![]() ![]() | ![]() Coin Miner,msdcsc entfernen Hallo habe schon ein passendes Thema gefunden allerdings wurde es nicht beendet bzw keine Lösung gefunden. Mein Problem ist das auf meinem Pc Coin Miner und msdcsc.exe sind. Habe schon MBAM scanen gelassen und OTL hat auch schon gescannt hier die Auswertung von OTL.txt : Code:
ATTFilter OTL logfile created on: 08.06.2013 20:18:27 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Fabian\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,91 Gb Total Physical Memory | 5,21 Gb Available Physical Memory | 65,78% Memory free 15,83 Gb Paging File | 12,99 Gb Available in Paging File | 82,09% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,66 Gb Total Space | 108,95 Gb Free Space | 23,40% Space Free | Partition Type: NTFS Computer Name: FABIAN-PC | User Name: Fabian | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - File not found PRC - C:\Users\Fabian\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Users\Fabian\AppData\Roaming\Acrobat\AcroRd32.exe (Adobe Systems Incorporated) PRC - C:\Users\Fabian\AppData\Local\Temp\82267msdcsc.exe () PRC - C:\Users\Fabian\AppData\Local\Temp\32992msdcsc.exe () PRC - C:\Windows\SysWOW64\PnkBstrA.exe () PRC - C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.) PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) PRC - C:\ProgramData\GinyasBrowserCompanion\tbhcn.exe (Blabbers Communications Ltd) PRC - C:\Programme\Web Assistant\ExtensionUpdaterService.exe () PRC - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe () PRC - C:\Users\Fabian\AppData\Roaming\BrowserCompanion\tbhcn.exe () PRC - C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe () PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) PRC - C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (AVM Berlin) PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Razer\Arctosa\razerhid.exe (Razer USA Ltd.) ========== Modules (No Company Name) ========== MOD - C:\Users\Fabian\AppData\Local\Temp\82267msdcsc.exe () MOD - C:\Users\Fabian\AppData\Local\Temp\32992msdcsc.exe () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\153143f74d840484b510d8cf5187796b\System.Windows.Forms.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a9594959e951127f16eb49644ba92f79\PresentationFramework.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\7cfbbd029ef945fbcdaedd24b2b67a24\PresentationCore.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\2f9e0112e10f9e70d3430d0be9863976\System.Core.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\af18b8a8f56494da44cc448f3b9704a5\WindowsBase.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\233661f3a2b632e9553915c8639637d0\System.Configuration.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\ac9e3eca6c148504588e7c6d09fe83e3\System.Management.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\ef7642a4f2724135d445e2ea36582e78\SMDiagnostics.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\866894ebe5258bf9f45d6b063229e990\System.Xaml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\43cd41484df96d15df949eb17dd88152\System.Xml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b573c6a62bb88df0ee2af59b6a8ca910\System.Drawing.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\dfeff31ab1e7cd3480c8942290c92f5d\PresentationFramework.Aero.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll () MOD - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe () MOD - C:\Users\Fabian\AppData\Roaming\BrowserCompanion\tbhcn.exe () MOD - C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll () MOD - C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe () MOD - C:\Program Files (x86)\MOUSE Editor\Data\MouseEditor\Forms\ScreenCapture\ScreenCapture.dll () MOD - C:\Program Files (x86)\MOUSE Editor\DLL\DLL_Wheel4D.dll () MOD - C:\Program Files (x86)\MOUSE Editor\DLL\DLL_AnalyzeGesturesInRight.dll () MOD - C:\Program Files (x86)\MOUSE Editor\Data\MouseEditor\Forms\TrayIconWebAdvertisement\TrayIconWebAdvertisement.dll () MOD - C:\Program Files (x86)\MOUSE Editor\DLL\DLL_MouseDeviceManager.dll () MOD - C:\Program Files (x86)\MOUSE Editor\Data\MouseEditor\Forms\OSD_Text\OSD_Text.dll () MOD - C:\Program Files (x86)\MOUSE Editor\DLL\DLL_AnalyzeGesturesInOne.dll () MOD - C:\Program Files (x86)\MOUSE Editor\DLL\DLL_ZoomControl.dll () MOD - C:\Program Files (x86)\MOUSE Editor\DLL\DLL_ScrollbarControl.dll () ========== Services (SafeList) ========== SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe () SRV - (BsUpdate) -- C:\Programme\BullGuard Ltd\BullGuard\BullGuardUpdate.exe (BullGuard Ltd.) SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) SRV - (HiPatchService) -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Hi-Rez Studios) SRV - (RzOvlMon) -- C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe (Razer) SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) SRV - (Akamai) -- c:\program files (x86)\common files\akamai/netsession_win_ca0e279.dll () SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies) SRV - (Web Assistant) -- C:\Programme\Web Assistant\ExtensionUpdaterService.exe () SRV - (BsFire) -- c:\Programme\BullGuard Ltd\BullGuard\BsFire.dll (BullGuard Ltd.) SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation) SRV - (BsMain) -- C:\Programme\BullGuard Ltd\BullGuard\BsMain.dll (BullGuard Ltd.) SRV - (BsScanner) -- C:\Programme\BullGuard Ltd\BullGuard\BullGuardScanner.exe (BullGuard Ltd.) SRV - (BsBhvScan) -- C:\Programme\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe (BullGuard Ltd.) SRV - (BsFileScan) -- c:\Programme\BullGuard Ltd\BullGuard\BsFileScan.dll (BullGuard Ltd.) SRV - (BsMailProxy) -- c:\Programme\BullGuard Ltd\BullGuard\BsMailProxy\BsMailProxy.dll (BullGuard Ltd.) SRV - (BsBackup) -- C:\Programme\BullGuard Ltd\BullGuard\BsBackup.dll (BullGuard Ltd.) SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia) SRV - (OfficeSvc) -- C:\Programme\Microsoft Office 15\ClientX64\integratedoffice.exe (Microsoft Corporation) SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (cFosSpeedS) -- C:\Programme\ASRock\XFast LAN\spd.exe (cFos Software GmbH) SRV - (nlsvc) -- C:\Programme\NetLimiter 3\nlsvc.exe (Locktime Software) SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) SRV - (AVM WLAN Connection Service) -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (AVM Berlin) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (rzudd) -- C:\Windows\SysNative\drivers\rzudd.sys (Razer Inc) DRV:64bit: - (rzendpt) -- C:\Windows\SysNative\drivers\rzendpt.sys (Razer Inc) DRV:64bit: - (RzDxgk) -- C:\Windows\SysNative\drivers\RzDxgk.sys (Razer USA Ltd) DRV:64bit: - (RzFilter) -- C:\Windows\SysNative\drivers\RzFilter.sys (Razer USA Ltd) DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation) DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation) DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) DRV:64bit: - (AFW) -- C:\Windows\SysNative\drivers\afw.sys (Agnitum Ltd.) DRV:64bit: - (afwcore) -- C:\Windows\SysNative\drivers\afwcore.sys (Agnitum Ltd.) DRV:64bit: - (BdNet) -- C:\Windows\SysNative\drivers\BdNet.sys (BullGuard Ltd.) DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.) DRV:64bit: - (truecrypt) -- C:\Windows\SysNative\drivers\truecrypt.sys (TrueCrypt Foundation) DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia) DRV:64bit: - (BdSpy) -- C:\Windows\SysNative\drivers\BdSpy.sys (BullGuard Ltd.) DRV:64bit: - (Trufos) -- C:\Windows\SysNative\drivers\Trufos.sys (BitDefender S.R.L.) DRV:64bit: - (NovaShieldFilterDriver) -- C:\Windows\SysNative\drivers\NSKernel.sys (NovaShield, Inc.) DRV:64bit: - (NovaShieldTDIDriver) -- C:\Windows\SysNative\drivers\NSNetmon.sys (NovaShield, Inc.) DRV:64bit: - (nmwcdc) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia) DRV:64bit: - (nmwcd) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia) DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys (Nokia) DRV:64bit: - (upperdev) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia) DRV:64bit: - (FNETTBOH_305) -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS (FNet Co., Ltd.) DRV:64bit: - (FNETURPX) -- C:\Windows\SysNative\drivers\FNETURPX.SYS (FNet Co., Ltd.) DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (tap0901) -- C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project) DRV:64bit: - (VirtuWDDM) -- C:\Windows\SysNative\drivers\VirtuWDDM.sys (Lucidlogix Inc.) DRV:64bit: - (cFosSpeed) -- C:\Windows\SysNative\drivers\cfosspeed6.sys (cFos Software GmbH) DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek ) DRV:64bit: - (LADF_RenderOnly) -- C:\Windows\SysNative\drivers\ladfGSRamd64.sys (Logitech) DRV:64bit: - (LADF_CaptureOnly) -- C:\Windows\SysNative\drivers\ladfGSCamd64.sys (Logitech) DRV:64bit: - (NLNdisPT) -- C:\Windows\SysNative\drivers\nlndis.sys (Locktime Software) DRV:64bit: - (NLNdisMP) -- C:\Windows\SysNative\drivers\nlndis.sys (Locktime Software) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (VClone) -- C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation) DRV:64bit: - (FWLANUSB) -- C:\Windows\SysNative\drivers\fwlanusb.sys (AVM GmbH) DRV:64bit: - (avmeject) -- C:\Windows\SysNative\drivers\avmeject.sys (AVM Berlin) DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation) DRV:64bit: - (LADF_SBVM) -- C:\Windows\SysNative\drivers\ladfSBVMamd64.sys (Logitech) DRV:64bit: - (LADF_DHP2) -- C:\Windows\SysNative\drivers\ladfDHP2amd64.sys (Logitech) DRV:64bit: - (ScreamBAudioSvc) -- C:\Windows\SysNative\drivers\ScreamingBAudio64.sys (Screaming Bee LLC) DRV:64bit: - (LGVirHid) -- C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.) DRV:64bit: - (LGBusEnum) -- C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.) DRV:64bit: - (MBfilt) -- C:\Windows\SysNative\drivers\MBfilt64.sys (Creative Technology Ltd.) DRV:64bit: - (Arctosa) -- C:\Windows\SysNative\drivers\Arctosa.sys (Razer USA Ltd.) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (xnacc) -- C:\Windows\SysNative\drivers\xnacc.sys (Microsoft Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.) DRV:64bit: - (athrusb) -- C:\Windows\SysNative\drivers\athrxusb.sys (Atheros Communications, Inc.) DRV - (nltdi) -- C:\Programme\NetLimiter 3\nltdi.sys (Locktime Software) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) DRV - (tandpl) -- C:\Windows\SysWOW64\drivers\tandpl.sys () ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = hxxp://search.babylon.com/?affID=110819&tt=120812_bandext_3312_6&babsrc=HP_ss&mntrId=50877b67000000000000bc5ff41a74a3 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/go/x0m [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-search.com/?affID=122304&tt=gc_&babsrc=HP_ss&mntrId=5087BC5FF41A74A3 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B8 46 A7 B4 BC 44 CD 01 [binary data] IE - HKCU\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://www.delta-search.com/?q={searchTerms}&affID=122304&tt=gc_&babsrc=SP_ss&mntrId=5087BC5FF41A74A3 IE - HKCU\..\SearchScopes\{32D25FF0-DED2-4F55-8808-D75183262EC7}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=6E7F53E6-DA4D-4DD5-BECC-02892B368336&apn_sauid=B69CFF74-9B41-4718-BB59-06F8B6687D05 IE - HKCU\..\SearchScopes\{407B02DB-A303-4e4a-BCAA-D1DE53A58BFE}: "URL" = hxxp://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=5480255188&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=de&q={searchTerms} IE - HKCU\..\SearchScopes\{4327FABE-3C22-4689-8DBF-D226CF777FE9}: "URL" = hxxp://www.searchplusnetwork.com/?sp=vit4&q={searchTerms} IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredibar.com/mb203?a=6OyWybSbU9&search={searchTerms}&i=26 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local;<local> ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.10 FF - prefs.js..browser.startup.homepage: FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@gametap.com/npdd,version=1.0: C:\Program Files (x86)\Downloader\npdd.dll (Metaboli) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@raidcall.en/RCplugin: C:\Users\Fabian\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Fabian\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Fabian\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2013.03.04 18:35:40 | 000,000,000 | ---D | M] 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2013.03.04 18:35:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2013.03.04 18:35:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\antiphishing@bullguard: C:\Program Files\BullGuard Ltd\BullGuard\Files32\Antiphishing\FF\antiphishing@bullguard\ [2012.10.28 00:59:05 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}: C:\Program Files\Web Assistant\Firefox [2013.03.04 18:35:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.15 18:03:35 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{380AE6CB-09B9-4373-B360-D01C2462A6E7}: C:\Program Files\BullGuard Ltd\BullGuard\files32\backup\thunderbirdbkplugin [2012.11.15 20:50:18 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{0E810812-F4BB-4309-942A-755587587A5E}: C:\Program Files\BullGuard Ltd\BullGuard\Files32\Spamfilter\TbSpamfilter [2012.11.15 20:50:18 | 000,000,000 | ---D | M] [2012.08.13 18:07:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Fabian\AppData\Roaming\mozilla\Extensions [2013.06.08 18:29:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Fabian\AppData\Roaming\mozilla\Firefox\Profiles\a7zvye9k.default\extensions [2013.03.15 15:30:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Fabian\AppData\Roaming\mozilla\Firefox\Profiles\a7zvye9k.