|
Log-Analyse und Auswertung: 2 Probleme mit Alienware M17xR3Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
03.03.2013, 21:16 | #1 |
| 2 Probleme mit Alienware M17xR3 Hoffe bin hier richtig. Ich habe mom 2 Probleme mit meinen Laptop, der jetze 1 Jahr alt ist. 1:Problem: Ich habe nach unregelmäßigen Abständen Black screens beim spielen und wenn ich grad so nur rumsurfe (da eher sehr selten ). Da geht dann gar nichts mehr und muss neu gestartet werden werden. Beim Black screen wiederholt sich der letzte Ton, der grad abgespielt wurde. Für den 23.02. habe ich folgenden Fehlercode bei AlienAutopsy stehen: Code:
ATTFilter Der Computer wurde nach einem schwerwiegenden Fehler neu gestartet. Der Fehlercode war: 0x00000117 {0xfffffa80072e24e0, 0xfffff88006237198, 0x0000000000000000, 0x0000000000000000} Code:
ATTFilter - System - Provider [ Name] Microsoft-Windows-Kernel-Power [ Guid] {331C3B3A-2005-44C2-AC5E-77220C37D6B4} EventID 41 Version 2 Level 1 Task 63 Opcode 0 Keywords 0x8000000000000002 - TimeCreated [ SystemTime] 2013-02-23T14:29:14.540024700Z EventRecordID 154210 Correlation - Execution [ ProcessID] 4 [ ThreadID] 8 Channel System Computer Draco-PC - Security [ UserID] S-1-5-18 - EventData BugcheckCode 0 BugcheckParameter1 0x0 BugcheckParameter2 0x0 BugcheckParameter3 0x0 BugcheckParameter4 0x0 SleepInProgress false PowerButtonTimestamp 0 Wenn ich mein Laptop anmache bootet er ganz normal bis zur eingabe des Passwortes. Dann kommt das Wilkommen Bild und dann nur noch für ca 3 Minuten ein schwarzer Bildschirm mit einem Mauszeiger, den ich übern Bildschirm wandern lassen kann. Wenn ich den Taskmanager öffne steht, dass der Prozess explorer.exe gestartet ist. Habe schon folgendes gemacht: - Hardware mit Furmark, AlienAutopsy und den Windows-Speicherdiagnose - Bios, OSD, Soundkartentreiber, Grafikkartentreiber und Synaptics Pointing Device Driver aktualisiert - Festplatte auf fehler überprüft - mit HijackThis Laptop gescannt: HiJackthis Logfile: Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 13:48:32, on 03.03.2013 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16464) Boot mode: Normal Running processes: C:\ProgramData\DatacardService\DCSHelper.exe C:\Program Files (x86)\AlienRespawn\TOASTER.EXE C:\Program Files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE C:\Program Files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe C:\Users\Draco\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe C:\Users\Draco\AppData\Roaming\Spotify\spotify.exe C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe C:\Program Files\Alienware\Command Center\AlienFusionController.exe C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe C:\Users\Draco\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Draco\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Draco\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe C:\Users\Draco\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.de/alienware R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-search.com/?affID=119828&babsrc=HP_ss&mntrId=2a6fe892000000000000247703491961 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll R3 - URLSearchHook: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll O2 - BHO: XfireXO - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll O3 - Toolbar: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll O3 - Toolbar: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" O4 - HKLM\..\Run: [AlienwareOn-ScreenDisplay] C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe O4 - HKLM\..\Run: [Integrated Webcam Live! Central] "C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe" /mode2 O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Draco\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" O4 - HKCU\..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe O4 - HKCU\..\Run: [Spotify] "C:\Users\Draco\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-21-1503614190-581956262-4018303520-1019\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser') O4 - HKUS\S-1-5-21-1503614190-581956262-4018303520-1019\..\Run: [EA Core] C:\Program Files (x86)\Electronic Arts\EA Link\Core.exe -silent (User 'UpdatusUser') O4 - HKUS\S-1-5-21-1503614190-581956262-4018303520-1019\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser') O4 - HKUS\S-1-5-21-1503614190-581956262-4018303520-1020\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'boinc_master') O4 - HKUS\S-1-5-21-1503614190-581956262-4018303520-1020\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'boinc_master') O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 O9 - Extra button: Virtuelle Tastatur - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: Links untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: *.clonewarsadventures.com O15 - Trusted Zone: *.dell.com O15 - Trusted Zone: *.freerealms.com O15 - Trusted Zone: *.soe.com O15 - Trusted Zone: *.sony.com O17 - HKLM\System\CCS\Services\Tcpip\..\{1FA38330-5782-44DE-B030-C763F3C82E97}: NameServer = 10.111.81.129 10.129.32.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{7FA4BB78-8895-4C48-99B5-0D9DAE3F15EE}: NameServer = 10.74.210.210 10.74.210.211 O17 - HKLM\System\CCS\Services\Tcpip\..\{A22F4455-0746-4345-91CE-6829482F76A1}: NameServer = 10.129.32.1 10.111.81.129 O17 - HKLM\System\CCS\Services\Tcpip\..\{D2763C48-FDE7-4683-8BB6-7D5C39768193}: NameServer = 10.129.32.1 10.111.81.129 O17 - HKLM\System\CS1\Services\Tcpip\..\{1FA38330-5782-44DE-B030-C763F3C82E97}: NameServer = 10.111.81.129 10.129.32.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{1FA38330-5782-44DE-B030-C763F3C82E97}: NameServer = 10.111.81.129 10.129.32.1 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Alienware Fusion Service (AlienFusionService) - Alienware - C:\Program Files\Alienware\Command Center\AlienFusionService.exe O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe O23 - Service: BOINC - Space Sciences Laboratory - C:\Program Files\BOINC\boinc.exe O23 - Service: CyberLink Product - 2012/02/28 09:48:47 (CLKMSVC10_9EC60124) - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe O23 - Service: Desura Install Service - Desura Pty Ltd - C:\Program Files (x86)\Common Files\Desura\desura_service.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: HWDeviceService64.exe - Unknown owner - C:\ProgramData\DatacardService\HWDeviceService64.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Internet Manager. OUC (Internet Manager. RunOuc) - Unknown owner - C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Radio.fx Server (Radio.fx) - Unknown owner - C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\AlienRespawn\sftservice.EXE O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: Druckwarteschlange (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe O23 - Service: @C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 17671 bytes Kann mir jemand das mal erklären, denn ich kann damit nichts anfangen. Geändert von Darkshadow77 (03.03.2013 um 21:31 Uhr) |
03.03.2013, 21:21 | #2 |
| 2 Probleme mit Alienware M17xR3 - mit OTL Laptop gescannt
__________________1. Logfile: Code:
ATTFilter OTL logfile created on: 03.03.2013 14:04:18 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Draco\Desktop 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,98 Gb Total Physical Memory | 5,01 Gb Available Physical Memory | 62,73% Memory free 15,96 Gb Paging File | 12,57 Gb Available in Paging File | 78,76% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 688,86 Gb Total Space | 216,99 Gb Free Space | 31,50% Space Free | Partition Type: NTFS Computer Name: DRACO-PC | User Name: Draco | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.03.03 14:02:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Draco\Desktop\OTL.exe PRC - [2013.02.22 15:30:32 | 003,818,776 | ---- | M] () -- C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe PRC - [2013.02.21 16:32:15 | 004,484,504 | ---- | M] (Spotify Ltd) -- C:\Users\Draco\AppData\Roaming\Spotify\spotify.exe PRC - [2013.02.21 16:32:15 | 001,103,768 | ---- | M] (Spotify Ltd) -- C:\Users\Draco\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe PRC - [2013.02.09 18:43:48 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2013.01.31 16:42:54 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe PRC - [2013.01.26 20:48:45 | 000,743,424 | ---- | M] () -- C:\ProgramData\BOINC\projects\climateprediction.net\hadcm3n_6.07_windows_intelx86.exe PRC - [2013.01.19 03:51:31 | 001,129,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe PRC - [2013.01.19 03:50:09 | 002,070,304 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe PRC - [2013.01.19 03:50:07 | 001,071,392 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe PRC - [2013.01.10 10:02:16 | 000,844,144 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe PRC - [2012.12.18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.12.02 16:58:00 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2012.06.15 16:14:40 | 000,014,192 | ---- | M] (Alienware) -- C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe PRC - [2012.06.15 16:12:40 | 000,071,024 | ---- | M] (Alienware) -- C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe PRC - [2012.06.15 16:10:58 | 000,016,240 | ---- | M] (Alienware) -- C:\Program Files\Alienware\Command Center\AlienFusionController.exe PRC - [2012.06.04 13:07:58 | 000,224,096 | ---- | M] () -- C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe PRC - [2012.03.10 10:18:15 | 000,406,016 | ---- | M] (Space Sciences Laboratory) -- C:\ProgramData\BOINC\projects\setiathome.berkeley.edu\setiathome_6.03_windows_intelx86.exe PRC - [2011.09.22 17:21:38 | 000,315,712 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe PRC - [2011.09.22 17:14:16 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\AlienRespawn\Components\Scheduler\STService.exe PRC - [2011.09.22 17:06:12 | 001,692,480 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\AlienRespawn\SftService.exe PRC - [2011.09.21 17:22:02 | 003,964,928 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\AlienRespawn\Toaster.exe PRC - [2011.09.02 18:24:28 | 001,636,208 | ---- | M] () -- C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe PRC - [2011.03.25 13:20:59 | 004,757,504 | ---- | M] () -- C:\ProgramData\BOINC\projects\climateprediction.net\hadcm3n_um_6.07_windows_intelx86.exe PRC - [2011.03.14 16:27:28 | 000,236,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe PRC - [2010.11.17 10:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe PRC - [2010.09.14 01:32:32 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe PRC - [2010.09.14 01:32:30 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe ========== Modules (No Company Name) ========== MOD - [2013.02.21 16:32:15 | 021,938,072 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\Spotify\Data\libcef.dll MOD - [2013.02.14 20:33:04 | 001,358,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\9266d6e1f8057b5b62b460cbf33cda21\System.WorkflowServices.ni.dll MOD - [2013.02.14 20:22:55 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll MOD - [2013.02.14 20:22:46 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll MOD - [2013.02.14 20:09:19 | 013,199,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\e963e9f51746f8e23837be7760e187c6\System.Windows.Forms.ni.dll MOD - [2013.01.31 15:31:29 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\5d5b1b0c6e8a714de39a06e3b61f35fe\System.Management.ni.dll MOD - [2013.01.31 15:30:35 | 000,134,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\f47057832c213ae1ab6ecc1329ea4745\System.Data.DataSetExtensions.ni.dll MOD - [2013.01.31 15:30:17 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\07753c0a8ed7f9bc61b0ee718f3c779d\System.Runtime.Remoting.ni.dll MOD - [2013.01.31 15:28:15 | 001,812,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\40c7a89fe2cbf3c12a2c39e034da54cf\System.Xaml.ni.dll MOD - [2013.01.31 15:27:33 | 001,707,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\1e04a5319c58010e945220af2751d34e\System.ServiceModel.Web.ni.dll MOD - [2013.01.31 15:27:30 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\25cfdeaf091f16f3f3a7123a91a179ab\System.Xml.Linq.ni.dll MOD - [2013.01.31 15:25:32 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\c24dc5c1953c9617b9529172e61ba202\IAStorCommon.ni.dll MOD - [2013.01.31 15:25:31 | 000,475,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\01d0ecf3e47d2559aa403d296ad5320a\IAStorUtil.ni.dll MOD - [2013.01.31 15:25:00 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\77dfcfed5fd5f67d0d3edc545935bb21\System.Core.ni.dll MOD - [2013.01.31 14:51:08 | 017,478,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\3e79256ce40faa9682f9e3511ca115ea\System.ServiceModel.ni.dll MOD - [2013.01.31 14:50:52 | 002,347,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ad51da1b752b19c992fcefd56eb7c01\System.Runtime.Serialization.ni.dll MOD - [2013.01.31 14:50:46 | 001,084,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\219c68f83fa608b496b163fd6782e696\System.IdentityModel.ni.dll MOD - [2013.01.31 14:50:45 | 000,256,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\eb33bf977e97e97b12e82c18e36fbaee\SMDiagnostics.ni.dll MOD - [2013.01.31 14:50:33 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll MOD - [2013.01.31 14:50:15 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll MOD - [2013.01.31 14:49:54 | 014,340,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll MOD - [2013.01.31 14:49:40 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll MOD - [2013.01.31 14:49:35 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll MOD - [2013.01.31 14:49:27 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll MOD - [2013.01.31 14:49:22 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll MOD - [2013.01.31 14:49:19 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll MOD - [2013.01.31 14:49:18 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll MOD - [2013.01.31 14:49:15 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll MOD - [2013.01.31 14:06:31 | 018,022,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\b8e60f81fd56934c9f9da7b15bee3376\PresentationFramework.ni.dll MOD - [2013.01.31 14:06:22 | 011,522,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\932901ff0ad5e365ffbe705d7459a37e\PresentationCore.ni.dll MOD - [2013.01.31 14:06:20 | 006,841,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\564f737274f47efdfa212f8da43286e7\System.Data.ni.dll MOD - [2013.01.31 14:06:16 | 007,070,208 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\b519f42484e1d488662a9a8a87cb8849\System.Core.ni.dll MOD - [2013.01.31 14:06:14 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\fc476bbac36944e352c2f547352ffa64\System.Xml.ni.dll MOD - [2013.01.31 14:06:13 | 003,883,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\8abaedf6aecb073b22f8801aa0b8babf\WindowsBase.ni.dll MOD - [2013.01.31 14:06:13 | 001,667,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\78ecbee4a7444353dce52afb9d9d795c\System.Drawing.ni.dll MOD - [2013.01.31 14:06:12 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7cd4aa51f6e6b9330b8f50bba8bb62c6\System.Configuration.ni.dll MOD - [2013.01.31 14:06:10 | 009,095,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\f93dca0e4baa1dcb37cf75392b7c89da\System.ni.dll MOD - [2013.01.31 14:06:07 | 000,145,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\221d903193177a76f68965e8ffb8cbb4\System.Numerics.ni.dll MOD - [2013.01.31 14:06:06 | 014,416,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\6a1ccc1e1a79ce267d3d1808af382cd6\mscorlib.ni.dll MOD - [2012.08.17 21:38:56 | 000,479,160 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll MOD - [2012.03.16 19:07:33 | 000,029,608 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Diagnostics.ServiceModelSink\3.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Diagnostics.ServiceModelSink.dll MOD - [2012.02.28 17:44:55 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll MOD - [2011.09.22 17:14:16 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\AlienRespawn\Components\Scheduler\STService.exe MOD - [2011.09.02 18:24:28 | 001,636,208 | ---- | M] () -- C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe MOD - [2010.11.24 22:44:02 | 000,375,280 | ---- | M] () -- c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll MOD - [2010.11.21 07:49:35 | 000,491,520 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.ServiceModel.resources\3.0.0.0_de_b77a5c561934e089\System.ServiceModel.resources.dll MOD - [2010.11.21 07:49:27 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Configuration.resources.dll MOD - [2010.11.21 07:49:25 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll MOD - [2010.11.21 07:49:22 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll MOD - [2010.11.17 10:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe MOD - [2009.12.18 11:07:06 | 000,577,536 | ---- | M] () -- C:\Program Files (x86)\Alienware On-Screen Display\EMSC.dll ========== Services (SafeList) ========== SRV:64bit: - [2012.06.15 16:10:58 | 000,014,704 | ---- | M] (Alienware) [Auto | Running] -- C:\Program Files\Alienware\Command Center\AlienFusionService.exe -- (AlienFusionService) SRV:64bit: - [2012.05.15 15:01:54 | 001,194,672 | ---- | M] (Space Sciences Laboratory) [Auto | Running] -- C:\Program Files\BOINC\boinc.exe -- (BOINC) SRV:64bit: - [2011.11.21 15:10:10 | 000,036,160 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp) SRV:64bit: - [2011.03.17 03:14:56 | 000,297,984 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV) SRV:64bit: - [2011.01.05 20:41:38 | 001,515,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) SRV:64bit: - [2011.01.05 20:28:50 | 000,340,240 | ---- | M] () [On_Demand | Running] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS) SRV:64bit: - [2011.01.05 20:26:56 | 000,836,880 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) SRV:64bit: - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV:64bit: - [2009.03.03 02:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters) SRV - [2013.03.01 16:47:46 | 000,251,248 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.02.22 15:30:32 | 003,818,776 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe -- (Radio.fx) SRV - [2013.02.09 18:43:48 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2013.01.31 16:42:54 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe -- (AVP) SRV - [2013.01.19 03:50:09 | 002,070,304 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012.12.18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.12.13 20:55:34 | 000,541,168 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2012.12.02 16:58:00 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2012.11.30 15:40:53 | 000,131,912 | ---- | M] (Desura Pty Ltd) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Desura\desura_service.exe -- (Desura Install Service) SRV - [2012.10.20 18:24:00 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.07.03 12:19:28 | 000,160,944 | R--- | M] (Skype Technologies) [On_Demand | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.06.04 13:07:58 | 000,224,096 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe -- (Internet Manager. RunOuc) SRV - [2012.03.08 18:59:06 | 000,607,040 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag) SRV - [2011.11.21 15:12:56 | 001,403,200 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc) SRV - [2011.11.21 15:10:04 | 000,030,016 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp) SRV - [2011.09.22 17:06:12 | 001,692,480 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\AlienRespawn\SftService.exe -- (SftService) SRV - [2011.08.12 01:04:58 | 000,248,304 | ---- | M] (CyberLink) [On_Demand | Stopped] -- c:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe -- (CLKMSVC10_9EC60124) SRV - [2011.08.01 17:24:00 | 003,889,424 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc) SRV - [2011.03.14 16:27:34 | 000,346,976 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\HWDeviceService64.exe -- (HWDeviceService64.exe) SRV - [2010.11.25 05:34:18 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12) SRV - [2010.11.25 05:33:18 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM) SRV - [2010.09.14 01:32:32 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013.02.24 15:17:10 | 000,088,480 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:64bit: - [2013.02.24 15:17:10 | 000,046,400 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:64bit: - [2013.02.10 04:25:27 | 000,448,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvstusb.sys -- (NvStUSB) DRV:64bit: - [2013.01.31 17:12:49 | 000,054,104 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kltdi.sys -- (kltdi) DRV:64bit: - [2013.01.31 17:12:48 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klmouflt.sys -- (klmouflt) DRV:64bit: - [2013.01.31 17:12:47 | 000,613,720 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\SysNative\drivers\klif.sys -- (KLIF) DRV:64bit: - [2013.01.31 17:12:47 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klkbdflt.sys -- (klkbdflt) DRV:64bit: - [2013.01.31 06:08:40 | 000,467,184 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:64bit: - [2012.12.19 06:41:52 | 000,194,488 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:64bit: - [2012.11.28 11:04:16 | 000,047,240 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tbhsd.sys -- (tbhsd) DRV:64bit: - [2012.11.28 11:04:11 | 000,037,480 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rrnetcap.sys -- (RRNetCapMP) DRV:64bit: - [2012.11.28 11:04:11 | 000,037,480 