Plagegeister aller Art und deren Bekämpfung: Hilfe bei der Entfernung von Spyhunter!
| ![]() Hilfe bei der Entfernung von Spyhunter! Hallo, seit ein paar Tagen hatten wir den Toolbar von search conduit auf dem Laptop - bei der Recherche, diesen wieder zu entfernen, bin ich auf spyhunter4 gestoßen und habe diesen runtergeladen. Nach weiterer Recherche habe ich dann festgestellt, dass ich die Sache damit schlimmer gemacht habe. Im 1. Versuch habe ich eine Systemwiederherstellung auf einen Zeitpunkt vor der Installation gemacht (habe allerdings hier im Forum gelesen, dass das nichts bringt; zumindest taucht Spyhunter nun nicht mehr unter "Programme" auf). Ansonsten läuft der Laptop gefühlt auch ganz normal, nur das Hochfahren dauert länger als sonst. Da ich unsicher bin, ob noch eine Infizierung vorliegt, wäre ich für Hilfe dankbar. Schritt 1 "defogger" habe ich installiert und "disable" geklickt. Es kam die Meldung "finished", Eine Fehlermldlung kam nicht. Schritt 2 OTL-Quick Scan habe ich durchgeführt. Schritt 3 "Gmer" habe ich ebenfalls durchgeführt. Vielen Dank schonmal vorab!! |
Hallo und
__________________![]() Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die jemals fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs posten! ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
| ![]() Hilfe bei der Entfernung von Spyhunter! Vielen Dank für die schnelle Antwort und die Erklärung, wie ich die Dateitexte direkt einfügen kann!! Soll ich die bereits versandten noch mal direkt einfügen?
__________________Ich habe von gestern abend nach der Systemzurücksetzung einen Log von Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.05.14.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 samsung :: SAMSUNG-PC [Administrator] 15.05.2013 00:00:20 mbam-log-2013-05-15 (00-00-20).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 240567 Laufzeit: 3 Minute(n), 59 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
Note: Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread. Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards. Bitte die drei Tools MBAR / aswMBR / TDSSkiller nun ausführen und die Logs in CODE-Tags posten MBAR (Malwarebytes Anti-Rootkit) Downloade dir bitte ![]()
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers aswMBR Downloade dir bitte ![]()
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). TDSS-Killer Downloade dir bitte ![]()
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
| ![]() Hilfe bei der Entfernung von Spyhunter! Hallo, 1. Schritt: Malwarebytes AntiRoot-Kit: Beim Öffnen kam folgende Meldung Zitat:
ATTFilter aswMBR version Copyright(c) 2011 AVAST Software Run date: 2013-05-15 21:59:38 ----------------------------- 21:59:38.840 OS Version: Windows x64 6.1.7601 Service Pack 1 21:59:38.840 Number of processors: 4 586 0x3A09 21:59:38.840 ComputerName: SAMSUNG-PC UserName: samsung 21:59:40.387 Initialize success 22:00:33.167 AVAST engine defs: 13051500 22:00:57.949 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 22:00:57.952 Disk 0 Vendor: Hitachi_ JF4O Size: 715404MB BusType: 3 22:00:58.038 Disk 0 MBR read successfully 22:00:58.041 Disk 0 MBR scan 22:00:58.048 Disk 0 unknown MBR code 22:00:58.052 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 22:00:58.067 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 688443 MB offset 206848 22:00:58.094 Disk 0 Partition 3 00 27 Hidden NTFS WinRE NTFS 26860 MB offset 1410138112 22:00:58.195 Disk 0 scanning C:\windows\system32\drivers 22:01:08.129 Service scanning 22:01:33.522 Modules scanning 22:01:33.532 Disk 0 trace - called modules: 22:01:33.592 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll 22:01:33.602 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008c32790] 22:01:33.612 3 CLASSPNP.SYS[fffff88001c8343f] -> nt!IofCallDriver -> [0xfffffa800790b950] 22:01:33.612 5 ACPI.sys[fffff88000d657a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8008c31050] 22:01:35.302 AVAST engine scan C:\windows 22:01:38.863 AVAST engine scan C:\windows\system32 22:04:02.097 AVAST engine scan C:\windows\system32\drivers 22:04:14.229 AVAST engine scan C:\Users\samsung 22:10:09.421 AVAST engine scan C:\ProgramData 22:11:13.560 Scan finished successfully 22:11:54.624 Disk 0 MBR has been saved successfully to "C:\Users\samsung\Desktop\MBR.dat" 22:11:54.634 The log file has been saved successfully to "C:\Users\samsung\Desktop\aswMBR.txt" 3. Schritt: TDSS Killer Code:
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Hilfe bei der Entfernung von Spyhunter! JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Im Anschluss: adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen Downloade Dir bitte ![]()
Danach eine Kontrolle mit OTL bitte:
__________________ --> Hilfe bei der Entfernung von Spyhunter! |
Hilfe bei der Entfernung von Spyhunter! So, hier die Logs:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Home Premium x64 Ran by samsung on 15.05.2013 at 22:59:55,37 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-808812791-3364131652-3434471583-1001\Software\Microsoft\Internet Explorer\Main\\Start Page ~~~ Registry Keys ~~~ Files Successfully deleted: [File] C:\install.res.1028.dll Successfully deleted: [File] C:\install.res.1031.dll Successfully deleted: [File] C:\install.res.1033.dll Successfully deleted: [File] C:\install.res.1036.dll Successfully deleted: [File] C:\install.res.1040.dll Successfully deleted: [File] C:\install.res.1041.dll Successfully deleted: [File] C:\install.res.1042.dll Successfully deleted: [File] C:\install.res.2052.dll Successfully deleted: [File] C:\install.res.3082.dll ~~~ Folders Successfully deleted: [Folder] "C:\Program Files (x86)\filesfrog update checker" Successfully deleted: [Empty Folder] C:\Users\samsung\appdata\local\{68B8DFEC-F63B-480B-894B-401ADFADD25B} Successfully deleted: [Empty Folder] C:\Users\samsung\appdata\local\{B2987B00-BD35-4BC2-AB4F-EFD3E259240F} ~~~ FireFox Successfully deleted: [File] C:\Users\samsung\AppData\Roaming\mozilla\firefox\profiles\6zq7cneh.default\invalidprefs.js Emptied folder: C:\Users\samsung\AppData\Roaming\mozilla\firefox\profiles\6zq7cneh.default\minidumps [141 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 15.05.2013 at 23:03:36,88 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 2. AdwCleaner (Es öffnete sich direkt der Log, auf Löschen konnte ich nicht klicken. Da die Dateien fortlaufend nummeriert sind und die neue Datei R[5] ist, gab es offenbar vorherige Versionen... die Datei R[4] habe ich gefunden; ich hatte das Programm offenbar am Vorabend schon laufen lassen... das wusste ich leider nicht mehr, sorry. Habe R[4] vorsichtshalber auch beigefügt. R[1]- R[3], die es dann wohl auch gegeben haben müsste, sind nicht mehr auf dem PC) AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.300 - Datei am 14/05/2013 um 23:49:54 erstellt # Aktualisiert am 28/04/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : samsung - SAMSUNG-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\samsung\Downloads\adwcleaner_2.3.0.0.exe # Option [Suche] **** [Dienste] **** Gefunden : Yontoo Desktop Updater ***** [Dateien / Ordner] ***** Datei Gefunden : C:\Users\samsung\AppData\Roaming\Mozilla\Firefox\Profiles\6zq7cneh.default\foxydeal.sqlite Ordner Gefunden : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB Ordner Gefunden : C:\Program Files (x86)\Conduit Ordner Gefunden : C:\Program Files (x86)\Yontoo Ordner Gefunden : C:\ProgramData\BrowserProtect Ordner Gefunden : C:\Users\samsung\AppData\Roaming\Yontoo ***** [Registrierungsdatenbank] ***** Daten Gefunden : HKLM\..