|
Plagegeister aller Art und deren Bekämpfung: Computerspiel lässt sich nicht deinstallierenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
17.04.2014, 10:43 | #1 |
| Computerspiel lässt sich nicht deinstallieren Hallo ich hab folgendes Problem. Und zwar ich hab mir heute von hxxp://www.4players.de zwei patch für das PC-Spiel Panzers Phase 2 runter geladen den 1.06 (hxxp://www.4players.de/4players.php/download_info/Downloads/Download/44892/Codename_Panzers_-_Phase_Two/Patch_106.html) und den 1.08 hxxp://www.4players.de/4players.php/download_info/Downloads/Download/46204/Codename_Panzers_-_Phase_Two/Patch_108.html kurz darauf kam ein komisches Bild, wo es hieß Schutz system, und ich solle meinen PC neu starten um die Installation der Kopierschutztreiber abzuschließen machte ich. Darauf hin kam beim Starten des Spieles die gleiche Meldung. Mir war es dann zu blöd ich wollte das Spiel Deinstallieren ging nicht mit den Hinweis INSTALL.LOG nicht gefunden. Ich lies dan mal mein Norten drüber laufen weil mir das ganze sehr komisch vorkam dieses sagte alles ist in ordnung. Kann mir da jemand von euch Helfen?? |
17.04.2014, 12:23 | #2 |
/// the machine /// TB-Ausbilder | Computerspiel lässt sich nicht deinstallieren hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
17.04.2014, 17:58 | #3 |
| Computerspiel lässt sich nicht deinstallieren FRST Logfile:
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-04-2014 Ran by XXXXX (administrator) on XXXXX-PC on 17-04-2014 18:52:29 Running from C:\Users\XXXXXr\Downloads Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe (Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\NST.exe () C:\Windows\system32\PnkBstrA.exe () C:\Program Files\CyberLink\Shared files\RichVideo.exe (Secunia) C:\Program Files\Secunia\PSI\PSIA.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\NST.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe (Panda Security) C:\Program Files\Panda USB Vaccine\USBVaccine.exe (CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Secunia) C:\Program Files\Secunia\PSI\sua.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\system32\cmd.exe (Akamai Technologies, Inc.) C:\Users\XXXX\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\XXXX\AppData\Local\Akamai\netsession_win.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [CLMLServer] => C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-06-03] (CyberLink) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7866912 2009-11-10] (Realtek Semiconductor) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation) HKU\S-1-5-21-633659925-2557700935-1756672399-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Zrenner\AppData\Local\Akamai\netsession_win.exe [4441920 2012-10-09] (Akamai Technologies, Inc.) HKU\S-1-5-21-633659925-2557700935-1756672399-1000\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_77_Plugin.exe [841096 2014-03-11] (Adobe Systems Incorporated) HKU\S-1-5-21-633659925-2557700935-1756672399-1000\...\Policies\Explorer: [] HKU\S-1-5-21-633659925-2557700935-1756672399-1004\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] () HKU\S-1-5-21-633659925-2557700935-1756672399-1004\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs AppInit_DLLs: 0 => 0 File Not Found Startup: C:\Users\XXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 4620 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 4620 series.lnk -> C:\Program Files\HP\HP Officejet 4620 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=BDT3&ocid=BDT3DHP&dt=071013 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com SearchScopes: HKCU - {F1916C67-7E1C-4C8B-A5AC-B2DEFAAD4952} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=3fe99603-b328-4298-89e7-8793938254f0&apn_sauid=7D960AC0-72C8-4774-8642-A9DD4D70C935 BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\coIEPlg.dll (Symantec Corporation) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Profiles\4j5617b3.default FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Google FF Homepage: https://startpage.com/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.4 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files\Virtual Earth 3D\ () FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DoNotTrackMe: Online Privacy Protection - C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Profiles\4j5617b3.default\Extensions\donottrackplus@abine.com [2014-03-15] FF Extension: WOT - C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Profiles\4j5617b3.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26] FF Extension: NoScript - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\4j5617b3.