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rrnetcap.sys -- (RRNetCap) DRV:64bit: - [2012.09.20 05:35:36 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm) DRV:64bit: - [2012.09.20 05:35:36 | 000,102,368 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus) DRV:64bit: - [2012.08.23 15:12:16 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt) DRV:64bit: - [2012.08.23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:64bit: - [2012.08.23 15:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2012.08.23 15:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2012.08.13 16:49:40 | 000,178,008 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kneps.sys -- (kneps) DRV:64bit: - [2012.08.02 15:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\klim6.sys -- (KLIM6) DRV:64bit: - [2012.06.19 17:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\kl1.sys -- (kl1) DRV:64bit: - [2012.06.04 13:07:58 | 000,421,376 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbwwan.sys -- (ewusbmbb) DRV:64bit: - [2012.06.04 13:07:58 | 000,222,464 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard) DRV:64bit: - [2012.06.04 13:07:58 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV:64bit: - [2012.06.04 13:07:58 | 000,086,016 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV:64bit: - [2012.06.04 13:07:58 | 000,039,552 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tcpipBM.sys -- (tcpipBM) DRV:64bit: - [2012.06.04 13:07:58 | 000,016,512 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BMLoad.sys -- (BMLoad) DRV:64bit: - [2012.06.04 13:07:58 | 000,013,952 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter) DRV:64bit: - [2012.03.06 19:08:32 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\taphss.sys -- (taphss) DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2012.02.28 17:45:14 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2012.02.28 17:45:14 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2011.12.08 05:22:28 | 000,177,640 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm) DRV:64bit: - [2011.12.08 05:22:28 | 000,157,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus) DRV:64bit: - [2011.12.08 05:22:28 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl) DRV:64bit: - [2011.09.22 21:01:54 | 000,311,144 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\RsFx0105.sys -- (RsFx0105) DRV:64bit: - [2011.05.04 01:35:08 | 000,337,512 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR) DRV:64bit: - [2011.03.17 03:14:56 | 000,521,728 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA) DRV:64bit: - [2011.03.04 01:42:38 | 008,507,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) DRV:64bit: - [2011.03.04 01:18:22 | 000,181,760 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:64bit: - [2011.03.04 01:18:22 | 000,082,432 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:64bit: - [2011.01.20 18:20:46 | 000,176,096 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt) DRV:64bit: - [2010.11.30 14:48:38 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) DRV:64bit: - [2010.11.21 04:23:48 | 000,168,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc60.sys -- (netvsc) DRV:64bit: - [2010.11.21 04:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub) DRV:64bit: - [2010.11.21 04:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc) DRV:64bit: - [2010.11.21 04:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:64bit: - [2010.11.21 04:23:48 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VMBusVideoM.sys -- (SynthVid) DRV:64bit: - [2010.11.21 04:23:47 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus) DRV:64bit: - [2010.11.21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.10.20 00:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2010.09.14 01:24:26 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2010.09.07 14:41:14 | 000,027,760 | ---- | M] (ST Microelectronics) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelern.sys -- (Acceler) DRV:64bit: - [2010.08.20 11:05:12 | 000,021,616 | ---- | M] (ST Microelectronics) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stdcfltn.sys -- (stdcfltn) DRV:64bit: - [2010.08.17 14:17:46 | 000,344,616 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (btwampfl) DRV:64bit: - [2010.08.17 14:17:46 | 000,135,720 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt) DRV:64bit: - [2010.08.17 14:17:46 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid) DRV:64bit: - [2010.03.19 10:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:64bit: - [2010.02.27 02:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd) DRV:64bit: - [2010.02.24 11:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11) DRV:64bit: - [2009.12.30 12:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt) DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.07.14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx) DRV:64bit: - [2009.06.26 22:43:42 | 000,016,752 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EMSC.sys -- (EMSC) DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2006.11.01 19:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr) DRV - [2013.01.23 07:12:38 | 000,013,368 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\MSI Afterburner\RTCore64.sys -- (RTCore64) DRV - [2011.06.04 22:51:52 | 000,009,728 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Games\ArtMoney\am73964.sys -- (am7pro) DRV - [2009.10.14 08:24:44 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv) DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) DRV - [2009.06.26 22:43:42 | 000,013,680 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\drivers\EMSC.sys -- (EMSC) DRV - [2005.01.01 10:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.de/alienware IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-search.com/?affID=119828&babsrc=HP_ss&mntrId=2a6fe892000000000000247703491961 IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll (Conduit Ltd.) IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://www.delta-search.com/?q={searchTerms}&affID=119828&babsrc=SP_ss&mntrId=2a6fe892000000000000247703491961 IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\..\SearchScopes\{9B4A834C-9A9A-425B-845E-484412CF9332}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=kw&q={searchTerms}&locale=&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=4081b162-03e1-44b8-b9b3-12b96dd7ec4b&apn_sauid=D55E0BAF-4CCA-4B19-A307-7611279EBCE9 IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1019\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.de/alienware IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1019\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1019\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll (Conduit Ltd.) IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1019\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1019\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1019\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1020\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.de/alienware IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1020\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1020\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll (Conduit Ltd.) IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1020\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1020\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1503614190-581956262-4018303520-1020\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultthis.engineName: "InnoGames Customized Web Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2682599&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.selectedEngine: "Delta Search" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.delta-search.com/?affID=119828&babsrc=HP_ss&mntrId=2a6fe892000000000000247703491961" FF - prefs.js..extensions.enabledAddons: nasanightlaunch@example.com:0.6.20121115 FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll () FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\url_advisor@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013.01.31 17:12:51 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtual_keyboard@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013.01.31 17:12:51 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\content_blocker@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013.01.31 17:12:51 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\anti_banner@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013.01.31 17:12:51 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\online_banking@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013.01.31 17:12:51 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.10.20 18:24:00 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.10.20 18:24:00 | 000,000,000 | ---D | M] [2012.03.12 15:37:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Draco\AppData\Roaming\Mozilla\Extensions [2013.03.03 12:43:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions [2013.02.23 19:59:46 | 000,000,000 | ---D | M] (XfireXO Community Toolbar) -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} [2013.02.23 19:59:44 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013.02.23 20:00:02 | 000,000,000 | ---D | M] (InnoGames Community Toolbar) -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\{c7478d43-2bd5-4844-98b8-c2a6aa9ed677} [2013.02.23 19:59:14 | 000,000,000 | ---D | M] ("Default Theme Engine - Personas Interactive") -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\btpersonas@brandthunder.com [2013.02.26 18:46:29 | 000,000,000 | ---D | M] ("SearchGBY") -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\plugin@searchgby.com [2013.01.19 21:08:59 | 000,000,000 | ---D | M] ("Avira SearchFree Toolbar plus Web Protection") -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\toolbar@ask.com [2012.07.05 16:56:13 | 000,123,385 | ---- | M] () (No name found) -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\elemhidehelper@adblockplus.org.xpi [2012.11.18 10:38:21 | 002,307,149 | ---- | M] () (No name found) -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\nasanightlaunch@example.com.xpi [2013.01.19 21:08:55 | 000,538,938 | ---- | M] () (No name found) -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\toolbar@web.de.xpi [2013.02.23 19:59:49 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013.03.03 12:43:40 | 000,269,007 | ---- | M] () (No name found) -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013.02.23 20:00:04 | 000,685,671 | ---- | M] () (No name found) -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi [2013.03.02 17:04:57 | 000,000,766 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\searchplugins\11-suche.xml [2013.02.27 18:57:07 | 000,002,834 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\searchplugins\askcom.xml [2013.02.27 18:57:07 | 000,001,127 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\searchplugins\conduit.xml [2013.02.27 18:59:10 | 000,001,294 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\searchplugins\delta.xml [2013.03.02 17:04:57 | 000,002,111 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\searchplugins\englische-ergebnisse.xml [2013.03.02 17:04:57 | 000,010,420 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\searchplugins\gmx-suche.xml [2013.03.02 17:04:57 | 000,002,392 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\searchplugins\lastminute.xml [2013.03.02 17:04:57 | 000,005,400 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\Mozilla\Firefox\Profiles\abt6zpny.default\searchplugins\webde-suche.xml [2012.10.20 18:23:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2012.10.20 18:23:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} [2012.10.20 18:23:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA} [2012.10.20 18:23:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012.10.20 18:24:00 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2013.03.02 17:04:57 | 000,001,400 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.03.02 17:04:57 | 000,001,679 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2013.03.02 17:04:57 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2013.03.02 17:04:57 | 000,006,818 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2013.02.27 18:57:07 | 000,001,278 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2013.03.02 17:04:57 | 000,000,903 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Bing () CHR - default_search_provider: search_url = hxxp://www.bing.com/search?setmkt=de-DE&q={searchTerms} CHR - default_search_provider: suggest_url = hxxp://api.bing.com/osjson.aspx?query={searchTerms}&language={language} CHR - homepage: hxxp://www.google.de/ CHR - Extension: SearchGBY = C:\Users\Draco\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmijdhkcgeclpfjmibnginbbkfcbpep\0.9.55_0\ O1 HOSTS File: ([2012.03.08 20:54:16 | 000,441,475 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 127.0.0.1 www.123fporn.info O1 - Hosts: 15172 more lines... O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2:64bit: - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) O2:64bit: - BHO: (no name) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No CLSID value found. O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll (Conduit Ltd.) O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4:64bit: - HKLM..\Run: [] File not found O4:64bit: - HKLM..\Run: [boincmgr] C:\Program Files\BOINC\boincmgr.exe (Space Sciences Laboratory) O4:64bit: - HKLM..\Run: [boinctray] C:\Program Files\BOINC\boinctray.exe (Space Sciences Laboratory) O4:64bit: - HKLM..\Run: [Command Center Controllers] C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe (Alienware) O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation) O4:64bit: - HKLM..\Run: [Nvtmru] C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation) O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AlienwareOn-ScreenDisplay] C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe () O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Kaspersky Lab ZAO) O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe () O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [Integrated Webcam Live! Central] C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe (Creative Technology Ltd) O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1000..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung) O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1000..\Run: [Spotify] C:\Users\Draco\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1000..\Run: [Spotify Web Helper] C:\Users\Draco\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1000..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1019..\Run: [Akamai NetSession Interface] C:\Users\Draco\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1019..\Run: [EA Core] C:\Program Files (x86)\Electronic Arts\EA Link\Core.exe -silent File not found O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1019..\Run: [Internet Manager] C:\Program Files (x86)\T-Mobile\InternetManager_H\Internet Manager.exe () O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1019..\Run: [rfxsrvtray] C:\Program Files (x86)\Tobit Radio.fx\Client\rfx-tray.exe (Tobit.Software) O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1019..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1020..\Run: [Akamai NetSession Interface] C:\Users\Draco\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1020..\Run: [EA Core] C:\Program Files (x86)\Electronic Arts\EA Link\Core.exe -silent File not found O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1020..\Run: [Internet Manager] C:\Program Files (x86)\T-Mobile\InternetManager_H\Internet Manager.exe () O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1020..\Run: [rfxsrvtray] C:\Program Files (x86)\Tobit Radio.fx\Client\rfx-tray.exe (Tobit.Software) O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1020..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKLM..\RunOnce: [SpybotDeletingA6911] command.com /c del "C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml" File not found O4 - HKLM..\RunOnce: [SpybotDeletingC8369] cmd.exe /c del "C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml" File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1000..\RunOnce: [SpybotDeletingB9880] command.com /c del "C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml" File not found O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1000..\RunOnce: [SpybotDeletingD9847] cmd.exe /c del "C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml" File not found O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1019..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-21-1503614190-581956262-4018303520-1020..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:64bit: - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html File not found O8:64bit: - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm () O8 - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html File not found O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm () O9:64bit: - Extra Button: Virtuelle Tastatur - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) O9:64bit: - Extra Button: Links untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra Button: Virtuelle Tastatur - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) O9 - Extra Button: Links untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in ) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\..Trusted Domains: dell.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1000\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1019\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1019\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1019\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1019\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1020\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1020\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1020\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1503614190-581956262-4018303520-1020\..Trusted Domains: sony.com ([]* in Trusted sites) O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16:64bit: - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25) O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1FA38330-5782-44DE-B030-C763F3C82E97}: NameServer = 10.111.81.129 10.129.32.