|
Log-Analyse und Auswertung: Viren blocken Security CenterWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
04.03.2011, 22:42 | #1 |
| Viren blocken Security Center Ich bins mal wieder mit den Viren nun ja habe 3 viren die sich mit Malwarebytes zwar immer wieder löschen lassen aber sich wieder neu von selber erstellen. Denke auch das ist der grund warum sich mein Avira Control Center immer nach 2 sek direkt schließt und nicht aktiv bleibt .. hab ich da recht? Nun möcht ich auch wissen wie ich diese Viren dauerthaft löschen kann^^ Code:
ATTFilter Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 5922 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 04.03.2011 22:27:36 mbam-log-2011-03-04 (22-27-36).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 133937 Laufzeit: 3 Minute(n), 42 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 3 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Malwarebytes' Anti-Malware 1.50.1.1100 Malwarebytes Datenbank Version: 5922 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 05.03.2011 12:45:21 mbam-log-2011-03-05 (12-45-15).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|) Durchsuchte Objekte: 318142 Laufzeit: 1 Stunde(n), 27 Minute(n), 13 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 3 Infizierte Verzeichnisse: 0 Infizierte Dateien: 16 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP12\A0008722.exe (Trojan.FakeMS) -> No action taken. c:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP12\A0010033.exe (Trojan.FakeMS) -> No action taken. c:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP15\A0011367.exe (Trojan.Agent.Gen) -> No action taken. c:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP15\A0011457.exe (Trojan.FakeMS) -> No action taken. c:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP15\A0012515.exe (Trojan.Agent.Gen) -> No action taken. c:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP3\A0001968.exe (FakeMS) -> No action taken. c:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP3\A0002504.exe (Trojan.Agent) -> No action taken. c:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP3\A0003632.exe (FakeMS) -> No action taken. c:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP3\A0003780.exe (Trojan.Agent) -> No action taken. e:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP34\A0025920.exe (Trojan.Agent.CK) -> No action taken. e:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP41\A0026878.exe (Trojan.Agent.CK) -> No action taken. e:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP42\A0027359.exe (Trojan.Agent.CK) -> No action taken. e:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP42\A0027376.exe (RiskWare.Tool.CK) -> No action taken. e:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP44\A0027607.exe (Trojan.Agent.CK) -> No action taken. e:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP45\A0027834.exe (Trojan.Agent.CK) -> No action taken. e:\system volume information\_restore{cecd0f58-dfb6-4c5e-994e-a9801a6cd7b0}\RP45\A0028361.exe (Trojan.Agent.CK) -> No action taken. auf diesen ordner " e:\system volume information " kann ich aber auch nicht zugreifen vllt hat der virus diesen ordner versteckt gemacht... bitte antwortet jemand hm sry für die 2 antwort bei mir hat die seite nicht geladen habs dann ausversehen 2 mal gepostet und weis nicht wie ich 1 eintrag lösche^^ Hallo ist hier keiner da der mir bei meinem problem helfen kann oder fehlt an meinen angaben noch was? bitte um hilfe |
07.03.2011, 18:34 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Viren blocken Security Center Deaktiviere die Systemwiederherstellung, im Verlauf der Infektion wurden auch Malwaredateien in Wiederherstellungspunkten mitgesichert - die sind alle nun unbrauchbar, da ein Zurücksetzen des Systems durch einen Wiederherstellungspunkt wahrscheinlich wieder eine Infektion nach sich ziehen würde.
__________________Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ |
07.03.2011, 21:48 | #3 |
| Viren blocken Security Center OTL EXTRAS Logfile:
__________________Code:
ATTFilter OTL Extras logfile created on: 07.03.2011 21:16:31 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = E:\Downloads u. Wichtige Programme\Downloads Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 67,00% Memory free 5,00 Gb Paging File | 4,00 Gb Available in Paging File | 83,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 74,53 Gb Total Space | 17,66 Gb Free Space | 23,70% Space Free | Partition Type: NTFS Drive E: | 465,76 Gb Total Space | 323,54 Gb Free Space | 69,47% Space Free | Partition Type: NTFS Computer Name: MAURICE | User Name: Nightmare | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. http [open] -- "C:\Programme\Google\Chrome\Application\chrome.exe" -- "%1" https [open] -- "C:\Programme\Google\Chrome\Application\chrome.exe" -- "%1" piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 1 "FirewallOverride" = 1 "UacDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "FirewallOverride" = 1 "UpdatesDisableNotify" = 1 "UacDisableNotify" = 1 ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "E:\Downloads u. Wichtige Programme\Programme\Google Earth\GoogleEarthWin.exe" = E:\Downloads u. Wichtige Programme\Programme\Google Earth\GoogleEarthWin.exe:*:Enabled:ipsec -- () "C:\WINDOWS\Explorer.EXE" = C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec -- (Microsoft Corporation) "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winoqmybm.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winoqmybm.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\qkrlfq.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\qkrlfq.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winxhqms.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winxhqms.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\oeha.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\oeha.exe:*:Enabled:ipsec "E:\Downloads u. Wichtige Programme\Programme\utorrent\uTorrent.exe" = E:\Downloads u. Wichtige Programme\Programme\utorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.) "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wf74e8.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wf74e8.exe:*:Enabled:ipsec "E:\Downloads u. Wichtige Programme\Programme\Tunngle\Tunngle\TnglCtrl.exe" = E:\Downloads u. Wichtige Programme\Programme\Tunngle\Tunngle\TnglCtrl.exe:*:Enabled:Tunngle Service -- (Tunngle.net GmbH) "E:\Downloads u. Wichtige Programme\Programme\Tunngle\Tunngle\Tunngle.exe" = E:\Downloads u. Wichtige Programme\Programme\Tunngle\Tunngle\Tunngle.exe:*:Enabled:Tunngle Client -- (Tunngle.net GmbH) "C:\Programme\TeamViewer\Version6\TeamViewer.exe" = C:\Programme\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application -- (TeamViewer GmbH) "C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe" = C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service -- (TeamViewer GmbH) "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\eojcts.