Log-Analyse und Auswertung: wssetup.exe von Perion Network Ltd.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.
| ![]() wssetup.exe von Perion Network Ltd. Guten Abend ![]() Zu erst einmal bitte ich um Verständnis , dass ich sehr wenig Ahnung von Computern und was dazu gehört habe bzw. ich kenne mich max. durchschnittlich damit aus ![]() So, & mit der "wssetup.exe" kommt meine PC-Kompetenz an ihre Grenzen.. Seit Tagen fragt mich mein PC ob ich die wssetup.exe von Perion Network Ltd. installieren möchte .. mir kam das etwas komisch vor und so hab ich dies immer mit Nein beantwortet. Allerdings hab ich mich jetzt mal 'schlau' gemacht und erfahren , dass es sich um wirklich nichts Gutes handelt. --> Wie werde ich es am schnellsten los? --> Welchen Schaden verursacht dieser Virus? bzw. kann es sein das der Virus schon Unheil angerichtet hat obwohl ich es immer verneint hab zu installieren? Ich bitte nur um eine Erklärung die ich nachvollziehen kann ![]() Ich bin dankbar für jede Hilfe!! ( & Sorry für eventuelle Rechtschreibfehler ) |
/// the machine /// TB-Ausbilder

wssetup.exe von Perion Network Ltd. Hi,
__________________Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden ).
| ![]() wssetup.exe von Perion Network Ltd. Danke für schnelle Antwort
__________________Nr 1: "OTL.txt" OTL Logfile: Code:
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{03C16B95-E008-438A-92D0-7D8383988C3A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{06368AFB-1E69-41AE-84A0-E07C87AADB14}" = rport=137 | protocol=17 | dir=out | app=system | "{07A2688E-376E-4398-AAB4-45E4E655D8F2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{0C81D4A7-20EB-47C5-A50D-944E9F8850F2}" = rport=445 | protocol=6 | dir=out | app=system | "{18CD2DFC-F469-4155-82DB-32386F6419DA}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{2165FDFD-2AC0-4332-B2D5-F1DF3BC96D8F}" = rport=10243 | protocol=6 | dir=out | app=system | "{27E7591B-3192-4F62-8FC7-505CE48501B1}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{2B1061B8-04F9-45A1-8363-8F0D9FFC72AB}" = rport=138 | protocol=17 | dir=out | app=system | "{2FFABCE8-FB12-47B6-BB50-3175FADEE4E3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{377F1443-1C66-45EA-A44F-3A5E5ED3CF8E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{3B934AD1-8E8F-4160-9115-CA985F7DC4C0}" = lport=139 | protocol=6 | dir=in | app=system | "{3CD7DE9D-DDB3-4280-AF0B-0B529850A5B7}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{4518CA1B-E48E-4E01-A29D-2F78E3B491C2}" = lport=445 | protocol=6 | dir=in | app=system | "{47582BE3-DB10-4DF7-BAB6-75C021596753}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{4FA7E3F6-3030-43F5-8519-562DF2C35AB4}" = lport=2869 | protocol=6 | dir=in | app=system | "{57D9ED55-4358-4D6F-A38A-32FF27F4CB95}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{7EA408C1-26F8-4737-8935-4A4CDBCAAF39}" = lport=2869 | protocol=6 | dir=in | app=system | "{85314452-4734-4AFA-91A6-10E440B56CC3}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{87EC79CF-16F4-4A47-8051-9078D27B94EE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{88297468-5B93-4D06-AB2D-50947C0AA616}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{8B009337-F046-4845-9580-34AA2F2E379F}" = lport=138 | protocol=17 | dir=in | app=system | "{9204005C-6F1C-448C-8838-CD92007EE22C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A9441CD2-5893-41DA-A0F5-6563BC309538}" = lport=137 | protocol=17 | dir=in | app=system | "{CBAB7FCB-9F6C-48FE-990F-4BA489F1128B}" = rport=139 | protocol=6 | dir=out | app=system | "{E605D973-B28B-4D8A-8A67-1ADFA6605FB5}" = lport=10243 | protocol=6 | dir=in | app=system | "{FA9D530C-6576-4E7D-B3C8-2E7AD6EFB55E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{FD060C93-AD1B-4ABC-BCF2-8C3592966434}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00D38F7D-D667-449A-A6A4-B017CB4751D8}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe | "{02DD24FB-0B8C-4CEA-A64A-89229C83B3B7}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{036797E3-8D74-434A-9F49-D552A3C57A2D}" = dir=in | app=c:\users\lukas\appdata\local\facebook\video\skype\facebookvideocalling.exe | "{10559EC6-6CC0-43CE-9E32-91022BBA6FCA}" = dir=in | app=c:\program