| Taskmanager Spinnt Virus... Hi
Mein kleiner Bruder hat irgent nen scheiß aus youtube gedownloadet was zu 100% virus ist und jetzt spinnt der Taskmanager
Er schliest und öffnet alle Dienste sowie Task andauernd...
Pc Funktioniert soweit aber irgentwas läuft das nicht richtig...
Hab die datei durch Virustotal laufen lassen seht selbst:
https://www.virustotal.com/de/file/fd8907d80d19821cd14d90e0c4fddb53699201628a6a113de5f5db0a167b59b4/analysis/1362480266/ Kennt das jemand oder kann abhilfe schaffen?!
Muss ich erstmal aufpassen wo ich mich einlogge Bank etc.?! gmer Ging nicht der Stützt ab nach ca. 5 min, gmer_2.1.19155.exe Funktioniert nicht mehr
OTL Zitat:
OTL logfile created on: 05.03.2013 12:57:53 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rene\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,53 Gb Available Physical Memory | 63,37% Memory free
8,00 Gb Paging File | 6,68 Gb Available in Paging File | 83,55% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 37,27 Gb Total Space | 2,90 Gb Free Space | 7,77% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 33,94 Gb Free Space | 7,29% Space Free | Partition Type: NTFS
Drive F: | 3,71 Gb Total Space | 3,71 Gb Free Space | 99,85% Space Free | Partition Type: FAT32
Computer Name: RENE-PC | User Name: Rene | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ==========
PRC - [2013.03.05 12:49:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Rene\Desktop\OTL.exe
PRC - [2013.02.10 04:25:27 | 001,266,464 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013.02.09 18:43:48 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2013.01.20 04:10:06 | 006,039,600 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
PRC - [2012.11.26 22:45:33 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012.11.19 17:25:32 | 002,598,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2012.09.23 20:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.02.14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2009.06.10 22:22:50 | 000,032,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe ========== Modules (No Company Name) ========== ========== Services (SafeList) ==========
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2013.02.27 16:13:51 | 000,251,248 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.02.10 04:25:27 | 001,266,464 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013.02.09 18:43:48 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2013.01.08 12:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.11.26 22:45:33 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012.11.02 03:51:18 | 005,174,392 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2012.10.01 20:34:38 | 005,132,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2012.10.01 20:34:38 | 000,178,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose64)
SRV - [2012.09.23 20:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.02.14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.12.19 06:41:52 | 000,194,488 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2012.12.10 03:28:34 | 000,127,328 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2012.11.08 03:49:24 | 000,307,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2012.08.24 15:43:16 | 000,384,352 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2012.04.19 04:50:26 | 000,028,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2012.03.01 07:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.31 04:46:48 | 000,036,944 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2011.12.23 13:32:14 | 000,047,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2011.12.23 13:32:04 | 000,029,776 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avgidsfiltera.sys -- (AVGIDSFilter)
DRV:64bit: - [2010.11.09 15:35:24 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Users\Rene\AppData\LocalLow\CT2625848\ldrtbDVDV.dll ()
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&userid=EB_USER_ID&ctid=CT2625848&SSPV=TB_IESB25
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 5E 32 78 3F E8 CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Users\Rene\AppData\LocalLow\CT2625848\ldrtbDVDV.dll ()
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{F2D8531B-F712-4FF5-A035-1667E3A140A4}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848&CUI=UN40040751181637529&SSPV=TB_IESB25
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Rene\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2013.03.05 12:54:11 | 000,000,000 | ---D | M]
[2012.10.01 20:43:54 | 000,034,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll ========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{googleriginalQueryForSuggestion}{google:assistedQueryStats}{google:se archFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParam eter}
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\pdf.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U9 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.90.5 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - Extension: YouTube = C:\Users\Rene\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google-Suche = C:\Users\Rene\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: DVDVideoSoft Browser Extension = C:\Users\Rene\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\