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\eojcts.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpkbuvm.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpkbuvm.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wingnxo.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wingnxo.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winltkgi.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winltkgi.exe:*:Enabled:ipsec "C:\Programme\Google\Update\GoogleUpdate.exe" = C:\Programme\Google\Update\GoogleUpdate.exe:*:Enabled:ipsec "C:\Programme\Google\Chrome\Application\chrome.exe" = C:\Programme\Google\Chrome\Application\chrome.exe:*:Enabled:ipsec "E:\Downloads u. Wichtige Programme\Programme\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamgui.exe" = E:\Downloads u. Wichtige Programme\Programme\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamgui.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpwulo.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpwulo.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\iyinw.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\iyinw.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winkmvdhl.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winkmvdhl.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\pmmvy.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\pmmvy.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w143a19.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w143a19.exe:*:Enabled:ipsec "C:\WINDOWS\Mixer.exe" = C:\WINDOWS\Mixer.exe:*:Enabled:ipsec "C:\Programme\Malwarebytes' Anti-Malware\mbam.exe" = C:\Programme\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:ipsec -- (Malwarebytes Corporation) "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winudusom.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winudusom.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\bnuqau.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\bnuqau.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\tkbn.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\tkbn.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w90478.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w90478.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winaspki.exe" = C:\WINDOWS\TEMP\winaspki.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\gaxmu.exe" = C:\WINDOWS\TEMP\gaxmu.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winokuals.exe" = C:\WINDOWS\TEMP\winokuals.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winbdheoy.exe" = C:\WINDOWS\TEMP\winbdheoy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w80151.exe" = C:\WINDOWS\TEMP\w80151.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winkxacqi.exe" = C:\WINDOWS\TEMP\winkxacqi.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winborhuh.exe" = C:\WINDOWS\TEMP\winborhuh.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\mspt.exe" = C:\WINDOWS\TEMP\mspt.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ttyl.exe" = C:\WINDOWS\TEMP\ttyl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winmvuhi.exe" = C:\WINDOWS\TEMP\winmvuhi.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\hyneu.exe" = C:\WINDOWS\TEMP\hyneu.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wingdqy.exe" = C:\WINDOWS\TEMP\wingdqy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winmemajw.exe" = C:\WINDOWS\TEMP\winmemajw.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winmrpfqj.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winmrpfqj.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\uyaex.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\uyaex.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winnjnf.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winnjnf.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\qtvh.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\qtvh.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w8c925.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w8c925.exe:*:Enabled:ipsec "E:\Downloads u. Wichtige Programme\Downloads\WinFuture_WinXPsp3_UpdatePack_3.30_Februar-2011-Upgrade.exe" = E:\Downloads u. Wichtige Programme\Downloads\WinFuture_WinXPsp3_UpdatePack_3.30_Februar-2011-Upgrade.exe:*:Enabled:ipsec -- () "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\7zS35.tmp\Setup.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\7zS35.tmp\Setup.exe:*:Enabled:ipsec -- () "C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" = C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe:*:Enabled:ipsec -- (Advanced Micro Devices, Inc.) "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\atcve.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\atcve.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winuvoc.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winuvoc.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winxfljr.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winxfljr.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winfvxau.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winfvxau.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w7fc5f.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w7fc5f.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winahvvr.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winahvvr.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winxyhhn.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winxyhhn.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winbpfo.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winbpfo.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\fqiy.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\fqiy.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w7cf34.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w7cf34.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winemxkf.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winemxkf.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winhmlgee.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winhmlgee.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winctto.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winctto.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winlkkptn.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winlkkptn.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\sabjnw.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\sabjnw.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\svikv.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\svikv.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\xbpxj.