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088} [2013.02.23 16:27:07 | 000,000,000 | ---D | M] (Ginyas Browser Companion) -- C:\Users\Fabian\AppData\Roaming\mozilla\Firefox\Profiles\a7zvye9k.default\extensions\bbrs_002@blabbers.com [2013.03.17 14:07:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Fabian\AppData\Roaming\mozilla\Firefox\Profiles\a7zvye9k.default\extensions\ffxtlbr@babylon.com [2013.03.17 14:08:50 | 000,000,000 | ---D | M] (Pagealicious) -- C:\Users\Fabian\AppData\Roaming\mozilla\Firefox\Profiles\a7zvye9k.default\extensions\Pagealicious [2013.02.20 22:05:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Fabian\AppData\Roaming\mozilla\Firefox\Profiles\a7zvye9k.default\extensions\staged [2012.10.27 21:41:39 | 000,002,515 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\mozilla\firefox\profiles\a7zvye9k.default\searchplugins\ask-search.xml [2012.11.10 23:15:25 | 000,002,308 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\mozilla\firefox\profiles\a7zvye9k.default\searchplugins\askcom.xml [2013.05.30 01:21:47 | 000,006,503 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\mozilla\firefox\profiles\a7zvye9k.default\searchplugins\babylon.xml [2012.08.14 19:30:50 | 000,002,227 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\mozilla\firefox\profiles\a7zvye9k.default\searchplugins\BabylonMngr.xml [2013.05.01 22:04:45 | 000,006,481 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\mozilla\firefox\profiles\a7zvye9k.default\searchplugins\BrowserProtect.xml [2013.03.17 14:07:33 | 000,001,300 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\mozilla\firefox\profiles\a7zvye9k.default\searchplugins\claro.xml [2013.05.30 01:22:09 | 000,001,294 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\mozilla\firefox\profiles\a7zvye9k.default\searchplugins\delta.xml [2013.06.08 18:25:14 | 000,002,120 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\mozilla\firefox\profiles\a7zvye9k.default\searchplugins\MyStart Search.xml [2013.02.20 22:06:28 | 000,002,060 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\mozilla\firefox\profiles\a7zvye9k.default\searchplugins\softonic.xml [2012.08.13 18:06:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions File not found (No name found) -- C:\USERS\FABIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\A7ZVYE9K.DEFAULT\EXTENSIONS\{ACAA314B-EEBA-48E4-AD47-84E31C44796C} [2012.07.14 02:15:45 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012.07.14 02:45:08 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.03.17 14:07:18 | 000,006,478 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml [2012.07.14 02:45:08 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012.07.14 02:45:08 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012.07.14 02:45:08 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012.07.14 02:45:08 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012.07.14 02:45:07 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR - homepage: hxxp://www.delta-search.com/?affID=122304&tt=gc_&babsrc=HP_ss&mntrId=5087BC5FF41A74A3 CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\Fabian\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Fabian\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Fabian\AppData\Local\Google\Chrome\Application\27.0.1453.110\gcswf32.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - Extension: YouTube = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: Ginyas Browser Companion = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\ CHR - Extension: Google-Suche = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\ CHR - Extension: Web Assistant = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\\ CHR - Extension: Logitech-Gerteerkennung = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\elncikmfipkphghakkmemnlnahadedno\\ CHR - Extension: Click to activate/deactivate ProxTube = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fclefogcenncfmmekelnpgpehiglcjln\1.2.1_0\ CHR - Extension: Stylish = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe\1.1_0\ CHR - Extension: AdBlock = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.63_0\ CHR - Extension: Gravity Duck = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\khpikpdaalmlcipfphefaajfiofglcma\1.3.0_0\ CHR - Extension: Vid-Saver = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgmfkblbflahhponhjmkcnpjinenhlnc\1.23.102_0\crossrider CHR - Extension: Vid-Saver = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgmfkblbflahhponhjmkcnpjinenhlnc\1.23.102_0\ CHR - Extension: Google Mail = C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) O2:64bit: - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Programme\Web Assistant\Extension64.dll () O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) O2:64bit: - BHO: (Microsoft SPFS Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (no name) - {2EECD738-5844-4a99-B4B6-146BF802613B} - No CLSID value found. O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Programme\Web Assistant\Extension32.dll () O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office 15\root\office15\urlredir.dll (Microsoft Corporation) O2 - BHO: (Microsoft SPFS Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Programme\Microsoft Office 15\root\office15\grooveex.dll (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4:64bit: - HKLM..\Run: [BullGuardUpdate2] c:\Programme\BullGuard Ltd\BullGuard\BullGuardUpdate2.exe (BullGuard Ltd.) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [Nvtmru] C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [THXCfg64] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Arctosa] C:\Program Files (x86)\Razer\Arctosa\razerhid.exe (Razer USA Ltd.) O4 - HKLM..\Run: [Razer Synapse] C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.) O4 - HKLM..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe (Simply Super Software) O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.) O4 - HKCU..\Run: [32992msdcsc.exe] C:\Users\Fabian\AppData\Local\Temp\32992msdcsc.exe () O4 - HKCU..\Run: [82267msdcsc.exe] C:\Users\Fabian\AppData\Local\Temp\82267msdcsc.exe () O4 - HKCU..\Run: [AcroRd32] C:\Users\Fabian\AppData\Roaming\Acrobat\AcroRd32.exe (Adobe Systems Incorporated) O4 - HKCU..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe File not found O4 - HKCU..\Run: [OscarEditor] C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe () O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe () O4 - HKCU..\Run: [rundll32] C:\Users\Fabian\AppData\Local\Temp\MSDCSC\msdcsc.exe () O4 - HKCU..\Run: [Spotify Web Helper] "C:\Users\Fabian\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" File not found O4 - Startup: C:\Users\Fabian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk = File not found O4 - Startup: C:\Users\Fabian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tbhcn.lnk = C:\Users\Fabian\AppData\Roaming\BrowserCompanion\tbhcn.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation) O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation) O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation) O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation) O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation) O9:64bit: - Extra Button: Report to BullGuard - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - C:\Programme\BullGuard Ltd\BullGuard\Antiphishing\IE\BgAntiphishingIE.dll (BullGuard Ltd.) O9:64bit: - Extra Button: Microsoft Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) O9:64bit: - Extra 'Tools' menuitem : Microsoft Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation) O9 - Extra Button: Report to BullGuard - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - C:\Programme\BullGuard Ltd\BullGuard\Files32\Antiphishing\IE\BgAntiphishingIE.dll (BullGuard Ltd.) O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9B21C34B-3B2A-4FD8-BF09-539620025832}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AC905FBF-6003-4722-9B68-D197B46315A4}: DhcpNameServer = O18:64bit: - Protocol\Handler\osf - No CLSID value found O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Programme\Microsoft Office 15\root\office15\msosb.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O20:64bit: - AppInit_DLLs: (C:\PROGRA~1\LUCIDL~1\VIRTU\APPINI~1.DLL c:\PROGRA~1\BULLGU~1\BULLGU~1\BgAgent.dll BgGamingMonitor.dll) - C:\Programme\Lucidlogix Technologies\VIRTU\appinit_dll.dll (Lucidlogix Inc.) O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation) O20 - AppInit_DLLs: (c:\progra~1\bullgu~1\bullgu~1\files32\bgagent.dll) - c:\Programme\BullGuard Ltd\BullGuard\Files32\BgAgent.dll (BullGuard Ltd.) O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{0e11c6f2-6d3c-11e2-809e-bc5ff41a74a3}\Shell - "" = AutoRun O33 - MountPoints2\{0e11c6f2-6d3c-11e2-809e-bc5ff41a74a3}\Shell\AutoRun\command - "" = E:\pushinst.exe O33 - MountPoints2\{66af8288-db46-11e1-89e2-bc5ff41a74a3}\Shell - "" = AutoRun O33 - MountPoints2\{66af8288-db46-11e1-89e2-bc5ff41a74a3}\Shell\AutoRun\command - "" = E:\pushinst.exe O33 - MountPoints2\{975e702c-a59b-11e1-8394-bc5ff41a74a3}\Shell - "" = AutoRun O33 - MountPoints2\{975e702c-a59b-11e1-8394-bc5ff41a74a3}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.06.08 20:09:03 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Roaming\dclogs [2013.06.08 19:31:30 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Fabian\Desktop\OTL.exe [2013.06.08 19:11:05 | 000,000,000 | -HSD | C] -- C:\Users\Fabian\AppData\Roaming\msnmsg [2013.06.08 19:06:01 | 000,000,000 | ---D | C] -- C:\Users\Fabian\Documents\Simply Super Software [2013.06.08 19:06:01 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Roaming\Simply Super Software [2013.06.08 19:05:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover [2013.06.08 19:05:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover [2013.06.08 19:05:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software [2013.06.08 19:05:18 | 001,169,224 | -HS- | C] (Microsoft Corporation) -- C:\Users\Fabian\AppData\Roaming\M5Q9IL20WA.exe [2013.06.08 19:03:39 | 012,311,184 | ---- | C] (Simply Super Software ) -- C:\Users\Fabian\Desktop\trjsetup685.exe [2013.06.08 18:50:38 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Roaming\Malwarebytes [2013.06.08 18:50:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.06.08 18:50:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013.06.08 18:50:32 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2013.06.08 18:50:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013.06.08 18:50:08 | 000,000,000 | -HSD | C] -- C:\Users\Fabian\AppData\Roaming\Acrobat [2013.06.08 18:47:56 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Fabian\Desktop\mbam-setup- [2013.06.08 18:19:00 | 002,776,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll [2013.06.08 18:18:58 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll [2013.06.08 18:18:58 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll [2013.06.08 18:18:58 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll [2013.06.08 18:18:58 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll [2013.06.08 18:18:56 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll [2013.06.08 18:18:56 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll [2013.06.08 18:18:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll [2013.06.08 18:18:55 | 001,643,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll [2013.06.08 18:18:55 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10core.dll [2013.06.08 18:18:54 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll [2013.06.08 18:02:39 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Local\DriverTuner [2013.06.08 14:09:06 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Roaming\GetRightToGo [2013.06.08 13:30:03 | 000,031,232 | ---- | C] (The OpenVPN Project) -- C:\Windows\SysNative\drivers\tap0901.sys [2013.06.08 11:58:26 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2013.06.08 11:58:26 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2013.06.08 11:58:25 