CHR - Extension: Google Mail = C:\Users\Rene\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Programme\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (DVDVideoSoftTB_DE Toolbar) - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Users\Rene\AppData\LocalLow\CT2625848\ldrtbDVDV.dll ()
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB_DE Toolbar) - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Users\Rene\AppData\LocalLow\CT2625848\ldrtbDVDV.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB_DE Toolbar) - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - C:\Users\Rene\AppData\LocalLow\CT2625848\ldrtbDVDV.dll ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKCU..\Run: [BitTorrent] C:\Program Files (x86)\BitTorrent\BitTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [explorer.exe] C:\Users\Rene\AppData\Roaming\explorer.exe (Krzysztof Kowalczyk)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Rene\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Rene\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office15\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Rene\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office15\EXCEL.EXE (Microsoft Corporation)
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Lync: Anruf per Mausklick - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Lync: Anruf per Mausklick - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {CB927D12-4FF7-4A9E-A169-56E4B8A75598} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Element Behavior)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AEC751E4-83B6-49D4-8E67-48CC69D6977B}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Programme\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml {807583E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012.12.10 19:26:11 | 000,000,000 | ---D | M] - D:\Auto -- [ NTFS ]
O33 - MountPoints2\{abd422c2-542d-11e2-b1d9-90fba63850e9}\Shell - "" = AutoRun
O33 - MountPoints2\{abd422c2-542d-11e2-b1d9-90fba63850e9}\Shell\AutoRun\command - "" = F:\CMADownloader.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ==========
[2013.03.05 12:57:02 | 000,000,000 | ---D | C] -- C:\Users\Rene\AppData\Roaming\AVG2012
[2013.03.05 12:55:48 | 000,000,000 | ---D | C] -- C:\Users\Rene\AppData\Roaming\TuneUp Software
[2013.03.05 12:55:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013.03.05 12:55:47 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\AVG
[2013.03.05 12:54:00 | 000,000,000 | -H-D | C] -- C:\$AVG
[2013.03.05 12:53:59 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012
[2013.03.05 12:53:59 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\AVG
[2013.03.05 12:51:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2013.03.05 12:48:52 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Rene\Desktop\OTL.exe
[2013.03.05 12:07:28 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2013.03.05 12:07:28 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2013.03.05 11:50:11 | 000,000,000 | ---D | C] -- C:\Users\Rene\AppData\Roaming\dclogs
[2013.03.05 11:50:10 | 000,861,184 | ---- | C] (Krzysztof Kowalczyk) -- C:\Users\Rene\AppData\Roaming\explorer.exe
[2013.03.04 18:44:27 | 000,000,000 | ---D | C] -- C:\Users\Rene\Documents\Raiderz
[2013.03.02 13:36:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2
[2013.03.02 13:35:35 | 000,000,000 | ---D | C] -- C:\Users\Rene\Documents\Guild Wars 2
[2013.02.28 13:29:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reFX
[2013.02.28 13:29:00 | 001,332,224 | ---- | C] (AD © 2009) -- C:\Windows\SysWow64\SYNSOEMU.DLL
[2013.02.28 13:29:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Digidesign
[2013.02.28 13:22:35 | 000,000,000 | ---D | C] -- C:\Users\Rene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
[2013.02.28 13:22:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ASIO4ALL v2
[2013.02.28 13:22:25 | 000,225,280 | ---- | C] (Propellerhead Software AB) -- C:\Windows\SysWow64\rewire.dll
[2013.02.28 13:22:17 | 000,000,000 | ---D | C] -- C:\Users\Rene\Documents\Image-Line
[2013.02.28 13:22:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Image-Line
[2013.02.28 13:22:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
[2013.02.28 13:22:05 | 000,000,000 | ---D | C] -- C:\Users\Rene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
[2013.02.28 13:21:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Outsim
[2013.02.28 13:08:54 | 000,000,000 | ---D | C] -- C:\Users\Rene\AppData\Roaming\FileZilla
[2013.02.28 13:08:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2013.02.28 13:08:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla FTP Client
[2013.02.20 19:49:26 | 000,051,972 | ---- | C] (Blizzard Entertainment) -- C:\Users\Rene\Desktop\Scan.dll
[2013.02.20 19:49:12 | 000,000,000 | ---D | C] -- C:\Users\Rene\Desktop\Cache
[2013.02.20 19:44:55 | 000,000,000 | ---D | C] -- C:\Users\Rene\Desktop\Logs
[2013.02.19 10:17:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2013.02.19 10:10:50 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2013.02.18 18:10:45 | 000,000,000 | ---D | C] -- C:\Users\Rene\Desktop\Neuer Ordner
