|
Log-Analyse und Auswertung: Externe Festplatte befallen, Daten verstecktWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
25.07.2015, 16:35 | #1 |
| Externe Festplatte befallen, Daten versteckt Hallo Leute, Ich bin neu hier im Board und fand die Beiträge die ich mir ab und zu durchgelesen habe sehr hilfreich, weswegen ich mich nun auch mit einem Probem an euch wende. Ich habe mich heute mal der Externen Festplatte einer Bekannten angenommen, die sich in Australien dort wohl einen Virus draufgespielt hatte. Sämtliche Dateien waren nicht mehr in ihren Ordnern, die Festplatte an sich war aber nicht leer. Als "Reparatur" hat sie sich einfach alle versteckten Datein auf der Festplatte anzeigen lassen, aber nichts desto trotz würde ich euch bitten, einmal rüber zu schauen und zu überprüfen ob die Festplatte gefahrlos für andere Leute zu benutzen ist. Ich bin dem Standartprotokoll gefolgt und habe hier die Logfiles von: Defogger: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 16:47 on 25/07/2015 (Otti) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... Unable to read sptd.sys SPTD -> Disabled (Service running -> reboot required) -=E.O.F=- Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x86) Version: 25-07-2015 durchgeführt von Otti (Administrator) auf OTTI-PC (25-07-2015 16:56:00) Gestartet von C:\Users\Otti\Downloads Geladene Profile: Otti (Verfügbare Profile: Otti) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Sprache: Deutsch (Deutschland) Internet Explorer Version 8 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avguard.exe (ASUSTeK Computer Inc.) C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe (DeviceVM, Inc.) C:\ASUS.SYS\config\DVMExportService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\System32\PnkBstrA.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\DAODx.exe (ASUSTeK Computer Inc.) C:\Program Files\ASUS\TurboV EVO\TurboVHelp.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avwebg7.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (NEC Electronics Corporation) C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avgnt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe ==================== Registry (Nicht auf der Ausnahmeliste) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [1780224 2010-03-15] (VIA) HKLM\...\Run: [TurboV EVO] => C:\Program Files\ASUS\TurboV EVO\TurboV_EVO.exe [9919104 2010-04-07] (ASUSTeK Computer Inc.) HKLM\...\Run: [Six Engine] => C:\Program Files\ASUS\EPU\EPU.exe [5309056 2010-03-16] ( ASUSTeK Computer Inc.) HKLM\...\Run: [NUSB3MON] => C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2010-01-22] (NEC Electronics Corporation) HKLM\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe [43632 2010-01-19] () HKLM\...\Run: [tsnp2uvc] => C:\Program Files\Common Files\SNP2UVC\tsnp2uvc.exe [321024 2011-07-20] (Sonix Technology Co., Ltd.) HKLM\...\Run: [Nvtmru] => "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-03] (NVIDIA Corporation) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\Antivirus\avgnt.exe [730416 2015-06-19] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.Systray.exe [134368 2015-06-02] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [217632 2015-07-07] (Geek Software GmbH) HKU\S-1-5-21-3534099020-634075679-966876233-1000\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [2895552 2015-07-24] (Valve Corporation) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..) HKU\S-1-5-21-3534099020-634075679-966876233-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.ask.com/?l=dis&o=APN10375&gct=hp&apn_ptnrs=^AHP&apn_dtid=^YYYYYY^YY^DE&p2=^AHP^YYYYYY^YY^DE&tpid=SGT-SAT&apn_dbr=ff_16.0&apn_uid=4B8FE4C5-97CF-4033-A601-BCBD1EFFAD61&itbv=11.3.0.661&doi=2012-12-03 HKU\S-1-5-21-3534099020-634075679-966876233-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-05-27] (Oracle Corporation) BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-10-02] (Skype Technologies S.A.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-27] (Oracle Corporation) Toolbar: HKU\S-1-5-21-3534099020-634075679-966876233-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - Keine Datei Toolbar: HKU\S-1-5-21-3534099020-634075679-966876233-1000 -> No Name - {5347542D-5341-5400-76A7-7A786E7484D7} - Keine Datei Toolbar: HKU\S-1-5-21-3534099020-634075679-966876233-1000 -> No Name - {41564952-412D-5637-00A7-7A786E7484D7} - Keine Datei Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-10-02] (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{C17DD923-E015-4AAE-9D11-5ADE08521ABA}: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Otti\AppData\Roaming\Mozilla\Firefox\Profiles\vd5nyfxp.default-1371114904938 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] () FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files\Battlelog Web Plugins\2.6.2\npbattlelog.dll [2015-01-13] (EA Digital Illusions CE AB) FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-27] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-27] (Oracle Corporation) FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-05-28] (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-05-28] (NVIDIA Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3534099020-634075679-966876233-1000: ubisoft.com/uplaypc -> C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-06-11] () FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.) FF Extension: Adblock Plus Pop-up Addon - C:\Users\Otti\AppData\Roaming\Mozilla\Firefox\Profiles\vd5nyfxp.default-1371114904938\Extensions\adblockpopups@jessehakanen.net.xpi [2013-06-16] FF Extension: ExHentai Easy 2 - C:\Users\Otti\AppData\Roaming\Mozilla\Firefox\Profiles\vd5nyfxp.default-1371114904938\Extensions\jid1-7NbXi2AqS1oUFw@jetpack.xpi [2014-08-23] FF Extension: Adblock Plus - C:\Users\Otti\AppData\Roaming\Mozilla\Firefox\Profiles\vd5nyfxp.default-1371114904938\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-16] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-07-04] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2015-07-04] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-07-04] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2015-07-04] FF HKLM\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff [2013-01-13] Chrome: ======= CHR Profile: C:\Users\Otti\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\Otti\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-12] CHR Extension: (YouTube) - C:\Users\Otti\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-12] CHR Extension: (Google Search) - C:\Users\Otti\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-12] CHR Extension: (Gmail) - C:\Users\Otti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-12] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx ==================== Dienste (All) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AntiVirMailService; C:\Program Files\Avira\Antivirus\avmailc7.exe [827184 2015-06-19] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\Antivirus\sched.exe [450808 2015-06-19] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\Antivirus\avguard.exe [450808 2015-06-19] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\Antivirus\avwebg7.exe [1188360 2015-06-19] (Avira Operations GmbH & Co. KG) S4 AODService; C:\Program Files\AMD\OverDrive\AODAssist.exe [136544 2009-10-22] () R2 AsSysCtrlService; C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [96896 2009-12-28] (ASUSTeK Computer Inc.) R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [217280 2015-06-02] (Avira Operations GmbH & Co. KG) R2 DvmMDES; C:\ASUS.SYS\config\DVMExportService.exe [319488 2009-10-16] (DeviceVM, Inc.) [Datei ist nicht signiert] R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [919184 2015-06-03] (NVIDIA Corporation) S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1893008 2015-06-03] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20694160 2015-06-03] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1997168 2015-06-06] (Electronic Arts) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-07-11] () S4 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ==================== Drivers (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [11296 2009-08-04] () R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2013-08-03] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-06-19] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-06-19] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-20] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-24] (Avira Operations GmbH & Co. KG) S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [99952 2010-01-11] (JMicron Technology Corp.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2013-08-03] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [13216 2009-07-16] () R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18576 2015-06-03] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [41648 2015-05-19] (NVIDIA Corporation) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [3564800 2011-07-22] () S4 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2011-09-21] (Duplex Secure Ltd.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-06-19] (Avira Operations GmbH & Co. KG) R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1127936 2010-03-02] (VIA Technologies, Inc.) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-07-25 16:56 - 2015-07-25 16:56 - 00015117 _____ C:\Users\Otti\Downloads\FRST.txt 2015-07-25 16:55 - 2015-07-25 16:56 - 00000000 ____D C:\FRST 2015-07-25 16:55 - 2015-07-25 16:55 - 00000000 ____D C:\Users\Otti\Downloads\FRST-OlderVersion 2015-07-25 16:47 - 2015-07-25 16:48 - 00000020 _____ C:\Users\Otti\defogger_reenable 2015-07-25 14:45 - 2015-07-25 16:49 - 00000842 _____ C:\Windows\PFRO.log 2015-07-25 11:46 - 2015-07-25 16:55 - 01650688 _____ (Farbar) C:\Users\Otti\Downloads\FRST.exe 2015-07-25 11:46 - 2015-07-25 11:46 - 00380416 _____ C:\Users\Otti\Downloads\Gmer-19357.exe 2015-07-25 11:44 - 2015-07-25 11:44 - 00050477 _____ C:\Users\Otti\Downloads\Defogger.exe 2015-07-14 22:22 - 2015-07-14 22:22 - 01187008 _____ (Adobe Systems Incorporated) C:\Users\Otti\Downloads\flashplayer18_ha_install(2).exe 2015-07-13 11:56 - 2015-07-13 11:56 - 00000891 _____ C:\Users\Public\Desktop\Gothic III CP.lnk 2015-07-13 11:50 - 2015-07-13 11:50 - 30254306 _____ (Gothic 3 CPT / Spellbound ) C:\Users\Otti\Downloads\Gothic_3_Community_Patch_v1.6_Incremental.exe 2015-07-12 16:43 - 2015-07-25 09:00 - 00000000 ____D C:\Users\Otti\Documents\gothic3 2015-07-11 16:11 - 2015-07-11 16:11 - 01187520 _____ (Adobe Systems Incorporated) C:\Users\Otti\Downloads\flashplayer18_ha_install(1).exe 2015-07-09 02:52 - 2015-07-09 02:52 - 00001819 _____ C:\Users\Public\Desktop\PDF24 Creator.lnk 2015-07-09 02:52 - 2015-07-09 02:52 - 00001799 _____ C:\Users\Public\Desktop\PDF24 Fax.lnk 2015-07-09 02:52 - 2015-07-09 02:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24 2015-07-09 02:52 - 2015-07-09 02:52 - 00000000 ____D C:\Program Files\PDF24 2015-07-09 02:46 - 2015-07-09 02:47 - 16381928 _____ (Geek Software GmbH ) C:\Users\Otti\Downloads\pdf24-creator-7.0.4.exe 2015-07-07 14:14 - 2015-07-07 14:14 - 08209285 _____ C:\Users\Otti\Downloads\Gothic2_130_de.exe 2015-07-07 12:31 - 2015-07-07 12:31 - 00009764 _____ C:\Users\Otti\Downloads\qLKGniPOExtrahieren Ordner.rar 2015-07-07 08:52 - 2015-07-25 16:51 - 00063168 _____ C:\Windows\setupact.log 2015-07-07 08:52 - 2015-07-07 08:52 - 00000000 _____ C:\Windows\setuperr.log 2015-07-04 13:17 - 2015-07-05 19:38 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-07-04 00:20 - 2015-07-04 00:20 - 00000000 ____D C:\Users\Otti\AppData\Local\CEF 2015-07-01 23:42 - 2015-07-14 22:23 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-07-01 23:42 - 2015-07-14 22:23 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-07-01 23:37 - 2015-07-01 23:37 - 01125056 _____ (Adobe Systems Incorporated) C:\Users\Otti\Downloads\flashplayer18_ha_install.exe ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-07-25 16:54 - 2011-09-21 18:43 - 00000000 ____D C:\Program Files\Steam 2015-07-25 16:53 - 2015-04-08 19:33 - 00000000 ____D C:\Users\Otti\Desktop\txt. und so 2015-07-25 16:53 - 2011-09-21 17:32 - 01891306 _____ C:\Windows\WindowsUpdate.log 2015-07-25 16:50 - 2012-12-12 