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-08-04] FF Extension: Adblock Plus - C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Profiles\4j5617b3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-17] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-30] FF HKLM\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.7.0.43\coFFPlgn\ FF Extension: Norton Identity Safe Toolbar - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.7.0.43\coFFPlgn\ [] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com/" CHR Extension: (Google Docs) - C:\Users\xXXXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-11] CHR Extension: (Google Drive) - C:\Users\XXXXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-11] CHR Extension: (YouTube) - C:\Users\XXXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-11] CHR Extension: (Google-Suche) - C:\Users\XXXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-11] CHR Extension: (Chrome In-App Payments service) - C:\Users\XXXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-11] CHR Extension: (Google Mail) - C:\Users\XXXXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-11] CHR HKLM\...\Chrome\Extension: [nppllibpnmahfaklnpggkibhkapjkeob] - C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\Exts\Chrome.crx [2014-03-26] ========================== Services (Whitelisted) ================= R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.) S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1044816 2012-11-13] (Flexera Software, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation) R2 NCO; C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\NST.exe [130104 2014-03-11] (Symantec Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [66872 2012-11-27] () R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [244904 2009-07-27] () R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [129112 2013-07-08] (Sandboxie Holdings, LLC) R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1227800 2013-04-18] (Secunia) R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [659992 2013-04-18] (Secunia) R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.) S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [83872 2013-02-24] () R1 ccSet_NST; C:\Windows\system32\drivers\NST\7DE07000.02B\ccSetx86.sys [127064 2013-09-27] (Symantec Corporation) R3 hidkmdf; C:\Windows\System32\DRIVERS\hidkmdf.sys [10360 2009-10-29] (Windows (R) Win 7 DDK provider) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2013-02-24] () R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation) R1 MpKsl03906206; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5FCF510D-0783-4722-8AE7-C46F63DB95C8}\MpKsl03906206.sys [39464 2014-04-17] (Microsoft Corporation) R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-06-05] (NVIDIA Corporation) R3 NW1950; C:\Windows\System32\DRIVERS\NW1950.sys [22392 2009-10-29] () R3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1558368 2009-12-22] (NXP Semiconductors Germany GmbH) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-04-18] (Secunia) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [159208 2013-07-08] (Sandboxie Holdings, LLC) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-17 18:52 - 2014-04-17 18:52 - 00015219 _____ () C:\Users\XXXXX\Downloads\FRST.txt 2014-04-17 18:52 - 2014-04-17 18:52 - 00000000 ____D () C:\FRST 2014-04-17 18:51 - 2014-04-17 18:51 - 01146880 _____ (Farbar) C:\Users\XXXX\Downloads\FRST.exe 2014-04-17 13:04 - 2014-04-17 13:04 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-04-17 13:03 - 2014-04-17 13:03 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-04-17 12:58 - 2014-04-17 12:58 - 11268944 _____ (Microsoft Corporation) C:\Users\XXXXX\Downloads\mseinstall.exe 2014-04-17 10:30 - 2014-04-17 10:32 - 88999296 _____ () C:\Users\XXXX\Downloads\Phase2_Patch_V1_06_CZ_DE_EN_FRA_HU.exe 2014-04-17 10:30 - 2014-04-17 10:30 - 02007751 _____ () C:\Users\XXXX\Downloads\Panzers_p2_v1.08.zip 2014-04-17 10:26 - 2014-04-17 11:54 - 00002258 _____ () C:\Windows\DirectX.log 2014-04-17 10:26 - 2014-04-17 11:53 - 00002308 _____ () C:\Users\XXXXX\Desktop\PANZERS - Phase2.lnk 2014-04-17 10:26 - 2014-04-17 11:53 - 00002308 _____ () C:\Users\UpdatusUser\Desktop\PANZERS - Phase2.lnk 2014-04-17 10:26 - 2014-04-17 11:53 - 00002308 _____ () C:\Users\XXXXX\Desktop\PANZERS - Phase2.lnk 2014-04-17 10:26 - 2014-04-17 10:26 - 00000000 ____D () C:\Users\XXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PANZERS - Phase2 2014-04-11 13:12 - 2014-04-11 13:12 - 01070840 _____ (Solid State Networks) C:\Users\XXXXX\Downloads\install_flashplayer13x32au_mssd_aaa_aih.exe 2014-04-09 13:15 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 13:15 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 13:15 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 13:15 - 2014-02-04 04:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 13:15 - 2014-02-04 04:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 13:15 - 2014-02-04 04:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 13:15 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 