[2013.02.17 18:18:01 | 000,000,000 | ---D | C] -- C:\Users\Rene\Desktop\Hurensohn
[2013.02.13 19:02:11 | 000,000,000 | ---D | C] -- C:\Users\Rene\AppData\Local\PMB Files
[2013.02.13 19:02:10 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2013.02.13 19:01:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
[2013.02.13 19:01:49 | 000,000,000 | ---D | C] -- C:\Users\Rene\.swt
[2013.02.12 17:24:08 | 000,000,000 | ---D | C] -- C:\Users\Rene\AppData\Roaming\TeamViewer
[2013.02.12 16:14:34 | 000,000,000 | ---D | C] -- C:\Users\Rene\Documents\Benutzerdefinierte Office-Vorlagen
[2013.02.08 21:26:43 | 000,000,000 | ---D | C] -- C:\Users\Rene\AppData\Roaming\LolClient
[2013.02.05 23:02:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games ========== Files - Modified Within 30 Days ==========
[2013.03.05 12:55:48 | 000,000,981 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk
[2013.03.05 12:55:47 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2013.03.05 12:55:47 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2013.03.05 12:54:38 | 000,642,720 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2013.03.05 12:54:28 | 000,377,856 | ---- | M] () -- C:\Users\Rene\Desktop\gmer_2.1.19155.exe
[2013.03.05 12:49:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Rene\Desktop\OTL.exe
[2013.03.05 12:46:03 | 000,000,000 | ---- | M] () -- C:\Users\Rene\defogger_reenable
[2013.03.05 12:44:53 | 000,050,477 | ---- | M] () -- C:\Users\Rene\Desktop\Defogger.exe
[2013.03.05 12:29:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.03.05 12:26:29 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.03.05 12:26:29 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.03.05 12:18:05 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-121225185-1033156058-1426507469-1000UA.job
[2013.03.05 12:13:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.03.05 12:08:36 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.03.05 12:08:36 | 000,653,928 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.03.05 12:08:36 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.03.05 12:08:36 | 000,129,800 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.03.05 12:08:36 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.03.05 11:52:13 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.03.05 11:51:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.03.05 11:51:26 | 3220,627,456 | -HS- | M] () -- C:\hiberfil.sys
[2013.03.05 10:27:07 | 000,207,134 | ---- | M] () -- C:\Users\Rene\Desktop\bhop.exe
[2013.03.04 22:35:34 | 000,001,191 | ---- | M] () -- C:\Users\Rene\Desktop\Raiderz Launcher - Verknüpfung.lnk
[2013.03.04 15:18:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-121225185-1033156058-1426507469-1000Core.job
[2013.03.04 12:40:05 | 000,220,861 | ---- | M] () -- C:\Users\Rene\Desktop\ALICE VERTRAG.png
[2013.03.03 20:44:12 | 000,790,865 | ---- | M] () -- C:\Users\Rene\Desktop\1362114633783.gif
[2013.03.02 13:36:33 | 000,000,678 | ---- | M] () -- C:\Users\Public\Desktop\Guild Wars 2.lnk
[2013.02.28 18:52:44 | 000,574,160 | ---- | M] () -- C:\Users\Rene\ts3_recording_13_02_28_18_52_38.wav
[2013.02.28 18:04:03 | 000,969,394 | ---- | M] () -- C:\Users\Rene\Desktop\Unbenannt.png
[2013.02.28 16:51:31 | 012,487,760 | ---- | M] () -- C:\ts3_recording_13_02_28_16_50_23.wav
[2013.02.28 13:22:35 | 000,001,138 | ---- | M] () -- C:\Users\Rene\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2013.02.28 13:22:24 | 000,000,872 | ---- | M] () -- C:\Users\Public\Desktop\FL Studio 10.lnk
[2013.02.28 13:08:52 | 000,002,000 | ---- | M] () -- C:\Users\Public\Desktop\FileZilla Client.lnk
[2013.02.20 19:56:48 | 000,000,253 | ---- | M] () -- C:\Users\Rene\Desktop\WoW.mfil
[2013.02.20 19:49:26 | 000,051,972 | ---- | M] (Blizzard Entertainment) -- C:\Users\Rene\Desktop\Scan.dll
[2013.02.13 19:03:34 | 000,000,642 | ---- | M] () -- C:\Users\Rene\Desktop\Resume Download of Blacklight Retribution.url
[2013.02.13 16:40:49 | 000,767,145 | ---- | M] () -- C:\Users\Rene\Desktop\worldedit-5.5.1.zip
[2013.02.12 19:13:53 | 000,000,553 | ---- | M] () -- C:\Users\Rene\Desktop\server.properties
[2013.02.10 04:25:27 | 000,017,738 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
[2013.02.08 23:57:33 | 000,861,184 | ---- | M] (Krzysztof Kowalczyk) -- C:\Users\Rene\AppData\Roaming\explorer.exe
[2013.02.06 00:36:30 | 000,021,575 | ---- | M] () -- C:\Users\Rene\Desktop\1178638.jpg
[2013.02.05 23:05:30 | 000,001,024 | ---- | M] () -- C:\Users\Public\Desktop\League of Legends spielen .lnk ========== Files Created - No Company Name ==========
[2013.03.05 12:55:48 | 000,000,981 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk
[2013.03.05 12:55:47 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2013.03.05 12:55:47 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2013.03.05 12:54:28 | 000,377,856 | ---- | C] () -- C:\Users\Rene\Desktop\gmer_2.1.19155.exe
[2013.03.05 12:46:03 | 000,000,000 | ---- | C] () -- C:\Users\Rene\defogger_reenable
[2013.03.05 12:44:53 | 000,050,477 | ---- | C] () -- C:\Users\Rene\Desktop\Defogger.exe
[2013.03.05 10:26:59 | 000,207,134 | ---- | C] () -- C:\Users\Rene\Desktop\bhop.exe
[2013.03.04 22:35:34 | 000,001,191 | ---- | C] () -- C:\Users\Rene\Desktop\Raiderz Launcher - Verknüpfung.lnk
