}" = Windows Live UX Platform Language Pack "{4D141929-141B-4605-95D6-2B8650C1C6DA}" = Windows Live UX Platform Language Pack "{4D83F339-5A5C-4B21-8FD3-5D407B981E72}" = Windows Live Photo Common "{50300123-F8FC-4B50-B449-E847D04F1BA2}" = Windows Live Messenger "{506FC723-8E6C-4417-9CFF-351F99130425}" = Windows Live UX Platform Language Pack "{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM) "{523DF2BB-3A85-4047-9898-29DC8AEB7E69}" = Windows Live UX Platform Language Pack "{5275D81E-83AD-4DE4-BC2B-6E6BA3A33244}" = Windows Live Writer Resources "{5495E9A4-501A-4D4C-87C9-E80916CA9478}" = Windows Live UX Platform Language Pack "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5C2F5C1B-9732-4F81-8FBF-6711627DC508}" = Windows Live Fotogalleri "{5C83944D-5319-4AD6-A803-C08446B27596}" = BlueStacks "{5CF5B1A5-CBC3-42F0-8533-5A5090665862}" = Windows Live Mesh "{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker "{5D2E7BD7-4B6F-4086-BA8A-E88484750624}" = Windows Live Writer Resources "{5D90ABE5-8A35-4947-8269-6F40BCE47A95}" = Windows Live Messenger "{5DA7D148-D2D2-4C67-8444-2F0F9BD88A06}" = Windows Live Writer "{5E627606-53B9-42D1-97E1-D03F6229E248}" = Windows Live UX Platform Language Pack "{5F6E678A-7E61-448A-86CB-BC2AD1E04138}" = Windows Live Messenger "{6057E21C-ABE9-4059-AE3E-3BEB9925E660}" = Windows Live Messenger "{60C3C026-DB53-4DAB-8B97-7C1241F9A847}" = Windows Live Movie Maker "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{625D45F0-5DCB-48BF-8770-C240A84DAAEB}" = Windows Live Mesh "{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources "{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}" = Nero Multimedia Suite 10 Essentials "{63AE67AA-1AB1-4565-B4EF-ABBC5C841E8D}" = Windows Live Messenger "{63CF7D0C-B6E7-4EE9-8253-816B613CC437}" = Windows Live Mail "{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2 "{640798A0-A4FB-4C52-AC72-755134767F1E}" = Windows Live Movie Maker "{64376910-1860-4CEF-8B34-AA5D205FC5F1}" = Poczta usługi Windows Live "{644063FA-ABA3-42AC-A8AC-3EDC0706018B}" = Windows Live Mesh "{6491AB99-A11E-41FD-A5E7-32DE8A097B8E}" = Windows Live Essentials "{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}" = Windows Live Movie Maker "{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Packard Bell Social Networks "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update "{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0 "{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail "{6807427D-8D68-4D30-AF5B-0B38F8F948C8}" = Windows Live Writer Resources "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting "{6986737B-F286-40D1-87AF-938339DCF6AB}" = Windows Live Messenger "{69C9C672-400A-43A0-B2DE-9DB38C371282}" = Windows Live Writer "{69CAC24D-B1DC-4B97-A1BE-FE21843108FE}" = Windows Live Writer Resources "{6A4ABCDC-0A49-4132-944E-01FBCCB3465C}" = Windows Live UX Platform Language Pack "{6A563426-3474-41C6-B847-42B39F1485B2}" = Windows Live Messenger "{6ABE832B-A5C7-44C1-B697-3E123B7B4D5B}" = Windows Live Mesh "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply "{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}" = VoiceOver Kit "{6B556C37-8919-4991-AC34-93D018B9EA49}" = Windows Live Photo Common "{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox "{6CB36609-E3A6-446C-A3C1-C71E311D2B9C}" = Windows Live Movie Maker "{6D30E864-46AE-435B-8230-8B5D42B4AE37}" = Windows Live Messenger "{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker "{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10 "{6EE9F44A-B8C7-4CDB-B2A9-441AF2AE315A}" = Windows Live Messenger "{6EF2BE2C-3121-48B7-B7A6-C56046B3A588}" = Windows Live Movie Maker "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0 "{6F37D92B-41AA-44B7-80D2-457ABDE11896}" = Windows Live Photo Common "{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10 "{709E38A9-7F80-4598-96CC-44B0D553FECE}" = Windows Live Messenger "{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-packardbell" = WildTangent Games App (Packard Bell Games) "{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames" = WildTangent Games App "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71527C7C-5289-4CB2-88C9-23344C0FF6C1}" = Windows Live Movie Maker "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser und SDK "{71A81378-79D5-40CC-9BDC-380642D1A87F}" = Windows Live Writer "{71C95134-F6A9-45E7-B7B3-07CA6012BF2A}" = Windows Live Mesh "{7272F232-A7E0-4B2B-A5D2-71B7C5E2379C}" = Windows Live Fotótár "{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic "{7327080F-6673-421F-BBD9-B618F357EEB3}" = Windows Live UX Platform Language Pack "{734104DE-C2BF-412F-BB97-FCCE1EC94229}" = Windows Live Writer Resources "{7373E17D-18E0-44A7-AC3A-6A3BFB85D3B3}" = Windows Live Movie Maker "{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common "{7465A996-0FCA-4D2D-A52C-F833B0829B5B}" = Windows Live Movie Maker "{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh "{74E8A7F6-575D-42C7-9178-E87D1B3BEFE8}" = Windows Live UX Platform Language Pack "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack "{77F69CA1-E53D-4D77-8BA3-FA07606CC851}" = Фотоальбом Windows Live "{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh "{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live "{7ADFA72D-2A9F-4DEC-80A5-2FAA27E23F0F}" = Windows Live Photo Common "{7AF8E500-B349-4A77-8265-9854E9A47925}" = Windows Live Movie Maker "{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World "{7BA19818-F717-4DFB-BC11-FAF17B2B8AEE}" = Pošta Windows Live "{7C2A3479-A5A0-412B-B0E6-6D64CBB9B251}" = Windows Live Photo Common "{7CB529B2-6C74-4878-9C3F-C29C3C3BBDC6}" = Windows Live Writer Resources "{7D0DE76C-874E-4BDE-A204-F4240160693E}" = Windows Live Photo Common "{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials "{7D926AD2-16D6-42C2-8CA1-AB09E96040BA}" = Windows Live Writer Resources "{7E017923-16F8-4E32-94EF-0A150BD196FE}" = Windows Live Writer "{7E566DEC-1C02-44CE-A4D0-B538D7C8A20C}" = shock "{7E90B133-FF47-48BB-91B8-36FC5A548FE9}" = Windows Live Writer Resources "{7F6021AE-E688-4D03-843A-C2260482BA0D}" = Windows Live Messenger "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Packard Bell Recovery Management "{7FF11E53-C002-4F40-8D68-6BE751E5DD62}" = Windows Live Writer Resources "{804DE397-F82C-4867-9085-E0AA539A3294}" = Windows Live Writer "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{80E8C65A-8F70-4585-88A2-ABC54BABD576}" = Windows Live Mesh "{827D3E4A-0186-48B7-9801-7D1E9DD40C07}" = Windows Live Essentials "{82803FF3-563F-414F-A403-8D4C167D4120}" = Windows Live Mail "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh "{84267681-BF16-40B6-9564-27BC57D7D71C}" = Windows Live Photo Common "{84A411F9-40A5-4CDA-BF46-E09FBB2BC313}" = Windows Live Essentials "{85373DA7-834E-4850-8AF5-1D99F7526857}" = Windows Live Photo Common "{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer "{861B1145-7762-4794-B40C-3FF0A389DFE6}" = Windows Live Photo Gallery "{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger "{87686C21-8A15-4b4d-A3F1-11141D9BE094}" = Battlefield Play4Free "{87976D85-DBF6-F263-39B6-500ACB658CE0}" = Catalyst Control Center Graphics Full Existing "{885F1BCD-C344-4758-85BD-09640CF449A5}" = Windows Live Photo Gallery "{8909CFA8-97BF-4077-AC0F-6925243FFE08}" = Windows Liven asennustyökalu "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8B9F50F9-BA6F-47c5-990B-76A74A1C68B0}" = 4500G510af "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8CF5D47D-27B7-49D6-A14F-10550B92749D}" = Windows Live UX Platform Language Pack "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch "{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends "{924B4D82-1B97-48EB-8F1E-55C4353C22DB}" = Windows Live Mail "{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{97F77D62-5110-4FA3-A2D3-410B92D31199}" = Windows Live Fotogaléria "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9932E1E3-9A6F-4C50-B8C1-D8FF01164368}" = GameMouse "{99BE7F5D-AB52-4404-9E03-4240FFAA7DE9}" = Windows Live Mesh "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc "{9BBB29A1-C71D-DD1D-66B1-352AAAB13FC6}" = CCC Help Danish "{9BD262D0-B788-4546-A0A5-F4F56EC3834B}" = Windows Live Photo Common "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9DA3F03B-2CEE-4344-838E-117861E61FAF}" = Windows Live Mail "{9DB90178-B5B0-45BD-B0A7-D40A6A1DF1CA}" = Windows Live Movie Maker "{9F4D1D9E-5542-B572-81A7-9DCB0AEED1BE}" = CCC Help French "{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail "{A0B91308-6666-4249-8FF6-1E11AFD75FE1}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A101F637-2E56-42C0-8E08-F1E9086BFAF3}" = Windows Live Movie Maker "{A199DB88-E22D-4CE7-90AC-B8BE396D7BF4}" = Windows Live Movie Maker "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A3EF3FAD-6ABA-1551-AD3B-D09361C5EEC9}" = CCC Help Polish "{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common "{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection "{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}" = Windows Live Photo Gallery "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A73FBC00-44F8-0ECF-76FB-14CF62120B55}" = ccc-core-static "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AACEAAE9-9CC3-5715-4539-EB13CA3C67BA}" = CCC Help Spanish "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB0B2113-5B96-4B95-8AD1-44613384911F}" = Windows Live Mesh "{AB78C965-5C67-409B-8433-D7B5BDB12073}" = Windows Live Writer Resources "{ABD534B7-E951-470E-92C2-CD5AF1735726}" = Windows Live Essentials "{ABE2F2AA-7ADC-4717-9573-BF3F83C696AC}" = Windows Live Mail "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch "{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh "{AD001A69-88CC-4766-B2DB-3C1DFAB9AC72}" = Windows Live Mesh "{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail "{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common "{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status "{AF01B90A-D25C-4F60-AECD-6EEDF509DC11}" = Windows Live Mesh "{B0AD205F-60D0-4084-AFB8-34D9A706D9A8}" = Windows Live Essentials "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail "{B2463AD3-1334-A30E-A523-D38E8E7B09A2}" = CCC Help Dutch "{B2BCA478-EC0F-45EE-A9E9-5EABE87EA72D}" = Windows Live Photo Common "{B33B61FE-701F-425F-98AB-2B85725CBF68}" = Windows Live Photo Common "{B3BE54A4-8DFE-4593-8E66-56AB7133B812}" = Windows Live Writer "{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials "{B63F0CE3-CCD0-490A-9A9C-E1A3B3A17137}" = Почта Windows Live "{B7B67AA5-12DA-4F01-918D-B1BF66779D8A}" = Windows Live Writer Resources "{BA2AD7F2-55AE-87B5-00DD-9B0C6F087FD0}" = Catalyst Control Center Graphics Light "{BC940CD7-FC71-83C5-2001-CF6FD07BA3D1}" = CCC Help Chinese Traditional "{BD4EBDB5-EB14-4120-BB04-BE0A26C7FB3E}" = Windows Live Photo Common "{BD695C2F-3EA0-4DA4-92D5-154072468721}" = Windows Live Fotoğraf Galerisi "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker "{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh "{BF847A60-119D-6888-B2DA-EC62F1B66BBB}" = CCC Help Chinese Standard "{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live "{C01FCACE-CC3D-49A2-ADC2-583A49857C58}" = Windows Live Essentials "{C08D5964-C42F-48EE-A893-2396F9562A7C}" = Windows Live Mesh "{C175D5B0-ED04-42C9-B23F-D8BD406173E7}" = 4500_G510af_Help "{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM) "{C1C9D199-B4DD-4895-92DD-9A726A2FE341}" = Windows Live Writer "{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant "{C454280F-3C3E-4929-B60E-9E6CED5717E7}" = Windows