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\xbpxj.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winrbnve.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winrbnve.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winovlh.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winovlh.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\uyvpob.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\uyvpob.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\sths.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\sths.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winlaaap.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winlaaap.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winsfcxjc.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winsfcxjc.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winohdl.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winohdl.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\jtlu.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\jtlu.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\fdyng.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\fdyng.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wintjlk.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wintjlk.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\ligu.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\ligu.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winrdtcxf.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winrdtcxf.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\yexklk.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\yexklk.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winbuyf.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winbuyf.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winujva.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winujva.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winuxtnsc.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winuxtnsc.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\gdvwiq.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\gdvwiq.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winapme.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winapme.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpfjrv.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpfjrv.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wykda.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wykda.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpwin.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpwin.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winqtyayq.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winqtyayq.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\mpsx.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\mpsx.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\gqgl.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\gqgl.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\hqnsmv.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\hqnsmv.exe:*:Enabled:ipsec "C:\Programme\Mozilla Firefox\firefox.exe" = C:\Programme\Mozilla Firefox\firefox.exe:*:Enabled:ipsec -- (Mozilla Corporation) "C:\Programme\Yahoo!\Widgets\YahooWidgets.exe" = C:\Programme\Yahoo!\Widgets\YahooWidgets.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\bxakp.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\bxakp.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\clcv.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\clcv.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winntrh.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winntrh.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\blbq.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\blbq.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w8a159.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w8a159.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winrhic.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winrhic.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wingatpsn.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wingatpsn.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\hgkm.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\hgkm.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\qqjk.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\qqjk.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpjkd.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpjkd.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\ujubn.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\ujubn.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winadjeif.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winadjeif.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winxhfrh.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winxhfrh.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\ttwkk.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\ttwkk.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\bquk.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\bquk.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winjecvi.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winjecvi.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w7ce79.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w7ce79.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winiqrl.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winiqrl.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winmiwuv.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winmiwuv.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\dnpet.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\dnpet.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\uyditg.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\uyditg.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\fvud.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\fvud.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winbqvaa.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winbqvaa.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winknxkt.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winknxkt.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winurssoj.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winurssoj.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w80f7a.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w80f7a.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\afohn.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\afohn.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winsetn.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winsetn.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winroml.