22:18 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-25 16:49 - 2011-09-21 17:39 - 00000000 ____D C:\ProgramData\NVIDIA 2015-07-25 16:49 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-25 16:48 - 2009-07-14 06:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-25 16:48 - 2009-07-14 06:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-25 16:47 - 2011-09-21 17:32 - 00000000 ____D C:\Users\Otti 2015-07-25 16:21 - 2012-12-12 22:18 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-25 15:34 - 2011-12-21 13:43 - 00000452 _____ C:\Windows\Tasks\Norton Internet Security - Otti - Vollständiger Systemscan.job 2015-07-25 14:56 - 2011-09-21 17:57 - 00000177 ____H C:\dvmexp.idx 2015-07-25 14:45 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system 2015-07-25 14:29 - 2012-12-03 13:37 - 00000000 ____D C:\ProgramData\APN 2015-07-25 11:51 - 2011-09-21 17:35 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI 2015-07-25 11:49 - 2014-10-29 22:17 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-07-25 11:42 - 2014-10-29 22:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-07-25 11:42 - 2014-10-29 22:17 - 00000000 ____D C:\Program Files\ Malwarebytes Anti-Malware 2015-07-25 11:42 - 2012-03-22 16:46 - 00001060 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-07-25 08:58 - 2011-09-21 18:06 - 00000000 ____D C:\Users\Otti\AppData\Local\CrashDumps 2015-07-25 01:23 - 2011-12-08 20:03 - 00000000 ____D C:\Users\Otti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2015-07-24 19:22 - 2011-09-21 18:43 - 00000000 ____D C:\Program Files\Common Files\Steam 2015-07-14 22:24 - 2011-09-21 20:56 - 00000000 ____D C:\Users\Otti\AppData\Local\Adobe 2015-07-12 16:42 - 2011-12-17 00:43 - 00000000 ____D C:\Users\Otti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2015-07-09 02:48 - 2011-09-21 21:03 - 00000000 ____D C:\Users\Otti\AppData\Roaming\Adobe 2015-07-06 13:08 - 2015-06-11 19:25 - 00001078 _____ C:\Users\Public\Desktop\Avira.lnk 2015-07-06 13:08 - 2015-05-04 20:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-07-06 13:08 - 2013-08-05 16:49 - 00000000 ____D C:\Program Files\Avira 2015-07-06 13:07 - 2015-05-04 20:28 - 00000000 ____D C:\ProgramData\Package Cache 2015-07-05 19:38 - 2012-05-04 02:47 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-07-03 13:48 - 2015-06-15 12:11 - 00000000 ____D C:\Users\Otti\AppData\Local\Game Dev Tycoon - Steam ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2014-06-05 18:08 - 2014-06-19 21:44 - 0000096 _____ () C:\Users\Otti\AppData\Roaming\LauncherSettings_live.cfg 2014-06-03 19:00 - 2015-05-28 15:36 - 0138056 _____ () C:\Users\Otti\AppData\Roaming\PnkBstrK.sys 2014-10-20 20:19 - 2015-03-22 18:49 - 0001395 _____ () C:\Users\Otti\AppData\Roaming\SpeedRunnersLog.txt 2014-06-05 18:11 - 2014-06-05 18:11 - 0000039 _____ () C:\Users\Otti\AppData\Roaming\TheHunterSettings_steam_live.cfg 2015-06-16 00:03 - 2015-06-16 00:03 - 0007607 _____ () C:\Users\Otti\AppData\Local\Resmon.ResmonCfg Einige Dateien in TEMP: ==================== C:\Users\Otti\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-07-23 02:46 ==================== Ende vom log ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x86) Version: 25-07-2015 durchgeführt von Otti an 2015-07-25 16:56:38 Gestartet von C:\Users\Otti\Downloads Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3534099020-634075679-966876233-500 - Administrator - Disabled) Gast (S-1-5-21-3534099020-634075679-966876233-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3534099020-634075679-966876233-1002 - Limited - Enabled) Otti (S-1-5-21-3534099020-634075679-966876233-1000 - Administrator - Enabled) => C:\Users\Otti ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.0.42.34 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) AdVenture Capitalist (HKLM\...\Steam App 346900) (Version: - Hyper Hippo Productions Ltd.) Age of Empires II: HD Edition (HKLM\...\Steam App 221380) (Version: - Hidden Path Entertainment, Ensemble Studios) AMD OverDrive (HKLM\...\{EA18DE8E-B3E6-4D82-A086-9BE2316FA5A5}) (Version: 3.1.0.0342 - Advanced Micro Devices, Inc.) Amnesia: The Dark Descent (HKLM\...\Steam App 57300) (Version: - Frictional Games) ANNO 1404 (HKLM\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.01.0000 - Ubisoft) Anno 1404 (Version: 1.00.0000 - Ubisoft) Hidden Assassin's Creed II (HKLM\...\Steam App 33230) (Version: - Ubisoft Montreal) Assassin's Creed IV Black Flag (HKLM\...\Steam App 242050) (Version: - Ubisoft Montreal) ATI Catalyst Install Manager (HKLM\...\{30EEC7C1-DE2F-2B49-41B1-8B90E05E6815}) (Version: 3.0.762.0 - ATI Technologies, Inc.) Audiosurf (HKLM\...\Steam App 12900) (Version: - Dylan Fitterer) Avira (HKLM\...\{8467e01f-0496-42ce-b247-88ef205b4880}) (Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG) Hidden Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.11.579 - Avira Operations GmbH & Co. KG) Battle.net (HKLM\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 1942™ (HKLM\...\{5BE7BD06-512B-43bf-AD78-3BD2A5F5F7B3}) (Version: 1.6.20.0 - Electronic Arts) Battlefield 3™ (HKLM\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlelog Web Plugins (HKLM\...\Battlelog Web Plugins) (Version: 2.6.2 - EA Digital Illusions CE AB) BioShock (HKU\S-1-5-21-3534099020-634075679-966876233-1000\...\{E280923D-C5D9-4728-8C79-AC9A0DC75875}) (Version: 2.62.0000 - 2K Games) BioShock 2 (HKLM\...\{4A8B461A-9336-4CF9-98F4-14DD38E673F0}) (Version: 1.00.0000 - 2K Games) BioShock Infinite (HKLM\...\BioShock Infinite_is1) (Version: - ) Borderlands (HKLM\...\Steam App 8980) (Version: - Gearbox Software) CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform) Crusader Kings II (HKLM\...\Steam App 203770) (Version: - Paradox Development Studio) Dead Space™ (HKLM\...\{4D87DC92-C328-46EC-A7B4-9C88129DC696}) (Version: 1.0.222.0 - Electronic Arts) Diablo III (HKLM\...\Diablo III) (Version: - Blizzard Entertainment) Die Sims™ 3 (HKLM\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.21.123 - Electronic Arts) Die Sims™ 3 Gib Gas-Accessoires (HKLM\...\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts) Die Sims™ 3 Late Night (HKLM\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts) Die Sims™ 3 Lebensfreude (HKLM\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts) Die Sims™ 3 Luxus-Accessoires (HKLM\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts) Die Sims™ 3 Reiseabenteuer (HKLM\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts) Die Sims™ 3 Traumkarrieren (HKLM\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts) Dota 2 (HKLM\...\Steam App 570) (Version: - ) Dota 2 Test (HKLM\...\Steam App 205790) (Version: - ) Dungeon Defenders Demo (HKLM\...\Steam App 201680) (Version: - ) EPU (HKLM\...\{9C2AC00C-0C06-4B7E-97A4-A833808D54D6}) (Version: 1.02.20 - ) Express Gate (HKLM\...\{99AD9D6D-A456-49EE-8360-F22EE7AA1272}) (Version: 1.5.17.9 - DeviceVM, Inc.) Fallout 3 (HKU\S-1-5-21-3534099020-634075679-966876233-1000\...\{974C4B12-4D02-4879-85E0-61C95CC63E9E}) (Version: 1.00.0000 - Bethesda Softworks) Fallout: New Vegas (HKLM\...\Steam App 22380) (Version: - Bethesda Softworks) Far Cry® 3 (HKLM\...\Steam App 220240) (Version: - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai) FEAR (HKLM\...\{2B653229-9854-4989-B780-D978F5F13EAB}) (Version: 1.00.0000 - Vivendi Universal Games, Inc.) FlatOut (HKLM\...\Steam App 6220) (Version: - Bugbear Entertainment) Free YouTube Download version 3.1.42.1212 (HKLM\...\Free YouTube Download_is1) (Version: 3.1.42.1212 - DVDVideoSoft Ltd.) Game Dev Tycoon (HKLM\...\Steam App 239820) (Version: - Greenheart Games) Geneious 8.0.4 (HKLM\...\4435-7533-6274-7601) (Version: 8.0.4 - Biomatters Ltd) Google Chrome (HKLM\...\Google Chrome) (Version: 44.0.2403.89 - Google Inc.) Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden Gothic 3 (HKLM\...\Steam App 39500) (Version: - Piranha – Bytes) Gothic_Patch (HKLM\...\{302AC480-43D2-11D5-A818-00500435FC18}) (Version: - ) Grand Theft Auto IV (HKLM\...\Steam App 12210) (Version: - Rockstar North) Grand Theft Auto: Episodes from Liberty City (HKLM\...\Steam App 12220) (Version: - Rockstar North / Toronto) Guitar Hero III (HKLM\...\{0CE1A6C0-F3F7-49E6-8F9D-2431F9827441}) (Version: 1.31 - Activision) Heroes of Might & Magic V: Tribes of the East (HKLM\...\Steam App 15370) (Version: - Nival) Heroes of Newerth (HKLM\...\hon) (Version: 1.0.20 - S2 Games) Heroes of the Storm (HKLM\...\Heroes of the Storm) (Version: - Blizzard Entertainment) Hitman 2: Silent Assassin (HKLM\...\Steam App 6850) (Version: - Eidos) Hitman: Blood Money (HKLM\...\Steam App 6860) (Version: - Eidos) ICQ7.2 (HKLM\...\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}) (Version: 7.2 - ICQ) IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.38 - Irfan Skiljan) Java 8 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) JMicron JMB36X Driver (HKLM\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.00.0000 - JMicron Technology Corp.) Just Cause 2 (HKLM\...\Steam App 8190) (Version: - Avalanche) League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (Version: 3.0.1 - Riot Games ) Hidden Left 4 Dead 2 (HKLM\...\Steam App 550) (Version: - Valve) Lethal League (HKLM\...\Steam App 261180) (Version: - Team Reptile) Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation) measure (HKLM\...\{5FC40A17-BC1D-4F59-A511-B308A669DBAA}) (Version: 4.6.11.1 - Phywe Systeme GmbH) Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 RC (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50861 - Microsoft Corporation) Microsoft Games for Windows - LIVE (HKLM\...\{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}) (Version: 3.1.186.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}) (Version: 3.1.99.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Mirror's Edge (HKLM\...\Steam App 17410) (Version: - DICE) Monaco (HKLM\...\Steam App 113020) (Version: - Pocketwatch Games) Mozilla Firefox 39.0 (x86 de) (HKLM\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) NEC Electronics USB 3.0 Host Controller Driver (HKLM\...\InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}) (Version: 1.0.19.0 - NEC Electronics Corporation) NEC Electronics USB 3.0 Host Controller Driver (Version: 1.0.19.0 - NEC Electronics Corporation) Hidden NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.06 - NVIDIA Corporation) NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5856 - NVIDIA Corporation) NVIDIA GeForce Experience 2.4.5.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.44 - NVIDIA Corporation) NVIDIA Grafiktreiber 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.06 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) OpenOffice.org 3.3 (HKLM\...\{4286716B-1287-48E7-9078-3DC8248DBA96}) (Version: 3.3.9567 - OpenOffice.org) Origin (HKLM\...\Origin) (Version: 9.1.15.109 - Electronic Arts, Inc.) PAYDAY 2 (HKLM\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.) PC Probe II (HKLM\...\{F7338FA3-DAB5-49B2-900D-0AFB5760C166}) (Version: 1.04.87 - ASUSTeK Computer Inc.) PDF24 Creator 7.0.4 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Platform (Version: 1.34 - VIA Technologies, Inc.) Hidden Port Royale 2 (HKLM\...\Steam App 12470) (Version: - Ascaron Entertainment ltd.) Prince of Persia (HKLM\...\{7C11154F-3539-4CB5-979D-EF7913473E53}) (Version: 1.0 - Ubisoft) PunkBuster Services (HKLM\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.) Realtek Ethernet Controller Driver For Windows 7 (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.15.209.2010 - Realtek) Roogoo (HKLM\...\Steam App 38210) (Version: - Spidermonk Entertainment) SEGA Genesis & Mega Drive Classics (HKLM\...\Steam App 34270) (Version: - Sega) SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.5.44 - NVIDIA Corporation) Hidden Sim City 4 Deluxe (HKLM\...\{90EEF48B-EAAF-44DC-B2F6-6FB97D7DAC4E}) (Version: 1.0.0 - Doctor Strange) SimCity™ Societies (HKLM\...\{0B5154C0-8F00-4616-B0AB-6240AE80D9CE}) (Version: 1.0.0.0 - Electronic Arts) Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.3.11079 - Skype Technologies S.A.) Skype™ 6.20 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.) South Park - The Stick of Truth Version 1.0.1353 (HKLM\...