Live Mail "{c5b74464-3a04-417c-9eee-d0dc7d6af196}" = TubeBox "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{C8421D85-CA0E-4E93-A9A9-B826C4FB88EA}" = Windows Live Mail "{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common "{C97396A9-44BC-C856-0B92-93A6A417D6A8}" = Catalyst Control Center Graphics Full New "{CA10114E-3941-E8ED-70A3-17CAA2226AFC}" = CCC Help Turkish "{CAB89605-7C12-8082-32DF-B419C696BD12}" = Catalyst Control Center Core Implementation "{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live "{CB66242D-12B1-4494-82D2-6F53A7E024A3}" = Galerie foto Windows Live "{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}" = Windows Live Movie Maker "{CD442136-9115-4236-9C14-278F6A9DCB3F}" = Windows Live Movie Maker "{CD7CB1E6-267A-408F-877D-B532AD2C882E}" = Windows Live Photo Common "{CDC39BF2-9697-4959-B893-A2EE05EF6ACB}" = Windows Live Writer "{CE026CFE-73FE-4FED-9D5F-2C8D4DB512B0}" = TuneUp Utilities Language Pack (de-DE) "{CE929F09-3853-4180-BD90-30764BFF7136}" = גלריית התמונות של Windows Live "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{CF671BFE-6BA3-44E7-98C1-500D9C51D947}" = Windows Live Photo Gallery "{D07B1FDA-876B-4914-9E9A-309732B6D44F}" = Windows Live Mail "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86 "{D299197D-CDEA-41A6-A363-F532DE4114FD}" = Windows Live UX Platform Language Pack "{D31169F2-CD71-4337-B783-3E53F29F4CAD}" = Windows Live Mail "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D54A52A8-DF24-4CE8-850B-074CA47DFA74}" = Windows Live Messenger "{D588365A-AE39-4F27-BDAE-B4E72C8E900C}" = Windows Live Mail "{D6CBB3B2-F510-483D-AE0D-1CF3F43CF1EE}" = Windows Live Writer Resources "{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}" = Windows Live UX Platform Language Pack "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86 "{D98C2191-0AE0-4087-9153-018A4810DF45}" = CCC Help Norwegian "{DA29F644-2420-4448-8128-1331BE588999}" = Windows Live Writer "{DAEF48AD-89C8-4A93-B1DD-45B7E4FB6071}" = Windows Live Movie Maker "{DB1208F4-B2FE-44E9-BFE6-8824DBD7891B}" = Windows Live Movie Maker "{DBAA2B17-D596-4195-A169-BA2166B0D69B}" = Windows Live Mail "{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp "{DCAB6BA7-6533-44BF-9235-E5BF33B7431C}" = Windows Live Writer "{DD89CE29-BC88-40C6-A845-E2548682C5D6}" = Alcor Micro USB Card Reader "{DDC1E1BD-7615-4186-89E1-F5F43F9B6491}" = Windows Live Movie Maker "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer "{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials "{DF71ABBB-B834-41C0-BB58-80B0545D754C}" = Windows Live UX Platform Language Pack "{DF7D3C5E-87FC-6AE6-D986-35E0F05FEFD9}" = CCC Help Italian "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E2AE009D-37E5-4724-A6B8-0ED6A6BA4F68}" = Elements STI Installer "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{E5377D46-83C5-445A-A1F1-830336B42A10}" = Windows Live Galerija fotografija "{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer "{E59969EA-3B5B-4B24-8B94-43842A7FBFE9}" = Fotogalerija Windows Live "{E5DD4723-FE0B-436E-A815-DC23CF902A0B}" = Windows Live UX Platform Language Pack "{E62E0550-C098-43A2-B54B-03FB1E634483}" = Windows Live Writer "{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources "{E7688C7D-DE09-4D43-9785-534EDE9BC18E}" = Windows Live Messenger "{E83DC314-C926-4214-AD58-147691D6FE9F}" = Основные компоненты Windows Live "{E8524B28-3BBB-4763-AC83-0E83FE31C350}" = Windows Live Writer "{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live "{E9D98402-21AB-4E9F-BF6B-47AF36EF7E97}" = Windows Live Writer Resources "{EA777812-4905-4C08-8F6E-13BDCC734609}" = Windows Live UX Platform Language Pack "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{EB9955F8-467C-47FC-90F8-12CD5DF684C3}" = Adobe Premiere Elements 9 "{EBA8538C-F0B1-A089-D555-44DBF3A47C9F}" = CCC Help