files\cyberlink\powerdirector10\pdr10.exe | "{10942B10-71FD-4EB2-9186-D70D37438FCB}" = protocol=6 | dir=out | app=system | "{15BEB4BC-CD58-4DF7-AA22-9CFF935788E0}" = protocol=6 | dir=in | app=c:\users\lukas\downloads\sweetimsetup.exe | "{19351548-D50B-4BC6-855F-D1CAA17067A9}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{1A9B8524-1213-4535-93DB-AC3D29BCBD6B}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe | "{1D8852D6-D380-48DB-8A23-BA285D6B59DB}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 2050 j510 series\bin\usbsetup.exe | "{20B01D16-DEA1-4E19-AEA2-F58EB98FA2FA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{27EBB1A8-7BA2-44D5-B794-3E7F0C272DA4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | "{2AD08588-9CED-44E9-BB73-135D60FACB7A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "{2E603772-98E0-4825-9400-1DE25745A033}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe | "{3750444B-CDE0-4372-8E33-04A02CDB64DA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe | "{378FB83E-D2AF-49ED-A560-2CC7A75B02F2}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{39126F06-CD6B-41E0-A5BF-7622385C58B3}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd11\pdvd11serv.exe | "{3B7727CD-5E88-44F4-AAC2-AC0429E0FB5D}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{46AA7044-F346-4E52-BEB2-FDF5312E95AC}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe | "{46D96EA7-5846-4B5C-8D73-E803BC3E3FB2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{47F2D89A-9036-4C21-B4F6-F517B7888543}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{4CE9AF3C-093F-49BC-8584-011D15FA10AD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe | "{4F1C4249-87A8-4328-BE93-CF334AE19F31}" = protocol=58 | dir=in | app=system | "{51384C1C-1ED9-4BED-B64A-CC7041268CCC}" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe | "{52C5C448-8867-4664-AB1E-F6704DC3B2BB}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{530B63C5-5E82-40B7-A48A-EC0CB2162E21}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{5468BE86-EB84-4EAD-A955-4CBFBD52168B}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe | "{54C21903-431E-4382-8681-86EA53F2DFD2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\day of defeat source\hl2.exe | "{56B236E6-FB6D-4517-87D8-44FA0F1AC59D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{5AC9ABEC-75D6-474D-A307-80679C3FF041}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{5C6CF5A2-0109-49ED-914A-9486FC652409}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{5CB6EECC-51E5-49BF-A5EF-8373794F5D3A}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd11\powerdvd11.exe | "{5D847636-20B8-4CBA-9740-8EDA8E210579}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\muckel9494\day of defeat source\hl2.exe | "{5D96F2C7-A11E-4A49-90B3-F4DC77029A16}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe | "{5F7BCC3C-D5D5-4C7E-9152-3D35C6B1C0C0}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\wow-x.x.x.x- | "{63255AFE-BDC5-425E-B678-2BA6869FE01C}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd11\movie\moviemodule.exe | "{6A876E2F-E234-4A9E-B950-3F8D5BC42DEA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{6BB9AD88-67EE-4DD5-AFEE-FF2DD23CA884}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\wow-x.x.x.x- | "{6D61F0BC-FC89-452D-8ACA-DB9171FB733D}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe | "{6F480297-8035-4BB3-B397-C53C2C6E78A9}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{6F613C55-12BC-4950-81A0-3E85F0DB911B}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 2050 j510 series\bin\usbsetup.exe | "{7206D89C-362F-46B6-BD5B-A46938AE7B2B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{727002FC-EC65-433F-9E3C-F84ECF00BD3F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{78753F8F-5031-4B10-85BB-C34B8BDD4EE2}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{78FA3DFE-2292-4DEA-996E-3AD1A475B715}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\muckel9494\day of defeat source\hl2.exe | "{7DCF651C-BC02-4485-B227-C0BE330145FF}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe | "{87A157D4-A82E-4425-92CD-BB77CE7C0F72}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{8B16EF21-A260-4B1E-9466-F5329DF9CC18}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe | "{922E9DC8-9B5E-4ED4-A907-8199A8E162C4}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{96B979AA-28E0-420D-A415-904231BE5099}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{96F1C2AE-35CA-4638-9309-3799AF2C889B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{98AFEDC4-9126-4C8E-A290-31166BD8E800}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 | "{9B5ADD55-E9A2-4084-BAC5-47EF64AA9DF0}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd11\common\mediaserver\clmsserverforpdvd11.exe | "{9BF1B22E-560E-41D3-A73F-8AE7857B9DBB}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe | "{9C4ACB1C-27D9-4F05-A8FD-2F66C541D3C4}" = protocol=17 | dir=in | app=c:\program files (x86)\war thunder\launcher.exe | "{A424343F-095C-4269-A655-84729C8E5152}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{A4735427-EE01-4FCE-B6E8-327199D0BF63}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{A7BA3DCA-4883-4DA9-8BF6-793C6505B5BE}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | "{A8BD465D-E668-4559-ACA8-F89F9C21BF14}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe | "{AA417904-3E55-435A-803E-06EB08D22843}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{AAEAF2F2-0E93-4B3B-AACF-D33B5329ADC6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\day of defeat source\hl2.exe | "{AE2ADCC5-E4ED-4641-866A-35AD822F8708}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | "{B0054025-DB47-4AEE-B6E4-DF80BABB725C}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{B1F60670-1C29-468D-8069-CC97A3946914}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{B975C3DB-98AD-459D-8919-E3CF873287FE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "{B9B200E2-D6E0-4DE0-A9EE-79187AC1671D}" = protocol=17 | dir=in | app=c:\users\lukas\downloads\sweetimsetup.exe | "{BC582535-C477-4A0E-83E1-F559A89ACF1D}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe | "{BE5BD327-2ABD-4D05-BF1A-FB8BB4276BEB}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd11\movie\powerdvd cinema\powerdvdcinema11.exe | "{C1032A43-5EE5-4D0B-8835-033D292E2784}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C136B700-B7B7-41C1-977E-E9BB69C8C2A5}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{C2149795-A9DB-4077-B639-CBE91DDBB96A}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{C4BB62DC-4B79-4B46-B6DB-0A219EAF4907}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{CA493B24-8A88-4B0B-839A-D95CF83EF69B}" = protocol=6 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe | "{CA81891C-E126-40D4-894F-490E6E314B69}" = protocol=17 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe | "{CBD7B94B-1966-4525-B127-53F6470833BD}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe | "{CC5FB677-B290-44ED-B701-AE744BCBB517}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | "{CDDB5425-9FF6-47F4-B160-33BB2DEE7784}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{D086D05E-5FD8-40AD-9F33-B87FA1A1AB9B}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | "{D0E22FE2-D3CC-4DA3-AC4A-2D35351EAFAE}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{D9E96581-4713-4269-97F0-4A5FBBAD3790}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe | "{E3808635-1766-4E89-8E31-36A0E8409AC4}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe | "{E56E7D2A-FBF0-480F-AB0A-B03C86765B06}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{EB1949D8-D84D-430A-85EF-5CC7512671A2}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | "{ED8FCACA-D860-4E99-8F33-8CBB505F3CA0}" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe | "{EDA21869-D96D-461F-927D-6CE53F9962DC}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe | "{EED12067-C861-499E-AA32-9C218814E3D9}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{F3B9EA5F-CE45-4553-941E-61B3A2A35042}" = protocol=6 | dir=in | app=c:\program files (x86)\war thunder\launcher.exe | "{F3DEFC0E-2AC9-4F6C-9086-E662F2237BF7}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{F447D683-3AA3-4991-B033-9EEA76DD4AE1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{F673811E-E172-4127-8C54-52646310A084}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe | "TCP Query User{021D247A-DDCC-432A-9106-E948DC9F9367}C:\program files (x86)\peter games\officers\bin\officers.exe" = protocol=6 | dir=in | app=c:\program files (x86)\peter games\officers\bin\officers.exe | "TCP Query User{15392091-D99D-4446-AC53-3666F3923C67}C:\program files (x86)\microsoft games\age of empires ii\empires2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires ii\empires2.exe | "TCP Query User{35616C66-ECFC-4F46-BF43-31F618591419}C:\program files (x86)\microsoft games\rise of nations\nations.