[2013.03.04 12:40:04 | 000,220,861 | ---- | C] () -- C:\Users\Rene\Desktop\ALICE VERTRAG.png
[2013.03.03 20:44:12 | 000,790,865 | ---- | C] () -- C:\Users\Rene\Desktop\1362114633783.gif
[2013.03.02 13:36:33 | 000,000,678 | ---- | C] () -- C:\Users\Public\Desktop\Guild Wars 2.lnk
[2013.02.28 18:52:39 | 000,574,160 | ---- | C] () -- C:\Users\Rene\ts3_recording_13_02_28_18_52_38.wav
[2013.02.28 18:04:02 | 000,969,394 | ---- | C] () -- C:\Users\Rene\Desktop\Unbenannt.png
[2013.02.28 16:50:25 | 012,487,760 | ---- | C] () -- C:\ts3_recording_13_02_28_16_50_23.wav
[2013.02.28 13:22:35 | 000,001,138 | ---- | C] () -- C:\Users\Rene\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2013.02.28 13:22:24 | 000,000,872 | ---- | C] () -- C:\Users\Public\Desktop\FL Studio 10.lnk
[2013.02.28 13:08:52 | 000,002,000 | ---- | C] () -- C:\Users\Public\Desktop\FileZilla Client.lnk
[2013.02.19 10:12:25 | 000,017,738 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2013.02.13 19:03:34 | 000,000,642 | ---- | C] () -- C:\Users\Rene\Desktop\Resume Download of Blacklight Retribution.url
[2013.02.06 00:36:30 | 000,021,575 | ---- | C] () -- C:\Users\Rene\Desktop\1178638.jpg
[2013.02.05 23:05:30 | 000,001,024 | ---- | C] () -- C:\Users\Public\Desktop\League of Legends spielen .lnk
[2012.12.23 16:57:21 | 000,004,505 | ---- | C] () -- C:\Windows\SysWow64\drivers\tihid.sys
[2012.12.23 16:57:20 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\Tipage.dll
[2012.12.14 16:13:25 | 000,000,025 | ---- | C] () -- C:\Windows\AutoOC.ini
[2012.11.26 22:29:37 | 000,281,520 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.11.26 22:29:35 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.11.26 18:22:29 | 000,007,607 | ---- | C] () -- C:\Users\Rene\AppData\Local\Resmon.ResmonCfg
[2012.09.28 16:45:06 | 000,247,296 | ---- | C] () -- C:\Windows\SysWow64\rtvcvfw32.dll ========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:30:56 | 014,165,504 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ==========
[2013.02.21 17:19:16 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\.minecraft
[2013.03.05 12:57:02 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\AVG2012
[2013.03.05 12:25:58 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\BitTorrent
[2013.03.05 11:53:38 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\dclogs
[2013.01.13 17:58:11 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\DVDVideoSoft
[2013.01.13 17:53:59 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\DVDVideoSoftIEHelpers
[2013.03.04 21:17:31 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\FileZilla
[2013.02.08 21:26:43 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\LolClient
[2013.02.11 19:18:17 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\Mumble
[2012.11.25 18:24:34 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\Opera
[2012.12.15 11:38:27 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\Origin
[2013.02.12 17:33:30 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\TeamViewer
[2013.03.05 12:50:24 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\TS3Client
[2013.03.05 12:55:48 | 000,000,000 | ---D | M] -- C:\Users\Rene\AppData\Roaming\TuneUp Software ========== Purity Check ==========
< End of report >
| Extras Zitat:
OTL Extras logfile created on: 05.03.2013 12:57:53 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rene\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,53 Gb Available Physical Memory | 63,37% Memory free
8,00 Gb Paging File | 6,68 Gb Available in Paging File | 83,55% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 37,27 Gb Total Space | 2,90 Gb Free Space | 7,77% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 33,94 Gb Free Space | 7,29% Space Free | Partition Type: NTFS
Drive F: | 3,71 Gb Total Space | 3,71 Gb Free Space | 99,85% Space Free | Partition Type: FAT32
Computer Name: RENE-PC | User Name: Rene | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0BEAB4BA-E75A-45CA-BAB5-4E27A4CD3C72}" = lport=138 | protocol=17 | dir=in | app=system |
"{1BC0F20F-E4F5-4137-9DB4-11DE292242A9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1E9A48ED-4312-4308-B498-805462AC51D0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{24349518-A916-4011-9BD2-7332AF1D64A7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2597D192-B098-4B9A-836B-49588B24497F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3B6EBA28-7154-4551-BB16-09167A6DF0F1}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4239EB0C-E921-43E6-9186-AA05736F1EF9}" = lport=10243 | protocol=6 | dir=in | app=system |
"{532C541A-B7A8-4571-BF77-EC689ACBC99C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{549C1C3F-060D-423E-A992-CBC4903958EF}" = lport=56231 | protocol=17 | dir=in | name=pando media booster |
"{59772F7F-DBC9-4916-9533-9D12EA055627}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{616525C8-7669-4465-85B1-E5A7DB175AF3}" = lport=56231 | protocol=6 | dir=in | name=pando media booster |
"{69B56736-66E4-46B2-AF80-A95ACFC877A7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{89A0AC92-4CC7-4B1C-BE65-FAC30EB41661}" = rport=10243 | protocol=6 | dir=out | app=system |
"{89E534F1-1BB5-463B-B914-17FDC22F6F57}" = rport=139 | protocol=6 | dir=out | app=system |