Finnish "{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live "{EE171732-BEB4-4576-887D-CB62727F01CA}" = Packard Bell Updater "{EE492B20-FB15-4A98-883C-3054354A11F8}" = Windows Live Messenger "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{EEF99142-3357-402C-B298-DEC303E12D92}" = Windows Live 影像中心 "{EF7EAB13-46FC-49DD-8E3C-AAF8A286C5BB}" = Windows Live 程式集 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0F5D89A-197C-495B-827E-3E98B811CD2E}" = Windows Live Photo Common "{F0F9505B-3ACF-4158-9311-D0285136AA00}" = Windows Live Essentials "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F22E305E-BD02-5CC1-92D0-BD7170CDFE45}" = CCC Help Portuguese "{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}" = Safari "{F302F4F0-588D-6501-1ACF-BE3FDCC9135D}" = Adobe Community Help "{F45BEC1B-DE2A-4F47-81E7-042D0C29CD09}" = TubeBox "{F4BEA6C1-AAC3-4810-AAEA-588E26E0F237}" = Windows Live UX Platform Language Pack "{F52C5BE7-3F57-464E-8A54-908402E43CE8}" = Windows Live Writer Resources "{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM) "{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10 "{F7A46527-DF1F-4B0F-9637-98547E189442}" = Windows Live Galeria de Fotos "{F7E80BA7-A09D-4DD1-828B-C4A0274D4720}" = Windows Live Mesh "{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{FA6CF94F-DACF-4FE7-959D-55C421B91B17}" = Windows Live Mail "{FB3D07AE-73D0-47A9-AC12-6F50BF8B6202}" = Windows Live Movie Maker "{FB79FDB7-4DE1-453D-99FE-9A880F57380E}" = Windows Live Fotogalerie "{FBCA06D2-4642-4F33-B20A-A7AB3F0D2E69}" = معرض صور Windows Live "{FCDE76CB-989D-4E32-9739-6A272D2B0ED7}" = Windows Live Mesh "{FD4B3108-0915-31E1-5A7C-AC5B3C33846C}" = CCC Help Greek "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials "{FEEF7F78-5876-438B-B554-C4CC426A4302}" = Windows Live Essentials "{FF105207-8423-4E13-B0B1-50753170B245}" = Windows Live Movie Maker "{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker "{FF737490-5A2D-4269-9D82-97DB2F7C0B09}" = Windows Live Movie Maker "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Photoshop Elements 9" = Adobe Photoshop Elements 9 "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "Akamai" = Akamai NetSession Interface Service "avast" = avast! Free Antivirus "Avira AntiVir Desktop" = Avira Free Antivirus "CamStudio" = CamStudio "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help "Desura" = Desura "Fraps" = Fraps (remove only) "Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.22.508 "Google Chrome" = Google Chrome "Identity Card" = Identity Card "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Video Web Camera "InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Packard Bell Social Networks "InstallShield_{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0 "InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Packard Bell MyBackup "InstallShield_{DD89CE29-BC88-40C6-A845-E2548682C5D6}" = Alcor Micro USB Card Reader "LManager" = Launch Manager "loadtbs-2.1" = loadtbs-2.1 "Mobile Partner" = Mobile Partner "Mozilla Firefox 16.0.2 (x86 de)" = Mozilla Firefox 16.0.2 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Office14.Click2Run" = Microsoft Office Klick-und-Los 2010 "Packard Bell Registration" = Packard Bell Registration "Packard Bell Screensaver" = Packard Bell ScreenSaver "Packard Bell Welcome Center" = Welcome Center "PremElem90" = Adobe Premiere Elements 9 "PunkBusterSvc" = PunkBuster Services "TuneUp Utilities 2012" = TuneUp Utilities 2012 "WildTangent packardbell Master Uninstall" = Packard Bell Games "WinLiveSuite" = Windows Live Essentials "Wisdom-soft Set up ASR 3.1 Free" = Wisdom-soft Set up ASR 3.1 Free "WTA-013c4596-5587-4af1-b8a0-93c24c1346c0" = John Deere Drive Green "WTA-1496e8cf-44e8-4c50-b43e-365ec591e2f1" = Mystery P.I. - The London Caper "WTA-1e5cb599-6179-4cdc-8b2f-2e8bd4ae4c97" = Zuma