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{751CB4AC-2956-410B-B93C-68ED5ED03CBF}: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7FA4BB78-8895-4C48-99B5-0D9DAE3F15EE}: NameServer = 10.74.210.210 10.74.210.211 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A22F4455-0746-4345-91CE-6829482F76A1}: NameServer = 10.129.32.1 10.111.81.129 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D2763C48-FDE7-4683-8BB6-7D5C39768193}: NameServer = 10.129.32.1 10.111.81.129 O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18 - Protocol\Handler\ms-help - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - File not found O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O29:64bit: - HKLM SecurityProviders - (credssp.dll) - File not found O29 - HKLM SecurityProviders - (credssp.dll) - File not found O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{984133bc-afa5-11e1-916a-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{984133bc-afa5-11e1-916a-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{c77b40a2-ae30-11e1-bb6d-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{c77b40a2-ae30-11e1-bb6d-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{c77b40d3-ae30-11e1-bb6d-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{c77b40d3-ae30-11e1-bb6d-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{c77b4104-ae30-11e1-bb6d-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{c77b4104-ae30-11e1-bb6d-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{c77b4119-ae30-11e1-bb6d-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{c77b4119-ae30-11e1-bb6d-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{c77b4126-ae30-11e1-bb6d-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{c77b4126-ae30-11e1-bb6d-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{c77b4179-ae30-11e1-bb6d-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{c77b4179-ae30-11e1-bb6d-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{c77b4192-ae30-11e1-bb6d-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{c77b4192-ae30-11e1-bb6d-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{f00001b4-abc6-11e1-a60b-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{f00001b4-abc6-11e1-a60b-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{f00001b9-abc6-11e1-a60b-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{f00001b9-abc6-11e1-a60b-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{f00001ca-abc6-11e1-a60b-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{f00001ca-abc6-11e1-a60b-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{f000028f-abc6-11e1-a60b-9cb70d52820c}\Shell - "" = AutoRun O33 - MountPoints2\{f000028f-abc6-11e1-a60b-9cb70d52820c}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\F\Shell - "" = AutoRun O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.03.03 14:02:12 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Draco\Desktop\OTL.exe [2013.03.03 14:00:43 | 010,156,344 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Draco\Desktop\mbam-setup-1.70.0.1100.exe [2013.03.03 13:25:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy [2013.03.03 13:25:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy [2013.03.03 11:23:01 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Draco\Desktop\HijackThis.exe [2013.03.02 18:23:30 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Roaming\Synaptics [2013.03.01 20:34:40 | 006,393,120 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll [2013.03.01 20:34:40 | 003,472,672 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll [2013.03.01 20:34:40 | 002,555,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll [2013.03.01 20:34:40 | 000,237,856 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll [2013.03.01 20:34:40 | 000,063,776 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll [2013.03.01 20:33:51 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation [2013.03.01 20:32:30 | 026,947,360 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll [2013.03.01 20:32:30 | 020,534,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll [2013.03.01 20:32:30 | 015,275,744 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll [2013.03.01 20:32:30 | 012,862,400 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll [2013.03.01 20:32:30 | 007,569,184 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll [2013.03.01 20:32:30 | 006,267,240 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll [2013.03.01 20:32:30 | 001,510,328 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdagenco6420103.dll [2013.03.01 20:32:30 | 001,510,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvir3dgenco6420162.dll [2013.03.01 20:32:30 | 000,448,288 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvstusb.sys [2013.03.01 20:32:30 | 000,194,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvhda64v.sys [2013.03.01 20:32:30 | 000,031,672 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdap64.dll [2013.03.01 20:32:29 | 025,256,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll [2013.03.01 20:32:29 | 017,987,192 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll [2013.03.01 20:32:29 | 017,560,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll [2013.03.01 20:32:29 | 015,038,296 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll [2013.03.01 20:32:29 | 009,422,672 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll [2013.03.01 20:32:29 | 007,964,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll [2013.03.01 20:32:29 | 002,911,008 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll [2013.03.01 20:32:29 | 002,854,344 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll [2013.03.01 20:32:29 | 002,726,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll [2013.03.01 20:32:29 | 002,528,840 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll [2013.03.01 20:32:29 | 002,350,368 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll [2013.03.01 20:32:29 | 001,990,944 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll [2013.03.01 20:32:29 | 001,807,136 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6420294.dll [2013.03.01 20:32:29 | 001,510,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6420162.dll [2013.03.01 17:43:21 | 000,652,288 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll [2013.03.01 17:42:34 | 000,000,000 | ---D | C] -- C:\Program Files\IDT [2013.02.27 20:16:11 | 002,776,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll [2013.02.27 20:16:11 | 002,284,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msmpeg2vdec.dll [2013.02.27 20:16:11 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIAnimation.dll [2013.02.27 20:16:11 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAnimation.dll [2013.02.27 20:16:08 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll [2013.02.27 20:16:08 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll [2013.02.27 20:16:05 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll [2013.02.27 20:16:05 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll [2013.02.27 20:16:05 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll [2013.02.27 20:16:05 | 000,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll [2013.02.27 20:16:05 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll [2013.02.27 20:16:05 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll [2013.02.27 20:16:05 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll [2013.02.27 20:16:05 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll [2013.02.27 20:16:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll [2013.02.27 20:16:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll [2013.02.27 20:16:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll [2013.02.27 20:16:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll [2013.02.27 20:16:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll [2013.02.27 20:16:05 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll [2013.02.27 20:16:05 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll [2013.02.27 20:16:04 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll [2013.02.27 20:16:04 | 001,887,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll [2013.02.27 20:16:04 | 001,682,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll [2013.02.27 20:16:04 | 001,643,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll [2013.02.27 20:16:04 | 001,504,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll [2013.02.27 20:16:04 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll [2013.02.27 20:16:04 | 001,238,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10.dll [2013.02.27 20:16:04 | 001,158,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll [2013.02.27 20:16:04 | 000,648,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll [2013.02.27 20:16:04 | 000,363,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll [2013.02.27 20:16:04 | 000,333,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll [2013.02.27 20:16:04 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10core.dll [2013.02.27 20:16:04 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecsExt.dll [2013.02.27 20:16:04 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll [2013.02.27 20:16:04 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll [2013.02.27 20:16:04 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll [2013.02.27 20:16:04 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll [2013.02.27 20:16:04 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll [2013.02.27 20:16:04 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll [2013.02.27 20:16:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll [2013.02.27 19:00:18 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Roaming\JAM Software [2013.02.27 18:57:07 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Roaming\Opera [2013.02.27 18:56:59 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Roaming\OCS [2013.02.26 17:09:49 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell [2013.02.26 17:09:32 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Local\Deployment [2013.02.26 17:09:32 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Local\Apps [2013.02.25 18:49:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Alienware On-Screen Display [2013.02.25 16:58:41 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Secrets of Da Vinci [2013.02.25 16:58:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secrets of Da Vinci [2013.02.25 16:53:53 | 000,000,000 | ---D | C] -- C:\Windows\Secrets of Da Vinci [2013.02.25 16:53:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secrets of Da Vinci [2013.02.24 21:53:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Uninstall [2013.02.24 21:50:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SureThing Shared [2013.02.24 21:50:03 | 000,000,000 | ---D | C] -- C:\ProgramData\PhotoShow Shared Assets [2013.02.24 21:49:56 | 000,000,000 | ---D | C] -- C:\Program Files\Roxio [2013.02.24 21:49:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio Creator Starter [2013.02.24 21:46:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine [2013.02.24 21:46:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared [2013.02.24 21:45:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Roxio [2013.02.24 21:31:05 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Roaming\Roxio Log Files [2013.02.24 15:17:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Tages [2013.02.24 15:12:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Peter Games [2013.02.24 15:10:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Peter Games [2013.02.24 11:30:18 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Local\capcom [2013.02.24 10:22:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CAPCOM [2013.02.23 18:40:33 | 000,000,000 | ---D | C] -- C:\Users\Draco\Desktop\Neuer Ordner (3) [2013.02.23 12:48:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor 2.5 [2013.02.23 12:48:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSI Kombustor 2.5 [2013.02.23 12:47:00 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner [2013.02.23 12:46:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSI Afterburner [2013.02.23 12:20:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer [2013.02.23 12:20:08 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Roaming\BrowserCompanion [2013.02.21 18:24:56 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Local\NVIDIA [2013.02.14 20:01:58 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2013.02.14 20:01:58 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2013.02.14 20:01:57 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2013.02.14 20:01:57 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2013.02.14 20:01:57 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2013.02.14 20:01:57 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2013.02.14 20:01:57 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2013.02.14 20:01:57 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2013.02.14 20:01:57 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2013.02.14 20:01:56 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2013.02.14 20:01:56 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2013.02.14 20:01:56 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2013.02.14 20:01:55 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2013.02.14 20:01:55 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2013.02.14 20:01:55 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2013.02.14 18:00:25 | 005,553,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2013.02.14 18:00:25 | 003,967,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2013.02.14 18:00:24 | 003,913,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2013.02.14 18:00:15 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll [2013.02.14 18:00:15 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2013.02.14 18:00:15 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2013.02.14 18:00:15 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2013.02.14 18:00:15 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2013.02.14 18:00:15 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2013.02.14 18:00:05 | 000,288,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS [2013.02.12 18:01:42 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Local\EA Games [2013.02.09 18:43:52 | 000,555,808 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe [2013.02.05 21:05:57 | 000,000,000 | ---D | C] -- C:\Users\Draco\Desktop\TheHunter2013 [2013.02.05 16:48:21 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Local\Nexway [2013.02.02 14:25:50 | 000,000,000 | ---D | C] -- C:\Users\Draco\Documents\theHunter [2013.02.02 14:23:46 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Local\theHunter [2013.02.02 12:06:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies [2013.02.02 10:16:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Hunter [2013.02.02 10:16:08 | 000,000,000 | ---D | C] -- C:\Users\Draco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\theHunter [2013.02.02 10:15:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\theHunter [7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [5 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [5 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.03.03 14:02:15 | 010,156,344 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Draco\Desktop\mbam-setup-1.70.0.1100.exe [2013.03.03 14:02:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Draco\Desktop\OTL.exe [2013.03.03 13:56:18 | 000,000,123 | ---- | M] () -- C:\Windows\wininit.ini [2013.03.03 13:44:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.03.03 13:25:10 | 000,001,220 | ---- | M] () -- C:\Users\Draco\Desktop\Spybot - Search & Destroy.lnk [2013.03.03 13:19:01 | 000,021,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.03.03 13:19:01 | 000,021,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.03.03 13:05:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.03.03 11:22:58 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Draco\Desktop\HijackThis.exe [2013.03.02 18:49:19 | 000,833,296 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.03.02 18:49:19 | 000,829,274 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat [2013.03.02 18:49:19 | 000,829,106 | ---- | M] () -- C:\Windows\SysNative\perfh00A.dat [2013.03.02 18:49:19 | 000,827,238 | ---- | M] () -- C:\Windows\SysNative\perfh013.dat [2013.03.02 18:49:19 | 000,824,182 | ---- | M] () -- C:\Windows\SysNative\perfh010.dat [2013.03.02 18:49:19 | 000,823,570 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2013.03.02 18:49:19 | 000,767,758 | ---- | M] () -- C:\Windows\SysNative\perfh00E.dat [2013.03.02 18:49:19 | 000,751,156 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat [2013.03.02 18:49:19 | 000,745,532 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.03.02 18:49:19 | 000,691,950 | ---- | M] () -- C:\Windows\SysNative\perfh008.dat [2013.03.02 18:49:19 | 000,591,980 | ---- | M] () -- C:\Windows\SysNative\perfh006.dat [2013.03.02 18:49:19 | 000,576,832 | ---- | M] () -- C:\Windows\SysNative\perfh014.dat [2013.03.02 18:49:19 | 000,564,294 | ---- | M] () -- C:\Windows\SysNative\perfh00B.dat [2013.03.02 18:49:19 | 000,561,696 | ---- | M] () -- C:\Windows\SysNative\perfh001.dat [2013.03.02 18:49:19 | 000,507,898 | ---- | M] () -- C:\Windows\SysNative\perfh012.dat [2013.03.02 18:49:19 | 000,496,214 | ---- | M] () -- C:\Windows\SysNative\perfh011.dat [2013.03.02 18:49:19 | 000,474,120 | ---- | M] () -- C:\Windows\SysNative\perfh00D.dat [2013.03.02 18:49:19 | 000,218,416 | ---- | M] () -- C:\Windows\SysNative\perfc00E.dat [2013.03.02 18:49:19 | 000,205,272 | ---- | M] () -- C:\Windows\SysNative\perfc00A.dat [2013.03.02 18:49:19 | 000,202,488 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2013.03.02 18:49:19 | 000,199,210 | ---- | M] () -- C:\Windows\SysNative\perfc013.dat [2013.03.02 18:49:19 | 000,197,616 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.03.02 18:49:19 | 000,195,528 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat [2013.03.02 18:49:19 | 000,193,210 | ---- | M] () -- C:\Windows\SysNative\perfc010.dat [2013.03.02 18:49:19 | 000,187,422 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat [2013.03.02 18:49:19 | 000,167,940 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.03.02 18:49:19 | 000,167,594 | ---- | M] () -- C:\Windows\SysNative\perfc011.dat [2013.03.02 18:49:19 | 000,165,882 | ---- | M] () -- C:\Windows\SysNative\perfc012.dat [2013.03.02 18:49:19 | 000,158,082 | ---- | M] () -- C:\Windows\SysNative\perfc008.dat [2013.03.02 18:49:19 | 000,147,614 | ---- | M] () -- C:\Windows\SysNative\perfc00B.dat [2013.03.02 18:49:19 | 000,144,818 | ---- | M] () -- C:\Windows\SysNative\perfc006.dat [2013.03.02 18:49:19 | 000,140,976 | ---- | M] () -- C:\Windows\SysNative\perfc014.dat [2013.03.02 18:49:19 | 000,140,190 | ---- | M] () -- C:\Windows\SysNative\perfc001.dat [2013.03.02 18:49:19 | 000,130,300 | ---- | M] () -- C:\Windows\SysNative\perfc00D.dat [2013.03.02 18:49:19 | 000,113,638 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat [2013.03.02 18:49:19 | 000,113,400 | ---- | M] () -- C:\Windows\SysNative\prfh0816.dat [2013.03.02 18:49:19 | 000,112,952 | ---- | M] () -- C:\Windows\SysNative\perfh019.dat [2013.03.02 18:49:19 | 000,111,348 | ---- | M] () -- C:\Windows\SysNative\perfh01F.dat [2013.03.02 18:49:19 | 000,111,012 | ---- | M] () -- C:\Windows\SysNative\perfh01D.dat [2013.03.02 18:49:19 | 000,097,564 | ---- | M] () -- C:\Windows\SysNative\prfh0404.dat [2013.03.02 18:49:19 | 000,096,906 | ---- | M] () -- C:\Windows\SysNative\prfh0804.dat [2013.03.02 18:49:19 | 000,058,850 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat [2013.03.02 18:49:19 | 000,058,716 | ---- | M] () -- C:\Windows\SysNative\prfc0816.dat [2013.03.02 18:49:19 | 000,058,266 | ---- | M] () -- C:\Windows\SysNative\perfc019.dat [2013.03.02 18:49:19 | 000,058,248 | ---- | M] () -- C:\Windows\SysNative\perfc01D.dat [2013.03.02 18:49:19 | 000,058,184 | ---- | M] () -- C:\Windows\SysNative\perfc01F.dat [2013.03.02 18:49:19 | 000,056,532 | ---- | M] () -- C:\Windows\SysNative\prfc0804.dat [2013.03.02 18:49:19 | 000,056,532 | ---- | M] () -- C:\Windows\SysNative\prfc0404.dat [2013.03.02 18:49:19 | 000,007,996 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.03.02 18:37:57 | 000,001,803 | ---- | M] () -- C:\Users\Public\Desktop\Alienware Command Center.lnk [2013.03.02 15:45:04 | 000,467,968 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013.03.01 21:10:53 | 000,005,037 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\EasyToolz.ini [2013.03.01 16:47:46 | 000,691,568 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2013.03.01 16:47:46 | 000,071,024 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2013.02.26 19:10:18 | 000,066,155 | ---- | M] () -- C:\Users\Draco\Desktop\bluescreenview_147.zip [2013.02.25 16:58:41 | 000,001,905 | ---- | M] () -- C:\Users\Draco\Desktop\The Secrets Of Da Vinci.lnk [2013.02.24 21:49:38 | 000,002,124 | ---- | M] () -- C:\Users\Public\Desktop\Roxio Creator Starter.lnk [2013.02.24 15:17:10 | 000,088,480 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys [2013.02.24 15:17:10 | 000,046,400 | ---- | M] () -- C:\Windows\SysNative\drivers\lirsgt.sys [2013.02.24 15:12:47 | 000,002,305 | ---- | M] () -- C:\Users\Draco\Desktop\Nostradamus - Die letzte Prophezeiung.lnk [2013.02.24 11:29:58 | 000,001,672 | ---- | M] () -- C:\Users\Draco\Desktop\LPCLauncher.exe.lnk [2013.02.22 19:28:17 | 000,504,922 | ---- | M] () -- C:\Users\Draco\Desktop\Crysis 3 v1.0 +6 Trainer.rar [2013.02.19 17:45:42 | 003,325,720 | ---- | M] (Tobit.Software) -- C:\Windows\RXSUnins.exe [2013.02.19 17:45:42 | 003,325,720 | ---- | M] (Tobit.Software) -- C:\Windows\RXCUnins.exe [2013.02.14 17:52:17 | 000,547,804 | ---- | M] () -- C:\Users\Draco\Desktop\DEAD SPACE 3 (+5 TRAINER).zip [2013.02.13 01:26:34 | 000,042,880 | ---- | M] () -- C:\Windows\SysWow64\xfcodec.dll [2013.02.13 01:26:34 | 000,028,544 | ---- | M] () -- C:\Windows\SysNative\xfcodec64.dll [2013.02.11 18:52:37 | 000,000,049 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\TheHunterSettings_live.cfg [2013.02.10 21:56:26 | 000,628,127 | ---- | M] () -- C:\Users\Draco\Desktop\Dead Space Trainer +3 v1.0.0.222.zip [2013.02.10 20:04:21 | 000,004,096 | ---- | M] () -- C:\Windows\d3dx.dat [2013.02.10 19:34:26 | 000,007,598 | ---- | M] () -- C:\Users\Draco\AppData\Local\resmon.resmoncfg [2013.02.10 04:25:27 | 026,947,360 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll [2013.02.10 04:25:27 | 025,256,736 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll [2013.02.10 04:25:27 | 020,534,560 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll [2013.02.10 04:25:27 | 017,987,192 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll [2013.02.10 04:25:27 | 017,560,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll [2013.02.10 04:25:27 | 015,275,744 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll [2013.02.10 04:25:27 | 015,038,296 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll [2013.02.10 04:25:27 | 012,862,400 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll [2013.02.10 04:25:27 | 009,422,672 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll [2013.02.10 04:25:27 | 007,964,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll [2013.02.10 04:25:27 | 007,569,184 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll [2013.02.10 04:25:27 | 006,267,240 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll [2013.02.10 04:25:27 | 002,911,008 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll [2013.02.10 04:25:27 | 002,854,344 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll [2013.02.10 04:25:27 | 002,726,176 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll [2013.02.10 04:25:27 | 002,528,840 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll [2013.02.10 04:25:27 | 002,350,368 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll [2013.02.10 04:25:27 | 001,990,944 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll [2013.02.10 04:25:27 | 001,807,136 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6420294.dll [2013.02.10 04:25:27 | 001,510,176 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvir3dgenco6420162.dll [2013.02.10 04:25:27 | 001,510,176 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6420162.dll [2013.02.10 04:25:27 | 000,448,288 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvstusb.sys [2013.02.10 04:25:27 | 000,017,738 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb [2013.02.10 02:04:31 | 006,393,120 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll [2013.02.10 02:04:31 | 003,472,672 