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2013.06.08 11:58:25 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2013.06.08 11:58:25 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2013.06.08 11:58:25 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2013.06.08 11:58:25 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2013.06.08 11:58:25 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2013.06.08 11:58:24 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2013.06.08 11:58:24 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2013.06.08 11:58:24 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2013.06.08 11:58:24 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2013.06.08 11:58:24 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2013.06.08 11:58:24 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2013.06.08 11:58:24 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2013.06.08 11:50:36 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll [2013.06.08 11:50:36 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll [2013.06.08 11:50:36 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll [2013.06.08 11:50:36 | 000,111,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe [2013.06.08 11:49:55 | 003,717,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll [2013.06.08 11:49:55 | 003,217,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll [2013.06.08 11:49:54 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aaclient.dll [2013.06.08 11:49:54 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aaclient.dll [2013.06.08 11:49:54 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll [2013.06.08 11:49:54 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll [2013.06.08 11:49:47 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023.sys [2013.06.08 11:48:35 | 000,265,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys [2013.06.08 11:48:35 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll [2013.06.08 11:48:33 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanprotdim.dll [2013.06.08 11:46:30 | 005,550,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2013.06.08 11:46:29 | 003,968,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2013.06.08 11:46:29 | 003,913,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2013.06.08 11:46:29 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe [2013.06.08 11:46:29 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll [2013.06.08 11:46:29 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll [2013.06.08 10:42:53 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Roaming\WindowsLogon [2013.06.07 23:09:59 | 000,000,000 | -HSD | C] -- C:\ProgramData\Realtek0 [2013.06.05 15:59:19 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Roaming\Awesomium [2013.06.05 15:58:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios [2013.06.05 15:58:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Hi-Rez Studios [2013.06.05 15:58:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hi-Rez Studios [2013.06.03 15:04:12 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Local\NVIDIA [2013.06.03 15:01:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [2013.06.03 15:01:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies [2013.06.03 15:00:39 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\NV [2013.06.03 15:00:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\NV [2013.06.03 14:59:21 | 025,256,224 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll [2013.06.03 14:59:21 | 021,096,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll [2013.06.03 14:59:21 | 017,560,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll [2013.06.03 14:59:21 | 015,143,904 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll [2013.06.03 14:59:21 | 013,403,168 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll [2013.06.03 14:59:21 | 009,233,688 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll [2013.06.03 14:59:21 | 007,682,960 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll [2013.06.03 14:59:21 | 007,641,832 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll [2013.06.03 14:59:21 | 006,324,360 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll [2013.06.03 14:59:21 | 002,942,240 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll [2013.06.03 14:59:21 | 002,754,336 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll [2013.06.03 14:59:21 | 002,363,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll [2013.06.03 14:59:21 | 002,002,720 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll [2013.06.03 14:59:21 | 001,832,224 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6432018.dll [2013.06.03 14:59:21 | 001,511,712 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6432018.dll [2013.06.03 14:59:21 | 000,925,648 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll [2013.06.03 14:59:21 | 000,550,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvFBC64.dll [2013.06.03 14:59:21 | 000,518,944 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFR64.dll [2013.06.03 14:59:21 | 000,443,168 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvFBC.dll [2013.06.03 14:59:21 | 000,421,152 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFR.dll [2013.06.03 14:59:21 | 000,266,448 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll [2013.06.03 14:59:21 | 000,218,592 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglshim64.dll [2013.06.03 14:59:21 | 000,214,448 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll [2013.06.03 14:59:21 | 000,194,848 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvhda64v.sys [2013.06.03 14:59:21 | 000,181,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglshim32.dll [2013.06.03 14:59:21 | 000,031,520 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdap64.dll [2013.06.03 14:01:30 | 000,000,000 | ---D | C] -- C:\Users\Fabian\Documents\Remedy [2013.05.31 11:47:12 | 000,000,000 | ---D | C] -- C:\Users\Fabian\Documents\Telltale Games [2013.05.30 01:22:33 | 000,000,000 | ---D | C] -- C:\ProgramData\BrowserProtect [2013.05.30 01:21:31 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Roaming\ExpressFiles [2013.05.30 01:19:15 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Local\iLivid [2013.05.17 05:17:30 | 000,126,464 | ---- | C] (Razer Inc) -- C:\Windows\SysNative\drivers\rzudd.sys [2013.05.17 05:17:28 | 000,031,232 | ---- | C] (Razer Inc) -- C:\Windows\SysNative\drivers\rzendpt.sys [2013.05.17 05:14:34 | 000,154,112 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rztouchdll.dll [2013.05.17 05:14:34 | 000,056,832 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzdevinfo.dll [2013.05.17 05:14:30 | 000,766,976 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzdevicedll.dll [2013.05.17 05:14:30 | 000,117,248 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzdisplaydll.dll [2013.05.17 05:14:28 | 000,296,448 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzaudiodll.dll [2013.05.14 21:43:25 | 009,195,912 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe [2013.05.12 15:43:36 | 000,566,048 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe [2013.05.11 14:01:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2013.05.11 14:01:35 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe [2013.05.11 14:01:31 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe [2013.05.11 14:01:31 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe [2013.05.11 14:01:31 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll [2013.05.10 20:04:50 | 000,000,000 | ---D | C] -- C:\tmp [2013.05.10 19:42:16 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Roaming\Blender Foundation [2013.05.09 21:53:47 | 000,000,000 | ---D | C] -- C:\Users\Fabian\.thumbnails [2013.05.09 21:53:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blender Foundation [2013.05.09 21:53:27 | 000,000,000 | ---D | C] -- C:\Program Files\Blender Foundation [2013.05.09 21:06:09 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Roaming\Google [2013.05.09 21:06:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Google [2013.05.09 21:05:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp 8 [2013.05.09 21:04:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.06.08 20:15:38 | 000,021,856 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.06.08 20:15:38 | 000,021,856 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.06.08 20:15:05 | 000,001,040 | ---- | M] () -- C:\Windows\tasks\GinyasBrowserCompanion Stats Report.job [2013.06.08 20:09:23 | 000,000,032 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\Local [2013.06.08 20:08:28 | 000,000,992 | ---- | M] () -- C:\Windows\tasks\GinyasBrowserCompanion Chrome Watcher.job [2013.06.08 20:08:25 | 000,000,992 | ---- | M] () -- C:\Windows\tasks\GinyasBrowserCompanion FireFox Watcher.job [2013.06.08 20:08:08 | 000,000,992 | ---- | M] () -- C:\Windows\tasks\GinyasBrowserCompanion Runner.job [2013.06.08 20:08:08 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\GinyasBrowserCompanion Update Checker.job [2013.06.08 20:07:52 | 000,000,480 | ---- | M] () -- C:\Windows\SysNative\F39D4DE6-98B8-4E05-91BD-549E8A8248BD [2013.06.08 20:07:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.06.08 20:07:35 | 2078,801,919 | -HS- | M] () -- C:\hiberfil.sys [2013.06.08 19:55:03 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3485898032-1890299033-1484769855-1000UA.job [2013.06.08 19:42:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.06.08 19:31:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Fabian\Desktop\OTL.exe [2013.06.08 19:11:27 | 000,000,056 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\mbam.context.scan [2013.06.08 19:05:55 | 000,001,143 | ---- | M] () -- C:\Users\Public\Desktop\Trojan Remover.lnk [2013.06.08 19:05:38 | 012,311,184 | ---- | M] (Simply Super Software ) -- C:\Users\Fabian\Desktop\trjsetup685.exe [2013.06.08 18:50:33 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.06.08 18:49:25 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Fabian\Desktop\mbam-setup- [2013.06.08 18:25:49 | 000,001,086 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk [2013.06.08 18:15:09 | 000,000,916 | ---- | M] () -- C:\Users\Fabian\AppData\Roaming\EasyToolz.ini [2013.06.08 13:00:18 | 000,487,256 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013.06.08 12:55:45 | 000,001,072 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3485898032-1890299033-1484769855-1000Core.job [2013.06.08 12:12:16 | 001,633,540 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.06.08 12:12:16 | 000,696,620 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.06.08 12:12:16 | 000,651,938 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.06.08 12:12:16 | 000,147,916 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.06.08 12:12:16 | 000,120,870 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.06.06 13:19:49 | 000,282,512 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe [2013.06.06 13:19:47 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe [2013.06.04 13:25:26 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_rzendpt_01009.Wdf [2013.06.04 13:25:08 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_rzudd_01009.Wdf [2013.05.17 05:17:30 | 000,126,464 | ---- | M] (Razer Inc) -- C:\Windows\SysNative\drivers\rzudd.sys [2013.05.17 05:17:28 | 000,031,232 | ---- | M] (Razer Inc) -- C:\Windows\SysNative\drivers\rzendpt.sys [2013.05.17 05:14:34 | 000,154,112 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rztouchdll.dll [2013.05.17 05:14:34 | 000,056,832 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzdevinfo.dll [2013.05.17 05:14:30 | 000,766,976 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzdevicedll.dll [2013.05.17 05:14:30 | 000,117,248 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzdisplaydll.dll [2013.05.17 05:14:28 | 000,296,448 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzaudiodll.dll [2013.05.14 21:43:28 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2013.05.14 21:43:28 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2013.05.14 21:43:25 | 009,195,912 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe [2013.05.12 23:42:27 | 027,775,776 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll [2013.05.12 23:42:27 | 025,256,224 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll [2013.05.12 23:42:27 | 021,096,736 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll [2013.05.12 23:42:27 | 017,560,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll [2013.05.12 23:42:27 | 015,910,736 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll [2013.05.12 23:42:27 | 015,143,904 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll [2013.05.12 