Deluxe "WTA-27609f1c-7c62-49c6-b93b-a7fec02d2cb7" = Jewel Quest Solitaire "WTA-3eb233d8-9e61-4180-8b85-7aceb266eace" = FATE "WTA-4b1ad90f-6c86-4041-9f69-6a011cd0514e" = Wedding Dash "WTA-5da7a7cd-086d-4667-9d85-8bd50f0b631e" = Chuzzle Deluxe "WTA-6cf7b628-cc0f-41f3-b3dc-d15295b4f073" = Slingo Deluxe "WTA-700ce3a6-3227-42fd-9a24-d5fd1118d407" = Polar Bowler "WTA-77107ae0-3289-4ba7-a1af-6010e61fda21" = Virtual Villagers - The Secret City "WTA-7d420375-28d4-4f8b-a115-df3e417c3633" = Agatha Christie - 4:50 from Paddington "WTA-8267faff-fb7c-4f8c-9db5-eff22db555df" = Plants vs. Zombies - Game of the Year "WTA-915558b6-e783-452a-82c7-d0eaa87d26b1" = Crazy Chicken Kart 2 "WTA-af4c16da-72c9-468b-bf04-24d70ab45207" = Diner Dash 2 Restaurant Rescue "WTA-afa6c663-3f95-41dc-89be-d07137f91841" = Penguins! "WTA-b68f3c91-526e-4e6c-82f1-6a0ffa1cecf1" = Torchlight "WTA-c29c590d-8770-4ad3-878b-0fc5c132326c" = Bejeweled 2 Deluxe ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-84541473-987749336-3452602534-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{87686C21-8A15-4b4d-A3F1-11141D9BE094}" = Battlefield Play4Free "876305d134f71bcc" = ROM-Runecalc "Akamai" = Akamai NetSession Interface "TeamSpeak 3 Client" = TeamSpeak 3 Client "UnityWebPlayer" = Unity Web Player ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 13.06.2012 12:33:13 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error - 14.06.2012 07:13:35 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 14.06.2012 07:23:55 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error - 14.06.2012 12:57:10 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 14.06.2012 13:24:47 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 15.06.2012 00:24:40 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 15.06.2012 06:26:09 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 15.06.2012 13:54:11 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 15.06.2012 16:41:06 | Computer Name = Marci´s-Laptop | Source = VSS | ID = 13 Description = Error - 15.06.2012 16:41:06 | Computer Name = Marci´s-Laptop | Source = VSS | ID = 8193 Description = Error - 16.06.2012 04:49:42 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = Error - 16.06.2012 07:05:24 | Computer Name = Marci´s-Laptop | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 18.11.2012 12:45:39 | Computer Name = Marci´s-Laptop | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Mobile Partner. OUC erreicht. Error - 18.11.2012 12:45:39 | Computer Name = Marci´s-Laptop | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 18.11.2012 12:48:05 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 18.11.2012 12:48:41 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 18.11.2012 13:11:31 | Computer Name = Marci´s-Laptop | Source = Service Control Manager | ID = 7000 Description = Der Dienst "TuneUp Designerweiterung" wurde aufgrund folgenden Fehlers nicht gestartet: %%1083 Error - 18.11.2012 13:12:03 | Computer Name = Marci´s-Laptop | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Mobile Partner. OUC erreicht. Error - 18.11.2012 13:12:03 | Computer Name = Marci´s-Laptop | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 18.11.2012 13:25:51 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 18.11.2012 14:59:31 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 18.11.2012 17:11:50 | Computer Name = Marci´s-Laptop | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = < End of report > |
19.11.2012, 20:31 | #9 | |||
/// TB-Ausbilder | Claro Search eingfangen :( OK, ein Rest noch. Aber Bitte auch beachten: Warnung: Registry-Cleaner Schritt 1: Deinstalliere Tuneup Schritt 2: Fix mit OTL Schritt 3: Quick-Scan mit Malwarebytes Schritt 4: ESET Online Scanner Zitat:
Schritt 5: Scan mit SecurityCheck Downloade Dir bitte SecurityCheck
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