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winroml.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\fgvy.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\fgvy.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winjvrdb.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winjvrdb.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wininqt.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wininqt.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\xomao.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\xomao.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\cevquc.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\cevquc.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w793c2.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w793c2.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\windeuvi.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\windeuvi.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winulcr.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winulcr.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winmvydo.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winmvydo.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winyygr.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winyygr.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\edvxy.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\edvxy.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpsccdy.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpsccdy.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winkndpgh.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winkndpgh.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\kuqxb.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\kuqxb.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\jvvunq.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\jvvunq.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wincrasex.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\wincrasex.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\lmryq.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\lmryq.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winrorst.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winrorst.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winlrkafw.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winlrkafw.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winvfmhp.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winvfmhp.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winrfvlkx.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winrfvlkx.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winjeng.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winjeng.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\dhhkme.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\dhhkme.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpwvo.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winpwvo.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winplqodv.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winplqodv.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\afban.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\afban.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w814c9.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w814c9.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winefax.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winefax.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winraac.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winraac.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winckayom.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winckayom.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\somw.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\somw.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winnhdjrc.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winnhdjrc.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winhwkuu.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winhwkuu.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\yhvj.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\yhvj.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winvfdkh.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winvfdkh.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winmkcvj.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winmkcvj.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winovlse.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winovlse.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winonyj.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winonyj.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winvbhbsk.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winvbhbsk.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\gjpcp.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\gjpcp.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winanmnda.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winanmnda.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\xgue.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\xgue.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\qbgr.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\qbgr.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\qeexh.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\qeexh.exe:*:Enabled:ipsec -- () "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winlwkq.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winlwkq.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\estcof.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\estcof.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winiqind.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winiqind.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w7ce89.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\w7ce89.exe:*:Enabled:ipsec -- () "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winaiajkr.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winaiajkr.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winimbje.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winimbje.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winhabj.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winhabj.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winjrsyt.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winjrsyt.exe:*:Enabled:ipsec "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winskotd.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winskotd.exe:*:Enabled:ipsec -- () "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\phsbm.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\phsbm.exe:*:Enabled:ipsec -- () "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winsujwqg.