23:42:27 | 013,403,168 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll [2013.05.12 23:42:27 | 012,426,216 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll [2013.05.12 23:42:27 | 009,233,688 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll [2013.05.12 23:42:27 | 007,682,960 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll [2013.05.12 23:42:27 | 007,641,832 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll [2013.05.12 23:42:27 | 006,324,360 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll [2013.05.12 23:42:27 | 002,942,240 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll [2013.05.12 23:42:27 | 002,935,696 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll [2013.05.12 23:42:27 | 002,754,336 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll [2013.05.12 23:42:27 | 002,597,344 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll [2013.05.12 23:42:27 | 002,363,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll [2013.05.12 23:42:27 | 002,002,720 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll [2013.05.12 23:42:27 | 001,832,224 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6432018.dll [2013.05.12 23:42:27 | 001,511,712 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6432018.dll [2013.05.12 23:42:27 | 001,059,560 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvumdshimx.dll [2013.05.12 23:42:27 | 000,925,648 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll [2013.05.12 23:42:27 | 000,550,176 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\NvFBC64.dll [2013.05.12 23:42:27 | 000,518,944 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFR64.dll [2013.05.12 23:42:27 | 000,443,168 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvFBC.dll [2013.05.12 23:42:27 | 000,421,152 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFR.dll [2013.05.12 23:42:27 | 000,266,448 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll [2013.05.12 23:42:27 | 000,218,592 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglshim64.dll [2013.05.12 23:42:27 | 000,214,448 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll [2013.05.12 23:42:27 | 000,181,488 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglshim32.dll [2013.05.12 23:42:27 | 000,020,536 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb [2013.05.12 22:34:14 | 006,491,936 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll [2013.05.12 22:34:14 | 003,514,656 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll [2013.05.12 22:34:12 | 002,555,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll [2013.05.12 22:34:12 | 000,063,776 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll [2013.05.12 22:34:11 | 000,237,856 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll [2013.05.12 15:43:36 | 000,566,048 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe [2013.05.11 14:01:24 | 000,095,648 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll [2013.05.11 14:01:23 | 000,866,720 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll [2013.05.11 14:01:23 | 000,788,896 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll [2013.05.11 14:01:23 | 000,263,584 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe [2013.05.11 14:01:23 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe [2013.05.11 14:01:23 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.06.08 20:09:23 | 000,000,032 | ---- | C] () -- C:\Users\Fabian\AppData\Roaming\Local [2013.06.08 20:07:52 | 000,000,480 | ---- | C] () -- C:\Windows\SysNative\F39D4DE6-98B8-4E05-91BD-549E8A8248BD [2013.06.08 19:11:27 | 000,000,056 | ---- | C] () -- C:\Users\Fabian\AppData\Roaming\mbam.context.scan [2013.06.08 19:05:55 | 000,001,143 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Remover.lnk [2013.06.08 18:50:33 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.06.08 18:12:46 | 000,000,916 | ---- | C] () -- C:\Users\Fabian\AppData\Roaming\EasyToolz.ini [2013.06.08 10:43:01 | 000,001,086 | ---- | C] () -- C:\Users\Fabian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.lnk [2013.06.04 13:25:26 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_rzendpt_01009.Wdf [2013.06.04 13:25:08 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_rzudd_01009.Wdf [2013.05.01 11:19:22 | 000,034,816 | ---- | C] () -- C:\Users\Fabian\AppData\Roaming\RZR_00208e6943aabcb45c048e5a9758.db [2013.04.07 20:39:04 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2013.03.15 15:30:46 | 000,000,288 | ---- | C] () -- C:\Users\Fabian\AppData\Roaming\.backup.dm [2013.03.14 20:36:53 | 000,000,600 | ---- | C] () -- C:\Users\Fabian\PUTTY.RND [2012.12.14 02:42:30 | 000,963,452 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng600.bin [2012.12.14 02:42:30 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll [2012.12.14 02:42:28 | 000,272,928 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng600.bin [2012.11.21 21:27:55 | 000,007,597 | ---- | C] () -- C:\Users\Fabian\AppData\Local\Resmon.ResmonCfg [2012.11.13 14:53:41 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini [2012.11.08 20:16:32 | 000,583,306 | ---- | C] () -- C:\Users\Fabian\AppData\Roaming\technic-launcher.jar.bak [2012.11.08 20:16:32 | 000,581,168 | ---- | C] () -- C:\Users\Fabian\AppData\Roaming\technic-launcher.jar [2012.10.25 13:40:44 | 000,282,512 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2012.10.25 13:40:42 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2012.09.25 15:34:00 | 001,145,382 | ---- | C] () -- C:\Users\Fabian\AppData\Local\Tempmusic.ogg [2012.08.13 16:32:24 | 000,001,441 | ---- | C] () -- C:\Windows\chhm-pdd48.ini [2012.08.13 16:26:51 | 000,000,856 | ---- | C] () -- C:\Users\Fabian\AppData\Local\recently-used.xbel [2012.08.05 22:21:53 | 000,007,552 | ---- | C] () -- C:\Windows\SysWow64\drivers\enodpl.sys [2012.08.05 22:21:52 | 000,004,736 | ---- | C] () -- C:\Windows\SysWow64\drivers\tandpl.sys [2012.07.01 19:19:01 | 001,589,442 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2012.06.19 14:02:17 | 003,123,272 | R--- | C] () -- C:\Windows\SysWow64\pbsvc.exe [2012.05.30 18:43:47 | 000,017,408 | ---- | C] () -- C:\Users\Fabian\AppData\Local\WebpageIcons.db [2012.05.24 19:41:55 | 000,000,412 | ---- | C] () -- C:\Users\Fabian\AppData\Roaming\All CPU Meter_Settings.ini [2012.05.24 14:21:14 | 000,001,424 | ---- | C] () -- C:\Windows\THXCfg_SP_APOIM.ini [2012.05.24 14:21:14 | 000,001,323 | ---- | C] () -- C:\Windows\THXCfg_HP_APOIM.ini [2012.05.24 14:21:14 | 000,001,323 | ---- | C] () -- C:\Windows\THXCfg_APOIM.ini [2012.05.24 14:21:12 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL [2012.05.24 14:21:12 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL [2012.05.24 14:18:38 | 000,000,003 | ---- | C] () -- C:\Users\Fabian\AppData\Local\user_data.ini [2012.05.24 14:12:02 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin [2012.05.24 14:12:01 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin [2012.05.24 14:12:01 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin [2011.11.08 12:39:38 | 000,311,296 | ---- | C] () -- C:\Windows\SysWow64\EMRegSys.dll [2011.08.11 04:06:32 | 000,007,764 | ---- | C] () -- C:\Windows\cadx2.ini ========== ZeroAccess Check ========== [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013.05.29 15:59:12 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\.minecraft [2012.10.01 13:18:36 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\.Nitrous [2012.12.05 21:54:28 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\.techniclauncher [2012.07.26 00:35:00 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\.terasology [2013.06.08 18:50:08 | 000,000,000 | -HSD | M] -- C:\Users\Fabian\AppData\Roaming\Acrobat [2012.05.28 16:58:28 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Alle meine Passworte [2013.04.17 19:01:35 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\AtomZombieData [2013.06.05 15:59:19 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Awesomium [2013.02.01 01:26:30 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Babylon [2013.05.10 19:42:16 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Blender Foundation [2013.06.08 20:18:53 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\BrowserCompanion [2012.12.13 21:08:50 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\BullGuard [2012.12.09 15:13:30 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Carbon [2013.06.08 20:09:03 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\dclogs [2013.02.26 22:10:08 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\de.3m5.wendel.flcd.FLCDB.FC622282278C06838B5CD08883589F2C8AB9EEDC.1 [2012.05.31 19:25:08 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\DeviceVm [2013.02.11 02:29:18 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Downloaded Installations [2013.06.08 18:30:51 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\DVDVideoSoft [2012.11.22 19:26:25 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Easy Thumbnails [2013.03.15 15:30:31 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\eBayDesktopShortcut [2013.01.12 20:22:50 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Engelmann Media [2013.05.30 01:21:40 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\ExpressFiles [2013.06.07 23:10:03 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\FileZilla [2013.06.08 14:09:19 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\GetRightToGo [2012.11.22 19:55:52 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Hobbyist Software [2013.02.22 19:41:26 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\iFunbox_UserCache [2012.09.19 16:48:33 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\IrfanView [2012.05.24 12:43:05 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Leadertech [2012.12.05 21:54:22 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\logs [2012.07.03 16:47:34 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\LolClient [2012.06.02 18:17:54 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\LolClient2 [2013.06.08 19:11:05 | 000,000,000 | -HSD | M] -- C:\Users\Fabian\AppData\Roaming\msnmsg [2012.10.06 00:15:13 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Nokia [2012.11.22 20:10:39 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\OpenCandy [2013.03.14 20:41:21 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\OpenOffice.org [2012.12.08 21:21:12 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Origin [2012.06.23 10:49:18 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\PC Suite [2013.02.01 01:41:51 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\PerformerSoft [2013.03.06 15:18:52 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\raidcall [2013.02.10 12:49:13 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Razer [2013.04.08 17:07:01 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\SanDisk [2013.03.16 19:55:52 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\SanDisk SecureAccess [2012.12.15 14:19:30 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Screaming Bee [2012.10.28 00:04:50 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\SecondLife [2013.06.08 19:06:01 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Simply Super Software [2012.06.24 13:36:40 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\six-zsync [2013.05.09 11:58:02 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Sony Online Entertainment [2012.08.13 17:25:49 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Spirited Machine [2012.06.07 20:09:07 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\SPORE [2013.06.08 16:38:36 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Spotify [2012.07.01 20:08:09 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Stardock [2012.06.20 17:19:01 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\Teeworlds [2012.10.03 17:07:48 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\thriXXX [2012.07.03 16:29:04 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\TrueCrypt [2012.11.05 16:29:46 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\TS3Client [2012.11.22 20:15:19 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\TuneUp Software [2013.06.08 19:21:18 | 000,000,000 | ---D | M] -- C:\Users\Fabian\AppData\Roaming\WindowsLogon ========== Purity Check ========== ========== Files - Unicode (All) ========== [2013.01.19 16:44:38 | 000,001,024 | ---- | M] ()(C:\Users\Fabian\AppData\Local\PMB Fik?s) -- C:\Users\Fabian\AppData\Local\PMB Fik聥s [2013.01.19 16:44:38 | 000,001,024 | ---- | C] ()(C:\Users\Fabian\AppData\Local\PMB Fik?s) -- C:\Users\Fabian\AppData\Local\PMB Fik聥s ========== Alternate Data Streams ========== @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:CB0AACC9 < End of report > |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Coin Miner,msdcsc entfernen Hi,