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\rise of nations\nations.exe | "TCP Query User{4DF9CEC4-49BB-4E83-9B3A-272FE33AE32B}C:\windows\syswow64\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe | "TCP Query User{76F9C8D6-8A31-47F1-84E8-7B04A2DB96D8}C:\program files (x86)\icq7.4\icq.exe" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe | "TCP Query User{BCC70170-9E46-4D29-9D2A-3A2278021504}C:\program files (x86)\war thunder\aces.exe" = protocol=6 | dir=in | app=c:\program files (x86)\war thunder\aces.exe | "TCP Query User{FF05327A-EAFF-4A8A-815C-6DCD295A9EA7}C:\program files (x86)\microsoft games\age of empires ii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires ii\age2_x1\age2_x1.exe | "UDP Query User{22F32927-0219-499F-B27F-60D1C3082C5D}C:\program files (x86)\microsoft games\rise of nations\nations.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\rise of nations\nations.exe | "UDP Query User{5C58ED93-FB2E-47F8-AF9B-CFA6E92864C8}C:\program files (x86)\microsoft games\age of empires ii\empires2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires ii\empires2.exe | "UDP Query User{74EC81F2-34FF-48CC-9A37-EE80939570B0}C:\program files (x86)\war thunder\aces.exe" = protocol=17 | dir=in | app=c:\program files (x86)\war thunder\aces.exe | "UDP Query User{94FE40DB-5BD0-4E39-BB3C-F7BF7CE2F0D8}C:\program files (x86)\icq7.4\icq.exe" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe | "UDP Query User{95DD8799-E079-4A85-AC0E-E68FE7D0C2EC}C:\program files (x86)\peter games\officers\bin\officers.exe" = protocol=17 | dir=in | app=c:\program files (x86)\peter games\officers\bin\officers.exe | "UDP Query User{9D9B0869-3FFA-4139-84CA-AC4FE8E262F4}C:\program files (x86)\microsoft games\age of empires ii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires ii\age2_x1\age2_x1.exe | "UDP Query User{B5FE8A3E-7549-485D-81BA-63BD9AC47831}C:\windows\syswow64\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center "{01DA217A-DB5F-B568-6932-42407D209516}" = ccc-utility64 "{0BD776F3-057D-4C11-020C-4FA9B13D04F9}" = AMD Catalyst Install Manager "{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes "{0E931A51-A183-4E66-8562-D82896E74C67}" = BFlix Gadget "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{24F93B56-61F5-415F-85B9-AA444DA34AFC}" = Microsoft-Maus- und Tastatur-Center "{26A24AE4-039D-4CA4-87B4-2F86416023FF}" = Java(TM) 6 Update 23 (64-bit) "{29AFE1B0-26A4-11E1-BFD4-F04DA23A5C58}" = MSVCRT Redists "{463FB535-67FB-17C9-6FD6-164BC60462F6}" = ccc-utility64 "{4D533F05-A3F6-F8A9-F1F6-FA6812089D36}" = AMD Drag and Drop Transcoding "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer "{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst "{A1F8353C-39A2-4327-867E-C6714131BEFC}" = Studie zur Verbesserung von HP Deskjet 2050 J510 series Produkten "{A6FE29A0-622B-2763-88AA-D1E084F77CD9}" = AMD Media Foundation Decoders "{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10 "{C263ED32-78DB-40EB-8B12-2925C8213E28}" = HP Deskjet 2050 J510 series - Grundlegende Software für das Gerät "{C73A3942-84C8-4597-9F9B-EE227DCBA758}" = Dell Dock "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources "{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support "{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "AC1148CDE5B10540E534CA01EAE59722C68646FB" = Windows-Treiberpaket - USB PC Camera Driver (01/01/2007 "Dell Support Center" = Dell Support Center "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft Mouse and Keyboard Center" = Microsoft-Maus- und Tastatur-Center "NewBlue Art Effects for PDR10" = Art Effects for PDR10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86 "{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0BAF04C4-9D21-2761-95A6-DE2DA9861323}" = CCC Help Spanish "{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup "{1C1473A1-1A26-4C8F-9548-A52D03066CE7}" = Catalyst Control Center - Branding "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources "{1EAC1D02-C6AC-4FA6-9A44-96258C37C812NA}_is1" = World of Tanks "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{23B4636C-A780-4FEB-B4C9-A2564E9B9F7C}" = Multimedia Card Reader "{24D3ACAC-E441-AF66-94CF-0C021A4EFBD8}" = Catalyst Control Center Localization All "{265245FC-4ECC-C35A-F2A9-3E915BFB2F6F}" = Catalyst Control Center Graphics Previews Common "{268679E8-7198-F2E6-5A71-F3D4C9A0C2FB}" = CCC Help Italian "{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 29 "{26A24AE4-039D-4CA4-87B4-2F83217011FF}" = Java 7 Update 11 "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{2ECA81CA-D932-4AD3-AD59-BF5CCF099C83}" = Catalyst Control Center - Branding "{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5 "{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor "{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{347151C4-7F16-B275-8865-CC6B64056D3F}" = Catalyst Control Center Graphics Previews Common "{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{38B2B0F6-0C7F-ECE6-9A61-C546658508F4}" = ccc-core-static "{4261174B-FCD7-CD19-E81C-24262EB5AF42}" = CCC Help Greek "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4C352349-421A-7E87-C7BD-DF27162B12CA}" = Catalyst Control Center Graphics Previews Vista "{4DF4CAB9-B628-4924-AD9A-1C457DD2960A}" = VirtualDJ Home FREE "{520C1D80-935C-42B9-9340-E883849D804F}_is1" = DriverTuner "{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack "{5CCF2E33-181B-BD49-57AE-B513D37C6909}" = CCC Help English "{62AEBBB6-8314-7902-B3DA-1690F97DFA74}" = CCC Help English "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86 "{649483EB-B464-1EE2-04E4-4BEC79B510D4}" = CCC Help German "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3 "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6A646891-7B53-C462-0B71-401E519D198C}" = Catalyst Control Center InstallProxy "{6BE7495E-8DF1-11E1-BB7D-F04DA23A5C58}" = Vegas Pro 11.0 "{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter "{70CB6C40-8DF1-11E1-BDCF-F04DA23A5C58}" = MSVCRT Redists "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71277DC4-4217-462A-9FF4-62D7815B2C69}" = ADDICT-THING "{7204BDEE-1A48-4D95-A964-44A9250B439E}" = Facebook Messenger 2.1.4814.0 "{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}" = ICQ7.4 "{75F36A60-9969-C24F-5EB1-6DBC03F15196}" = CCC Help Russian "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar "{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{79872596-B887-E700-8D56-CADBC78BA5DE}" = Adobe Download Assistant "{7A3DF2E2-CF13-44FB-A93E-F71D5381DB3F}" = HP Deskjet 2050 J510 series Hilfe "{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide "{7EC66A95-AC2D-4127-940B-0445A526AB2F}" = Dell DataSafe Online "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer "{85F93FBC-02AF-1E39-D027-0E1FCA5C90F5}" = Skins "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar "{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger "{887D48C8-DA00-232B-3CB6-0FB086AD6FBB}" = CCC Help Chinese Standard "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8CF2328D-A3D1-B08C-E868-68CDA4025E1D}" = CCC Help Polish "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch "{915284CD-1A88-82B0-7ED8-08BCF1B8509A}" = CCC Help Norwegian "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{9720C029-0C2C-4D1E-9DE0-E89971C4C8C7}" = Silent Hunter III "{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars "{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A8B88634-7F90-402F-B66A-86429755F6A5}" = eBay "{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{ABEE1201-0FEA-E62F-6CB9-5D54BEB5E4AA}" = CCC Help Dutch "{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.4) MUI "{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh "{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime "{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail "{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86 "{B82EC7CD-5FB1-32A5-444A-8F896B734CC7}" = CCC