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll [2013.02.10 02:04:29 | 002,555,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll [2013.02.10 02:04:29 | 000,237,856 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll [2013.02.10 02:04:29 | 000,063,776 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll [2013.02.09 18:43:52 | 000,555,808 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe [2013.02.07 16:34:50 | 000,101,548 | ---- | M] () -- C:\Users\Draco\Desktop\Drachenbaby.jpg [2013.02.07 16:34:50 | 000,000,840 | ---- | M] () -- C:\Users\Draco\.recently-used.xbel [2013.02.06 19:56:47 | 000,048,225 | ---- | M] () -- C:\Users\Draco\Desktop\Blackdragon.jpg [2013.02.03 13:06:33 | 000,011,869 | ---- | M] () -- C:\Users\Draco\AppData\Roaming\TheHunterSettings_live.bin [7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [5 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [5 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.03.03 13:56:18 | 000,000,123 | ---- | C] () -- C:\Windows\wininit.ini [2013.03.03 13:25:10 | 000,001,220 | ---- | C] () -- C:\Users\Draco\Desktop\Spybot - Search & Destroy.lnk [2013.03.02 18:37:57 | 000,001,803 | ---- | C] () -- C:\Users\Public\Desktop\Alienware Command Center.lnk [2013.03.01 20:32:29 | 000,017,738 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb [2013.02.26 19:10:21 | 000,066,155 | ---- | C] () -- C:\Users\Draco\Desktop\bluescreenview_147.zip [2013.02.25 16:58:41 | 000,001,905 | ---- | C] () -- C:\Users\Draco\Desktop\The Secrets Of Da Vinci.lnk [2013.02.24 21:49:38 | 000,002,124 | ---- | C] () -- C:\Users\Public\Desktop\Roxio Creator Starter.lnk [2013.02.24 15:12:47 | 000,002,305 | ---- | C] () -- C:\Users\Draco\Desktop\Nostradamus - Die letzte Prophezeiung.lnk [2013.02.24 14:47:59 | 000,088,480 | ---- | C] () -- C:\Windows\SysNative\drivers\atksgt.sys [2013.02.24 14:47:59 | 000,046,400 | ---- | C] () -- C:\Windows\SysNative\drivers\lirsgt.sys [2013.02.24 11:29:58 | 000,001,672 | ---- | C] () -- C:\Users\Draco\Desktop\LPCLauncher.exe.lnk [2013.02.22 19:28:09 | 000,504,922 | ---- | C] () -- C:\Users\Draco\Desktop\Crysis 3 v1.0 +6 Trainer.rar [2013.02.14 17:52:22 | 000,547,804 | ---- | C] () -- C:\Users\Draco\Desktop\DEAD SPACE 3 (+5 TRAINER).zip [2013.02.13 01:26:34 | 000,042,880 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll [2013.02.13 01:26:34 | 000,028,544 | ---- | C] () -- C:\Windows\SysNative\xfcodec64.dll [2013.02.10 21:55:54 | 000,628,127 | ---- | C] () -- C:\Users\Draco\Desktop\Dead Space Trainer +3 v1.0.0.222.zip [2013.02.10 20:04:21 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat [2013.02.07 16:34:50 | 000,000,840 | ---- | C] () -- C:\Users\Draco\.recently-used.xbel [2013.02.06 20:00:02 | 000,048,225 | ---- | C] () -- C:\Users\Draco\Desktop\Blackdragon.jpg [2013.02.06 19:55:44 | 000,101,548 | ---- | C] () -- C:\Users\Draco\Desktop\Drachenbaby.jpg [2013.02.02 14:26:27 | 000,011,869 | ---- | C] () -- C:\Users\Draco\AppData\Roaming\TheHunterSettings_live.bin [2013.02.02 14:23:15 | 000,000,049 | ---- | C] () -- C:\Users\Draco\AppData\Roaming\TheHunterSettings_live.cfg [2012.10.28 20:26:16 | 000,005,632 | ---- | C] () -- C:\Users\Draco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.10.28 17:59:09 | 000,007,598 | ---- | C] () -- C:\Users\Draco\AppData\Local\resmon.resmoncfg [2012.09.28 20:45:06 | 000,247,296 | ---- | C] () -- C:\Windows\SysWow64\rtvcvfw32.dll [2012.09.26 09:07:26 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe [2012.06.19 13:02:17 | 003,123,272 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe [2012.06.16 17:14:50 | 000,184,320 | ---- | C] () -- C:\Windows\SysWow64\miccyhook.dll [2012.06.15 16:13:58 | 000,022,384 | ---- | C] () -- C:\Windows\SysWow64\LightFX.dll [2012.05.22 16:47:02 | 000,113,180 | ---- | C] () -- C:\Users\Draco\AppData\Roaming\icarus-dxdiag.xml [2012.04.06 22:12:01 | 000,000,000 | ---- | C] () -- C:\Users\Draco\hsqlprefs.dat [2012.03.10 14:01:45 | 002,648,064 | ---- | C] () -- C:\Windows\SysWow64\dvmsg.dll [2012.03.10 11:48:36 | 000,281,688 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2012.03.10 11:48:36 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2012.03.09 14:54:54 | 000,005,037 | ---- | C] () -- C:\Users\Draco\AppData\Roaming\EasyToolz.ini [2012.03.08 22:21:48 | 001,970,176 | ---- | C] () -- C:\Windows\SysWow64\d3dx9.dll [2012.02.14 13:20:40 | 000,002,093 | ---- | C] () -- C:\ProgramData\ENGPOL.2012-02.pl.nicolasgames_4F1DC181-E82E-4492-94DF-511B0A5FD4C0.swidtag [2012.01.31 17:15:44 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe [2012.01.31 17:15:42 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll [2012.01.31 17:15:42 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll [2012.01.31 17:15:42 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll [2012.01.31 17:15:42 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll [2011.09.28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2011.06.27 09:07:14 | 000,098,232 | ---- | C] () -- C:\Windows\SysWow64\CCBiosSupportAPI.dll ========== ZeroAccess Check ========== [2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2012.11.01 10:45:27 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Acreon [2012.04.04 18:51:13 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Bioshock [2012.10.05 20:50:33 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\BitTorrent [2012.04.04 16:37:18 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\bizarre creations [2013.03.02 17:25:19 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\BrowserCompanion [2012.08.31 09:48:54 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Command & Conquer 3 Tiberium Wars [2012.03.16 22:39:04 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Dev-Cpp [2012.08.03 18:28:40 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\EoN [2012.03.08 20:59:45 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\fltk.org [2012.11.09 13:48:05 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Galaxy on Fire 2 Full HD [2012.09.11 15:23:08 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\GetRightToGo [2012.04.20 17:57:16 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\gnupg [2012.12.10 00:01:35 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\gtk-2.0 [2012.03.09 19:29:21 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\IDT [2013.02.27 19:09:50 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\JAM Software [2012.03.12 15:43:21 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Media Finder [2012.09.05 17:13:32 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\NCH Swift Sound [2012.10.05 20:31:09 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Need for Speed World [2013.03.02 17:05:30 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\OCS [2013.02.27 18:57:07 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Opera [2012.11.17 20:43:02 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Origin [2012.03.10 18:44:37 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\PCDr [2012.11.04 09:23:04 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\PlayFirst [2012.11.08 19:04:37 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\ProtectDISC [2012.04.01 19:27:37 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Samsung [2012.10.26 10:35:25 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\six-updater [2012.10.26 10:33:15 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\six-zsync [2012.06.26 18:08:45 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Sports Interactive [2013.03.03 14:16:31 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Spotify [2013.03.02 18:23:30 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Synaptics [2012.03.08 22:38:57 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\System [2012.06.01 10:02:36 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\T-Mobile [2012.06.09 11:40:27 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Temp [2013.01.03 17:28:07 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\The Creative Assembly [2012.03.20 21:07:19 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Tobit [2012.10.26 12:40:44 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\ts3overlay [2012.10.26 12:40:58 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\ts3overlay_hook_win64 [2012.03.08 17:46:12 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\TuneUp Software [2012.10.31 17:44:24 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\Ubisoft [2012.10.05 15:46:59 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\wargaming.net [2012.08.18 20:17:21 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\WinBatch [2012.03.08 22:40:03 | 000,000,000 | -HSD | M] -- C:\Users\Draco\AppData\Roaming\wyUpdate AU [2012.05.13 10:49:37 | 000,000,000 | ---D | M] -- C:\Users\Draco\AppData\Roaming\XRay Engine ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:05EE1EEF < End of report > |
03.03.2013, 21:26 | #3 |
| 2 Probleme mit Alienware M17xR3 2. Logfile - Teil 1:
__________________Code:
ATTFilter OTL Extras logfile created on: 03.03.2013 14:04:18 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Draco\Desktop 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,98 Gb Total Physical Memory | 5,01 Gb Available Physical Memory | 62,73% Memory free 15,96 Gb Paging File | 12,57 Gb Available in Paging File | 78,76% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 688,86 Gb Total Space | 216,99 Gb Free Space | 31,50% Space Free | Partition Type: NTFS Computer Name: DRACO-PC | User Name: Draco | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .reg [@ = regfile] -- regedit.exe "%1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .reg [@ = regfile] -- regedit.exe "%1" [HKEY_USERS\S-1-5-21-1503614190-581956262-4018303520-1000\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [open] -- regedit.exe "%1" regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [open] -- regedit.exe "%1" regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{031A122D-D577-4457-8F74-F67EE78B075C}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{04A6BF93-E3E6-4E5D-A508-10E8077287BE}" = lport=2869 | protocol=6 | dir=in | app=system | "{0D0AF8D0-82BB-4E61-A244-2F4B267FC6BA}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{161374C6-F859-4E34-8C72-E4D85C29736D}" = lport=137 | protocol=17 | dir=in | app=system | "{1A14FD92-3C3B-47DB-9E97-8EDE248931C6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{22A37095-5C87-44B9-82DB-A54E2CFB425E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{3A46C092-EE70-4821-8E85-AEE58D795993}" = rport=445 | protocol=6 | dir=out | app=system | "{48A649C0-2128-474D-B36B-BEEB6E0EF8DB}" = rport=138 | protocol=17 | dir=out | app=system | "{4B61FDB5-956B-4086-AEB6-539B0C36802A}" = rport=137 | protocol=17 | dir=out | app=system | "{4E9258C8-7F61-4AFC-9DF0-F56D90A40871}" = lport=2869 | protocol=6 | dir=in | app=system | "{4EBAEADA-0D0F-4BB8-84D7-0B075C858B2B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5EB614F0-2F7E-4B42-A387-0A8528D9FC22}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{63FE6E29-42E5-4C2A-B92A-FA1E96E39D42}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{74178DD1-8F02-4E59-A86C-FB8D3C010598}" = lport=12972 | protocol=6 | dir=in | name=audials localhttpserver 12972 | "{75F5A15F-6DCC-4332-9A1E-50D9F81B22C7}" = lport=139 | protocol=6 | dir=in | app=system | "{79339585-9BBD-47A1-B471-19A4AFD9AD11}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{84278F52-8EEF-403B-A6CA-C0E70375339B}" = rport=139 | protocol=6 | dir=out | app=system | "{855CF942-D0C7-4916-B39B-30469289A45B}" = rport=10243 | protocol=6 | dir=out | app=system | "{8E958C89-2E5A-46C9-8572-87401ED44BDB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{9FFF4DD3-77B2-4996-A8DF-25AC3F6F53D7}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{B58296D2-FFC5-45E5-BF6C-8C8CC31B2A33}" = lport=10243 | protocol=6 | dir=in | app=system | "{B981C0E7-C1D1-411A-ADB0-A5C346207EB5}" = rport=2869 | protocol=6 | dir=out | app=system | "{CA6F956F-6232-4B02-8217-CF5BE533847F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{CE937B43-648D-4E7F-80F3-5C102794EB13}" = lport=31931 | protocol=6 | dir=in | name=audials localhttpserver 31931 | "{D0D90C1E-0777-4B8C-A289-B656B9BC366F}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{DAA3D0C6-689F-4B4F-84E7-05683614BC6E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{DDD7A515-D1D9-4DC0-862F-A254E03101B0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E02EA900-914F-4C5C-A853-FB1F9C50570E}" = lport=445 | protocol=6 | dir=in | app=system | "{F3BDE11A-960A-420D-ADEF-05E7C39AE409}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{F3E6979C-EA8B-48D5-9B55-5BA000CC884A}" = lport=14714 | protocol=6 | dir=in | name=audials localhttpserver 14714 | "{F3ED5832-E5AA-4D14-AB0C-2C882AD995AD}" = lport=138 | protocol=17 | dir=in | app=system | "{F79F2FB6-F8D4-4B1C-B55A-2D8626728EE7}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FB53CEAD-9546-4989-AE95-556A580160D4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0005199B-61E7-4705-BE0A-D0D2BF04B3A0}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\metro 2033\metro2033.exe | "{001BB54A-881D-4FED-9B95-8E016601444C}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\installerhelp.exe | "{00476C33-4FD6-4683-8346-E9F62C329658}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe | "{006AB649-D405-44A3-9C66-71280F2C33E5}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe | "{00A78A9D-2DE7-4DBE-A677-255581206C3F}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\jedi academy\gamedata\jasp.exe | "{01307B1E-6CBC-49B1-9356-5D398857F71F}" = protocol=17 | dir=in | app=c:\program files (x86)\bitcomposer games\s.t.a.l.k.e.r. - call of pripyat\bin\xrengine.exe | "{01D4D293-BE2B-4667-BCF6-F6E950DCC12A}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\euro truck simulator 2\bin\win_x86\eurotrucks2.exe | "{025B81A9-62F4-4B32-A3D8-8902245D7C0D}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\x-tension\runme.exe | "{0403E16C-13E4-4A92-8539-C572673C6E57}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremote.exe | "{04EB1409-5590-4C43-844C-79232FB4736A}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{055EFF4B-AD6D-421C-9A35-45FFB6F5EE2E}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars empire at war\runme.exe | "{05AE9777-CF9D-4EEC-A152-DB3F7A55965B}" = protocol=17 | dir=in | app=c:\program files (x86)\bitcomposer games\s.t.a.l.k.e.r. - call of pripyat\bin\dedicated\xrengine.exe | "{06329662-7183-45CE-AD76-8D6B3AEC90A8}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dead island\deadislandgame.exe | "{081AB853-E201-4DE8-8770-A4BCF0322D30}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars jedi knight\jk.exe | "{0842B766-CBF6-4473-BAEE-1C1DF01F6EDE}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia forgotten sands\prince of persia.exe | "{0852EE52-9E70-4E0B-9548-CCC967056052}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\resident evil operation raccoon city\raccooncity.exe | "{095041F1-25B4-4562-88E6-3EAE0ED6BA7D}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe | "{09E93C40-6D03-492F-B1BD-0435D3349D7C}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hitman blood money\configure.exe | "{0A9C9163-434F-45E1-8068-9D8FE5031BF7}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 3 tiberium wars\support\ea help\electronic_arts_technical_support.htm | "{0B1973D4-F273-4464-8A5E-C1F9F0F2ACCD}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | "{0C4EC097-2DD3-4687-9628-8ADCE51F2044}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\deus ex - human revolution\dxhr.exe | "{0CCD3B67-1D26-463C-9C7E-56E647E00687}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dragon age ii\dragonage2launcher.exe | "{0D2984F3-0580-4C08-9CBE-8F60FF52B1BF}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hitman 2 silent assassin\hitman2.exe | "{0D6B4511-9E04-419C-9770-8B42404EE3DF}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\prototype\prototypef.exe | "{0E06F769-CFD2-4249-9FEE-A76B52C30DD2}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\grid\grid.exe | "{0E2AFA9C-9433-457E-AB19-77122ADB3C18}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{0F0A8A97-D3ED-4B03-AF43-2B01E59B490A}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\rage\rage64.exe | "{0F6E6BD7-0C39-4C9A-B0E8-50319433A2E2}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\arma 2\arma2.exe | "{0FA3EFA2-8079-4F89-9E88-088B7FE561A9}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\amnesia the dark descent\launcher.exe | "{0FC5D3DD-9303-483B-842C-F628AE587D39}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 2\binaries\eacoreserver.exe | "{0FD417D2-FDCE-40D8-ADF3-6AC28A58E4CA}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\the walking dead\walkingdead101.exe | "{104A9E35-BF78-482A-B229-784D5E9F4C83}" = protocol=17 | dir=in | app=c:\program files (x86)\capcom\lostplanetcolonies\lostplanetcoloniesdx9.exe | "{11811AA6-3F45-4B71-B71A-1755581DC18C}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\the sims 3\game\bin\sims3launcher.exe | "{11ACF068-7F07-42C3-8FA5-4395282420A0}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | "{12E500C8-22BF-4A6F-B454-1F47D5938CC7}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\silent hunter 5\sh5.exe | "{12FF6C2C-8544-44AA-81DE-2B85EE239FA9}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1309D072-EF06-414C-A574-7DF930802182}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\lucius\lucius.exe | "{140BFA87-F4C6-4980-A839-BCBBEFF303F5}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hitman absolution\hma.exe | "{156A7F32-05FC-467A-87A2-03BFC72AA663}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\far cry 3\bin\farcry3.exe | "{157F0DCC-0DDF-4138-B491-1EA26097526B}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dishonored\binaries\win32\dishonored.exe | "{15ECD15E-5895-4803-9963-EF63980BEC67}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dirt 3\dirt3.exe | "{1772AB71-1874-4674-B3ED-03E3FA93C474}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dc universe online\launchpad.exe | "{182A3EF6-7DBF-40A2-9C52-7101A6CAEB42}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hitman blood money\hitmanbloodmoney.exe | "{191A34BD-0F2D-4263-BD85-0861596535AF}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\two worlds ii\twoworlds2.exe | "{1965B235-95FE-4085-940C-01D846B3FEF8}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\kings bounty crossworlds\kb.exe | "{197475C9-420C-4053-A366-1537045B24F3}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dungeon siege 2\dungeonsiege2.exe | "{19B073D6-95C9-4C04-AF24-DCE907F7B20A}" = protocol=6 | dir=in | app=c:\program files (x86)\tobit radio.fx\client\rfx-client.exe | "{1A0F2B6F-4DCF-443D-BE00-1536740C22E1}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\dead space 3\deadspace3.exe | "{1A54E10D-D9E4-408A-B6DB-C0C563DBBF8C}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\x3 - reunion\x3.exe | "{1AF0EB77-E73E-4C28-A7D7-C19084F77008}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hitman blood money\hitmanbloodmoney.exe | "{1B869E5F-A8B0-4AA7-818F-7589C97F144E}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe | "{1C5EA78B-DC44-4512-B7A6-03698FFE2C2D}" = protocol=17 | dir=in | app=c:\program files (x86)\even balance, inc\punkbuster\pb\pnkbstra.exe | "{1C6E91C6-EE17-4EEC-8A82-383F471F195A}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\saints row the third\game_launcher.exe | "{1CD2501B-4D32-4E1A-82C5-F915CE37C593}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars battlefront ii\gamedata\battlefrontii.exe | "{1CF68C2D-97E4-4CAC-9376-245E8FE6993F}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\prototype 2\prototype2.exe | "{1CF8D43B-A5F9-4F00-9ED8-1E83E7F550A4}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\jedi outcast\gamedata\jk2sp.exe | "{1D83F3B9-1A04-4EA1-9A59-F25BF759B2D6}" = dir=in | app=c:\program files (x86)\audials\audials 10\audials.exe | "{1E90071C-A4C4-4058-A1A3-0546A062DA84}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe | "{1EC7AC50-F7F0-4624-8F7C-F529259DD8EB}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\crysis 2\bin32\crysis2.exe | "{1F1D2304-7BDA-42D9-A568-60CF2B8D4F6E}" = protocol=17 | dir=in | app=c:\program files (x86)\capcom\lostplanetcolonies\lostplanetcoloniesdx10.exe | "{201DE1F4-C37A-4D4D-92B2-ACA862F7420C}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\jedi knight mysteries of the sith\jkm.exe | "{2038D4E5-E2A4-48B7-A606-2E6AEA375865}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\silent hunters wolves of the pacific\sh4.exe | "{21367C60-50A4-4D8E-8777-6263A0AEBC69}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\prototype\prototypef.exe | "{213A5BE8-434D-4D71-BD22-5A919B46A003}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\crysis 2\support\ea help\electronic_arts_technical_support.htm | "{2143CEC2-7368-4A8B-B77B-55ED872E83FF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{22033114-4994-45F6-ADE1-DDAC4B797398}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia forgotten sands\prince of persia.exe | "{22A01BDA-4E0D-445C-A1B7-FAF9EE0DF2E7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{22AB7F95-3F83-43BD-8365-8691A67121F4}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\x3 - reunion\x3_reunion_manual_steam_english.pdf | "{22CA7F78-3280-4352-BEAD-D3AC72A57267}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{23DD576F-1899-40A5-8ABF-65E44F959AE6}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | "{2404FF06-DBD3-49E8-A12B-2A291A44F193}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\cities