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\winsujwqg.exe:*:Enabled:ipsec -- () "C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\anngr.exe" = C:\DOKUME~1\NIGHTM~1\LOKALE~1\Temp\anngr.exe:*:Enabled:ipsec -- () "C:\WINDOWS\TEMP\winbqtnae.exe" = C:\WINDOWS\TEMP\winbqtnae.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winlsji.exe" = C:\WINDOWS\TEMP\winlsji.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\dyxyf.exe" = C:\WINDOWS\TEMP\dyxyf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winfpmna.exe" = C:\WINDOWS\TEMP\winfpmna.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w6e69a.exe" = C:\WINDOWS\TEMP\w6e69a.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\windcfni.exe" = C:\WINDOWS\TEMP\windcfni.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winvpgj.exe" = C:\WINDOWS\TEMP\winvpgj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\windyys.exe" = C:\WINDOWS\TEMP\windyys.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winwyhje.exe" = C:\WINDOWS\TEMP\winwyhje.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\rmwaah.exe" = C:\WINDOWS\TEMP\rmwaah.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\gsmpmh.exe" = C:\WINDOWS\TEMP\gsmpmh.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\hmckxc.exe" = C:\WINDOWS\TEMP\hmckxc.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\pajiq.exe" = C:\WINDOWS\TEMP\pajiq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winnbnsr.exe" = C:\WINDOWS\TEMP\winnbnsr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ndfrvx.exe" = C:\WINDOWS\TEMP\ndfrvx.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\oxttxp.exe" = C:\WINDOWS\TEMP\oxttxp.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winaeht.exe" = C:\WINDOWS\TEMP\winaeht.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w75477.exe" = C:\WINDOWS\TEMP\w75477.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\windluov.exe" = C:\WINDOWS\TEMP\windluov.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winhkxf.exe" = C:\WINDOWS\TEMP\winhkxf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\xqmck.exe" = C:\WINDOWS\TEMP\xqmck.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\xujqm.exe" = C:\WINDOWS\TEMP\xujqm.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\gpicbb.exe" = C:\WINDOWS\TEMP\gpicbb.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winhgorqa.exe" = C:\WINDOWS\TEMP\winhgorqa.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wincmmga.exe" = C:\WINDOWS\TEMP\wincmmga.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\windhcig.exe" = C:\WINDOWS\TEMP\windhcig.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w7a0e1.exe" = C:\WINDOWS\TEMP\w7a0e1.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\nmdo.exe" = C:\WINDOWS\TEMP\nmdo.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winghle.exe" = C:\WINDOWS\TEMP\winghle.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winnnngym.exe" = C:\WINDOWS\TEMP\winnnngym.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qkneg.exe" = C:\WINDOWS\TEMP\qkneg.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w74a64.exe" = C:\WINDOWS\TEMP\w74a64.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winqxjcrf.exe" = C:\WINDOWS\TEMP\winqxjcrf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winpjsdjd.exe" = C:\WINDOWS\TEMP\winpjsdjd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\esqyh.exe" = C:\WINDOWS\TEMP\esqyh.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winxmvip.exe" = C:\WINDOWS\TEMP\winxmvip.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winmbybxf.exe" = C:\WINDOWS\TEMP\winmbybxf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winhlejg.exe" = C:\WINDOWS\TEMP\winhlejg.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\mdmsmc.exe" = C:\WINDOWS\TEMP\mdmsmc.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\grsg.exe" = C:\WINDOWS\TEMP\grsg.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winkjtx.exe" = C:\WINDOWS\TEMP\winkjtx.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\hldj.exe" = C:\WINDOWS\TEMP\hldj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\shwim.exe" = C:\WINDOWS\TEMP\shwim.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winlpbjt.exe" = C:\WINDOWS\TEMP\winlpbjt.exe:*:Enabled:ipsec "E:\Spiele\Crysis 2 Beta\bin32\Crysis2Launcher.exe" = E:\Spiele\Crysis 2 Beta\bin32\Crysis2Launcher.exe:*:Enabled:Crysis® 2 Demo "C:\WINDOWS\TEMP\w785d7.exe" = C:\WINDOWS\TEMP\w785d7.exe:*:Enabled:ipsec "C:\Programme\Xfire\Xfire.exe" = C:\Programme\Xfire\Xfire.exe:*:Enabled:Xfire -- (Xfire Inc.) "E:\Spiele\COD4\iw3mp.exe" = E:\Spiele\COD4\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) -- () "C:\WINDOWS\TEMP\winvwfwm.exe" = C:\WINDOWS\TEMP\winvwfwm.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winucyamd.exe" = C:\WINDOWS\TEMP\winucyamd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winwehm.exe" = C:\WINDOWS\TEMP\winwehm.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wingihao.exe" = C:\WINDOWS\TEMP\wingihao.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winsfbrq.exe" = C:\WINDOWS\TEMP\winsfbrq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wintujqva.exe" = C:\WINDOWS\TEMP\wintujqva.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wingojcdr.exe" = C:\WINDOWS\TEMP\wingojcdr.exe:*:Enabled:ipsec "E:\Spiele\Crysis 2 Beta\bin32\Crysis2Demo.exe" = E:\Spiele\Crysis 2 Beta\bin32\Crysis2Demo.exe:*:Enabled:Crysis2Demo "C:\WINDOWS\TEMP\wingapv.exe" = C:\WINDOWS\TEMP\wingapv.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\mqotkc.exe" = C:\WINDOWS\TEMP\mqotkc.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winmqxj.exe" = C:\WINDOWS\TEMP\winmqxj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qnsjw.exe" = C:\WINDOWS\TEMP\qnsjw.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qmamy.exe" = C:\WINDOWS\TEMP\qmamy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winlfmtxs.exe" = C:\WINDOWS\TEMP\winlfmtxs.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\htfq.exe" = C:\WINDOWS\TEMP\htfq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winocbidk.exe" = C:\WINDOWS\TEMP\winocbidk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\cywqc.exe" = C:\WINDOWS\TEMP\cywqc.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\xhnfye.exe" = C:\WINDOWS\TEMP\xhnfye.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ljfm.exe" = C:\WINDOWS\TEMP\ljfm.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w75060.exe" = C:\WINDOWS\TEMP\w75060.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\tdqr.exe" = C:\WINDOWS\TEMP\tdqr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\liwjo.exe" = C:\WINDOWS\TEMP\liwjo.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\kyssim.exe" = C:\WINDOWS\TEMP\kyssim.