Help Korean "{B89E66E6-659A-9078-2BDF-14E8C11928AA}" = CCC Help Chinese Traditional "{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling "{BAF6A826-DF92-8954-98F1-2CC67C6B419E}" = CCC Help Portuguese "{BB761E7E-2635-4E12-A7E8-7431BE178953}" = Chrome toolbar by SweetPacks "{BD6A872A-A0AE-36FC-9284-6E3595FB39ED}" = CCC Help Danish "{C01AE05C-3C8C-75B3-C9F0-1B525DD3697C}" = Catalyst Control Center InstallProxy "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" = Internet Explorer Toolbar 4.6 by SweetPacks "{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections "{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser "{C9461813-98BB-5823-FFAB-11FBD1B124DF}" = CCC Help Japanese "{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D1AE1C98-646A-DC21-076A-0FD5957FCAD2}" = CCC Help Czech "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D4A97EBC-ABA6-9F3A-1EE0-D5B6C36FDFB5}" = CCC Help Finnish "{D5B1535A-FDFC-4B40-B2E2-21DA83D9CB57}" = Adobe Audition CS5.5 "{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM) "{D98C9637-93DA-44DB-B73A-B11A1192AB26}" = GameShadow "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E398E7CC-30B8-4D63-B07B-741163A12565}" = USB PC Camera Driver "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{E5AF275B-D4B1-EE5E-27BD-844C491B86CA}" = CCC Help Swedish "{E5FCC675-C479-3CAB-0B9E-CC1838417049}" = CCC Help Hungarian "{E8C5BD56-F5D8-41D3-8A71-273468FE256A}" = T-Home Dialerschutz-Software "{E9811C8F-D729-01D3-9347-DCE297354C0A}" = CCC Help French "{EA4340F5-7676-693D-A908-DF9D44771F7B}" = CCC Help Thai "{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}" = Update Manager for SweetPacks 1.1 "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1" = War Thunder Launcher "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter "{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter "{F09C03B6-CF93-5099-4ED7-CF47DB2027E6}" = CCC Help Turkish "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F232C87C-6E92-4775-8210-DFE90B7777D9}" = CyberLink PowerDVD 11 "{F865B0B5-0D43-2704-0B22-35C5F721374B}" = Catalyst Control Center "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Age of Empires 2.0" = Microsoft Age of Empires II "Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion "Audacity_is1" = Audacity 1.2.6 "Avira AntiVir Desktop" = Avira Free Antivirus "BabylonToolbar" = Babylon toolbar "BitTorrent" = BitTorrent "BittorrentBar_DE Toolbar" = BittorrentBar_DE Toolbar "Call of Duty Modern Warfare 2_is1" = Call of Duty Modern Warfare 2 "Call of Duty: Black Ops_is1" = Call of Duty: Black Ops "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help "com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant "DAEMON Tools Lite" = DAEMON Tools Lite "Dell Dock" = Dell Dock "DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar "Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7 "Free YouTube Download_is1" = Free YouTube Download version "Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version "GCH Guitar academy" = GCH Guitar academy "HP Photo Creations" = HP Photo Creations "ICQToolbar" = ICQ Toolbar "InstallShield_{23B4636C-A780-4FEB-B4C9-A2564E9B9F7C}" = Multimedia Card Reader "InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5 "InstallShield_{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor "InstallShield_{9720C029-0C2C-4D1E-9DE0-E89971C4C8C7}" = Silent Hunter III "InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10 "InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM) "InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}" = CyberLink PowerDVD 11 "LAME for Audacity_is1" = LAME v3.98.3 for Audacity "MAGIX Podcast Maker e-version D" = MAGIX Podcast Maker e-version (D) "McAfee Security Scan" = McAfee Security Scan Plus "Monster Stimme 1" = Monster Stimme 1 "Mozilla Firefox 20.0.1 (x86 de)" = Mozilla Firefox 20.