xl 2011\citiesxl_2011.exe | "{25A5E09A-89B5-40CA-89CD-006768CAD406}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe | "{25BD2DB4-98F4-4173-A882-A5C7236A26D0}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe | "{25E64B1C-E93E-4E52-A2E6-3536A05CA43A}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\rage\rage64.exe | "{2655B255-6315-4A10-AD60-2D9CC482429D}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe | "{274919AB-DE77-470C-926C-7BE387EFAF63}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{27A07BE4-1BA0-40C9-84EB-C99E368466A8}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe | "{28107610-8E17-4649-8D5E-EEFC78C53F84}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\galaxy on fire 2 hd\gof2launcher.exe | "{29A7E14F-88A0-4476-9287-D79B3676438F}" = protocol=17 | dir=in | app=c:\games\world_of_warplanes\worldofwarplanes.exe | "{2A209977-8334-430A-A61D-1E93DCD3BD34}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\batman2\binaries\win32\batmanac.exe | "{2C33CDE3-92F0-46FE-9A1D-0B9021C116C4}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\swkotor\swkotor.exe | "{2C9D0E66-212F-4867-AB1C-6E3D9E37C00F}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\need for speed(tm) most wanted\nfs13.exe | "{2CE4033D-DE68-40AB-A28A-23B66513D57C}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\x beyond the frontier\runme.exe | "{2D457D65-D070-48C5-A716-63B31C8D6E59}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dirt 2\dirt2.exe | "{2EB9B223-0D07-4CA4-8457-B3C5EC074E86}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia two thrones\princeofpersia.exe | "{2EDFDC84-E709-47DA-BE8C-6134FD552013}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\football manager 2012\fm.exe | "{2F3893D5-5A13-4FD1-B9AF-1C1040A08BA2}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\anno 2070\anno5.exe | "{2FAC8E1F-F6FE-441D-80C7-FD7647E6E3BE}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hitman codename 47\setup.exe | "{2FDF9AC1-E42A-43A6-BA1B-8F5000D37541}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 3 tiberium wars\support\ea help\electronic_arts_technical_support.htm | "{3025D0A5-03F8-4E3A-985C-DE18C8B9D8D4}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\the sims 3\support\ea help\electronic_arts_technical_support.htm | "{3090CA08-346A-4888-A399-1FAEB7724805}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\blacklightretribution\blacklight retribution.exe | "{30AE04E9-6682-495B-B8B1-A3BEE87C3294}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\binary domain\binarydomainconfiguration.exe | "{30B430E4-DC2A-4D4A-82F3-37C9BCB5852E}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\alan wake\alanwake.exe | "{30E3F543-1BAB-473F-9816-1041E80F8409}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\cities xl 2012\citiesxl_2012.exe | "{30F18C47-20DB-49BC-B60E-BEFB5A8EAE12}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\x2 - the threat\x2.exe | "{31404D38-6179-4398-8509-61DD95759447}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\lucius\lucius.exe | "{32988458-C5EC-4298-BCF7-CC6DA462DFEF}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\kings bounty crossworlds\kb.exe | "{337B8A28-EC57-4B35-97EE-7F370F716EB2}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dragon age ultimate edition\daoriginslauncher.exe | "{34201C8C-9484-48DD-B422-BDF0FF84E5FC}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars republic commando\gamedata\system\swrepubliccommando.exe | "{348E6CE4-4267-4304-A7F2-B920D118C30E}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 3 - kane's wrath\cnc3ep1.exe | "{34E5CEC7-806A-4890-B10A-35B17253CE94}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{350A004B-9737-4D2C-B7F2-1801D938D48B}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\assassins creed brotherhood\acbsp.exe | "{3559A233-CDCF-46D3-873D-D4BFBC281370}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\assassin's creed revelations\acrsp.exe | "{35A4BBAD-9C81-4916-AFC0-8021F26BB145}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star trek online\star trek online.exe | "{37BBD6B8-B926-46C8-AB1D-7D016045C4C2}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hitman codename 47\setup.exe | "{37C732D2-1EC2-4317-B9C8-936FE71EB91B}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hacker evolution untold\hacker evolution untold.exe | "{37E619ED-1A27-45E0-8B3E-5141B75036A8}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\fallen earth f2p\feupdater.exe | "{3854FC8F-5EFB-42F2-A26F-1F84C5D317E3}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{38BBF434-28D2-4DF8-BF97-BCE47C87C3E9}" = protocol=6 | dir=in | app=c:\program files (x86)\capcom\lostplanetcolonies\lostplanetcoloniesdx9.exe | "{39A7C048-7F18-4C1A-9E81-4B0850961035}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 2\binaries\masseffect2.exe | "{39B110E1-BD87-4BE4-A900-8096BCDE4475}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\need for speed(tm) most wanted\nfs13.exe | "{39C40299-0459-4514-8D46-98D715A69969}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\doom 3\doom3.exe | "{39EC9888-6B75-4C4F-A8D0-AE851E1F5D47}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\arma 2\arma2.exe | "{3A2B7DAD-0CB2-4B3F-BDAC-8A7DA7826562}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | "{3A6E96DA-DE58-49B7-A6B2-FAC4B3A3F9C3}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia\launcher\launcher.exe | "{3B160422-945F-4AA1-911A-C8443E8655BD}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\king's bounty - the legend\save_fixer.exe | "{3B529433-C380-49AB-B81A-0151BA3D7F82}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | "{3C2F2BE8-255A-4024-BC7B-57CF80A67411}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\railworks\railworks.exe | "{3C7E3EC4-8D16-481A-A9D4-13C8EBD888EA}" = protocol=17 | dir=in | app=c:\program files (x86)\thehunter\launcher\launcher.exe | "{3CBEA6CB-9C0B-4F0C-A654-601F8F276BD1}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\doom 3\doom3ded.exe | "{3CC861CA-A741-4DC3-8C7B-613F813C5811}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars republic commando\gamedata\system\swrepubliccommando.exe | "{3DA6E0D8-1198-43DE-A12A-510C0F72A71B}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\tom clancys endwar\binaries\endwar.exe | "{3E3AA642-7A7C-4B17-A7FB-52F09E66BFB5}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\arma 2\arma2.exe | "{3E42C78E-8D53-43EB-B7C7-CB7D8E83F9BA}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{3E561655-A34F-4BA7-BD3F-4C5C3AFE0C14}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\medal of honor warfighter\mohw.exe | "{3ECAFEE8-4371-46E2-90DC-5578759812FF}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | "{3F2A21C6-D9E9-4D5E-A59F-BB4A1AFD3C19}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe | "{3FAE244C-CE99-431C-883C-D7C7001A882A}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\just cause\jcsetup.exe | "{400C3EC8-DB04-47E0-AC98-4EBF47EA5927}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\swkotor\swkotor.exe | "{40402A9C-DF2E-4C39-A1F6-E692E560455D}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\rage\rage.exe | "{404FED56-F543-4723-AFFC-FF26A477F7E9}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe | "{40785032-F602-45B5-B7C5-D3F3071FC7D7}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars starfighter\starfighter.exe | "{409F831F-7D67-4C43-B3C8-EDD3C41F426B}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\dmr.exe | "{410D4188-6CA7-4C5F-A3D0-7D37E3253C0E}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dear esther\dearesther.exe | "{41175034-7858-47AF-9F47-A40449F8A467}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 4 tiberian twilight\support\ea help\electronic_arts_technical_support.htm | "{414D6AA4-BA38-4AE0-B654-A2D642276B02}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\king's bounty - the legend\save_fixer.exe | "{424D6B87-B709-4EC3-A65E-B9DAE5393E6C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{42E1CE44-C9C9-462C-BFB4-CCE09D108F89}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead\left4dead.exe | "{433B54A1-B27B-4FD1-80C5-DEF24FFBAB0D}" = protocol=6 | dir=in | app=c:\program files (x86)\tobit radio.fx\server\rfx-server.exe | "{43BF24FF-6C05-4D8E-9FDD-976B4CDCE782}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{43C7F827-7E3D-4D0F-8424-01F5A30B3033}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\installerhelp.exe | "{44568AAB-33C3-45C0-89A9-71F47B596FF7}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\anno 2070\anno5.exe | "{45500D88-C1D7-4E83-B91C-7D093F8C0E38}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars jedi knight\jk.exe | "{46291583-2A40-467A-9E35-7A6BCBC382F9}" = protocol=17 | dir=in | app=c:\program files (x86)\tobit radio.fx\client\rfx-client.exe | "{47A716A3-2A1F-4FF1-84F1-2060AD0FBC64}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\anno 2070\anno5.exe | "{47AF2989-BC62-4A1A-A7CF-10B30041DE54}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\euro truck simulator 2\bin\win_x86\eurotrucks2.exe | "{48B75A47-A732-4873-B32B-9C9C0C35551A}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\kings bounty armored princess\kb.exe | "{4931DA18-088B-4886-BF50-9477572FC51A}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\duke nukem forever\system\dukeforever.exe | "{4A6BF722-A12F-481F-BB2A-751CD0915DB6}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\alien swarm\swarm.exe | "{4B480C56-0BC5-4D21-9D01-2B0461D87FC0}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\crysis\bin32\crysis.exe | "{4C292199-EB55-40F0-BE88-3081D4F21DA0}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\gotham city impostors\engine.exe | "{4CC8D551-DAA0-4437-94DE-7BC7C5098B78}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe | "{4CF95AFD-F6E1-4E88-BB8E-00E347DBA4F3}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\specops_theline\binaries\win32\specopstheline.exe | "{4D2AC204-000A-4986-93D3-6BD71755B618}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dragon age ii\docs\ea help\electronic_arts_technical_support.htm | "{4E05C6C9-CE2C-441B-AC84-86014D52A846}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dirt 3\dirt3.exe | "{4EB210B9-DAFD-45EE-A8A5-0F2008594691}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\blur\blur.exe | "{4ECFDC37-43CE-4F8C-827E-5D51EAFA5A24}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hitman 2 silent assassin\config.exe | "{4FCE064E-F6EC-4A52-B982-3E8DB960B2B8}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\just cause 2\justcause2.exe | "{4FD2C342-736A-47C5-9307-DC3612AD3E28}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\forsaken world\patcher.exe | "{51BC240F-59ED-430B-927E-5C3BBDB6CB0F}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\king's bounty - the legend\kb.exe | "{524040D2-D300-4A33-8D37-0CB3F649FF69}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hitman absolution\hma.exe | "{52EABBDD-5CFE-4A2B-8CA7-5C43A738261C}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\batman arkham asylum goty\binaries\bmlauncher.exe | "{536BC1CF-3F8D-4DCD-8E34-6B64396D1B19}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dungeon siege 2\dungeonsiege2.exe | "{54538C36-A89D-4BB6-91BB-DB384DA648A3}" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe | "{557AFAB5-C980-48DE-8BF6-76EF9C4B88A6}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 2\masseffect2launcher.exe | "{55B7D1B2-BED1-408F-BF3F-E8E2624EE63E}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\crysis 3\bin32\crysis3.exe | "{55F6C247-2956-4D5E-BF69-E79C5479BD2A}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\lucius\lucius.exe | "{5608F3A9-657D-4620-9C8F-1A391BA8FA6D}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 3 - kane's wrath\support\ea help\electronic_arts_technical_support.htm | "{567F48A3-A71E-4427-BE8A-BE900CD6C2EF}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\fifa 13\game\fifa13.exe | "{56984E15-4737-4DD3-B964-1722088B4B10}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\crysis\bin32\crysis.exe | "{56BEBF10-A87A-476F-8EFF-00921BA70DDD}" = protocol=17 | dir=in | app=c:\program files (x86)\anno 1701\anno1701.exe | "{571D2B5C-30E1-4DA3-9080-BBD418D7572C}" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe | "{575043C1-309B-470C-BC33-E8EF8E24153F}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead\left4dead.exe | "{57550CEE-68E4-4ED8-9424-26B24E72F591}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\x3 - reunion\x3_reunion_quickstart.pdf | "{57D1A672-DE44-4443-815B-A6650458FAA4}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe | "{57D2C5C1-A29F-4C79-90B7-71A99C303E8A}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\crysis 2\support\ea help\electronic_arts_technical_support.htm | "{57F1F316-2ECF-4919-9625-81B78A3FA9B6}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | "{58D56CA0-08DB-40EC-8348-B8D03FCC4B7A}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\x beyond the frontier\runme.exe | "{58FED743-E05D-4A13-B5EB-5252EB1D48C8}" = protocol=6 | dir=in | app=c:\program files (x86)\thehunter\launcher\launcher.exe | "{5925ED27-1639-490A-A49C-6A9CD2B20D38}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\saints row the third\saintsrowthethird.exe | "{5966D115-EB31-47F0-95C0-8834E7A96D66}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\gotham city impostors\engine.exe | "{59F6358C-45A1-4B50-8867-B1001D96001F}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\prototype\prototypef.exe | "{5B855C3F-BFB7-4E0A-81B6-2A95A9424736}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\swkotor\swkotor.exe | "{5C3D4833-6D48-4E52-8462-F0456C61A20A}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars the force unleashed\swtfu launcher.exe | "{5C64FA7A-491E-45A9-B5B8-D9AB035C21B4}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\tom clancys endwar\binaries\endwar.exe | "{5CAAF40B-E44D-45E7-8FD6-4F954F9301E8}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\il 2 sturmovik 1946\il2fb.exe | "{5CEFB284-5640-4782-889D-FC0E95865250}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dirt\dirt.exe | "{5D5E9F4B-20DA-46EF-A93E-9C5C8A6B5E4D}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe | "{5DDF9F19-F2EE-4D3B-8333-ABFAC68C1F26}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\silent hunter 5\sh5.exe | "{5EF75B10-6A46-4E88-88CE-2013EE3437DF}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe | "{5F3C8FAC-BEFE-4E04-AA6E-41D89BA1B3D7}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{5FE9A2AB-0A76-465F-8A69-C1776BAFA38B}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\jedi academy\gamedata\jasp.exe | "{6174CE27-DC88-46AE-8FAD-3B1C861B5A2A}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hacker evolution untold\hacker evolution untold.exe | "{618582E1-B241-40C1-8C1B-EB28F35D6203}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\assassins creed brotherhood\acbsp.exe | "{61D74160-959F-4ACF-BF52-B060AD8D5027}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 4 tiberian twilight\cnc4.exe | "{61DD734E-9E59-4AB4-9CA1-00E964FA0C07}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars the force unleashed\swtfu launcher.exe | "{61E71B24-19F2-4F3A-BD14-00B1856DD3B6}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe | "{61EE9212-4268-4CC2-9AA7-699C7961AD66}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\swkotor\swkotor.exe | "{6294C92E-0FF4-4263-B14D-063ABD6EA792}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\sniper elite v2\bin\sniperelitev2.exe | "{629E2C9B-A9F8-4980-B33C-4F6D7BBE2199}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe | "{63D6AA9E-CC89-4DAA-AB24-C3A713DCF014}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\fear2\fear2.exe | "{64080B4C-17F0-4F78-A719-6699EE3B9846}" = protocol=6 | dir=in | app=e:\program files\steam\steam.exe | "{6448DF68-659D-4652-8FFC-4B45F6AC2B68}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dear esther\dearesther.exe | "{644BA9D0-3401-4302-AB3E-4E58C458203E}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia two thrones\princeofpersia.exe | "{65D60EE8-D750-4E15-8D5B-A03F88BF7F9D}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe | "{66DE1C26-299F-49ED-A16B-CE70CE98E538}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | "{6752EB2A-20F1-437A-B447-CEF402B954FE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{6821A65A-4F50-4864-BAC3-DFC21D8942C8}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\lucius\lucius.exe | "{68D40232-B05F-48AF-9D67-DCAEE41296BF}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\x3 - reunion\x3_reunion_quickstart.pdf | "{695B67A2-0406-4E6F-891B-AE98C126EAA8}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\jedi academy\gamedata\jamp.exe | "{69AAFA0F-EADC-42B6-9F01-6EEE91E420A0}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\controller.exe | "{69BC2594-E2EC-4715-9F98-0F22147EDAC7}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\just cause\justcause.exe | "{6A8A4DD0-D57C-447F-B0B8-14701830AC1F}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 3 tiberium wars\cnc3.exe | "{6B7E353D-D70C-45DB-B789-EBD193F12A86}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\gotham city impostors\impostors.exe | "{6C417E9A-9E1E-4CB5-92E2-BE77DDDCF1D0}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\batman2\runlauncher.bat | "{6CC04617-1752-47C0-812F-C2F133DE0F8D}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\blacklightretribution\blacklight retribution.exe | "{6DA06335-4D55-444E-B870-317E1E28B46C}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3mp.exe | "{6DA83543-0D05-4F1D-9092-CA6281D158DB}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{6E75ED3E-0AEB-42A3-A35B-542BFA29940B}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\rage\rage.exe | "{6F5B4947-CF69-4C85-B492-A9956D9035ED}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe | "{6FB0D582-2460-437C-AAB7-0B25960CFAAE}" = protocol=6 | dir=in | app=e:\program files\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe | "{700611A6-F179-4A90-A1F2-4F7A04C69FAF}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\controller.exe | "{7144F433-A9B0-44F0-A647-586A743105A3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{7157FD99-1F23-4252-8AA5-1A320F6CB4C2}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{71CFAEAE-A4A9-42F8-9FDA-688928E78D46}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{7228AD5B-ED1A-4FBD-9BA3-675F90DD5F6A}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\football manager 2012\fm.exe | "{723BE436-6D09-4222-ACB5-DDCA49BA2AE9}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe | "{7291DC1C-927C-492B-9262-E084C32543D9}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe | "{72A3B311-DCD6-4F19-B5DA-14FAE41048A1}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\il 2 sturmovik 1946\il2fb.exe | "{72B0FB25-E8DD-40ED-9DCA-6944E8D5E984}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe | "{72C47E9B-22BF-4154-9A2E-9DAB13F2D98C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{735667C0-0B44-4C38-A63F-06AD8A03E6DC}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\kings bounty armored princess\kb.exe | "{745C34C6-19A2-457C-A4BE-12E36C314D6E}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\the walking dead\walkingdead101.exe | "{7479B5A5-36EC-4C9C-9A16-62A91AFB9E4C}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{74DEF0D8-D2FC-4242-8837-91D0FF307C0D}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{754D4024-2747-401D-BACF-28AD33A9C522}" = protocol=17 | dir=in | app=c:\program files (x86)\tobit radio.fx\server\rfx-server.exe | "{75EAE5D2-4C59-4027-B773-A35198B969A1}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\sniper elite v2\bin\sniperelitev2.exe | "{7607BE5F-58DD-4198-8E4A-55DD1206DCDE}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\the sims 3\game\bin\sims3launcher.exe | "{76A7A948-2024-473B-AD56-AB3F4683CE6F}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\kings bounty crossworlds\kb.exe | "{773002E2-BA95-4690-A260-2FF387F08275}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect\binaries\masseffect.exe | "{78205BA6-298C-45E3-AE7E-986C584A5B33}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\fifa 13\game\fifa13.exe | "{795E6324-8669-4AB0-8B5C-D6086764DA22}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\jedi academy\gamedata\jamp.exe | "{7A79ECAB-B6CB-4E71-8A40-B9B049C39C95}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | "{7A7D27B8-CA40-4EB0-92A0-E35CE0069E30}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars starfighter\starfighter.exe | "{7ACAE226-169C-4A1E-9341-2964C2294DBA}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\fallen earth f2p\feupdater.exe | "{7BC45D5D-8DEF-4438-9CD9-32F9060D4439}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe | "{7C94A669-784F-408C-94DF-D8772F39F448}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{7C968DD7-2B51-481A-A60F-EABA7363101D}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\forsaken world\patcher.exe | "{7CB29FC8-6656-44B2-BD5B-F628BB5B48D3}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe | "{7D41855E-81B3-4C39-95D2-4E1F338B6816}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{7DB62827-B542-4EC7-BE36-10179CBEFF44}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dungeon siege 1\dungeonsiege.exe | "{7DB80AF2-5A65-49FB-8E6B-A2B84D27566E}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\amnesia the dark descent\launcher.exe | "{7DD45EAD-B50C-432E-946B-1A5E6EF16471}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\stalker clear sky\bin\xrengine.exe | "{7E3EFA6A-90FF-4819-93CC-8FAD65C647DF}" = protocol=6 | dir=in | app=c:\program files (x86)\even balance, inc\punkbuster\pb\pnkbstra.exe | "{7E8209EF-1810-4EE7-9FBE-B058E14C62AB}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dragon age ii\docs\ea help\electronic_arts_technical_support.htm | "{7EB415B8-E607-4024-9454-71DDCC963E88}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars empire at war\gamedata\sweaw.exe | "{7FD7238F-F4AF-401A-A623-40220251D27B}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars the force unleashed 2\swtfu2.exe | "{8039EFAF-FB48-425C-85C8-85236625A497}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe | "{8068AD1F-C315-439F-9257-9B8C444DC800}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe | "{80D4152F-FD50-40BE-981F-1B1343B7A8F7}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\two worlds ii\twoworlds2_dx10.exe | "{81063D41-1D8F-426F-A108-9D68EC6D2553}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\x2 - the threat\x2.exe | "{8153EFE3-2123-48DA-ADC1-39A08EC5A3D0}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe | "{818CCC15-1CBD-4CF8-9721-628347948106}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 3 - kane's wrath\cnc3ep1.exe | "{81F2D4F5-C259-4240-A25F-6CF25221BEC6}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\prototype\prototypef.exe | "{823B0724-08CE-4ACB-A8F0-853C8302EA0A}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\crysis 3\bin32\crysis3.exe | "{825F783F-F8AA-4F06-8744-0598317ACAD9}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 2\binaries\eacoreserver.exe | "{82BCCA73-6ADA-409A-B535-ED852B0F3FE2}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars empire at war\gamedata\sweaw.exe | "{83635242-A23B-46F1-9678-428BCAC97029}" = protocol=17 | dir=in | app=c:\program files (x86)\funcom\the secret world\clientpatcher.exe | "{8457FA17-26F8-481B-B16F-B4602FA69138}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\magicka176\half-life\hl.exe | "{84CCF60B-1DE1-4B00-80B4-C3F96AC610A6}" = protocol=17 | dir=in | app=c:\program files (x86)\ccp\eve\bin\exefile.exe | "{851D359F-9DDF-43BB-AA5D-D7F6CF82BB2E}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremote.exe | "{8604AC7B-5346-4576-9791-01D18B0D7519}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia the warrior within\princeofpersia.exe | "{87F8C3F0-C207-423F-8082-028CD4E9E60D}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\mafia ii\pc\mafia2.exe | "{883E72AD-824A-439A-9D7F-CB5FB92D6D0C}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\lunar flight\lunarflight.exe | "{885CEFDE-9CEE-4504-8C46-9FD5D08A3B16}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\duke nukem forever\system\dukeforever.exe | "{89B7BC94-334F-4490-9DDD-44A7ED0B67CC}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\doom 3 bfg edition\doom3bfg.exe | "{89EC1AB5-3F3A-4E2F-AA9D-79C1B35FFB16}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hacker evolution untold\hacker evolution mod editor.exe | "{89ECE401-36EE-4BEF-A84F-CFF0C7ED9ED9}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe | "{8B54FDD3-C40D-4F43-A423-3E4C026E9678}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\alien swarm\swarm.exe | "{8B717D70-64AB-49FD-8948-FE5C16B5D481}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\prototype 2\prototype2.exe | "{8C5F4FE6-F81B-47B8-8070-696B6598A31D}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\railworks\railworks.exe | "{8C6716FF-B31E-4DC2-8933-557ED1B5F80B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{8CA9BDA4-192F-4EFA-9D7B-F54FF3362F76}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars starfighter\starfighter.exe | "{8CBD406A-A19F-4D2C-8D7A-E305E13F50EE}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\crysis 2\bin32\crysis2.exe | "{8CE9144B-0435-4430-B9D0-1B99434BAFD8}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\binary domain\binarydomainconfiguration.exe | "{8D187419-B784-4788-A7DC-E78EA8D22A2E}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\the sims 3\support\ea help\electronic_arts_technical_support.htm | "{8E88A0CA-2A8B-47DE-B387-83DC4807B590}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia the sands of time\princeofpersia.exe | "{8E8BCAD2-E96D-43E5-84F2-5D26B8D52C7E}" = protocol=17 | dir=in | app=e:\program files\steam\steam.exe | "{8F3FBC89-2704-4324-A9A9-E98071CF1A1F}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | "{8F7BC98B-EBF7-4D62-8038-3AED45DB7799}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\portal 2\portal2.exe | "{8FCE11F8-4508-46D8-9498-7B32D9D30E47}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia the warrior within\princeofpersia.exe | "{90851732-5010-48EA-80C7-D2A547CFE229}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe | "{91AAF204-0CEC-46DC-8FF5-C0B085F42C18}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\two worlds ii\twoworlds2.exe | "{92E70224-DDDB-42D9-B04F-1DA68794019A}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\x3 - reunion\x3_reunion_manual_steam_english.pdf | "{92F39774-CF62-4EE2-96BB-910D64211B06}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\tom clancy's ghost recon future soldier\future soldier.exe | "{933CCFCA-49BD-4096-BE9B-0F3AC860B27E}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\alan wakes american nightmare\alan_wakes_american_nightmare.exe | "{948A23F4-2539-4377-B4C7-3BEE371492C9}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\wheelman\run_game.bat | "{95173B12-81F3-4FE9-BF52-98A5EB4DDEAE}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\jedi outcast\gamedata\jk2mp.exe | "{95A50196-334D-44CB-863B-0AECB52D9E52}" = protocol=6 | dir=out | app=system | "{96B3E449-D761-48D7-877D-38712B02C8C2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{97707860-B5CE-44EC-B471-E869310BFF3F}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect\masseffectlauncher.exe | "{97E4F8A7-676D-46D5-8CEA-BE16B86968F8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{981B5EDD-3516-448D-A34C-E81D733A4518}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\cities xl 2012\citiesxl_2012.exe | "{98AEFD09-D5FE-4D20-A018-90D6794DC885}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\planetside 2\launchpad.exe | "{99069BB2-B93C-42FB-9E11-D74F3240F1D4}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe | "{993E89E8-2485-4A3E-8B5B-93E7F1C619C5}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{9A39C3C6-A53A-4A67-8F80-B786A25AA343}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{9A9854E8-9378-40AA-B206-055A627671AC}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\the sims 3\support\ea help\electronic_arts_technical_support.htm | "{9B3CB2E4-3C79-4E68-B6DE-792CD91A9254}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\sleepingdogs\hkship.exe | "{9BCD949C-681D-4876-B433-3571771CA406}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\doom 3 bfg edition\doom3bfg.exe | "{9C42A1C4-0139-4616-BC22-3A73D83769DD}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\tom clancy's ghost recon future soldier\future soldier.exe | "{9C9C9134-E6FC-4EBE-BE52-8357FAEFAEA6}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\cities xl 2011\citiesxl_2011.exe | "{9DC825EB-148E-4A2C-A665-9A852CE7B337}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{9E1C6226-C48B-466D-A54B-963E8B78BCD6}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe | "{9E6B898A-A540-41F6-AE7D-73576E5AF562}" = protocol=6 | dir=in | app=c:\program files (x86)\bitcomposer games\s.t.a.l.k.e.r. - call of pripyat\bin\dedicated\xrengine.exe | "{9F6A3357-4A99-40D7-A72A-4E28DBFA27E5}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\jedi outcast\gamedata\jk2mp.exe | "{A0280690-7D98-48C0-8B2D-6DBCCB78F9CC}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\just cause\jcsetup.exe | "{A0A76E1F-4019-4842-9297-6987F06BFF94}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\batman arkham asylum goty\binaries\bmlauncher.exe | "{A1F54308-2953-415E-83C8-B8E5B324AE9E}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{A20BE125-4AFD-4AFC-8FCE-32EEACAF09C6}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\x-tension\runme.exe | "{A311A3A1-3407-4C8F-BF49-93A3E74152B0}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\railworks\railworks.exe | "{A37BEB2E-9EC0-472C-95EE-4704174B4BDA}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\magicka176\half-life\hl.exe | "{A39E6F88-EB34-4500-AE80-0518296B4126}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\jabia\jaggedalliancebia.exe | "{A3D82F24-D1A2-449F-AC1D-390F47DA1E41}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\magicka176\half-life\hl.exe | "{A43017B2-F655-45CE-BADE-C163987A45DA}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\fallout 3\fallout3.exe | "{A4F4EE6E-87B6-4B4C-B563-B2AE998D16AA}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia the sands of time\princeofpersia.exe | "{A52079AF-B592-46CC-8DE3-D25B09E6F796}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\jabia\jaggedalliancebia.exe | "{A5226264-B1BE-49DD-8A0C-2B0404690235}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | "{A61E3BF1-91F6-4852-A650-A58A83B061EE}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hitman 2 silent assassin\hitman2.exe | "{A67213EF-EBB6-4851-ABD4-CE5727D36B37}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\assassin's creed revelations\acrsp.exe | "{A6A8C694-D605-43FC-BD7F-8F3B38F33078}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dungeon siege 1\dungeonsiege.exe | "{A71C6F12-6B45-4C41-AF37-BC103D4ECA61}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hunted\binaries\win32\hunted.exe | "{A72413FD-352C-4AFE-81CA-19D3E0A3CD2E}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{A7A226E9-78AD-40DE-A6A0-EE9B144BD096}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hitman blood money\configure.exe | "{A7D9FFE6-94D1-40F6-B5CE-0A97CB760127}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hitman sniper challenge\hmsc.exe | "{A856E752-4820-4267-9140-35B8B58D46CD}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\empire total war\empire.exe | "{A889EE57-9BF6-49CE-A145-323611796FB5}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\tom clancy's ghost recon future soldier\future soldier.exe | "{A893DC1A-57BC-4CD5-9AC6-970B0BB8FAEC}" = protocol=6 | dir=in | app=c:\games\world_of_warplanes\worldofwarplanes.exe | "{A8C27824-B0AE-4D4C-A629-D3B5E886BFD0}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\medal of honor airborne\unrealengine3\binaries\moha.exe | "{A94550F3-D722-4EAD-A374-7A99F7F610D2}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars the force unleashed 2\swtfu2.exe | "{AAB92FFC-923A-49EF-AC30-EB0298B76814}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dc universe online\launchpad.exe | "{AAD48257-2D39-4380-B022-BE33943E969B}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\kings bounty crossworlds\kb.exe | "{AC25438E-B74B-47BD-8B9B-D6FB0AB8212E}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{AD15B6AF-173D-4CF3-8C1E-EFFC70EA5B9B}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\alan wake\alanwake.exe | "{AD2D26A5-CA37-4EB1-98C5-3CD1D154DBF7}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe | "{AD82787D-4B42-4278-9610-F51C21C0954B}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\wormsxhd\launcher.exe | "{AE1CB414-1683-4C11-A40B-BD2FA1D18B9F}" = protocol=6 | dir=in | app=c:\program files (x86)\ccp\eve\bin\exefile.exe | "{AEC34EF0-7B22-453D-B1EE-74AA5A991900}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\anno 2070\anno5.exe | "{AF82478E-5627-4920-80CE-C6F1943B4933}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\metro 2033\metro2033.exe | "{B07E4209-E8FC-419E-8ADD-0507DE7E01DB}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\deus ex - human revolution\dxhr.exe | "{B2D3D211-84E3-4EF5-AAA2-B43CA3853F02}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 3 - kane's wrath\support\ea help\electronic_arts_technical_support.htm | "{B2D8174C-B06E-43A1-A65C-DFBE8951663E}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe | "{B34B05B4-95E7-4602-BF39-D32437E6E121}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\tom clancy's ghost recon future soldier\future soldier.exe | "{B4199823-E381-41B1-98CC-E947D7EE84F4}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2launcher.exe | "{B47CFC6C-3DF4-43AF-8194-BBFC9D295D4B}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\postal iii\p3.exe | "{B4B75B40-7382-48AB-9508-EA9918334671}" = protocol=6 | dir=in | app=c:\program files (x86)\funcom\the secret world\clientpatcher.exe | "{B558C4F3-D88D-47D3-A291-2B65F47ED48E}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dirt 2\dirt2.exe | "{B60633FD-6F29-40A3-A737-E774DE85ECFA}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{B629522E-BDB4-4965-90FF-2A0A4872100F}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\binary domain\binarydomain.exe | "{B650749C-C923-4FAE-945F-2A47837D63CC}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\railworks\railworks.exe | "{B669FD6D-44A7-439A-92DC-73BBC151E841}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\wheelman\run_game.bat | "{B71CE41C-E00E-48FC-BC9F-8F854D7CA431}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\x3 - reunion\x3.exe | "{B816E5F3-CF30-4DCF-B6D0-E1F04CA63B24}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\postal iii\p3.exe | "{B84288EB-FE7E-4C4B-98E0-26BBB3BA8078}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe | "{B8A192BA-3FB2-4DFC-815B-B2FEEC6F21B6}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hitman sniper challenge\hmsc.exe | "{B8A8BE35-C6A1-42F3-BEAB-3CCFD36CA60E}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\king's bounty - the legend\kb.exe | "{B997F2BD-6AA3-4818-815E-62D8ADB3E9B5}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\homefront\binaries\homefront.exe | "{BA1E7CE2-ECD8-4A19-BD1B-9B028B341A61}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\stalker clear sky\bin\xrengine.exe | "{BB842FEC-0620-45C6-8587-072567FAAB53}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\magicka176\half-life\hl.exe | "{BD09B25E-3CD2-431D-9A3C-0EC16C267AE7}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\dmr.exe | "{BD91671E-85A0-44ED-B3C4-DA6AC92E51F5}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\crysis warhead\bin32\crysis.exe | "{BEB1C7F3-7732-4781-A20B-EA40832AD80F}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe | "{BEE62A15-5FE7-48A7-94CD-5BBAA46C55D8}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hacker evolution untold\hacker evolution mod editor.exe | "{BF726503-B38F-4E8B-AB96-88D9AF8CC3A8}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hitman codename 47\hitman.exe | "{C05DABF1-CB9C-4385-96A8-419567ABC756}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C10BF412-DD22-4269-AD76-A5B267EAC818}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dishonored\binaries\win32\dishonored.exe | "{C153957F-E448-4B49-9837-92A19D4012F2}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\forsaken world\patcher.exe | "{C18A2EE8-C3EE-4412-954A-2AA921743FE2}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | "{C1C25F15-6AF5-4910-9EB1-344793DDBAB8}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\crysis wars\bin32\crysis.exe | "{C335A27F-B0B0-4A6B-BD7B-8169E2E8DCFC}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\jedi outcast\gamedata\jk2sp.exe | "{C393F614-EBC8-4671-BE70-492BF640BDDE}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hunted\binaries\win32\hunted.exe | "{C43F8002-65E1-4DD4-9023-EBE8FBEEC08F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C4B84154-9834-4C94-A047-A387CA5FA72C}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star trek online\star trek online.exe | "{C4E5B2FC-3AA4-446F-BD7A-939B70C5B566}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | "{C4F62AD2-C7BE-4C39-8C8D-7FDD4D67BBE2}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\dead space 3\deadspace3.exe | "{C554D49D-A466-4ACC-A19E-CB1C6C3CF0AF}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\crysis wars\bin32\crysis.exe | "{C6BFED14-BE47-4455-845B-CDC3DE48E5A5}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\specops_theline\binaries\win32\specopstheline.exe | "{C721D6C3-A95C-45F5-BDC8-24C563292927}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\batman2\binaries\win32\batmanac.exe | "{C756D1CE-2C6A-4FB6-8D5D-ADEBC09DEB0D}" = protocol=6 | dir=in | app=c:\program files (x86)\bitcomposer games\s.t.a.l.k.e.r. - call of pripyat\bin\xrengine.exe | "{C853C729-D5D4-4005-BF89-F0BEE455CB48}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2launcher.exe | "{C8D418E1-5347-48A7-B36C-4C7B6E637CD0}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\silent hunters wolves of the pacific\sh4.exe | "{C92228BE-68C9-4DDE-8E73-AB22DBAA34FA}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe | "{C944B391-C23A-4BB6-9AF1-EC9E2238435F}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\sniper ghost warrior\sniper_x86.exe | "{CB1AA9DB-C8DB-4D48-A9F7-72D349444A48}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\alan wakes american nightmare\alan_wakes_american_nightmare.exe | "{CB4410B4-345E-40D3-859C-C8513D9A6AF0}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\batman2\runlauncher.bat | "{CBA281DE-8934-46D5-A055-F8EAB9B1BA81}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\doom 3\doom3ded.exe | "{CD3EDAE7-C0FC-4990-94D2-64F59E1B62C0}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\assassins creed\assassinscreed_game.exe | "{CDB35261-B5AD-4350-9A0D-D75C35EC9D26}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\saints row the third\saintsrowthethird.exe | "{CDBB2E16-C903-402A-AC80-A6090ED62988}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\the sims 3\support\ea help\electronic_arts_technical_support.htm | "{CE5270AC-DE42-4FB1-8731-A6ECAEEB0013}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\fear2\fear2.exe | "{CE8EC5EA-A5EF-4372-A20C-8D9CF20F1417}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect\binaries\masseffect.exe | "{CEC2D5C2-859C-46B8-893C-E230BE8682C9}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\far cry 3\bin\farcry3.exe | "{CF0C20D1-DFFC-4948-B1E9-19B09750B043}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe | "{CF123C6C-77CA-4572-ADE2-839E3F93193A}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hitman 2 silent assassin\config.exe | "{D24F516D-42A9-46A7-A54A-F1E3CC9ECC69}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\planetside 2\launchpad.exe | "{D35FC4AD-5ACE-434E-B7E4-618DCAC3F9C6}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars the clone wars\republicheroeslauncher.exe | "{D3BBA142-80A2-4CEA-951A-202C2ACB9F33}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe | "{D4E9CDD2-0A90-4650-82A6-0F5AD58B1249}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\grid\grid.exe | "{D54917BD-9285-42A3-852F-BC534A70FDEF}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars starfighter\starfighter.exe | "{D5F361C2-08A1-471A-8DF8-1D7D3E32C65C}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe | "{D607705F-C056-468A-A3B5-34F6A51885E7}" = protocol=6 | dir=in | app=c:\program files (x86)\capcom\lostplanetcolonies\lostplanetcoloniesdx10.exe | "{D688EDE5-B283-483D-859F-FDF046F4EEDF}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\batman arkham asylum goty\binaries\bmlauncher.exe | "{D6CC04A9-FFE1-4E34-9CC8-7F5502D13419}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe | "{D81EF250-5708-4F54-92CC-9E23093B7596}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\assassins creed\assassinscreed_game.exe | "{D81FA579-0912-4D3A-857E-79ECF3DAE1B1}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\resident evil operation raccoon city\raccooncity.exe | "{D85D2991-C915-4699-98C1-5197F5E48415}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dark forces\dosbox\dosbox.exe | "{D918E22E-E8E6-47D4-A2B8-127D6020DB3A}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\homefront\binaries\homefront.exe | "{D98095A4-6FDC-4468-A42C-36452FA07EC3}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\medal of honor warfighter\mohw.exe | "{D99BD79C-1381-4925-AAD8-3AFBC314D5C1}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect\masseffectlauncher.exe | "{DAB463C2-B155-43E5-B55F-E1B4587816B7}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars battlefront ii\gamedata\battlefrontii.exe | "{DC1A35D7-FAE2-4429-9335-1B4467D407F4}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\crysis warhead\bin32\crysis.exe | "{DC962AF6-1EDC-4868-8449-D07387052D27}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\fallout 3\fallout3.exe | "{DD5BA7C3-017F-4C8C-876E-2D543695D07A}" = protocol=17 | dir=in | app=e:\program files\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe | "{DD62092C-4B98-4E24-B707-CBEE7C0C8207}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia\launcher\launcher.exe | "{DD8292E9-2918-47EC-89C3-22C50B195E3F}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\jedi knight mysteries of the sith\jkm.exe | "{DDDF570A-410C-4F71-ACC5-BBD07512A9D2}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\assassinscreed3.exe | "{DE31E92F-E7B3-44C0-9F1C-283C1E1E8C1D}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe | "{DF4AFB2F-9C8A-4F1A-B3BC-3BF5B2EDD37E}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\gotham city impostors\impostors.exe | "{DFE0F1C1-3970-444F-99F4-44B32A736773}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead\left4dead.exe | "{E0095224-5F96-4789-BD58-B3E551E87E83}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 2\masseffect2launcher.exe | "{E05E993C-808C-4BC8-A179-C23EDCCE147F}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty black ops\blackops.exe | "{E0CF994B-0BEF-444C-A537-0623348E7F0A}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | "{E0DE1F38-19FA-46B5-9A95-A3575B5EC3AD}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\galaxy on fire 2 hd\gof2launcher.exe | "{E11822EF-6352-4F35-94EC-DA38BC342A07}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe | "{E1BA03AF-3B25-4F66-A5DB-FB0D194BC658}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe | "{E1E1C56B-A4FA-4F48-BDA1-F1CD11078001}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 4 tiberian twilight\support\ea help\electronic_arts_technical_support.htm | "{E207E445-49A1-4BCF-A9B3-6A6DF00D001A}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 2\binaries\masseffect2.exe | "{E2449A6C-66C1-4823-B47B-6D9068EF3AB4}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\mafia ii\pc\mafia2.exe | "{E25A02CE-3A04-4076-A0AA-A1FACF77B30F}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\arma 2\arma2.exe | "{E2841B64-DB33-481B-B6F5-D5E6FD7935F6}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\two worlds ii\twoworlds2_dx10.exe | "{E4DB74A4-83BE-4D7D-9DA7-CD6FFDBE8143}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\just cause\justcause.exe | "{E55E0353-3B40-4670-8D53-FF4CF9E96476}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars the clone wars\republicheroeslauncher.exe | "{E570DFD8-B49D-462C-B214-13702B3C54E3}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe | "{E674FA1C-BBAE-465D-8F23-C6B35E0BC9DD}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{E686A738-41D9-45DE-89EA-8CE76B4B3F2F}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\empire total war\empire.exe | "{E70F06AF-C49C-422C-8CFA-0E250E105EAC}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\doom 3\doom3.exe | "{E8D6CBAB-4A40-473A-84AB-5B491FBA28ED}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{EA0EF0EC-4E6E-4909-86D7-0F92ACDAE64F}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremoteservice.exe | "{EA5024AD-4F90-41B7-BACA-08FFEE38D3CE}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe | "{EBBEAB8B-F775-4117-80DB-2246E993CDE4}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\sleepingdogs\hkship.exe | "{EC0AF835-0F43-46BE-97D3-2BB4298AF9B1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{EC6528A2-458D-474F-9961-4DCB6104D936}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\batman arkham asylum goty\binaries\bmlauncher.exe | "{EDC6A4F1-F5C0-4197-9667-632ECAFE5061}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\wormsxhd\launcher.exe | "{EDCB73D1-24B2-4258-9C09-3B5FA944DD8D}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe | "{EDE7105F-7FD3-4031-A526-5C1CF5CD3B7B}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 3 tiberium wars\cnc3.exe | "{EDEBC216-422C-4543-A413-256B9AFDAAC1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{EE0A3FB1-D0B1-46E7-9B8B-DD3291264B30}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dark forces\dosbox\dosbox.exe | "{EE182A68-B492-4F7F-AD29-A644C36A159B}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe | "{EE256266-1BB8-4167-A9C9-4DEC627A6B86}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremoteservice.exe | "{EEE61653-9644-47FF-AA7B-EA13F5ABB1DF}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars empire at war\runme.exe | "{EEF1BF04-639E-45CB-8220-573981E7414F}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe | "{F04B6E7A-2BD9-4729-A626-B25831BCF83D}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\hacker evolution duality\hacker evolution duality.exe | "{F07C3EB5-FC57-4723-930F-42D9201B5E08}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3mp.exe | "{F143E7DF-F38B-43AF-AD69-A0D9E4C68D72}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\cities xl 2011\citiesxl_2011.exe | "{F15C8F61-F5FF-4EBC-B812-D337ADA92A85}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\saints row the third\game_launcher.exe | "{F1F57F93-7534-40A0-9E02-82780E9BA428}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe | "{F34C4C8E-26CB-4E09-B1D0-26B46FAA22F2}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\medal of honor airborne\unrealengine3\binaries\moha.exe | "{F379D869-B11F-4110-992B-03FC2A52ABAA}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hacker evolution duality\hacker evolution duality.exe | "{F3B3AFCA-296F-44A5-A771-B63F8194F52E}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\portal 2\portal2.exe | "{F3C29F88-C1B0-41A1-A82F-5D9F1DA7A57C}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dirt\dirt.exe | "{F3E42161-C6ED-4977-90DB-57E5676F1181}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dungeon siege iii\dungeon siege iii.exe | "{F49B04B6-2E7D-4742-A734-15E311BE03EB}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars empire at war\runme2.exe | "{F4F40162-7B4D-4C13-945C-6EB401D57270}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\lunar flight\lunarflight.exe | "{F4F500C2-BE91-4ADC-B3D8-DAF04E8A5785}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\forsaken world\patcher.exe | "{F5FB7B81-DCE6-4F63-A62A-CE9C7A0F0BF4}" = protocol=6 | dir=in | app=c:\program files (x86)\anno 1701\anno1701.exe | "{F66C8134-0A10-4DC3-BFEE-AB88E756D22A}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dungeon siege iii\dungeon siege iii.exe | "{F68ED6B8-26E4-4A64-B37B-44BF3D26C3E3}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{F69F3857-DB19-4A7F-94B6-64633C2683C7}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\sniper ghost warrior\sniper_x86.exe | "{F6AAF860-2AD6-4950-8608-609057654F07}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd cinema\powerdvdcinema.exe | "{F74A9EA9-D31D-40E1-9384-0487E820C63B}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\just cause 2\justcause2.exe | "{F984E775-4C59-4D75-BC43-11BC812742E3}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe | "{FA0A0948-4D14-4043-B11F-B88679B85899}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars empire at war\runme2.exe | "{FA6CD65B-568E-4446-AC71-0D638ECBC0A4}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\cities xl 2011\citiesxl_2011.exe | "{FABBEF7B-2BF2-4969-AFD0-C908D4A26A4B}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\left 4 dead\left4dead.exe | "{FB96DB58-E20E-48AD-BBCC-C87DB3CA8B18}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dragon age ultimate edition\daoriginslauncher.exe | "{FBBA73E1-4B53-4B67-AF03-3D36031DE606}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{FBD7B31D-698B-455A-9BA9-545B946662A8}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\assassinscreed3.exe | "{FC07C49F-D6C9-4C4C-9C9B-A1EEC7BB5365}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | "{FC799C28-466C-4083-B7A2-7F795275790E}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\hitman codename 47\hitman.exe | "{FC80AE2A-1656-4D60-A048-8149A2C770F3}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\command and conquer 4 tiberian twilight\cnc4.exe | "{FCDD9EF0-5AFB-4FFE-9C28-3DD4A5AFCCD8}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty black ops\blackops.exe | "{FD5FFD40-D38C-4D8D-948B-B458423AD962}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\binary domain\binarydomain.exe | "{FDBC7A71-2192-454A-91DD-BDFE33A2C8F1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{FE4FFF51-99C9-4387-BA1F-4AFE8AD78257}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dead island\deadislandgame.exe | "{FE59A130-DDAC-4D21-95CC-7C2E770E9FE9}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe | "{FE5E185B-E966-4C2D-853D-90D2095F0B0D}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dragon age ii\dragonage2launcher.exe | "{FF256B60-1F9B-4288-9517-C50994A0B0EC}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\blur\blur.exe | "{FFED22C0-B921-41FD-A331-B209736729E5}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | "TCP Query User{0954A83D-C8BB-424F-BB2A-1C80B22A6A02}C:\program files (x86)\six projects\six updater\tools\bin\rsync.exe" = protocol=6 | dir=in | app=c:\program files (x86)\six projects\six updater\tools\bin\rsync.exe | "TCP Query User{29E1B067-074D-4D07-9B6F-09342393B67B}E:\program files\steam\steamapps\common\star wars empire at war\gamedata\sweaw.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars empire at war\gamedata\sweaw.exe | "TCP Query User{2A963726-9AD8-48BC-BA1A-D8A6D9A02BE4}E:\program files\steam\steamapps\common\alien swarm\swarm.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\alien swarm\swarm.exe | "TCP Query User{2DC5A5BB-6212-4099-A68C-A09F0E84B517}E:\program files\steam\steamapps\common\planetside 2\planetside2.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\planetside 2\planetside2.exe | "TCP Query User{3316B72E-EF35-499D-A213-7CA1D96883AD}E:\program files\steam\steamapps\common\assassins creed brotherhood\acbsp.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\assassins creed brotherhood\acbsp.exe | "TCP Query User{370B7E45-8835-4ECB-89BE-CDAF75281EE7}C:\users\draco\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\draco\appdata\local\akamai\netsession_win.exe | "TCP Query User{3BE0E3A6-9C6B-48E0-91F5-6196C9E72570}E:\program files\steam\steamapps\common\dirt 3\dirt3_game.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dirt 3\dirt3_game.exe | "TCP Query User{41FA0981-B33A-443E-9602-5EEA44FF66A5}C:\users\draco\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\draco\appdata\roaming\spotify\spotify.exe | "TCP Query User{45DE586C-C373-4497-86E0-3EF0987E7599}E:\program files\steam\steamapps\magicka176\bloody good time\bgt.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\magicka176\bloody good time\bgt.exe | "TCP Query User{49C43912-683B-405C-B47D-B8E52093DA52}E:\program files\steam\steamapps\common\dead space\dead space.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dead space\dead space.exe | "TCP Query User{4A7461FE-30E2-411D-9AEA-51428E3969C7}C:\games\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | "TCP Query User{614386CB-3B93-4F8E-B592-99D20305A9F2}C:\program files (x86)\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xfire\xfire.exe | "TCP Query User{63BB87DE-02E1-4F65-AC6D-9522BBCBBE54}E:\program files\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe | "TCP Query User{64190DC8-318C-4AD9-9472-B724369CDC16}C:\games\world_of_warplanes\worldofwarplanes.exe" = protocol=6 | dir=in | app=c:\games\world_of_warplanes\worldofwarplanes.exe | "TCP Query User{65CFA57F-7005-4620-BE46-FFD252CFDD70}C:\users\draco\desktop\cryengine 3 sdk 3.4\bin64\launcher.exe" = protocol=6 | dir=in | app=c:\users\draco\desktop\cryengine 3 sdk 3.4\bin64\launcher.exe | "TCP Query User{6B140A01-CE32-4930-B70B-CA4E6FA47E41}E:\program files\steam\steamapps\common\dead island\deadislandgame.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dead island\deadislandgame.exe | "TCP Query User{6D4C7A45-297B-4B76-85BA-13F2454C07C9}E:\program files\steam\steamapps\common\dc universe online\unreal3\binaries\win32\dcgame.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dc universe online\unreal3\binaries\win32\dcgame.exe | "TCP Query User{726CBA58-89B8-483D-B5B5-C02EA3565A96}E:\program files\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2.exe | "TCP Query User{7689BE45-915B-40F3-B175-7672C5582D62}C:\program files (x86)\ccp\eve\bin\exefile.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ccp\eve\bin\exefile.exe | "TCP Query User{8C77E464-F08C-490F-B224-C31402ACAABD}E:\program files\steam\steamapps\common\far cry 2\bin\farcry2.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\far cry 2\bin\farcry2.exe | "TCP Query User{9A001E02-C7B2-4B03-9A57-F81DC45A6EFE}C:\program files (x86)\origin games\mass effect 2\binaries\masseffect2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 2\binaries\masseffect2.exe | "TCP Query User{A250A574-A5EF-4003-B703-99543CFD60B8}E:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe | "TCP Query User{AB791726-0EDE-41A9-A56F-89285FFFFF38}E:\program files\steam\steamapps\common\crysis 2\bin32\crysis2.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\crysis 2\bin32\crysis2.exe | "TCP Query User{B36A6543-9276-4486-8AF3-9D11FA685455}E:\program files\steam\steamapps\common\prince of persia forgotten sands\prince of persia.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia forgotten sands\prince of persia.exe | "TCP Query User{B3E51F87-8359-4F91-8C43-4D8FEE523D8D}C:\users\draco\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\draco\appdata\local\akamai\netsession_win.exe | "TCP Query User{B52B462F-332E-4051-AF25-D3407C6AD6DD}E:\program files\steam\steamapps\common\star wars battlefront ii\gamedata\battlefrontii.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\star wars battlefront ii\gamedata\battlefrontii.exe | "TCP Query User{B73C7770-646E-4728-976A-7AAD935B12C4}C:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe | "TCP Query User{C002445D-40D3-4332-9575-583D194FE6ED}E:\program files\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe | "TCP Query User{CF97E4E0-3675-4952-8A84-46659ACE42A3}C:\games\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | "TCP Query User{D86A901B-C476-4548-82E0-D19FB3BBBC7E}C:\users\draco\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\draco\appdata\roaming\spotify\spotify.exe | "TCP Query User{D8FCCCC5-1DC2-41EF-9125-0017CB4AFEAB}C:\program files (x86)\origin games\mass effect 2\binaries\eacoreserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 2\binaries\eacoreserver.exe | "TCP Query User{DABA8BA8-79E7-472F-98DF-D6F35EAAE412}C:\program files (x86)\origin games\need for speed(tm) most wanted\nfs13.exe" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\need for speed(tm) most wanted\nfs13.exe | "TCP Query User{DCE54A92-A0C2-48BA-8098-2069D2F00ADC}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | "TCP Query User{DF40B489-81F9-45AB-AD7E-2FEA9555BBDD}C:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe | "TCP Query User{E13C120A-FAEB-4FD6-B417-FA4E8FF8C211}E:\program files\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe | "TCP Query User{E272FFAD-F111-46C8-903D-A860074E319F}C:\program files (x86)\the witcher 2\bin\witcher2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\the witcher 2\bin\witcher2.exe | "TCP Query User{E5FF6490-D078-418B-9CE0-F0B088261DD2}E:\program files\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe | "UDP Query User{00E3E705-492C-438E-85D8-613C6CD1757E}E:\program files\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe | "UDP Query User{103995B8-7D18-446F-9E1A-C6053C8B4CCF}E:\program files\steam\steamapps\common\star wars battlefront ii\gamedata\battlefrontii.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars battlefront ii\gamedata\battlefrontii.exe | "UDP Query User{19D7A50F-6062-449E-BE2C-B402854DB4F3}E:\program files\steam\steamapps\common\dirt 3\dirt3_game.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dirt 3\dirt3_game.exe | "UDP Query User{2AD50B8A-6132-4CB0-93E1-562397549027}C:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe | "UDP Query User{2BD84AF5-A49E-416B-A18A-C7E8BEBBACF9}E:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe | "UDP Query User{30D7E996-BE38-4491-9346-C26238626553}E:\program files\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2.exe | "UDP Query User{38DDB46E-C26F-4615-B5BF-1EC9341D70F8}C:\users\draco\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\draco\appdata\local\akamai\netsession_win.exe | "UDP Query User{3A26147C-AEB6-4284-8B0C-993B1D45C29F}C:\users\draco\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\draco\appdata\roaming\spotify\spotify.exe | "UDP Query User{43157D76-B9F2-407A-82D9-59F6EBCA85C9}E:\program files\steam\steamapps\common\star wars empire at war\gamedata\sweaw.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star wars empire at war\gamedata\sweaw.exe | "UDP Query User{451D7B67-AE65-4EA9-A240-F92B6105C590}C:\program files (x86)\ccp\eve\bin\exefile.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ccp\eve\bin\exefile.exe | "UDP Query User{45413323-BBD7-4A5F-9577-F1AC5122BE96}E:\program files\steam\steamapps\common\dead island\deadislandgame.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dead island\deadislandgame.exe | "UDP Query User{497E4F62-631B-4164-B773-59759295C6EB}C:\program files (x86)\origin games\need for speed(tm) most wanted\nfs13.exe" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\need for speed(tm) most wanted\nfs13.exe | "UDP Query User{4A3261E2-FF5D-44FE-8E88-CDF6B28C0585}E:\program files\steam\steamapps\common\dead space\dead space.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dead space\dead space.exe | "UDP Query User{591D84AC-0AD7-4CBA-8F83-F70251BDFB6F}E:\program files\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe | "UDP Query User{5D068C57-EDB5-4DAB-AFF9-DF5F834CB92E}E:\program files\steam\steamapps\common\far cry 2\bin\farcry2.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\far cry 2\bin\farcry2.exe | "UDP Query User{5F5EC564-C0B4-4876-AEFB-43396EEC1958}E:\program files\steam\steamapps\common\crysis 2\bin32\crysis2.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\crysis 2\bin32\crysis2.exe | "UDP Query User{6A7C7EA3-D62B-48AB-BAC4-EA0A74269792}E:\program files\steam\steamapps\common\planetside 2\planetside2.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\planetside 2\planetside2.exe | "UDP Query User{7094C5FF-A33B-4AC0-98A2-9152CA61E696}C:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe | "UDP Query User{70E2565D-8932-430A-8BB3-C0D2905D0A7B}E:\program files\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe | "UDP Query User{7483AF6A-92EF-4D46-8656-3DC7A92402AB}C:\program files (x86)\six projects\six updater\tools\bin\rsync.exe" = protocol=17 | dir=in | app=c:\program files (x86)\six projects\six updater\tools\bin\rsync.exe | "UDP Query User{7A47E55C-539C-4177-A3F9-03D60686CC38}C:\program files (x86)\origin games\mass effect 2\binaries\eacoreserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 2\binaries\eacoreserver.exe | "UDP Query User{7E5ED55A-B5A9-44B3-A27D-E6E3A4A7E984}E:\program files\steam\steamapps\magicka176\bloody good time\bgt.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\magicka176\bloody good time\bgt.exe | "UDP Query User{973678C7-F6DF-4E6A-B1E3-A2FD66A81AFC}E:\program files\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe | "UDP Query User{A33788E4-AD24-4A7C-8530-90361FCF9236}E:\program files\steam\steamapps\common\prince of persia forgotten sands\prince of persia.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\prince of persia forgotten sands\prince of persia.exe | "UDP Query User{A4BE9A8F-373D-4895-9285-97D407BA75AC}C:\program files (x86)\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xfire\xfire.exe | "UDP Query User{B61E330C-2000-45F0-9A68-18C58CADC23E}E:\program files\steam\steamapps\common\assassins creed brotherhood\acbsp.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\assassins creed brotherhood\acbsp.exe | "UDP Query User{BEACF1B4-9A52-465F-B6CC-F3BB2AB50E45}C:\users\draco\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\draco\appdata\roaming\spotify\spotify.exe | "UDP Query User{C4C1AFF8-1673-49FF-A934-D1CDCF7B9056}C:\games\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | "UDP Query User{C6C678CB-7FC9-4BB1-961B-3740CBFC80E3}C:\games\world_of_warplanes\worldofwarplanes.exe" = protocol=17 | dir=in | app=c:\games\world_of_warplanes\worldofwarplanes.exe | "UDP Query User{DA50E369-370C-47B8-B7BE-909B5224B4BB}C:\program files (x86)\origin games\mass effect 2\binaries\masseffect2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 2\binaries\masseffect2.exe | "UDP Query User{DE30B194-7C42-454E-B7B4-9A0378A8C525}C:\games\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | "UDP Query User{E9477DA0-4373-45D8-B514-531A796344E1}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | "UDP Query User{EB6ED69C-9FC2-4605-86D0-FB57F67CF031}E:\program files\steam\steamapps\common\dc universe online\unreal3\binaries\win32\dcgame.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dc universe online\unreal3\binaries\win32\dcgame.exe | "UDP Query User{EE742119-94BF-4B69-9313-C22622A18F3F}C:\program files (x86)\the witcher 2\bin\witcher2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\the witcher 2\bin\witcher2.exe | "UDP Query User{F03E08D9-BB5D-4115-B26B-234FC87193EB}C:\users\draco\desktop\cryengine 3 sdk 3.4\bin64\launcher.exe" = protocol=17 | dir=in | app=c:\users\draco\desktop\cryengine 3 sdk 3.4\bin64\launcher.exe | "UDP Query User{F27CB184-B6FC-44FF-BA6F-96937E3228FD}C:\users\draco\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\draco\appdata\local\akamai\netsession_win.exe | "UDP Query User{FEFF9867-4887-49A9-AB06-1B087FE7F7FE}E:\program files\steam\steamapps\common\alien swarm\swarm.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\alien swarm\swarm.exe | |
03.03.2013, 21:28 | #4 |
| 2 Probleme mit Alienware M17xR3 2. Logfile - Teil 2: Code:
