Log-Analyse und Auswertung: Amazon-Konto gehackt! Ist mein PC infiziert?
| ![]() Amazon-Konto gehackt! Ist mein PC infiziert? Mein Amazon-Konto wurde nachweislich von einer dritten Person unbefugt benutzt, um massiv damit einzukaufen! Ich versuche nun einzugrenzen, woran das liegen könnte. Ich habe eine PC und einen Laptop, beide mit Windows 8 Pro und hier sind nun die Logfiles: (Username wurde durch *** ersetzt) Die Laptop-Files habe ich als Archiv hinzugefügt, da der Thread sonst zu groß wird. Ich danke im Voraus für eure Hilfe. Logfiles meines PCs: Gmer: Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-04-10 11:26:37 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 SAMSUNG_470_Series_SSD rev.AXM09B1Q 119,24GB Running: gmer_2.1.19163.exe; Driver: C:\Users\***\AppData\Local\Temp\kxloipow.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\Windows\System32\win32k.sys!W32pServiceTable fffff960000dbd00 7 bytes [40, A9, 82, 01, 00, 51, F2] .text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff960000dbd08 7 bytes [01, BA, C1, FF, 00, 58, DC] ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\atiesrxx.exe[784] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fbaff8177a 4 bytes [F8, AF, FB, 07] .text C:\Windows\system32\atiesrxx.exe[784] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fbaff81782 4 bytes [F8, AF, FB, 07] .text C:\Program Files\Windows Defender\MsMpEng.exe[1616] C:\Windows\system32\psapi.dll!GetProcessImageFileNameA + 306 000007fbaff8177a 4 bytes [F8, AF, FB, 07] .text C:\Program Files\Windows Defender\MsMpEng.exe[1616] C:\Windows\system32\psapi.dll!GetProcessImageFileNameA + 314 000007fbaff81782 4 bytes [F8, AF, FB, 07] .text C:\Windows\system32\atieclxx.exe[3648] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fbaff8177a 4 bytes [F8, AF, FB, 07] .text C:\Windows\system32\atieclxx.exe[3648] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fbaff81782 4 bytes [F8, AF, FB, 07] .text C:\Windows\Explorer.EXE[2172] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fbac6d1532 4 bytes [6D, AC, FB, 07] .text C:\Windows\Explorer.EXE[2172] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fbac6d153a 4 bytes [6D, AC, FB, 07] .text C:\Windows\Explorer.EXE[2172] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fbac6d165a 4 bytes [6D, AC, FB, 07] .text C:\Program Files\Microsoft Office\Office15\MsoSync.exe[3412] C:\Windows\system32\USER32.dll!BeginPaint 000007fbb0c24a10 8 bytes JMP 000007fc70c20238 .text C:\Program Files\Microsoft Office\Office15\MsoSync.exe[3412] C:\Windows\system32\USER32.dll!RegisterClipboardFormatW 000007fbb0c2b260 9 bytes JMP 000007fc70c201d8 .text C:\Program Files\Microsoft Office\Office15\MsoSync.exe[3412] C:\Windows\system32\USER32.dll!RegisterClipboardFormatA 000007fbb0c2b350 6 bytes JMP 000007fc70c20178 .text C:\Program Files\Microsoft Office\Office15\MsoSync.exe[3412] C:\Windows\system32\USER32.dll!ValidateRect 000007fbb0c2e1a0 8 bytes JMP 000007fc70c20298 .text C:\Program Files\Microsoft Office\Office15\MsoSync.exe[3412] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fbac6d1532 4 bytes [6D, AC, FB, 07] .text C:\Program Files\Microsoft Office\Office15\MsoSync.exe[3412] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fbac6d153a 4 bytes [6D, AC, FB, 07] .text C:\Program Files\Microsoft Office\Office15\MsoSync.exe[3412] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fbac6d165a 4 bytes [6D, AC, FB, 07] ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [3588:4008] fffff960008cc5e8 Thread C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe [3560:2956] 000007fbaefc5990 Thread C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe [3560:2880] 000007fbaf9db364 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\RNG@RNGAuxiliarySeed -1475865756 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x01 0x45 0xD6 0x96 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x72 0x40 0x0F 0x53 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x28 0xEC 0x4E 0xE8 ... ---- EOF - GMER 2.1 ---- Code:
ATTFilter OTL Extras logfile created on: 10.04.2013 08:38:19 - Run 1 OTL by OldTimer - Version Folder = C:\Users\***\Desktop 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16540) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,00 Gb Total Physical Memory | 5,87 Gb Available Physical Memory | 83,91% Memory free 11,25 Gb Paging File | 10,03 Gb Available in Paging File | 89,13% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 118,90 Gb Total Space | 64,06 Gb Free Space | 53,88% Space Free | Partition Type: NTFS Drive D: | 931,51 Gb Total Space | 445,53 Gb Free Space | 47,83% Space Free | Partition Type: NTFS Computer Name: HOME-PC | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{5F40C3C5-7FF1-4535-8BA8-96A80E0AD753}" = lport=1688 | protocol=6 | dir=in | name=open port 1688 | "{DCF80AA4-9F16-4C17-B817-E092146972C9}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe | "{FC3D1280-8012-4A06-86B5-617428C61277}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01BBE408-C45B-4044-9385-A2FFE677ACCB}" = dir=in | name=windows phone | "{0743D397-6A87-4E6F-BF49-FD0313602B0C}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{1DB8A937-6FB1-4274-832C-CB920411CABD}" = dir=out | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{21952D94-A097-4C73-BD76-E74FFD789FD1}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{285DCC5A-73C2-4985-AD45-B5DA24E955CF}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{2B86E035-A51B-4083-9C84-93BA356A0F1D}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{33C1EF18-9190-49C3-BD66-B41043ECB57F}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{3B906B88-C49D-4791-BDF7-9636AD727F69}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{3F50C2D4-482E-4431-8F97-C0A2034FB22B}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{41B65666-28CC-49F4-9E1E-5A755744797E}" = dir=out | name=monster island | "{443A78D9-8A21-414A-BC74-1DD556CA1959}" = dir=out | name=gravity guy | "{4510DA06-DB5B-494C-974B-691AEE164911}" = dir=out | name=@{microsoft.bingsports_1.8.0.51_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{477441E8-866D-4F26-8A8C-436A35F213A6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe | "{4991BD28-0E05-43DC-954D-FF7479B61F20}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | "{4F6AF1CA-76E8-48A0-A24C-61C9F126D0A9}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{5885B5EF-2DE3-40BA-870C-72FE1EA39A6D}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{5C8DDDED-2D47-45B0-954A-F08D09D24A8E}" = dir=out | name=@{microsoft.zunevideo_1.2.150.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{5FB36C75-8E9D-4EB2-838B-AB844BEBE4B0}" = dir=out | name=hp printer control | "{66EB2E47-C3BE-4A3C-9A32-720398A923D6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe | "{6E55E754-72AC-4FAB-922A-4F543ED1A70A}" = dir=in | name=hp printer control | "{6E8D3F85-31F2-435E-97C5-DCEE451C0D2B}" = dir=out | name=@{microsoft.bingfinance_1.7.0.38_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{6EF2FC39-DFF9-490A-9E3F-307600E23546}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{70436C93-28DB-4043-8558-ECA63342501A}" = protocol=6 | dir=in | app=c:\users\***\appdata\roaming\dropbox\bin\dropbox.exe | "{71469E45-ABD8-49EC-BB20-E366A06BDC05}" = dir=in | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{7AB64E89-F18A-4A69-B318-ADE8D9C1A98E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{81E5F5B5-0E69-442F-8021-6B7DAD8F061A}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{8308659F-65C2-4FF7-A20B-424C4967E610}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{8409E627-4A42-4B42-8158-BCC0F86BD3D7}" = dir=in | name=@{ad2f1837.hpscanandcapture_12.0.82.0_neutral__v10z8vjag6ke6?ms-resource://ad2f1837.hpscanandcapture/resources/apptitle} | "{898353F9-F39B-4DE2-B679-0B04AA68D292}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{8DAA9BDB-C1F2-442B-B82A-54DB70C3B3CE}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | "{90ADA111-9B76-47A6-B83A-7955169E83FB}" = protocol=17 | dir=in | app=c:\users\***\appdata\roaming\dropbox\bin\dropbox.exe | "{90FE884B-BEF0-4384-9B2F-E1528D62E4BB}" = dir=in | app=c:\users\***\appdata\local\microsoft\skydrive\skydrive.exe | "{98520FD0-C4AB-40AE-B85D-B84D827FE603}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{9A5C9BEA-1C0C-4F7A-9569-3C2DEAC0AED6}" = dir=out | name=istunt 2 | "{AA4C3A90-C84D-41C3-B093-44FEBDC511E5}" = dir=out | name=onenote | "{BB8A343D-0F44-4330-A7DD-486858991158}" = dir=out | name=windows phone | "{BD86BD27-A22B-4359-8478-60D63B08CDC8}" = dir=out | name=@{microsoft.xboxlivegames_1.2.143.