13:15 - 2014-01-24 04:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-07 16:51 - 2014-04-17 12:00 - 00000000 ____D () C:\Users\XXXX\AppData\Local\CrashDumps 2014-04-07 15:22 - 2014-04-07 15:22 - 02278856 _____ () C:\Users\xXXXX\Downloads\avira_pc_cleaner_de.exe 2014-04-01 16:54 - 2014-04-17 16:17 - 00002128 _____ () C:\Windows\setupact.log 2014-04-01 16:54 - 2014-04-17 13:25 - 01047772 _____ () C:\Windows\PFRO.log 2014-04-01 16:54 - 2014-04-01 16:54 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-31 20:56 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-03-31 20:48 - 2014-03-31 20:51 - 240202472 ____N (Symantec Corporation) C:\Users\XXXXX\Downloads\NAV_21.1.0.18_SYMTB_PROMO_4_MRFTT_828_10143-DE1.exe 2014-03-31 20:34 - 2013-10-02 02:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-03-31 20:34 - 2013-10-02 02:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-03-31 20:34 - 2013-10-02 02:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-03-31 20:34 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-03-31 20:34 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-03-31 20:34 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-03-31 20:34 - 2013-10-02 01:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-03-31 20:34 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-03-31 20:34 - 2013-10-02 01:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-03-31 20:34 - 2013-10-02 00:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-03-31 20:34 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-03-31 20:30 - 2014-03-31 20:30 - 00283192 _____ (Mozilla) C:\Users\Zrenner\Downloads\Firefox Setup Stub 28.0.exe 2014-03-31 20:20 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-03-30 18:53 - 2014-03-31 20:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-03-29 15:33 - 2014-03-29 15:33 - 00000000 ____D () C:\Users\XXXX\Documents\Command & Conquer 3 Tiberium Wars 2014-03-26 19:42 - 2014-03-26 19:42 - 00002475 _____ () C:\Users\Public\Desktop\Norton Identity Safe.lnk 2014-03-26 19:41 - 2014-03-26 19:41 - 00000000 ____D () C:\Windows\system32\Drivers\NST 2014-03-26 19:41 - 2014-03-26 19:41 - 00000000 ____D () C:\Program Files\Norton Identity Safe 2014-03-26 19:39 - 2014-03-26 19:39 - 00000244 _____ () C:\Users\XXXX\Desktop\Command & Conquer 3 Tiberium Wars.lnk 2014-03-26 19:10 - 2014-03-26 19:10 - 00000000 ____D () C:\Program Files\Electronic Arts 2014-03-25 20:38 - 2014-03-25 20:38 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-25 20:38 - 2014-03-25 20:38 - 00000000 ____D () C:\Users\XXXX\AppData\Local\Skype 2014-03-25 20:38 - 2014-03-25 20:38 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-03-24 20:28 - 2014-04-01 16:55 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird ==================== One Month Modified Files and Folders ======= 2014-04-17 18:52 - 2014-04-17 18:52 - 00015219 _____ () C:\Users\XXXX\Downloads\FRST.txt 2014-04-17 18:52 - 2014-04-17 18:52 - 00000000 ____D () C:\FRST 2014-04-17 18:51 - 2014-04-17 18:51 - 01146880 _____ (Farbar) C:\Users\XXXXX\Downloads\FRST.exe 2014-04-17 18:48 - 2012-11-12 17:55 - 00000000 ____D () C:\Users\XXXX\AppData\Local\Akamai 2014-04-17 18:47 - 2014-01-29 16:31 - 01383432 _____ () C:\Windows\WindowsUpdate.log 2014-04-17 18:47 - 2012-07-17 18:30 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-17 16:25 - 2009-07-14 06:34 - 00009888 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-17 16:25 - 2009-07-14 06:34 - 00009888 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-17 16:17 - 2014-04-01 16:54 - 00002128 _____ () C:\Windows\setupact.log 2014-04-17 16:17 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-17 13:25 - 2014-04-01 16:54 - 01047772 _____ () C:\Windows\PFRO.log 2014-04-17 13:25 - 2014-02-04 17:56 - 00000000 ____D () C:\avast! sandbox 2014-04-17 13:25 - 2014-01-25 14:33 - 00000000 ____D () C:\ProgramData\Norton 2014-04-17 13:25 - 2013-06-17 11:46 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-04-17 13:04 - 2014-04-17 13:04 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-04-17 13:03 - 2014-04-17 13:03 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-04-17 12:58 - 2014-04-17 12:58 - 11268944 _____ (Microsoft Corporation) C:\Users\XXXXX\Downloads\mseinstall.exe 2014-04-17 12:00 - 2014-04-07 16:51 - 00000000 ____D () C:\Users\XXXXX\AppData\Local\CrashDumps 2014-04-17 11:55 - 2012-05-20 10:53 - 00000064 _____ () C:\Windows\WININIT.INI 2014-04-17 11:54 - 2014-04-17 10:26 - 00002258 _____ () C:\Windows\DirectX.log 2014-04-17 11:53 - 2014-04-17 10:26 - 00002308 _____ () C:\Users\XXXX\Desktop\PANZERS - Phase2.lnk 2014-04-17 11:53 - 2014-04-17 10:26 - 00002308 _____ () C:\Users\UpdatusUser\Desktop\PANZERS - Phase2.lnk 2014-04-17 11:53 - 2014-04-17 10:26 - 00002308 _____ () C:\Users\XXXXX\Desktop\PANZERS - Phase2.lnk 2014-04-17 11:53 - 2012-06-15 11:02 - 00002308 _____ () C:\Users\Gast\Desktop\PANZERS - Phase2.lnk 2014-04-17 11:53 - 2012-06-15 10:48 - 00000000 ____D () C:\Program Files\Common Files\PANZERS - Phase2 2014-04-17 10:32 - 2014-04-17 10:30 - 88999296 _____ () C:\Users\XXXXX\Downloads\Phase2_Patch_V1_06_CZ_DE_EN_FRA_HU.exe 2014-04-17 10:30 - 2014-04-17 10:30 - 02007751 _____ () C:\Users\XXXX\Downloads\Panzers_p2_v1.08.zip 2014-04-17 10:26 - 2014-04-17 10:26 - 00000000 ____D () C:\Users\XXXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PANZERS - Phase2 2014-04-17 09:15 - 2013-01-12 18:19 - 00000000 ____D () C:\Users\XXXX\Desktop\Tor Browser 2014-04-16 18:48 - 2010-01-22 13:40 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-14 20:25 - 2012-07-15 13:38 - 00136344 _____ () C:\Users\XXXXX\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-13 20:48 - 2009-07-14 10:56 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-04-12 21:31 - 2013-09-28 16:12 - 00000000 ____D () C:\Users\XXXX\WORK 2014-04-11 13:22 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF 2014-04-11 13:12 - 2014-04-11 13:12 - 01070840 _____ (Solid State Networks) C:\Users\XXXXX\Downloads\install_flashplayer13x32au_mssd_aaa_aih.exe 2014-04-09 21:59 - 2012-07-15 13:28 - 00000000 ____D () C:\Users\XXXXX 2014-04-09 21:59 - 2012-06-01 20:58 - 00000000 ____D () C:\Users\Gast 2014-04-09 21:45 - 2013-04-08 12:12 - 00000000 ____D () C:\Program Files\Steam 2014-04-09 21:42 - 2012-12-14 16:13 - 00000000 ____D () C:\Program Files\Common Files\Steam 2014-04-09 18:47 - 2010-11-11 14:07 - 00000000 ____D () C:\Users\XXXXX 2014-04-09 18:44 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-04-09 14:01 - 2010-01-22 17:26 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-09 13:59 - 2013-08-15 00:07 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 13:55 - 2010-01-22 15:33 - 88028728 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 13:05 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-08 17:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-04-07 15:22 - 2014-04-07 15:22 - 02278856 _____ () C:\Users\XXXX\Downloads\avira_pc_cleaner_de.exe 2014-04-01 16:55 - 2014-03-24 20:28 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird 2014-04-01 16:54 - 2014-04-01 16:54 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-31 20:51 - 2014-03-31 20:48 - 240202472 ____N (Symantec Corporation) C:\Users\XXXXX\Downloads\NAV_21.1.0.18_SYMTB_PROMO_4_MRFTT_828_10143-DE1.exe 2014-03-31 20:41 - 2010-01-22 15:06 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-03-31 20:39 - 2014-03-30 18:53 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-03-31 20:39 - 2012-07-17 18:37 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-03-31 20:38 - 2009-07-14 10:47 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE 2014-03-31 20:32 - 2012-07-17 18:33 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-31 20:30 - 2014-03-31 20:30 - 00283192 _____ (Mozilla) C:\Users\XXXXX\Downloads\Firefox Setup Stub 28.0.exe 2014-03-31 02:13 - 2014-04-09 13:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 13:15 - 17073152 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-30 22:41 - 2014-02-15 17:37 - 00000000 ____D () C:\Program Files\Mozilla Firefox.bak 2014-03-29 19:54 - 2014-03-06 17:25 - 00001003 _____ () C:\Users\XXXXX\Documents\MailShield.der 2014-03-29 15:33 - 2014-03-29 15:33 - 00000000 ____D () C:\Users\XXXXX\Documents\Command & Conquer 3 Tiberium Wars 2014-03-26 19:42 - 2014-03-26 19:42 - 00002475 _____ () C:\Users\Public\Desktop\Norton Identity Safe.lnk 2014-03-26 19:41 - 2014-03-26 19:41 - 00000000 ____D () C:\Windows\system32\Drivers\NST 2014-03-26 19:41 - 2014-03-26 19:41 - 00000000 ____D () C:\Program Files\Norton Identity Safe 2014-03-26 19:39 - 2014-03-26 19:39 - 00000244 _____ () C:\Users\XXXX\Desktop\Command & Conquer 3 Tiberium Wars.lnk 2014-03-26 19:10 - 2014-03-26 19:10 - 00000000 ____D () C:\Program Files\Electronic Arts 2014-03-25 21:26 - 2012-07-17 19:08 - 00000000 ____D () C:\Users\XXXX\AppData\Roaming\Skype 2014-03-25 20:38 - 2014-03-25 20:38 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-25 20:38 - 2014-03-25 20:38 - 00000000 ____D () C:\Users\XXXXX\AppData\Local\Skype 2014-03-25 20:38 - 2014-03-25 20:38 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-03-25 20:38 - 2012-07-17 19:08 - 00000000 ___RD () C:\Program Files\Skype 2014-03-25 20:38 - 2012-07-17 19:07 - 00000000 ____D () C:\ProgramData\Skype 2014-03-25 20:33 - 2010-11-22 13:15 - 00136344 _____ () C:\Users\XXXXX\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-25 17:35 - 2009-07-14 06:33 - 00469696 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-24 20:37 - 2010-02-04 10:23 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-03-19 20:20 - 2014-03-06 15:30 - 00000000 ____D () C:\Users\XXXXX\AppData\Local\Thunderbird Some content of TEMP: ==================== C:\Users\XXXXX\AppData\Local\Temp\AskSLib.dll C:\Users\XXXX\AppData\Local\Temp\DivSetup.exe C:\Users\XXXX\AppData\Local\Temp\drm_dyndata_7290008.