\{83736891-79AE-49BA-96F5-55DD6F2186AC}_is1) (Version: 1.0.1353 - Ubisoft) SPEEDLINK CASE (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.54200.103 - Sonix) SpeedRunners (HKLM\...\Steam App 207140) (Version: - DoubleDutch Games) StarCraft II (HKLM\...\StarCraft II) (Version: - Blizzard Entertainment) Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Super Amazing Wagon Adventure (HKLM\...\Steam App 250500) (Version: - sparsevector) TeamSpeak 3 Client (HKU\S-1-5-21-3534099020-634075679-966876233-1000\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Terraria (HKLM\...\Steam App 105600) (Version: - Re-Logic) The Elder Scrolls V: Skyrim (HKLM\...\Steam App 72850) (Version: - Bethesda Game Studios) The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version: - CD Projekt RED) TrackMania Nations Forever (HKLM\...\Steam App 11020) (Version: - Nadeo) TrackMania² Stadium Open Beta (HKLM\...\Steam App 233070) (Version: - Nadeo) Trine 2 (HKLM\...\Steam App 35720) (Version: - Frozenbyte) Tropico 3 - Steam Special Edition (HKLM\...\Steam App 23490) (Version: - Haemimont Games) TurboV EVO (HKLM\...\{491D92A9-69CA-4EB4-81D3-0106F9337957}) (Version: 1.02.20 - ) Ubisoft Game Launcher (HKLM\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Unturned (HKLM\...\Steam App 304930) (Version: - Nelson Sexton) Uplay (HKLM\...\Uplay) (Version: 4.4 - Ubisoft) VIA Plattform-Geräte-Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.) VirtualDJ Home FREE (HKLM\...\{5E1375CB-6792-4464-8715-CC3EC83D48FA}) (Version: 7.0.5 - Atomix Productions) VLC media player 1.1.9 (HKLM\...\VLC media player) (Version: 1.1.9 - VideoLAN) WinRAR 4.01 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) YTD Video Downloader 3.9.6 (HKLM\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 3.9.6 - GreenTree Applications SRL) <==== ATTENTION ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{1c492e6a-2803-5ed7-83e1-1b1d4d41eb39}\InprocServer32 -> C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{30A2652A-DDF7-45e7-ACA6-3EAB26FC8A4E}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{41662FC2-0D57-4aff-AB27-AD2E12E7C273}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{448BB771-CFE2-47C4-BCDF-1FBF378E202C}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{7B342DC4-139A-4a46-8A93-DB0827CCEE9C}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\ooofilt.dll (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{7FA8AE11-B3E3-4D88-AABF-255526CD1CE8}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{82154420-0FBF-11d4-8313-005004526AB4}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{D0484DE6-AAEE-468a-991F-8D4B0737B57A}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{D2D59CD1-0A6A-4D36-AE20-47817077D57C}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{E5A0B632-DFBA-4549-9346-E414DA06E6F8}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{EE5D1EA4-D445-4289-B2FC-55FC93693917}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) CustomCLSID: HKU\S-1-5-21-3534099020-634075679-966876233-1000_Classes\CLSID\{F616B81F-7BB8-4F22-B8A5-47428D59F8AD}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) ==================== Wiederherstellungspunkte ========================= 12-07-2015 16:40:11 DirectX wurde installiert 13-07-2015 11:54:57 Microsoft Visual C++ 2005 Redistributable wird installiert 23-07-2015 02:55:40 Geplanter Prüfpunkt ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {212395F8-BF05-48CB-8DD8-CC09589DF3C0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-12] (Google Inc.) Task: {260E6265-B5D2-43E2-A1CB-25C1AD7B3936} - System32\Tasks\{F9DDD321-AAE5-4267-A62E-46046C1DA01D} => H:\C&C G\generals.exe [2003-02-09] () Task: {31855B55-CA9B-460D-8772-021CB6D58D96} - System32\Tasks\{C17E8858-867F-44F9-8E08-BE03850DF90A} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=5.3.0.111.259&LastError=404 Task: {390D5489-300C-463B-B86B-2979C85004AF} - System32\Tasks\Norton Internet Security - Otti - Vollständiger Systemscan => C:\Program Files\Norton Internet Security\Engine\17.9.0.12\navw32.exe Task: {69A655CC-26B7-494E-B630-A69355641EBF} - System32\Tasks\ASUS\ASUS RegRun Loader => C:\Program Files\ASUS\AASP\1.01.02\AsLoader.exe [2009-12-28] (ASUSTeK Computer Inc.) Task: {88EEE1FF-1FE5-48D8-8148-1FAB946D6C1E} - System32\Tasks\ASUS\RunDAOD => C:\Windows\DAODx.exe [2009-03-30] () Task: {93648F48-097D-47CE-AF18-E7E347D1BA99} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: {9804ABC1-EFEE-4444-9248-BEF74E812770} - System32\Tasks\{D75400F9-CEF5-4B9A-8A35-583C9357DFC0} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=5.3.0.111.259&LastError=12007 Task: {98415088-2D91-412A-8F50-86C0F8C528FF} - System32\Tasks\{56861F2F-779A-4A46-B206-DBEA0CDCC14C} => pcalua.exe -a C:\Users\Otti\Downloads\Diablo-III-8370-deDE-Installer-downloader.exe -d "C:\Program Files\Mozilla Firefox" Task: {A97CA397-B93D-43D0-A171-0DE73D9B93EA} - System32\Tasks\{D2B8A2BB-6D39-4FDF-9DBB-257E057C55F3} => D:\SteamLibrary\SteamApps\common\PAYDAY 2\payday2_win32_release.exe [2015-07-17] () Task: {E41C18AC-9250-42F9-B625-11ED57641030} - System32\Tasks\ASUS\TurboVHelp => C:\Program Files\ASUS\TurboV EVO\TurboVHELP.exe [2010-04-02] (ASUSTeK Computer Inc.) Task: {F2905056-495B-4773-9D29-FB4B97C3643B} - System32\Tasks\{FEAFA12A-00FB-49E0-AB06-AB93FE578D57} => pcalua.exe -a F:\DIRECTX\dxsetup.exe -d F:\DIRECTX Task: {FE5205E8-7F93-4A10-924B-0184E8104307} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-12] (Google Inc.) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Norton Internet Security - Otti - Vollständiger Systemscan.job => C:\Program Files\Norton Internet Security\Engine\17.9.0.12\navw32.exe ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2012-03-20 22:58 - 2015-05-28 05:50 - 00106128 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2014-06-03 19:00 - 2014-07-11 11:06 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe 2009-03-30 08:32 - 2009-03-30 08:32 - 00032768 ____R () C:\Windows\DAODx.exe 2011-09-21 19:09 - 2009-09-30 05:33 - 00024576 ____R () C:\Windows\system32\AsIO.dll 2011-09-21 19:09 - 2010-02-08 17:19 - 00053248 _____ () C:\Program Files\ASUS\TurboV EVO\HookKey32.dll 2011-09-21 19:09 - 2008-12-10 20:04 - 00253952 _____ () C:\Program Files\ASUS\TurboV EVO\pngio.dll 2015-06-19 12:30 - 2015-06-03 23:06 - 00011920 _____ () C:\Program Files\NVIDIA Corporation\Update Core\detoured.dll 2012-01-12 19:39 - 2011-05-28 23:04 - 00140288 _____ () C:\Program Files\WinRAR\rarext.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. The "AlternateShell" value will be restored.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer trusted/restricted =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3534099020-634075679-966876233-1000\Control Panel\Desktop\\Wallpaper -> DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\Services: APNMCP => 2 MSCONFIG\Services: Skype C2C Service => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: ApnTBMon => "C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: EKIJ5000StatusMonitor => C:\Windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: snp2uvc => C:\Windows\vsnp2uvc.exe ==================== FirewallRules (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{E568A85F-3488-4295-AD5C-F3814D61B0FA}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{A9E0534C-D39E-4807-901F-FEDB6025091F}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{573A2CBA-DDA1-4D07-9AE4-8274B26F0A43}] => (Allow) D:\World of Warcraft\Launcher.exe FirewallRules: [{A341FD75-CA47-42A3-A435-4030FCEA6F30}] => (Allow) D:\World of Warcraft\Launcher.exe FirewallRules: [{9DAE4A5D-0818-4BA5-B355-43398E62720C}] => (Allow) D:\World of Warcraft\Launcher.patch.exe FirewallRules: [{4DCA2361-29A6-4B99-8745-6219236D5C96}] => (Allow) D:\World of Warcraft\Launcher.patch.exe FirewallRules: [{467A5113-CCD2-4111-947D-3D1F8E483ADB}] => (Allow) C:\Program Files\ICQ7.2\ICQ.exe FirewallRules: [{93840C42-9FF7-4B9F-9E19-E9BF631E1F6E}] => (Allow) C:\Program Files\ICQ7.2\ICQ.exe FirewallRules: [{DAAF1158-F8FF-4956-B07A-B6C83575AAFA}] => (Allow) C:\Program Files\ICQ7.2\ICQ.exe FirewallRules: [{AFA5CA22-0E17-4923-B5BE-235315446348}] => (Allow) C:\Program Files\ICQ7.2\ICQ.exe FirewallRules: [{D4DEDCCF-19F5-4192-8BDA-505C7D9DD83B}] => (Allow) C:\Program Files\ICQ7.2\aolload.exe FirewallRules: [{C029ECB3-445A-4D5E-99C0-176570E472B1}] => (Allow) C:\Program Files\ICQ7.2\aolload.exe FirewallRules: [{B666F467-9BC4-442F-97E0-4006B9DD1793}] => (Allow) E:\WoW Test\World of Warcraft Public Test\Launcher.exe FirewallRules: [{8E64879A-AAAD-48B9-8E61-0DD806E4C57D}] => (Allow) E:\WoW Test\World of Warcraft Public Test\Launcher.exe FirewallRules: [{0C42C1C6-0E4C-4241-8878-A34D1E6D809C}] => (Allow) E:\WoW Test\World of Warcraft Public Test\Launcher.patch.exe FirewallRules: [{6C7AD351-0845-4F47-8AEA-55F62B919BF9}] => (Allow) E:\WoW Test\World of Warcraft Public Test\Launcher.patch.exe FirewallRules: [{03D4C544-BBF1-487E-BA25-0A60BE018614}] => (Allow) E:\World of Warcraft\Launcher.exe FirewallRules: [{279FFE3F-4B7C-42AD-8F3A-32CC6F43B152}] => (Allow) E:\World of Warcraft\Launcher.exe FirewallRules: [{A6FB244B-F89A-4EA4-868B-F1EF7F1A9B3C}] => (Allow) E:\World of Warcraft\Launcher.patch.exe FirewallRules: [{FEB4BC64-D50C-496A-A224-167513946BCF}] => (Allow) E:\World of Warcraft\Launcher.patch.exe FirewallRules: [{52CDAF9D-044F-4859-A917-322F87BC3599}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{96586C3E-15CC-4980-87E7-D1B8CAAA03A7}E:\warcraft iii\war3.exe] => (Allow) E:\warcraft iii\war3.exe FirewallRules: [UDP Query User{DCA09D93-DD03-43C1-AB7D-1CB5E147E855}E:\warcraft iii\war3.exe] => (Allow) E:\warcraft iii\war3.exe FirewallRules: [TCP Query User{1F7797DB-BD7B-4E47-AC82-34E291AED0A7}E:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe FirewallRules: [UDP Query User{636CD2BC-7259-42A0-B2CC-D285CFBB4B07}E:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2706-enus-tools-downloader.exe FirewallRules: [{D70989FC-7720-4569-A26B-3CA3D490A0E2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.515\Agent.exe FirewallRules: [{E4BED6F8-78B1-4792-A325-EEFAA690F53F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.515\Agent.exe FirewallRules: [{C4C007F1-E78D-4B10-BC07-585A00768CB6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.516\Agent.exe FirewallRules: [{A0D3BFBC-0453-4AA2-AD12-311105D783C0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.516\Agent.exe FirewallRules: [{D6CD1D59-ED4E-4474-9D87-A21357D70DF5}] => (Allow) C:\Program Files\Diablo III Beta\Diablo III.exe FirewallRules: [{E66780C7-C155-4CEB-B8E3-D6A356088FE8}] => (Allow) C:\Program Files\Diablo III Beta\Diablo III.exe FirewallRules: [{76B3B89E-08B5-4840-B208-8E4230EC0498}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.649\Agent.exe FirewallRules: [{A17AFCD0-C9B1-47B1-8638-BC90446B51D3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.649\Agent.exe FirewallRules: [{2272C476-2915-4E3E-80F3-B1F24014B150}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{EAAB0B20-5C10-4E34-98AB-65764C0594BC}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [TCP Query User{05F0CA97-12C9-4A60-AC40-86D4C94CCBDA}C:\programdata\battle.net\agent\agent.649\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.649\agent.exe FirewallRules: [UDP Query User{65BD2E2B-B2C3-4792-9D74-98488376C42D}C:\programdata\battle.net\agent\agent.649\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.649\agent.exe FirewallRules: [TCP Query User{FF81B32F-D392-47E3-BC0F-3D8030FF090E}C:\program files\diablo iii beta\diablo iii.exe] => (Allow) C:\program files\diablo iii beta\diablo iii.exe FirewallRules: [UDP Query User{D801B325-89B4-418C-9C30-0EF3A3AA4A05}C:\program files\diablo iii beta\diablo iii.exe] => (Allow) C:\program files\diablo iii beta\diablo iii.exe FirewallRules: [{A8C1D08D-08F6-461B-A68E-D3F81DD2B0C5}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman 2 Silent Assassin\hitman2.exe FirewallRules: [{3A06FA7E-AEBF-47E9-A4C0-D94A7B0923F1}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman 2 Silent Assassin\hitman2.exe FirewallRules: [{A490D29C-331B-4728-9683-61457735592C}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman 2 Silent Assassin\config.exe FirewallRules: [{92EC4CEE-6AA8-4AA8-8879-1BE0C5B993F9}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman 2 Silent Assassin\config.exe