|
Plagegeister aller Art und deren Bekämpfung: ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
20.04.2013, 17:11 | #17 |
/// Winkelfunktion /// TB-Süch-Tiger™ | ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen Das ist das falsche Log von MBAR, bitte die Anleitungen genauer lesen und umsetzen
__________________
__________________ |
20.04.2013, 19:42 | #18 |
| ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen Ist das der Richtige?
__________________Danke und schönen Samstag und Sonntag Gruß Ahnungslos61 Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.05.0.1001 www.malwarebytes.org Database version: v2013.04.20.08 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16540 Astrid-Coach :: ASTRID [administrator] 20.04.2013 20:41:02 mbar-log-2013-04-20 (20-41-02).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 8654 Time elapsed: 9 minute(s), 30 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) |
20.04.2013, 21:12 | #19 |
/// Winkelfunktion /// TB-Süch-Tiger™ | ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen aswMBR Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). TDSS-Killer Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ Logfiles bitte immer in CODE-Tags posten |
21.04.2013, 09:45 | #20 |
| ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen Hier kommen die Ergebnisse: Code:
ATTFilter aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-04-21 10:23:22 ----------------------------- 10:23:22.478 OS Version: Windows x64 6.2.9200 10:23:22.478 Number of processors: 4 586 0x3A09 10:23:22.478 ComputerName: ASTRID UserName: 10:23:22.603 Initialze error 1 10:23:23.276 AVAST engine defs: 13042000 10:24:13.265 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000003e 10:24:13.265 Disk 0 Vendor: ST1000LM024_HN-M101MBB 2AR10001 Size: 953869MB BusType: 11 10:24:13.281 Disk 0 MBR read successfully 10:24:13.281 Disk 0 MBR scan 10:24:13.281 Disk 0 unknown MBR code 10:24:13.281 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1 10:24:13.281 Disk 0 scanning C:\Windows\system32\drivers 10:24:13.281 Service scanning 10:24:13.984 Modules scanning 10:24:13.984 Disk 0 trace - called modules: 10:24:13.984 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll iaStorA.sys 10:24:14.000 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008f59060] 10:24:14.000 3 CLASSPNP.SYS[fffff880011a1fea] -> nt!IofCallDriver -> [0xfffffa80076cccb0] 10:24:14.015 5 ACPI.sys[fffff88001001a91] -> nt!IofCallDriver -> \Device\0000003e[0xfffffa80076cc060] 10:24:14.015 AVAST engine scan C:\Windows 10:24:14.031 AVAST engine scan C:\Windows\system32 10:24:14.031 AVAST engine scan C:\Windows\system32\drivers 10:24:14.031 AVAST engine scan C:\Users\Astrid-Coach 10:24:14.031 AVAST engine scan C:\ProgramData 10:24:14.047 Scan finished successfully 10:24:39.301 Disk 0 MBR has been saved successfully to "C:\Users\Astrid-Coach\Desktop\MBR.dat" 10:24:39.301 The log file has been saved successfully to "C:\Users\Astrid-Coach\Desktop\aswMBR.txt" Danke und Grüße aus Gonsenheim Ahnunglos61 |
21.04.2013, 10:31 | #21 |
| ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen ... oder ist das die richtige Datei? Im Anhang! |
21.04.2013, 22:29 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Im Anschluss: adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen Downloade Dir bitte AdwCleaner auf deinen Desktop.
Danach eine Kontrolle mit OTL bitte:
__________________ Logfiles bitte immer in CODE-Tags posten |
22.04.2013, 07:46 | #23 |
| ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen Hier kommen die files: Code:
ATTFilter OTL Extras logfile created on: 22.04.2013 08:31:33 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Astrid-Coach\Desktop 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16540) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,89 Gb Total Physical Memory | 6,09 Gb Available Physical Memory | 77,25% Memory free 15,89 Gb Paging File | 14,02 Gb Available in Paging File | 88,25% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 869,80 Gb Total Space | 798,76 Gb Free Space | 91,83% Space Free | Partition Type: NTFS Drive D: | 60,00 Gb Total Space | 40,90 Gb Free Space | 68,16% Space Free | Partition Type: NTFS Computer Name: ASTRID | User Name: Astrid-Coach | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1435033098-840508067-3058036539-1002\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1212CC03-871F-4276-A446-8D26C81BC6FA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{16343735-E6BC-4BF6-AB82-B585588DF1A4}" = rport=139 | protocol=6 | dir=out | app=system | "{1EC42E47-9194-4F02-B2DA-98DC73E06634}" = rport=138 | protocol=17 | dir=out | app=system | "{202B5A30-F5B0-4D6B-B36D-3FCEE6BEBB76}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{2A3FB734-6A05-48FC-9774-C32698627DD7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2A7BA9D9-4977-4665-8DD0-E6014303AA72}" = rport=10243 | protocol=6 | dir=out | app=system | "{419BC377-5D0F-4C69-A4AE-33D2E7F42CB7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{55E96179-8C41-4C22-BE95-77CA36762D58}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5FBDD534-3EBB-479A-B649-AFE033CD1FAB}" = rport=137 | protocol=17 | dir=out | app=system | "{89075959-3BDA-4689-A8CC-FA91AFC7AC58}" = lport=2869 | protocol=6 | dir=in | app=system | "{89ED1B9A-6D90-438C-AC44-267956878D10}" = lport=445 | protocol=6 | dir=in | app=system | "{8CAD0ED7-7FAE-4BDF-B7F6-B6AD64B20713}" = rport=445 | protocol=6 | dir=out | app=system | "{A2C96B23-7BFC-4521-A7A7-0F1EB3CFF8B0}" = lport=10243 | protocol=6 | dir=in | app=system | "{ADFF30D8-2932-4850-B1C9-5D1739E1C30A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B18286CA-57CF-4EB2-A4ED-192F702A7833}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B52DB6FB-9BD0-4FCF-97DB-34D933B1464C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{B729D9E4-052E-4A53-B391-331DD080613A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{BE34FC85-DF1C-4171-A739-743C1B8E6419}" = lport=138 | protocol=17 | dir=in | app=system | "{CD4342CD-16C2-4129-9228-7EFB05504CBC}" = lport=139 | protocol=6 | dir=in | app=system | "{D61DE085-B5D0-4C60-AFBD-C62898F4B833}" = lport=137 | protocol=17 | dir=in | app=system | "{D8F7672F-14C6-4F17-9058-61D04236F5AF}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{DD411DF8-5638-4E1B-955B-A143E18D1E75}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{E5927AC1-9F11-402F-8D8D-15DC242D4743}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{EEB76AC2-8660-454F-9D3D-0D01A02C499A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{EFA69EAC-2C86-4F01-A310-10BB981E712E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07874BCD-A3F4-4375-B1EC-D6DF0C821078}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{0844533D-E375-44ED-B3B9-E115CC8C03A2}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{0B84B913-97C0-427A-A231-DDD71D1BCEBE}" = dir=in | name=ebay | "{0BA9DD78-639F-4783-B4B4-441492DCF4E9}" = dir=in | name=music maker jam | "{10F51AF5-FA5D-4FC6-92B6-E2DA8AD9AC0A}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe | "{1562D40E-79DD-4845-9336-0750EBAAB43A}" = dir=out | name=ebay | "{194182FE-F8A5-415D-A55B-756DAA7F0BB5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{1F14DCA6-7485-4E51-8803-B1765244A5F5}" = dir=out | name=windows_ie_ac_001 | "{1FCD6BF7-18DC-4AD2-B26B-FE9AE490F46F}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{202C76FD-D565-4361-8874-876122CCABC3}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{2353E3BE-6CB6-4838-9EE3-6A680B9C994D}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{244648D2-91C9-4495-850C-2CEF4F7D3C34}" = dir=out | name=music maker jam | "{266070C5-41E9-4C3A-8805-59D5C870EF06}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{26EFED50-1282-46CA-A87F-CF537F4F2FA3}" = dir=out | name=accuweather for windows 8 | "{2A2A5324-68D3-4EFB-91A1-8E78BCBCA3DA}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{2AB1687F-F66D-4C24-B498-117CEEA8510E}" = dir=in | app=c:\program files (x86)\laplink\pcmover\pcmover.exe | "{2C1C0863-ACB0-4EA4-A3D3-55CC616461E1}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{2C77F7AB-D0DD-4756-85DA-ED78F8945CA5}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{2EE3001D-5A5D-498B-961B-DC46A9B8C7D9}" = protocol=58 | dir=in | app=system | "{31A8C68C-0E2A-44F4-B506-688317F6B7DA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3225A2B2-1C0B-45BF-BF37-90B9BF48D56F}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{33DCB526-E5EA-4148-A84B-0CD1394E7283}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{37A39DC7-1003-4603-B5AD-800C643FFDAA}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 | "{39F645D0-65A0-4D94-883E-3EB3F8BBE81F}" = dir=out | name=microsoft solitaire collection | "{3AB6E771-8EC6-4370-8D50-FBF88AF5FE3C}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{3AE3C468-CC90-477D-B065-FBF286B65DF7}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{401B25C7-71A3-4EC8-BA0A-A3D230D600DE}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{41596E60-3955-4F2B-80B7-905921F50243}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{438E2051-5224-4F27-99DB-67EEEDAA1937}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{444B5DB3-FC44-45F6-AF9F-4012B025986A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{57F1E900-6AF5-463E-B387-64022B7041EA}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{5A89A9C2-5F6C-4F8E-B38E-8F65EB0E1912}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{5C889934-4625-4655-AC86-136B03B4966A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{5F633249-5A99-446D-B457-8CC89EA630D3}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{611158C1-3B4F-4BE9-9AED-6DF977601802}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{624E8D26-5F44-48D5-8C2C-981EA2CCB4E7}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{6DEC399E-0853-4577-B536-AAC11CDF8C71}" = dir=in | name=@{microsoft.skypeapp_1.1.0.25_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{6EFEDA2C-2F1C-4E44-8997-0488850DDA90}" = dir=out | name=adera | "{7532DC3A-CB57-4D38-A94A-39CF9B8EAF66}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{775D916E-C2F9-442F-B668-BF5556F683BB}" = protocol=6 | dir=in | app=c:\windows\system32\supdsvc2.exe | "{7B8883AE-AE1E-4B31-9BC3-52B305706A23}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7BCD8BF1-F07A-4BE8-B674-F500AD46750A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{7DCFB2DE-B478-4009-8457-AF40D39D6BE7}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{7F1CCCEC-172B-4303-8397-C7247DA0F01D}" = dir=out | name=pinball fx2 | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{817625FD-175D-4D37-93D5-A3BE191C32DF}" = dir=out | name=@{microsoft.skypeapp_1.1.0.25_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{86039665-D3ED-4584-896E-E347897E04E9}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\pdvd10serv.exe | "{869E3A75-1936-4059-A462-EABFC6E11A18}" = dir=in | app=c:\program files\intel corporation\intel widi\widiapp.exe | "{8902D3F5-047D-4B1C-8F61-E816EA5F5665}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{8951D21A-D679-490F-B099-0A850CD0ABA3}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{8BF08C86-81C2-48C3-A3C3-F1F63F62469D}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{92A82894-784B-41F6-AD19-413D73758B2C}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{94A3041B-663C-468A-ACA3-BB68068B32D7}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | "{9C5D82EE-A858-41FE-8DDD-73DC820B03B2}" = dir=out | name=fresh paint | "{A66A3477-B187-4F98-9E6B-D092C80131BE}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{ABC74D6E-9A2C-4E8D-8603-5D98BEEC40D2}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{AD5DB2C2-E6CF-4D5E-8F5F-44E618EB7EFD}" = dir=out | name=powerdvd for medion | "{AEB1F279-484C-4599-B9E4-6CD4F0643027}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{B06D776F-4DF8-491A-8E61-3690F6922E12}" = dir=out | name=wordament | "{B8392CC2-AA50-4AAC-BA7E-995FD51B4B73}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{BC432C60-4C49-428A-AF60-80DF139C894A}" = dir=in | name=pinball fx2 | "{BD6CA211-7EFC-4C72-ADAC-A206B51FC453}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{BD75C830-F41F-4AB9-A5F9-D3E920378663}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{C18A70DD-534A-4C32-95DC-96DCBAAB8361}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr9.exe | "{C18D1F24-3C12-467C-BC95-1FF7786E3A43}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{C2172024-DBC6-49E1-9EF5-0B5E9E8CE31E}" = dir=out | name=taptiles | "{C37ED2E0-1436-4F48-9A2B-FA9AA34AD809}" = dir=out | name=youcam for medion | "{C3878C94-23F1-4313-893C-F46DF1A9EF30}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{C7354364-37CB-45E6-B0CD-F6BB4A949CC8}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{C7AFA6F8-E1A3-42D7-8555-DB3A3121FB4C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{CB1FD4B3-8FCE-44D8-B5E5-5061B6D93FBD}" = protocol=17 | dir=in | app=c:\windows\system32\supdsvc2.exe | "{D15A7A66-6132-4FFA-8C1B-67E0C75BFE7E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{D58EBA08-D403-45A4-9232-520EEB05E672}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\device\mediaserver\clmsserver.exe | "{DCFE1708-4456-4303-84BB-FCA22567A1DD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{DDB726E6-3742-4C85-8470-2D9975BF88B6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E04E09B1-AE32-4701-B5AD-4E198460375C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{E7E9A7D0-1B2B-4085-86DA-F45AB299316B}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe | "{E9C89A9E-817C-4DA4-836A-D88535331089}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{EA3B6C51-76A4-411F-890D-44B1759F4EE5}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{EB46D28F-DCDE-453F-8B22-9BC9B04291AC}" = dir=out | name=microsoft mahjong | "{EC5B1A4C-54B9-4742-A1DF-EACB0DF40398}" = dir=out | name=microsoft minesweeper | "{F282DBE2-6276-4005-B447-E4D67D4A7A01}" = protocol=6 | dir=out | app=system | "{F61CD37A-5817-4E16-BA26-77A7C4E05815}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{FB653721-54E8-4D60-B757-3C49E0406571}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FF16AB0E-38F9-4978-BAED-827F7DC506E5}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes "{1593C708-5535-47A4-8C0F-F8D4BE2B4560}" = Intel® PROSet/Wireless WiFi Software "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{23170F69-40C1-2702-0922-000001000000}" = 7-Zip 9.22 (x64 edition) "{26A24AE4-039D-4CA4-87B4-2F86417013FF}" = Java 7 Update 13 (64-bit) "{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = CyberLink PowerRecover "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6097158B-0184-4140-BEC3-7885794D2571}" = Intel(R) WiDi "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 307.17 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 307.17 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "{D0CB24F4-084F-40DE-B6B9-A03626E682F0}" = iCloud "{DA2600C1-6BDF-4FD1-8F3D-148929CC1385}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology "{E77289CF-12B9-4CAB-A49E-FEAE947F4D95}" = Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed "{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64 "{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client "CCleaner" = CCleaner "ProInst" = Intel PROSet Wireless "SynTPDeinstKey" = Synaptics Pointing Device Driver "ZoneAlarm LTD Toolbar" = ZoneAlarm LTD Toolbar [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam 5 "{03CC9D58-B132-4CC0-A521-4F3660AA43C7}" = Movie Maker "{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform "{061FF8F3-5226-4278-8AAB-282C1B024F58}" = Photo Common "{0DF95460-2887-4011-9344-1959CDF18ADC}" = Photo Common "{0E1BB4B4-00FF-45B1-914B-AB8D8B9862B3}" = Windows Live UX Platform Language Pack "{13F3CEA5-9E2C-4C4E-9F0F-D0DB389CF4A9}" = Movie Maker "{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser "{1F0C818D-4A41-4E40-BAFB-BB940C82A518}" = Fotogalerija "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema 10 "{1FEE19BC-6F0C-42E4-82FF-FB597F6141DF}" = Windows Live Essentials "{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1 "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8 "{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery "{39337565-330E-4ab6-A9AE-AC81E0720B10}" = CyberLink PhotoDirector 3 "{3C63F944-803E-49A7-B3A2-B8AB3313E883}" = Windows Live UX Platform Language Pack "{3CBD94C1-BA15-488C-888B-D8DD296CC6DC}" = Fotogalerie "{3D4F3F4C-E364-4E46-BFB1-A00BF9777422}" = Windows Live UX Platform Language Pack "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{446CC8CE-0E90-44F7-ADD0-774B243EF090}" = Galerie de photos "{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple Application Support "{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}" = Google Earth "{49110532-D289-4BFF-807C-45B782E66A7C}" = Photo Common "{49F068F2-4323-417B-AFC8-1E43F479D46C}" = Windows Live Essentials "{4AA2A466-8031-403A-8236-5301B4E391FB}" = Windows Live UX Platform Language Pack "{4AF53C99-315D-4536-873F-029D2D274AE2}" = Photo Common "{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform "{63824BC0-B747-43F3-9863-1066D64AD919}" = Photo Gallery "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{690F5BA3-5DEB-42CD-962B-F687EE59FAA7}" = Windows Live Essentials "{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform "{6CEA775F-E70A-4D72-A3B4-1EB3A5AD4B5C}" = Windows Live Essentials "{701FE1BC-834A-4857-AF62-6EBA50CFBC78}" = Movie Maker "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{715F9B21-2817-402A-9BF0-BDA764D21F09}" = Windows Live Essentials "{743FD554-A73F-4FE8-BE7B-C283D16297F9}" = Photo Common "{751EB657-3F22-4150-8CE4-D79A262F1D92}" = Movie