Log-Analyse und Auswertung: Skypevirus wie entfernen?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.
| ![]() Skypevirus wie entfernen? Hallo Leute ich bitte hier umhilfe, weil ich mir aus lauter dusslichkeit einen Skype Virus eingefangen habe. Nun habe ich schon in YT nachgeschaut wie ich diesen loskriege. Hilft aber nichts kommt immer wieder. Bin absolut neu hier und hoffe ihr könnt mir helfen. |
Skypevirus wie entfernen? Hallo NextEpisode und
Mein Name ist Leo und ich werde dich durch die Bereinigung deines Rechners begleiten. Eins vorneweg: Ich kann dir keine Garantien geben, dass ich alles finden werde. Bei schwerwiegenden Infektionen ist ein Formatieren und Neuinstallieren meist der schnellere und immer der sicherere Weg. Wenn du dich für eine Bereinigung entscheidest, dann sollten wir gründlich vorgehen. Bleib also dran, bis ich dir eindeutig mitteile, dass wir fertig sind. Auch wenn die auffälligen Symptome schon früh verschwinden, bedeutet das nicht, dass dein Rechner dann schon sauber und sicher ist.
Los geht's: Mach bitte die folgenden Scans, damit ich mir ein Bild der Lage machen kann: Schritt 1 Downloade dir bitte defogger (von jpshortstuff) auf deinen Desktop.
Schritt 2 Bitte lade dir ![]()
Schritt 3 Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
Bitte poste in deiner nächsten Antwort:
Skypevirus wie entfernen?
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0A57970E-9B9C-414A-8531-881FC1892855}" = rport=139 | protocol=6 | dir=out | app=system | "{0F8B10BE-B512-43DB-9B5B-FA9EDD09D046}" = rport=138 | protocol=17 | dir=out | app=system | "{145ECE50-FBF3-49F0-A24D-288A60139C61}" = rport=445 | protocol=6 | dir=out | app=system | "{1D2A5F80-8F55-4CAE-B155-D0BA4444C3FC}" = lport=445 | protocol=6 | dir=in | app=system | "{3477F7A9-D46F-46BA-A381-B89F49E8076D}" = lport=57377 | protocol=17 | dir=in | name=pando media booster | "{35B29D31-9BD8-4800-90C2-8E2396CE2658}" = lport=137 | protocol=17 | dir=in | app=system | "{36D284A7-110C-4A8C-B5F1-FDECD1522615}" = lport=57377 | protocol=6 | dir=in | name=pando media booster | "{38D4F270-88FA-4456-AD0D-A651783A94B7}" = lport=57377 | protocol=17 | dir=in | name=pando media booster | "{39847371-B2A9-4772-ADE1-0FD1E022C891}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{438737C6-E65B-41DB-8219-C93DA2CEACF9}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{57A1178F-967B-41D8-8B5C-5DF35DEDD228}" = lport=138 | protocol=17 | dir=in | app=system | "{59FF5343-83E0-4968-AAAC-5039F9B8E375}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{5D38815E-FF43-4C91-BA22-7EB2C83151BA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{711D3EE4-E1EE-4488-8D11-1D921524B528}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{786BC501-8F7A-49FD-9F19-BB2DE7EE547E}" = lport=10243 | protocol=6 | dir=in | app=system | "{85D8A1F6-22CC-419A-8645-9D59C5C22915}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8D98B43F-2D2B-4FCE-BD59-252DE186FDAC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{A0D56080-F5DD-4760-ADC5-B96652489510}" = lport=139 | protocol=6 | dir=in | app=system | "{A19D8207-351F-4B3E-8997-9D3815A8AAB0}" = lport=2869 | protocol=6 | dir=in | app=system | "{C0F498F2-3B85-47F7-BDE6-6ADEECB1CD8D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{CC323590-5E76-4EE1-A59C-3335A3AD45EA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D3C90CEA-AEDF-4B2A-8873-808C0A159224}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{E8B77997-1D49-4796-A4ED-400F3D5BE37D}" = rport=10243 | protocol=6 | dir=out | app=system | "{EF5827D8-886A-4559-8FE2-D9A5AB595516}" = rport=137 | protocol=17 | dir=out | app=system | "{F0592D07-C3D4-4759-B7E8-67F7B0755A30}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{F643036D-B974-4146-BC05-0D52574E9409}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{FE2F4297-F7F9-445A-ACC9-3EF71B24ACFE}" = lport=57377 | protocol=6 | dir=in | name=pando media booster | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{010F903F-2FE7-4827-9DBB-0A369D9B6442}" = protocol=17 | dir=in | app=c:\program files\opera x64\pluginwrapper\opera_plugin_wrapper.exe | "{03C5FA58-3028-4306-882F-53EDE1D21F9A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{03EE940B-212F-40EE-BFFA-B81E4E1A63A2}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{0AA42006-6816-4A6C-835E-4381C16A562A}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{0ABCF163-5BB9-459E-A5CF-967701C3501B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tomb raider\tombraider.exe | "{0E2D7DFE-B122-4C04-A966-3A04B52385B6}" = protocol=6 | dir=out | app=system | "{0F68BD40-2B01-41FB-ABD8-CD3011D9AE26}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{109E1891-65DD-4E97-8398-34556DC25939}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{138BE279-A62B-4ACB-81A8-B433BA55142B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{16C7D152-94F6-49C3-A1F5-5DD656AE6FEC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\bioshockinfinite.exe | "{1C0CB0E8-87F5-45AA-8AE9-F7B91350D8F5}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{2B515A89-EFAB-4C15-BEF0-5699DE9CFA59}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{2E40E0CB-E560-45FD-AFE5-DB841E1B504D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{2F27BA94-08B9-41F9-994F-5F990133F512}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{3359EE95-3126-464A-A9EE-75B9F98B8CDB}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{35D8CD09-FF83-4DC8-9CE2-4A674C49E223}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\surgeon simulator 2013\ss2013.exe | "{3A2B37DA-5824-45C5-AA6E-237BB2E73682}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{3BAD77A5-D0BD-49C1-B671-E608481F87EF}" = protocol=17 | dir=in | app=c:\program files\opera x64\pluginwrapper\opera_plugin_wrapper_32.exe | "{3EAC94BB-FB41-4ED9-804C-243CB54245D6}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{423D173F-0B6B-4EBB-9003-8A4134A9A6E9}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{470142E8-481B-4D4E-9B6D-74F6EDA61E69}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{47BF15EC-E702-459A-B0A9-2DEF1A1BA0AE}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{4D389625-CBDC-499C-862D-A1D361364955}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{4ED7BAB6-3D17-49DE-9591-06627EB6057C}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{4EF47EDC-6047-422A-A811-6969838B0624}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{4EF9A3F9-2370-4443-9C18-6D9D7333EB36}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "{556226B5-FA2D-4D1D-8CC8-A6260E0DC8B1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{55790D07-1CFF-492B-9428-14A9FB81F9B1}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{587E2A97-3A13-408A-AD01-D260B0C6E64C}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{59D9B5DD-DE91-4454-B72C-4FCA4E46AEE9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{5CF34B0E-EB10-487C-838A-44EA05AF0F61}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe | "{5EAE68FB-3EA9-4541-9BC0-A559F45B1524}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\proflamer7\counter-strike source\hl2.exe | "{600D21EF-2D84-4DC0-8FC4-F328A2F25ED2}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{6142CF75-708D-4CCE-A603-D0DC09BE5D69}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{621DA94C-80D6-4318-A06B-D6C0B9331D62}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{62281265-4F5C-494A-9D5B-CE0355AFDD02}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "{62D54517-9E7C-4B3C-8C4F-CE77282803E1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{67E89C98-52E4-4CD9-A6C7-A0AADDA451E2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike source\hl2.exe | "{6E5F2C21-0F5C-4AF3-BEBC-D9898070B826}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tomb raider\tombraider.exe | "{6F9431E8-F404-4656-849E-79E988E2F954}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{700D712B-1992-4498-B7E6-49E2096E5C16}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{7177B2E5-8391-4E38-92F5-4866317B8385}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{7BBF0DC3-4BEC-4197-AF1C-D199B868EE5D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{7CA1E2D3-EB01-4F31-9B25-F3D57C99441E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike source\hl2.exe | "{7FC56366-FD1F-4F9E-9FA8-A59D83F25C52}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe | "{80D02BCA-B77E-4AD5-B3E3-54A4E1A6BD58}" = protocol=17 | dir=in | app=c:\program files\opera x64\opera.exe | "{8883C834-F987-4FF1-9F6D-489E966715EE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\benchmark.bat | "{8EB79922-DFC8-4A0B-8049-DEFCF825F354}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\surgeon simulator 2013\ss2013.exe | "{9721340C-2AE8-46A7-95FC-87B4D8CC5464}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\proflamer7\counter-strike source\hl2.exe | "{97E24CED-CF2D-4DDD-A31B-134B5AD30E06}" = protocol=6 | dir=in | app=c:\program files\opera x64\pluginwrapper\opera_plugin_wrapper_32.exe | "{98412823-3A9C-4838-B299-36ECD9F08B44}" = protocol=6 | dir=in | app=c:\program files\opera x64\pluginwrapper\opera_plugin_wrapper.exe | "{9B2F59FA-1642-4CE8-A94B-066629B5D238}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe | "{9B4175A6-B2D5-4369-B64F-B04E62EBAF9F}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{9DA12057-12FF-4297-B6FE-BA3178709E1B}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{A2D716E7-3507-489D-AE05-55DCDB756D56}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{B3E1F684-A0CD-446F-9BF8-6012712C0BD3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe | "{B500B0D8-D0F8-467C-B2CA-3F736EDB5126}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\bioshockinfinite.exe | "{BB99DA85-1F6D-403D-9347-A643C77B72BB}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{C26E48B3-92D8-4BF0-BBED-929E116DE42F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{C6B16B78-B68A-4698-A8CA-1A53C6B2405E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C73487B1-5FCA-4C74-B8E7-9AF2B230A46A}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "{CD11BBFB-4C50-466B-A757-831284C0155D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{CE1F40C0-CE07-4235-8EF8-B0528271F67C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{CEB77877-8A63-4B2E-B4A2-9EE0FA42AC5A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D2EFDD20-2E95-46F1-BE18-F12A75356042}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{DDE007F3-A543-422E-A095-F7ED531B5E5F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{DEEFFC94-1000-4C60-B739-243030E6E470}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{DFABDCEB-F9DE-4CBD-8E9F-AFBE680855DF}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{E129799C-1EF8-423B-B59A-C24FD0E365D7}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{E66041A3-696D-4CBE-84B2-513F3B62C243}" = protocol=6 | dir=in | app=c:\program files\opera x64\opera.exe | "{E9EEEE63-BC5A-428C-B78E-3941DE23C154}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{EC5E6CFB-6F2E-480A-B135-271929D2C3BD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe | "{EC8A029F-3C4B-4941-A394-8594D98A1672}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe | "{F1D9B46E-216C-4930-A6EB-FBB2A3BC6309}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "{F6396D8B-740B-478D-BC94-C5D23BE9F721}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{FC485575-6A26-44DB-9462-15408CDD95FF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\benchmark.bat | "{FC96CA03-E9F7-4ECB-A6F1-FC44DCDD9BC8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "TCP Query User{6BF50627-B538-4F57-BC58-B1BD9A671A09}C:\program files (x86)\microsoft games\age of empires\empiresx.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires\empiresx.exe | "TCP Query User{95686755-F2E2-42BE-A6B2-8670BD3D0C7D}C:\users\fickdich\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\fickdich\appdata\roaming\spotify\spotify.exe | "TCP Query User{BE1648DC-5A0D-4AC9-A202-2D406947C08E}C:\program files (x86)\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "UDP Query User{6CF660EF-CDFA-4C55-A1A6-3EF4A6689F0D}C:\program files (x86)\microsoft games\age of empires\empiresx.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires\empiresx.exe | "UDP Query User{E5F66372-6DB3-45A4-AB55-7BB007D44C93}C:\program files (x86)\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "UDP Query User{F480345B-9F7B-47D4-935F-D71D7DB993BC}C:\users\fickdich\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\fickdich\appdata\roaming\spotify\spotify.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding "{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes "{0C1DE303-E41B-44BA-8ABA-B7F09D857001}" = Oracle VM VirtualBox 4.2.12 "{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}" = Microsoft .NET Framework 4.5 "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{26A24AE4-039D-4CA4-87B4-2F86417015FF}" = Java 7 Update 15 (64-bit) "{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support "{338CE2A1-7BD6-AC18-0069-4A90F7C3D836}" = AMD Steady Video Plug-In "{35BD87CD-1E57-A87E-53F0-62B9925F7B36}" = AMD Drag and Drop Transcoding "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6397820D-9FC6-774C-1EF5-CBA09049E426}" = AMD Fuel "{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64 "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager "{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}" = Microsoft Xbox 360 Accessories 1.2 "{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant "{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64 "CCleaner" = CCleaner "CPUID CPU-Z_is1" = CPUID CPU-Z 1.64.0 "CPUID HWMonitor_is1" = CPUID HWMonitor 1.22 "CyberGhost VPN_is1" = CyberGhost VPN "HyperCam 2" = HyperCam 2 "Opera 12.14.1738" = Opera 12.14 "TeamSpeak 3 Client" = TeamSpeak 3 Client "VLC media player" = VLC