FirewallRules: [{0D2FCEC1-6A15-44C3-9B8C-6444E5E9FF45}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman Blood Money\HitmanBloodMoney.exe FirewallRules: [{1883B0E8-EF14-4FC1-9C9E-1819E0D38C82}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman Blood Money\HitmanBloodMoney.exe FirewallRules: [{0CE86750-7537-4D03-AB33-406D1D3B1BD3}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman Blood Money\configure.exe FirewallRules: [{C48C6730-224A-46E5-86F0-E7CF2F9B13D8}] => (Allow) C:\Program Files\Steam\SteamApps\common\Hitman Blood Money\configure.exe FirewallRules: [TCP Query User{1764764C-FD19-4C15-B299-D971E3B148E7}E:\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe FirewallRules: [UDP Query User{ED3D5300-D335-43BC-93A5-18461F2934F2}E:\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe FirewallRules: [TCP Query User{E9AD4D43-9545-453D-B639-F1E6DBDBF547}C:\programdata\battle.net\agent\agent.749\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.749\agent.exe FirewallRules: [UDP Query User{0F878FC7-073B-4856-AF45-6B671FAE64FF}C:\programdata\battle.net\agent\agent.749\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.749\agent.exe FirewallRules: [TCP Query User{A164D4CD-B1DE-4CF0-BBD0-FF8DD47F49F3}E:\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe FirewallRules: [UDP Query User{B3FEA817-DF86-4037-A347-60B98C067355}E:\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe FirewallRules: [{8E60F03B-866C-4994-92CE-4D032ADBCA0A}] => (Allow) C:\Program Files\Steam\SteamApps\common\dungeon defenders demo\Binaries\Win32\DungeonDefenders.exe FirewallRules: [{49F95687-4AFB-4BA0-AF52-851F92C8A763}] => (Allow) C:\Program Files\Steam\SteamApps\common\dungeon defenders demo\Binaries\Win32\DungeonDefenders.exe FirewallRules: [TCP Query User{BB0A4E42-766C-480E-A123-2F6EBFB096BA}E:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe FirewallRules: [UDP Query User{335A9644-8FFA-47ED-847F-6165B104F5CC}E:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe] => (Allow) E:\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe FirewallRules: [TCP Query User{F82639CF-EF49-4A3E-B09C-0B2352E173D9}C:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe] => (Allow) C:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe FirewallRules: [UDP Query User{C0F3DBA2-129D-401D-A4DA-25DC8972F4B4}C:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe] => (Allow) C:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe FirewallRules: [TCP Query User{3704E7FE-25F0-4611-B641-48713D4AD6AB}C:\programdata\battle.net\agent\agent.868\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.868\agent.exe FirewallRules: [UDP Query User{C27B6CD4-5BF0-4C83-9109-BEA2778BEE9C}C:\programdata\battle.net\agent\agent.868\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.868\agent.exe FirewallRules: [TCP Query User{C03462CD-672A-4291-817F-095DC4E694FC}C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader.exe] => (Allow) C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader.exe FirewallRules: [UDP Query User{16992B69-EF89-432D-B0E2-913946A143BB}C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader.exe] => (Allow) C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader.exe FirewallRules: [{0E05B281-A4B3-4DBC-BA94-C4AB44B086B8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.913\Agent.exe FirewallRules: [{D43E50CF-3391-4873-A870-57346655AB02}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.913\Agent.exe FirewallRules: [TCP Query User{E999B39F-F3D3-40DA-8B35-9907B9EAA645}C:\programdata\battle.net\agent\agent.954\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.954\agent.exe FirewallRules: [UDP Query User{36342DE5-2EF6-4367-A5C4-250E53F5A050}C:\programdata\battle.net\agent\agent.954\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.954\agent.exe FirewallRules: [{79A44702-3AFE-47C1-AAE7-DB79D8BA6F13}] => (Allow) D:\2K Games\Bioshock 2\SP\Builds\Binaries\Bioshock2.exe FirewallRules: [{508E877F-B18A-455D-B2B9-7BFF9AEEC227}] => (Allow) D:\2K Games\Bioshock 2\SP\Builds\Binaries\Bioshock2.exe FirewallRules: [{C03D883F-0C85-4035-A789-282E3EBC172E}] => (Allow) D:\2K Games\Bioshock 2\MP\Builds\Binaries\Bioshock2.exe FirewallRules: [{731B2187-EABA-4E95-B12D-E51A402C21F6}] => (Allow) D:\2K Games\Bioshock 2\MP\Builds\Binaries\Bioshock2.exe FirewallRules: [TCP Query User{A83941C7-82E1-42FD-B999-6D08E9553220}C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader(1).exe] => (Allow) C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader(1).exe FirewallRules: [UDP Query User{94411FCA-8831-4979-B9E9-94EB776D3844}C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader(1).exe] => (Allow) C:\users\otti\downloads\diablo-iii-8370-dede-installer-downloader(1).exe FirewallRules: [{6243AD7F-F734-4A3B-A3E9-3BA345B07843}] => (Allow) D:\Diablo III\Diablo III.exe FirewallRules: [{527B18BD-C8CC-4AA3-853B-37007B844515}] => (Allow) D:\Diablo III\Diablo III.exe FirewallRules: [TCP Query User{F1BDAD3D-27C3-4B5F-AB6D-EFCB475CF6E4}C:\programdata\battle.net\agent\agent.976\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.976\agent.exe FirewallRules: [UDP Query User{F1874D76-E126-4088-A6F4-B4626133C55F}C:\programdata\battle.net\agent\agent.976\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.976\agent.exe FirewallRules: [TCP Query User{0EEA1371-F366-4848-B7D6-57E57C7B4EBB}C:\programdata\battle.net\agent\agent.998\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.998\agent.exe FirewallRules: [UDP Query User{47FB1774-5A72-4E0D-B267-5817CC27D0DA}C:\programdata\battle.net\agent\agent.998\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.998\agent.exe FirewallRules: [TCP Query User{DF358BBB-C9A9-4F76-BED6-43B18766A637}C:\programdata\battle.net\agent\agent.1040\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.1040\agent.exe FirewallRules: [UDP Query User{1693B1ED-D012-4CA2-9F5A-1917E5DFA10E}C:\programdata\battle.net\agent\agent.1040\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.1040\agent.exe FirewallRules: [{880138E1-65F8-4FF2-B812-1FF88A3C7C92}] => (Allow) C:\Program Files\Steam\SteamApps\common\borderlands\Binaries\Borderlands.exe FirewallRules: [{8F9AFAB6-B2A8-4EE1-AB3F-EC21CE55B2BB}] => (Allow) C:\Program Files\Steam\SteamApps\common\borderlands\Binaries\Borderlands.exe FirewallRules: [TCP Query User{46267F84-A1C1-461F-8682-36DBC8C7FEDE}D:\guitar hero iii\gh3.exe] => (Block) D:\guitar hero iii\gh3.exe FirewallRules: [UDP Query User{25BF16CE-4EEF-4F91-95DC-7F9DD2342ACD}D:\guitar hero iii\gh3.exe] => (Block) D:\guitar hero iii\gh3.exe FirewallRules: [{272884C9-FF1B-4D06-8627-B9E9B04B92A2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe FirewallRules: [{EFB1F124-0471-4972-8A86-A9078CC11594}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe FirewallRules: [{B221F76D-14DF-4742-AC3E-94CAC52A0784}] => (Allow) C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{22F4F794-D602-494D-AF25-9047DD00AC1C}] => (Allow) C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{0425783C-CB3F-455D-9687-B0D1CE0117C7}] => (Allow) D:\Assassin's Creed II\AssassinsCreedIIGame.exe FirewallRules: [{6541CD77-D363-4223-B349-1B6AB7D218B1}] => (Allow) D:\Assassin's Creed II\AssassinsCreedIIGame.exe FirewallRules: [{58DEC5C5-C756-409C-A113-26625DB5924A}] => (Allow) D:\Assassin's Creed II\AssassinsCreedII.exe FirewallRules: [{97BE214F-9FD7-4AEA-8273-5AA4B2F49CDE}] => (Allow) D:\Assassin's Creed II\AssassinsCreedII.exe FirewallRules: [{E95B16E5-6E54-404B-864A-C3D5E82F39E5}] => (Allow) D:\Assassin's Creed II\UPlayBrowser.exe FirewallRules: [{4B06FC8A-A5B9-416B-AB70-1100FA0C2C9D}] => (Allow) D:\Assassin's Creed II\UPlayBrowser.exe FirewallRules: [TCP Query User{2D5E9B56-FD7C-4D71-871D-8A95716D419C}E:\warcraft iii\war3.exe] => (Block) E:\warcraft iii\war3.exe FirewallRules: [UDP Query User{8BC5115D-3876-4C78-8E0A-8B062F7F5479}E:\warcraft iii\war3.exe] => (Block) E:\warcraft iii\war3.exe FirewallRules: [{AF4E9EF3-B3E0-475A-ADCC-4934F2365851}] => (Allow) D:\Prince of Persia\Prince of Persia.exe FirewallRules: [{9ADB38DE-162D-4AA3-8421-6ED153EBDEF2}] => (Allow) D:\Prince of Persia\Prince of Persia.exe FirewallRules: [{C313EF7B-3312-4C73-B45C-4F215E2DDFE6}] => (Allow) D:\Prince of Persia\PrinceOfPersia_Launcher.exe FirewallRules: [{1BBE6291-4B67-4428-A6B2-EF25FA036FC5}] => (Allow) D:\Prince of Persia\PrinceOfPersia_Launcher.exe FirewallRules: [TCP Query User{3957A71D-F374-42A4-82EC-F54E31162431}D:\electronic arts\deadspace\deadspace.exe] => (Block) D:\electronic arts\deadspace\deadspace.exe FirewallRules: [UDP Query User{28C11678-3FE6-44F2-BAC9-906C81604573}D:\electronic arts\deadspace\deadspace.exe] => (Block) D:\electronic arts\deadspace\deadspace.exe FirewallRules: [TCP Query User{76D2DD88-F48C-4E28-9A59-AFD6BC4D957B}D:\electronic arts\deadspace\dead space.exe] => (Block) D:\electronic arts\deadspace\dead space.exe FirewallRules: [UDP Query User{D1C93ADB-6154-4E1D-A17C-0012DFC4254D}D:\electronic arts\deadspace\dead space.exe] => (Block) D:\electronic arts\deadspace\dead space.exe FirewallRules: [{35933EE3-F9AD-4334-A439-47B6D49479D5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe FirewallRules: [{645483AD-43D2-44BD-8F03-20835B494638}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe FirewallRules: [{325A6244-9B92-46E4-B9AC-D6116E907431}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe FirewallRules: [{BC059A93-A380-453A-BD21-B7A58003BF11}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe FirewallRules: [{F52BE773-E851-4196-AD7C-B7E444AA7EEB}] => (Allow) C:\Program Files\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe FirewallRules: [{BA3C7D9F-F7C8-4E32-B0BA-3428A756C7DD}] => (Allow) C:\Program Files\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe FirewallRules: [TCP Query User{34D6E995-FB14-4058-A1D0-345E8701F719}C:\program files\java\jre6\bin\java.exe] => (Allow) C:\program files\java\jre6\bin\java.exe FirewallRules: [UDP Query User{37EE1F71-B728-4F17-BAF2-452B7F870A33}C:\program files\java\jre6\bin\java.exe] => (Allow) C:\program files\java\jre6\bin\java.exe FirewallRules: [TCP Query User{15133073-817B-4729-94B9-7AAE23406460}C:\program files\java\jre6\bin\javaw.exe] => (Allow) C:\program files\java\jre6\bin\javaw.exe FirewallRules: [UDP Query User{752A253E-DE53-4B24-AADA-8345C76BA07F}C:\program files\java\jre6\bin\javaw.exe] => (Allow) C:\program files\java\jre6\bin\javaw.exe FirewallRules: [TCP Query User{3714A085-66AD-4E71-BF6E-71AA78545D4D}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{C27B4C30-292D-46E9-A90B-0BDED30AC2A9}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [{31A67AF3-9FEB-4E65-BFFE-780B618AAE61}] => (Allow) C:\Program Files\Origin Games\Battlefield 1942\BF1942.exe FirewallRules: [{7694C910-321C-4770-A206-C26D65AE2430}] => (Allow) C:\Program Files\Origin Games\Battlefield 1942\BF1942.exe FirewallRules: [{2141C595-3A0D-42C8-9482-AFA254FE720B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe FirewallRules: [{4493DC5D-D4D9-4602-91AF-D9CB92489154}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe FirewallRules: [TCP Query User{8D2693C9-53C3-4BA4-9375-A88E0977113B}D:\heroes of newerth\hon.exe] => (Block) D:\heroes of newerth\hon.exe FirewallRules: [UDP Query User{87AABD27-E609-4ECE-BEAA-518C7428EB9E}D:\heroes of newerth\hon.exe] => (Block) D:\heroes of newerth\hon.exe FirewallRules: [{99634AC9-3115-4F1D-9914-B51BC762E627}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{80C7397A-6FF9-4068-B14F-326F7DB4E677}] => (Allow) C:\Program Files\Steam\SteamApps\common\ManiaPlanet_TMStadium\ManiaPlanetLauncher.exe FirewallRules: [{A1CD4298-0885-4A77-B540-8089DCE76B0C}] => (Allow) C:\Program Files\Steam\SteamApps\common\ManiaPlanet_TMStadium\ManiaPlanetLauncher.exe FirewallRules: [{C51CE07B-0494-4A6A-A89A-79D98A3CF732}] => (Allow) C:\Program Files\Steam\SteamApps\common\ManiaPlanet_TMStadium\ManiaPlanet.exe FirewallRules: [{C9AD272B-4A78-4E58-A4B6-6A39936C0BB1}] => (Allow) C:\Program Files\Steam\SteamApps\common\ManiaPlanet_TMStadium\ManiaPlanet.exe FirewallRules: [{A95E232C-B319-4BA0-9C65-1BED433C1622}] => (Allow) C:\Program Files\Steam\SteamApps\common\TrackMania Nations Forever\TmForever.exe FirewallRules: [{F3209092-4D43-49CF-AF98-81F3FE8667DB}] => (Allow) C:\Program Files\Steam\SteamApps\common\TrackMania