Maker "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7E63F102-A9E9-4F4C-8004-BC62974736BF}" = Movie Maker "{7E9A63B3-8572-4A4B-9F87-3C2A873BBC55}" = Windows Live UX Platform Language Pack "{8063EB67-E777-4A56-9C1E-FAD75C2F5EC2}" = Photo Common "{857BC375-BCFB-474E-9BD9-7EBB18EC55E0}" = Windows Live Essentials "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions "{8D813AFF-D91D-4EE0-821F-B901FC2E89FA}" = Windows Live "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110 "{8E6E8CBB-8E58-493C-943F-4664F5F2FEDB}" = Movie Maker "{8F7FECEC-088F-431D-A5FB-2B59E1E69943}" = Galería de fotos "{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0407-1000-0000000FF1CE}_Office14.SingleImage_{594128C9-2CDF-43CE-8103-DC100CF013B6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010 "{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90993BD9-C7D9-4C2F-B56C-2F7AFEBD4CD0}" = Windows Live UX Platform Language Pack "{94ED52E0-24A0-4AD8-9BFD-0560CA680A80}" = ArcSoft TV 5.0 "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A17946CA-18E5-4CF0-8D55-A56D804718F8}" = Movie Maker "{A47EA9D4-BB87-415E-9239-28860434E5A0}" = Movie Maker "{A802F1E3-34C8-4C84-9948-C1C4E37D0FA9}" = QuickLaunch "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime "{AC2C8B53-E04D-4A84-B791-1741493D25DF}" = PCmover Home "{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.02) - Deutsch "{AE8044B5-FCA3-4EBE-AC78-0FB3A6E8DC76}" = Movie Maker "{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}" = RealDownloader "{B096A0E4-26A1-4E9F-8548-577964B9434B}" = Windows Live Essentials "{B26438B4-BF51-49C3-9567-7F14A5E40CB9}" = Dolby Home Theater v4 "{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB "{B727564C-47D3-473A-AC9E-F4BE7B1BD5D3}" = Windows Live UX Platform Language Pack "{B7F31B9C-8775-4500-8E9D-6ABE9AE17CF4}" = Windows Live Essentials "{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint 2.5 "{C7929038-EDFB-416D-A2C9-CC65416DA0DF}" = Photo Common "{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common "{CE542E0D-E056-4426-9F98-084C13E18641}" = Windows Live UX Platform Language Pack "{D04EBB49-C985-4A38-8695-62000861293A}" = Raccolta foto "{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10 "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E0E0FB88-D570-463E-A98E-733B7B656867}" = Photo Gallery "{E1203F8C-FF34-4968-A4A5-B4F1F8533DAB}" = Photo Common "{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso 6.5 "{E3D04529-6EDB-11D8-A372-0050BAE317E1}" = CyberLink PowerDVD Copy 1.5 "{E50C224A-BBF2-428D-9DCF-DBF9DF85C40E}" = PHotkey "{E50E3DBC-46AA-4827-B2A6-F995D81DF526}" = Fotótár "{E864A1C8-EEE1-47D0-A7F8-00CC86D26D5E}_is1" = Wise Care 365 version 2.31 "{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker "{EFFED0C0-5299-422E-AFE6-8B8066D18A2A}" = Mediathek "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F21F0424-B2FF-40BF-A984-9E0D7FB4C97E}" = Windows Live UX Platform Language Pack "{F54030F3-14B6-432D-9361-78DCB1473920}" = Photo Common "{F67CA22C-C11F-4573-8406-57F75BA06B51}" = Photo Gallery "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package "{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Ashampoo AppLauncher (Medion)_is1" = Ashampoo AppLauncher (Medion) v.1.0.0 "avast" = avast! Internet Security "B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind "Decor8" = Decor8 "Google Chrome" = Google Chrome "InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}" = CyberLink PhotoDirector 3 "InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = CyberLink PowerRecover "InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}" = Medion Home Cinema 10 "InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "lrcspal@xinghao.net" = LyricsPal "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300 "McAfee Security Scan" = McAfee Security Scan Plus "Mozilla Firefox 20.0.1 (x86 de)" = Mozilla Firefox 20.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Office14.SingleImage" = Microsoft Office Home and Student 2010 "RealPlayer 16.0" = RealPlayer "Samsung CLP-320 Series" = Wartung Samsung CLP-320 Series "WinLiveSuite" = Windows Live Essentials ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 22.04.2013 01:35:54 | Computer Name = Astrid | Source = SideBySide | ID = 16842785 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". [ System Events ] Error - 22.04.2013 01:50:25 | Computer Name = Astrid | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 22.04.2013 01:50:55 | Computer Name = Astrid | Source = Service Control Manager | ID = 7000 Description = Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 22.04.2013 01:51:00 | Computer Name = Astrid | Source = Service Control Manager | ID = 7000 Description = Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 22.04.2013 01:56:29 | Computer Name = Astrid | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 22.04.2013 01:56:58 | Computer Name = Astrid | Source = Service Control Manager | ID = 7000 Description = Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 22.04.2013 01:57:14 | Computer Name = Astrid | Source = Service Control Manager | ID = 7000 Description = Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 < End of report > Hier kommen die files: Code:
ATTFilter OTL Extras logfile created on: 22.04.2013 08:31:33 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Astrid-Coach\Desktop 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16540) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,89 Gb Total Physical Memory | 6,09 Gb Available Physical Memory | 77,25% Memory free 15,89 Gb Paging File | 14,02 Gb Available in Paging File | 88,25% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 869,80 Gb Total Space | 798,76 Gb Free Space | 91,83% Space Free | Partition Type: NTFS Drive D: | 60,00 Gb Total Space | 40,90 Gb Free Space | 68,16% Space Free | Partition Type: NTFS Computer Name: ASTRID | User Name: Astrid-Coach | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1435033098-840508067-3058036539-1002\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1212CC03-871F-4276-A446-8D26C81BC6FA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{16343735-E6BC-4BF6-AB82-B585588DF1A4}" = rport=139 | protocol=6 | dir=out | app=system | "{1EC42E47-9194-4F02-B2DA-98DC73E06634}" = rport=138 | protocol=17 | dir=out | app=system | "{202B5A30-F5B0-4D6B-B36D-3FCEE6BEBB76}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{2A3FB734-6A05-48FC-9774-C32698627DD7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2A7BA9D9-4977-4665-8DD0-E6014303AA72}" = rport=10243 | protocol=6 | dir=out | app=system | "{419BC377-5D0F-4C69-A4AE-33D2E7F42CB7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{55E96179-8C41-4C22-BE95-77CA36762D58}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5FBDD534-3EBB-479A-B649-AFE033CD1FAB}" = rport=137 | protocol=17 | dir=out | app=system | "{89075959-3BDA-4689-A8CC-FA91AFC7AC58}" = lport=2869 | protocol=6 | dir=in | app=system | "{89ED1B9A-6D90-438C-AC44-267956878D10}" = lport=445 | protocol=6 | dir=in | app=system | "{8CAD0ED7-7FAE-4BDF-B7F6-B6AD64B20713}" = rport=445 | protocol=6 | dir=out | app=system | "{A2C96B23-7BFC-4521-A7A7-0F1EB3CFF8B0}" = lport=10243 | protocol=6 | dir=in | app=system | "{ADFF30D8-2932-4850-B1C9-5D1739E1C30A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B18286CA-57CF-4EB2-A4ED-192F702A7833}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B52DB6FB-9BD0-4FCF-97DB-34D933B1464C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{B729D9E4-052E-4A53-B391-331DD080613A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{BE34FC85-DF1C-4171-A739-743C1B8E6419}" = lport=138 | protocol=17 | dir=in | app=system | "{CD4342CD-16C2-4129-9228-7EFB05504CBC}" = lport=139 | protocol=6 | dir=in | app=system | "{D61DE085-B5D0-4C60-AFBD-C62898F4B833}" = lport=137 | protocol=17 | dir=in | app=system | "{D8F7672F-14C6-4F17-9058-61D04236F5AF}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{DD411DF8-5638-4E1B-955B-A143E18D1E75}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{E5927AC1-9F11-402F-8D8D-15DC242D4743}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{EEB76AC2-8660-454F-9D3D-0D01A02C499A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{EFA69EAC-2C86-4F01-A310-10BB981E712E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07874BCD-A3F4-4375-B1EC-D6DF0C821078}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{0844533D-E375-44ED-B3B9-E115CC8C03A2}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{0B84B913-97C0-427A-A231-DDD71D1BCEBE}" = dir=in | name=ebay | "{0BA9DD78-639F-4783-B4B4-441492DCF4E9}" = dir=in | name=music maker jam | "{10F51AF5-FA5D-4FC6-92B6-E2DA8AD9AC0A}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe | "{1562D40E-79DD-4845-9336-0750EBAAB43A}" = dir=out | name=ebay | "{194182FE-F8A5-415D-A55B-756DAA7F0BB5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{1F14DCA6-7485-4E51-8803-B1765244A5F5}" = dir=out | name=windows_ie_ac_001 | "{1FCD6BF7-18DC-4AD2-B26B-FE9AE490F46F}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{202C76FD-D565-4361-8874-876122CCABC3}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{2353E3BE-6CB6-4838-9EE3-6A680B9C994D}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{244648D2-91C9-4495-850C-2CEF4F7D3C34}" = dir=out | name=music maker jam | "{266070C5-41E9-4C3A-8805-59D5C870EF06}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{26EFED50-1282-46CA-A87F-CF537F4F2FA3}" = dir=out | name=accuweather for windows 8 | "{2A2A5324-68D3-4EFB-91A1-8E78BCBCA3DA}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{2AB1687F-F66D-4C24-B498-117CEEA8510E}" = dir=in | app=c:\program files (x86)\laplink\pcmover\pcmover.exe | "{2C1C0863-ACB0-4EA4-A3D3-55CC616461E1}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{2C77F7AB-D0DD-4756-85DA-ED78F8945CA5}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{2EE3001D-5A5D-498B-961B-DC46A9B8C7D9}" = protocol=58 | dir=in | app=system | "{31A8C68C-0E2A-44F4-B506-688317F6B7DA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3225A2B2-1C0B-45BF-BF37-90B9BF48D56F}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{33DCB526-E5EA-4148-A84B-0CD1394E7283}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{37A39DC7-1003-4603-B5AD-800C643FFDAA}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 | "{39F645D0-65A0-4D94-883E-3EB3F8BBE81F}" = dir=out | name=microsoft solitaire collection | "{3AB6E771-8EC6-4370-8D50-FBF88AF5FE3C}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{3AE3C468-CC90-477D-B065-FBF286B65DF7}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{401B25C7-71A3-4EC8-BA0A-A3D230D600DE}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{41596E60-3955-4F2B-80B7-905921F50243}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{438E2051-5224-4F27-99DB-67EEEDAA1937}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{444B5DB3-FC44-45F6-AF9F-4012B025986A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{57F1E900-6AF5-463E-B387-64022B7041EA}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{5A89A9C2-5F6C-4F8E-B38E-8F65EB0E1912}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{5C889934-4625-4655-AC86-136B03B4966A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{5F633249-5A99-446D-B457-8CC89EA630D3}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{611158C1-3B4F-4BE9-9AED-6DF977601802}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{624E8D26-5F44-48D5-8C2C-981EA2CCB4E7}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{6DEC399E-0853-4577-B536-AAC11CDF8C71}" = dir=in | name=@{microsoft.skypeapp_1.1.0.25_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{6EFEDA2C-2F1C-4E44-8997-0488850DDA90}" = dir=out | name=adera | "{7532DC3A-CB57-4D38-A94A-39CF9B8EAF66}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{775D916E-C2F9-442F-B668-BF5556F683BB}" = protocol=6 | dir=in | app=c:\windows\system32\supdsvc2.exe | "{7B8883AE-AE1E-4B31-9BC3-52B305706A23}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7BCD8BF1-F07A-4BE8-B674-F500AD46750A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{7DCFB2DE-B478-4009-8457-AF40D39D6BE7}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{7F1CCCEC-172B-4303-8397-C7247DA0F01D}" = dir=out | name=pinball fx2 | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{817625FD-175D-4D37-93D5-A3BE191C32DF}" = dir=out | name=@{microsoft.skypeapp_1.1.0.25_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{86039665-D3ED-4584-896E-E347897E04E9}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\pdvd10serv.exe | "{869E3A75-1936-4059-A462-EABFC6E11A18}" = dir=in | app=c:\program files\intel corporation\intel widi\widiapp.exe | "{8902D3F5-047D-4B1C-8F61-E816EA5F5665}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{8951D21A-D679-490F-B099-0A850CD0ABA3}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{8BF08C86-81C2-48C3-A3C3-F1F63F62469D}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{92A82894-784B-41F6-AD19-413D73758B2C}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{94A3041B-663C-468A-ACA3-BB68068B32D7}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | "{9C5D82EE-A858-41FE-8DDD-73DC820B03B2}" = dir=out | name=fresh paint | "{A66A3477-B187-4F98-9E6B-D092C80131BE}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{ABC74D6E-9A2C-4E8D-8603-5D98BEEC40D2}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{AD5DB2C2-E6CF-4D5E-8F5F-44E618EB7EFD}" = dir=out | name=powerdvd for medion | "{AEB1F279-484C-4599-B9E4-6CD4F0643027}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{B06D776F-4DF8-491A-8E61-3690F6922E12}" = dir=out | name=wordament | "{B8392CC2-AA50-4AAC-BA7E-995FD51B4B73}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{BC432C60-4C49-428A-AF60-80DF139C894A}" = dir=in | name=pinball fx2 | "{BD6CA211-7EFC-4C72-ADAC-A206B51FC453}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{BD75C830-F41F-4AB9-A5F9-D3E920378663}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{C18A70DD-534A-4C32-95DC-96DCBAAB8361}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr9.exe | "{C18D1F24-3C12-467C-BC95-1FF7786E3A43}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{C2172024-DBC6-49E1-9EF5-0B5E9E8CE31E}" = dir=out | name=taptiles | "{C37ED2E0-1436-4F48-9A2B-FA9AA34AD809}" = dir=out | name=youcam for medion | "{C3878C94-23F1-4313-893C-F46DF1A9EF30}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{C7354364-37CB-45E6-B0CD-F6BB4A949CC8}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{C7AFA6F8-E1A3-42D7-8555-DB3A3121FB4C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{CB1FD4B3-8FCE-44D8-B5E5-5061B6D93FBD}" = protocol=17 | dir=in | app=c:\windows\system32\supdsvc2.exe | "{D15A7A66-6132-4FFA-8C1B-67E0C75BFE7E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{D58EBA08-D403-45A4-9232-520EEB05E672}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\device\mediaserver\clmsserver.exe | "{DCFE1708-4456-4303-84BB-FCA22567A1DD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{DDB726E6-3742-4C85-8470-2D9975BF88B6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E04E09B1-AE32-4701-B5AD-4E198460375C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{E7E9A7D0-1B2B-4085-86DA-F45AB299316B}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe | "{E9C89A9E-817C-4DA4-836A-D88535331089}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{EA3B6C51-76A4-411F-890D-44B1759F4EE5}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{EB46D28F-DCDE-453F-8B22-9BC9B04291AC}" = dir=out | name=microsoft mahjong | "{EC5B1A4C-54B9-4742-A1DF-EACB0DF40398}" = dir=out | name=microsoft minesweeper | "{F282DBE2-6276-4005-B447-E4D67D4A7A01}" = protocol=6 | dir=out | app=system | "{F61CD37A-5817-4E16-BA26-77A7C4E05815}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{FB653721-54E8-4D60-B757-3C49E0406571}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FF16AB0E-38F9-4978-BAED-827F7DC506E5}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes "{1593C708-5535-47A4-8C0F-F8D4BE2B4560}" = Intel® PROSet/Wireless WiFi Software "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{23170F69-40C1-2702-0922-000001000000}" = 7-Zip 9.22 (x64 edition) "{26A24AE4-039D-4CA4-87B4-2F86417013FF}" = Java 7 Update 13 (64-bit) "{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = CyberLink PowerRecover "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6097158B-0184-4140-BEC3-7885794D2571}" = Intel(R) WiDi "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 307.17 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 307.17 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "{D0CB24F4-084F-40DE-B6B9-A03626E682F0}" = iCloud "{DA2600C1-6BDF-4FD1-8F3D-148929CC1385}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology "{E77289CF-12B9-4CAB-A49E-FEAE947F4D95}" = Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed "{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64 "{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client "CCleaner" = CCleaner "ProInst" = Intel PROSet Wireless "SynTPDeinstKey" = Synaptics Pointing Device Driver "ZoneAlarm LTD Toolbar" = ZoneAlarm LTD Toolbar [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam 5 "{03CC9D58-B132-4CC0-A521-4F3660AA43C7}" = Movie Maker "{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform "{061FF8F3-5226-4278-8AAB-282C1B024F58}" = Photo Common "{0DF95460-2887-4011-9344-1959CDF18ADC}" = Photo Common "{0E1BB4B4-00FF-45B1-914B-AB8D8B9862B3}" = Windows Live UX Platform Language Pack "{13F3CEA5-9E2C-4C4E-9F0F-D0DB389CF4A9}" = Movie Maker "{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser "{1F0C818D-4A41-4E40-BAFB-BB940C82A518}" = Fotogalerija "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema 10 "{1FEE19BC-6F0C-42E4-82FF-FB597F6141DF}" = Windows Live Essentials "{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1 "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8 "{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery "{39337565-330E-4ab6-A9AE-AC81E0720B10}" = CyberLink PhotoDirector 3 "{3C63F944-803E-49A7-B3A2-B8AB3313E883}" = Windows Live UX Platform Language Pack "{3CBD94C1-BA15-488C-888B-D8DD296CC6DC}" = Fotogalerie "{3D4F3F4C-E364-4E46-BFB1-A00BF9777422}" = Windows Live UX Platform Language Pack "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{446CC8CE-0E90-44F7-ADD0-774B243EF090}" = Galerie de photos "{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple Application Support "{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}" = Google Earth "{49110532-D289-4BFF-807C-45B782E66A7C}" = Photo Common "{49F068F2-4323-417B-AFC8-1E43F479D46C}" = Windows Live Essentials "{4AA2A466-8031-403A-8236-5301B4E391FB}" = Windows Live UX Platform Language Pack "{4AF53C99-315D-4536-873F-029D2D274AE2}" = Photo Common "{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform "{63824BC0-B747-43F3-9863-1066D64AD919}" = Photo Gallery "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{690F5BA3-5DEB-42CD-962B-F687EE59FAA7}" = Windows Live Essentials "{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform "{6CEA775F-E70A-4D72-A3B4-1EB3A5AD4B5C}" = Windows Live Essentials "{701FE1BC-834A-4857-AF62-6EBA50CFBC78}" = Movie Maker "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{715F9B21-2817-402A-9BF0-BDA764D21F09}" = Windows Live Essentials "{743FD554-A73F-4FE8-BE7B-C283D16297F9}" = Photo Common "{751EB657-3F22-4150-8CE4-D79A262F1D92}" = Movie Maker "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7E63F102-A9E9-4F4C-8004-BC62974736BF}" = Movie Maker "{7E9A63B3-8572-4A4B-9F87-3C2A873BBC55}" = Windows Live UX Platform Language Pack "{8063EB67-E777-4A56-9C1E-FAD75C2F5EC2}" = Photo Common "{857BC375-BCFB-474E-9BD9-7EBB18EC55E0}" = Windows Live Essentials "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions "{8D813AFF-D91D-4EE0-821F-B901FC2E89FA}" = Windows Live "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110 "{8E6E8CBB-8E58-493C-943F-4664F5F2FEDB}" = Movie Maker "{8F7FECEC-088F-431D-A5FB-2B59E1E69943}" = Galería de fotos "{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0407-1000-0000000FF1CE}_Office14.SingleImage_{594128C9-2CDF-43CE-8103-DC100CF013B6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010 "{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90993BD9-C7D9-4C2F-B56C-2F7AFEBD4CD0}" = Windows Live UX Platform Language Pack "{94ED52E0-24A0-4AD8-9BFD-0560CA680A80}" = ArcSoft TV 5.0 "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A17946CA-18E5-4CF0-8D55-A56D804718F8}" = Movie Maker "{A47EA9D4-BB87-415E-9239-28860434E5A0}" = Movie Maker "{A802F1E3-34C8-4C84-9948-C1C4E37D0FA9}" = QuickLaunch "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime "{AC2C8B53-E04D-4A84-B791-1741493D25DF}" = PCmover Home "{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.02) - Deutsch "{AE8044B5-FCA3-4EBE-AC78-0FB3A6E8DC76}" = Movie Maker "{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}" = RealDownloader "{B096A0E4-26A1-4E9F-8548-577964B9434B}" = Windows Live Essentials "{B26438B4-BF51-49C3-9567-7F14A5E40CB9}" = Dolby Home Theater v4 "{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB "{B727564C-47D3-473A-AC9E-F4BE7B1BD5D3}" = Windows Live UX Platform Language Pack "{B7F31B9C-8775-4500-8E9D-6ABE9AE17CF4}" = Windows Live Essentials "{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint 2.5 "{C7929038-EDFB-416D-A2C9-CC65416DA0DF}" = Photo Common "{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common "{CE542E0D-E056-4426-9F98-084C13E18641}" = Windows Live UX Platform Language Pack "{D04EBB49-C985-4A38-8695-62000861293A}" = Raccolta foto "{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10 "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E0E0FB88-D570-463E-A98E-733B7B656867}" = Photo Gallery "{E1203F8C-FF34-4968-A4A5-B4F1F8533DAB}" = Photo Common "{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso 6.5 "{E3D04529-6EDB-11D8-A372-0050BAE317E1}" = CyberLink PowerDVD Copy 1.5 "{E50C224A-BBF2-428D-9DCF-DBF9DF85C40E}" = PHotkey "{E50E3DBC-46AA-4827-B2A6-F995D81DF526}" = Fotótár "{E864A1C8-EEE1-47D0-A7F8-00CC86D26D5E}_is1" = Wise Care 365 version 2.31 "{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker "{EFFED0C0-5299-422E-AFE6-8B8066D18A2A}" = Mediathek "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F21F0424-B2FF-40BF-A984-9E0D7FB4C97E}" = Windows Live UX Platform Language Pack "{F54030F3-14B6-432D-9361-78DCB1473920}" = Photo Common "{F67CA22C-C11F-4573-8406-57F75BA06B51}" = Photo Gallery "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package "{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Ashampoo AppLauncher (Medion)_is1" = Ashampoo AppLauncher (Medion) v.1.0.0 "avast" = avast! Internet Security "B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind "Decor8" = Decor8 "Google Chrome" = Google Chrome "InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}" = CyberLink PhotoDirector 3 "InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = CyberLink PowerRecover "InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}" = Medion Home Cinema 10 "InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "lrcspal@xinghao.net" = LyricsPal "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300 "McAfee Security Scan" = McAfee Security Scan Plus "Mozilla Firefox 20.0.1 (x86 de)" = Mozilla Firefox 20.