__________________otl fix Fixen mit OTL
ATTFilter :OTL O4 - HKCU..\Run: [rundll32] C:\Users\Fabian\AppData\Local\Temp\MSDCSC\msdcsc.exe () O4 - HKCU..\Run: [AcroRd32] C:\Users\Fabian\AppData\Roaming\Acrobat\AcroRd32.exe (Adobe Systems Incorporated) O4 - HKCU..\Run: [AcroRd32] C:\Users\Fabian\AppData\Roaming\Acrobat\AcroRd32.exe (Adobe Systems Incorporated) O4 - HKCU..\Run: [AcroRd32] C:\Users\Fabian\AppData\Roaming\Acrobat\AcroRd32.exe (Adobe Systems Incorporated) O4 - HKCU..\Run: [82267msdcsc.exe] C:\Users\Fabian\AppData\Local\Temp\82267msdcsc.exe () O4 - HKCU..\Run: [32992msdcsc.exe] C:\Users\Fabian\AppData\Local\Temp\32992msdcsc.exe () [2013.06.08 20:09:03 | 000,000,000 | ---D | C] -- C:\Users\Fabian\AppData\Roaming\dclogs [2013.06.08 19:05:18 | 001,169,224 | -HS- | C] (Microsoft Corporation) -- C:\Users\Fabian\AppData\Roaming\M5Q9IL20WA.exe :files C:\Users\Fabian\AppData\Local\Temp\MSDCSC C:\Users\Fabian\AppData\Roaming\Acrobat C:\Users\Fabian\AppData\Roaming\Acrobat :Commands [emptytemp]
Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang in den Thread posten! Drücke bitte die ![]()
__________________ |
![]() ![]() | ![]() Coin Miner,msdcsc entfernen Extras.txt:
ATTFilter OTL Extras logfile created on: 08.06.2013 20:18:27 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Fabian\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,91 Gb Total Physical Memory | 5,21 Gb Available Physical Memory | 65,78% Memory free 15,83 Gb Paging File | 12,99 Gb Available in Paging File | 82,09% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,66 Gb Total Space | 108,95 Gb Free Space | 23,40% Space Free | Partition Type: NTFS Computer Name: FABIAN-PC | User Name: Fabian | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Scan with Trojan Remover] -- C:\Program Files (x86)\Trojan Remover\rmvtrjan.exe /d "%1" (Simply Super Software) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Scan with Trojan Remover] -- C:\Program Files (x86)\Trojan Remover\rmvtrjan.exe /d "%1" (Simply Super Software) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00C0475E-7B72-46E1-A586-E9B6E39E3A6E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{0FF4C4DF-D55A-40D5-8699-708EB3DBA8F1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{0FF6A0B9-07B2-46D3-91B3-5A7A8E8D565D}" = rport=10243 | protocol=6 | dir=out | app=system | "{43E29356-22F0-47AD-A491-2E8414F1BFAB}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5A0EF280-F752-410B-8762-ACD3123B98FE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{63A7DC8B-F722-4D07-96B9-24F55F0ED05B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6566CC95-643D-456E-8CE5-9FF155E53A0E}" = lport=138 | protocol=17 | dir=in | app=system | "{688E1440-4E1D-40F9-A6AA-4ED61F9BE9D5}" = rport=139 | protocol=6 | dir=out | app=system | "{74A4D958-350E-48DA-AE61-DE41DDBBB31A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{78460461-0F97-4C13-8EC6-07175ADFFCF9}" = lport=139 | protocol=6 | dir=in | app=system | "{7EEA1AC2-B620-4748-964A-F24834AC83EE}" = lport=445 | protocol=6 | dir=in | app=system | "{8C81D55C-283C-4FA8-9CBA-D959A5487B36}" = lport=10243 | protocol=6 | dir=in | app=system | "{98FEC081-7B3F-4047-A795-3FAF0A5E42CD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{A34259D4-1C13-40D0-9162-62EE88CB9D4C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{ABEBF008-AE30-4000-A085-7F2FC0B82973}" = rport=137 | protocol=17 | dir=out | app=system | "{B22C4422-F339-4DD7-BEAD-85F9A0FF7882}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{B525976E-E44C-457D-9024-B50B1D3BBA8B}" = lport=137 | protocol=17 | dir=in | app=system | "{BC8BA62A-823A-48C4-9E2E-2C8F5443D266}" = lport=2869 | protocol=6 | dir=in | app=system | "{C09AB0F4-74F6-4FA6-95CB-CFFD7D607D9A}" = rport=138 | protocol=17 | dir=out | app=system | "{DDA8F6F9-B0E1-478C-B5F2-38AD99ABC64A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E32F35A0-BC7B-4BA7-B229-B6FCE839BC88}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{E43C00BE-D819-40A1-9258-7F65F75F1D5E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\outlook.exe | "{E58AA575-8AA4-44E9-81BD-36F59AFB33A1}" = rport=445 | protocol=6 | dir=out | app=system | "{F0BD6E67-FB76-4DED-A87B-FE6D86B70EE9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00C7A906-5DEA-46C5-B8CC-A5478C9FFD25}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wallace and gromit ep1\wallacegromit101.exe | "{04FEF248-A67A-40CA-8CCF-892D4A71BE83}" = protocol=6 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe | "{059CAC44-0D4E-438E-8296-AC2A277CA1F4}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\farcry 3\bin\fc3updater.exe | "{0D9D2A1C-426D-4185-91C5-EC466B27AA4E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | "{0DC1C999-E0F4-41C8-A1B7-E29CAFBAEBB9}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\assassinscreed3.exe | "{0E2E214B-0718-4076-9F6E-7681BF5B6B75}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{0E720C65-B6F8-4311-AF43-178923C9E42F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the binding of isaac\isaac.exe | "{12D79C5D-8351-43D9-9E56-6BFFC1666B0D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe | "{1318D643-6F20-4498-9469-83D8EE36858B}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{13842B8E-E457-4B28-BFD3-E459E0BD8EF9}" = dir=in | app=c:\program files (x86)\hobbyist software\vlc streamer\mdnsresponder.exe | "{16F8A8B5-CD6E-48C4-8A3F-F89EA7A7C105}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wallace and gromit ep4\wallacegromit104.exe | "{17F1B815-2EFB-4142-9469-35FD5454CCB3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe | "{191468C4-15D1-4F33-A833-A5F8F9B3B8C9}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{197E7431-AE17-40D0-8E0F-76B1F59B9EFB}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{1A91988E-77F5-4B52-A8A7-990C4DA72909}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\simcity\simcity\simcity.exe | "{1E56F566-D28A-4B00-A2C7-1641DC660D57}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\airforte\data\airforte.exe | "{1E837585-652F-42ED-B663-F45FD5F2CC67}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wallace and gromit ep3\wallacegromit103.exe | "{1F632E48-1399-47BC-99AF-9EC9F83F34AA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{1F8E9433-03A6-4DD1-A83C-C1BEB2FD7577}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{266855C2-81D6-418D-987B-1618A80DAF58}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alan wake\alanwake.exe | "{2A161A71-C6CF-4B6F-832A-EC2C26175F3C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war gold\w40k.exe | "{2A183B9B-4DD6-4999-A861-C8FBFA0C18F7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\airmech\airmech.exe | "{2A4CA343-E987-41C4-9432-0D85E77B4666}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alan wake\alanwake.exe | "{2A7BFC67-C1EA-41FC-A399-A64A5914A724}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\assassinscreed3.exe | "{2C0C2835-3D6F-4D08-B73A-F8D12559675D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{2F4DD163-A1F0-4173-9F5F-FA8A10553583}" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe | "{31A722C5-3EE5-4846-B19D-54B9B27F7CB7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\airforte\data\airforte.exe | "{334DBB40-3726-4FB2-B7BB-7E4AF2D1B560}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the binding of isaac\isaac.exe | "{342B08BC-A7E5-4A8C-921B-956B9A163B78}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{34F45429-DE7B-4DB1-8C95-C7DC02157165}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | "{380B3662-469A-40B3-8176-912F38C925E3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "{39473C15-BB15-4F24-BBFA-F5C0A5DE1CBB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the walking dead\walkingdead101.exe | "{3AEDE667-AF92-4612-95FC-7134F11D542C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{3E669EBB-EAF3-4F8E-9077-9A6EA694C163}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | "{3F3B53DC-64AC-49E9-8C08-7FF299B9901E}" = protocol=17 | dir=in | app=c:\program files (x86)\expressfiles\expressfiles.exe | "{3F7432B1-C752-49EC-AA40-F0E8AAC04164}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{3F7D76BB-4782-4D85-B62A-0C08E8AFDA5E}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\medal of honor warfighter\mohw.exe | "{444D55CA-717B-4ED4-8712-324E27577E92}" = protocol=6 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred 2 - fallen angel\system\s2gs.exe | "{45B7FBB7-D359-433A-81F7-EC0D9471821B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | "{48AF3327-832D-42B3-ABD2-04FF05529419}" = protocol=17 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred 2 - fallen angel\system\sacred2.exe | "{4A8D5575-28ED-4BC1-AA5C-571A03700B39}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wallace and gromit ep1\wallacegromit101.exe | "{4B1B028E-3C68-4C75-A1D1-C09A9A93F9E7}" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher1.exe | "{4B9241C0-5F4D-4273-BAC1-420F6B11F9C9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wallace and gromit ep2\wallacegromit102.exe | "{4CBB2B00-6425-4674-A7E8-FAA908C3C4E5}" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher1.exe | "{4D419B23-FD40-4397-8E90-4D191D8746CD}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{4D4F65E6-7499-419D-8826-D17CE8918597}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{4D76262C-274A-4C99-A85B-FCECC77FBB2A}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{55D36B7C-3386-463B-95D5-7F31628D51F1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{5972CF0D-CDC4-4B29-A1AE-D5FE14CD5DD1}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{5AA567B4-12CF-4FB5-9C1B-F93B6FE216E9}" = protocol=6 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe | "{5B0C844D-A709-41E0-9AAD-5CDBBFD2F22F}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | "{5C2296BE-0AAA-4F87-B168-2182537930ED}" = protocol=17 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe | "{5E9846D7-6F17-4FB5-9C4D-23A4CAC11D30}" = protocol=6 | dir=in | app=c:\users\fabian\appdata\local\akamai\netsession_win.exe | "{5E9BB59B-5616-413B-973F-FC255A4053B8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\airmech\airmech.exe | "{61C7BDCD-71A2-4DAF-BA64-D0980C512561}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{6226E14A-F1C8-4E93-9EA0-9985E83C3D82}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe | "{623190EE-2DF2-4BDC-AC05-8B604E2AE3FF}" = protocol=17 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe | "{6481526C-E24E-4E2A-A562-8E84EF969DB5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe | "{6A76578F-F31C-4A3A-9240-9C8AAB069629}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\farcry 3\bin\farcry3_d3d11.exe | "{70B045DC-5F70-475F-84C8-73753620C031}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{71CB00D2-DF1B-48F8-8FE7-606A45C82136}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | "{749EE999-FB3A-40DD-9A2C-43B0D74D0795}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\closure\closure.exe | "{752A4FB0-1F43-4F7D-A884-5A64CA323BE5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd | "{78F69B4B-CE06-49D0-BCF6-48B80999C42C}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{79FB0048-FD4B-489E-8D95-FAFDE7801169}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{7B79A55E-7515-48F5-8052-5178C2455B8A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\metro 2033\metro2033.exe | "{7CCC1726-9CFA-41AF-BFF7-70AFDC41EE49}" = protocol=6 | dir=in | app=c:\program files (x86)\expressfiles\expressfiles.exe | "{804257B4-F946-4CCD-ADB1-AB4698DF4F69}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{8145BB86-5DD9-4305-97DD-BF17679F0F6E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | "{821E8E77-35E5-4384-9DE1-3336F4194EE2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe | "{857ABEFB-634B-4160-B9DB-43F1707550C9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{85B6F6E8-A090-4E80-BE76-36E87E0E8C9E}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{8945C972-931C-48EE-AB09-E2AD8D745E8A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{8A3A25A8-01D9-47C5-84BB-C216AE34895C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{8AC2F353-41A8-403E-ACF0-83CB68983143}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{8CD01BDF-6A52-4766-9776-9E841E7608A0}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | "{8D3EF20A-1E7C-44BD-8828-7A5CB9B0E91B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\metro 2033\metro2033.exe | "{8E1C8DED-7D93-423F-AD04-2E488B089516}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hector episode 1\hector101.exe | "{8EBA13AE-49B4-4529-BDE8-725E3AE37267}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{8F493007-59F8-4CB8-AA35-196E8FC60B58}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wallace