media player 2.0.6 "WinRAR archiver" = WinRAR 4.20 (64-Bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{106B4413-ACBB-4CDE-8707-587DB9BD77EC}" = LogMeIn Hamachi "{13464292-6666-B2DB-1B0C-A3FE14DAD1F9}" = CCC Help Dutch "{185F9795-9663-4F13-9EF9-307A282ADB5A}" = ph "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{26A24AE4-039D-4CA4-87B4-2F83217015FF}" = Java 7 Update 15 "{2A075BB4-E976-4278-BF3F-E5C6945D84C0}" = bl "{338CD56F-1CDC-CF32-33F6-DED2DF92284E}" = CCC Help French "{33999F1F-EA46-4E55-A239-1BA803235396}" = Hercules DJ Products Series drivers "{42DCB650-F003-4535-A5CD-32AD815CD2DD}" = Play withSIX "{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple Application Support "{46458556-5C46-79A9-A6FF-81DF1F8B2729}" = CCC Help Hungarian "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform "{4D594333-0076-A76A-76A7-A758B70B0802}" = Ask Toolbar "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3 "{519D68B8-A768-4CDC-E4C9-B115D49CED93}" = CCC Help Norwegian "{51D383BC-D988-8C1E-FAA1-BC5260A32A87}" = CCC Help Polish "{5A883D2B-D279-0D01-6E62-B810AFD8CC62}" = Catalyst Control Center InstallProxy "{67A4760F-9804-CCF6-C319-27840ED77924}" = CCC Help Korean "{690F5BA3-5DEB-42CD-962B-F687EE59FAA7}" = Windows Live Essentials "{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform "{6BE5E4A9-D88B-532D-26E6-883C32BF098A}" = CCC Help Thai "{6E0D26C1-4265-1D02-4D19-D0A8F6A463F8}" = AMD VISION Engine Control Center "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7176B973-6011-43C1-AEBC-2D73FE7C6982}" = Adobe Premiere Pro CS6 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6 "{75C3C9C0-6CE6-42FA-A0E9-658E8F539124}" = PCMark 7 "{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™ "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7DD62206-7B6C-E32E-BD11-B49B3B089D16}" = CCC Help Danish "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher "{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110 "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{9580813D-94B1-4C28-9426-A441E2BB29A5}" = Counter-Strike: Source "{9739158D-EDED-D628-9865-1460B5A7FAE3}" = CCC Help Portuguese "{9809124C-0C4C-2367-7889-1E16D8EF1AAF}" = CCC Help Chinese Standard "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A6E1EE9D-01DD-82FD-BDBC-193BCEF9FD5C}" = CCC Help Greek "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AB13F192-49FC-A065-F15C-746B10CC43C8}" = CCC Help Japanese "{AE364ACC-B9DF-466B-B4EA-AEECD0CD581E}" = Windows Live Messenger "{AE548812-D611-608D-61C6-7E40F28573A2}" = CCC Help Russian "{AF37176A-78CA-545B-34EF-8B6A21514DD1}" = Adobe Help Manager "{B727564C-47D3-473A-AC9E-F4BE7B1BD5D3}" = Windows Live UX Platform Language Pack "{BC63AEF9-1367-9F7C-5926-52E56450EDCD}" = CCC Help Spanish "{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo "{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6 "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die*Sims™*3 "{C1E2D27F-B363-588E-8859-9EF7F4EBF418}" = CCC Help Chinese Traditional "{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer "{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common "{D76AC809-CCC1-6198-4970-A63FA5CF7DCB}" = CCC Help Swedish "{DA675EE2-4C04-9699-0EE2-7EF9FE7AB870}" = CCC Help German "{E06F7C95-4D68-63D9-2231-AA5F8E186FCB}" = CCC Help English "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E1203F8C-FF34-4968-A4A5-B4F1F8533DAB}" = Photo Common "{E21A8F3C-1ACB-46B1-CE72-E9CF09549DED}" = Catalyst Control Center Localization All "{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding "{E2F52AC2-B925-C18F-E1AE-42FBD46ECAC7}" = CCC Help Czech "{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI "{E649AC39-69C0-C6FE-0A54-4752DB5D1FD2}" = Catalyst Control Center Graphics Previews Common "{E9463114-898C-7C2A-2C47-E9ABC63F5D43}" = CCC Help Finnish "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F2235E5E-7881-4293-9B6F-04B2609FBFF0}" = Windows Live Messenger "{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR "{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE "{FF10AC4D-3349-99DA-3E58-5197CEA1D833}" = CCC Help Italian "{FFEC93FF-C162-C0C3-B5E7-01214B0E5F2D}" = CCC Help Turkish "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Afterburner" = MSI Afterburner 2.3.1 "Age of Empires Gold 1.0" = Microsoft Age of Empires Gold "AVMWLANCLI" = AVM FRITZ!WLAN "BattlEye for OA" = BattlEye for OA Uninstall "bi_uninstaller" = Bundled software uninstaller "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Help Manager "DAEMON Tools Pro" = DAEMON Tools Pro "ESN Sonar-0.70.4" = ESN Sonar "Fraps" = Fraps (remove only) "Google Chrome" = Google Chrome "Gothic_Screenfun" = Gothic (SCREENFUN-DVD November 2005) "LogMeIn Hamachi" = LogMeIn Hamachi "ManyCam" = ManyCam 3.1.53 "MinecraftAlpha" = MinecraftAlpha "Mozilla Firefox 20.0.1 (x86 de)" = Mozilla Firefox 20.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "MTA:SA 1.3" = MTA:SA v1.3.1 "NIS" = Norton Internet Security "Notepad++" = Notepad++ "Origin" = Origin "PremiumSoft Navicat Lite_is1" = PremiumSoft Navicat Lite 10.0 "PunkBusterSvc" = PunkBuster Services "SpeedFan" = SpeedFan (remove only) "Steam App 10180" = Call of Duty: Modern Warfare 2 "Steam App 10190" = Call of Duty: Modern Warfare 2 - Multiplayer "Steam App 203160" = Tomb Raider "Steam App 233720" = Surgeon Simulator 2013 "Steam App 33910" = Arma 2 "Steam App 33930" = Arma 2: Operation Arrowhead "Steam App 42700" = Call of Duty: Black Ops "Steam App 42710" = Call of Duty: Black Ops - Multiplayer "Steam App 8870" = BioShock Infinite "Unigine Heaven Benchmark (Basic Edition)_is1" = Heaven Benchmark version 4.0 "WinLiveSuite" = Windows Live Essentials "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Messenger" = Yahoo! Messenger "Yahoo! Software Update" = Yahoo! Software Update ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "CopyTrans Suite" = Nur Entfernen der CopyTrans Suite möglich "Spotify" = Spotify ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 22.05.2013 12:23:27 | Computer Name = FickDich-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: mc.exe, Version:, Zeitstempel: 0x482ac3b0 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000258 ID des fehlerhaften Prozesses: 0x14f0 Startzeit der fehlerhaften Anwendung: 0x01ce5708ac1e7309 Pfad der fehlerhaften Anwendung: C:\Users\FickDich\Desktop\client dodified-client.v4.5 by '0x72967'@epvp\Modified-Client\mc.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: ee0b8648-c2fb-11e2-b644-bc054303e114 Error - 22.05.2013 12:25:19 | Computer Name = FickDich-PC | Source = SideBySide | ID = 16842832 Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\FickDich\Downloads\SoftonicDownloader_fuer_windows-xp-mode.