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{C1E90C01-1B30-4C89-90CA-6CAD7D7573B1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{CC814391-08F6-46E2-9572-FA503E99BF78}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{D5F03317-9243-4485-A65F-09D510B8B06A}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{D8F7F481-34C7-4CEB-98FF-ADC7403794BF}" = dir=out | name=@{microsoft.bingnews_1.7.0.38_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{D93CB1B4-CE6A-454D-83B2-35BBA421B7FD}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | "{DB48709C-39D6-4DB4-B39A-2AE11375C5DA}" = dir=out | name=@{microsoft.bingtravel_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{E39C8FCE-9A30-4C37-84E2-7E399B586A27}" = dir=out | name=@{microsoft.bingweather_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{E3EA3C71-D75B-40F5-8761-A1068A102E63}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe | "{E6045D34-663D-41D7-A0E1-F9DF1A12B3B5}" = dir=in | name=onenote | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{EC8B1C15-0B65-4D92-B248-656115024457}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe | "{ED288D29-BCA3-4C0C-8C35-5C1FB7A88474}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe | "{ED7033D6-2429-4E72-BB77-1E75509A9350}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{F29E7C28-677E-44BA-91AB-7E93229301FE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | "{F2CD5014-9A99-4C02-B88C-78C83E84D220}" = dir=out | name=@{ad2f1837.hpscanandcapture_12.0.82.0_neutral__v10z8vjag6ke6?ms-resource://ad2f1837.hpscanandcapture/resources/apptitle} | "{F3EACAB3-364F-44AB-B8E3-8D0D5758555E}" = dir=out | name=@{microsoft.zunemusic_1.2.150.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{F744AEA1-5F2A-4727-B489-9623984052DF}" = dir=out | name=@{microsoft.bingmaps_1.5.1.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{F8CC1471-C0E9-4423-A0C6-5B7A55846450}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{FA19B7FB-CD81-4D22-9159-AE1549ED72BB}" = dir=in | app=c:\users\***\appdata\local\temp\7zs7bd7\setup\hpznui40.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{008C42A1-FB22-7DB4-618F-08E2C5059C0C}" = ccc-utility64 "{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB) "{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}" = Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{26A24AE4-039D-4CA4-87B4-2F86417017FF}" = Java 7 Update 17 (64-bit) "{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}" = Zune Language Pack (CHS) "{2B997E80-3BEC-3222-9114-98DBE1182B2E}" = Microsoft Visual C++ 2012 x64 Debug Runtime - 11.0.50727 "{30B7A7A6-D519-3332-BEB3-D105EFC7389A}" = Microsoft Visual Studio 2012 Express Prerequisites x64 - ENU "{3589A659-F732-4E65-A89A-5438C332E59D}" = Zune Language Pack (ELL) "{393D3B4C-1F95-CDD2-4F0A-395D99D5F553}" = AMD Accelerated Video Transcoding "{3BE02C4F-5884-36F4-959B-1DD3746F7737}" = Windows Phone Tools Finalizer "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}" = Zune Language Pack (KOR) "{53A19094-2C04-A9B9-7309-3E92152D4845}" = AMD Catalyst Install Manager "{57C51D56-B287-4C11-9192-EC3C46EF76A4}" = Zune Language Pack (RUS) "{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG) "{5DEFD397-4012-46C3-B6DA-E8013E660772}" = Zune Language Pack (NOR) "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD) "{68A48EF1-DF03-394F-AF40-1E4FE42BB8DD}" = Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - ENU "{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP) "{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64 "{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}" = Zune Language Pack (SVE) "{6F07A6C2-9068-3673-A120-DC10012468C6}" = Microsoft Visual Studio Team Foundation Server 2012 Object Model "{76BA306B-2AA0-47C0-AB6B-F313AB56C136}" = Zune Language Pack (MSL) "{78909610-D229-459C-A936-25D92283D3FD}" = Microsoft SQL Server Compact 4.0 SP1 x64 ENU "{8960A0A1-BB5A-479E-92CF-65AB9D684B43}" = Zune Language Pack (PLK) "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8B112338-2B08-4851-AF84-E7CAD74CEB32}" = Zune Language Pack (DAN) "{90150000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2013 "{90150000-0015-0407-1000-0000000FF1CE}" = Microsoft Access MUI (German) 2013 "{90150000-0016-0407-1000-0000000FF1CE}" = Microsoft Excel MUI (German) 2013 "{90150000-0018-0407-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (German) 2013 "{90150000-0019-0407-1000-0000000FF1CE}" = Microsoft Publisher MUI (German) 2013 "{90150000-001A-0407-1000-0000000FF1CE}" = Microsoft Outlook MUI (German) 2013 "{90150000-001B-0407-1000-0000000FF1CE}" = Microsoft Word MUI (German) 2013 "{90150000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Korrekturhilfen 2013 - Deutsch "{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English "{90150000-001F-040C-1000-0000000FF1CE}" = Outils de vérification linguistique 2013 de Microsoft Office*- Français "{90150000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - Italiano "{90150000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2013 "{90150000-0044-0407-1000-0000000FF1CE}" = Microsoft InfoPath MUI (German) 2013 "{90150000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2013 "{90150000-0090-0407-1000-0000000FF1CE}" = Microsoft DCF MUI (German) 2013 "{90150000-00A1-0407-1000-0000000FF1CE}" = Microsoft OneNote MUI (German) 2013 "{90150000-00BA-0407-1000-0000000FF1CE}" = Microsoft Groove MUI (German) 2013 "{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013 "{90150000-00C1-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2013 "{90150000-00E1-0407-1000-0000000FF1CE}" = Microsoft Office OSM MUI (German) 2013 "{90150000-00E2-0407-1000-0000000FF1CE}" = Microsoft Office OSM UX MUI (German) 2013 "{90150000-012B-0407-1000-0000000FF1CE}" = Microsoft Lync MUI (German) 2013 "{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}" = Zune Language Pack (IND) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{951AF289-1B6A-44CA-B4F3-259BFC49148F}" = HP Photosmart Prem C410 All-In-One Driver Software 14.0 Rel. 7 "{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}" = Zune "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 "{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}" = Zune Language Pack (CHT) "{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}" = Zune Language Pack (CSY) "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B4870774-5F3A-46D9-9DFE-06FB5599E26B}" = Zune Language Pack (FIN) "{BCA26999-EC22-3007-BB79-638913079C9A}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU "{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU) "{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA) "{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA) "{C6BE19C6-B102-4038-B2A6-1C313872DBB4}" = Zune Language Pack (HUN) "{D37A3DAC-AE13-3DC3-951C-00D18D1E99DB}" = Windows Phone Emulator x64 - ENU "{D8A781C9-3892-4E2E-9320-480CF896CFBB}" = Zune Language Pack (JPN) "{E5748D30-7E6D-3A8E-BFE6-C1D02C6DDABB}" = Microsoft Help Viewer 1.1 "{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}" = Windows Mobile Device Updater Component "{FE09AF6D-78B2-4093-B012-FCDAF78693CE}_is1" = MPC-BE x64 "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "HP Imaging Device Functions" = HP Imaging Device Functions 14.0 "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0 "HPOCR" = OCR Software by I.R.I.S. 14.0 "Microsoft Help Viewer 1.1" = Microsoft Help Viewer 1.1 "Office15.PROPLUS" = Microsoft Office Professional Plus 2013 "Totalcmd64" = Total Commander 64-bit (Remove or Repair) "WinRAR archiver" = WinRAR 4.20 (64-Bit) "Zune" = Zune [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{1050A3D4-BC3B-4443-BD60-68C2BAE65EF4}" = CCC Help English "{12B8E200-99CC-4203-A8D1-4145FC4D0192}" = Microsoft Expression Blend SDK for Windows Phone OS 7.1 "{1321BDD4-C5FC-BCFA-F281-7C66D5DE187F}" = CCC Help French "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery "{15051E6B-65DA-46C8-A265-CC0F8C38BC8F}" = PS_AIO_07_C410_SW_Min "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant "{1670FA36-1008-48BE-BD7F-6EC4851EAA91}" = Microsoft Visual Studio 2012 Preparation "{1690CE56-2231-4E59-9006-A0876D949EA8}" = Tools for .Net 3.5 "{17B6BB82-637A-32C5-A861-95A0CF0C0AD7}" = Microsoft Visual C++ 2012 Core Libraries For Windows Phone "{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}" = Microsoft Silverlight 4 SDK "{18D0383D-F666-3561-9D8B-74269B424415}" = Microsoft Portable Library Multi-Targeting Pack "{1948E039-EC79-4591-951D-9867A8C14C90}" = Microsoft .NET Framework 4.5 SDK "{1B9BBB23-65CB-3AEE-BFC6-633E7CA299FD}" = Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - ENU "{1C163D33-33B3-33EB-A617-0D4D852BE8E1}" = Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.50727 "{1C997E1C-5CE9-4AF3-AAA9-DC65E6090827}" = Microsoft Expression Blend SDK for Silverlight 4 "{1D6DF721-54B7-6AA4-2050-7E286CCE13E8}" = Catalyst Control Center "{1EF73F13-8A60-7910-A59D-8F62A8BCD47D}" = CCC Help Swedish "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F8E06E2-BA93-40DC-B183-E024CBD853A8}" = Microsoft Visual C++ 2012 Compilers "{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK "{22E62B37-5D05-C5AD-F53E-691342495A45}" = CCC Help Spanish "{2348da3b-1257-4a83-a554-b094a08d06d9}" = Windows Phone SDK 8.0 - ENU "{23528772-43DB-1E20-E845-DB1CE00FBB10}" = CCC Help Danish "{256E7DAC-9BE8-494E-8DE7-7857BF96B774}" = Microsoft Expression Blend 3 SDK "{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17 "{27F100DD-20D2-BCD8-CF3B-721529678E1F}" = Windows Software Development Kit Tools for Windows Store Apps "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox "{2C0CC01A-DDBC-3AED-AF18-E741242FD727}" = Microsoft Visual Studio Ultimate 2012 XAML UI Designer enu Resources "{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 "{38FC6E9A-F719-431A-A83D-4C86D5FD6555}" = Microsoft Visual Studio 2012 Shell (Minimum) Resources "{3B2E6F73-6EBE-3D44-84F9-00CCE7C8592A}" = Microsoft Visual Studio 2012 Add-in for Windows Phone "{403759F5-1D77-49F4-812D-AF43196E8C74}" = Blend for Visual Studio SDK for Windows Phone 8.0 "{406EEB41-4A21-46E6-82D1-EF643D97B3B4}" = Microsoft Visual C++ 2012 Compilers For Windows Phone "{40A5C393-C233-3DDD-8563-362871D81B69}" = Microsoft Visual Studio Express 2012 for Windows Phone "{495F9F88-D14C-4D28-BE61-9BADCF290011}" = C410 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4C6D5779-A766-45DF-9938-D6F595A66F2B}" = Microsoft Expression Blend 4 "{532DBCC8-9468-435C-AEF6-30B7F50735A2}" = Blend for Visual Studio 2012 ENU resources "{53CC28C4-F068-484F-8876-3BAEDCCE6E72}" = Microsoft Advertising SDK for Windows Phone - ENU "{565E7B0E-B76B-4EAD-9753-F1E72A5CF12E}" = HPAppStudio "{57F20F04-014D-453F-B6A3-AE9485C4DFAB}" = Blend for Visual Studio 2012 "{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}" = Status "{5BB2F6B0-10A4-3CBD-B248-CA32CEFFA3A9}" = Windows Phone SDK 7.1 Assemblies "{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7 "{5EE6E987-1B79-4A93-832B-27472C7D1579}" = WPF Toolkit February 2010 (Version 3.5.50211.1) "{5F32FD5A-6F9D-50FD-1896-0AEC107DE5D0}" = CCC Help Portuguese "{60AAE030-8621-5187-F7CF-41A241698407}" = CCC Help Dutch "{619DC4E1-DA11-48A1-4587-4E3E3D02D103}" = Catalyst Control Center Graphics Previews Common "{69942BB6-252E-4BDE-BB32-BBFBF09EB5C4}" = Windows Phone SDK 8.0 Extensions for XNA Game Studio 4.0 "{69E11501-75F7-4ACE-8103-52513DDCFE26}" = Microsoft Expression Blend SDK for Windows Phone 7 "{6DAB46E3-D017-3E2B-85D8-F57A230384C0}" = Microsoft Visual Studio Team Foundation Server 2012 Team Explorer "{6F05E0AC-22D3-BE6E-05DD-623504F54FB2}" = CCC Help Chinese Standard "{6F33C2E2-5E02-4344-90BC-ED55C48341D2}" = WCF Data Services SDK for Windows Phone "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{722D1AB9-61D3-4F87-9F6B-9C83EC3D9E62}" = Microsoft NuGet - Visual Studio 2012 Express for Windows Phone "{72440FE9-C897-31C4-AC17-A360E9DDA606}" = Microsoft Portable Library Multi-Targeting Pack Language Pack - enu "{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6 "{7515082B-0B97-331C-9725-9D42EF0DE501}" = Windows Phone 8.0 Emulation