"{8AD7C6F5-29F3-4C81-A9DD-C429E2603BAA}" = lport=445 | protocol=6 | dir=in | app=system |
"{972F1AA6-ED3B-4F1D-A388-15BE0F732248}" = lport=137 | protocol=17 | dir=in | app=system |
"{A2919452-96A3-44E4-870B-3BC0FCF2C63B}" = rport=445 | protocol=6 | dir=out | app=system |
"{A341412B-19AC-4A0D-8637-E794D2052719}" = rport=137 | protocol=17 | dir=out | app=system |
"{A8C617BF-56B9-499F-B604-9CBCB6FE2C9A}" = lport=56231 | protocol=17 | dir=in | name=pando media booster |
"{A9F08CA2-3570-48C9-9B04-C520832EDB68}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe |
"{AB6CC1BE-4747-417A-AAA0-7EE7ED36ADCE}" = rport=138 | protocol=17 | dir=out | app=system |
"{B1E009D3-EBB4-4A48-8A8B-805A9D43E891}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C5869867-813D-4C2B-B66C-B2E4BFC1E4C6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D0981C0C-6AB8-451F-BE9B-FDBEC50ADEF6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D36E9B2F-09B3-4EE5-B83C-F6FF75D32F00}" = lport=139 | protocol=6 | dir=in | app=system |
"{E4E1F892-0028-46CB-A596-1130315B9B2A}" = lport=56231 | protocol=6 | dir=in | name=pando media booster | ========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00A60248-F891-4EF5-8F03-2DBB1CB6F3EB}" = protocol=17 | dir=in | app=d:\games_apps\steam\steamapps\common\orcs must die 2\build\release\orcsmustdie2.exe |
"{0C8AC602-B94D-4AAF-987C-5340D9BB77D6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0D27F5D4-B8AC-4217-A10D-78C7FB68542A}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{15E187D9-82B5-4985-8320-995E781FE6A6}" = protocol=6 | dir=in | app=d:\games_apps\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{18A9CC93-3F77-4282-8A3A-891845DE97C2}" = protocol=17 | dir=in | app=d:\games_apps\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{194E3A31-DA60-4822-B787-9C722F06FAD2}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{210776BD-29F1-4104-A165-C90C090C2F01}" = protocol=17 | dir=in | app=d:\games_apps\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{276F0CD6-9138-4F3A-B7BE-01D4EC5DE582}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{29838947-1818-40BB-8E06-83F6EE449ACD}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{2B56AC63-8230-48A1-82BA-17486974EABF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{304062DC-98E0-4CBB-86A5-408E21C568D0}" = protocol=17 | dir=in | app=d:\games_apps\steam\steamapps\common\bullet run\launchpad.exe |
"{31FE0627-578B-4C32-BD0C-3AFC5B163AAC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{354C486E-BA2A-4603-B0AC-7CA4EB80D2CD}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{39B8FD3A-12A2-4A20-81A7-D5E930196094}" = protocol=6 | dir=in | app=d:\games_apps\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{3D9631E5-9DA4-4003-867E-DEE22E9EED6A}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{3E2C5CE0-0346-42B7-ACE3-27670B09DA82}" = dir=in | app=c:\users\rene\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{3F5D7F60-0D5E-4259-8677-F23D6CB1B827}" = protocol=6 | dir=in | app=d:\games_apps\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
"{4119F657-CD50-40F5-A66A-8813C23232DF}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{41B3ACD0-FBBA-4CB7-A43C-C5E4C68B03BA}" = protocol=17 | dir=in | app=d:\games_apps\steam\steamapps\common\dota 2 beta\dota.exe |
"{42C81E39-3D44-4FD6-8B2D-D5B8E1EA6812}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{43EEEF3D-B2D3-470E-A559-6E2CBA489353}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{44CACC1D-7EC7-4C2D-8AD2-F8ADC6453A40}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{52F9B458-FB5B-4CAD-B34C-A7187D9AC18D}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{558DDA0E-51D7-42B5-B086-6B149DDE7A62}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{619F714C-146E-42A7-975E-05DD3643DB91}" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"{61DFD982-AEB7-4A99-80FE-04E1F66755E7}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{6A4B3B16-3EBA-48EE-961B-E335D4AC8C4B}" = protocol=6 | dir=in | app=d:\games_apps\steam\steamapps\common\orcs must die 2\build\release\orcsmustdie2.exe |
"{6D021BEA-AFFA-49A5-A2E4-690FE7EE27BF}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{6E88D40A-3C14-4ECF-9ED1-D62060A9528E}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{71C0F4EE-ADE6-4AA2-B4A3-FE26636A540C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe |
"{726A0479-BA1C-4CEF-B23F-7BE9699AAF67}" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"{74D6508C-A487-4A9D-9AAC-72CF98B231DE}" = protocol=17 | dir=in | app=d:\games_apps\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{7A74667C-9FD2-4C51-AFC0-0975FDE3F41E}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{7C0CBEA9-634D-474A-9726-5967AC33E1FE}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{801931B6-73A6-4AC2-98D0-3EEAFB34FA81}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{8089ECDC-C8AA-465E-A464-AB65EBD1F6FC}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{80D31A04-0E4E-457A-AE85-409F61C9046D}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{82C9E66D-4BB7-4223-BC03-17E444C0159D}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{86A587EC-EF87-431F-9BDC-4CF3E68467B8}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{86FC4377-7645-4676-B041-44580E41A1D1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe |
"{88E324F5-D2D6-4B5E-A078-A1C8CE8661BE}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe |
"{8A1F667C-88D1-4962-9E2F-AC5D7AAA0D67}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{99368D3B-E5F9-44B4-8744-22CECB66C6F1}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{9A11BBBD-C8D6-400B-A8DD-C8F1ED386291}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{9D124201-90F9-4F5F-BA5F-2695B63F163B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A196E3F6-C9FA-421D-B41A-D9B1FEF68147}" = protocol=6 | dir=out | app=system |
"{A28B6C04-46AF-456F-9990-FC5DF30DE69D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A592EAFC-05AD-4D42-BE4B-02CC2597B554}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A6EE7591-C3D4-441F-8D6A-AA31939AFDA9}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{B3486812-B0AF-43AA-8B3C-D00E13AD006F}" = protocol=17 | dir=in | app=d:\program files (x86)\origin\games\battlefield 3\bf3.exe |
"{B62E8304-BF8C-4677-A017-481933E8C6DE}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{B723A56B-F1AA-4E7C-BC13-E946BF3CE492}" = protocol=17 | dir=in | app=d:\games_apps\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
"{BB1BCE89-D680-4C47-99F0-79FF744939FB}" = protocol=17 | dir=in | app=d:\games_apps\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
"{BBC2ACF9-9748-466F-B536-A5A989A8E624}" = protocol=6 | dir=in | app=d:\games_apps\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{BDE01172-9737-4D68-9CF3-30BD8A878FD6}" = protocol=6 | dir=in | app=d:\games_apps\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{C444E068-FDA6-4BEF-B713-986B54891A76}" = protocol=6 | dir=in | app=d:\program files (x86)\origin\games\battlefield 3\bf3.exe |
"{C890CD52-6569-47AA-9540-DCDBE7720653}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CF8672EF-3015-4BFF-8ED8-0F8ED741C7F5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D0352572-2B26-4F4A-93B6-6FF99B723509}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D626486A-3CCD-40DC-AE6C-609DF8197233}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{DA336C94-3F2D-45CC-96E7-8BB189E84BD7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DEF4F8D6-840C-4FAF-B673-874D4E275FD6}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe |
"{E4D5F015-3AE5-47AD-9752-32A37219A869}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EBC73EC7-A4F1-4D95-A3C6-38FE39B565BA}" = protocol=6 | dir=in | app=d:\games_apps\steam\steamapps\common\bullet run\launchpad.exe |
"{FA9F651A-0FA5-40E5-991D-AA92637A9C03}" = protocol=6 | dir=in | app=d:\games_apps\steam\steamapps\common\dota 2 beta\dota.exe |
"{FCD509C1-4CED-467A-8092-36E5B71CFFB3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"TCP Query User{469F56CD-A28F-4F4D-8A8F-3B9D96B699C9}D:\games_apps\steam\steam.exe" = protocol=6 | dir=in | app=d:\games_apps\steam\steam.exe |
"TCP Query User{49837DCA-87EF-4C0E-A91E-EAFEB40750AD}D:\games_apps\steam\steamapps\onkymonky\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=d:\games_apps\steam\steamapps\onkymonky\counter-strike source\hl2.exe |
"TCP Query User{5A04BCD6-08A9-45CB-AC1F-DE515921AE15}D:\program files (x86)\call of duty\coduomp.exe" = protocol=6 | dir=in | app=d:\program files (x86)\call of duty\coduomp.exe |
"TCP Query User{5A7090B5-7B1D-4C61-8A1A-8934D73BB9C9}C:\users\rene\appdata\local\temp\gw2.exe" = protocol=6 | dir=in | app=c:\users\rene\appdata\local\temp\gw2.exe |
"TCP Query User{9D374B93-452F-40AD-B261-23C748E9143C}D:\program files (x86)\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=d:\program files (x86)\guild wars 2\gw2.exe |
"TCP Query User{DE2118A2-1ED4-4241-A0BF-1A6D9A3FFEDC}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{1C4816D7-256C-475A-90C2-23AEDB4C2DC6}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{44FCD381-64F4-4C61-8989-B0BB300C4127}D:\games_apps\steam\steam.exe" = protocol=17 | dir=in | app=d:\games_apps\steam\steam.exe |
"UDP Query User{5DA8B46F-BC9F-40BE-8BBB-FB357A9BFF1B}C:\users\rene\appdata\local\temp\gw2.exe" = protocol=17 | dir=in | app=c:\users\rene\appdata\local\temp\gw2.exe |
"UDP Query User{A3251DE0-76AF-4F3A-9061-D2BD73C75EF6}D:\program files (x86)\call of duty\coduomp.exe" = protocol=17 | dir=in | app=d:\program files (x86)\call of duty\coduomp.exe |
"UDP Query User{CABF1D44-6136-49DE-A107-1D8818F65771}D:\games_apps\steam\steamapps\onkymonky\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=d:\games_apps\steam\steamapps\onkymonky\counter-strike source\hl2.exe |
"UDP Query User{F521F5A1-F36C-4D31-8A51-63193111096D}D:\program files (x86)\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=d:\program files (x86)\guild wars 2\gw2.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86417009FF}" = Java 7 Update 9 (64-bit)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8EBE1375-11F7-482D-936C-4C575F3D9BCB}" = AVG 2012
"{90150000-0015-0407-1000-0000000FF1CE}" = Microsoft Access MUI (German) 2013
"{90150000-0016-0407-1000-0000000FF1CE}" = Microsoft Excel MUI (German) 2013
"{90150000-0018-0407-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (German) 2013
"{90150000-0019-0407-1000-0000000FF1CE}" = Microsoft Publisher MUI (German) 2013