and gromit ep3\wallacegromit103.exe | "{9137EFF0-BD81-4B70-B713-2BDEA989F65E}" = protocol=6 | dir=in | name=mc tdp | "{914A4A5A-467C-479F-BC61-A6BD57451A2D}" = protocol=17 | dir=in | name=mc udp | "{91B4A46D-6D96-4DC3-AF56-C744AB24B07B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\atomzombiesmasher\data\atomzombiesmasher.exe | "{9558687C-D557-48B4-A81B-DE7CA83955D6}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\farcry 3\bin\farcry3.exe | "{9748E8B0-46D9-4580-984C-A94C735730AA}" = protocol=17 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred 2 - fallen angel\system\s2gs.exe | "{99C02B56-FFCB-469E-94C1-1A149A84BF34}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{9B2DEA81-A08A-4FF0-8B84-015132368EB4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "{9B533948-9651-4839-A23A-4D565250A817}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{9CEFBB2C-2267-4A25-8D32-31E07B48B60C}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{9D0F81EE-BA97-43A7-AB49-A8F109F91C5F}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{9D82BC2E-FF58-4BD0-84DE-9BEA56A4256B}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3mp.exe | "{A3F07ADD-B6B6-47ED-B147-0229A33A1110}" = dir=in | app=c:\program files (x86)\hobbyist software\vlc streamer\vlc streamer configuration.exe | "{A852E488-445A-4985-AD29-04EB1AF8AE4E}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{A88B51C9-4605-4E18-B24E-09DD22D04501}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\closure\closure.exe | "{AA85C98F-4D56-42C7-A4D0-818CB698395D}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\farcry 3\bin\farcry3_d3d11.exe | "{AAD901E8-9CFE-4035-B0A5-45210181264C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\atomzombiesmasher\data\atomzombiesmasher.exe | "{AE449C63-5478-41D0-9D63-B865C216BDE5}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{AFA64A5C-B12A-4856-84C5-B18E1DDEE084}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\medal of honor warfighter\mohw.exe | "{B4E3AC02-C625-4ADC-96FE-C804D30B1624}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3mp.exe | "{B887A15C-D822-40D6-A318-50A0E0CBCAC2}" = protocol=6 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred 2 - fallen angel\system\sacred2.exe | "{BB939239-55C8-4898-B7A2-C6FC3F0488AD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{C1C45D48-C72D-465F-9ABB-F6FF83E8E8E4}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{C642549D-C181-428E-9265-63A838AE901A}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{C7F96920-243A-416C-92E2-390284ADE3F8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | "{CD5AE668-C43A-4F83-9B88-1BB8F6D65EF8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hector episode 1\hector101.exe | "{CD95B12F-41D4-4C65-AE0D-279C21846063}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war gold\w40k.exe | "{D02F437D-4A17-42F0-9A22-20D94A62D1C9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D1B66B5E-CE2E-4C18-AB95-6D8BE4047EE0}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{D3C1330D-7DD2-4FAC-8C39-C428B46E175A}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\farcry 3\bin\farcry3.exe | "{D52519AB-D77A-4970-91C9-ABB93C06333F}" = protocol=17 | dir=in | app=c:\users\fabian\appdata\local\akamai\netsession_win.exe | "{D6961109-95A8-4BB3-BB39-CB2AADC6C0C5}" = protocol=17 | dir=in | app=c:\program files (x86)\expressfiles\expressdl.exe | "{D874E4E0-B2F2-4359-9A3A-1CF19446D22E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wallace and gromit ep4\wallacegromit104.exe | "{D91147B2-4F61-4321-BFF4-9AB594B74668}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\farcry 3\bin\fc3editor.exe | "{DE255ABA-2A9E-4473-9488-AC59F59BEF75}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wallace and gromit ep2\wallacegromit102.exe | "{E19EE700-6BD8-41CE-A5B5-A59D960E6E8F}" = protocol=6 | dir=in | app=c:\program files (x86)\expressfiles\expressdl.exe | "{E2FBF41B-127F-4418-BA09-95457A8B5CC4}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe | "{E6378F91-0C7E-4AD8-830F-EF66538A3401}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd | "{E9476A17-336D-4A40-BDC4-0D84F3AED99E}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | "{E984455C-31C7-42D9-9178-1CC9C57DC148}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\farcry 3\bin\fc3editor.exe | "{E9CADF4E-FDBC-4E49-A6DE-88F6B631648F}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\devicesetup.exe | "{E9F4F016-1FDE-48A6-8753-D744C1198C55}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{EA43A660-DECF-425F-89B6-49C0AF89E7B8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe | "{EBDB6826-DEF2-4E6C-8630-D3B4E89CFC63}" = protocol=6 | dir=out | app=system | "{EC53F5A0-9EE8-47BC-906C-E44DC4DBA8B7}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\farcry 3\bin\fc3updater.exe | "{ED23419A-EB4D-4739-B2CB-A28211A6A587}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{EFE16EDF-B789-434A-8CE9-550F3F6460DA}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\hpnetworkcommunicator.exe | "{F16AC757-5516-4EE0-A430-50C634AB0D1E}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\simcity\simcity\simcity.exe | "{F4CE2DB0-F99E-407F-B475-4B7A11E4FC6D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{FDAD265F-3C95-4449-8C2D-4A03E46A34C5}" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe | "{FDF23DF5-5546-49C6-91DC-D195F61710E1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe | "{FEA2EAD0-2CD7-41D3-94AC-CC7A4F711D70}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the walking dead\walkingdead101.exe | "TCP Query User{0136348C-BF9B-4A32-BF5F-30609B6D8121}C:\users\fabian\desktop\*\spiele\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\users\fabian\desktop\*\spiele\guild wars 2\gw2.exe | "TCP Query User{083FBD11-C329-42FE-9388-36ACA6D62B6A}C:\users\fabian\desktop\*\spiele\sonstige\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\users\fabian\desktop\*\spiele\sonstige\guild wars 2\gw2.exe | "TCP Query User{097A1033-2CC6-4F7B-9523-2859F9A3C9B9}C:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | "TCP Query User{0A819CD6-6F70-4EDA-94D5-7F65B26B82BD}C:\program files (x86)\maniaplanet\maniaplanet.exe" = protocol=6 | dir=in | app=c:\program files (x86)\maniaplanet\maniaplanet.exe | "TCP Query User{1D2E8A30-6F60-4758-94E6-10FCBEBBC244}C:\users\fabian\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\fabian\appdata\local\akamai\netsession_win.exe | "TCP Query User{2A42BF2F-D85D-4311-B431-8A64A18A50B7}C:\users\fabian\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\fabian\appdata\roaming\spotify\spotify.exe | "TCP Query User{2F275784-B2A3-4C04-91A9-0A8A1CCEAEA3}C:\program files\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\java.exe | "TCP Query User{2FA25496-A70F-4C0D-BCF1-BD8C9595C7EE}C:\program files (x86)\ubisoft\xiii\system\xiii.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\xiii\system\xiii.exe | "TCP Query User{3B4F8B9F-8C97-4529-AB3E-D56CC8BEF0DC}C:\users\fabian\desktop\*\spiele\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\users\fabian\desktop\*\spiele\guild wars 2\gw2.exe | "TCP Query User{3C1C3D80-C17F-4597-8107-0F5A7AB98684}C:\program files (x86)\tmunitedforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tmunitedforever\tmforever.exe | "TCP Query User{3DAEEF68-A04C-4C1C-B386-1A8953D7A970}C:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe | "TCP Query User{45E0DC29-F7DC-47E8-AC12-737947A9CFB6}C:\program files (x86)\team17\worms 2\frontend.exe" = protocol=6 | dir=in | app=c:\program files (x86)\team17\worms 2\frontend.exe | "TCP Query User{4C1B3D2B-8C20-4C57-A46E-25D1D4D78F77}C:\users\fabian\desktop\*\spiele\sonstige\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\users\fabian\desktop\*\spiele\sonstige\guild wars 2\gw2.exe | "TCP Query User{53702275-C954-449D-8D23-D01EFAA0DC29}C:\users\fabian\desktop\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\users\fabian\desktop\guild wars 2\gw2.exe | "TCP Query User{54363B56-3D1B-4470-9A3A-295BAEBFE264}C:\users\fabian\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\fabian\appdata\roaming\spotify\spotify.exe | "TCP Query User{66CBB960-DA6B-49AA-BCDE-88F4C57F8111}C:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "TCP Query User{6C4775B1-9B18-49D9-90FE-BBE1E506208F}C:\windows\system32\java.exe" = protocol=6 | dir=in | app=c:\windows\system32\java.exe | "TCP Query User{71394FF0-85AA-47F3-9EAC-69B10ABE38DC}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe | "TCP Query User{99D1B461-EE0B-4C34-BE36-BA43730FC2D8}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | "TCP Query User{A4065F8B-B496-4B91-AE4D-75FB6AF8AD50}C:\users\fabian\desktop\spiele\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\users\fabian\desktop\spiele\guild wars 2\gw2.exe | "TCP Query User{AEECB13C-FC77-402D-851D-58741CA4C6BE}C:\program files (x86)\tmunitedforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tmunitedforever\tmforever.exe | "TCP Query User{BD2FDC44-8E32-4250-AA23-B9629FECE508}C:\users\public\sony online entertainment\installed games\planetside 2\planetside2.exe" = protocol=6 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2\planetside2.exe | "TCP Query User{BFB83684-7F3C-4E1F-8650-5A95501E4727}C:\program files (x86)\six projects\six updater\tools\bin\rsync.exe" = protocol=6 | dir=in | app=c:\program files (x86)\six projects\six updater\tools\bin\rsync.exe | "TCP Query User{DC472359-E342-4787-B26E-2BB20D15D8C4}C:\users\fabian\appdata\local\temp\rar$exa0.170\teeworlds-b122-r50edfd37-win32\teeworlds_srv.exe" = protocol=6 | dir=in | app=c:\users\fabian\appdata\local\temp\rar$exa0.170\teeworlds-b122-r50edfd37-win32\teeworlds_srv.exe | "TCP Query User{DCC9958F-05A1-4DDB-92AE-B9193A64E35D}C:\program files (x86)\lolreplay\lolreplay.exe" = protocol=6 | dir=in | app=c:\program files (x86)\lolreplay\lolreplay.exe | "TCP Query User{E4657D13-07EE-4819-A85A-F8F00D7DC3FC}C:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tmnationsforever\tmforever.exe | "TCP Query User{F9852E57-4454-4314-A1A2-E1F992CED39A}C:\users\fabian\appdata\local\temp\rar$exa0.027\survivers_beta_3.exe" = protocol=6 | dir=in | app=c:\users\fabian\appdata\local\temp\rar$exa0.027\survivers_beta_3.exe | "UDP Query User{16B8B3D8-FD5D-49D2-9DBE-2605D9CC7DD1}C:\windows\system32\java.exe" = protocol=17 | dir=in | app=c:\windows\system32\java.exe | "UDP Query User{18190CA8-01C6-4358-BEB0-7332F9AC9473}C:\users\fabian\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\fabian\appdata\local\akamai\netsession_win.exe | "UDP Query User{1C3CBF17-FEF4-4D39-ACCF-BC3F5B7BC449}C:\program files (x86)\tmunitedforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tmunitedforever\tmforever.exe | "UDP Query User{1F706D98-3D04-4FAA-80D5-FF981028DEF1}C:\program files (x86)\lolreplay\lolreplay.exe" = protocol=17 | dir=in | app=c:\program files (x86)\lolreplay\lolreplay.exe | "UDP Query User{2820604F-E23D-4FEB-AA11-A67B4B1E9BCF}C:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe | "UDP Query User{3FDE79BF-F3B1-4F60-B0A4-1BD9717FA6B8}C:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | "UDP Query User{48D13E88-3674-4A97-9205-5C3A0A1EA0F7}C:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "UDP Query User{4A0666B2-5077-4C7A-99E5-E8F52EE28298}C:\program files (x86)\maniaplanet\maniaplanet.exe" = protocol=17 | dir=in | app=c:\program files (x86)\maniaplanet\maniaplanet.exe | "UDP Query User{621E30B8-DEAD-4449-BDF3-0EFA5FB2FAA6}C:\users\fabian\desktop\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\users\fabian\desktop\guild wars 2\gw2.exe | "UDP Query User{6309E64D-471B-41B6-BF75-52E57F85F4AB}C:\users\fabian\appdata\local\temp\rar$exa0.170\teeworlds-b122-r50edfd37-win32\teeworlds_srv.exe" = protocol=17 | dir=in | app=c:\users\fabian\appdata\local\temp\rar$exa0.170\teeworlds-b122-r50edfd37-win32\teeworlds_srv.exe | "UDP Query User{672D3A9F-F456-4D18-A68D-AE8F5EE5DB6C}C:\users\fabian\desktop\spiele\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\users\fabian\desktop\spiele\guild wars 2\gw2.exe | "UDP Query User{73E13BFE-A6B7-4FD4-A0DA-F50AB9E28480}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe | "UDP Query User{7BA1E02B-7E71-4169-A361-78B68119EE6C}C:\users\fabian\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\fabian\appdata\roaming\spotify\spotify.exe | "UDP Query User{7BD0B291-E974-4666-91AC-5782CCB70C96}C:\program files (x86)\team17\worms 2\frontend.exe" = protocol=17 | dir=in | app=c:\program files (x86)\team17\worms 2\frontend.exe | "UDP Query User{8C0231FE-C5FC-4D77-9041-6B7A53B35E66}C:\users\fabian\appdata\local\temp\rar$exa0.027\survivers_beta_3.exe" = protocol=17 | dir=in | app=c:\users\fabian\appdata\local\temp\rar$exa0.027\survivers_beta_3.exe | "UDP Query User{9E82D9AF-29C2-48F8-B597-CD5684236B0D}C:\users\fabian\desktop\*\spiele\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\users\fabian\desktop\*\spiele\guild wars 2\gw2.exe | "UDP Query User{AC0E9B34-232F-4F18-82C0-BB066C2ACF36}C:\users\public\sony online entertainment\installed games\planetside 2\planetside2.exe" = protocol=17 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2\planetside2.exe | "UDP Query User{B458A061-24A1-4BF4-B693-47EB73FED130}C:\users\fabian\desktop\*\spiele\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\users\fabian\desktop\*\spiele\guild wars 2\gw2.exe | "UDP Query User{BF20FDED-86ED-4D49-B42B-D198418174BA}C:\users\fabian\desktop\*\spiele\sonstige\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\users\fabian\desktop\*\spiele\sonstige\guild wars 2\gw2.exe | "UDP Query User{C152BE24-41C9-45DF-8D9F-7DC5E87FF24F}C:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tmnationsforever\tmforever.exe | "UDP Query User{D4AC6DB3-14D8-4D78-9246-C978E346D5C7}C:\program files\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\java.exe | "UDP Query User{D8C47059-6AD9-4F0A-A849-B143F334DEA2}C:\program files (x86)\ubisoft\xiii\system\xiii.