20.11.2012, 15:53 | #10 |
| Claro Search eingfangen :( Hey, ich hab gerade versucht TuneUp zu deinstallieren aber es sagt mir dass ich da eine andere datei brauche und jetzt habe ich versucht den ordner zu löschen dort kommt jetzt dass es im Hintergrund läuft obwohl da nichts ist #edit: habe es hinbekommen |
20.11.2012, 15:55 | #11 |
/// TB-Ausbilder | Claro Search eingfangen :( Schon wieder ein Grund mehr dieses dumme Programm nicht zu benutzen. Dann mache erstmal so weiter.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
20.11.2012, 16:11 | #12 |
| Claro Search eingfangen :( Hallo ich hab jetzt den 2. schritt gemacht: All processes killed ========== OTL ========== Registry key HKEY_USERS\S-1-5-21-84541473-987749336-3452602534-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C17FE121-70C8-4338-9C80-98633E896532}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C17FE121-70C8-4338-9C80-98633E896532}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes User: Administrator.Marci´s-Laptop ->Temp folder emptied: 280312 bytes ->Temporary Internet Files folder emptied: 1328076910 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 13310766 bytes ->Google Chrome cache emptied: 144608005 bytes ->Flash cache emptied: 41941 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41941 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default.migrated User: Marci´s ->Temp folder emptied: 80156154 bytes ->Temporary Internet Files folder emptied: 45641416 bytes ->Java cache emptied: 19545734 bytes ->FireFox cache emptied: 26915613 bytes ->Google Chrome cache emptied: 397153853 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 76462 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2967192 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes RecycleBin emptied: 8353932824 bytes Total Files Cleaned = 9.930,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 11202012_155611 Files\Folders moved on Reboot... C:\Users\Marci´s\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... Ich habe ein Frage zu Schritt 4, bei der Anleitung steht nur IE und Firefox, wie ist es bei google Chrome Hier der SChritt 3: Malwarebytes Anti-Malware (Test) 1.65.1.1000 Malwarebytes : Free Anti-Malware download Datenbank Version: v2012.11.20.02 Windows 7 x64 NTFS Internet Explorer 9.10.9200.16433 Marci´s :: MARCI´S-LAPTOP [Administrator] Schutz: Aktiviert 20.11.2012 16:18:05 mbam-log-2012-11-20 (16-18-05).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 250520 Laufzeit: 4 Minute(n), 58 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Ich mach gerade Schritt 4 und das ist erst bei 28% nach einer stunde kann das sein? Geändert von Marci08 (20.11.2012 um 16:26 Uhr) |
20.11.2012, 18:38 | #13 |
/// TB-Ausbilder | Claro Search eingfangen :( Ja das kann locker einige Stunden dauern. Umso wichtiger ist es das mal durchlaufen zu lassen.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
20.11.2012, 18:58 | #14 |
| Claro Search eingfangen :( ok dass heißt dann wohl geduldig sein aber es jedenfalls schon einmal zu geschnappt gestern hat es leider nicht mehr gereicht deshalb muss ich es wohl heute weitermachen |
22.11.2012, 15:55 | #15 |
/// TB-Ausbilder | Claro Search eingfangen :( Hallo, benötigst Du noch weiterhin Hilfe ? Sollte ich innerhalb der nächsten 24 Stunden keine Antwort von dir erhalten, werde ich dein Thema aus meinen Abos nehmen und bekomme dadurch keine Nachricht über neue Antworten. Das Verschwinden der Symptome bedeutet nicht, dass dein System schon sauber ist
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
Themen zu Claro Search eingfangen :( |
appdatalow, claro, claro search, eingefangen, gefangen, gen, hoffe, individuelle, internet browser, lösung, nicht mehr, pc performer, performer, registrierungsdatenbank, search, tarma, total, wegbekomme, windows 8 pro |