"{90150000-001A-0407-1000-0000000FF1CE}" = Microsoft Outlook MUI (German) 2013
"{90150000-001B-0407-1000-0000000FF1CE}" = Microsoft Word MUI (German) 2013
"{90150000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Korrekturhilfen 2013 - Deutsch
"{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English
"{90150000-001F-040C-1000-0000000FF1CE}" = Outils de vérification linguistique 2013 de Microsoft Office*- Français
"{90150000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - Italiano
"{90150000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2013
"{90150000-0044-0407-1000-0000000FF1CE}" = Microsoft InfoPath MUI (German) 2013
"{90150000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2013
"{90150000-0090-0407-1000-0000000FF1CE}" = Microsoft DCF MUI (German) 2013
"{90150000-00A1-0407-1000-0000000FF1CE}" = Microsoft OneNote MUI (German) 2013
"{90150000-00BA-0407-1000-0000000FF1CE}" = Microsoft Groove MUI (German) 2013
"{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013
"{90150000-00C1-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2013
"{90150000-00E1-0407-1000-0000000FF1CE}" = Microsoft Office OSM MUI (German) 2013
"{90150000-00E2-0407-1000-0000000FF1CE}" = Microsoft Office OSM UX MUI (German) 2013
"{90150000-012B-0407-1000-0000000FF1CE}" = Microsoft Lync MUI (German) 2013
"{91150000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2013
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 314.07
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 314.07
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 314.07
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 314.07
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.1031
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.12.12
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.23.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{F2A13695-0BD3-47E2-91E0-2F5DB86FA439}" = AVG 2012
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2012
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.58
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Office15.PROPLUSR" = Microsoft Office Professional Plus 2013
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"WinRAR archiver" = WinRAR 4.20 (64-Bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{24F2E03B-ACF2-42FB-8A2A-5F015ACBDD16}" = FOX ONE
"{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{64BFBE7A-886C-4CA2-A9B4-0C2B5A5942BC}" = Battlefield 3™
"{75B90ADC-066D-454C-9D3C-CB0C6BAF7A27}_is1" = ClearSky Benchmark 1.0
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI - Deutsch
"{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287
"{C3E9887A-23BA-4777-8080-191A5AFCAB74}" = Mumble 1.2.3
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Afterburner" = MSI Afterburner 2.3.0
"ASIO4ALL" = ASIO4ALL
"Battlelog Web Plugins" = Battlelog Web Plugins
"BitTorrent" = BitTorrent
"ESN Sonar-0.70.4" = ESN Sonar
"FileZilla Client" = FileZilla Client 3.2.7.1
"FL Studio 10" = FL Studio 10
"Fraps" = Fraps (remove only)
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.37.1212
"Google Chrome" = Google Chrome
"Guild Wars 2" = Guild Wars 2
"IL Download Manager" = IL Download Manager
"Mouse Joypad V1.0" = Mouse Joypad V1.0
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Opera 12.14.1738" = Opera 12.14
"Origin" = Origin
"PunkBusterSvc" = PunkBuster Services
"reFX Nexus_is1" = reFX Nexus VSTi RTAS v2.2.0
"Steam App 201790" = Orcs Must Die! 2
"Steam App 42680" = Call of Duty: Modern Warfare 3
"Steam App 42690" = Call of Duty: Modern Warfare 3 - Multiplayer ========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CT2625848" = DVDVideoSoftTB DE Toolbar ========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 19.02.2013 16:24:27 | Computer Name = Rene-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel:
0x50b9061a Name des fehlerhaften Moduls: rename me or die.dll, Version: 0.0.0.0,
Zeitstempel: 0x51180cf8 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000010c8 ID des fehlerhaften
Prozesses: 0xd74 Startzeit der fehlerhaften Anwendung: 0x01ce0edf07735863 Pfad der
fehlerhaften Anwendung: d:\games_apps\steam\steamapps\common\call of duty modern
warfare 3\iw5mp.exe Pfad des fehlerhaften Moduls: C:\Users\Rene\Desktop\Neuer Ordner\rename
me or die.dll Berichtskennung: 5b654387-7ad2-11e2-9746-90fba63850e9
Error - 19.02.2013 17:17:14 | Computer Name = Rene-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel:
0x50b9061a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel:
0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses:
0xde4 Startzeit der fehlerhaften Anwendung: 0x01ce0edf23abe12c Pfad der fehlerhaften
Anwendung: d:\games_apps\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe
Pfad
des fehlerhaften Moduls: unknown Berichtskennung: ba9dc9cc-7ad9-11e2-9746-90fba63850e9
Error - 20.02.2013 16:01:18 | Computer Name = Rene-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel:
0x50b9061a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel:
0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses:
0x77c Startzeit der fehlerhaften Anwendung: 0x01ce0f9ed6702977 Pfad der fehlerhaften
Anwendung: d:\games_apps\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe