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winmbcdr.exe" = C:\WINDOWS\TEMP\winmbcdr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w78f9b.exe" = C:\WINDOWS\TEMP\w78f9b.exe:*:Enabled:ipsec "E:\Spiele\Crysis 2 Demo\bin32\Crysis2Launcher.exe" = E:\Spiele\Crysis 2 Demo\bin32\Crysis2Launcher.exe:*:Enabled:Crysis® 2 Demo -- (Crytek GmbH) "E:\Spiele\Crysis 2 Demo\bin32\Crysis2Demo.exe" = E:\Spiele\Crysis 2 Demo\bin32\Crysis2Demo.exe:*:Enabled:Crysis2Demo -- (Crytek GmbH) "C:\WINDOWS\TEMP\wnrvb.exe" = C:\WINDOWS\TEMP\wnrvb.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\labhg.exe" = C:\WINDOWS\TEMP\labhg.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\uvxdqk.exe" = C:\WINDOWS\TEMP\uvxdqk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\hfnae.exe" = C:\WINDOWS\TEMP\hfnae.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winrvawtb.exe" = C:\WINDOWS\TEMP\winrvawtb.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\uppx.exe" = C:\WINDOWS\TEMP\uppx.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winqlwy.exe" = C:\WINDOWS\TEMP\winqlwy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winoeyr.exe" = C:\WINDOWS\TEMP\winoeyr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w7058b.exe" = C:\WINDOWS\TEMP\w7058b.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winvgia.exe" = C:\WINDOWS\TEMP\winvgia.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winayybl.exe" = C:\WINDOWS\TEMP\winayybl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winuwxmyd.exe" = C:\WINDOWS\TEMP\winuwxmyd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wyts.exe" = C:\WINDOWS\TEMP\wyts.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winhcosph.exe" = C:\WINDOWS\TEMP\winhcosph.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winfmao.exe" = C:\WINDOWS\TEMP\winfmao.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winlddy.exe" = C:\WINDOWS\TEMP\winlddy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\tsgvd.exe" = C:\WINDOWS\TEMP\tsgvd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w79c5d.exe" = C:\WINDOWS\TEMP\w79c5d.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\vdkdjg.exe" = C:\WINDOWS\TEMP\vdkdjg.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\gjefo.exe" = C:\WINDOWS\TEMP\gjefo.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\gwftd.exe" = C:\WINDOWS\TEMP\gwftd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wininxk.exe" = C:\WINDOWS\TEMP\wininxk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w79f1c.exe" = C:\WINDOWS\TEMP\w79f1c.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\jhhchj.exe" = C:\WINDOWS\TEMP\jhhchj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ulrxf.exe" = C:\WINDOWS\TEMP\ulrxf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qhnfj.exe" = C:\WINDOWS\TEMP\qhnfj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winydea.exe" = C:\WINDOWS\TEMP\winydea.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winrolv.exe" = C:\WINDOWS\TEMP\winrolv.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wintdkckm.exe" = C:\WINDOWS\TEMP\wintdkckm.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\nwyqsa.exe" = C:\WINDOWS\TEMP\nwyqsa.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\odrau.exe" = C:\WINDOWS\TEMP\odrau.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winynspw.exe" = C:\WINDOWS\TEMP\winynspw.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ggvk.exe" = C:\WINDOWS\TEMP\ggvk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\rwhnin.exe" = C:\WINDOWS\TEMP\rwhnin.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\pygvn.exe" = C:\WINDOWS\TEMP\pygvn.exe:*:Enabled:ipsec "C:\Programme\Google\Google Earth\client\googleearth.exe" = C:\Programme\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google) "C:\WINDOWS\TEMP\lmymko.exe" = C:\WINDOWS\TEMP\lmymko.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\brqsll.exe" = C:\WINDOWS\TEMP\brqsll.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\poqfsm.exe" = C:\WINDOWS\TEMP\poqfsm.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\lwryc.exe" = C:\WINDOWS\TEMP\lwryc.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winprauuq.exe" = C:\WINDOWS\TEMP\winprauuq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winygixl.exe" = C:\WINDOWS\TEMP\winygixl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winfpgfpj.exe" = C:\WINDOWS\TEMP\winfpgfpj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winaljnj.exe" = C:\WINDOWS\TEMP\winaljnj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\cvgxh.exe" = C:\WINDOWS\TEMP\cvgxh.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\etjrn.exe" = C:\WINDOWS\TEMP\etjrn.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winqwlmui.exe" = C:\WINDOWS\TEMP\winqwlmui.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winngqvvk.exe" = C:\WINDOWS\TEMP\winngqvvk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\rootxq.exe" = C:\WINDOWS\TEMP\rootxq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\quvxcv.exe" = C:\WINDOWS\TEMP\quvxcv.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winkyqt.exe" = C:\WINDOWS\TEMP\winkyqt.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winkveim.exe" = C:\WINDOWS\TEMP\winkveim.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winweukc.exe" = C:\WINDOWS\TEMP\winweukc.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winvwgww.exe" = C:\WINDOWS\TEMP\winvwgww.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ksiryi.exe" = C:\WINDOWS\TEMP\ksiryi.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\gssda.exe" = C:\WINDOWS\TEMP\gssda.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w7ce5a.exe" = C:\WINDOWS\TEMP\w7ce5a.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winlrkq.exe" = C:\WINDOWS\TEMP\winlrkq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winrewkfj.exe" = C:\WINDOWS\TEMP\winrewkfj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winfuevhu.exe" = C:\WINDOWS\TEMP\winfuevhu.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winkfdmw.exe" = C:\WINDOWS\TEMP\winkfdmw.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\rufn.exe" = C:\WINDOWS\TEMP\rufn.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winjjha.exe" = C:\WINDOWS\TEMP\winjjha.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winyoyh.exe" = C:\WINDOWS\TEMP\winyoyh.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\windnia.exe" = C:\WINDOWS\TEMP\windnia.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winxbafk.exe" = C:\WINDOWS\TEMP\winxbafk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wincnwnw.exe" = C:\WINDOWS\TEMP\wincnwnw.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\uinyht.exe" = C:\WINDOWS\TEMP\uinyht.