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\xiii\system\xiii.exe | "UDP Query User{E5F6991C-AFC5-4D87-9EB1-6AA08659DBA0}C:\users\fabian\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\fabian\appdata\roaming\spotify\spotify.exe | "UDP Query User{F2342B56-FBFB-41EF-9EF0-2B096A9443D3}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | "UDP Query User{F6D3DF2E-D0B8-4CAA-891D-0A64F9D3C17D}C:\users\fabian\desktop\*\spiele\sonstige\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\users\fabian\desktop\*\spiele\sonstige\guild wars 2\gw2.exe | "UDP Query User{FA61BDBE-BB3A-43C6-B378-6BFDECF2CB59}C:\program files (x86)\six projects\six updater\tools\bin\rsync.exe" = protocol=17 | dir=in | app=c:\program files (x86)\six projects\six updater\tools\bin\rsync.exe | "UDP Query User{FD6F3950-A90C-492B-A9FE-C829CE2163E6}C:\program files (x86)\tmunitedforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tmunitedforever\tmforever.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp version 0.99.7 "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{26A24AE4-039D-4CA4-87B4-2F86417004FF}" = Java(TM) 7 Update 4 (64-bit) "{336D0C35-8A85-403a-B9D2-65C292C39087}_is1" = Web Assistant "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{4BC310C4-B898-46E2-B5FB-B85A30AA7142}" = iCloud "{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2 "{50150000-008F-0000-1000-0000000FF1CE}" = Office 15 Click-to-Run Licensing Component "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{680EDA59-9266-44B4-949E-0C24F65DFF82}" = Microsoft_VC100_CRT_SP1_x64 "{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{913923AB-3AAB-4870-8910-627C4CD82789}" = NetLimiter 3 "{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 320.18 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 320.18 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 320.18 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.5 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 320.18 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.1031 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 4.11.9 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{B6B44AEB-3F57-45D7-9A89-5020135CBF90}" = Studie zur Verbesserung von HP Officejet 6600 Produkten "{C768E610-4DFB-4A60-A59B-71549EB7BF75}" = HP Officejet 6600 - Grundlegende Software für das Gerät "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F" = Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 "Blender" = Blender "BullGuard" = BullGuard "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft Office Professional 15 (Technical Preview) - en-us" = Microsoft Office 365 Home Premium Preview - en-us "TeamSpeak 3 Client" = TeamSpeak 3 Client "VIRTU_is1" = VIRTU 1.2.106 "WinRAR archiver" = WinRAR 4.11 (64-Bit) "XFast LAN" = XFast LAN v6.61 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{0906982B-A432-4C06-8F01-C01BE1143779}" = Nokia Connectivity Cable Driver "{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}" = Razer Synapse 2.0 "{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0 "{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20150000-008C-0000-0000-0000000FF1CE}" = Office 15 Click-to-Run Extensibility Component "{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1 "{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 21 "{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0 "{2D9C81F2-CF30-47F9-860E-58DACF92ABC9}" = Razer Arctosa "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update "{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}" = Smite "{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service "{3F0D0ABE-CDAF-431A-00BC-CBBE018EA74E}" = SimCity 4 Deluxe "{415FA9AD-DA10-4ABE-97B6-5051D4795C90}" = HP FWUpdateEDO2 "{42BC0474-6E50-464A-8183-5E3D32E41B1B}" = XIII "{48379835-BF2E-4487-9CB1-D5E654502B53}" = Medal of Honor™ Warfighter "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3 "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{63B7AC7E-0178-4F4F-A79B-08D97ADD02D7}" = System Requirements Lab for Intel "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2 "{72376EB6-0189-45B3-A4F6-823F549697C3}" = MOUSE Editor "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™ "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX "{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends "{929CE49F-1CA7-4CF3-A9A1-6D757443C63F}" = Microsoft Games for Windows - LIVE Redistributable "{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3 "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9CC4840D-EF1C-406F-AF08-3C19EB1335B9}" = Zoo Tycoon 2 - Ultimate Collection "{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}" = Assassin's Creed III 1.01 "{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™ "{A0087DDE-69D0-11E2-AD57-43CA6188709B}" = Adobe AIR "{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9 "{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime "{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86 "{AFB907F5-C0E6-4753-8284-DE955EF86AC2}" = THX TruStudio "{B8F4A45C-581C-4707-8EF2-2B9E6722270C}" = SketchUp 8 "{BA77F9D2-CD35-41EB-9BC9-769879DFF8A6}" = PC Connectivity Solution "{C3592426-531E-4110-911D-BFECE2CE284C}" = osu! "{C818BA3A-226F-4ED0-9CEF-96A0DF300211}" = HP Officejet 6600 Hilfe "{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR "{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86 "{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}" = Far Cry 3 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F30787F6-EA4F-4BC8-0001-398BDCC33E1E}" = MovieSaver*3.0 "{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support "{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}" = SimCity™ "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "{FCD3BA7F-0DFA-2679-44D2-0EC11238AF9D}" = Fragen-Lern-CD 4.3 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 12.0 "AJCompressCopy" = AJScreensaver "Akamai" = Akamai NetSession Interface "AllemeinePassworte" = Alle meine Passworte 3.20 "aTube Catcher" = aTube Catcher "AVMWLANCLI" = AVM FRITZ!WLAN "Battlelog Web Plugins" = Battlelog Web Plugins "BattlEye A2 Free" = BattlEye (A2Free) Uninstall "BattlEye for OA" = BattlEye for OA Uninstall "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "Cossacks : The Art Of War" = Cossacks - The Art Of War "de.3m5.wendel.flcd.FLCDB.FC622282278C06838B5CD08883589F2C8AB9EEDC.1" = Fragen-Lern-CD 4.3 "Downloader" = Downloader "ESN Sonar-0.70.4" = ESN Sonar "EVEREST Home Edition_is1" = EVEREST Home Edition v2.20 "FileZilla Client" = FileZilla Client 3.6.0 "GinyasBrowserCompanion" = GinyasBrowserCompanion "Guild Wars" = GUILD WARS "HP Photo Creations" = HP Photo Creations "iFunbox_is1" = iFunbox (v2.1.2228.731), iFunbox DevTeam "InstallShield_{72376EB6-0189-45B3-A4F6-823F549697C3}" = Mouse Editor "LOLReplay" = LOLReplay "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version "Mozilla Firefox 14.0.1 (x86 de)" = Mozilla Firefox 14.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "MySSID_is1" = EXPERTool 7.21 "nfsDigitalPaintClockWhite New Free Screensaver_is1" = NewFreeScreensaver nfsDigitalPaintClockWhite "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "Origin" = Origin "PunkBusterSvc" = PunkBuster Services "RaidCall" = RaidCall "Razer Core" = Razer Core "Steam App 107100" = Bastion "Steam App 108710" = Alan Wake "Steam App 113200" = The Binding of Isaac "Steam App 205790" = Dota 2 Test "Steam App 206500" = AirMech "Steam App 207610" = The Walking Dead "Steam App 31100" = Wallace & Gromit Ep 1: Fright of the Bumblebees "Steam App 31110" = Wallace & Gromit Ep 2: The Last Resort "Steam App 31120" = Wallace & Gromit Ep 3: Muzzled! "Steam App 31130" = Wallace & Gromit Ep 4: The Bogey Man "Steam App 43110" = Metro 2033 "Steam App 4570" = Warhammer 40,000: Dawn of War - Game of the Year Edition "Steam App 49520" = Borderlands 2 "Steam App 55000" = Flotilla "Steam App 55020" = Air Forte "Steam App 55040" = Atom Zombie Smasher "Steam App 55230" = Saints Row: The Third "Steam App 570" = Dota 2 "Steam App 65800" = Dungeon Defenders "Steam App 72000" = Closure "Steam App 94600" = Hector: Ep 1 "Steam App 94610" = Hector: Ep 2 "Steam App 94620" = Hector: Ep 3 "TmNationsForever_is1" = TmNationsForever "TmUnitedForever_is1" = TmUnitedForever "Trojan Remover_is1" = Trojan Remover 6.8.6 "TrueCrypt" = TrueCrypt "Uplay" = Uplay "WNLT" = IB Updater Service "XFastUsb" = XFastUsb ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe" = SanDiskSecureAccess_Manager.exe "Akamai" = Akamai NetSession Interface "Google Chrome" = Google Chrome "SOE-C:/Users/Fabian/AppData/Local/Sony Online Entertainment/ApplicationUpdater" = applicationupdater "SOE-C:/Users/Public/Sony Online Entertainment/Installed Games/PlanetSide 2" = gamelauncher-ps2-live "Spotify" = Spotify ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 08.06.2013 07:01:36 | Computer Name = Fabian-PC | Source = WinMgmt | ID = 10 Description = Error - 08.06.2013 08:49:30 | Computer Name = Fabian-PC | Source = SideBySide | ID = 16842832 Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Fabian\Desktop\*\SoftonicDownloader_fuer_winds-pro.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error - 08.06.2013 08:50:56 | Computer Name = Fabian-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version:, Zeitstempel: 0x4e65c1ac Name des fehlerhaften Moduls: rads_user_kernel.exe, Version:, Zeitstempel: 0x4e65c1ac Ausnahmecode: 0xc0000005 Fehleroffset: 0x000b8554 ID des fehlerhaften Prozesses: 0x15f0 Startzeit der fehlerhaften Anwendung: 0x01ce6446d136036e Pfad der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Pfad des fehlerhaften Moduls: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Berichtskennung: 0f627e36-d03a-11e2-9ce7-bc5ff41a74a3 Error - 08.06.2013 09:28:38 | Computer Name = Fabian-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: tbhcn.exe, Version:, Zeitstempel: 0x5121f458 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002e41b ID des fehlerhaften Prozesses: 0x13d8 Startzeit der fehlerhaften Anwendung: 0x01ce644bdb886771 Pfad der fehlerhaften Anwendung: C:\ProgramData\GinyasBrowserCompanion\tbhcn.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 539603ef-d03f-11e2-9ce7-bc5ff41a74a3 Error - 08.06.2013 10:40:21 | Computer Name = Fabian-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: PinkVisual-141.002.exe, Version:, Zeitstempel: 0x5166aec4 Name des fehlerhaften Moduls: ThriXXX-010278-SYS.dll, Version:, Zeitstempel: 0x5166ae4c Ausnahmecode: 0xc0000005 Fehleroffset: 0x000aa3e4 ID des fehlerhaften Prozesses: 0x950c Startzeit der fehlerhaften Anwendung: 0x01ce6455a6a3cc62 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\thriXXX\PinkVisual\Binaries\PinkVisual-141.002.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\thriXXX\PinkVisual\Binaries\ThriXXX-010278-SYS.dll Berichtskennung: 581ac0c4-d049-11e2-9ce7-bc5ff41a74a3 Error - 08.06.2013 12:25:30 | Computer Name = Fabian-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: tbhcn.exe, Version:, Zeitstempel: 0x5121f458 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002e3be ID des fehlerhaften Prozesses: 0x96c Startzeit der fehlerhaften Anwendung: 0x01ce6464be7fe46b Pfad der fehlerhaften Anwendung: C:\ProgramData\GinyasBrowserCompanion\tbhcn.