\Windows [AppInit_DLLs] = c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gefunden : HKCU\Software\Conduit Schlüssel Gefunden : HKCU\Software\delta LTD Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT1561552 Schlüssel Gefunden : HKLM\Software\Conduit Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\ConduitUninstaller_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\ConduitUninstaller_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\blaofbhgbmeikidhlkmjhbkbfohpgekf Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Wert Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Yontoo Desktop] Wert Gefunden : HKCU\Software\Mozilla\Firefox\Extensions [{0F827075-B026-42F3-885D-98981EE7B1AE}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16476 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v20.0.1 (de) Datei : C:\Users\samsung\AppData\Roaming\Mozilla\Firefox\Profiles\6zq7cneh.default\prefs.js Gefunden : user_pref("CT1561552_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[...] Gefunden : user_pref("Smartbar.SearchFromAddressBarSavedUrl", ""); Gefunden : user_pref("avg.install.userSPSettings", "Delta Search"); Gefunden : user_pref("extensions.delta.admin", false); Gefunden : user_pref("extensions.delta.aflt", "babsst"); Gefunden : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Gefunden : user_pref("extensions.delta.autoRvrt", "false"); Gefunden : user_pref("extensions.delta.dfltLng", "en"); Gefunden : user_pref("extensions.delta.excTlbr", false); Gefunden : user_pref("extensions.delta.id", "2ea89ebc000000000000c485080a7bee"); Gefunden : user_pref("extensions.delta.instlDay", "15758"); Gefunden : user_pref("extensions.delta.instlRef", "sst"); Gefunden : user_pref("extensions.delta.newTab", false); Gefunden : user_pref("extensions.delta.prdct", "delta"); Gefunden : user_pref("extensions.delta.prtnrId", "delta"); Gefunden : user_pref("extensions.delta.rvrt", "false"); Gefunden : user_pref("extensions.delta.smplGrp", "none"); Gefunden : user_pref("extensions.delta.tlbrId", "base"); Gefunden : user_pref("extensions.delta.tlbrSrchUrl", ""); Gefunden : user_pref("extensions.delta.vrsn", ""); Gefunden : user_pref("extensions.delta.vrsnTs", ""); Gefunden : user_pref("extensions.delta.vrsni", ""); Gefunden : user_pref("extentions.y2layers.defaultEnableAppsList", "twittube,buzzdock,YontooNewOffers"); Gefunden : user_pref("extentions.y2layers.installId", "22b278cd-b56e-437d-a030-83f3bff6bb52"); Gefunden : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=2&CU[...] Gefunden : user_pref("smartbar.machineId", "9FXWUZJUODYYIJ1EVRRARFRJEPLKXZC4UFYET+MCVW2GBRJMIFMT+JYFJZM02UYMMSH[...] -\\ Google Chrome v26.0.1410.64 Datei : C:\Users\samsung\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R3].txt - [10572 octets] - [14/05/2013 22:48:40] AdwCleaner[R4].txt - [4864 octets] - [14/05/2013 23:49:54] AdwCleaner[S3].txt - [5651 octets] - [14/05/2013 22:49:00] ########## EOF - C:\AdwCleaner[R4].txt - [4984 octets] ########## [/CODE] AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.300 - Datei am 15/05/2013 um 23:06:00 erstellt # Aktualisiert am 28/04/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : samsung - SAMSUNG-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\samsung\Desktop\adwcleaner(1).exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gefunden : C:\Users\samsung\AppData\Roaming\Mozilla\Firefox\Profiles\6zq7cneh.default\foxydeal.sqlite ***** [Registrierungsdatenbank] ***** Schlüssel Gefunden : HKCU\Software\BI Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16476 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v20.0.1 (de) Datei : C:\Users\samsung\AppData\Roaming\Mozilla\Firefox\Profiles\6zq7cneh.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v26.0.1410.64 Datei : C:\Users\samsung\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R4].txt - [5049 octets] - [14/05/2013 23:49:54] AdwCleaner[R5].txt - [1199 octets] - [15/05/2013 23:06:00] ########## EOF - C:\AdwCleaner[R5].txt - [1259 octets] ########## [/CODE] 3. Schritt: OTL OTL Logfile: Code:
ATTFilter OTL logfile created on: 15.05.2013 23:20:13 - Run 3 OTL by OldTimer - Version Folder = C:\Users\samsung\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,90 Gb Total Physical Memory | 5,43 Gb Available Physical Memory | 68,68% Memory free 15,80 Gb Paging File | 13,19 Gb Available in Paging File | 83,47% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 672,31 Gb Total Space | 237,61 Gb Free Space | 35,34% Space Free | Partition Type: NTFS Computer Name: SAMSUNG-PC | User Name: samsung | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\samsung\Desktop\adwcleaner(1).exe () PRC - C:\Users\samsung\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe (Adobe Systems, Inc.) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.) PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.) PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.) PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.) PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.) PRC - C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe (Samsung Electronics Co., Ltd.) PRC - C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe (Samsung Electronics Co., Ltd.) PRC - C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe () PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe () PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) PRC - C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe (Samsung) PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.) PRC - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation) PRC - C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (SEC) PRC - C:\Program Files (x86)\Samsung\Easy Support Center\SSCKbdHk.exe (SAMSUNG Electronics) PRC - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink) PRC - C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe (Symantec Corporation) PRC - C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (CyberLink Corp.) PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) PRC - C:\Program Files (x86)\PrintKey2000\Printkey2000.exe (Fred's Software) ========== Modules (No Company Name) ========== MOD - C:\Users\samsung\Desktop\adwcleaner(1).exe () MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll () MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl () MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl () MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl () MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl () MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl () MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll () MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll () MOD - C:\Program Files (x86)\Samsung\Easy Software Manager\SWMFuncDLL.dll () MOD - C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll () MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF () MOD - C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll () MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll () MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll () MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll () MOD - C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll () ========== Services (SafeList) ========== SRV:64bit: - (Samsung UPD Service2) -- C:\Windows\SysNative\SUPDSvc2.exe (Samsung Electronics) SRV:64bit: - (Intel(R) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation) SRV:64bit: - (ZeroConfigService) -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel® Corporation) SRV:64bit: - (MyWiFiDHCPDNS) -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe () SRV:64bit: - (EvtEng) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) SRV:64bit: - (RegSrvc) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation) SRV:64bit: - (AMPPALR3) -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation) SRV:64bit: - (BTHSSecurityMgr) -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel(R) Corporation) SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.) SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies) SRV - (SamsungDeviceConfigurationWinService) -- C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe () SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) SRV - (Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe () SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation) SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) SRV - (Bluetooth OBEX Service) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) SRV - (Bluetooth Media Service) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation) SRV - (Bluetooth Device Monitor) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation) SRV - (NIS) -- C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe (Symantec Corporation) SRV - (NOBU) -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (taphss6) -- C:\Windows\SysNative\drivers\taphss6.sys (Anchorfree Inc.) DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation) DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.) DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation) DRV:64bit: - (Fs_Rec) -- C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (nvpciflt) -- C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation) DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated) DRV:64bit: - (iusb3xhc) -- C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation) DRV:64bit: - (iusb3hub) -- C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation) DRV:64bit: - (iusb3hcs) -- C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation) DRV:64bit: - (intaud_WaveExtensible) -- C:\Windows\SysNative\drivers\intelaud.sys (Intel Corporation) DRV:64bit: - (iwdbus) -- C:\Windows\SysNative\drivers\iwdbus.sys (Intel Corporation) DRV:64bit: - (ibtfltcoex) -- C:\Windows\SysNative\drivers\iBtFltCoex.sys (Intel Corporation) DRV:64bit: - (btmhsf) -- C:\Windows\SysNative\drivers\btmhsf.sys (Intel Corporation) DRV:64bit: - (btmaux) -- C:\Windows\SysNative\drivers\btmaux.sys (Intel Corporation) DRV:64bit: - (SABI) -- C:\Windows\SysNative\drivers\SABI.sys (SAMSUNG ELECTRONICS) DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation) DRV:64bit: - (AMPPALP) -- C:\Windows\SysNative\drivers\AmpPal.sys (Windows (R) Win 7 DDK provider) DRV:64bit: - (AMPPAL) -- C:\Windows\SysNative\drivers\AmpPal.sys (Windows (R) Win 7 DDK provider) DRV:64bit: - (NETwNs64) -- C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek ) DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation) DRV:64bit: - (clwvd) -- C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation) DRV:64bit: - (ccSet_NIS) -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\ccSetx64.sys (Symantec Corporation) DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\srtsp64.sys (Symantec Corporation) DRV:64bit: - (SRTSPX) -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\srtspx64.sys (Symantec Corporation) DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\SymEFA64.sys (Symantec Corporation) DRV:64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\symnets.sys (Symantec Corporation) DRV:64bit: - (SymDS) -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\SymDS64.sys (Symantec Corporation) DRV:64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\Ironx64.sys (Symantec Corporation) DRV:64bit: - (ssadmdm) -- C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation) DRV:64bit: - (ssadserd) -- C:\Windows\SysNative\drivers\ssadserd.sys (MCCI Corporation) DRV:64bit: - (ssadbus) -- C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation) DRV:64bit: - (androidusb) -- C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc) DRV:64bit: - (ssadmdfl) -- C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation) DRV:64bit: - (SGDrv) -- C:\Windows\SysNative\drivers\SGDrv64.sys (Phoenix Technologies Ltd.) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV - (BHDrvx64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20130322.001\BHDrvx64.sys (Symantec Corporation) DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20130407.007\ex64.sys (Symantec Corporation) DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation) DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation) DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20130407.007\eng64.sys (Symantec Corporation) DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20130405.001\IDSviA64.sys (Symantec Corporation) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-808812791-3364131652-3434471583-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-808812791-3364131652-3434471583-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com IE - HKU\S-1-5-21-808812791-3364131652-3434471583-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-808812791-3364131652-3434471583-1001\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-808812791-3364131652-3434471583-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-808812791-3364131652-3434471583-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)" FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.4.8 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.15.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPlgn\ [2013.05.15 19:31:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\ [2013.05.15 19:31:33 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.04.12 08:49:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.04.12 08:49:44 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.08.04 16:08:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\samsung\AppData\Roaming\mozilla\Extensions [2013.05.12 15:24:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\samsung\AppData\Roaming\mozilla\Firefox\Profiles\6zq7cneh.default\extensions [2013.05.12 15:24:19 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\samsung\AppData\Roaming\mozilla\Firefox\Profiles\6zq7cneh.default\extensions\ich@maltegoetz.de [2013.04.30 21:40:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2013.04.12 08:49:43 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012.07.14 02:45:08 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.13 07:58:22 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012.07.14 02:45:08 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012.07.14 02:45:08 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012.07.14 02:45:08 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012.07.14 02:45:07 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: () CHR - default_search_provider: search_url = CHR - default_search_provider: suggest_url = CHR - homepage: hxxp://www.delta-search.com/?affID=119776&babsrc=HP_ss&mntrId=2ea89ebc000000000000c485080a7bee CHR - Extension: No name found = C:\Users\samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: No name found = C:\Users\samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\ CHR - Extension: No name found = C:\Users\samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.1.0.30_0\ CHR - Extension: No name found = C:\Users\samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\\CoIEPlg.dll (Symantec Corporation) O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\\IPS\IPSBHO.dll (Symantec Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\\CoIEPlg.dll (Symantec Corporation) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-808812791-3364131652-3434471583-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-808812791-3364131652-3434471583-1001..\Run: [Spybot-S&D Cleaning] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.) O4 - HKLM..\RunOnce: [awde7zip23646] File not found O4 - HKLM..\RunOnce: [Z1] C:\windows\SysWow64\cmd.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-21-808812791-3364131652-3434471583-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-808812791-3364131652-3434471583-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200 File not found O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\samsung\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\windows\SysWow64\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\samsung\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3FE89B9D-FADF-4695-9CF1-21CAEF103537}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7772B2B7-66EB-4000-A9CE-9F6F2323FAA7}: DhcpNameServer = O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20:64bit: - AppInit_DLLs: (C:\windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation) O20 - AppInit_DLLs: (c:\windows\syswow64\nvinit.dll) - c:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation) O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2013.05.14 22:32:17 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{6f2519bc-3f11-11e2-9582-c485080a7bf1}\Shell - "" = AutoRun O33 - MountPoints2\{6f2519bc-3f11-11e2-9582-c485080a7bf1}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.05.15 22:59:51 | 000,000,000 | ---D | C] -- C:\windows\ERUNT [2013.05.15 22:59:20 | 000,000,000 | ---D | C] -- C:\JRT [2013.05.15 22:58:56 | 000,545,954 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\samsung\Desktop\JRT.exe [2013.05.15 22:14:44 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\samsung\Desktop\tdsskiller.exe [2013.05.15 21:39:55 | 000,000,000 | ---D | C] -- C:\Users\samsung\Desktop\mbar [2013.05.15 20:10:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2013.05.15 20:10:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip [2013.05.15 19:51:27 | 000,000,000 | ---D | C] -- C:\Users\samsung\Local Settings [2013.05.14 23:58:05 | 000,000,000 | ---D | C] -- C:\Users\samsung\AppData\Roaming\Malwarebytes [2013.05.14 23:57:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.05.14 23:57:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013.05.14 23:57:55 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys [2013.05.14 23:57:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013.05.14 23:24:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2013.05.14 23:23:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 [2013.05.14 23:23:51 | 000,017,272 | ---- | C] (Safer Networking Limited) -- C:\windows\SysNative\sdnclean64.exe [2013.05.14 23:23:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2 [2013.05.14 23:23:15 | 000,000,000 | ---D | C] -- C:\Users\samsung\AppData\Local\Programs [2013.05.14 22:31:58 | 000,000,000 | ---D | C] -- C:\sh4ldr [2013.05.14 22:31:58 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group [2013.05.14 21:52:53 | 000,000,000 | ---D | C] -- C:\Users\samsung\Desktop\Bibi Blocksberg - 96 - Das traurige Einhorn [2013.05.13 23:15:05 | 000,000,000 | ---D | C] -- C:\ProgramData\eMule [2013.05.13 23:14:46 | 000,000,000 | ---D | C] -- C:\Users\samsung\AppData\Local\eMule [2013.05.05 23:21:58 | 000,000,000 | ---D | C] -- C:\tödliche versprechen [2013.05.05 22:09:55 | 000,000,000 | ---D | C] -- C:\big Miracle [2013.04.28 00:21:16 | 000,000,000 | ---D | C] -- C:\Users\samsung\AppData\Roaming\cef-cache [2013.04.21 13:39:30 | 000,000,000 | ---D | C] -- C:\Users\samsung\Documents\Bank [1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.05.15 23:17:00 | 000,000,328 | ---- | M] () -- C:\windows\tasks\Xerox PhotoCafe Communicator.job [2013.05.15 23:05:16 | 000,628,743 | ---- | M] () -- C:\Users\samsung\Desktop\adwcleaner(1).exe [2013.05.15 22:59:00 | 000,545,954 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\samsung\Desktop\JRT.exe [2013.05.15 22:47:00 | 000,001,112 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job [2013.05.15 22:31:00 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job [2013.05.15 22:14:46 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\samsung\Desktop\tdsskiller.exe [2013.05.15 22:11:54 | 000,000,512 | ---- | M] () -- C:\Users\samsung\Desktop\MBR.dat [2013.05.15 20:15:10 | 000,028,280 | ---- | M] () -- C:\Users\samsung\Desktop\logfiles.7z [2013.05.15 19:55:44 | 000,000,000 | ---- | M] () -- C:\Users\samsung\defogger_reenable [2013.05.15 19:36:53 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.05.15 19:36:53 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.05.15 19:35:45 | 001,498,506 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI [2013.05.15 19:35:45 | 000,654,166 | ---- | M] () -- C:\windows\SysNative\perfh007.dat [2013.05.15 19:35:45 | 000,616,008 | ---- | M] () -- C:\windows\SysNative\perfh009.dat [2013.05.15 19:35:45 | 000,130,006 | ---- | M] () -- C:\windows\SysNative\perfc007.dat [2013.05.15 19:35:45 | 000,106,388 | ---- | M] () -- C:\windows\SysNative\perfc009.dat [2013.05.15 19:29:24 | 000,001,108 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job [2013.05.15 19:29:02 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2013.05.15 19:29:00 | 4187,361,279 | -HS- | M] () -- C:\hiberfil.sys [2013.05.15 19:28:59 | 702,712,688 | ---- | M] () -- C:\windows\MEMORY.DMP [2013.05.14 23:23:55 | 000,002,133 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk [2013.05.14 22:32:17 | 000,000,000 | ---- | M] () -- C:\autoexec.bat [2013.05.14 20:49:26 | 141,796,035 | ---- | M] () -- C:\Users\samsung\Desktop\Botswana.pdf [2013.05.14 20:32:11 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerApp.exe [2013.05.14 20:32:11 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerCPLApp.cpl [2013.05.11 11:51:00 | 000,000,830 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job [2013.05.06 21:22:34 | 000,000,837 | ---- | M] () -- C:\Users\samsung\AppData\Local\recently-used.xbel [2013.05.06 20:00:39 | 001,247,726 | ---- | M] () -- C:\Users\samsung\Desktop\blumen.png [2013.05.02 22:50:58 | 000,039,618 | ---- | M] () -- C:\Users\samsung\Desktop\Zara_C9704_106246.pdf [1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.05.15 23:05:12 | 000,628,743 | ---- | C] () -- C:\Users\samsung\Desktop\adwcleaner(1).exe [2013.05.15 22:11:54 | 000,000,512 | ---- | C] () -- C:\Users\samsung\Desktop\MBR.dat [2013.05.15 20:15:10 | 000,028,280 | ---- | C] () -- C:\Users\samsung\Desktop\logfiles.7z [2013.05.15 19:55:44 | 000,000,000 | ---- | C] () -- C:\Users\samsung\defogger_reenable [2013.05.14 23:23:55 | 000,002,145 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk [2013.05.14 23:23:55 | 000,002,133 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk [2013.05.14 22:32:17 | 000,000,000 | ---- | C] () -- C:\autoexec.bat [2013.05.14 21:52:19 | 041,492,827 | ---- | C] () -- C:\Users\samsung\Desktop\94 - Bibi Blocksberg - Die verhexte Zeitreise.mp3 [2013.05.14 21:51:55 | 078,266,089 | ---- | C] () -- C:\Users\samsung\Desktop\93 - Bibi Blocksberg - Bibi braucht Hilfe.mp3 [2013.05.14 21:51:22 | 039,627,513 | ---- | C] () -- C:\Users\samsung\Desktop\92 - Bibi Blocksberg - Das Geheimnisvolle Schloss.mp3 [2013.05.14 20:49:27 | 141,796,035 | ---- | C] () -- C:\Users\samsung\Desktop\Botswana.pdf [2013.05.12 15:20:58 | 000,054,964 | ---- | C] () -- C:\Users\samsung\Desktop\proxtube_gesperrte_youtube_videos_schauen-1.4.8-fx.xpi [2013.05.06 21:22:34 | 000,000,837 | ---- | C] () -- C:\Users\samsung\AppData\Local\recently-used.xbel [2013.05.06 20:00:38 | 001,247,726 | ---- | C] () -- C:\Users\samsung\Desktop\blumen.png [2013.05.02 22:50:58 | 000,039,618 | ---- | C] () -- C:\Users\samsung\Desktop\Zara_C9704_106246.pdf [2012.08.26 17:14:37 | 001,558,432 | ---- | C] () -- C:\windows\TotalUninstaller.exe [2012.03.02 16:17:08 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe [2012.03.02 15:30:00 | 000,001,340 | ---- | C] () -- C:\windows\HotFixList.ini [2012.02.06 04:29:35 | 000,734,772 | ---- | C] () -- C:\windows\SysWow64\igkrng700.bin [2012.02.06 04:29:30 | 000,557,476 | ---- | C] () -- C:\windows\SysWow64\igfcg700m.bin [2012.02.06 04:29:27 | 000,058,880 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll [2012.02.06 04:29:25 | 012,978,688 | ---- | C] () -- C:\windows\SysWow64\ig7icd32.dll [2012.02.02 15:08:26 | 000,001,536 | ---- | C] () -- C:\windows\SysWow64\IusEventLog.dll ========== ZeroAccess Check ========== [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] < End of report > [/CODE] OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 15.05.2013 23:20:13 - Run 3 OTL by OldTimer - Version Folder = C:\Users\samsung\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,90 Gb Total Physical Memory | 5,43 Gb Available Physical Memory | 68,68% Memory free 15,80 Gb Paging File | 13,19 Gb Available in Paging File | 83,47% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 672,31 Gb Total Space | 237,61 Gb Free Space | 35,34% Space Free | Partition Type: NTFS Computer Name: SAMSUNG-PC | User Name: samsung | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-808812791-3364131652-3434471583-1001\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.) ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{032F0593-D9CA-4313-A65B-A4D807D946B8}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{0A1C72D0-609B-4F26-BEAA-4C937D9907B1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{0D6EC47C-752C-41B9-A807-D12A4B374A95}" = rport=138 | protocol=17 | dir=out | app=system | "{0EBA4A18-2019-414F-AA87-C9CB06391DFD}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{1B537D47-F894-4F9B-B0A1-E5F8F291FA09}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{24BDFCD8-B9D6-480A-838C-F843B88087BF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{30632E76-D621-40BA-B351-3F0D0C5E79F2}" = lport=138 | protocol=17 | dir=in | app=system | "{3EA91949-8BF2-4E67-8523-8F728D3D7DA0}" = lport=445 | protocol=6 | dir=in | app=system | "{53DC60CE-5E10-498F-B491-518BF2E9AC4A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{542CCF13-37CB-431A-9811-CE6DF442E6F9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{575EC890-8A74-4B59-9C96-6E2D4BF6E997}" = lport=139 | protocol=6 | dir=in | app=system | "{59831124-7479-4BAC-9DE2-DC157CA56D06}" = rport=445 | protocol=6 | dir=out | app=system | "{7B5A4852-6F01-4AB8-A084-EDE0BD919849}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{802AB5C0-88F3-4951-A75D-264DD3717D79}" = lport=2869 | protocol=6 | dir=in | app=system | "{8CB29E2B-2A9E-4DC1-ABA4-93A6111DB202}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{9B5BA163-4028-44A5-8254-87EA66AEFEAB}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{B1E1449F-6BF5-49E2-8096-143229FD6C10}" = rport=139 | protocol=6 | dir=out | app=system | "{D1227C7F-7555-42FD-B79A-CBB1017A1F6B}" = lport=10243 | protocol=6 | dir=in | app=system | "{D2FC454A-687C-4D52-B8DA-4E842590D17A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D55D9C6C-97E4-4ACB-9227-FF315E260816}" = rport=10243 | protocol=6 | dir=out | app=system | "{D96F16D6-A974-44CA-97DE-172D1479F0F8}" = lport=137 | protocol=17 | dir=in | app=system | "{DAE75AF0-0E5F-4B0A-AA29-E8446ED5EDF0}" = rport=137 | protocol=17 | dir=out | app=system | "{E874848F-981A-4670-A80D-A5396FD13616}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1B3573F2-DEB6-451C-84AD-44F766D4464C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{1BD61F8C-28BA-4224-9B44-749D27D1A4D4}" = protocol=6 | dir=out | app=system | "{29B26E0B-452B-4BC5-BB34-D7F83F2EFBEF}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{2E45DD3D-4B62-4D72-BE5B-C3F16D3B4C24}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{2F14D253-5CD9-4B48-A2CA-8BFF255A815F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{317EC8A0-CB0F-4FBB-8260-B8CB4A250FE3}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{34370226-AC95-4B0A-A561-643668CCE33D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{3885B114-BCF6-4A97-B34F-0EFCC99D80E6}" = dir=in | app=c:\program files (x86)\intel corporation\intel widi\widiapp.exe | "{3E2117FF-497A-4EAE-8878-321BE3C0BEB8}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{3FE11C16-478D-471D-9918-1FDDA069C9D1}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe | "{403A821C-5047-44C2-A76D-5B229A6A1C7E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{41380786-D32C-441B-84E8-531663A784CC}" = dir=in | app=c:\users\samsung\appdata\local\microsoft\skydrive\skydrive.exe | "{4310D0D5-1699-4745-A523-47A7F39BE698}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{43E96249-6472-4286-BC24-D8D798F24307}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{5FDC43EC-51CA-4844-B778-CCF4692C77B6}" = protocol=17 | dir=in | app=c:\windows\system32\supdsvc2.exe | "{66D8F063-713D-4AE4-B048-1341FBE7EA25}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{724F1430-0247-4498-B5B4-619F8C478BF5}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{85148758-87C1-4ECE-B623-5DCDE24D1B4D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{8899D98E-E4DD-44C7-A022-9CDB023AADD2}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe | "{89DE5B8C-A207-470D-A712-AE43A5650AB2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{8FF28049-4444-499B-9A71-40F3FE6EB609}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{9A60ECEB-025B-412A-AC82-8E460F2A8CD1}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{B1D564E1-3BEB-4640-9FAC-97B03B7AEC9A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{BCC3F805-1531-4BD5-ACF0-11790F8F7CCE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{BD3E3541-9508-4C38-8ED0-1B36C3DE4860}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr8.exe | "{C4FC189D-BC19-405E-ABAB-149810FF2F87}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{C7074C2F-9F05-4A6F-9271-D8EC3E3BA2EA}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{C717D449-B108-4AA6-A0A0-856C717664B6}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{C7721DA7-B7F9-4B7B-8C01-5E9D7B4E6929}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{CA9034F0-C133-41BC-A05F-951D3E3EEB04}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{CCDF8D22-7C15-4C41-B410-4EB1092C81D8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D13368C6-546E-48B0-B6FD-103AA5A1E6B7}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{D18BE736-AB38-4243-839D-42F222AA095A}" = protocol=6 | dir=in | app=c:\windows\system32\supdsvc2.exe | "{D4B8A113-045C-4B39-ACD8-FD86848A385B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{DFDD9375-CDC0-4D52-B65F-1E120F96543A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{EB4747F7-8EC3-4C22-9ECF-36AE03E83C56}" = dir=in | app=c:\program files (x86)\cyberlink\media+player10\media+player10.exe | "{F2AEC4EA-ABFB-46EA-8236-E2E93A525CFC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{F37D2CC6-ABAE-42A0-9CA2-5C7239CA0ADB}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | "{FED95060-0118-480F-839E-298DCB421709}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "TCP Query User{FE033FB9-BB2B-4C5A-AB89-CD3C8A386B34}C:\program files (x86)\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files (x86)\emule\emule.exe | "UDP Query User{06B741DD-94C4-48A9-BD01-512F6D44C368}C:\program files (x86)\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files (x86)\emule\emule.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{09536BA1-E498-4CC3-B834-D884A67D7E34}" = Intel® Trusted Connect Service Client "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel(R) Wireless Display "{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}" = Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5F611ADA-B98C-4DBB-ADDE-414F08457ECF}" = Windows Live Family Safety "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010 "{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 295.55 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 295.55 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.7.12 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.11.1111 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DF7756DD-656A-45C3-BA71-74673E8259A9}" = Intel® PROSet/Wireless WiFi Software "{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64 "{F0932859-AA60-459E-B843-0BDECA34E2C7}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{F6822EFD-3F7D-4B35-8845-757A26AEC8E2}" = Windows Live MIME IFilter "Bullzip PDF Printer_is1" = Bullzip PDF Printer "GIMP-2_is1" = GIMP 2.8.2 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "ProInst" = Intel PROSet Wireless "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{000AD938-EEBB-46F5-BD33-23CB34A57C54}" = Movie Maker "{00476F3E-3C4D-4E02-B8BB-125350157EB9}" = Windows Live Mail "{017E337D-D709-437C-83DB-71F82AA78BF6}" = 照片库 "{01944037-D136-45EE-A007-403EAD929FC7}" = Windows Live Writer "{01ABAEC3-8F96-4D00-9672-E49AAFDC0685}" = Windows Live Writer Resources "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{022C7C52-B294-4346-88BC-C7C2FF7FF1B7}" = Movie Maker "{03426ED9-9D9C-4F71-B293-BBE6493367A2}" = Windows Live Mail "{03CC9D58-B132-4CC0-A521-4F3660AA43C7}" = Movie Maker "{03E2EED4-368D-49EA-B1AC-8B615E37E16D}" = Windows Live Messenger "{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform "{048C8498-C20B-4AF7-9978-7A79E567D74C}" = Photo Common "{04CCBB46-37C1-4623-9477-C65A32DFD023}" = Photo Common "{058EDEC8-1873-4B49-9A08-54ADE9CC129B}" = Movie Maker "{0618FAAA-E236-4F74-924F-837A5592E506}" = Windows Live Writer Resources "{061FF8F3-5226-4278-8AAB-282C1B024F58}" = Photo Common "{06EED60F-7FFC-43A7-936E-AA4A8BD948B4}" = Windows Live Writer "{087D261B-73AE-4B8A-8F18-2EE80DD2ED8B}" = Фотоальбом "{0AD576A7-EDCE-469E-ADD7-1AC9DB200C6B}" = Windows Live Mail "{0B660563-2836-49A3-AEDE-928D13ECC19A}" = Windows Live Writer "{0B783100-6F04-4E2F-B83D-0A9B4EEDE47A}" = Windows Live Writer Resources "{0BC39E89-506A-4ADA-8924-27AEE2C97618}" = Windows Live Writer "{0BFF2188-2D8E-4BE2-95D0-B3CCD4C6A0C9}" = Photo Common "{0DF95460-2887-4011-9344-1959CDF18ADC}" = Photo Common "{0E1BB4B4-00FF-45B1-914B-AB8D8B9862B3}" = Windows Live UX Platform Language Pack "{0E3A4650-A873-4D53-A9DE-E84D57F6A085}" = Windows Live Messenger "{0F6A576E-C6E3-437E-B389-262EBC86B09A}" = Windows Live UX Platform Language Pack "{1026DF85-1C0F-4839-888E-EB9D5B73CF46}" = Windows Live Writer "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support "{12F81925-F3C1-40DB-91F7-777817974319}" = Easy File Share "{13F3CEA5-9E2C-4C4E-9F0F-D0DB389CF4A9}" = Movie Maker "{144113A4-1A98-452F-8506-60F8C811D316}" = Movie Maker "{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution 5 "{1532CEFF-ADB4-4230-BF03-30A6B3182663}" = Movie Maker "{1590089E-44E5-4334-BA45-869E194F1D5B}" = Windows Live 메일 "{15F32CAE-4504-4F33-89F8-182FF38CA036}" = Windows Live Family Safety "{15F3A6F5-06AE-4332-AE3E-21CD0416827A}" = Windows Live Mail "{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Settings "{18272881-CFC0-434D-A975-E5BE44206AA0}" = Windows Live UX Platform Language Pack "{182D3167-FE80-4DF6-96C2-84AC0ABA20D8}" = Windows Live Writer Resources "{184A0D4F-4BCF-40EF-A73C-F0313FDB5CCD}" = Windows Live Messenger "{187A0FCA-2FE2-4827-83CA-D4887E965047}" = Photo Common "{193464D1-D974-4456-949F-28ED63610126}" = Windows Live Family Safety "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{19AFD9A4-B584-41C8-91EA-38EB2FC1BD50}" = Windows Live Messenger "{1A79A578-4277-48AF-98A6-F9E48CF1B6D8}" = Windows Live Writer "{1D03A585-879D-45DB-B77A-C4D5A04E7286}" = Windows Live Family Safety "{1D485014-D9A4-42DE-B04C-2DB691ABDE02}" = Windows Live Writer "{1D6F9A9A-DCF3-45A7-9B14-46DDA778313F}" = Windows Liven sähköposti "{1DA74ED3-BAE9-4A89-B24E-18B4E78E075F}" = Movie Maker "{1EA7C505-E6DA-4B85-9432-EBD3C70D510D}" = Windows Live Messenger "{1F0C818D-4A41-4E40-BAFB-BB940C82A518}" = Fotogalerija "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite "{1FEE19BC-6F0C-42E4-82FF-FB597F6141DF}" = Windows Live Essentials "{207E9B4C-48A9-47CE-BBC8-ACF0B2006351}" = Windows