Images "{7668B02B-DDDA-A67C-F86B-9D1061DD08CD}" = CCC Help Hungarian "{786D445C-F3D7-35D2-81AA-60DB61F9F552}" = Microsoft Visual Studio 2010 Express for Windows Phone 7.1 - ENU "{7BA420C3-3629-2AD6-19D0-0A6E27D6B782}" = CCC Help Thai "{7F4B8974-F6FA-3DCB-B14D-CCFEDAA3D837}" = Windows Phone Emulator 8.0 Configurator "{800F484E-9D69-492D-B656-7BAA32586142}" = Microsoft Visual Studio 2012 Shell (Minimum) "{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7 "{8125DCCA-4B43-4C53-9A3A-3B4FDFF669E5}" = Blend for Visual Studio Add-in for Adobe FXG Import "{820C677A-41B2-48C3-8136-FEE35A052E73}" = Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies "{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg "{8EFA9357-75F9-EF3D-B7F9-BC913BA8DAC5}" = CCC Help Norwegian "{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable "{91DA5EBA-C240-289B-0AB4-6604CDE6A27F}" = CCC Help Czech "{9294F169-72EE-4D74-AE92-CA25F64B4FF8}" = Fax "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9711CA3C-614D-5B3B-E10F-062FD292075E}" = CCC Help Italian "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc "{9B3A1C97-A361-463E-8817-444F9F88CDFE}" = Microsoft Expression Blend SDK for .NET 4 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9FCBD98D-F8B3-6ECC-5293-9C28817E3269}" = Catalyst Control Center InstallProxy "{A0B1B905-88E8-CBBB-C936-0FFECD06BBDC}" = Catalyst Control Center Localization All "{A2DFDB99-5576-391D-9F62-D1223A41C7F4}" = Microsoft Visual Studio 2012 Add-in for Windows Phone - ENU Language Pack "{A4366F69-CE22-4DB7-9C8C-46A5845AF997}" = Microsoft Visual C++ 2012 Compilers - ENU Resources "{A721BC43-E63E-3531-B1BF-6A405F9530BD}" = Windows Phone SDK 7.1 Add-in for Visual Studio 2010 - ENU "{AC76BA86-1033-FFFF-7760-000000000006}" = Adobe Acrobat XI Pro "{AE4A81B0-B85D-3B81-B57B-9EEF1641CB5E}" = Microsoft Visual Studio Express 2012 for Windows Phone - ENU "{AF749638-8C8C-84E8-DA4A-37D014824E33}" = CCC Help German "{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update "{B0B4575E-EB62-1BDC-994A-A42ED7E8FF46}" = CCC Help Greek "{B1504E18-0D34-1554-20FB-2BF6459D4683}" = CCC Help Russian "{B90B9B89-2B62-B281-25C3-A59B189C249F}" = CCC Help Finnish "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2 "{BC5DD87B-0143-4D14-AAE6-97109614DC6B}" = SolutionCenter "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6 "{C1BE4600-7D15-3D1E-8AA2-B3241DB1D063}" = Microsoft Visual Studio Ultimate 2012 XAML UI Designer Core "{C5ED3F69-3A6D-EA6E-EE57-342C0274FE5F}" = CCC Help Japanese "{C7EE26EC-477D-37D0-87B4-ED146C5A9CD2}" = Windows Phone SDK 8.0 Assemblies "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CCF298AF-9CE1-4B26-B251-486E98A34789}" = Windows 7 USB/DVD Download Tool "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp "{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack "{D21B5F75-8042-3B39-80A1-F1D56D6DB4AB}" = Windows Phone 8.0 Managed SDK Profiler (X86) "{D348A566-3447-4138-82FE-5BC424FBB94B}" = Microsoft Visual C++ 2012 Compilers For Windows Phone - ENU Resources "{D5C8D5EE-EA3C-3B65-9273-C537D21003F1}" = Windows Phone 8.0 Emulation Host "{D60C7163-23D1-3083-AD0E-E6FEDDBAC5DC}" = Windows Phone 7.8 Emulation Images - enu "{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh "{D6DEA3AD-637E-368A-BD00-501D443F5E86}" = Windows Phone 8.0 Managed SDK Profiler (ARM) "{DBD353DB-F37D-3CBB-65A7-0B3BA8634263}" = CCC Help Turkish "{dbf8d9e1-1a4a-4f0d-bb08-bbd1035d583a}" = Windows Phone SDK update for WP 7.8 "{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding "{E517094C-06B6-419F-8FFD-EF4F57972130}" = QuickTransfer "{EE6EBBD2-C278-5F48-B021-C9314ABE7593}" = CCC Help Korean "{EFBBD030-48F0-43B3-A8AD-789894DAD0B5}" = Microsoft Expression Blend 4 Add-in for Adobe FXG Import "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F5C1211F-8F5E-B4BE-8046-3BB6B7944BA0}" = CCC Help Polish "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm "{FA115E3B-1A2D-F0F1-52CE-99D1BD346C08}" = CCC Help Chinese Traditional "{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 "{FEB375AB-6EEC-3929-8FAF-188ED81DD8B5}" = Microsoft Help Viewer 2.0 "5513-1208-7298-9440" = JDownloader 