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error - 23.05.2013 07:02:04 | Computer Name = FickDich-PC | Source = WinMgmt | ID = 10 Description = Error - 23.05.2013 11:47:25 | Computer Name = FickDich-PC | Source = WinMgmt | ID = 10 Description = Error - 23.05.2013 19:16:57 | Computer Name = FickDich-PC | Source = Application Hang | ID = 1002 Description = Programm WinRAR.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1024 Startzeit: 01ce580b72e04b05 Endzeit: 3 Anwendungspfad: C:\Program Files\WinRAR\WinRAR.exe Berichts-ID: db00ace0-c3fe-11e2-872f-bc054303e114 Error - 24.05.2013 05:34:23 | Computer Name = FickDich-PC | Source = WinMgmt | ID = 10 Description = Error - 24.05.2013 14:42:33 | Computer Name = FickDich-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: 7799.exe, Version:, Zeitstempel: 0x519f9c66 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b83c8a Ausnahmecode: 0xe06d7363 Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x1d94 Startzeit der fehlerhaften Anwendung: 0x01ce58ae6aa21c01 Pfad der fehlerhaften Anwendung: C:\ProgramData\7799.exe Pfad des fehlerhaften Moduls: C:\Windows\syswow64\KERNELBASE.dll Berichtskennung: b16ed08e-c4a1-11e2-9570-bc054303e114 Error - 24.05.2013 14:44:45 | Computer Name = FickDich-PC | Source = SideBySide | ID = 16842832 Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\FickDich\Downloads\SoftonicDownloader_fuer_windows-xp-mode.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error - 24.05.2013 15:27:36 | Computer Name = FickDich-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: BC28.exe, Version:, Zeitstempel: 0x519f9c66 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b83c8a Ausnahmecode: 0xe06d7363 Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x13e0 Startzeit der fehlerhaften Anwendung: 0x01ce58b4b955236d Pfad der fehlerhaften Anwendung: C:\ProgramData\BC28.exe Pfad des fehlerhaften Moduls: C:\Windows\syswow64\KERNELBASE.dll Berichtskennung: fce00e46-c4a7-11e2-9570-bc054303e114 Error - 24.05.2013 15:42:30 | Computer Name = FickDich-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: 794F.exe, Version:, Zeitstempel: 0x519f9c66 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b83c8a Ausnahmecode: 0xe06d7363 Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x13e0 Startzeit der fehlerhaften Anwendung: 0x01ce58b6ce93c8d4 Pfad der fehlerhaften Anwendung: C:\ProgramData\794F.exe Pfad des fehlerhaften Moduls: C:\Windows\syswow64\KERNELBASE.dll Berichtskennung: 11a2cb1c-c4aa-11e2-9570-bc054303e114 [ System Events ] Error - 22.05.2013 18:35:58 | Computer Name = FickDich-PC | Source = BROWSER | ID = 8032 Description = Error - 23.05.2013 07:00:58 | Computer Name = FickDich-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "AODDriver4.2.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 23.05.2013 11:46:03 | Computer Name = FickDich-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "AODDriver4.2.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 23.05.2013 11:46:40 | Computer Name = FickDich-PC | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Live ID Sign-in Assistant erreicht. Error - 23.05.2013 11:46:40 | Computer Name = FickDich-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Windows Live ID Sign-in Assistant" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 23.05.2013 11:50:28 | Computer Name = FickDich-PC | Source = bowser | ID = 8003 Description = Error - 24.05.2013 05:33:21 | Computer Name = FickDich-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "AODDriver4.2.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 24.05.2013 06:48:17 | Computer Name = FickDich-PC | Source = DCOM | ID = 10010 Description = Error - 24.05.2013 10:38:35 | Computer Name = FickDich-PC | Source = bowser | ID = 8003 Description = Error - 24.05.2013 14:02:19 | Computer Name = FickDich-PC | Source = BROWSER | ID = 8032 Description = < End of report > Code:
ATTFilter OTL Extras logfile created on: 24.05.2013 22:57:52 - Run 1 OTL by OldTimer - Version Folder = C:\Users\FickDich\Downloads 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16576) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 10,00 Gb Total Physical Memory | 7,52 Gb Available Physical Memory | 75,19% Memory free 20,00 Gb Paging File | 17,44 Gb Available in Paging File | 87,21% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 297,99 Gb Total Space | 64,94 Gb Free Space | 21,79% Space Free | Partition Type: NTFS Computer Name: FICKDICH-PC | User Name: FickDich | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (All) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation) .hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html[@ = Opera.HTML] -- C:\Program Files\Opera x64\Opera.exe (Opera Software) .inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation) .txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .bat [@ = batfile] -- "%1" %* .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cmd [@ = cmdfile] -- "%1" %* .com [@ = comfile] -- "%1" %* .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .exe [@ = exefile] -- "%1" %* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html [@ = Opera.HTML] -- C:\Program Files\Opera x64\Opera.exe (Opera Software) .inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .pif [@ = piffile] -- "%1" %* .reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation) .scr [@ = scrfile] -- "%1" /S .txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Opera x64\Opera.exe" "%1" (Opera Software) https [open] -- "C:\Program Files\Opera x64\Opera.exe" "%1" (Opera Software) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0A57970E-9B9C-414A-8531-881FC1892855}" = rport=139 | protocol=6 | dir=out | app=system | "{0F8B10BE-B512-43DB-9B5B-FA9EDD09D046}" = rport=138 | protocol=17 | dir=out | app=system | "{145ECE50-FBF3-49F0-A24D-288A60139C61}" = rport=445 | protocol=6 | dir=out | app=system | "{1D2A5F80-8F55-4CAE-B155-D0BA4444C3FC}" = lport=445 | protocol=6 | dir=in | app=system | "{3477F7A9-D46F-46BA-A381-B89F49E8076D}" = lport=57377 | protocol=17 | dir=in | name=pando media booster | "{35B29D31-9BD8-4800-90C2-8E2396CE2658}" = lport=137 | protocol=17 | dir=in | app=system | "{36D284A7-110C-4A8C-B5F1-FDECD1522615}" = lport=57377 | protocol=6 | dir=in | name=pando media booster | "{38D4F270-88FA-4456-AD0D-A651783A94B7}" = lport=57377 | protocol=17 | dir=in | name=pando media booster | "{39847371-B2A9-4772-ADE1-0FD1E022C891}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{438737C6-E65B-41DB-8219-C93DA2CEACF9}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{57A1178F-967B-41D8-8B5C-5DF35DEDD228}" = lport=138 | protocol=17 | dir=in | app=system | "{59FF5343-83E0-4968-AAAC-5039F9B8E375}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{5D38815E-FF43-4C91-BA22-7EB2C83151BA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{711D3EE4-E1EE-4488-8D11-1D921524B528}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{786BC501-8F7A-49FD-9F19-BB2DE7EE547E}" = lport=10243 | protocol=6 | dir=in | app=system | "{85D8A1F6-22CC-419A-8645-9D59C5C22915}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8D98B43F-2D2B-4FCE-BD59-252DE186FDAC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{A0D56080-F5DD-4760-ADC5-B96652489510}" = lport=139 | protocol=6 | dir=in | app=system | "{A19D8207-351F-4B3E-8997-9D3815A8AAB0}" = lport=2869 | protocol=6 | dir=in | app=system | "{C0F498F2-3B85-47F7-BDE6-6ADEECB1CD8D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{CC323590-5E76-4EE1-A59C-3335A3AD45EA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D3C90CEA-AEDF-4B2A-8873-808C0A159224}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{E8B77997-1D49-4796-A4ED-400F3D5BE37D}" = rport=10243 | protocol=6 | dir=out | app=system | "{EF5827D8-886A-4559-8FE2-D9A5AB595516}" = rport=137 | protocol=17 | dir=out | app=system | "{F0592D07-C3D4-4759-B7E8-67F7B0755A30}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{F643036D-B974-4146-BC05-0D52574E9409}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{FE2F4297-F7F9-445A-ACC9-3EF71B24ACFE}" = lport=57377 | protocol=6 | dir=in | name=pando media booster | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{010F903F-2FE7-4827-9DBB-0A369D9B6442}" = protocol=17 | dir=in | app=c:\program files\opera x64\pluginwrapper\opera_plugin_wrapper.exe | "{03C5FA58-3028-4306-882F-53EDE1D21F9A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{03EE940B-212F-40EE-BFFA-B81E4E1A63A2}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{0AA42006-6816-4A6C-835E-4381C16A562A}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{0ABCF163-5BB9-459E-A5CF-967701C3501B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tomb raider\tombraider.exe | "{0E2D7DFE-B122-4C04-A966-3A04B52385B6}" = protocol=6 | dir=out | app=system | "{0F68BD40-2B01-41FB-ABD8-CD3011D9AE26}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{109E1891-65DD-4E97-8398-34556DC25939}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{138BE279-A62B-4ACB-81A8-B433BA55142B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{16C7D152-94F6-49C3-A1F5-5DD656AE6FEC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\bioshockinfinite.exe | "{1C0CB0E8-87F5-45AA-8AE9-F7B91350D8F5}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{2B515A89-EFAB-4C15-BEF0-5699DE9CFA59}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{2E40E0CB-E560-45FD-AFE5-DB841E1B504D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{2F27BA94-08B9-41F9-994F-5F990133F512}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{3359EE95-3126-464A-A9EE-75B9F98B8CDB}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{35D8CD09-FF83-4DC8-9CE2-4A674C49E223}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\surgeon simulator 2013\ss2013.exe | "{3A2B37DA-5824-45C5-AA6E-237BB2E73682}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{3BAD77A5-D0BD-49C1-B671-E608481F87EF}" = protocol=17 | dir=in | app=c:\program files\opera x64\pluginwrapper\opera_plugin_wrapper_32.exe | "{3EAC94BB-FB41-4ED9-804C-243CB54245D6}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{423D173F-0B6B-4EBB-9003-8A4134A9A6E9}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{470142E8-481B-4D4E-9B6D-74F6EDA61E69}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{47BF15EC-E702-459A-B0A9-2DEF1A1BA0AE}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{4D389625-CBDC-499C-862D-A1D361364955}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{4ED7BAB6-3D17-49DE-9591-06627EB6057C}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{4EF47EDC-6047-422A-A811-6969838B0624}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{4EF9A3F9-2370-4443-9C18-6D9D7333EB36}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "{556226B5-FA2D-4D1D-8CC8-A6260E0DC8B1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{55790D07-1CFF-492B-9428-14A9FB81F9B1}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{587E2A97-3A13-408A-AD01-D260B0C6E64C}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{59D9B5DD-DE91-4454-B72C-4FCA4E46AEE9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{5CF34B0E-EB10-487C-838A-44EA05AF0F61}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe | "{5EAE68FB-3EA9-4541-9BC0-A559F45B1524}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\proflamer7\counter-strike source\hl2.exe | "{600D21EF-2D84-4DC0-8FC4-F328A2F25ED2}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{6142CF75-708D-4CCE-A603-D0DC09BE5D69}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{621DA94C-80D6-4318-A06B-D6C0B9331D62}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{62281265-4F5C-494A-9D5B-CE0355AFDD02}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "{62D54517-9E7C-4B3C-8C4F-CE77282803E1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{67E89C98-52E4-4CD9-A6C7-A0AADDA451E2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike source\hl2.exe | "{6E5F2C21-0F5C-4AF3-BEBC-D9898070B826}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tomb raider\tombraider.exe | "{6F9431E8-F404-4656-849E-79E988E2F954}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{700D712B-1992-4498-B7E6-49E2096E5C16}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{7177B2E5-8391-4E38-92F5-4866317B8385}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{7BBF0DC3-4BEC-4197-AF1C-D199B868EE5D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{7CA1E2D3-EB01-4F31-9B25-F3D57C99441E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike source\hl2.exe | "{7FC56366-FD1F-4F9E-9FA8-A59D83F25C52}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe | "{80D02BCA-B77E-4AD5-B3E3-54A4E1A6BD58}" = protocol=17 | dir=in | app=c:\program files\opera x64\opera.exe | "{8883C834-F987-4FF1-9F6D-489E966715EE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\benchmark.bat | "{8EB79922-DFC8-4A0B-8049-DEFCF825F354}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\surgeon simulator 2013\ss2013.exe | "{9721340C-2AE8-46A7-95FC-87B4D8CC5464}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\proflamer7\counter-strike source\hl2.exe | "{97E24CED-CF2D-4DDD-A31B-134B5AD30E06}" = protocol=6 | dir=in | app=c:\program files\opera x64\pluginwrapper\opera_plugin_wrapper_32.exe | "{98412823-3A9C-4838-B299-36ECD9F08B44}" = protocol=6 | dir=in | app=c:\program files\opera x64\pluginwrapper\opera_plugin_wrapper.exe | "{9B2F59FA-1642-4CE8-A94B-066629B5D238}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe | "{9B4175A6-B2D5-4369-B64F-B04E62EBAF9F}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{9DA12057-12FF-4297-B6FE-BA3178709E1B}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{A2D716E7-3507-489D-AE05-55DCDB756D56}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{B3E1F684-A0CD-446F-9BF8-6012712C0BD3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe | "{B500B0D8-D0F8-467C-B2CA-3F736EDB5126}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\bioshockinfinite.exe | "{BB99DA85-1F6D-403D-9347-A643C77B72BB}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{C26E48B3-92D8-4BF0-BBED-929E116DE42F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{C6B16B78-B68A-4698-A8CA-1A53C6B2405E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C73487B1-5FCA-4C74-B8E7-9AF2B230A46A}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "{CD11BBFB-4C50-466B-A757-831284C0155D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{CE1F40C0-CE07-4235-8EF8-B0528271F67C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{CEB77877-8A63-4B2E-B4A2-9EE0FA42AC5A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D2EFDD20-2E95-46F1-BE18-F12A75356042}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{DDE007F3-A543-422E-A095-F7ED531B5E5F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{DEEFFC94-1000-4C60-B739-243030E6E470}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{DFABDCEB-F9DE-4CBD-8E9F-AFBE680855DF}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{E129799C-1EF8-423B-B59A-C24FD0E365D7}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{E66041A3-696D-4CBE-84B2-513F3B62C243}" = protocol=6 | dir=in | app=c:\program files\opera x64\opera.exe | "{E9EEEE63-BC5A-428C-B78E-3941DE23C154}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{EC5E6CFB-6F2E-480A-B135-271929D2C3BD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe | "{EC8A029F-3C4B-4941-A394-8594D98A1672}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe | "{F1D9B46E-216C-4930-A6EB-FBB2A3BC6309}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "{F6396D8B-740B-478D-BC94-C5D23BE9F721}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{FC485575-6A26-44DB-9462-15408CDD95FF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\benchmark.bat | "{FC96CA03-E9F7-4ECB-A6F1-FC44DCDD9BC8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "TCP Query User{6BF50627-B538-4F57-BC58-B1BD9A671A09}C:\program files (x86)\microsoft games\age of empires\empiresx.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires\empiresx.exe | "TCP Query User{95686755-F2E2-42BE-A6B2-8670BD3D0C7D}C:\users\fickdich\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\fickdich\appdata\roaming\spotify\spotify.exe | "TCP Query User{BE1648DC-5A0D-4AC9-A202-2D406947C08E}C:\program files (x86)\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "UDP Query User{6CF660EF-CDFA-4C55-A1A6-3EF4A6689F0D}C:\program files (x86)\microsoft games\age of empires\empiresx.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires\empiresx.exe | "UDP Query User{E5F66372-6DB3-45A4-AB55-7BB007D44C93}C:\program files (x86)\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "UDP Query User{F480345B-9F7B-47D4-935F-D71D7DB993BC}C:\users\fickdich\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\fickdich\appdata\roaming\spotify\spotify.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding "{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes "{0C1DE303-E41B-44BA-8ABA-B7F09D857001}" = Oracle VM VirtualBox 4.2.12 "{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}" = Microsoft .NET Framework 4.5 "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{26A24AE4-039D-4CA4-87B4-2F86417015FF}" = Java 7 Update 15 (64-bit) "{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support "{338CE2A1-7BD6-AC18-0069-4A90F7C3D836}" = AMD Steady Video Plug-In "{35BD87CD-1E57-A87E-53F0-62B9925F7B36}" = AMD Drag and Drop Transcoding "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6397820D-9FC6-774C-1EF5-CBA09049E426}" = AMD Fuel "{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64 "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager "{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}" = Microsoft Xbox 360 Accessories 1.2 "{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant "{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64 "CCleaner" = CCleaner "CPUID CPU-Z_is1" = CPUID CPU-Z 1.64.0 "CPUID HWMonitor_is1" = CPUID HWMonitor 1.22 "CyberGhost VPN_is1" = CyberGhost VPN "HyperCam 2" = HyperCam 2 "Opera 12.14.1738" = Opera 12.14 "TeamSpeak 3 Client" = TeamSpeak 3 Client "VLC media player" = VLC media player 2.0.6 "WinRAR archiver" = WinRAR 4.20 (64-Bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{106B4413-ACBB-4CDE-8707-587DB9BD77EC}" = LogMeIn Hamachi "{13464292-6666-B2DB-1B0C-A3FE14DAD1F9}" = CCC Help Dutch "{185F9795-9663-4F13-9EF9-307A282ADB5A}" = ph "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{26A24AE4-039D-4CA4-87B4-2F83217015FF}" = Java 7 Update 15 "{2A075BB4-E976-4278-BF3F-E5C6945D84C0}" = bl "{338CD56F-1CDC-CF32-33F6-DED2DF92284E}" = CCC Help French "{33999F1F-EA46-4E55-A239-1BA803235396}" = Hercules DJ Products Series drivers "{42DCB650-F003-4535-A5CD-32AD815CD2DD}" = Play withSIX "{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple Application Support "{46458556-5C46-79A9-A6FF-81DF1F8B2729}" = CCC Help Hungarian "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform "{4D594333-0076-A76A-76A7-A758B70B0802}" = Ask Toolbar "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3 "{519D68B8-A768-4CDC-E4C9-B115D49CED93}" = CCC Help Norwegian "{51D383BC-D988-8C1E-FAA1-BC5260A32A87}" = CCC Help Polish "{5A883D2B-D279-0D01-6E62-B810AFD8CC62}" = Catalyst Control Center InstallProxy "{67A4760F-9804-CCF6-C319-27840ED77924}" = CCC Help Korean "{690F5BA3-5DEB-42CD-962B-F687EE59FAA7}" = Windows Live Essentials "{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform "{6BE5E4A9-D88B-532D-26E6-883C32BF098A}" = CCC Help Thai "{6E0D26C1-4265-1D02-4D19-D0A8F6A463F8}" = AMD VISION Engine Control Center "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7176B973-6011-43C1-AEBC-2D73FE7C6982}" = Adobe Premiere Pro CS6 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6 "{75C3C9C0-6CE6-42FA-A0E9-658E8F539124}" = PCMark 7 "{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™ "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7DD62206-7B6C-E32E-BD11-B49B3B089D16}" = CCC Help Danish "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher "{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110 "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{9580813D-94B1-4C28-9426-A441E2BB29A5}" = Counter-Strike: Source "{9739158D-EDED-D628-9865-1460B5A7FAE3}" = CCC Help Portuguese "{9809124C-0C4C-2367-7889-1E16D8EF1AAF}" = CCC Help Chinese Standard "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A6E1EE9D-01DD-82FD-BDBC-193BCEF9FD5C}" = CCC Help Greek "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AB13F192-49FC-A065-F15C-746B10CC43C8}" = CCC Help Japanese "{AE364ACC-B9DF-466B-B4EA-AEECD0CD581E}" = Windows Live Messenger "{AE548812-D611-608D-61C6-7E40F28573A2}" = CCC Help Russian "{AF37176A-78CA-545B-34EF-8B6A21514DD1}" = Adobe Help Manager "{B727564C-47D3-473A-AC9E-F4BE7B1BD5D3}" = Windows Live UX Platform Language Pack "{BC63AEF9-1367-9F7C-5926-52E56450EDCD}" = CCC Help Spanish "{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo "{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6 "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die*Sims™*3 "{C1E2D27F-B363-588E-8859-9EF7F4EBF418}" = CCC Help Chinese Traditional "{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer "{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common "{D76AC809-CCC1-6198-4970-A63FA5CF7DCB}" = CCC Help Swedish "{DA675EE2-4C04-9699-0EE2-7EF9FE7AB870}" = CCC Help German "{E06F7C95-4D68-63D9-2231-AA5F8E186FCB}" = CCC Help English "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E1203F8C-FF34-4968-A4A5-B4F1F8533DAB}" = Photo Common "{E21A8F3C-1ACB-46B1-CE72-E9CF09549DED}" = Catalyst Control Center Localization All "{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding "{E2F52AC2-B925-C18F-E1AE-42FBD46ECAC7}" = CCC Help Czech "{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI "{E649AC39-69C0-C6FE-0A54-4752DB5D1FD2}" = Catalyst Control Center Graphics Previews Common "{E9463114-898C-7C2A-2C47-E9ABC63F5D43}" = CCC Help Finnish "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F2235E5E-7881-4293-9B6F-04B2609FBFF0}" = Windows Live Messenger "{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR "{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE "{FF10AC4D-3349-99DA-3E58-5197CEA1D833}" = CCC Help Italian "{FFEC93FF-C162-C0C3-B5E7-01214B0E5F2D}" = CCC Help Turkish "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Afterburner" = MSI Afterburner 2.3.1 "Age of Empires Gold 1.0" = Microsoft Age of Empires Gold "AVMWLANCLI" = AVM FRITZ!WLAN "BattlEye for OA" = BattlEye for OA Uninstall "bi_uninstaller" = Bundled software uninstaller "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Help Manager "DAEMON Tools Pro" = DAEMON Tools Pro "ESN Sonar-0.70.4" = ESN Sonar "Fraps" = Fraps (remove only) "Google Chrome" = Google Chrome "Gothic_Screenfun" = Gothic (SCREENFUN-DVD November 2005) "LogMeIn Hamachi" = LogMeIn Hamachi "ManyCam" = ManyCam 3.1.53 "MinecraftAlpha" = MinecraftAlpha "Mozilla Firefox 20.0.1 (x86 de)" = Mozilla Firefox 20.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "MTA:SA 1.3" = MTA:SA v1.3.1 "NIS" = Norton Internet Security "Notepad++" = Notepad++ "Origin" = Origin "PremiumSoft Navicat Lite_is1" = PremiumSoft Navicat Lite 10.0 "PunkBusterSvc" = PunkBuster Services "SpeedFan" = SpeedFan (remove only) "Steam App 10180" = Call of Duty: Modern Warfare 2 "Steam App 10190" = Call of Duty: Modern Warfare 2 - Multiplayer "Steam App 203160" = Tomb Raider "Steam App 233720" = Surgeon Simulator 2013 "Steam App 33910" = Arma 2 "Steam App 33930" = Arma 2: Operation Arrowhead "Steam App 42700" = Call of Duty: Black Ops "Steam App 42710" = Call of Duty: Black Ops - Multiplayer "Steam App 8870" = BioShock Infinite "Unigine Heaven Benchmark (Basic Edition)_is1" = Heaven Benchmark version 4.0 "WinLiveSuite" = Windows Live Essentials "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Messenger" = Yahoo! Messenger "Yahoo! Software Update" = Yahoo! Software Update ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "CopyTrans Suite" = Nur Entfernen der CopyTrans Suite möglich "Spotify" = Spotify ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 22.05.2013 12:23:27 | Computer Name = FickDich-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: mc.exe, Version:, Zeitstempel: 0x482ac3b0 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000258 ID des fehlerhaften Prozesses: 0x14f0 Startzeit der fehlerhaften Anwendung: 0x01ce5708ac1e7309 Pfad der fehlerhaften Anwendung: C:\Users\FickDich\Desktop\client dodified-client.v4.5 by '0x72967'@epvp\Modified-Client\mc.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: ee0b8648-c2fb-11e2-b644-bc054303e114 Error - 22.05.2013 12:25:19 | Computer Name = FickDich-PC | Source = SideBySide | ID = 16842832 Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\FickDich\Downloads\SoftonicDownloader_fuer_windows-xp-mode.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error - 23.05.2013 07:02:04 | Computer Name = FickDich-PC | Source = WinMgmt | ID = 10 Description = Error - 23.05.2013 11:47:25 | Computer Name = FickDich-PC | Source = WinMgmt | ID = 10 Description = Error - 23.05.2013 19:16:57 | Computer Name = FickDich-PC | Source = Application Hang | ID = 1002 Description = Programm WinRAR.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1024 Startzeit: 01ce580b72e04b05 Endzeit: 3 Anwendungspfad: C:\Program Files\WinRAR\WinRAR.exe Berichts-ID: db00ace0-c3fe-11e2-872f-bc054303e114 Error - 24.05.2013 05:34:23 | Computer Name = FickDich-PC | Source = WinMgmt | ID = 10 Description = Error - 24.05.2013 14:42:33 | Computer Name = FickDich-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: 7799.exe, Version:, Zeitstempel: 0x519f9c66 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b83c8a Ausnahmecode: 0xe06d7363 Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x1d94 Startzeit der fehlerhaften Anwendung: 0x01ce58ae6aa21c01 Pfad der fehlerhaften Anwendung: C:\ProgramData\7799.exe Pfad des fehlerhaften Moduls: C:\Windows\syswow64\KERNELBASE.dll Berichtskennung: b16ed08e-c4a1-11e2-9570-bc054303e114 Error - 24.05.2013 14:44:45 | Computer Name = FickDich-PC | Source = SideBySide | ID = 16842832 Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\FickDich\Downloads\SoftonicDownloader_fuer_windows-xp-mode.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error - 24.05.2013 15:27:36 | Computer Name = FickDich-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: BC28.exe, Version:, Zeitstempel: 0x519f9c66 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b83c8a Ausnahmecode: 0xe06d7363 Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x13e0 Startzeit der fehlerhaften Anwendung: 0x01ce58b4b955236d Pfad der fehlerhaften Anwendung: C:\ProgramData\BC28.exe Pfad des fehlerhaften Moduls: C:\Windows\syswow64\KERNELBASE.dll Berichtskennung: fce00e46-c4a7-11e2-9570-bc054303e114 Error - 24.05.2013 15:42:30 | Computer Name = FickDich-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: 794F.exe, Version:, Zeitstempel: 0x519f9c66 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b83c8a Ausnahmecode: 0xe06d7363 Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x13e0 Startzeit der fehlerhaften Anwendung: 0x01ce58b6ce93c8d4 Pfad der fehlerhaften Anwendung: C:\ProgramData\794F.exe Pfad des fehlerhaften Moduls: C:\Windows\syswow64\KERNELBASE.dll Berichtskennung: 11a2cb1c-c4aa-11e2-9570-bc054303e114 [ System Events ] Error - 22.05.2013 18:35:58 | Computer Name = FickDich-PC | Source = BROWSER | ID = 8032 Description = Error - 23.05.2013 07:00:58 | Computer Name = FickDich-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "AODDriver4.2.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 23.05.2013 11:46:03 | Computer Name = FickDich-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "AODDriver4.2.