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\mgbufk.exe" = C:\WINDOWS\TEMP\mgbufk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w709e1.exe" = C:\WINDOWS\TEMP\w709e1.exe:*:Enabled:ipsec "E:\Spiele\Steam\SteamApps\_nightmare95_\counter-strike source\hl2.exe" = E:\Spiele\Steam\SteamApps\_nightmare95_\counter-strike source\hl2.exe:*:Enabled:Counter-Strike: Source -- () "C:\WINDOWS\TEMP\winpuljcy.exe" = C:\WINDOWS\TEMP\winpuljcy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ceucil.exe" = C:\WINDOWS\TEMP\ceucil.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\gcoon.exe" = C:\WINDOWS\TEMP\gcoon.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winkuudj.exe" = C:\WINDOWS\TEMP\winkuudj.exe:*:Enabled:ipsec "E:\Spiele\Dead Space 2\deadspace2.exe" = E:\Spiele\Dead Space 2\deadspace2.exe:*:Enabled:Dead Space™ 2 -- (Electronic Arts Inc.) "C:\WINDOWS\TEMP\lomdob.exe" = C:\WINDOWS\TEMP\lomdob.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wintsdiek.exe" = C:\WINDOWS\TEMP\wintsdiek.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\mknmy.exe" = C:\WINDOWS\TEMP\mknmy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wingmxfcc.exe" = C:\WINDOWS\TEMP\wingmxfcc.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\hbqj.exe" = C:\WINDOWS\TEMP\hbqj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winfduvgb.exe" = C:\WINDOWS\TEMP\winfduvgb.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winnjyq.exe" = C:\WINDOWS\TEMP\winnjyq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winaqod.exe" = C:\WINDOWS\TEMP\winaqod.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winvkmgj.exe" = C:\WINDOWS\TEMP\winvkmgj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\aniqyx.exe" = C:\WINDOWS\TEMP\aniqyx.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winmmiqdm.exe" = C:\WINDOWS\TEMP\winmmiqdm.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\cudtf.exe" = C:\WINDOWS\TEMP\cudtf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\meiqa.exe" = C:\WINDOWS\TEMP\meiqa.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\lqrwuq.exe" = C:\WINDOWS\TEMP\lqrwuq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winltmms.exe" = C:\WINDOWS\TEMP\winltmms.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qknof.exe" = C:\WINDOWS\TEMP\qknof.exe:*:Enabled:ipsec "E:\Spiele\Bulletstorm\Binaries\Win32\ShippingPC-StormGame.exe" = E:\Spiele\Bulletstorm\Binaries\Win32\ShippingPC-StormGame.exe:*:Enabled:Bulletstorm -- (Epic Games, Inc.) "C:\WINDOWS\TEMP\wingddf.exe" = C:\WINDOWS\TEMP\wingddf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winncjus.exe" = C:\WINDOWS\TEMP\winncjus.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winfqwjhl.exe" = C:\WINDOWS\TEMP\winfqwjhl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ednrb.exe" = C:\WINDOWS\TEMP\ednrb.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winhipujr.exe" = C:\WINDOWS\TEMP\winhipujr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winusjc.exe" = C:\WINDOWS\TEMP\winusjc.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\twtbmu.exe" = C:\WINDOWS\TEMP\twtbmu.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\hbcg.exe" = C:\WINDOWS\TEMP\hbcg.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winxjgepw.exe" = C:\WINDOWS\TEMP\winxjgepw.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qmxe.exe" = C:\WINDOWS\TEMP\qmxe.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\nsgg.exe" = C:\WINDOWS\TEMP\nsgg.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winyapirc.exe" = C:\WINDOWS\TEMP\winyapirc.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winrpmevk.exe" = C:\WINDOWS\TEMP\winrpmevk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wfptk.exe" = C:\WINDOWS\TEMP\wfptk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winyovmr.exe" = C:\WINDOWS\TEMP\winyovmr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qwugo.exe" = C:\WINDOWS\TEMP\qwugo.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winbfqfy.exe" = C:\WINDOWS\TEMP\winbfqfy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wingioec.exe" = C:\WINDOWS\TEMP\wingioec.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\rdfjn.exe" = C:\WINDOWS\TEMP\rdfjn.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\vbkf.exe" = C:\WINDOWS\TEMP\vbkf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winarupo.exe" = C:\WINDOWS\TEMP\winarupo.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winkjosy.exe" = C:\WINDOWS\TEMP\winkjosy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winahkugp.exe" = C:\WINDOWS\TEMP\winahkugp.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wineokql.exe" = C:\WINDOWS\TEMP\wineokql.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winbrnyei.exe" = C:\WINDOWS\TEMP\winbrnyei.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winigsu.exe" = C:\WINDOWS\TEMP\winigsu.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winthkmv.exe" = C:\WINDOWS\TEMP\winthkmv.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\cmwqnd.exe" = C:\WINDOWS\TEMP\cmwqnd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\dpgd.exe" = C:\WINDOWS\TEMP\dpgd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winfjetj.exe" = C:\WINDOWS\TEMP\winfjetj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wintlwg.exe" = C:\WINDOWS\TEMP\wintlwg.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winwouqlb.exe" = C:\WINDOWS\TEMP\winwouqlb.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winhticrb.exe" = C:\WINDOWS\TEMP\winhticrb.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winxqbv.exe" = C:\WINDOWS\TEMP\winxqbv.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ijdvw.exe" = C:\WINDOWS\TEMP\ijdvw.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\buirqj.exe" = C:\WINDOWS\TEMP\buirqj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winsapgh.exe" = C:\WINDOWS\TEMP\winsapgh.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\plbfho.exe" = C:\WINDOWS\TEMP\plbfho.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winfsvdpw.exe" = C:\WINDOWS\TEMP\winfsvdpw.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\egivt.exe" = C:\WINDOWS\TEMP\egivt.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winhkofnq.exe" = C:\WINDOWS\TEMP\winhkofnq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winukjge.exe" = C:\WINDOWS\TEMP\winukjge.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winxlsvtu.exe" = C:\WINDOWS\TEMP\winxlsvtu.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winounp.exe" = C:\WINDOWS\TEMP\winounp.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qhfwj.exe" = C:\WINDOWS\TEMP\qhfwj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wingyhvlv.exe" = C:\WINDOWS\TEMP\wingyhvlv.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\xmoku.exe" = C:\WINDOWS\TEMP\xmoku.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\nbagh.exe" = C:\WINDOWS\TEMP\nbagh.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winhaqto.exe" = C:\WINDOWS\TEMP\winhaqto.