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 088f1838-d058-11e2-8b42-bc5ff41a74a3 Error - 08.06.2013 12:26:21 | Computer Name = Fabian-PC | Source = WinMgmt | ID = 10 Description = Error - 08.06.2013 12:28:50 | Computer Name = Fabian-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: shell.exe, Version: 7.0.13060.0, Zeitstempel: 0x51ae3b03 Name des fehlerhaften Moduls: MSVCRT.dll, Version: 7.0.7601.17744, Zeitstempel: 0x4eeaf722 Ausnahmecode: 0x40000015 Fehleroffset: 0x0005620a ID des fehlerhaften Prozesses: 0x14a0 Startzeit der fehlerhaften Anwendung: 0x01ce6464d6aaabb2 Pfad der fehlerhaften Anwendung: C:\Users\Fabian\AppData\Roaming\WindowsLogon\shell.exe Pfad des fehlerhaften Moduls: C:\Windows\syswow64\MSVCRT.dll Berichtskennung: 7fe2dfbe-d058-11e2-8b42-bc5ff41a74a3 Error - 08.06.2013 12:31:12 | Computer Name = Fabian-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: shell.exe, Version: 7.0.13060.0, Zeitstempel: 0x51ae3b03 Name des fehlerhaften Moduls: MSVCRT.dll, Version: 7.0.7601.17744, Zeitstempel: 0x4eeaf722 Ausnahmecode: 0x40000015 Fehleroffset: 0x0005620a ID des fehlerhaften Prozesses: 0x11e0 Startzeit der fehlerhaften Anwendung: 0x01ce64654daa6a14 Pfad der fehlerhaften Anwendung: C:\Users\Fabian\AppData\Roaming\WindowsLogon\shell.exe Pfad des fehlerhaften Moduls: C:\Windows\syswow64\MSVCRT.dll Berichtskennung: d451ba2c-d058-11e2-8b42-bc5ff41a74a3 Error - 08.06.2013 14:08:26 | Computer Name = Fabian-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: tbhcn.exe, Version:, Zeitstempel: 0x5121f458 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002e3be ID des fehlerhaften Prozesses: 0x970 Startzeit der fehlerhaften Anwendung: 0x01ce64732197af9c Pfad der fehlerhaften Anwendung: C:\ProgramData\GinyasBrowserCompanion\tbhcn.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 69d1f453-d066-11e2-895e-bc5ff41a74a3 Error - 08.06.2013 14:09:25 | Computer Name = Fabian-PC | Source = WinMgmt | ID = 10 Description = [ NetLimiter 3 Events ] Error - 24.04.2013 15:12:26 | Computer Name = Fabian-PC | Source = NetLimiter 3 Service | ID = 1000 Description = Registration or trial period expired Error - 25.04.2013 08:55:36 | Computer Name = Fabian-PC | Source = NetLimiter 3 Service | ID = 1000 Description = Registration or trial period expired Error - 26.04.2013 08:52:42 | Computer Name = Fabian-PC | Source = NetLimiter 3 Service | ID = 1000 Description = Registration or trial period expired Error - 27.04.2013 05:25:36 | Computer Name = Fabian-PC | Source = NetLimiter 3 Service | ID = 1000 Description = Registration or trial period expired Error - 28.04.2013 09:41:28 | Computer Name = Fabian-PC | Source = NetLimiter 3 Service | ID = 1000 Description = Registration or trial period expired Error - 29.04.2013 12:39:12 | Computer Name = Fabian-PC | Source = NetLimiter 3 Service | ID = 1000 Description = Registration or trial period expired Error - 30.04.2013 10:58:01 | Computer Name = Fabian-PC | Source = NetLimiter 3 Service | ID = 1000 Description = Registration or trial period expired Error - 30.04.2013 15:49:56 | Computer Name = Fabian-PC | Source = NetLimiter 3 Service | ID = 1000 Description = Registration or trial period expired Error - 01.05.2013 05:10:05 | Computer Name = Fabian-PC | Source = NetLimiter 3 Service | ID = 1000 Description = Registration or trial period expired Error - 02.05.2013 09:32:53 | Computer Name = Fabian-PC | Source = NetLimiter 3 Service | ID = 1000 Description = Registration or trial period expired [ System Events ] Error - 05.12.2012 10:26:20 | Computer Name = Fabian-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error - 06.12.2012 10:45:53 | Computer Name = Fabian-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Browser Manager" wurde aufgrund folgenden Fehlers nicht gestartet: %%3 Error - 06.12.2012 10:45:55 | Computer Name = Fabian-PC | Source = Application Popup | ID = 1060 Description = Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\tandpl.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error - 06.12.2012 10:47:27 | Computer Name = Fabian-PC | Source = Service Control Manager | ID = 7034 Description = Dienst "BullGuard e-mail monitoring service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error - 06.12.2012 10:48:49 | Computer Name = Fabian-PC | Source = Service Control Manager | ID = 7038 Description = Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error - 06.12.2012 10:48:49 | Computer Name = Fabian-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error - 06.12.2012 15:22:22 | Computer Name = Fabian-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Browser Manager" wurde aufgrund folgenden Fehlers nicht gestartet: %%3 Error - 06.12.2012 15:22:23 | Computer Name = Fabian-PC | Source = Application Popup | ID = 1060 Description = Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\tandpl.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error - 06.12.2012 15:24:33 | Computer Name = Fabian-PC | Source = Service Control Manager | ID = 7038 Description = Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error - 06.12.2012 15:24:33 | Computer Name = Fabian-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 < End of report > MFG Fabian Neises |
Coin Miner,msdcsc entfernen siehe post2b
Coin Miner,msdcsc entfernen Habe Zip Datei erfolgreich hochgeladen Hier die .txt Datei:
ATTFilter All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\rundll32 not found. C:\Users\Fabian\AppData\Local\Temp\MSDCSC\msdcsc.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AcroRd32 not found. C:\Users\Fabian\AppData\Roaming\Acrobat\AcroRd32.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AcroRd32 not found. File C:\Users\Fabian\AppData\Roaming\Acrobat\AcroRd32.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AcroRd32 not found. File C:\Users\Fabian\AppData\Roaming\Acrobat\AcroRd32.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\82267msdcsc.exe not found. C:\Users\Fabian\AppData\Local\Temp\82267msdcsc.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\32992msdcsc.exe not found. C:\Users\Fabian\AppData\Local\Temp\32992msdcsc.exe moved successfully. C:\Users\Fabian\AppData\Roaming\dclogs folder moved successfully. C:\Users\Fabian\AppData\Roaming\M5Q9IL20WA.exe moved successfully. ========== FILES ========== C:\Users\Fabian\AppData\Local\Temp\MSDCSC\Uhv1HAwUyC9F\Uhv1HAwUyC9F folder moved successfully. C:\Users\Fabian\AppData\Local\Temp\MSDCSC\Uhv1HAwUyC9F folder moved successfully. C:\Users\Fabian\AppData\Local\Temp\MSDCSC folder moved successfully. C:\Users\Fabian\AppData\Roaming\Acrobat folder moved successfully. File\Folder C:\Users\Fabian\AppData\Roaming\Acrobat not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 57472 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Fabian ->Temp folder emptied: 1809006455 bytes ->Temporary Internet Files folder emptied: 691987468 bytes ->Java cache emptied: 1327619 bytes ->FireFox cache emptied: 21118946 bytes ->Google Chrome cache emptied: 359719187 bytes ->Flash cache emptied: 97157 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 155648 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 542121148 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 51845885 bytes RecycleBin emptied: 1563672 bytes Total Files Cleaned = 3.318,00 mb OTL by OldTimer - Version log created on 06082013_210319 Files\Folders moved on Reboot... C:\Users\Fabian\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Windows\temp\_avast_\unp4319538.tmp not found! File\Folder C:\Windows\temp\_avast_\unp75567540.tmp not found! File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. File\Folder C:\Windows\temp\_asw_aisI.tm~a06012\setup.lok not found! File move failed. C:\Windows\temp\avast_ash\iTunes (64 Bit)\BIT53BD.tmp scheduled to be moved on reboot. C:\Windows\temp\FireFly(20130608203252BC4).log moved successfully. C:\Windows\temp\integratedoffice.exe_c2rdll(20130608203252BC4).log moved successfully. C:\Windows\temp\integratedoffice.exe_c2ruidll(20130608203252BC4).log moved successfully. C:\Windows\temp\integratedoffice.exe_streamserver(20130608203252BC4).log moved successfully. File move failed. C:\Windows\temp\ood_stream.x86.en-us.dat scheduled to be moved on reboot. File move failed. C:\Windows\temp\ood_stream.x86.x-none.dat scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
Coin Miner,msdcsc entfernen Danke fürs hochladen Downloade dir bitte
__________________ --> Coin Miner,msdcsc entfernen |
Coin Miner,msdcsc entfernen .txt aus TDSSKiller:
ATTFilter 21:24:32.0511 4640 TDSS rootkit removing tool Feb 11 2013 18:50:42 21:24:33.0411 4640 ============================================================ 21:24:33.0411 4640 Current date / time: 2013/06/08 21:24:33.0411 21:24:33.0411 4640 SystemInfo: 21:24:33.0411 4640 21:24:33.0411 4640 OS Version: 6.1.7601 ServicePack: 1.0 21:24:33.0411 4640 Product type: Workstation 21:24:33.0411 4640 ComputerName: FABIAN-PC 21:24:33.0411 4640 UserName: Fabian 21:24:33.0411 4640 Windows directory: C:\Windows 21:24:33.0411 4640 System windows directory: C:\Windows 21:24:33.0411 4640 Running under WOW64 21:24:33.0411 4640 Processor architecture: Intel x64 21:24:33.0411 4640 Number of processors: 4 21:24:33.0411 4640 Page size: 0x1000 21:24:33.0411 4640 Boot type: Normal boot 21:24:33.0411 4640 ============================================================ 21:24:34.0246 4640 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 21:24:34.0251 4640 ============================================================ 21:24:34.0251 4640 \Device\Harddisk0\DR0: 21:24:34.0252 4640 MBR partitions: 21:24:34.0252 4640 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 21:24:34.0252 4640 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x3A353000 21:24:34.0252 4640 ============================================================ 21:24:34.0269 4640 C: <-> \Device\Harddisk0\DR0\Partition2 21:24:34.0269 4640 ============================================================ 21:24:34.0269 4640 Initialize success 21:24:34.0269 4640 ============================================================ 21:25:11.0173 0188 ============================================================ 21:25:11.0174 0188 Scan started 21:25:11.0174 0188 Mode: Manual; SigCheck; TDLFS; 21:25:11.0174 0188 ============================================================ 21:25:11.0645 0188 ================ Scan system memory ======================== 21:25:11.0645 0188 System memory - ok 21:25:11.0646 0188 ================ Scan services ============================= 21:25:11.0760 0188 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 21:25:11.0852 0188 1394ohci - ok 21:25:11.0875 0188 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 21:25:11.0887 0188 ACPI - ok 21:25:11.0898 0188 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 21:25:11.0927 0188 AcpiPmi - ok 21:25:12.0114 0188 [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 21:25:12.0124 0188 AdobeFlashPlayerUpdateSvc - ok 21:25:12.0154 0188 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 21:25:12.0169 0188 adp94xx - ok 21:25:12.0186 0188 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys 21:25:12.0199 0188 adpahci - ok 21:25:12.0211 0188 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 21:25:12.0222 0188 adpu320 - Coin Miner,msdcsc entfernen Hi, Scan mit Combofix
Coin Miner,msdcsc entfernen Combofix.txt
ATTFilter ComboFix 13-06-08.01 - Fabian 08.06.2013 21:36:20.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8105.5861 [GMT 2:00] ausgeführt von:: c:\users\Fabian\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: BullGuard Antivirus *Disabled/Updated* {C3CCAC61-52F7-A056-1860-6406566E2578} FW: BullGuard Firewall *Disabled* {FBF72D44-1898-A10E-333F-CD33A8BD6203} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: BullGuard Antispyware *Disabled/Outdated* {78AD4D85-74CD-AFD8-22D0-5F742DE96FC5} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . Coin Miner,msdcsc entfernen hi öffnest du mal bitte Computer, c: qoobox rechtsklick quarantain, packen und im Uploadchannel hochladen, melden bitte, wenn fertig.
Coin Miner,msdcsc entfernen Fertig hochgeladen.
Coin Miner,msdcsc entfernen danke dir. malwarebytes: Downloade Dir bitte Malwarebytes
Coin Miner,msdcsc entfernen Sooo ich melde mich Zurück Wurden keine Infizierten Dateien gefunden
ATTFilter Malwarebytes Anti-Malware (Test) www.malwarebytes.org Datenbank Version: v2013.06.08.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Fabian :: FABIAN-PC [Administrator] Schutz: Aktiviert 08.06.2013 22:14:25 mbam-log-2013-06-08 (22-14-25).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 488587 Laufzeit: 1 Stunde(n), 18 Minute(n), 8 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
Coin Miner,msdcsc entfernen Hi, lade den CCleaner standard: CCleaner - Download - Filepony falls der CCleaner bereits instaliert, überspringen. öffnen, Tools (extras),uninstall Llist, als txt speichern. öffnen. hinter, jedes von dir benötigte programm, schreibe notwendig. hinter, jedes, von dir nicht benötigte, unnötig. hinter, dir unbekannte, unbekannt. liste posten.
Coin Miner,msdcsc entfernen Auftrag erledigt.