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Office14.SingleImage" = Microsoft Office Home and Student 2010 "RealPlayer 16.0" = RealPlayer "Samsung CLP-320 Series" = Wartung Samsung CLP-320 Series "WinLiveSuite" = Windows Live Essentials ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 22.04.2013 01:35:54 | Computer Name = Astrid | Source = SideBySide | ID = 16842785 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". [ System Events ] Error - 22.04.2013 01:50:25 | Computer Name = Astrid | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 22.04.2013 01:50:55 | Computer Name = Astrid | Source = Service Control Manager | ID = 7000 Description = Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 22.04.2013 01:51:00 | Computer Name = Astrid | Source = Service Control Manager | ID = 7000 Description = Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 22.04.2013 01:56:29 | Computer Name = Astrid | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 22.04.2013 01:56:58 | Computer Name = Astrid | Source = Service Control Manager | ID = 7000 Description = Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 22.04.2013 01:57:14 | Computer Name = Astrid | Source = Service Control Manager | ID = 7000 Description = Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 < End of report > |
22.04.2013, 07:50 | #24 |
| ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen hier sind die anderen beiden als zip dateien. Gruß und DANKE! Ahnungslos61 |
22.04.2013, 11:21 | #25 |
/// Winkelfunktion /// TB-Süch-Tiger™ | ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen Log vom adwCleaner fehelt, bitte nachreichen, in CODE-Tags posten
__________________ Logfiles bitte immer in CODE-Tags posten |
22.04.2013, 11:37 | #26 |
| ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen ..hier kommt adwcleaner: DANKE + Gruß Code:
ATTFilter # AdwCleaner v2.201 - Datei am 22/04/2013 um 07:49:10 erstellt # Aktualisiert am 21/04/2013 von Xplode # Betriebssystem : Windows 8 (64 bits) # Benutzer : Astrid-Coach - ASTRID # Bootmodus : Normal # Ausgeführt unter : C:\Users\Astrid-Coach\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Users\Astrid-Coach\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data Datei Gelöscht : C:\Users\Astrid-Coach\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences Datei Gelöscht : C:\Users\Astrid-Coach\AppData\Roaming\Mozilla\Firefox\Profiles\l05874jm.default\searchplugins\11-suche.xml Datei Gelöscht : C:\Users\Astrid-Coach\Desktop\Check for Updates.lnk Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\BI Schlüssel Gelöscht : HKCU\Software\DataMngr Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar Schlüssel Gelöscht : HKCU\Software\Delta Schlüssel Gelöscht : HKCU\Software\delta LTD Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKCU\Software\5855dcdbb33fef10 Schlüssel Gelöscht : HKLM\Software\AVG Secure Search Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\Delta Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\5855dcdbb33fef10 Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Delta Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope] ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16537 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v20.0.1 (de) Datei : C:\Users\Astrid-Coach\AppData\Roaming\Mozilla\Firefox\Profiles\l05874jm.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v26.0.1410.64 Datei : C:\Users\Astrid-Coach\AppData\Local\Google\Chrome\User Data\Default\Preferences Gelöscht [l.2395] : homepage = "hxxp://www1.delta-search.com/?affID=119816&tt=180413_new&babsrc=HP_ss&mntrId=3C2284A[...] Gelöscht [l.2732] : urls_to_restore_on_startup ="session": {"restore_on_startup": 4, [ "hxxp://www1.delta-search.co[...] ************************* AdwCleaner[S1].txt - [5305 octets] - [22/04/2013 07:49:10] ########## EOF - C:\AdwCleaner[S1].txt - [5365 octets] ########## |
22.04.2013, 13:52 | #27 |
/// Winkelfunktion /// TB-Süch-Tiger™ | ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes - denk bitte vorher daran, Malwarebytes über den Updatebutton zu aktualisieren Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
22.04.2013, 21:05 | #28 |
| ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen Erst lief malwarebytes, das kam raus. Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.04.22.04 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16540 Astrid-Coach :: ASTRID [Administrator] Schutz: Aktiviert 22.04.2013 15:13:40 mbam-log-2013-04-22 (15-13-40).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 234420 Laufzeit: 3 Minute(n), 36 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Gruß und Gute Nacht! Ahnungslos61 Code:
ATTFilter C:\Program Files (x86)\XingHaoLyrics\XingHaoUpdater.exe a variant of Win32/Adware.AddLyrics.B application Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=0dc7dea754147f4c90ee5fb038f5d598 # engine=13671 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-04-22 07:11:21 # local_time=2013-04-22 09:11:21 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.2.9200 NT # compatibility_mode=772 16777213 83 94 47689 143371353 0 0 # compatibility_mode=5893 16776574 100 94 2290390 15385197 0 0 # scanned=247762 # found=1 # cleaned=0 # scan_time=11273 sh=9383ABC24228D36FBBDD41786D3766DE732AAB85 ft=1 fh=98f533f53e657a33 vn="a variant of Win32/Adware.AddLyrics.B application" ac=I fn="C:\Program Files (x86)\XingHaoLyrics\XingHaoUpdater.exe" |
22.04.2013, 21:49 | #29 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassenZitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
23.04.2013, 06:39 | #30 |
| ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen Ich bin bei XIng angemeldet (Social Network). Ist es das? Ein "Programm" dazu kenne ich nicht. Es ist wie facebook. Soll ich es mal anstarten? Oder löschen und gucken was passiert? DANKE und Gruß aus Gonsenheim. Ahnungslos61 |
Themen zu ZeuS/Zbot Trojaner, was tun? Avira schon durchlaufen lassen |
ahnungslos, avira, deutsche, deutschen, entdeck, entdeckt, firma, https, link, mail, mailanhang, neu, paypal, programm, rechner, relativ, schickt, schäden, telekom, troja, trojaner, umgang, was tun, was tun?, windows, zbot-trojaner, zeus trojaner, zeus/zbot |