ATTFilter ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{09782D89-1CA6-4B7D-82C5-2DE01AF5601B}" = Microsoft SQL Server 2008 Common Files "{0ADF605D-2D94-4467-91F7-D75C71CF328D}" = Microsoft SQL Server 2008 Database Engine Shared "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{12FE6AA6-65D2-40EE-B925-62193128A0E6}" = Microsoft SQL Server 2008 Native Client "{1927E640-A2C6-4BA7-8F43-FFD2AE3DFCF3}" = Intel(R) PROSet/Wireless WiFi-Software "{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}" = Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{26A24AE4-039D-4CA4-87B4-2F86416031FF}" = Java(TM) 6 Update 31 (64-bit) "{28D06854-572C-4A65-83E5-F8CAF26B9FDC}" = Microsoft SQL Server VSS Writer "{2DF4C5DD-7417-301D-935D-939D3B7B5997}" = Microsoft Help Viewer 1.0 Language Pack - DEU "{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program "{3C983A67-DFB2-3D3D-AD9E-CA1A5A09FD18}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU "{440668AA-7524-40DB-966A-60BE535E1B3F}" = Microsoft SQL Server 2008 Database Engine Services "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup "{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.3 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0015-0407-1000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0015-0407-1000-0000000FF1CE}_Office14.PROPLUS_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0407-1000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0016-0407-1000-0000000FF1CE}_Office14.PROPLUS_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0407-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0018-0407-1000-0000000FF1CE}_Office14.PROPLUS_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0407-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-0019-0407-1000-0000000FF1CE}_Office14.PROPLUS_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0407-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001A-0407-1000-0000000FF1CE}_Office14.PROPLUS_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0407-1000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001B-0407-1000-0000000FF1CE}_Office14.PROPLUS_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUS_{70A3169E-288F-454F-A08D-20DF66639B50}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUS_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-001F-0410-1000-0000000FF1CE}_Office14.PROPLUS_{3013A793-10A7-4D1F-B8B4-2FAA82F4D259}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-002C-0407-1000-0000000FF1CE}_Office14.PROPLUS_{98782D5D-A9EE-43C6-88AD-B50AD8530E78}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010 "{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0043-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2010 "{90140000-0043-0407-1000-0000000FF1CE}_Office14.PROPLUS_{8DFD91C7-66AE-4E54-9901-5D5F401AD329}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0407-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010 "{90140000-0044-0407-1000-0000000FF1CE}_Office14.PROPLUS_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-006E-0407-1000-0000000FF1CE}_Office14.PROPLUS_{8299B64F-1537-4081-974C-033EAB8F098E}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0407-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00A1-0407-1000-0000000FF1CE}_Office14.PROPLUS_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0407-1000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010 "{90140000-00BA-0407-1000-0000000FF1CE}_Office14.PROPLUS_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst "{A140A094-942E-4F76-B8F4-850EC146170F}" = Alienware M17x Manual "{AA72DFB8-BA38-49C9-B5A4-A95FD62641F8}" = BOINC "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{ADBD6E65-46CB-4A97-9AFB-64963FEACC40}" = Microsoft SQL Server 2008 RsFx Driver "{B143BE44-8723-315E-9413-011C55873C0E}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 314.07 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 314.07 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 314.07 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.0.1 (BETA) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 314.07 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.1031 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 2.47.62 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.23.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{B9E62002-BD74-30EC-9049-93E0E003C736}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU "{C214301F-F5D7-36D9-B3A2-1467C5586495}" = Microsoft Help Viewer 1.1 Language Pack - DEU "{C3EAE456-7E7A-451F-80EF-F34C7A13C558}" = Microsoft SQL Server Compact 3.5 SP2 x64 DEU "{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared "{CD95F661-A5C4-44F5-A6AA-ECDD91C240C9}" = WinZip 16.0 "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{D8125A39-ADEE-4187-B04D-DB6CF489AF61}" = Unterstützungsdateien für Microsoft SQL Server 2008-Setup "{E5748D30-7E6D-3A8E-BFE6-C1D02C6DDABB}" = Microsoft Help Viewer 1.1 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services "{FD1AE10F-163C-4D4B-9FCE-AC667AF1DC6E}" = Alienware Command Center "CCleaner" = CCleaner "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack "Microsoft Help Viewer 1.0 Language Pack - DEU" = Microsoft Help Viewer 1.0 Language Pack - DEU "Microsoft Help Viewer 1.1" = Microsoft Help Viewer 1.1 "Microsoft Help Viewer 1.1 Language Pack - DEU" = Microsoft Help Viewer 1.1 Language Pack - DEU "Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit) "Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit) "Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) "Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU" = Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "PC-Doctor for Windows" = AlienAutopsy "ProInst" = Intel PROSet Wireless "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0125D081-30D0-4A97-82A8-C28D444B6256}" = Microsoft SQL Server Compact 3.5 SP2 DEU "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{0B7C79A5-5CB2-4ABD-A9C1-92A6213CE8DD}_is1" = MSI Kombustor 2.5.0 "{0D69462F-99CC-4F8D-942E-666E21CE59F8}" = Alienware On-Screen Display "{0DFDF745-3163-4C2F-8E6B-81CA5F297A1E}" = EasyToolz "{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime "{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = AlienRespawn "{1040143F-FEFB-4B90-8E51-E47D40E14C4E}" = Medal of Honor™ Warfighter "{1B0FBB9A-995D-47CD-87CD-13E68B676E4F}" = Mass Effect "{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1" = World of Tanks "{1EAC1D02-C6AC-4FA6-9A44-96258C37C813}_is1" = World of Warplanes "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{25F28E39-FDBB-11DB-8314-0800200C9A66}" = Medal of Honor Airborne "{26A24AE4-039D-4CA4-87B4-2F83216025F0}" = Java(TM) 6 Update 25 "{26A24AE4-039D-4CA4-87B4-2F83216034FF}" = Java(TM) 6 Update 35 "{2A0CC26E-6FC8-46FF-989D-335B7E1712E2}" = Afterfall InSanity "{2D8CED57-CCDB-4D86-9087-3BBCAE8F8F22}" = Six Updater "{2F8B731A-5F2D-3EA8-8B25-C3E5E43F4BDB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x86 "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress "{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0 "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{406FB8A4-F539-48A9-809C-F94706F9C9F6}_is1" = S.T.A.L.K.E.R. - Call Of Pripyat [v1.6.01] "{4198AE83-A3C6-4C41-85C8-EC63E990696E}" = Crysis®3 "{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4AF2248C-B3DF-46FB-9596-87F5DB193689}" = Microsoft SQL Server 2008 Browser "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace "{4D87DC92-C328-46EC-A7B4-9C88129DC696}" = Dead Space™ "{4EAE665D-957A-4D04-9679-3AD582008877}" = NVIDIA PhysX "{528145C0-462A-11E1-B8B4-B8AC6F97B88E}" = Google Earth "{534A31BD-20F4-46b0-85CE-09778379663C}" = Mass Effect™ 3 "{560985FB-4B76-4121-9189-7A2CDC7886D6}" = Kaspersky Internet Security 2013 "{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync "{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack "{5AB7D739-1735-3A9E-BE73-C43507CB4E6F}" = Microsoft Visual Studio 2010 Service Pack 1 "{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 "{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}" = GameSpy Comrade "{616C6F39-4CE1-3434-A665-2F6A04C09A7F}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3 "{67711EE7-BC7C-4FF1-BBC1-733C38D93F7E}_is1" = Windows Movie Maker 6.0.6000.16386 "{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter "{6FCFA783-CE7B-4018-AC48-0E6EEAAEA322}" = LOST PLANET COLONIES "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "{75D84EF7-0D8C-4E70-B3FA-7B42A5D4E0EB}" = Mass Effect 2 "{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™ "{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn "{7EE873AF-46BB-4B5D-BA6F-CFE4B0566E22}" = TuneUp Utilities Language Pack (de-DE) "{820B6609-4C97-3A2B-B644-573B06A0F0CC}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher "{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX "{9116E9E6-E1F9-4835-95B8-31E7F158E9F7}" = Audials "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}" = Assassin's Creed III 1.01 "{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer "{A0111B84-718C-4016-94DA-0EFC1FD65EFC}" = Aeria Ignite "{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module "{A2433A63-5F5D-40E5-B529-9123C2B3E734}" = Anno 1701 "{A29E18C2-7AB1-4b6b-848C-5D5E2C85F0C0}" = FIFA 13 "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker "{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9.6 "{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = AlienRespawn - Support Software "{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.6) MUI "{AF4D3C63-009B-4A17-B02E-D395065DD3F0}" = Dell Stage Remote "{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{C668416A-9213-4058-B7F2-01A42D85559D}" = Microsoft SQL Server System CLR Types "{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CCAC7E52-ECCE-3C4D-B1BE-BC2ACF1C1C0E}" = Microsoft Visual Basic 2010 Express - DEU "{CFCB8616-A5D1-4281-80E8-389F685BFAE2}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU "{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack "{D08A5DFE-F0C2-74FC-DD56-A3B371E9344D}" = EA Shared Game Component: Activation "{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.8 Game "{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities "{D4329609-4102-4F8C-B83F-7FE024EEA314}" = Dead Space™ 3 "{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh "{DE042823-C359-4B87-B66B-308057E8B6AF}" = Camtasia Studio 7 "{DEEB5FE3-40F5-3C5B-8F85-5306EF3C08F4}" = Microsoft Visual C++ 2010 Express - DEU "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio "{E9089B6A-1FDE-47F3-8D29-175F5B7A0722}" = Microsoft SQL Server 2008 R2 Management Objects "{EA8ADAA9-6671-4839-A51E-0C6792B78F3E}" = FIFA 12 "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter "{EFF1798F-4286-406E-B48D-BF7F6102E644}" = PunkBuster "{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{FB0127F3-985B-44CE-AE29-378CAF60B361}" = Need for Speed™ Most Wanted "{FEF06E73-A519-4510-8CF3-B66041B91D8A}" = EMSC "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Advanced Audio FX Engine" = Advanced Audio FX Engine "Aeria Ignite 1.6.1062" = Aeria Ignite "Afterburner" = MSI Afterburner 2.3.1 "ArtMoney PRO_is1" = ArtMoney PRO v7.39.3 "ArtMoney SE_is1" = ArtMoney SE v7.40.2 "Battlelog Web Plugins" = Battlelog Web Plugins "BattlEye for OA" = BattlEye for OA Uninstall "BitTorrent" = BitTorrent "Bridge Constructor_is1" = Bridge Constructor v1.2 "Cheat Engine 5.6_is1" = Cheat Engine 5.6 "com.ea.Activation.919CACB699904AC5D41B606703500DD39747C02D.1" = EA Shared Game Component: Activation "Desura" = Desura "Desura_72481868087328" = Desura: Alien Shooter "Desura_80590766342176" = Desura: 2012 "Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2) "DFHEXEditor 1.1_is1" = DF HEXEditor 1.1 "ESN Sonar-0.70.4" = ESN Sonar "EVE" = [translation missing: EVERemoveOnly] "FormatFactory" = FormatFactory 2.50 "Fraps" = Fraps (remove only) "FUSSBALL MANAGER 12" = FUSSBALL MANAGER 12 "HD Tune_is1" = HD Tune 2.55 "HyperCam 3" = HyperCam 3 "InstallShield_{0D69462F-99CC-4F8D-942E-666E21CE59F8}" = Alienware On-Screen Display "InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "InstallShield_{A140A094-942E-4F76-B8F4-850EC146170F}" = Alienware M17x Manual "InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9.6 "InstallShield_{FD1AE10F-163C-4D4B-9FCE-AC667AF1DC6E}" = Alienware Command Center "InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}" = Kaspersky Internet Security 2013 "Integrated Webcam Live! Central" = Integrated Webcam Live! Central "Internet Manager" = Internet Manager "IsoBuster_is1" = IsoBuster 3.1 "MegaTrainer eXperience_is1" = MegaTrainer eXperience V1.1.2.6c "Microsoft Visual Basic 2010 Express - DEU" = Microsoft Visual Basic 2010 Express - DEU "Microsoft Visual C++ 2010 Express - DEU" = Microsoft Visual C++ 2010 Express - DEU "Microsoft Visual Studio 2010 Service Pack 1" = Microsoft Visual Studio 2010 Service Pack 1 "Mozilla Firefox 15.0.1 (x86 de)" = Mozilla Firefox 15.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Nostradamus - Die letzte Prophezeiung_is1" = Nostradamus - Die letzte Prophezeiung "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "OpenAL" = OpenAL "Origin" = Origin "Pathologic_is1" = Pathologic "PC Wizard 2010_is1" = PC Wizard 2010.1.94 "ProjectZomboid" = Project Zomboid (remove only) "ProtectDisc Driver 11" = ProtectDisc Driver, Version 11 "PunkBusterSvc" = PunkBuster Services "Secrets of Da Vinci" = Secrets of Da Vinci "Steam App 10220" = Postal 3 "Steam App 10500" = Empire: Total War "Steam App 108800" = Crysis 2 Maximum Edition "Steam App 113420" = Fallen Earth "Steam App 11440" = DiRT "Steam App 115320" = PROTOTYPE 2 "Steam App 12750" = GRID "Steam App 12840" = DiRT 2 "Steam App 15320" = IL-2 Sturmovik: 1946 "Steam App 201760" = Cities XL 2012 "Steam App 202170" = Sleeping Dogs™ "Steam App 202750" = Alan Wake's American Nightmare "Steam App 203140" = Hitman: Absolution "Steam App 203750" = Binary Domain "Steam App 203810" = Dear Esther "Steam App 205100" = Dishonored "Steam App 205930" = Hitman: Sniper Challenge "Steam App 207610" = The Walking Dead "Steam App 208200" = DOOM 3: BFG Edition "Steam App 208600" = Lunar Flight "Steam App 209100" = Resident Evil™: Operation Raccoon City "Steam App 209870" = Blacklight: Retribution "Steam App 212010" = Galaxy on Fire 2™ Full HD "Steam App 212630" = Tom Clancy's Ghost Recon Future Soldier "Steam App 218" = Source SDK Base 2007 "Steam App 218230" = PlanetSide 2 "Steam App 218640" = Lucius "Steam App 219540" = ARMA 2: Operation Arrowhead Beta "Steam App 220240" = Far Cry® 3 "Steam App 226470" = Far Cry 3 - Map Editor "Steam App 227300" = Euro Truck Simulator 2 "Steam App 24010" = Train Simulator 2012 "Steam App 24200" = DC Universe Online "Steam App 2450" = Bloody Good Time "Steam App 25900" = King's Bounty: The Legend "Steam App 3170" = King's Bounty: Armored Princess "Steam App 32350" = Star Wars Starfighter "Steam App 32370" = Star Wars: Knights of the Old Republic "Steam App 32380" = Star Wars Jedi Knight: Dark Forces II "Steam App 32390" = Star Wars - Jedi Knight: Mysteries of the Sith "Steam App 32400" = Star Wars: Dark Forces "Steam App 32420" = Star Wars The Clone Wars: Republic Heroes "Steam App 32430" = Star Wars: The Force Unleashed "Steam App 32470" = Star Wars: Empire at War Gold "Steam App 32500" = Star Wars: The Force Unleashed II "Steam App 33905" = ARMA 2 Dedicated Server "Steam App 33910" = ARMA 2 "Steam App 33930" = ARMA 2: Operation Arrowhead "Steam App 35140" = Batman: Arkham Asylum GOTY Edition "Steam App 44320" = DiRT 3 "Steam App 47700" = Command and Conquer 4: Tiberian Twilight "Steam App 49520" = Borderlands 2 "Steam App 50300" = Spec Ops: The Line "Steam App 55230" = Saints Row: The Third "Steam App 57400" = Batman: Arkham City™ "Steam App 57900" = Duke Nukem Forever "Steam App 6000" = Star Wars Republic Commando "Steam App 6020" = Star Wars Jedi Knight: Jedi Academy "Steam App 6030" = Star Wars - Jedi Knight II: Jedi Outcast "Steam App 6060" = Star Wars - Battlefront II "Steam App 630" = Alien Swarm "Steam App 63380" = Sniper Elite V2 "Steam App 63910" = King's Bounty: Crossworlds "Steam App 6850" = Hitman 2: Silent Assassin "Steam App 6860" = Hitman: Blood Money "Steam App 6880" = Just Cause "Steam App 6900" = Hitman: Codename 47 "Steam App 70120" = Hacker Evolution Duality "Steam App 71270" = Football Manager 2012 "Steam App 8190" = Just Cause 2 "Steam App 8980" = Borderlands "Steam App 9050" = DOOM 3 "The Secret World_is1" = The Secret World "The Witcher 2 Enhanced Edition_is1" = The Witcher 2 Enhanced Edition Version 3.0 "theHunter" = theHunter (remove only) "Tobit Radio.fx Server" = Radio.fx "TuneUp Utilities" = TuneUp Utilities "Uplay" = Uplay "VLC media player" = VLC media player 0.9.4 "WavePad" = WavePad Audiobearbeitungs-Software "WinGimp-2.0_is1" = GIMP 2.6.11 "WinLiveSuite_Wave3" = Windows Live Essentials "World of Warcraft" = World of Warcraft "Xfire" = Xfire (remove only) "XfireXO Toolbar" = XfireXO Toolbar ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1503614190-581956262-4018303520-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{79A765E1-C399-405B-85AF-466F52E918B0}" = Avira SearchFree Toolbar plus Web Protection Updater "9204f5692a8faf3b" = Dell System Detect "Akamai" = Akamai NetSession Interface "Google Chrome" = Google Chrome "Mozilla Firefox 16.0.1 (x86 de)" = Mozilla Firefox 16.0.1 (x86 de) "MyFreeCodec" = MyFreeCodec "Spotify" = Spotify "TeamSpeak 3 Client" = TeamSpeak 3 Client ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1503614190-581956262-4018303520-1019\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface "Google Chrome" = Google Chrome ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1503614190-581956262-4018303520-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface "Google Chrome" = Google Chrome ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 02.03.2013 13:49:16 | Computer Name = Draco-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error - 02.03.2013 13:49:16 | Computer Name = Draco-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error - 02.03.2013 13:49:16 | Computer Name = Draco-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error - 02.03.2013 13:49:16 | Computer Name = Draco-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error - 03.03.2013 05:41:35 | Computer Name = Draco-PC | Source = WinMgmt | ID = 10 Description = Error - 03.03.2013 06:38:13 | Computer Name = Draco-PC | Source = WinMgmt | ID = 10 Description = Error - 03.03.2013 06:50:31 | Computer Name = Draco-PC | Source = WinMgmt | ID = 10 Description = Error - 03.03.2013 07:36:43 | Computer Name = Draco-PC | Source = WinMgmt | ID = 4 Description = Error - 03.03.2013 08:25:11 | Computer Name = Draco-PC | Source = SideBySide | ID = 16842787 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" in Zeile 8. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error - 03.03.2013 08:26:28 | Computer Name = Draco-PC | Source = SideBySide | ID = 16842787 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" in Zeile 8. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error - 03.03.2013 08:26:29 | Computer Name = Draco-PC | Source = SideBySide | ID = 16842787 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" in Zeile 8. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. [ FxaaToolError Events ] Error - 31.01.2013 14:39:59 | Computer Name = Draco-PC | Source = FxaaToolError | ID = 0 Description = System.IO.DirectoryNotFoundException: Ein Teil des Pfades "E:\Program Files\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\injFX_Settings\injFxaaTemp.tmp" konnte nicht gefunden werden. bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy, Boolean useLongPath) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) bei System.IO.StreamWriter.CreateFile(String path, Boolean append) bei System.IO.StreamWriter..ctor(String path, Boolean append, Encoding encoding, Int32 bufferSize) bei System.IO.StreamWriter..ctor(String path) bei FXAA_Tool.FxaaWriter.WriteFxaaSettings() [ System Events ] Error - 03.03.2013 07:26:22 | Computer Name = Draco-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 03.03.2013 07:29:07 | Computer Name = Draco-PC | Source = Service Control Manager | ID = 7022 Description = Der Dienst "Gemeinsame Nutzung der Internetverbindung" wurde nicht richtig gestartet. Error - 03.03.2013 07:54:12 | Computer Name = Draco-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Art*Money*Pro7.39.3" wurde aufgrund folgenden Fehlers nicht gestartet: %%577 Error - 03.03.2013 07:54:28 | Computer Name = Draco-PC | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Error - 03.03.2013 07:54:28 | Computer Name = Draco-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 03.03.2013 08:05:27 | Computer Name = Draco-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am ?03.?03.?2013 um 13:03:49 unerwartet heruntergefahren. Error - 03.03.2013 08:07:57 | Computer Name = Draco-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Art*Money*Pro7.39.3" wurde aufgrund folgenden Fehlers nicht gestartet: %%577 Error - 03.03.2013 08:08:16 | Computer Name = Draco-PC | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Error - 03.03.2013 08:08:16 | Computer Name = Draco-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 03.03.2013 08:11:00 | Computer Name = Draco-PC | Source = Service Control Manager | ID = 7022 Description = Der Dienst "Gemeinsame Nutzung der Internetverbindung" wurde nicht richtig gestartet. < End of report > Prozessor: Intel Core i7 2860QM Arbeitsspeicher:8 GB Grafikkarte: NVIDIA Geforce GTX 580M Beetriebssystem: Windows 7 Ultimate Edition 64-Bit SP1 |
06.03.2013, 19:58 | #5 |
| 2 Probleme mit Alienware M17xR3 Keiner Ratschläge, wie ich die Probleme lösen kann? Hab grad herausgefunden, dass ich in den abgesicherten Modus starten kann, ohne das ich das Problem mit dem schwarzen BIldschirm nach dem anmelden habe. |
Themen zu 2 Probleme mit Alienware M17xR3 |
acrobat update, adobe, alienware, avira, avira searchfree toolbar, bho, bildschirm, black, computer, desktop, device driver, ebanking, explorer, festplatte, flash player, google, grafikkarte, hijack, hijackthis, internet, internet explorer, internet security 2013, kaspersky, kaspersky internet security 2013, mozilla, nvidia, nvidia update, plug-in, registry, schwarzer bildschirm, security, senden, software, spielen, spotify web helper, system, tastatur |