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "N360" = Norton 360 "Office14.Click2Run" = Microsoft Office Klick-und-Los 2010 "Office8.0" = Microsoft Office 97, Professional Edition "Peter Games Officers" = Peter Games Officers "PriceGong" = PriceGong 2.6.7 "PunkBusterSvc" = PunkBuster Services "RealPlayer 12.0" = RealPlayer "RiseOfNations 1.0" = Microsoft Rise Of Nations "ScanQuery" = ScanQuery 1.0 build 125 powered by FIRST SEARCHBAR "Steam App 240" = Counter-Strike: Source "Steam App 300" = Day of Defeat: Source "Steam App 42710" = Call of Duty: Black Ops - Multiplayer "Steam App 550" = Left 4 Dead 2 "TeamSpeak 3 Client" = TeamSpeak 3 Client "Uninstall_is1" = Uninstall "WildTangent dell Master Uninstall" = WildTangent-Spiele "WinGimp-2.0_is1" = GIMP 2.6.11 "Wings of Prey (Collector's Edition)_is1" = Wings of Prey (Collector's Edition) "WinLiveSuite" = Windows Live Essentials "WinRAR archiver" = WinRAR 4.00 (32-Bit) "WNLT" = IB Updater Service "World of Warcraft" = World of Warcraft "YTdetect" = Yahoo! Detect ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater "Casino Riva" = Casino Riva "Google Chrome" = Google Chrome ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 15.06.2013 20:12:03 | Computer Name = Lukas-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 6053 Error - 15.06.2013 20:12:04 | Computer Name = Lukas-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 15.06.2013 20:12:04 | Computer Name = Lukas-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 7052 Error - 15.06.2013 20:12:04 | Computer Name = Lukas-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 7052 Error - 15.06.2013 20:12:05 | Computer Name = Lukas-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 15.06.2013 20:12:05 | Computer Name = Lukas-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 8066 Error - 15.06.2013 20:12:05 | Computer Name = Lukas-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 8066 Error - 17.06.2013 15:15:07 | Computer Name = Lukas-PC | Source = Application Hang | ID = 1002 Description = Programm OTL.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1ad4 Startzeit: 01ce6b8e4f331bf3 Endzeit: 8 Anwendungspfad: C:\Users\Lukas\Downloads\OTL.exe Berichts-ID: 32abb308-d782-11e2-bb95-842b2bb81361 Error - 17.06.2013 15:17:19 | Computer Name = Lukas-PC | Source = Application Hang | ID = 1002 Description = Programm OTL.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1114 Startzeit: 01ce6b8efdcca47d Endzeit: 4 Anwendungspfad: C:\Users\Lukas\Desktop\OTL.exe Berichts-ID: 84b28521-d782-11e2-bb95-842b2bb81361 Error - 17.06.2013 15:19:00 | Computer Name = Lukas-PC | Source = Application Hang | ID = 1002 Description = Programm OTL.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 160c Startzeit: 01ce6b8f4c76d17c Endzeit: 6 Anwendungspfad: C:\Users\Lukas\Desktop\OTL.exe Berichts-ID: c1938494-d782-11e2-bb95-842b2bb81361 [ Dell Events ] Error - 11.04.2011 10:22:12 | Computer Name = Lukas-PC | Source = DataSafe | ID = 17 Description = Der Vorgang wurde unterbrochen, bevor er abgeschlossen werden konnte. Error - 12.04.2011 15:15:13 | Computer Name = Lukas-PC | Source = DataSafe | ID = 17 Description = Der Vorgang wurde unterbrochen, bevor er abgeschlossen werden konnte. Error - 12.04.2011 15:15:13 | Computer Name = Lukas-PC | Source = DataSafe | ID = 17 Description = Der Vorgang wurde unterbrochen, bevor er abgeschlossen werden konnte. Error - 17.05.2011 14:34:08 | Computer Name = Lukas-PC | Source = DataSafe | ID = 17 Description = Der Vorgang wurde unterbrochen, bevor er abgeschlossen werden konnte. Error - 05.07.2011 15:38:32 | Computer Name = Lukas-PC | Source = DataSafe | ID = 17 Description = Der Vorgang wurde unterbrochen, bevor er abgeschlossen werden konnte. Error - 05.07.2011 15:38:32 | Computer Name = Lukas-PC | Source = DataSafe | ID = 17 Description = Der Vorgang wurde unterbrochen, bevor er abgeschlossen werden konnte. Error - 01.07.2012 11:05:24 | Computer Name = Lukas-PC | Source = DataSafe | ID = 17 Description = Der Vorgang wurde unterbrochen, bevor er abgeschlossen werden konnte. Error - 17.01.2013 02:52:53 | Computer Name = Lukas-PC | Source = DataSafe | ID = 17 Description = Der Vorgang wurde unterbrochen, bevor er abgeschlossen werden konnte. Error - 17.01.2013 02:52:53 | Computer Name = Lukas-PC | Source = DataSafe | ID = 17 Description = Der Vorgang wurde unterbrochen, bevor er abgeschlossen werden konnte. Error - 17.01.2013 20:01:39 | Computer Name = Lukas-PC | Source = DataSafe | ID = 17 Description = Der Vorgang wurde unterbrochen, bevor