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-10 22:11 ==================== End Of Log ============================ --- --- --- --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 17-04-2014 Ran by XXXXX at 2014-04-17 18:53:11 Running from C:\Users\XXXXX\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 32 Bit HP CIO Components Installer (Version: 6.1.1 - Hewlett-Packard) Hidden 4500_G510nz_Help (Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz (Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz_Software_Min (Version: 000.0.423.000 - Hewlett-Packard) Hidden Adobe Acrobat 4.0 (HKLM\...\Adobe Acrobat 4.0) (Version: - ) Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\{0099B484-C24C-4D5F-8167-B0F6DF196E72}) (Version: 12.0.3.133 - Adobe Systems, Inc) Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.) Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.0.84.0 - Autodesk) Autodesk Content Service (Version: 3.0.84.0 - Autodesk) Hidden Autodesk Content Service Language Pack (Version: 3.0.84.0 - Autodesk) Hidden Autodesk Inventor Fusion plug-in for AutoCAD 2013 (HKLM\...\Autodesk Inventor Fusion plug-in for AutoCAD 2013) (Version: 0.2.0.230 - Autodesk) Autodesk Inventor Fusion plug-in for AutoCAD 2013 (Version: 0.2.0.230 - Autodesk) Hidden Autodesk Inventor Fusion Plugin Language Pack for AutoCAD 2013 (Version: 0.2.0.230 - Autodesk) Hidden Avira SearchFree Toolbar plus Web Protection Updater (HKCU\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.3.0.23930 - Ask.com) <==== ATTENTION AVM FRITZ!Box Dokumentation (HKLM\...\AVMFBox) (Version: - AVM Berlin) AVM FRITZ!Box Druckeranschluss (HKLM\...\AVMFBoxPrinter) (Version: - AVM Berlin) Bing Bar (HKLM\...\{B4089055-D468-45A4-A6BA-5A138DD715FC}) (Version: 7.0.850.0 - Microsoft Corporation) Bing Maps 3D (HKLM\...\{2D87E961-577B-492B-AD54-1368680FB9A7}) (Version: 4.0.903.16005 - Microsoft Corporation) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.21 - Piriform) Command & Conquer 3 (HKLM\...\{DDEDAF6C-488E-4CDA-8276-1CCF5F3C5C32}) (Version: 1.00.0000 - Ihr Firmenname) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) CyberLink PhotoNow (HKLM\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.6904 - CyberLink Corp.) CyberLink PhotoNow (Version: 1.1.6904 - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3213 - CyberLink Corp.) CyberLink Power2Go (Version: 6.1.3213 - CyberLink Corp.) Hidden CyberLink PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.2221 - CyberLink Corp.) CyberLink PowerDirector (Version: 8.0.2221 - CyberLink Corp.) Hidden CyberLink PowerDVD 9 (HKLM\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.2010 - CyberLink Corp.) CyberLink PowerDVD 9 (Version: 9.0.2010 - CyberLink Corp.) Hidden CyberLink PowerDVD Copy (HKLM\...\{E3D04529-6EDB-11D8-A372-0050BAE317E1}) (Version: 1.0.6720 - CyberLink Corp.) CyberLink PowerProducer (HKLM\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0.2.2130 - CyberLink Corp.) CyberLink PowerProducer (Version: 5.0.2.2130 - CyberLink Corp.) Hidden CyberLink YouCam (HKLM\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2423 - CyberLink Corp.) CyberLink YouCam (Version: 3.0.2423 - CyberLink Corp.) Hidden CyberLink YouMemo (HKLM\...\InstallShield_{5176C4D8-E6C1-422A-8D6F-E13EB996DCEA}) (Version: 1.0.3706 - CyberLink Corp.) CyberLink YouMemo (Version: 1.0.3706 - CyberLink Corp.) Hidden CyberLink YouPaint (HKLM\...\InstallShield_{72BF1DA0-2B00-4794-9173-159722019B74}) (Version: 1.2.1223a - CyberLink Corp.) CyberLink YouPaint (Version: 1.2.1223a - CyberLink Corp.) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5971CA1F-6BDE-498F-952C-9F2BF94070A4}) (Version: - Microsoft) Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (Version: 130.0.372.000 - Hewlett-Packard) Hidden DocMgr (Version: 130.0.000.000 - Ihr Firmenname) Hidden DocProc (Version: 13.0.0.0 - Hewlett-Packard) Hidden EXSL-Win Version X (HKLM\...\{BDA0DBBA-BBDD-11D5-9901-005004491D37}) (Version: Xxx - ) FARO LS 1.1.406.58 (HKLM\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production) Fax (Version: 130.0.418.000 - Hewlett-Packard) Hidden GameSpy Arcade (HKLM\...\GameSpy Arcade) (Version: - ) HiCAD 2013 DE (HKLM\...\{9FFC8F2E-9AA2-451F-85F8-ED71A899215A}) (Version: 18.2.0.258 - ISD Software und Systeme) HP Document Manager 2.0 (HKLM\...\HP Document Manager) (Version: 2.0 - HP) HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP) HP Officejet 4500 G510n-z (HKLM\...\{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}) (Version: 13.0 - HP) HP Officejet 4620 series - Grundlegende Software für das Gerät (HKLM\...\{717130C7-FEA7-4D63-AEE3-00EF2F41ACDD}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Officejet 4620 series Hilfe (HKLM\...