Live Mail "{2177152C-83DD-4540-B2F0-970F7303B7BA}" = Windows Live Writer Resources "{2329E182-DFC8-4C1E-AF2C-758F25347F69}" = „Windows Live Essentials“ "{23A3E560-069F-4CFC-8F6C-1B526EC735FC}" = Windows Live Writer Resources "{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver "{241F87F6-CEA4-4493-B4EE-0973C6088FEC}" = Windows Live Family Safety "{24DF33E0-F924-4D0D-9B96-11F28F0D602D}" = Windows Live UX Platform Language Pack "{252D22BA-FD4A-48C0-A937-C0E0B799F1EF}" = Windows Live Family Safety "{254F7574-53A7-43D1-BC4D-B1E894AEE175}" = Windows Live Writer "{25CD4B12-8CC5-433E-B723-C9CB41FA8C5A}" = Windows Live Writer "{262E7632-72F9-4CBE-9461-937F24106EF2}" = Windows Live Essentials "{26A24AE4-039D-4CA4-87B4-2F83217015FF}" = Java 7 Update 15 "{28B2947F-FC0B-4450-80E3-6DF698E824A6}" = Windows Liven peruspaketti "{2A078A2B-E2C8-43A3-862C-DC57090AB7C2}" = Movie Maker "{2AC4C6D7-512D-4B78-A85B-2C16E748AB8E}" = Movie Maker "{2AEAFC79-79E6-4784-9CF9-D9D82932BF88}" = Windows Live Family Safety "{2B068A64-F867-44E9-8827-A795647C8730}" = Фотографии (общедоступная версия) "{2B919309-7052-45A4-B1C8-5B4894E8648B}" = Windows Live Writer "{2BD71DFE-604F-411A-92B6-B957983B81C6}" = Windows Live Family Safety "{2E50E321-4747-4EB5-9ECB-BBC6C3AC0F31}" = Windows Live Writer Resources "{2FE8AE4C-1B6E-4F70-A639-14FD881F559F}" = „Windows Live Mail“ "{306C7AEF-16C7-428D-93AA-99D4A4090243}" = Movie Maker "{30B984FC-F436-4666-AAEF-10FF2453478E}" = Windows Live Mail "{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery "{3123396C-3EFE-4DCB-8033-F5D182D6597D}" = Windows Live Essentials "{31846283-C955-4CE1-9297-8670BD0C9A7E}" = Windows Live Messenger "{32AA7594-09A9-437F-9541-5F760509B752}" = Фотогалерия "{330BBA5F-4A63-4545-900F-8446F205BA52}" = Windows Live Writer Resources "{34FBC7C4-CD31-4D93-A428-0E524EAC4586}" = CyberLink Media+ Player10 "{35CB7C2D-B421-46FC-89CF-3B630628876F}" = Windows Live Writer Resources "{36BEC461-B58A-414D-993E-E2BDD1F1A14B}" = Movie Maker "{373EF285-A2DC-44EB-8D79-18918F33CB3A}" = Windows Live Messenger "{37FDD121-C443-4FD3-A213-2449B397C068}" = Windows Live Messenger "{381AAE35-6FB5-437E-8DD9-9C5C733943ED}" = Windows Live Family Safety "{38814879-FCE1-491C-AC22-D0659921F53F}" = Windows Live Family Safety "{3A9ECD64-DE00-4779-A89E-C878513B2B37}" = Windows Live Writer Resources "{3C3DCD2B-6FC7-41BF-BB80-40A936E1A785}" = Windows Live Writer "{3C41298B-A3F5-40C8-8BE3-A9A3F0644B0A}" = Windows Live Writer "{3C63F944-803E-49A7-B3A2-B8AB3313E883}" = Windows Live UX Platform Language Pack "{3CBD94C1-BA15-488C-888B-D8DD296CC6DC}" = Fotogalerie "{3D44D783-D027-4135-AC39-81E320ED2D3A}" = Windows Live Family Safety "{3D4F3F4C-E364-4E46-BFB1-A00BF9777422}" = Windows Live UX Platform Language Pack "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{3F459DA9-0D88-452E-97A4-5B69C8C8C6B5}" = Windows Live Family Safety "{3FD0036E-236A-4EDD-894D-4374BEE64464}" = Windows Live UX Platform Language Pack "{400C31E4-796F-4E86-8FDC-C3C4FACC6847}" = Junk Mail filter update "{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "{42B6C7E0-0DAE-488D-8DAF-838898102F19}" = Windows Live Writer "{43CCAC37-4E31-495F-9077-471E4E92DCEA}" = Windows Live Messenger "{446CC8CE-0E90-44F7-ADD0-774B243EF090}" = Galerie de photos "{44A3A561-AE74-472D-A51C-43F4C9E7B5E5}" = Windows Live 软件包 "{46A648D2-C097-41A3-A517-E709F045B6CD}" = Movie Maker "{46ED2B64-85C7-4E1F-920C-A555B21F2E4C}" = NVIDIA PhysX "{46EF173F-A437-48B9-B950-A13F5619E7C6}" = Windows Live Mail "{476C5E21-9418-4A76-80A3-0C6A470AC637}" = Windows Live Essentials "{47CF356B-5EC9-46C2-91F1-19DCAA990A34}" = Windows Live Writer Resources "{4848ECCF-2AF6-413D-BD62-2447BBF2B547}" = Windows Live Family Safety "{49B666FA-917B-48D7-B81D-E7F829CFC713}" = Windows Live Family Safety "{49F068F2-4323-417B-AFC8-1E43F479D46C}" = Windows Live Essentials "{49F8A207-E3A3-4DAF-A0CC-9A787F1D8424}" = Windows Live Family Safety "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4AA2A466-8031-403A-8236-5301B4E391FB}" = Windows Live UX Platform Language Pack "{4AA72B0D-F42C-43BE-A8D9-7E2D993D7FE5}" = „Windows Live Messenger“ "{4AF53C99-315D-4536-873F-029D2D274AE2}" = Photo Common "{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform "{4E55905B-849D-4633-9267-3EC77E24221A}" = Poczta usługi Windows Live "{5006FD66-7E9B-4F92-BD36-275AD7712348}" = معرض الصور "{5078CEC3-A56F-4080-8CD4-ED7BCBE5686B}" = Photo Common "{50849B2C-097E-47A5-A076-6F11A939E093}" = Windows Live Mail "{51449A7F-4820-4757-9236-87A3BE7B6F27}" = Windows Live Writer "{51EF51B6-0D9F-4977-8F9D-A1E15017D2B7}" = Windows Live Mail "{525E7EA7-481F-499D-A7F7-4682AC46A454}" = Movie Maker "{537B16E0-A39F-47CB-9C1E-50978862B108}" = Windows Live UX Platform Language Pack "{55268806-FC27-4CA2-9CCA-1269FD4831FE}" = Windows Live Writer "{56232E3D-7EA9-45E0-A371-26CD80510AF7}" = Windows Live UX Platform Language Pack "{5681FEA2-1CF8-461E-B611-55D2C50FC4EF}" = بريد Windows Live "{5917D694-AFC3-46BF-8CAB-0DABAF9D6FCB}" = Windows Live UX Platform Language Pack "{5A30E103-9FA6-4A23-A107-E1F5F174BB62}" = Windows Live Temel Parçalar "{5BABDA39-61CF-41EE-992D-4054B6649A9B}" = Movie Maker "{5C2F5C1B-9732-4F81-8FBF-6711627DC508}" = Windows Live Fotogalleri "{5D6D7C60-FE76-43E7-A135-8B0CD15914C7}" = Windows Live UX Platform Language Pack "{5FE3BC4E-2BD5-4D6B-8BC4-640A42626AAD}" = Почта Windows Live "{6209125A-46C5-4099-96DC-72FD55B07C1C}" = Windows Live Writer Resources "{62BBCDDC-4979-4E59-9D97-5B8E874C3191}" = Movie Maker "{62CC9AF4-EDD9-43C8-9856-FFD60362CFA9}" = Windows Live Messenger "{631C4E4F-6FDC-4CC0-A067-E9876A9BA7FD}" = 影像中心 "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{66DB6D91-BF91-480B-933D-7CB8B1E64D74}" = Windows Live Messenger "{685EE156-6B74-4F0D-BF87-9A15AAA1D9A3}" = Windows Live 필수 패키지 "{690F5BA3-5DEB-42CD-962B-F687EE59FAA7}" = Windows Live Essentials "{69D48C91-CCC2-4305-89DE-D1F8122EDBF4}" = Photo Common "{69FCA957-224F-4623-8BE0-6295CFB2C3E4}" = Windows Live Mail "{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform "{6B8F13E2-F02B-445C-9A31-3C0E5D547CBA}" = Photo Common "{6D9DD7D9-4167-4541-8DA8-619B9B802D72}" = Fotogalerija "{6DA675F3-B549-4BDE-90FA-BEF8C3B87F00}" = Windows Live Mail "{701FE1BC-834A-4857-AF62-6EBA50CFBC78}" = Movie Maker "{70854FE6-3BF1-4C69-94D0-BEB821102E34}" = Windows Live Mail "{70BF63A5-DE6A-417C-AB93-5E31D0DA994E}" = Windows Live Writer "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{715F9B21-2817-402A-9BF0-BDA764D21F09}" = Windows Live Essentials "{719E4DA1-A17B-4B46-9D5D-925D4FBE4D69}" = Movie Maker "{7211F448-F865-4D37-B905-24D84E6C3E5E}" = Windows Live Writer Resources "{72DFDA9F-C07B-40B6-BA5C-C4C04AFF883D}" = Windows Live Family Safety "{733EC941-EDAF-4DB8-920A-6CD70488676A}" = Windows Live Writer "{73669388-1011-4B57-A90F-8B0415093AB2}" = Windows Live Writer "{743FD554-A73F-4FE8-BE7B-C283D16297F9}" = Photo Common "{751EB657-3F22-4150-8CE4-D79A262F1D92}" = Movie Maker "{7595CAD2-87D0-4D01-AC02-3FDD3A891BB8}" = Galeria fotografii "{7607440C-FDCA-4210-9CD9-13D8F0DDAD0C}" = Windows Live Writer Resources "{76E62ACD-1536-4AC7-9A2E-B7DB4F2ACE5E}" = Windows Live Family Safety "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{794D971F-7EC1-4F71-A51C-773074CAB8DA}" = Windows Live Writer "{797DC296-ADC5-4A08-8CBC-AEB0D6F4B249}" = Windows Live Essentials "{79A1AF43-BD17-4A81-B38A-6D6535D3F377}" = Windows Live Writer "{7A83618D-879A-4258-8B5E-5AD8B5F3EDD0}" = Windows Live Writer "{7ADFA72D-2A9F-4DEC-80A5-2FAA27E23F0F}" = Windows Live Photo Common "{7B0C5EF6-DE4C-4E20-8889-C17604FFE5CD}" = Windows Live Family Safety "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{7E41F42B-7ED8-4E15-A492-B93B287C027F}" = Windows Live Writer Resources "{7E63F102-A9E9-4F4C-8004-BC62974736BF}" = Movie Maker "{7E9A63B3-8572-4A4B-9F87-3C2A873BBC55}" = Windows Live UX Platform Language Pack "{80136E5C-7CB8-4534-B263-FE622BC9C782}" = Windows Live Writer "{802E137D-DA8F-47CC-AC21-6DD075CD948C}" = Windows Live UX Platform Language Pack "{8030AE22-7FA0-4880-A538-8906EDBF49F4}" = Windows Live Writer Resources "{8063EB67-E777-4A56-9C1E-FAD75C2F5EC2}" = Photo Common "{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow "{8146445E-B14D-4CBA-AB9A-728CF166DAC9}" = Windows Live Messenger "{8176B9CA-F037-49C0-BD77-661B1DDCA6F3}" = Movie Maker "{81CF4226-47C1-418C-8718-1B3ED2C37878}" = Windows Live Essentials "{824F9823-9F10-4032-8666-DCF5CFF4113E}" = Windows Live Writer Resources "{83C9377F-5ED1-4AD8-B113-7C876AEAF3AB}" = Windows Live Messenger "{8502F597-4852-48BB-99E5-824AC4C057F0}" = Windows Live Family Safety "{854A24E3-A0EF-472A-B1D6-A2E9D43D5D8B}" = Windows Live Writer Resources "{857BC375-BCFB-474E-9BD9-7EBB18EC55E0}" = Windows Live Essentials "{85CE9026-C02A-46B4-B08C-4C77CCCC54FF}" = Windows Live Family Safety "{862780DF-67D4-40B4-BDC7-E82B3F116504}" = Movie Maker "{86C40513-B5A4-476E-9EAB-EC118DCF4502}" = Windows Live Writer "{87425773-10F4-4858-8CBF-465093FA43DE}" = Windows Live Mail "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{88809C3E-8C92-4454-AEB7-B26166E3D6CD}" = Windows Live UX Platform Language Pack "{8913AC02-67B8-4B52-91B2-BBA7B9C265B5}" = Windows Live Writer Resources "{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions "{8AAEB5A5-A397-46B6-8AF3-B6DC790C4E48}" = Windows Live Messenger "{8B37F794-E318-44BA-9A13-233344202ABA}" = Photo Common "{8D813AFF-D91D-4EE0-821F-B901FC2E89FA}" = Windows Live "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110 "{8E241C05-52BF-4862-AD1F-AAE465C0075B}" = Windows Live Mail "{8E31695A-4694-4DC4-8BEF-F8F22520D38D}" = Windows Live Writer "{8E6AB06E-FE46-433B-85D5-BC27ABE06570}" = Photo Common "{8F7FECEC-088F-431D-A5FB-2B59E1E69943}" = Galería de fotos "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010 "{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010 "{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010 "{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 "{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010 "{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010 "{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 "{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 "{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010 "{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 "{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010 "{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010 "{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 "{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010 "{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{902C4E0E-89CE-43B9-BCC0-F3A91E987F99}" = Windows Live Writer "{9093B0D5-EA59-4C9E-A2E3-CC130138DFCD}" = Fotogaléria "{90993BD9-C7D9-4C2F-B56C-2F7AFEBD4CD0}" = Windows Live UX Platform Language Pack "{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{924B4D82-1B97-48EB-8F1E-55C4353C22DB}" = Windows Live Mail "{9341E0BE-ADA3-4590-BB51-5D916D8FAE65}" = Windows Live Mail "{93F34C5C-ACAA-48F3-9B26-70359A117F12}" = Intel(R) WiDi "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{95D78710-DEE9-4577-9FC6-35BE431898DC}" = Windows Live Family Safety "{96361BC7-B7C8-4594-AD89-813C371F4246}" = Windows Live Writer Resources "{9636FF74-65AF-4714-90A4-08982C368100}" = Windows Live Family Safety "{96914829-DF65-40AE-8A31-6F3E96BAEBBD}" = Windows Live Mail "{97368584-CA0D-45C6-8151-AE96A33A867B}" = Fotoattēlu galerija "{97C79BEC-43F7-4BD8-A6A7-85C0257E488A}" = Windows Live Writer "{9869099A-6A44-4590-9430-BF7AC74EBCC6}" = Windows Live UX Platform Language Pack "{989889A7-D13D-4DA4-B059-B250784DFABC}" = Photo Common "{9939B8FF-7D2D-4258-B5B9-B6BA8DD59905}" = Windows Live Mail "{99AA6730-54CD-4B9E-B05B-0A5196743923}" = Windows Live UX Platform Language Pack "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B4D3AFE-8679-4704-AA4C-BAB0E41870EF}" = Windows Live Essentials "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C60D080-84E7-43A5-8ECA-28253D253BD7}" = Windows Live Essentials "{9D204CE2-C8D8-4CC9-A74B-F2768DBC1E3B}" = Photo Common "{9EDF46F0-2D4E-4C00-B2B6-0660666E9F60}" = Movie Maker "{9F470E17-4FC3-4091-A508-D5347A16A2B9}" = Fotogalleriet "{9F9F5784-1E5A-47D2-BB82-21F89352859B}" = Windows Live Family Safety "{A035950F-15BA-41C0-9D8F-165FC0536012}" = Movie Maker "{A0E4C4A6-1CC7-4442-8CAE-2D825B7BC1C1}" = Windows Live Writer Resources "{A132CE8A-79EA-4BB5-9A24-4348B4DDD48A}" = Photo Common "{A17946CA-18E5-4CF0-8D55-A56D804718F8}" = Movie Maker "{A19A8C25-272A-4CD6-8BA8-3772321A021B}" = Συλλογή φωτογραφιών "{A1FBD2B3-6768-472D-BA46-C00EACBCE16C}" = Fotogalerie "{A37F2060-813A-4325-9456-272B10EE75EF}" = Windows Live Essentials "{A3D995FA-C9A0-4E7D-B430-3F7A6731B4D5}" = Windows Live UX Platform Language Pack "{A412D7BD-FD86-461D-B385-CD8062F34131}" = Windows Live Messenger "{A47EA9D4-BB87-415E-9239-28860434E5A0}" = Movie Maker "{A58FCEF4-3191-466C-8949-0FFFFFB7631D}" = Windows Live Writer Resources "{A5DC64EE-2FC4-4C35-9975-639DD8499369}" = Windows Live Family Safety "{A6C48A9F-694A-4234-B3AA-62590B668927}" = Intel(R) Manageability Engine Firmware Recovery Agent "{A72739F4-3E29-457C-AFB0-D5B75AB782A5}" = Windows Live Messenger "{A7E73DE5-E5FD-4923-9D88-E09ECD1F3545}" = Podstawowe programy Windows Live "{A86C7338-BE18-4770-AA25-138513D89B0D}" = Multimedia POP "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A96A855B-89F7-40D4-A57E-580DFD4235B3}" = Windows Live UX Platform Language Pack "{AA82E5EF-70C2-41CB-8432-309078304CBB}" = Photo Common "{ABAF6F07-0D84-4700-948E-EC5042B9D978}" = Windows Live Mail "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch "{AD86049C-3D9C-43E1-BE73-643F57D83D50}" = Easy Migration "{ADE1F206-1365-4B14-9A24-4B1A7DD58BAC}" = Windows Live UX Platform Language Pack "{AE364ACC-B9DF-466B-B4EA-AEECD0CD581E}" = Windows Live Messenger "{AE8044B5-FCA3-4EBE-AC78-0FB3A6E8DC76}" = Movie Maker "{AEC637CC-78F4-4746-9707-56B37105B799}" = Windows Live Messenger "{B096A0E4-26A1-4E9F-8548-577964B9434B}" = Windows Live Essentials "{B20502AB-2A3F-48F9-AD09-9FB61689A6D4}" = Windows Live Writer "{B27EDD14-869E-4A44-905A-5DE652F7278F}" = Windows Live Messenger "{B306F739-A414-4698-BFAD-0AB23F73D14F}" = Windows Live Messenger "{B328282C-DCE9-49B7-8B98-C08D9AA28C46}" = Windows Live Mail "{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy "{B413088F-F01D-467A-8F39-94F6EE473321}" = 사진 갤러리 "{B474FC1C-4619-4C99-8ECE-382D71627CCA}" = Windows Live Family Safety "{B625668D-34AA-462D-AA32-44BFA70F08E7}" = Windows Live Messenger "{B66CFC88-6729-4A0F-8610-258413159C35}" = Windows Live UX Platform Language Pack "{B67B2671-2981-466B-BA14-25538AA871DC}" = Windows Live Messenger "{B693A4C3-B708-4F25-978E-56CA2517914C}" = Windows Live UX Platform Language Pack "{B727564C-47D3-473A-AC9E-F4BE7B1BD5D3}" = Windows Live UX Platform Language Pack "{B750B5C2-CC17-4967-905B-29F4EB986131}" = Software Launcher "{B77D2795-23C0-4DBD-B7B5-CFB542D1FA3F}" = Windows Live Writer Resources "{B7F31B9C-8775-4500-8E9D-6ABE9AE17CF4}" = Windows Live Essentials "{B80D3EA9-A252-4AE5-AC51-81729F5C586F}" = Windows Live Mail "{BA068968-594F-40BE-8EE8-99119123C991}" = Windows Live UX Platform Language Pack "{BAD4B8FA-4BDA-4A59-BE64-9741031680C7}" = Movie Maker "{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide "{BE5650DD-D298-421B-B7A7-3A18DC55565B}" = Windows Live Messenger "{BE5FFB4F-FA58-48DF-BDA9-E7AE79DA9C3E}" = Windows Live Family Safety "{BEA0C361-4CEF-4132-AA16-86E95AE9293E}" = Windows Live Essentials "{BFA6D5AD-25EA-475F-AD80-ECD408C674AB}" = Movie Maker "{C034A6F9-6569-491B-B3BF-F5D15221A708}" = Windows Live Essentials "{C08D0804-1DB0-4375-AF23-7120F4C121E1}" = Windows Live Family Safety "{C0AA1615-49F8-4580-A329-63693C7C5127}" = Windows Live Family Safety "{C2F1EBBF-9AC4-4E0B-A7F4-74C9C7AD4813}" = Galerie foto "{C32D87E1-6310-4CD5-8D6D-865AFE0E9B4E}" = Movie Maker "{C32F4F5A-C9FB-427C-9F6F-9DB157611FFF}" = Valokuvavalikoima "{C346ACB1-BD21-402E-8F2D-E08E58AD1105}" = Windows Live Family Safety "{C40D110E-0718-4E11-A69B-D4EC7BF2EB04}" = Windows Live UX Platform Language Pack "{C41A3B9E-A238-4E83-AD37-D1EDD1105F5A}" = Windows Live Writer "{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer "{C4D82144-B2D5-4A0E-A470-16F13EBC5BCB}" = Windows Live Essentials "{C4E8BC59-BD60-4B73-999B-758890DF4E62}" = Windows Live Writer Resources "{C595F480-788A-4F8F-8277-1A91F32CA879}" = Windows Live Writer "{C5B383EB-B85B-481C-9946-34FBF021678B}" = Galerija fotografija "{C67BC332-A59A-4D40-977F-664F60AB21D8}" = Photo Common "{C7929038-EDFB-416D-A2C9-CC65416DA0DF}" = Photo Common "{C8BBA220-8549-462A-B411-1AF44DE098B5}" = Photo Common "{C9A99D28-EE86-4D0F-B3E1-25EB87BFFEB1}" = Windows Live Messenger "{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common "{C9D08433-5FDD-43C6-8482-7AFA7D891D98}" = Windows Live UX Platform Language Pack "{CA5C4498-C7E7-4808-AB41-A2B534A476AF}" = Windows Live Messenger "{CAACAA13-42A3-4FFD-A0AC-B2C6D8626A89}" = Windows Live Writer "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "{CB294330-450C-4704-8F88-06E4C8C97181}" = Windows Live Messenger "{CB51B0C8-57D5-411E-8A69-3F55D3FC8857}" = Windows Live Writer Resources "{CB5CC924-4B5C-4682-BB21-F160C12F56AB}" = Foto-galerija "{CD442136-9115-4236-9C14-278F6A9DCB3F}" = Windows Live Movie Maker "{CE44687E-BC21-4B69-B0AE-6BDFD6B5C327}" = Windows Live Messenger "{CE542E0D-E056-4426-9F98-084C13E18641}" = Windows Live UX Platform Language Pack "{CE7773A5-8556-44A3-84AB-B95F67E8D766}" = Photo Common "{D04EBB49-C985-4A38-8695-62000861293A}" = Raccolta foto "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D0F03C35-6196-4992-8621-6F390DFA9073}" = Windows Live Messenger "{D16E0F0C-5D10-45CF-A585-CE3689B5A913}" = Windows Live Writer "{D1952E4A-9F67-4693-A06D-DA8E0FB2B00D}" = Windows Live Essentials "{D1F5A388-09C9-4998-A793-B15DCDEB3B42}" = Photo Common "{D201E6C1-1A5C-4816-B2C1-89CB6E6C7B3B}" = Windows Live Mail "{D2C146B1-948D-47EF-8387-5D1C6B980F7C}" = Windows Live Writer "{D4EA8070-20E0-4BAF-BC44-D166C292FEBE}" = Windows Live Writer Resources "{D5082B89-2E86-447E-A02C-922534592FA8}" = Photo Common "{D824AFCC-3408-4FB2-A6C9-28C660700DD4}" = Photo Common "{D888F114-7537-4D48-AF03-5DA9C82D7540}" = Photo Common "{D9D4D271-609F-440D-A9EC-A66B0815CFE2}" = Windows Live Essentials "{DAD85607-2C8E-43D5-B068-4B218F1A7DB8}" = Windows Live Mail "{DB169E8F-5332-4DBF-B085-84AA2C373304}" = Windows Live Messenger "{DB7B6508-2AAB-4F26-99D4-74559A2F5E42}" = Fotoğraf Galerisi "{DC8D03B1-FAEA-41AE-82FE-7AA42F77398D}" = Windows Live Family Safety "{DCA5D0DE-F6AC-4E24-A924-03561D26BE97}" = Windows Live Essentials "{DDFF51C0-A729-49E2-B777-8432C0F74FD9}" = Windows Live Mail "{DE256D8B-D971-456D-BC02-CB64DA24F115}" = Easy Software Manager "{DF2B3089-8B7A-4CBC-87D0-8AD60CAED564}" = Windows Live Writer "{DF9A76D9-BBFA-483C-AD7F-7D6E7627AD0E}" = Windows Live Family Safety "{DFB0E1FE-B5DE-42D7-97A9-2A69FB530A73}" = Windows Live Messenger "{DFBFFB0C-EB8A-46C9-9316-202005551897}" = Windows Live Family Safety "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E0AEFDEF-9BC4-4D6F-BE11-B4BD7E3B8816}" = Windows Live Writer "{E0B5FDF0-6940-44B2-8204-CFA746A6B4AF}" = Movie Maker "{E0E0FB88-D570-463E-A98E-733B7B656867}" = Photo Gallery "{E1203F8C-FF34-4968-A4A5-B4F1F8533DAB}" = Photo Common "{E18F981B-401C-4D90-BC57-D8903564D558}" = Windows Live UX Platform Language Pack "{E22E95E7-0A26-4AEC-A907-390C568C5BC1}" = Windows Live Messenger "{E2F4F742-0172-4306-B32E-66DF9CB57992}" = Windows Live Writer Resources "{E354D495-5DA4-4CCF-AB39-080F6A4141BE}" = Fotogalleri "{E37CD6E8-BC51-4D48-9840-803EC3B418D3}" = גלריית התמונות "{E50E3DBC-46AA-4827-B2A6-F995D81DF526}" = Fotótár "{E570053D-8ABC-4938-9E23-C634E08E7490}" = Windows Live Mail "{E6A3F960-E593-4DDE-B9F2-66885D973A26}" = Pošta Windows Live "{E7AE39C6-B669-433F-A351-CA132C611310}" = Windows Live UX Platform Language Pack "{E800ADC4-F459-42F5-89A2-E754634B010A}" = Windows Live Writer Resources "{EA2BE047-FF29-4336-BB70-6AF201085BAF}" = Windows Live 程式集 "{EA348D4B-FB4D-4449-8749-654CA51F56A6}" = Windows Live UX Platform Language Pack "{EB570008-46BB-4126-9016-529FC5D85127}" = Windows Live Pošta "{EB91007A-0110-42A6-B869-2709955A9B2A}" = Photo Common "{EC33D375-5164-4374-9061-43F5C6073219}" = Photo Common "{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker "{EE2E1BED-0821-4244-ABDC-149E9F9750C3}" = Photo Common "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}" = E-POP "{F09DD76B-D3D3-4558-B5BC-F1EEA6E00162}" = Windows Live UX Platform Language Pack "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F0F9505B-3ACF-4158-9311-D0285136AA00}" = Windows Live Essentials "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F1CA7DAE-F998-499C-8CA5-FC58CA2416EC}" = Windows Live Essentials "{F2235E5E-7881-4293-9B6F-04B2609FBFF0}" = Windows Live Messenger "{F29C9CFE-350A-42AC-A7C8-04154D5FE8A9}" = Windows Live Writer "{F341F73D-0D6E-4D37-995D-74F28EBD406C}" = Windows Live Writer Resources "{F5248B7E-779A-4FA4-8134-D1933D8680FA}" = Galeria de Fotos "{F5261248-C4EB-43AD-B07C-9FF9B940896C}" = Photo Gallery "{F54030F3-14B6-432D-9361-78DCB1473920}" = Photo Common "{F54A07A9-9716-4094-9E79-F5E929679FFF}" = Windows Live Writer Resources "{F5E338CE-E1C6-4F7D-8300-44DBD05B9F14}" = Galeria de Fotografias "{F67CA22C-C11F-4573-8406-57F75BA06B51}" = Photo Gallery "{F687E657-F636-44DF-8125-9FEEA2C362F5}" = Easy Support Center 1.0 "{F7304CCF-B4A0-49C7-88A8-CD3F28FFBF9A}" = Основные компоненты Windows Live "{F9B257B6-0DA2-40E1-BAE4-0D64A2C9EE5E}" = Windows Live Essentials "{FA75723A-BF4A-40A2-BFCB-BBC320C27DC9}" = Windows Live Mail "{FB0145BF-B1CD-4681-8ED1-095A7827E2E4}" = Windows Live Writer Resources "{FC1900CF-AC11-49EA-867A-F2AE5830F43A}" = Windows Live Writer Resources "{FC5EAB7E-8898-44C6-85D9-5BC7DAFD80A3}" = Movie Maker "{FC6C7107-7D72-41A1-A031-3CE751159BAB}" = Photo Gallery "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) OpenCL CPU Runtime "{FE5B524F-CD89-4457-B8C1-9299F17E6634}" = Windows Live UX Platform Language Pack "{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE "{FEFD91C5-A25D-48D9-89DA-0FB7BB8B3EF7}" = Windows Live Writer Resources "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "{FFC2BC49-3A72-409C-8176-B3E972DB8603}" = Windows Live Family Safety "{FFFA0584-8E3D-4195-8283-CCA3AD73C746}" = Windows Live Messenger "7-Zip" = 7-Zip 9.20 "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Audacity_is1" = Audacity 2.0.2 "bi_uninstaller" = Bundled software uninstaller "DVD Shrink_is1" = DVD Shrink 3.2 "Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version "Google Chrome" = Google Chrome "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite "InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}" = CyberLink Media+ Player10 "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version "McAfee Security Scan" = McAfee Security Scan Plus "Mozilla Firefox 20.0.1 (x86 de)" = Mozilla Firefox 20.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "NIS" = Norton Internet Security "Office14.PROPLUSR" = Microsoft Office Professional Plus 2010 "PartyPoker" = PartyPoker "Picasa 3" = Picasa 3 "PrintKey2000" = PrintKey2000 "Samsung Universal Print Driver" = Samsung Universal Print Driver "WinLiveSuite" = Windows Live Essentials "WinRAR archiver" = WinRAR 4.20 (32-Bit) "Xerox PhotoCafe" = Xerox PhotoCafe ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-808812791-3364131652-3434471583-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "SkyDriveSetup.exe" = Microsoft SkyDrive ========== Last 20 Event Log Errors ========== [ Spybot - Search and Destroy Events ] Error - 14.05.2013 17:48:11 | Computer Name = samsung-PC | Source = SDCleaner | ID = 100 Description = LoadCleaningInstructions < End of report > [/CODE] |
![]() | #8 |
Hilfe bei der Entfernung von Spyhunter! Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Vollscan mit Malwarebytes - denk bitte vorher daran, Malwarebytes über den Updatebutton zu aktualisieren Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
Hilfe bei der Entfernung von Spyhunter! Hi, Malwarebytes hat nichts gefunden:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.05.16.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 samsung :: SAMSUNG-PC [Administrator] 16.05.2013 20:14:34 mbam-log-2013-05-16 (20-14-34).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 399403 Laufzeit: 43 Minute(n), 11 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Der ESET Scanner hingegen hat drei Sachen gefunden: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=4dfd388151ff9a49b89d538757344abb # engine=13855 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-05-18 08:56:20 # local_time=2013-05-18 10:56:20 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=3591 16777213 100 96 24634719 131492764 0 0 # compatibility_mode=5893 16776573 100 94 48695 120497230 0 0 # scanned=172609 # found=3 # cleaned=0 # scan_time=5024 sh=4ECAEAA68000FEE2E12DE83896A5609B94A1F52B ft=0 fh=0000000000000000 vn="JS/Adware.Yontoo.A application" ac=I fn="C:\$Recycle.Bin\S-1-5-21-808812791-3364131652-3434471583-1001\$RO59M76.crx" sh=56778DC1BFE9E1FA49DF14F166D81F59B6F392A8 ft=1 fh=8c8191f651417f2e vn="a variant of Win32/Adware.Yontoo.A application" ac=I fn="C:\$Recycle.Bin\S-1-5-21-808812791-3364131652-3434471583-1001\$ROZ1OU6.dll" sh=97DE410CA61D4251AFF13C02B6A6362C8C447639 ft=1 fh=fdd990f8020c5088 vn="Win32/Adware.1ClickDownload.W application" ac=I fn="C:\Users\samsung\Downloads\hdplugin_firefox.exe" Danke und viele Grüße |
Hilfe bei der Entfernung von Spyhunter! Was soll das für ein Plugin für den Firefox sein? Liegt bei dir im Download-Ordner Der andere Kram ist Müll, liegt im Papierkorb. Bitte mal TFC anwenden: TFC - Temp File Cleaner Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen.
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