Nations Forever\TmForever.exe FirewallRules: [{F4D9DF15-8DAA-4384-A9F6-CE9A828C6C56}] => (Allow) C:\Program Files\Steam\SteamApps\common\TrackMania Nations Forever\TmForeverLauncher.exe FirewallRules: [{2D6C2AC8-4F23-41D6-B5B2-1F6EADF26422}] => (Allow) C:\Program Files\Steam\SteamApps\common\TrackMania Nations Forever\TmForeverLauncher.exe FirewallRules: [{2E3A52B2-9761-4263-8CA3-6F563ECBFF07}] => (Allow) D:\F.E.A.R\FEAR.exe FirewallRules: [{656AEB94-F935-43A4-A4E3-122EC7132AE4}] => (Allow) D:\F.E.A.R\FEAR.exe FirewallRules: [{676ADBF2-1798-4815-9B7A-49FB3CE901C8}] => (Allow) D:\F.E.A.R\FEARMP.exe FirewallRules: [{8BAB504C-4E98-4A56-A928-3828454483B1}] => (Allow) D:\F.E.A.R\FEARMP.exe FirewallRules: [TCP Query User{E7AF5D4F-EF15-4A40-A03E-3443AF39AA9A}D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe FirewallRules: [UDP Query User{5C6519CA-8BB6-4337-B94E-7F8FF6A379C6}D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe FirewallRules: [TCP Query User{E5A8D9E6-2A8A-4DC6-B98E-C2D98076786A}D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Block) D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe FirewallRules: [UDP Query User{43A26C19-0EE3-40AD-A046-29CD1BACA4B2}D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Block) D:\steamlibrary\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe FirewallRules: [TCP Query User{2FF589EC-9F9B-44EC-9715-75E83491C73D}D:\magic 2014 — duels of the planeswalkers\dotp_d14.exe] => (Block) D:\magic 2014 — duels of the planeswalkers\dotp_d14.exe FirewallRules: [UDP Query User{B78212E9-3466-4B51-B568-F39DD06EEAE5}D:\magic 2014 — duels of the planeswalkers\dotp_d14.exe] => (Block) D:\magic 2014 — duels of the planeswalkers\dotp_d14.exe FirewallRules: [{ADE60596-8BDF-443E-AC4B-8B4ED51290E3}] => (Allow) C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{0002D1DF-8D83-401F-8915-F378E9DB6864}] => (Allow) C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [TCP Query User{D8A390AD-4E3A-4332-9AFA-83AA3A78E957}D:\anno 1404\tools\anno4web.exe] => (Block) D:\anno 1404\tools\anno4web.exe FirewallRules: [UDP Query User{EC343EE4-3123-4FC2-A343-B35F5E1D2862}D:\anno 1404\tools\anno4web.exe] => (Block) D:\anno 1404\tools\anno4web.exe FirewallRules: [TCP Query User{1DB9693B-C1BF-4603-98DA-05B61DF94278}E:\magic 2014 — duels of the planeswalkers\dotp_d14.exe] => (Block) E:\magic 2014 — duels of the planeswalkers\dotp_d14.exe FirewallRules: [UDP Query User{EFEC7492-6516-412A-93B7-7086CF135772}E:\magic 2014 — duels of the planeswalkers\dotp_d14.exe] => (Block) E:\magic 2014 — duels of the planeswalkers\dotp_d14.exe FirewallRules: [TCP Query User{479A26BB-6461-498D-94A3-D0361FE5032D}D:\dead island\deadislandgame_x86_rwdi.exe] => (Block) D:\dead island\deadislandgame_x86_rwdi.exe FirewallRules: [UDP Query User{A23471E0-459A-472F-8BE2-F62199E28B32}D:\dead island\deadislandgame_x86_rwdi.exe] => (Block) D:\dead island\deadislandgame_x86_rwdi.exe FirewallRules: [{F9C77335-EA3F-4A95-996E-FCF0C6D65114}] => (Allow) C:\Program Files\Steam\SteamApps\common\Marvel Heroes\UnrealEngine3\Binaries\Win32\MarvelGame.exe FirewallRules: [{00C66733-C1CF-4075-B11D-FAB7D2EBC2A5}] => (Allow) C:\Program Files\Steam\SteamApps\common\Marvel Heroes\UnrealEngine3\Binaries\Win32\MarvelGame.exe FirewallRules: [TCP Query User{54566374-E743-460B-B0CD-AE04F8580DDD}D:\anno 1404\tools\anno4web.exe] => (Block) D:\anno 1404\tools\anno4web.exe FirewallRules: [UDP Query User{8EB29137-663B-4786-99A0-7F87EFEC6F39}D:\anno 1404\tools\anno4web.exe] => (Block) D:\anno 1404\tools\anno4web.exe FirewallRules: [{6ED7DA77-7316-40D0-98E1-23F6A7D76E45}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{F74AF459-9A7D-4916-B29D-68D60D479973}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{6A7003E2-F5BD-4C6E-97CB-4BB597FCF57C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{B8623E96-5E41-455D-9BA3-FECA9C84F24A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [TCP Query User{03D54A90-E92D-4874-B66F-C00BC1F02DEC}D:\steamlibrary\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe] => (Block) D:\steamlibrary\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe FirewallRules: [UDP Query User{E94D12D0-334B-4DB9-844C-CF9EF14555CC}D:\steamlibrary\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe] => (Block) D:\steamlibrary\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe FirewallRules: [TCP Query User{2EA24E4C-060D-4E7E-AED0-C010241D8658}C:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe] => (Block) C:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe FirewallRules: [UDP Query User{BA7EE73D-26E4-4222-B24F-6531175CC604}C:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe] => (Block) C:\program files\steam\steamapps\common\trackmania nations forever\tmforever.exe FirewallRules: [{E7C36135-BB2D-430B-A799-5CCB7B502170}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{6D42EDEF-A367-4083-9CAF-4AE03FE79D27}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{7F7C8B25-BAC4-457E-960D-E6D784CECBE9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{F43A1D6E-3E8A-4344-8005-9617EA62A696}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{64B2EAD2-F488-447A-B17F-9751C1A3BC02}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{8300EB33-51CC-4E18-830B-E54FF15E32AA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{8EB3947B-0581-43E1-B85D-161DD0361F25}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{D8DB85C6-E2AB-4A3E-99A5-A0FEC926F3BD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{2526CDAC-79F6-43C5-B444-0201B7760886}] => (Allow) D:\SteamLibrary\SteamApps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{2B74999D-72A7-48B1-B017-1B4A0C907CF7}] => (Allow) D:\SteamLibrary\SteamApps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{D97A092E-7E32-48BF-A899-8C1CF2211A4E}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{A9318A99-42EF-4BCF-9F67-E5578DF5E66D}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{E830A068-1AED-44C6-9CCD-5147B4985FCD}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{0B40C744-0F8A-4070-84B2-01EA4B761D88}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{0CCC8685-6953-4D7C-88CF-0228E715D581}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{6ECD6B26-F0EA-4902-8D5B-6418A2988466}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{424CFC3F-541B-40B8-B3BA-533F8141A0EF}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{4DA40D0E-5DB9-423D-9DBB-8AE84BBFC74B}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{C1E2AC4E-68CF-441F-BDC8-2096423AF90F}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{06F4D475-06BB-4F37-B510-0D10C112ACCD}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{82A1CC89-879B-419E-A0BB-CAB5B4F2E3F1}] => (Allow) C:\Windows\System32\PnkBstrA.exe FirewallRules: [{A639A706-06D1-4995-AF32-0819A7B8EA39}] => (Allow) C:\Windows\System32\PnkBstrA.exe FirewallRules: [{81CF0714-56EF-4029-9BBE-4AF2568997C8}] => (Allow) C:\Windows\System32\PnkBstrB.exe FirewallRules: [{45BF4069-9800-4429-9AC2-1D33A6C53B73}] => (Allow) C:\Windows\System32\PnkBstrB.exe FirewallRules: [{427BD3D2-36BD-42F6-8B0E-02F8D25EFD94}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{9F4D8942-34B1-4BF5-B25B-284C7C946315}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{FF31A829-99CB-46D3-B745-2EE89F9AC1C7}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{B67AA204-A108-43B6-8CA9-5BB4D041E18D}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{B9FDFC38-182C-421E-8C50-D706EDC2B143}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{2A12023F-72B2-42C9-AE6D-F7234F2D7F03}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{B5727E9B-59A1-40F8-B58E-150491FB1B77}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{7F858E23-BE14-464E-8943-74B886D4EB87}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{011DB4AA-14F7-401D-899C-DBE0E97985B0}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{3F84FDB6-88B9-4F90-BECB-B25B4017FD17}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{554933FE-3FBB-4DC7-8569-E77624DD64D1}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{6039FDD4-4F1A-4559-8891-110F635F5753}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 test\dota.exe FirewallRules: [{15F9F389-8A75-40D6-8857-7E0F5C809ABA}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{54CF5F3A-00CA-49BE-8D9B-4DA5F39F10DF}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{40D2E168-3BAE-4AA2-81CF-D82A55B9F36A}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{B1BF2F1B-DF6F-4BB0-A0B1-DAB19763857F}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{2625B82F-F62C-4ED8-81D1-A6B3DE020AD1}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{E855FF44-F6FE-414B-A49F-95A2FD31E473}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{8EF8DC26-B0B7-4372-BA4D-E5D5235CF300}] => (Allow) D:\SteamLibrary\SteamApps\common\Audiosurf\engine\QuestViewer.exe FirewallRules: [{0DC1F4B9-533B-466E-A10A-27205540D45B}] => (Allow) D:\SteamLibrary\SteamApps\common\Audiosurf\engine\QuestViewer.exe FirewallRules: [{1EE76C8D-11FE-46D3-A3BB-7CBCF21B275B}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{30166ED7-E497-44E1-A972-F8E3F12DD937}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{281F9925-BEE6-4A50-93D6-4C87C2A0A834}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{3C2CC5DA-058A-47D5-B1BC-6CBB593CB818}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{41ADFF37-0AC7-40CA-89BC-6C27E5E5D16F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{25B722DB-A076-4D9A-BA82-9C06E6EF6E8E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{FCACE500-2C83-4E87-B962-C1E2D7E2AACC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{6B0AAB97-A26D-4119-BDCF-397BAB06E559}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{AC05E1FE-DF9F-41EC-BA6D-C3EFCC53381B}] => (Allow) D:\SteamLibrary\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{4A456AAD-2571-420F-B11C-2C10EE36EB7A}] => (Allow) D:\SteamLibrary\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{84DA8FF2-C2C3-44A3-80F1-13B8529DBD13}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{50DAE296-9717-4D15-99AB-E1F3ACC53D69}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{FC100A19-B707-48B4-BE6C-495C826880B7}] => (Allow) D:\Battle.net\Battle.net.exe FirewallRules: [{6146C5BE-7933-43E5-965A-A63D298E1F06}] => (Allow) D:\Battle.net\Battle.net.exe FirewallRules: [{609FA4C8-8255-4C1E-94C2-F2DC4103E261}] => (Allow) C:\Program Files\Steam\SteamApps\common\Free to Play\FTP.exe FirewallRules: [{17845C48-00CA-40BF-8D42-EF7D68CC25D3}] => (Allow) C:\Program Files\Steam\SteamApps\common\Free to Play\FTP.exe FirewallRules: [{DD7050DC-1D14-4494-AEEB-516343E13068}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe FirewallRules: [{33EED445-7A34-4041-88A4-7C58E5DE269B}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe FirewallRules: [{79006F9F-ADCD-4B97-BA87-DE9CD7D93E8C}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\farcry3.exe FirewallRules: [{C21D905D-49DF-4BA8-8BDB-1737D4BAA0FF}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\farcry3.exe FirewallRules: [{92573FDE-B00A-4BF5-9085-FFA09DB1E119}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe FirewallRules: [{5A243312-8610-4171-88FA-C17FAACEDD91}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe FirewallRules: [{2CDDA180-1AD4-49AD-A4EB-16C0F27CF125}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{7EE2999D-6458-4AD3-AE17-0E518FEC5C06}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{29F87D8C-E47D-483C-AD05-B1EFD7C7424A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{A37F1082-576E-44B1-9B3B-48A260460E0F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{80CC07D9-64A8-4DF2-A589-822701962296}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe FirewallRules: [{F85DA0A2-E516-4A64-8F20-1F4E5F8F0673}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe FirewallRules: [{72891B8E-6973-4CAC-8989-3E938A84F5A6}] => (Allow) D:\StarCraft II\StarCraft II.exe FirewallRules: [{877E8F2A-4FCC-4F3B-8C84-31AC17955B9F}] => (Allow) D:\StarCraft II\StarCraft II.exe FirewallRules: [TCP Query User{DA32A0DD-BF06-4ECB-88FB-AEE3AB1BD04D}D:\starcraft ii\versions\base28667\sc2.exe] => (Allow) D:\starcraft ii\versions\base28667\sc2.exe FirewallRules: [UDP Query User{00D049C8-486B-46C5-9E1E-8389825AA167}D:\starcraft