0.9 "abgx360" = abgx360 v1.0.6 "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Blend_4.0.30816.0" = Microsoft Expression Blend 4 "CoreAVC Professional Edition" = CoreAVC Professional Edition (remove only) "DAEMON Tools Lite" = DAEMON Tools Lite "HaaliMkx" = Haali Media Splitter "ImgBurn" = ImgBurn "Microsoft Help Viewer 2.0" = Microsoft Help Viewer 2.0 "Microsoft Visual Studio 2010 Express for Windows Phone 7.1 - ENU" = Windows Phone SDK 7.1 - ENU "Mp3tag" = Mp3tag v2.54 "Notepad++" = Notepad++ "Opera 12.15.1748" = Opera 12.15 ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-748043225-2171842829-3866205916-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "SkyDriveSetup.exe" = Microsoft SkyDrive ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 05.04.2013 04:52:57 | Computer Name = Home-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: wwahost.exe, Version: 6.2.9200.16384, Zeitstempel: 0x50107c6e Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.2.9200.16384, Zeitstempel: 0x5010ab2d Ausnahmecode: 0xe0434352 Fehleroffset: 0x00000000000189cc ID des fehlerhaften Prozesses: 0x1020 Startzeit der fehlerhaften Anwendung: 0x01ce31dac9c4e9c4 Pfad der fehlerhaften Anwendung: C:\Windows\system32\wwahost.exe Pfad des fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll Berichtskennung: 3593cb93-9dce-11e2-be67-001fd08c23a6 Vollständiger Name des fehlerhaften Pakets: Microsoft.BingSports_1.2.0.135_x64__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: AppexSports Error - 05.04.2013 04:53:08 | Computer Name = Home-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: wwahost.exe, Version: 6.2.9200.16384, Zeitstempel: 0x50107c6e Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.2.9200.16384, Zeitstempel: 0x5010ab2d Ausnahmecode: 0x00000004 Fehleroffset: 0x00000000000189cc ID des fehlerhaften Prozesses: 0x1020 Startzeit der fehlerhaften Anwendung: 0x01ce31dac9c4e9c4 Pfad der fehlerhaften Anwendung: C:\Windows\system32\wwahost.exe Pfad des fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll Berichtskennung: 3c13b188-9dce-11e2-be67-001fd08c23a6 Vollständiger Name des fehlerhaften Pakets: Microsoft.BingSports_1.2.0.135_x64__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: AppexSports Error - 05.04.2013 06:17:58 | Computer Name = Home-PC | Source = MsiInstaller | ID = 11722 Description = Error - 05.04.2013 06:18:01 | Computer Name = Home-PC | Source = MsiInstaller | ID = 10005 Description = Error - 05.04.2013 06:41:50 | Computer Name = Home-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: WPexpress_full.exe, Version: 11.0.50727.38, Zeitstempel: 0x4ff5c68c Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x082aeba0 ID des fehlerhaften Prozesses: 0xe00 Startzeit der fehlerhaften Anwendung: 0x01ce31e9821f9fd9 Pfad der fehlerhaften Anwendung: D:\Downloads\Programme\free\wp\WPexpress_full.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 6b7e76c6-9ddd-11e2-be69-001fd08c23a6 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error - 05.04.2013 07:28:11 | Computer Name = Home-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: regsvr32.exe, Version: 6.2.9200.16384, Zeitstempel: 0x5010a4f2 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000e6e21a90 ID des fehlerhaften Prozesses: 0xd24 Startzeit der fehlerhaften Anwendung: 0x01ce31f0a78472bd Pfad der fehlerhaften Anwendung: C:\Windows\system32\regsvr32.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: e573a445-9de3-11e2-be6a-001fd08c23a6 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error - 05.04.2013 07:28:14 | Computer Name = Home-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: regsvr32.exe, Version: 6.2.9200.16384, Zeitstempel: 0x5010a4f2 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000e6e21a90 ID des fehlerhaften Prozesses: 0x37c Startzeit der fehlerhaften Anwendung: 0x01ce31f0a9acb335 Pfad der fehlerhaften Anwendung: C:\Windows\system32\regsvr32.