Pfad
des fehlerhaften Moduls: unknown Berichtskennung: 49aca483-7b98-11e2-94a5-90fba63850e9
Error - 20.02.2013 18:05:55 | Computer Name = Rene-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel:
0x50b9061a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel:
0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses:
0xb54 Startzeit der fehlerhaften Anwendung: 0x01ce0fb21a814e2c Pfad der fehlerhaften
Anwendung: d:\games_apps\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe
Pfad
des fehlerhaften Moduls: unknown Berichtskennung: b25325f5-7ba9-11e2-94a5-90fba63850e9
Error - 21.02.2013 10:23:20 | Computer Name = Rene-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel:
0x50b9061a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel:
0x00000000 Ausnahmecode: 0xc0000096 Fehleroffset: 0x003d5d4a ID des fehlerhaften Prozesses:
0xfe4 Startzeit der fehlerhaften Anwendung: 0x01ce103c3151c4c3 Pfad der fehlerhaften
Anwendung: d:\games_apps\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe
Pfad
des fehlerhaften Moduls: unknown Berichtskennung: 3d30d98c-7c32-11e2-b638-90fba63850e9
Error - 21.02.2013 10:23:20 | Computer Name = Rene-PC | Source = Application Error | ID = 1005
Description = Aus einem der folgenden Gründe kann nicht auf die Datei "" zugegriffen
werden: Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger mit der
gespeicherten Datei bzw. den auf dem Computer installierten Speichertreibern, oder
der Datenträger fehlt. Das Programm iw5mp.exe wurde wegen dieses Fehlers geschlossen.
Programm:
iw5mp.exe Datei: Der Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet.
Benutzeraktion
1.
Öffnen Sie die Datei erneut. Diese Situation ist eventuell ein temporäres Problem,
das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird. 2. Wenn
Sie weiterhin nicht auf die Datei zugreifen können und - diese sich im Netzwerk
befindet, dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem
besteht und dass eine Verbindung mit dem Server hergestellt werden kann. - diese
sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet,
überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist. 3. Überprüfen
und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu
im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben
Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE.
4.
Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin
besteht. 5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet
werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt.
Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware,
um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt. Zusätzliche
Daten Fehlerwert: 00000000 Datenträgertyp: 0
Error - 21.02.2013 11:43:27 | Computer Name = Rene-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel:
0x50b9061a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel:
0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x3b2c0000 ID des fehlerhaften Prozesses:
0x104c Startzeit der fehlerhaften Anwendung: 0x01ce10454d491262 Pfad der fehlerhaften
Anwendung: d:\games_apps\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe
Pfad
des fehlerhaften Moduls: unknown Berichtskennung: 6e796a77-7c3d-11e2-b638-90fba63850e9
Error - 21.02.2013 12:22:39 | Computer Name = Rene-PC | Source = Application Hang | ID = 1002
Description = Programm javaw.exe, Version 7.0.90.5 kann nicht mehr unter Windows
ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 9e4 Startzeit:
01ce104f1d581612 Endzeit: 93 Anwendungspfad: C:\Program Files\Java\jre7\bin\javaw.exe
Berichts-ID:
Error - 22.02.2013 08:47:41 | Computer Name = Rene-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel:
0x50b9061a Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel:
0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses:
0x604 Startzeit der fehlerhaften Anwendung: 0x01ce10f6dfe00a2d Pfad der fehlerhaften
Anwendung: d:\games_apps\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe
Pfad
des fehlerhaften Moduls: unknown Berichtskennung: 0b6388ec-7cee-11e2-8349-90fba63850e9
Error - 05.03.2013 07:18:05 | Computer Name = Rene-PC | Source = Google Update | ID = 20
Description =
[ System Events ]
Error - 25.02.2013 08:15:10 | Computer Name = Rene-PC | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
Error - 25.02.2013 13:04:39 | Computer Name = Rene-PC | Source = bowser | ID = 8003
Description =
Error - 27.02.2013 13:03:37 | Computer Name = Rene-PC | Source = DCOM | ID = 10010
Description =
Error - 03.03.2013 14:10:11 | Computer Name = Rene-PC | Source = bowser | ID = 8003
Description =
Error - 03.03.2013 14:34:14 | Computer Name = Rene-PC | Source = bowser | ID = 8003
Description =
Error - 03.03.2013 14:49:16 | Computer Name = Rene-PC | Source = bowser | ID = 8003
Description =
Error - 03.03.2013 14:52:16 | Computer Name = Rene-PC | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
Error - 03.03.2013 15:34:19 | Computer Name = Rene-PC | Source = bowser | ID = 8003
Description =
Error - 04.03.2013 13:35:42 | Computer Name = Rene-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error - 05.03.2013 06:51:35 | Computer Name = Rene-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?05.?03.?2013 um 11:50:26 unerwartet heruntergefahren.
< End of report >
| |