er abgeschlossen werden konnte. [ System Events ] Error - 14.06.2013 13:34:12 | Computer Name = Lukas-PC | Source = Service Control Manager | ID = 7038 Description = Der Dienst "PolicyAgent" konnte sich nicht als "NT Authority\NetworkService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1352 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error - 14.06.2013 13:34:12 | Computer Name = Lukas-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "IPsec-Richtlinien-Agent" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error - 14.06.2013 13:34:12 | Computer Name = Lukas-PC | Source = Service Control Manager | ID = 7038 Description = Der Dienst "PolicyAgent" konnte sich nicht als "NT Authority\NetworkService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1352 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error - 14.06.2013 13:34:12 | Computer Name = Lukas-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "IPsec-Richtlinien-Agent" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error - 14.06.2013 13:34:12 | Computer Name = Lukas-PC | Source = Service Control Manager | ID = 7038 Description = Der Dienst "PolicyAgent" konnte sich nicht als "NT Authority\NetworkService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1352 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error - 14.06.2013 13:34:12 | Computer Name = Lukas-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "IPsec-Richtlinien-Agent" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error - 14.06.2013 13:34:12 | Computer Name = Lukas-PC | Source = Service Control Manager | ID = 7038 Description = Der Dienst "PolicyAgent" konnte sich nicht als "NT Authority\NetworkService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1352 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error - 14.06.2013 13:34:12 | Computer Name = Lukas-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "IPsec-Richtlinien-Agent" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error - 15.06.2013 20:11:39 | Computer Name = Lukas-PC | Source = Service Control Manager | ID = 7034 Description = Dienst "CyberLink PowerDVD 11.0 Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error - 15.06.2013 23:19:19 | Computer Name = Lukas-PC | Source = Service Control Manager | ID = 7034 Description = Dienst "CyberLink PowerDVD 11.0 Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. < End of report > [TABLE] |
/// the machine /// TB-Ausbilder

wssetup.exe von Perion Network Ltd. Downloade Dir bitte
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches OTL log. Noch PRobleme? ![]()
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| ![]() wssetup.exe von Perion Network Ltd. ____ Geändert von Einz (20.06.2013 um 00:40 Uhr) |
| ![]() wssetup.exe von Perion Network Ltd. Danke! scheint alles gut zu sein ![]() SecurityCheck : UNSUPPORTED OPERATING SYSTEM! ABORTED! |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() wssetup.exe von Perion Network Ltd. Das OTL log fehlt noch ![]()
![]() | #8 |
| ![]() wssetup.exe von Perion Network Ltd. soo , da sind sie. & eine Frage hab ich noch , auf meinem Desktop sind jetzt 4 neue Ordner : 2x Desktop.ini - Folder.jpg - AlbumArtSmall.jpg Was mach ich mit den? ich kann die nicht verschieben.. da ist auch so eine Zahnrad drauf .. keine Ahnung hab diese Ordner noch nie gesehen ![]() OTL Logfile: Code:
/// the machine /// TB-Ausbilder

wssetup.exe von Perion Network Ltd. Das kommt weil wir versteckte Dateien anzeigen lassen, das geht nachher wieder weg

ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST LOg bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| ![]() wssetup.exe von Perion Network Ltd. Den Eset Online Scan habe ich bereits durchgeführt , den SecurityCheck ebenso. Ist es notwendig diesen nochmal durchzuführen? |
/// the machine /// TB-Ausbilder

wssetup.exe von Perion Network Ltd. Ignorier mich, mir fehlt Kaffee

Fertig

Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| ![]() wssetup.exe von Perion Network Ltd. Mir fällt ein , hab ganz vergessen mich zu bedanken ![]() --> Danke! ![]() |
/// the machine /// TB-Ausbilder

wssetup.exe von Perion Network Ltd. Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