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: e7606244-9de3-11e2-be6a-001fd08c23a6 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error - 06.04.2013 07:39:29 | Computer Name = Home-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error - 06.04.2013 07:39:29 | Computer Name = Home-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error - 06.04.2013 11:20:02 | Computer Name = Home-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: OUTLOOK.EXE, Version: 15.0.4481.1003, Zeitstempel: 0x5110da83 Name des fehlerhaften Moduls: OUTLOOK.EXE, Version: 15.0.4481.1003, Zeitstempel: 0x5110da83 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000001820fe ID des fehlerhaften Prozesses: 0xaec Startzeit der fehlerhaften Anwendung: 0x01ce32da31fc2aa7 Pfad der fehlerhaften Anwendung: C:\Program Files\Microsoft Office\Office15\OUTLOOK.EXE Pfad des fehlerhaften Moduls: C:\Program Files\Microsoft Office\Office15\OUTLOOK.EXE Berichtskennung: 737383d3-9ecd-11e2-be6c-001fd08c23a6 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: [ System Events ] Error - 05.04.2013 05:18:48 | Computer Name = Home-PC | Source = DCOM | ID = 10010 Description = Error - 05.04.2013 05:38:22 | Computer Name = Home-PC | Source = DCOM | ID = 10016 Description = Error - 05.04.2013 05:38:22 | Computer Name = Home-PC | Source = DCOM | ID = 10016 Description = Error - 05.04.2013 05:38:31 | Computer Name = Home-PC | Source = DCOM | ID = 10016 Description = Error - 06.04.2013 10:54:24 | Computer Name = Home-PC | Source = Schannel | ID = 36888 Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 10. Der Windows-SChannel-Fehlerstatus lautet: 10. Error - 06.04.2013 10:54:24 | Computer Name = Home-PC | Source = Schannel | ID = 36888 Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 10. Der Windows-SChannel-Fehlerstatus lautet: 10. Error - 07.04.2013 06:33:08 | Computer Name = Home-PC | Source = Schannel | ID = 36888 Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus lautet: 900. Error - 07.04.2013 06:33:08 | Computer Name = Home-PC | Source = Schannel | ID = 36888 Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus lautet: 900. Error - 07.04.2013 06:33:08 | Computer Name = Home-PC | Source = Schannel | ID = 36888 Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus lautet: 900. Error - 07.04.2013 06:33:08 | Computer Name = Home-PC | Source = Schannel | ID = 36887 Description = Es wurde eine schwerwiegende Warnung vom Remoteendpunkt empfangen. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. < End of report > Code:
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Amazon-Konto gehackt! Ist mein PC infiziert? Hallo und
__________________![]() Es reicht völlig aus, die Logs einmal zu posten. Wenn du die direkt postest in CODE-Tags, was du vorrangig machen sollst (denn Logs im Anhang erschweren die Auswertung) dann ist es völlig überflüssig die nochmal in den Anhang gezippt zu legen. Letztres soll nur gemacht werden, wenn die Logs zu groß sind, um direkt in CODE-Tags gepostet zu werden. Code:
ATTFilter O1 - Hosts: lmlicenses.wip4.adobe.com O1 - Hosts: lm.licenses.adobe.com ![]() Diese Einträge in der Hosts dienen dazu, raubkopierte (gecrackte) Software lauffähig zu machen ![]() Siehe auch => http://www.trojaner-board.de/95393-c...-software.html Falls wir Hinweise auf illegal erworbene Software finden, werden wir den Support ohne jegliche Diskussion beenden. Cracks/Keygens sind zu 99,9% gefährliche Schädlinge, mit denen man nicht spaßen sollte. Ausserdem sind diese illegal und wir unterstützen die Verwendung von geklauter Software nicht. Somit beschränkt sich der Support auf Anleitung zur kompletten Neuinstallation!! Dass illegale Cracks und Keygens im Wesentlichen dazu dienen, Malware zu verbreiten ist kein Geheimnis und muss jedem klar sein! In Zukunft Finger weg von: Softonic, Registry-Bereinigern und illegalem Zeugs Cracks/Keygens/Serials
__________________ |
Amazon-Konto gehackt! Ist mein PC infiziert?
adobe, defender, error, excel, flash player, homepage, iexplore.exe, infiziert, infiziert?, install.exe, jdownloader, livecomm.exe, mp3, msiinstaller, object, opera, pc infiziert, pdf, photoshop, registry, remote control, rundll, scan, security, server, software, svchost.exe, system, temp, total commander, usb, visual studio, warnung, win32k.sys, windows, windows 8 pro, windowsapps |