ii\versions\base28667\sc2.exe] => (Allow) D:\starcraft ii\versions\base28667\sc2.exe FirewallRules: [{8669CF9C-D6AA-4FFC-A938-41D4A2C70FF7}] => (Allow) C:\Program Files\Origin Games\Battlefield 3\bf3.exe FirewallRules: [{EE2E86A6-E17A-4143-88A0-F7B3A72968B4}] => (Allow) C:\Program Files\Origin Games\Battlefield 3\bf3.exe FirewallRules: [TCP Query User{8E8D3A44-97EC-4F20-8EC9-2AB50868D22D}D:\steamlibrary\steamapps\common\thehunter\game\thehunter.exe] => (Allow) D:\steamlibrary\steamapps\common\thehunter\game\thehunter.exe FirewallRules: [UDP Query User{EAA7D2F3-9BD7-402D-A287-5C011007C5E4}D:\steamlibrary\steamapps\common\thehunter\game\thehunter.exe] => (Allow) D:\steamlibrary\steamapps\common\thehunter\game\thehunter.exe FirewallRules: [{951FB2FB-BF2D-4E2B-830A-8785A44D3BE8}] => (Allow) D:\SteamLibrary\SteamApps\common\Magic 2014\DotP_D14.exe FirewallRules: [{774D7E95-09DE-4013-A033-743F01985CA6}] => (Allow) D:\SteamLibrary\SteamApps\common\Magic 2014\DotP_D14.exe FirewallRules: [{758887FF-E66F-41D1-ACBD-9579807F8660}] => (Allow) D:\SteamLibrary\SteamApps\common\theHunter\launcher\launcher.exe FirewallRules: [{3D190ED8-B9BA-4553-AB7B-FB9B7A8E4BF2}] => (Allow) D:\SteamLibrary\SteamApps\common\theHunter\launcher\launcher.exe FirewallRules: [{995ABA57-A52D-4069-8912-C42646A77089}] => (Allow) D:\SteamLibrary\SteamApps\common\the witcher 2\Launcher.exe FirewallRules: [{4EEE7BFC-4EC0-4107-949B-4C5D7B79F957}] => (Allow) D:\SteamLibrary\SteamApps\common\the witcher 2\Launcher.exe FirewallRules: [TCP Query User{C971B5C5-BD6E-441A-9EA1-507B6076B720}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe FirewallRules: [UDP Query User{D6074904-862C-4554-A23F-89C9689B26BA}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe FirewallRules: [{30B6605E-BBC0-499C-B5BD-83AC0E112D49}] => (Allow) D:\SteamLibrary\SteamApps\common\Monaco\MONACO.exe FirewallRules: [{F85B2AF1-5B87-47B3-B55E-AF2B7107D286}] => (Allow) D:\SteamLibrary\SteamApps\common\Monaco\MONACO.exe FirewallRules: [{BE2DCE7D-6214-4EDE-9741-8E7609E16F6A}] => (Allow) D:\SteamLibrary\SteamApps\common\PAYDAY 2\payday2_win32_release.exe FirewallRules: [{8B74A210-B2D8-4C02-845E-985183A5BDD2}] => (Allow) D:\SteamLibrary\SteamApps\common\PAYDAY 2\payday2_win32_release.exe FirewallRules: [{C77E2011-0C90-4091-A8CA-0F4BC034D559}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed 2\AssassinsCreedIIGame.exe FirewallRules: [{3F230923-FD6D-4276-AF44-69D53AC56E9C}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed 2\AssassinsCreedIIGame.exe FirewallRules: [{6BB7CA3A-0D66-4C8D-B140-AB57EB226B6C}] => (Allow) D:\SteamLibrary\SteamApps\common\Terraria\Terraria.exe FirewallRules: [{07F3836B-EEA0-443E-88A8-24171ABD6B89}] => (Allow) D:\SteamLibrary\SteamApps\common\Terraria\Terraria.exe FirewallRules: [{33E4EBF0-3E01-46C4-87B3-D5649F72E0A9}] => (Allow) D:\SteamLibrary\SteamApps\common\Super Amazing Wagon Adventure\WagonAdventure.exe FirewallRules: [{43F9DE32-5A97-4EC4-8E30-78CF44F7A23D}] => (Allow) D:\SteamLibrary\SteamApps\common\Super Amazing Wagon Adventure\WagonAdventure.exe FirewallRules: [{1A715213-B909-407A-9128-C3165E06CB55}] => (Allow) D:\SteamLibrary\SteamApps\common\Crusader Kings II\CK2game.exe FirewallRules: [{A61A572F-C336-4B37-B4EE-F9C814A6B31B}] => (Allow) D:\SteamLibrary\SteamApps\common\Crusader Kings II\CK2game.exe FirewallRules: [TCP Query User{9CDADCF9-080E-4A60-97C9-F3491FC59F90}D:\steamlibrary\steamapps\common\terraria\terrariaserver.exe] => (Block) D:\steamlibrary\steamapps\common\terraria\terrariaserver.exe FirewallRules: [UDP Query User{E2E72813-7AAF-44EA-A0EA-7D39808C6C6C}D:\steamlibrary\steamapps\common\terraria\terrariaserver.exe] => (Block) D:\steamlibrary\steamapps\common\terraria\terrariaserver.exe FirewallRules: [{6107C44F-815D-491B-ABBE-0880B8DB4674}] => (Allow) D:\SteamLibrary\SteamApps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{6FE3DE32-2EDF-49E9-9875-151F06021F96}] => (Allow) D:\SteamLibrary\SteamApps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{2BC8FAFA-A36C-42C5-8C04-E1E98634BD52}] => (Allow) D:\SteamLibrary\SteamApps\common\Unturned\Unturned.exe FirewallRules: [{B1DDB7A1-5F00-47B0-BD20-F1B07913A585}] => (Allow) D:\SteamLibrary\SteamApps\common\Unturned\Unturned.exe FirewallRules: [{0161E88A-B633-4727-9EBB-D8C984965C67}] => (Allow) D:\SteamLibrary\SteamApps\common\Trine 2\trine2_launcher.exe FirewallRules: [{400E3C14-E9BD-4807-AA0C-34AD9A234AA5}] => (Allow) D:\SteamLibrary\SteamApps\common\Trine 2\trine2_launcher.exe FirewallRules: [TCP Query User{ACAFB545-0BB9-4ACA-81DB-901322E5BF9B}D:\steamlibrary\steamapps\common\trine 2\trine2_32bit.exe] => (Allow) D:\steamlibrary\steamapps\common\trine 2\trine2_32bit.exe FirewallRules: [UDP Query User{A2685D1A-E981-4F0A-80B8-2FCB6684758F}D:\steamlibrary\steamapps\common\trine 2\trine2_32bit.exe] => (Allow) D:\steamlibrary\steamapps\common\trine 2\trine2_32bit.exe FirewallRules: [{09719E56-C9F6-4B38-AAA2-F05002CBE937}] => (Allow) D:\SteamLibrary\SteamApps\common\mirrors edge\Binaries\MirrorsEdge.exe FirewallRules: [{F114DBD2-4BCA-4B57-9951-4F64669C4A7D}] => (Allow) D:\SteamLibrary\SteamApps\common\mirrors edge\Binaries\MirrorsEdge.exe FirewallRules: [TCP Query User{B531253E-1173-4050-8D30-EBC135058B52}D:\steamlibrary\steamapps\common\far cry 3\bin\farcry3_d3d11.exe] => (Block) D:\steamlibrary\steamapps\common\far cry 3\bin\farcry3_d3d11.exe FirewallRules: [UDP Query User{D03A3FEC-42B3-49D9-9BE5-283019D0EAD8}D:\steamlibrary\steamapps\common\far cry 3\bin\farcry3_d3d11.exe] => (Block) D:\steamlibrary\steamapps\common\far cry 3\bin\farcry3_d3d11.exe FirewallRules: [TCP Query User{2F2A6484-443A-4248-913B-EFB82947825E}H:\warcraft iii\war3.exe] => (Allow) H:\warcraft iii\war3.exe FirewallRules: [UDP Query User{7CB1CCB0-B700-4001-82C1-8D31F86EE48E}H:\warcraft iii\war3.exe] => (Allow) H:\warcraft iii\war3.exe FirewallRules: [{DC48228E-8534-4FD1-AAD3-F64AD8AAADDD}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe FirewallRules: [{F7D9B3A2-C90D-4175-8357-EFE17746245A}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe FirewallRules: [{695EE005-79C1-43E6-8609-51EC571107AB}] => (Allow) D:\SteamLibrary\SteamApps\common\Roogoo\Roogoo.exe FirewallRules: [{F3A4CF65-9E88-40B3-A53D-DEEB07AF718C}] => (Allow) D:\SteamLibrary\SteamApps\common\Roogoo\Roogoo.exe FirewallRules: [{4CB6A84B-4BE5-43C4-81AF-A6CFA54C5344}] => (Allow) D:\SteamLibrary\SteamApps\common\FlatOut\flatout.exe FirewallRules: [{F0BB7343-63EE-4C2A-B8E8-F9127B1962F0}] => (Allow) D:\SteamLibrary\SteamApps\common\FlatOut\flatout.exe FirewallRules: [{9EFF69BE-3522-464F-8E98-D7F78A95D20D}] => (Allow) D:\SteamLibrary\SteamApps\common\Tropico 3\tropico3.exe FirewallRules: [{C956A2DD-953A-4BC8-912E-87CF7306BAD6}] => (Allow) D:\SteamLibrary\SteamApps\common\Tropico 3\tropico3.exe FirewallRules: [{0F98A126-DE04-4906-A44D-27936D5DC5BC}] => (Allow) D:\SteamLibrary\SteamApps\common\SpeedRunners\SpeedRunners.exe FirewallRules: [{9BFFD0E1-5F62-4989-B4FE-85C98DEC1DD8}] => (Allow) D:\SteamLibrary\SteamApps\common\SpeedRunners\SpeedRunners.exe FirewallRules: [{4D63FCA0-9D2B-41BB-9AA2-A00F9A59671C}] => (Allow) D:\SteamLibrary\SteamApps\common\Just Cause 2\JustCause2.exe FirewallRules: [{23C372F5-DAFE-4976-BC18-89758A42AD04}] => (Allow) D:\SteamLibrary\SteamApps\common\Just Cause 2\JustCause2.exe FirewallRules: [{6D6D4FF2-79B0-4A22-BE9F-1F578281F258}] => (Allow) D:\SteamLibrary\SteamApps\common\lethalleague\LethalLeague.exe FirewallRules: [{B030D5BE-74E6-4A3D-A9FC-CBE466E7EB8A}] => (Allow) D:\SteamLibrary\SteamApps\common\lethalleague\LethalLeague.exe FirewallRules: [TCP Query User{544C29AD-E24E-4123-BC07-336342A1DE7A}C:\program files\geneious\jre\bin\java.exe] => (Allow) C:\program files\geneious\jre\bin\java.exe FirewallRules: [UDP Query User{3315995D-4CFB-4739-9AF4-3547769F7148}C:\program files\geneious\jre\bin\java.exe] => (Allow) C:\program files\geneious\jre\bin\java.exe FirewallRules: [{E1BEBB8B-CAE6-46A1-B2DB-61F66CC5F54D}] => (Allow) D:\SteamLibrary\SteamApps\common\Amnesia The Dark Descent\Amnesia.exe FirewallRules: [{035AE7C9-7F8F-42A1-92DC-ED8DFCEEC774}] => (Allow) D:\SteamLibrary\SteamApps\common\Amnesia The Dark Descent\Amnesia.exe FirewallRules: [{06A413F3-D3F1-48F2-9760-0846EA05AB3D}] => (Allow) D:\SteamLibrary\SteamApps\common\Amnesia The Dark Descent\Launcher.exe FirewallRules: [{C2CD5402-7C0C-41F6-AE4A-05154EE8F187}] => (Allow) D:\SteamLibrary\SteamApps\common\Amnesia The Dark Descent\Launcher.exe FirewallRules: [TCP Query User{F431765F-4205-4544-BC27-D6546082A2BE}D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Block) D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe FirewallRules: [UDP Query User{3AF5D673-39EB-40F7-9896-44B8A2D41E84}D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Block) D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe FirewallRules: [TCP Query User{ACB7A484-EC4B-45F1-8BF7-A8C6B8504E9C}D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Block) D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe FirewallRules: [UDP Query User{C70643F1-CC41-4DFF-8018-366F43C81DCF}D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Block) D:\leagueoffaggots\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe FirewallRules: [{29C5102E-B2B2-4415-B047-C978F5C3B91B}] => (Allow) D:\SteamLibrary\SteamApps\common\Planetary Annihilation\PA.exe FirewallRules: [{9DA54B2A-5177-4D9F-BA44-10905B78EA1B}] => (Allow) D:\SteamLibrary\SteamApps\common\Planetary Annihilation\PA.exe FirewallRules: [{A5AED074-D454-4AF1-A16B-80C3E630B350}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{256E15DB-D5A1-418D-A07D-4BB47A8AE342}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{1DE54C33-6145-4A29-9425-926C623988FB}] => (Allow) D:\SteamLibrary\SteamApps\common\Port Royale 2\PR2.exe FirewallRules: [{4D6CAFC6-854A-405D-A839-838D4117C466}] => (Allow) D:\SteamLibrary\SteamApps\common\Port Royale 2\PR2.exe FirewallRules: [{4C58F486-2DD8-418E-A44A-BB7314344B93}] => (Allow) D:\SteamLibrary\SteamApps\common\Port Royale 2\PR2Config.exe FirewallRules: [{AD56DF24-935F-402A-9713-60D51B06E78E}] => (Allow) D:\SteamLibrary\SteamApps\common\Port Royale 2\PR2Config.exe FirewallRules: [TCP Query User{0E99E21F-00A0-4DCA-8712-E568FE89ACCF}C:\programdata\battle.net\agent\agent.3632\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3632\agent.exe FirewallRules: [UDP Query User{C1841E25-07B5-44A5-96FF-367CCD8A0F01}C:\programdata\battle.net\agent\agent.3632\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3632\agent.exe FirewallRules: [{7A47B7FE-95E9-4598-9B00-36CA7C5C02C7}] => (Allow) D:\SteamLibrary\SteamApps\common\Sega Classics\SEGAGenesisClassics.exe FirewallRules: [{732378E6-6A02-4EC4-B807-40D3723038B7}] => (Allow) D:\SteamLibrary\SteamApps\common\Sega Classics\SEGAGenesisClassics.exe FirewallRules: [TCP Query User{61F1E079-0AB6-4C3E-B356-9792ED776D4C}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{A92D1A85-EE4B-408B-AE89-4506C8D1D9C0}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [TCP Query User{8D80575E-B390-488B-8DE1-C899CA4C3408}D:\heroes of the storm\versions\base34659\heroesofthestorm.exe] => (Allow) D:\heroes of the storm\versions\base34659\heroesofthestorm.exe FirewallRules: [UDP Query User{479D4095-B4A3-4067-A1E5-63AB76B6677D}D:\heroes of the storm\versions\base34659\heroesofthestorm.exe] => (Allow) D:\heroes of the storm\versions\base34659\heroesofthestorm.exe FirewallRules: [{25814D4B-7FB0-4977-8176-64D1B4189537}] => (Allow) D:\SteamLibrary\SteamApps\common\AdVenture Capitalist\adventure-capitalist.exe FirewallRules: [{E60EBBEC-643F-4832-B231-2F92BDBBBD5D}] => (Allow) D:\SteamLibrary\SteamApps\common\AdVenture Capitalist\adventure-capitalist.exe FirewallRules: [TCP Query User{36A225D5-0DCE-4CA7-9FFD-281F95BF4ED2}D:\heroes of the storm\versions\base34846\heroesofthestorm.exe] => (Allow) D:\heroes of the storm\versions\base34846\heroesofthestorm.exe FirewallRules: [UDP Query User{AEFA2525-A07B-458A-ADEA-5769E5D1CBA1}D:\heroes of the storm\versions\base34846\heroesofthestorm.exe] => (Allow) D:\heroes of the storm\versions\base34846\heroesofthestorm.exe FirewallRules: [{BDF8D20F-5CBC-4088-B4F0-A392A204CF1E}] => (Allow) D:\SteamLibrary\SteamApps\common\Space\spacegame\Binaries\Win32\spacegame-Win32-Shipping.exe FirewallRules: [{5E83B031-F4B2-4185-86A5-368D1A15EBF6}] => (Allow) D:\SteamLibrary\SteamApps\common\Space\spacegame\Binaries\Win32\spacegame-Win32-Shipping.exe FirewallRules: [TCP Query User{047B1566-774C-429E-ABAB-CC49EF8FCA1B}J:\neuer ordner\dawn of war - soulstorm( ua)\soulstorm.exe] => (Block) J:\neuer ordner\dawn of war - soulstorm( ua)\soulstorm.exe FirewallRules: [UDP Query User{F914C1CE-3E32-47AF-9CDD-2D36EB310D3F}J:\neuer ordner\dawn of war - soulstorm( ua)\soulstorm.exe] => (Block) J:\neuer ordner\dawn of war - soulstorm( ua)\soulstorm.exe FirewallRules: [{6D1ACC45-9F70-4DA1-B05C-1147602D5E54}] => (Allow) D:\SteamLibrary\SteamApps\common\Heroes of Might and Magic 5 Tribes of the East\bin\H5_Game.exe FirewallRules: [{5A864CF4-BFBC-477B-97BE-9892DB08F2D5}] => (Allow) D:\SteamLibrary\SteamApps\common\Heroes of Might and Magic 5 Tribes of the East\bin\H5_Game.exe FirewallRules: [{EA6DF6D6-CB19-4126-A88C-C474053699C6}] => (Allow) D:\SteamLibrary\SteamApps\common\Game Dev Tycoon\nw.exe FirewallRules: [{E000B7E1-28A3-4432-B4CF-309743AE1097}] => (Allow) D:\SteamLibrary\SteamApps\common\Game Dev Tycoon\nw.exe FirewallRules: [{72649A71-3A3D-4B71-9D32-65EFAA51C600}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{8BDA8251-F3A8-4EC0-98CB-387395CE1417}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{DC5A2A6D-544B-4136-B89E-2BF1C5BBBE95}] => (Allow) D:\SteamLibrary\SteamApps\common\Age2HD\Launcher.exe FirewallRules: [{A404998B-5CEE-41CA-97E1-DE0FC75A48B6}] => (Allow) D:\SteamLibrary\SteamApps\common\Age2HD\Launcher.exe FirewallRules: [{1533A207-FC63-4DC3-8C07-1A5C6C174F85}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe FirewallRules: [{200D00AF-302D-4372-920E-CAE13137C349}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe FirewallRules: [{38FC7F71-43E1-494D-B03F-306B0CA53B86}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFMP.exe FirewallRules: [{06028079-7D6E-4245-BEB9-31461143C1E5}] => (Allow) D:\SteamLibrary\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFMP.exe FirewallRules: [{616F6893-4E18-4C14-9A2B-5500E1F924A4}] => (Allow) D:\SteamLibrary\SteamApps\common\Gothic 3\Gothic3.exe FirewallRules: [{1B731D39-69CC-47A8-9FC6-DC44DF3C54F0}] => (Allow) D:\SteamLibrary\SteamApps\common\Gothic 3\Gothic3.exe FirewallRules: [{11D536ED-4BC8-4A7F-828B-D5101EE4B096}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Broadcom 802.11g Network Adapter Description: Broadcom 802.11g Network Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Broadcom Service: BCM43XX Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (07/25/2015 03:32:14 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/25/2015 08:57:41 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Gothic3.exe, Version: 1.60.25931.29, Zeitstempel: 0x47a1062b Name des fehlerhaften Moduls: Engine.dll, Version: 1.60.25931.29, Zeitstempel: 0x47a10236 Ausnahmecode: 0xc0000005 Fehleroffset: 0x004abad6 ID des fehlerhaften Prozesses: 0x320 Startzeit der fehlerhaften Anwendung: 0xGothic3.exe0 Pfad der fehlerhaften Anwendung: Gothic3.exe1 Pfad des fehlerhaften Moduls: Gothic3.exe2 Berichtskennung: Gothic3.exe3 Error: (07/23/2015 02:52:32 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/23/2015 02:11:02 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Gothic3.exe, Version: 1.60.25931.29, Zeitstempel: 0x47a1062b Name des fehlerhaften Moduls: Engine.dll, Version: 1.60.25931.29, Zeitstempel: 0x47a10236 Ausnahmecode: 0xc0000005 Fehleroffset: 0x004abad6 ID des fehlerhaften Prozesses: 0x4b4 Startzeit der fehlerhaften Anwendung: 0xGothic3.exe0 Pfad der fehlerhaften Anwendung: Gothic3.exe1 Pfad des fehlerhaften Moduls: Gothic3.exe2 Berichtskennung: Gothic3.exe3 Error: (07/15/2015 11:19:45 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/14/2015 01:51:50 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Gothic3.exe, Version: 1.60.25931.29, Zeitstempel: 0x47a1062b Name des fehlerhaften Moduls: SharedBase.dll, Version: 1.60.25931.29, Zeitstempel: 0x47a0ff42 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000a7aea ID des fehlerhaften Prozesses: 0xf20 Startzeit der fehlerhaften Anwendung: 0xGothic3.exe0 Pfad der fehlerhaften Anwendung: Gothic3.exe1 Pfad des fehlerhaften Moduls: Gothic3.exe2 Berichtskennung: Gothic3.exe3 Error: (07/13/2015 11:46:23 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Gothic3.exe, Version 1.60.25931.29 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1aa4 Startzeit: 01d0bd4a9cf8df5c Endzeit: 632 Anwendungspfad: D:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exe Berichts-ID: Error: (07/13/2015 06:35:28 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/12/2015 07:26:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Gothic3.exe, Version: 1.60.25931.29, Zeitstempel: 0x47a1062b Name des fehlerhaften Moduls: Engine.dll, Version: 1.60.25931.29, Zeitstempel: 0x47a10236 Ausnahmecode: 0xc0000005 Fehleroffset: 0x004abad6 ID des fehlerhaften Prozesses: 0x1a6c Startzeit der fehlerhaften Anwendung: 0xGothic3.exe0 Pfad der fehlerhaften Anwendung: Gothic3.exe1 Pfad des fehlerhaften Moduls: Gothic3.exe2 Berichtskennung: Gothic3.exe3 Error: (07/12/2015 05:12:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Gothic3.exe, Version: 1.60.25931.29, Zeitstempel: 0x47a1062b Name des fehlerhaften Moduls: Engine.dll, Version: 1.60.25931.29, Zeitstempel: 0x47a10236 Ausnahmecode: 0xc0000005 Fehleroffset: 0x003a0a75 ID des fehlerhaften Prozesses: 0x1814 Startzeit der fehlerhaften Anwendung: 0xGothic3.exe0 Pfad der fehlerhaften Anwendung: Gothic3.exe1 Pfad des fehlerhaften Moduls: Gothic3.exe2 Berichtskennung: Gothic3.exe3 Systemfehler: ============= Error: (07/24/2015 02:40:30 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/24/2015 02:40:30 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error: (07/23/2015 11:34:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/23/2015 11:34:58 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error: (07/23/2015 11:34:26 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SSDP-Suche" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/23/2015 11:34:25 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SSDP-Suche erreicht. Error: (07/22/2015 02:12:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/22/2015 02:12:21 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error: (07/22/2015 02:11:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SSDP-Suche" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/22/2015 02:11:14 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SSDP-Suche erreicht. Microsoft Office: ========================= Error: (07/25/2015 03:32:14 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"d:\steamlibrary\steamapps\common\Trine 2\tools\luac_x64.exe Error: (07/25/2015 08:57:41 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Gothic3.exe1.60.25931.2947a1062bEngine.dll1.60.25931.2947a10236c0000005004abad632001d0c6a060ee618aD:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exeD:\SteamLibrary\steamapps\common\Gothic 3\Engine.dll709a8701-329a-11e5-a752-20cf3093393a Error: (07/23/2015 02:52:32 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"d:\steamlibrary\steamapps\common\Trine 2\tools\luac_x64.exe Error: (07/23/2015 02:11:02 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Gothic3.exe1.60.25931.2947a1062bEngine.dll1.60.25931.2947a10236c0000005004abad64b401d0c4d11c924827D:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exeD:\SteamLibrary\steamapps\common\Gothic 3\Engine.dll4cd77810-30cf-11e5-986b-20cf3093393a Error: (07/15/2015 11:19:45 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"d:\steamlibrary\steamapps\common\Trine 2\tools\luac_x64.exe Error: (07/14/2015 01:51:50 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Gothic3.exe1.60.25931.2947a1062bSharedBase.dll1.60.25931.2947a0ff42c0000005000a7aeaf2001d0bdb982eea28fD:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exeD:\SteamLibrary\steamapps\common\Gothic 3\SharedBase.dll20d16d48-29ba-11e5-8c31-20cf3093393a Error: (07/13/2015 11:46:23 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Gothic3.exe1.60.25931.291aa401d0bd4a9cf8df5c632D:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exe Error: (07/13/2015 06:35:28 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"d:\steamlibrary\steamapps\common\Trine 2\tools\luac_x64.exe Error: (07/12/2015 07:26:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Gothic3.exe1.60.25931.2947a1062bEngine.dll1.60.25931.2947a10236c0000005004abad61a6c01d0bcba227dc7faD:\SteamLibrary\steamapps\common\Gothic 3\Gothic3.exeD:\SteamLibrary\steamapps\common\Gothic 3\Engine.dll29aec87f-28bb-11e5-9261-20cf3093393a Error: (07/12/2015 05:12:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Gothic3.exe1.60.25931.2947a1062bEngine.dll1.60.25931.2947a10236c0000005003a0a75181401d0bcb52ee69cc1D:\SteamLibrary\SteamApps\common\Gothic 3\Gothic3.exeD:\SteamLibrary\SteamApps\common\Gothic 3\Engine.dll715ea270-28a8-11e5-9261-20cf3093393a ==================== Memory info =========================== Processor: AMD Phenom(tm) II X4 955 Processor Percentage of memory in use: 61% Total physical RAM: 3326.18 MB Available physical RAM: 1283.71 MB Total Virtual: 6650.65 MB Available Virtual: 4403.06 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:294.04 GB) (Free:129.31 GB) NTFS Drive d: () (Fixed) (Total:392.66 GB) (Free:83.24 GB) NTFS Drive e: () (Fixed) (Total:244.71 GB) (Free:189.25 GB) NTFS Drive h: () (Fixed) (Total:232.88 GB) (Free:75.06 GB) NTFS Drive j: (MEMUP 1TB) (Fixed) (Total:931.51 GB) (Free:619.1 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 232.9 GB) (Disk ID: 24C249AC) Partition 1: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 101FB8C2) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=294 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=637.4 GB) - (Type=OF Extended) ======================================================== Disk: 2 (Size: 931.5 GB) (Disk ID: 000E0861) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ==================== Ende vom log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2015-07-25 17:10:33 Windows 6.1.7601 Service Pack 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-3 ST31000528AS rev.CC38 931,51GB Running: Gmer-19357.exe; Driver: C:\Users\Otti\AppData\Local\Temp\kxldapod.sys ---- System - GMER 2.1 ---- SSDT 968531C6 ZwCreateSection SSDT 9685319E ZwCreateSymbolicLinkObject SSDT 968531A3 ZwLoadDriver SSDT 96853199 ZwOpenSection SSDT 968531D0 ZwRequestWaitReplyPort SSDT 968531CB ZwSetContextThread SSDT 968531D5 ZwSetSecurityObject SSDT 968531A8 ZwSetSystemInformation SSDT 968531DA ZwSystemDebugControl SSDT 96853167 ZwTerminateProcess SSDT 96853162 ZwWriteVirtualMemory ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 8324CA15 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 83286212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 8328D58C 1 Byte [C6] .text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 8328D58C 4 Bytes [C6, 31, 85, 96] .text ntkrnlpa.exe!KeRemoveQueueEx + 11FF 8328D594 4 Bytes [9E, 31, 85, 96] .text ntkrnlpa.exe!KeRemoveQueueEx + 1313 8328D6A8 4 Bytes [A3, 31, 85, 96] .text ntkrnlpa.exe!KeRemoveQueueEx + 13AF 8328D744 4 Bytes [99, 31, 85, 96] .text ... .text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0xA11B1300, 0x3B6D8, 0xE8000020] .text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0xA1000300, 0x1BEE, 0xE8000020] ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x47 0xAC 0x87 0xE5 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x4B 0x37 0x83 0xD6 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF9 0xFC 0x31 0xE6 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x47 0xAC 0x87 0xE5 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x4B 0x37 0x83 0xD6 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF9 0xFC 0x31 0xE6 ... ---- EOF - GMER 2.1 ---- Ich bedanke mich bereits im vorraus schonmal für die Hilfe und die Arbeit die ihr euch macht MfG Ottel |
25.07.2015, 16:39 | #2 |
/// the machine /// TB-Ausbilder | Externe Festplatte befallen, Daten versteckt hi,
__________________Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Scan mit Combofix
__________________ |
25.07.2015, 18:02 | #3 |
| Externe Festplatte befallen, Daten versteckt Hallo Schrauber, danke für die schnelle Antwort.