\{72EDA2AC-2908-4BB3-97E5-4F9DDEBF9731}) (Version: 6.0.0 - Hewlett Packard) HP Update (HKLM\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) I.R.I.S. OCR (HKLM\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) Interaktive Sprachreise - English Intensivkurs (HKLM\...\ISREIK_15_676830) (Version: - digital publishing AG) Internet-TV für Windows Media Center (HKLM\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 4.2.2.0 - Microsoft Corporation) Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) MEDION Fotos auf CD & DVD SE Sued (HKLM\...\MEDION Fotos auf CD & DVD SE Sued D) (Version: 8.0.3.4 - MAGIX AG) Medion Home Cinema (HKLM\...\InstallShield_{AB770FDE-8087-4C98-9A85-BD64262C104C}) (Version: 6.0.0000 - CyberLink Corp.) Medion Home Cinema (Version: 6.0.0000 - CyberLink Corp.) Hidden Medion Touch Center (HKLM\...\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 7.0.3707 - CyberLink Corp.) Medion Touch Center (Version: 7.0.3707 - CyberLink Corp.) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.4 (HKLM\...\{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}) (Version: 2.0.3008.0 - Microsoft Corporation) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint Viewer 2007 (German) (HKLM\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Suite Activation Assistant (HKLM\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (HKLM\...\{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Touch Pack for Windows 7 (HKLM\...\{8FF90DB8-6DED-44A3-B182-244FEC09012F}) (Version: 1.0.40517.00 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{09298F26-A95C-31E2-9D95-2C60F586F075}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.40303 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (Version: 10.0.40308 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU (Version: 10.0.40303 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.40303 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.0 (HKLM\...\{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}) (Version: 3.0.11010.0 - Microsoft Corporation) Mozilla Firefox 28.0 (x86 de) (HKLM\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Network (Version: 130.0.374.000 - Hewlett-Packard) Hidden Norton Identity Safe (HKLM\...\NST) (Version: 2014.7.0.43 - Symantec Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.9 - NVIDIA Corporation) NVIDIA Grafiktreiber 327.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.02 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA PhysX (Version: 9.12.1031 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation) NVIDIA Systemsteuerung 327.02 (Version: 327.02 - NVIDIA Corporation) Hidden NVIDIA Update 1.14.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.14.17 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.14.17 - NVIDIA Corporation) Hidden OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP) OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0 - Microsoft Corporation) Hidden Panda USB Vaccine 1.0.1.4 (HKLM\...\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1) (Version: - Panda Security) PANZERS - Phase2 (HKLM\...\PANZERS - Phase2) (Version: - ) PlayReady PC Runtime x86 (HKLM\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation) PlayStation(R)Store (HKLM\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.18.0.15698 - Sony Computer Entertainment Inc.) PowerCinema Movie (Version: 9.0.6106 - CyberLink Corp.) Hidden PunkBuster Services (HKLM\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5978 - Realtek Semiconductor Corp.) Sandboxie 4.04 (32-bit) (HKLM\...\Sandboxie) (Version: 4.04 - Sandboxie Holdings, LLC) Scan (Version: 13.0.0.0 - Hewlett-Packard) Hidden Secunia PSI (3.0.0.7009) (HKLM\...\Secunia PSI) (Version: 3.0.0.7009 - Secunia) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version: - Microsoft) Hidden Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.3.11079 - Skype Technologies S.A.) Skype™ 6.14 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Sony Ericsson Update Engine (HKLM\...\Update Engine) (Version: 2.13.10.201308300830 - Sony Ericsson Communications AB) Sony PC Companion 2.10.188 (HKLM\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.188 - Sony) Spelling Dictionaries Support For Adobe Reader 9 (HKLM\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated) Status (Version: 130.0.373.000 - Hewlett-Packard) Hidden Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden The Elder Scrolls V: Skyrim (HKLM\...\Steam App 72850) (Version: - Bethesda Game Studios) TNCguide (HKLM\...\TNCguide) (Version: - ) Toolbox (Version: 130.0.648.000 - Hewlett-Packard) Hidden Tor 0.2.3.25 (HKLM\...\Tor) (Version: - ) TrayApp (Version: 130.0.376.000 - Hewlett-Packard) Hidden Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{799005D3-9B70-4219-AFE0-BC479614CC4D}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft) Vidalia 0.2.21 (HKLM\...