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 23.05.2013 11:46:40 | Computer Name = FickDich-PC | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Live ID Sign-in Assistant erreicht. Error - 23.05.2013 11:46:40 | Computer Name = FickDich-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Windows Live ID Sign-in Assistant" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 23.05.2013 11:50:28 | Computer Name = FickDich-PC | Source = bowser | ID = 8003 Description = Error - 24.05.2013 05:33:21 | Computer Name = FickDich-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "AODDriver4.2.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 24.05.2013 06:48:17 | Computer Name = FickDich-PC | Source = DCOM | ID = 10010 Description = Error - 24.05.2013 10:38:35 | Computer Name = FickDich-PC | Source = bowser | ID = 8003 Description = Error - 24.05.2013 14:02:19 | Computer Name = FickDich-PC | Source = BROWSER | ID = 8032 Description = < End of report > Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-05-24 22:56:45 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_HD322HJ rev.1AC01118 298,09GB Running: 6mehidhh.exe; Driver: C:\Users\FickDich\AppData\Local\Temp\pxlcakoc.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\Explorer.EXE[1880] C:\Windows\SYSTEM32\ntdll.dll!atan 0000000077cc9604 39 bytes [40, 53, 48, 83, EC, 30, 80, ...] .text C:\Windows\Explorer.EXE[1880] C:\Windows\SYSTEM32\ntdll.dll!atan + 40 0000000077cc962c 1 byte [F8] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000073b01a22 2 bytes [B0, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000073b01ad0 2 bytes [B0, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000073b01b08 2 bytes [B0, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000073b01bba 2 bytes [B0, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000073b01bda 2 bytes [B0, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077df1465 2 bytes [DF, 77] .text C:\Windows\SysWOW64\PnkBstrA.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077df14bb 2 bytes [DF, 77] .text ... * 2 .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2620] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000761587b1 5 bytes [33, C0, C2, 04, 00] .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077df1465 2 bytes [DF, 77] .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077df14bb 2 bytes [DF, 77] .text ... * 2 ---- Threads - GMER 2.1 ---- Thread C:\Windows\Explorer.EXE [1880:7004] 0000000002c248b0 Thread C:\Windows\Explorer.EXE [1880:6732] 0000000002c257a0 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch@Epoch 24831 Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch@Epoch 24831 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 Windows 7 default MBR code found via API Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- Code:
![]() | #5 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Skypevirus wie entfernen? Hi, ja du bist infiziert. Das werden wir entfernen. Aber zuvor muss noch was geklärt werden: Schritt 1 Downloade dir bitte ![]()
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). Schritt 2 Lade dir bitte Emsisoft MBR Master herunter und speichere es auf den Desktop.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
![]() | #6 |
| ![]() Skypevirus wie entfernen?Code:
ATTFilter aswMBR version Copyright(c) 2011 AVAST Software Run date: 2013-05-25 01:58:37 ----------------------------- 01:58:37.356 OS Version: Windows x64 6.1.7601 Service Pack 1 01:58:37.356 Number of processors: 4 586 0x403 01:58:37.356 ComputerName: FICKDICH-PC UserName: FickDich 01:58:42.338 Initialize success 02:04:51.812 AVAST engine defs: 13052400 02:05:10.366 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 02:05:10.368 Disk 0 Vendor: SAMSUNG_HD322HJ 1AC01118 Size: 305245MB BusType: 3 02:05:10.464 Disk 0 MBR read successfully 02:05:10.466 Disk 0 MBR scan 02:05:10.469 Disk 0 Windows 7 default MBR code 02:05:10.480 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 02:05:10.483 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 305143 MB offset 206848 02:05:10.510 Disk 0 scanning C:\Windows\system32\drivers 02:05:21.653 Service scanning 02:05:38.543 Modules scanning 02:05:38.547 Disk 0 trace - called modules: 02:05:38.556 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 02:05:38.558 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80092f8060] 02:05:38.562 3 CLASSPNP.SYS[fffff880011ce43f] -> nt!IofCallDriver -> [0xfffffa8008324580] 02:05:38.567 5 ACPI.sys[fffff88000f337a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800832b060] 02:05:39.199 AVAST engine scan C:\Windows 02:05:41.668 AVAST engine scan C:\Windows\system32 02:07:54.978 AVAST engine scan C:\Windows\system32\drivers 02:08:05.927 AVAST engine scan C:\Users\FickDich 02:09:36.221 File: C:\Users\FickDich\AppData\LocalOZEJJPIgAe.exe **INFECTED** MSIL:Bladabindi-AZ [Trj] 02:13:03.891 AVAST engine scan C:\ProgramData 02:14:01.651 Scan finished successfully 02:15:34.440 Disk 0 MBR has been saved successfully to "C:\Users\FickDich\Desktop\MBR.dat" 02:15:34.445 The log file has been saved successfully to "C:\Users\FickDich\Desktop\aswMBR.txt" Code:
ATTFilter Detected Windows version: 6.1 Build 7601 Service Pack 1 Installing direct disk access driver ... Driver connection handle: 0x00000118 1 valid drive(s) found. Details for Disk 0 - SAMSUNG HD322HJ Rev 1AC01118: Device name : \\.\PhysicalDrive0 Geometry (C/H/S) : 38913/255/63 Boot loader reputation : Known Good (Windows 7) Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 MD5 : A36C5E4F47E84449FF07ED3517B43A31 |
![]() | #7 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Skypevirus wie entfernen? Hm, da muss man auf Nummer sicher gehen..
__________________ cheers, Leo |
![]() | #8 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Skypevirus wie entfernen? Hi, ich hab schon länger keine Antwort mehr von dir erhalten. Brauchst du weiterhin noch Hilfe? Wenn ich in den nächsten 24 Stunden nichts von dir höre, gehe ich davon aus, dass sich das Thema erledigt hat und lösche es aus meinen Abos. Hinweis: Wir sind noch nicht fertig! Auch wenn die Symptome verschwunden sein sollten, kann dein System weiterhin infiziert sein und über Sicherheitslücken verfügen, welche eine erneute Infektion möglich machen.
__________________ cheers, Leo |
![]() | #9 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Skypevirus wie entfernen? Fehlende Rückmeldung Dieses Thema wurde aus meinen Abos gelöscht. Somit bekomme ich keine Benachrichtigung mehr über neue Antworten. Schreib mir eine PM, falls du das Thema doch wieder fortsetzen möchtest. Dann machen wir hier weiter. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass dein Rechner schon sauber ist. Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
![]() |
Themen zu Skypevirus wie entfernen? |
absolut, eingefangen, entferne, entfernen, gefangen, gen, hoffe, lauter, leute, neu, nichts, skype, skype virus, skypevirus, virus, virus eingefangen, wie entfernen, wie entfernen? |