__________________Hier ist die Logfile vom Combofix, gemeckert hat das Suchprogramm nicht: Code:
ATTFilter ComboFix 15-07-23.01 - Otti 25.07.2015 18:44:43.1.4 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3326.1948 [GMT 2:00] ausgeführt von:: c:\users\Otti\Downloads\ComboFix.exe AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Otti\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll c:\users\Otti\AppData\Roaming\SpeedRunnersLog.txt E:\install.exe . . ((((((((((((((((((((((( Dateien erstellt von 2015-06-25 bis 2015-07-25 )))))))))))))))))))))))))))))) . . 2015-07-25 16:34 . 2015-07-25 16:34 -------- d-----w- c:\program files\VS Revo Group 2015-07-25 14:55 . 2015-07-25 14:57 -------- d-----w- C:\FRST 2015-07-09 00:52 . 2015-07-09 00:52 -------- d-----w- c:\program files\PDF24 2015-07-03 22:20 . 2015-07-03 22:20 -------- d-----w- c:\users\Otti\AppData\Local\CEF 2015-07-01 21:42 . 2015-07-14 20:23 778416 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2015-07-01 21:42 . 2015-07-14 20:23 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-07-25 09:49 . 2014-10-29 20:17 98520 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2015-06-19 01:02 . 2015-05-04 19:02 136728 ----a-w- c:\windows\system32\drivers\avipbb.sys 2015-06-19 01:02 . 2015-05-04 19:02 108448 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2015-06-18 06:41 . 2014-10-29 20:17 51928 ----a-w- c:\windows\system32\drivers\mwac.sys 2015-06-18 06:41 . 2014-10-29 20:17 94936 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2015-06-18 06:41 . 2012-03-22 14:46 23256 ----a-w- c:\windows\system32\drivers\mbam.sys 2015-06-07 21:00 . 2014-06-03 17:00 139888 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2015-06-07 21:00 . 2014-06-03 17:00 348672 ----a-w- c:\windows\system32\PnkBstrB.exe 2015-06-07 21:00 . 2013-12-12 00:47 348672 ----a-w- c:\windows\system32\PnkBstrB.xtr 2015-06-07 20:59 . 2013-12-12 00:37 290184 ----a-w- c:\windows\system32\PnkBstrB.ex0 2015-06-03 21:04 . 2014-07-15 13:28 1316000 ----a-w- c:\windows\system32\nvspbridge.dll 2015-06-03 21:04 . 2013-10-29 09:57 1320304 ----a-w- c:\windows\system32\nvspcap.dll 2015-05-28 13:36 . 2014-06-03 17:00 138056 ----a-w- c:\users\Otti\AppData\Roaming\PnkBstrK.sys 2015-05-28 07:00 . 2015-06-19 10:38 939264 ----a-w- c:\windows\system32\nvumdshim.dll 2015-05-28 07:00 . 2015-06-19 10:38 912712 ----a-w- c:\windows\system32\nvhdagenco3220103.dll 2015-05-28 07:00 . 2015-06-19 10:38 28480 ----a-w- c:\windows\system32\nvhdap32.dll 2015-05-28 07:00 . 2015-06-19 10:38 22946960 ----a-w- c:\windows\system32\nvoglv32.dll 2015-05-28 07:00 . 2015-06-19 10:38 162624 ----a-w- c:\windows\system32\drivers\nvhda32v.sys 2015-05-28 07:00 . 2015-06-19 10:38 13304280 ----a-w- c:\windows\system32\nvopencl.dll 2015-05-28 07:00 . 2015-06-19 10:38 128512 ----a-w- c:\windows\system32\nvoglshim32.dll 2015-05-28 07:00 . 2015-06-19 10:38 982856 ----a-w- c:\windows\system32\NvIFR.dll 2015-05-28 07:00 . 2015-06-19 10:38 9115464 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2015-05-28 07:00 . 2015-06-19 10:38 154256 ----a-w- c:\windows\system32\nvinit.dll 2015-05-28 07:00 . 2015-06-19 10:38 974480 ----a-w- c:\windows\system32\NvFBC.dll 2015-05-28 07:00 . 2015-06-19 10:38 912712 ----a-w- c:\windows\system32\nvdispgenco3235306.dll 2015-05-28 07:00 . 2015-06-19 10:38 1049232 ----a-w- c:\windows\system32\nvdispco3235306.dll 2015-05-28 07:00 . 2015-06-19 10:38 2599056 ----a-w- c:\windows\system32\nvcuvid.dll 2015-05-28 07:00 . 2015-06-19 10:38 11830320 ----a-w- c:\windows\system32\nvcuda.dll 2015-05-28 07:00 . 2015-06-19 10:38 37741712 ----a-w- c:\windows\system32\nvcompiler.dll 2015-05-28 07:00 . 2010-06-14 22:07 2986392 ----a-w- c:\windows\system32\nvapi.dll 2015-05-28 07:00 . 2010-06-14 22:07 14987528 ----a-w- c:\windows\system32\nvwgf2um.dll 2015-05-28 07:00 . 2010-06-14 22:07 12852152 ----a-w- c:\windows\system32\nvd3dum.dll 2015-05-28 03:52 . 2015-06-19 10:41 571024 ----a-w- c:\windows\system32\nvStreaming.exe 2015-05-28 03:50 . 2010-06-13 22:09 672064 ----a-w- c:\windows\system32\nvvsvc.exe 2015-05-28 03:50 . 2010-06-13 22:09 2554184 ----a-w- c:\windows\system32\nvsvcr.dll 2015-05-28 03:50 . 2010-06-13 22:09 61584 ----a-w- c:\windows\system32\nvshext.dll 2015-05-28 03:50 . 2010-06-13 22:09 375112 ----a-w- c:\windows\system32\nvmctray.dll 2015-05-28 03:50 . 2010-06-13 22:09 4385424 ----a-w- c:\windows\system32\nvcpl.dll 2015-05-28 03:50 . 2010-06-13 22:09 3020104 ----a-w- c:\windows\system32\nvsvc.dll 2015-05-27 00:16 . 2014-08-07 09:34 96352 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2015-05-20 15:19 . 2015-05-04 19:02 37896 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2015-05-19 03:29 . 2015-06-19 10:29 41648 ----a-w- c:\windows\system32\drivers\nvvad32v.sys 2015-05-19 03:14 . 2013-09-01 17:37 57520 ----a-w- c:\windows\system32\nvaudcap32v.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files\Steam\steam.exe" [2015-07-23 2895552] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2010-03-15 1780224] "TurboV EVO"="c:\program files\ASUS\TurboV EVO\TurboV_EVO.exe" [2010-04-07 9919104] "Six Engine"="c:\program files\ASUS\EPU\EPU.exe" [2010-03-16 5309056] "NUSB3MON"="c:\program files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-01-22 106496] "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632] "tsnp2uvc"="c:\program files\Common Files\SNP2UVC\tsnp2uvc.exe" [2011-07-20 321024] "ShadowPlay"="c:\windows\system32\nvspcap.dll" [2015-06-03 1320304] "NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-06-03 2754704] "avgnt"="c:\program files\Avira\Antivirus\avgnt.exe" [2015-06-19 730416] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2015-04-30 334896] "Avira Systray"="c:\program files\Avira\Launcher\Avira.Systray.exe" [2015-06-02 134368] "PDFPrint"="c:\program files\PDF24\pdf24.exe" [2015-07-07 217632] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2013-11-21 16:57 959904 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] 2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EKIJ5000StatusMonitor] 2010-09-02 13:23 1638400 ----a-w- c:\windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2014-08-27 07:20 22041192 ----a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2uvc] 2009-08-12 14:06 662016 ----a-w- c:\windows\vsnp2uvc.exe . R2 MBAMService;MBAMService;c:\program files\ Malwarebytes Anti-Malware \mbamservice.exe [2015-06-18 1133880] R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2015-06-18 51928] R3 Origin Client Service;Origin Client Service;c:\program files\Origin\OriginClientService.exe [2015-06-06 1997168] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R4 AODService;AODService;c:\program files\AMD\OverDrive\AODAssist.exe [2009-10-22 136544] R4 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000] R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-09-21 691696] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2015-05-20 37896] S2 AntiVirMailService;Avira Email-Schutz;c:\program files\Avira\Antivirus\avmailc7.exe [2015-06-19 827184] S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\Antivirus\sched.exe [2015-06-19 450808] S2 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\Antivirus\avwebg7.exe [2015-06-19 1188360] S2 AsSysCtrlService;ASUS System Control Service;c:\program files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-12-28 96896] S2 Avira.ServiceHost;Avira Service Host;c:\program files\Avira\Launcher\Avira.ServiceHost.exe [2015-06-02 217280] S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys [2015-03-24 37896] S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [2009-10-16 319488] S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-06-03 919184] S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-06-03 1893008] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2015-06-03 20694160] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-05-28 410768] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2015-06-18 23256] S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-01-22 59904] S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-01-22 139648] S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-06-03 18576] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2015-05-19 41648] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-10-19 31288] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2010-03-02 1127936] . . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2015-07-22 22:22 995144 ----a-w- c:\program files\Google\Chrome\Application\44.0.2403.89\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2015-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-12-12 20:18] . 2015-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-12-12 20:18] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://de.ask.com/?l=dis&o=APN10375&gct=hp&apn_ptnrs=^AHP&apn_dtid=^YYYYYY^YY^DE&p2=^AHP^YYYYYY^YY^DE&tpid=SGT-SAT&apn_dbr=ff_16.0&apn_uid=4B8FE4C5-97CF-4033-A601-BCBD1EFFAD61&itbv=11.3.0.661&doi=2012-12-03 IE: Free YouTube Download - c:\users\Otti\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Otti\AppData\Roaming\Mozilla\Firefox\Profiles\vd5nyfxp.default-1371114904938\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . WebBrowser-{5347542D-5341-5400-76A7-7A786E7484D7} - (no file) WebBrowser-{41564952-412D-5637-00A7-7A786E7484D7} - (no file) HKLM-Run-Nvtmru - c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe MSConfigStartUp-ApnTBMon - c:\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe AddRemove-Battlelog Web Plugins - c:\program files\Battlelog Web Plugins\uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-3534099020-634075679-966876233-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:51,27,41,c7,9f,c8,28,04,a5,24,8e,27,d4,65,80,f6,79,17,cd,5a,cd,6a,6f, 97,ac,47,56,8a,c0,23,f1,6f,92,b7,49,1d,38,6f,01,87,8e,ad,0b,a8,86,d8,c3,9c,\ "??"=hex:b5,33,74,b2,61,ce,10,dd,2c,cb,33,5c,33,6e,6a,9d . [HKEY_USERS\S-1-5-21-3534099020-634075679-966876233-1000\Software\SecuROM\License information*] "datasecu"=hex:c8,a2,8e,b9,e0,64,7d,c5,0f,d4,c0,bb,0a,99,6f,64,8d,79,14,eb,5a, 81,ed,16,6f,ee,65,a5,f0,b3,9d,6c,d9,cb,69,49,9f,69,09,c2,f1,17,1b,1b,05,ee,\ "rkeysecu"=hex:ea,a2,90,7c,c4,34,ba,95,ea,ab,dc,db,59,de,fe,81 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\system32\nvvsvc.exe c:\program files\NVIDIA Corporation\Display\nvxdsync.exe c:\windows\system32\nvvsvc.exe c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\Avira\Antivirus\avguard.exe c:\windows\system32\taskhost.exe c:\windows\DAODx.exe c:\program files\ASUS\TurboV EVO\TurboVHELP.exe c:\windows\system32\PnkBstrA.exe c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe c:\windows\system32\conhost.exe c:\windows\system32\conhost.exe c:\program files\Avira\Antivirus\avshadow.exe c:\program files\NVIDIA Corporation\Display\nvtray.exe c:\users\Otti\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe c:\windows\system32\sppsvc.exe c:\windows\System32\rundll32.exe c:\windows\system32\conhost.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Steam\bin\steamwebhelper.exe c:\program files\Common Files\Steam\SteamService.exe . ************************************************************************** . Zeit der Fertigstellung: 2015-07-25 18:56:28 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2015-07-25 16:56 . Vor Suchlauf: 8 Verzeichnis(se), 138.251.120.640 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 138.209.284.096 Bytes frei . - - End Of File - - 2858E28DC328DA3CF4C3D3A619F1790C A36C5E4F47E84449FF07ED3517B43A31 PS: Als ich die Festplatte sicher entfernen wollte, wurde mit gesagt dass noch etwas auf die Festplatte zugreift und das entfernen deshalb nicht möglich ist. Mysteriös, da sämtliche Anwendungen geschlossen waren. MfG, Ottel |
26.07.2015, 13:11 | #4 |
/// the machine /// TB-Ausbilder | Externe Festplatte befallen, Daten versteckt PLatte dran und nicht mehr ab machen. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Externe Festplatte befallen, Daten versteckt |
antivirus, avira, computer, desktop, downloader, error, festplatte, firefox, flash player, helper, home, mozilla, mp3, registry, required, rundll, scan, security, software, stick, svchost.exe, system, usb, virus, windows, windows xp |