\Vidalia) (Version: - ) VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN) WebReg (Version: 130.0.132.017 - Hewlett-Packard) Hidden Windows Live Call (Version: 14.0.8064.0206 - Microsoft Corporation) Hidden Windows Live Communications Platform (Version: 14.0.8064.206 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live Essentials (Version: 14.0.8089.726 - Microsoft Corporation) Hidden Windows Live Fotogalerie (Version: 14.0.8081.709 - Microsoft Corporation) Hidden Windows Live ID-Anmelde-Assistent (HKLM\...\{10A44844-4465-456E-8C97-80BDD4F68845}) (Version: 6.500.3146.0 - Microsoft Corporation) Windows Live Mail (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live Messenger (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live Movie Maker (Version: 14.0.8091.0730 - Microsoft Corporation) Hidden Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation) Windows Live Writer (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) ==================== Restore Points ========================= 24-03-2014 18:36:02 Konfiguriert Command and Conquer(TM) Generäle Die Stunde Null 24-03-2014 18:37:06 Konfiguriert Command & Conquer(TM) Generäle 26-03-2014 17:10:11 Installed Command & Conquer 3. 31-03-2014 18:16:02 Windows Update 31-03-2014 18:22:07 Windows Update 31-03-2014 18:46:11 avast! antivirus system restore point 31-03-2014 18:57:48 Windows Update 07-04-2014 16:00:48 Avira PC Cleaner - 07.04.2014 18:00 09-04-2014 11:51:32 Windows Update 17-04-2014 11:05:36 Windows Update 17-04-2014 11:10:18 avast! antivirus system restore point ==================== Hosts content: ========================== 2009-07-14 04:04 - 2013-06-15 11:18 - 00449637 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {06803A4B-4AA7-4349-B7FF-06C6473400C4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-07-24] (Piriform Ltd) Task: {07162CF6-31BD-4A37-9444-2B7EE56D2B28} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-11] (Adobe Systems Incorporated) Task: {0885CBB0-159B-4B95-98DC-26005D82DF20} - System32\Tasks\Norton Identity Safe\Norton Error Analyzer => C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {0F0419FB-ACA0-4759-9360-10EACF4F30DC} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated) Task: {A0C759F8-8E1B-4825-A013-B4154157F6E6} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: {AB51C5F0-393D-4FEE-B2E4-106873637CD4} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {EADBC2B3-E5EB-4649-AAC0-159A592B6F8C} - System32\Tasks\PandaUSBVaccine => C:\Program Files\Panda USB Vaccine\RunInteractiveWin.exe [2009-09-23] () Task: {FBD1075B-208F-4C9E-905F-ECB7D62884AC} - System32\Tasks\Norton Identity Safe\Norton Error Processor => C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\SymErr.exe [2014-01-30] (Symantec Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2012-10-26 17:56 - 2013-08-30 01:08 - 00088864 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2012-10-26 16:44 - 2012-11-27 19:47 - 00066872 ____N () C:\Windows\system32\PnkBstrA.exe 2010-02-04 11:04 - 2009-07-27 16:49 - 00244904 ____N () C:\Program Files\CyberLink\Shared files\RichVideo.exe 2009-06-03 21:59 - 2009-06-03 21:59 - 00619816 ____N () C:\Program Files\CyberLink\Power2Go\CLMediaLibrary.dll 2009-06-03 21:59 - 2009-06-03 21:59 - 00013096 ____N () C:\Program Files\CyberLink\Power2Go\CLMLSvcPS.dll 2014-03-30 18:53 - 2014-03-15 10:40 - 03642480 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk => C:\Windows\pss\Secunia PSI Tray.lnk.CommonStartup MSCONFIG\startupreg: ADSK DLMSession => C:\Program Files\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe MSCONFIG\startupreg: ApnUpdater => "C:\Program Files\Ask.com\Updater\Updater.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: Autodesk Sync => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe MSCONFIG\startupreg: ccleaner => "C:\Program Files\CCleaner\CCleaner.exe" /AUTO MSCONFIG\startupreg: EADM => "C:\Program Files\Origin\Origin.exe" -AutoStart MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: SandboxieControl => "C:\Program Files\Sandboxie\SbieCtrl.exe" MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Sony PC Companion => "C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe" /Background MSCONFIG\startupreg: Steam => "C:\Program Files\Steam\Steam.exe" -silent ==================== Faulty Device Manager Devices ============= Name: Realtek PCIe GBE Family Controller Description: Realtek PCIe GBE Family Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Realtek Service: RTL8167 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (04/17/2014 06:48:21 PM) (Source: MsiInstaller) (User: XXXXX-PC) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\XXXX\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können. Error: (04/17/2014 06:47:37 PM) (Source: MsiInstaller) (User: XXXXX-PC) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\XXX\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können. Error: (04/17/2014 04:20:13 PM) (Source: MsiInstaller) (User: XXXX-PC) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error: (04/17/2014 04:19:19 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error: (04/17/2014 04:19:16 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error: (04/17/2014 04:19:14 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error: (04/17/2014 04:19:11 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error: (04/17/2014 04:19:09 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error: (04/17/2014 04:19:06 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. Error: (04/17/2014 04:19:04 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'. System errors: ============= Error: (04/17/2014 06:46:52 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (04/17/2014 04:18:08 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: sfdrv01 sfsync02 Error: (04/17/2014 04:17:19 PM) (Source: Application Popup) (User: ) Description: Treiber sfdrv01.sys konnte nicht geladen werden. Error: (04/17/2014 04:17:19 PM) (Source: Application Popup) (User: ) Description: Treiber sfsync02.sys konnte nicht geladen werden. Error: (04/17/2014 01:26:43 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: sfdrv01 sfsync02 Error: (04/17/2014 01:25:24 PM) (Source: Application Popup) (User: ) Description: Treiber sfdrv01.sys konnte nicht geladen werden. Error: (04/17/2014 01:25:24 PM) (Source: Application Popup) (User: ) Description: Treiber sfsync02.sys konnte nicht geladen werden. Error: (04/17/2014 00:52:03 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: sfdrv01 sfsync02 Error: (04/17/2014 00:51:22 PM) (Source: Application Popup) (User: ) Description: Treiber sfdrv01.sys konnte nicht geladen werden. Error: (04/17/2014 00:51:22 PM) (Source: Application Popup) (User: ) Description: Treiber sfsync02.sys konnte nicht geladen werden. Microsoft Office Sessions: ========================= Error: (04/17/2014 06:48:21 PM) (Source: MsiInstaller)(User: XXXX-PC) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\XXXX\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/17/2014 06:47:37 PM) (Source: MsiInstaller)(User: XXXX-PC) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\XXXXX\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/17/2014 04:20:13 PM) (Source: MsiInstaller)(User: XXXXX-PC) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/17/2014 04:19:19 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/17/2014 04:19:16 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/17/2014 04:19:14 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/17/2014 04:19:11 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/17/2014 04:19:09 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/17/2014 04:19:06 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/17/2014 04:19:04 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Status -- Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'.(NULL)(NULL)(NULL)(NULL)(NULL) ==================== Memory info =========================== Percentage of memory in use: 36% Total physical RAM: 3327.24 MB Available physical RAM: 2105.06 MB Total Pagefile: 6652.77 MB Available Pagefile: 4937.14 MB Total Virtual: 2047.88 MB Available Virtual: 1898.64 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:910.41 GB) (Free:805.03 GB) NTFS Drive d: (Recover) (Fixed) (Total:20 GB) (Free:10.38 GB) NTFS Drive e: (CPP2) (CDROM) (Total:2.9 GB) (Free:0 GB) CDFS Drive i: () (Removable) (Total:3.77 GB) (Free:3.18 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 2BD2C32A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=910 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=20 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ======================================================== Disk: 1 (Size: 4 GB) (Disk ID: 04DD5721) Partition 1: (Active) - (Size=4 GB) - (Type=06) ==================== End Of Log ============================ Geändert von Wolf9 (17.04.2014 um 18:28 Uhr) |
18.04.2014, 16:22 | #4 |
/// the machine /// TB-Ausbilder | Computerspiel lässt sich nicht deinstallieren Revo Uninstaller - Download - Filepony damit deinstallieren.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.04.2014, 19:18 | #5 |
| Computerspiel lässt sich nicht deinstallieren Hey vielen Dank, vor allem das des so schnell ging. Gruß Wolf9 |
19.04.2014, 12:19 | #6 |
/// the machine /// TB-Ausbilder | Computerspiel lässt sich nicht deinstallieren Gern Geschehen
__________________ --> Computerspiel lässt sich nicht deinstallieren |
Themen zu Computerspiel lässt sich nicht deinstallieren |
arten, beim starten, bild, blöd, computerspiel, deinstalliere, deinstallieren, folge, folgendes, geladen, heute, hinweis, installation, komisches, kopierschutz, laufen, neu, norten, patch, phase, runter, schutz, starte, starten, system |