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\reqwkd.exe" = C:\WINDOWS\TEMP\reqwkd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\xnhant.exe" = C:\WINDOWS\TEMP\xnhant.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\esps.exe" = C:\WINDOWS\TEMP\esps.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\egill.exe" = C:\WINDOWS\TEMP\egill.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\dabf.exe" = C:\WINDOWS\TEMP\dabf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wintclyx.exe" = C:\WINDOWS\TEMP\wintclyx.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\avikis.exe" = C:\WINDOWS\TEMP\avikis.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\yojkx.exe" = C:\WINDOWS\TEMP\yojkx.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winicxuwf.exe" = C:\WINDOWS\TEMP\winicxuwf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wingxrapf.exe" = C:\WINDOWS\TEMP\wingxrapf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wlbk.exe" = C:\WINDOWS\TEMP\wlbk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w73621.exe" = C:\WINDOWS\TEMP\w73621.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\nqej.exe" = C:\WINDOWS\TEMP\nqej.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winseig.exe" = C:\WINDOWS\TEMP\winseig.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winhikk.exe" = C:\WINDOWS\TEMP\winhikk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\gcude.exe" = C:\WINDOWS\TEMP\gcude.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\kapip.exe" = C:\WINDOWS\TEMP\kapip.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winamqj.exe" = C:\WINDOWS\TEMP\winamqj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winjwme.exe" = C:\WINDOWS\TEMP\winjwme.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winkjsegn.exe" = C:\WINDOWS\TEMP\winkjsegn.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\pfmq.exe" = C:\WINDOWS\TEMP\pfmq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winobfxsm.exe" = C:\WINDOWS\TEMP\winobfxsm.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\svlhcr.exe" = C:\WINDOWS\TEMP\svlhcr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\rjxckb.exe" = C:\WINDOWS\TEMP\rjxckb.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winjqjybt.exe" = C:\WINDOWS\TEMP\winjqjybt.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winodfb.exe" = C:\WINDOWS\TEMP\winodfb.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winteusp.exe" = C:\WINDOWS\TEMP\winteusp.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winqhwcg.exe" = C:\WINDOWS\TEMP\winqhwcg.exe:*:Enabled:ipsec "E:\Spiele\World of Warcraft\World of Warcraft\Launcher.exe" = E:\Spiele\World of Warcraft\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment) "C:\WINDOWS\TEMP\wjky.exe" = C:\WINDOWS\TEMP\wjky.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\woiqpd.exe" = C:\WINDOWS\TEMP\woiqpd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\kung.exe" = C:\WINDOWS\TEMP\kung.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\fkjex.exe" = C:\WINDOWS\TEMP\fkjex.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winvfxxca.exe" = C:\WINDOWS\TEMP\winvfxxca.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\windkkpf.exe" = C:\WINDOWS\TEMP\windkkpf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\tixsk.exe" = C:\WINDOWS\TEMP\tixsk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wkam.exe" = C:\WINDOWS\TEMP\wkam.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qfhyfu.exe" = C:\WINDOWS\TEMP\qfhyfu.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winiojscv.exe" = C:\WINDOWS\TEMP\winiojscv.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winpfvbnj.exe" = C:\WINDOWS\TEMP\winpfvbnj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\jrefu.exe" = C:\WINDOWS\TEMP\jrefu.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\tykelw.exe" = C:\WINDOWS\TEMP\tykelw.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winwqotpo.exe" = C:\WINDOWS\TEMP\winwqotpo.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winupbwev.exe" = C:\WINDOWS\TEMP\winupbwev.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wininei.exe" = C:\WINDOWS\TEMP\wininei.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winaebaw.exe" = C:\WINDOWS\TEMP\winaebaw.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wesusf.exe" = C:\WINDOWS\TEMP\wesusf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\iaxay.exe" = C:\WINDOWS\TEMP\iaxay.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winbtur.exe" = C:\WINDOWS\TEMP\winbtur.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\igkl.exe" = C:\WINDOWS\TEMP\igkl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\kotkms.exe" = C:\WINDOWS\TEMP\kotkms.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winuephpg.exe" = C:\WINDOWS\TEMP\winuephpg.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wincjnvi.exe" = C:\WINDOWS\TEMP\wincjnvi.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winmatxs.exe" = C:\WINDOWS\TEMP\winmatxs.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\vjwmii.exe" = C:\WINDOWS\TEMP\vjwmii.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\scfrai.exe" = C:\WINDOWS\TEMP\scfrai.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winhoxmp.exe" = C:\WINDOWS\TEMP\winhoxmp.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wintxwgr.exe" = C:\WINDOWS\TEMP\wintxwgr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\gmkr.exe" = C:\WINDOWS\TEMP\gmkr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wintbkbv.exe" = C:\WINDOWS\TEMP\wintbkbv.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\uake.exe" = C:\WINDOWS\TEMP\uake.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\opfel.exe" = C:\WINDOWS\TEMP\opfel.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\dudl.exe" = C:\WINDOWS\TEMP\dudl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winfbhwfs.exe" = C:\WINDOWS\TEMP\winfbhwfs.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\sfwlq.exe" = C:\WINDOWS\TEMP\sfwlq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\detohc.exe" = C:\WINDOWS\TEMP\detohc.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wchr.exe" = C:\WINDOWS\TEMP\wchr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\cmeo.exe" = C:\WINDOWS\TEMP\cmeo.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\dwcjns.exe" = C:\WINDOWS\TEMP\dwcjns.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winwqpdf.exe" = C:\WINDOWS\TEMP\winwqpdf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\cxutuk.exe" = C:\WINDOWS\TEMP\cxutuk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\uapmjl.exe" = C:\WINDOWS\TEMP\uapmjl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\lntd.exe" = C:\WINDOWS\TEMP\lntd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winwojj.exe" = C:\WINDOWS\TEMP\winwojj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qrfij.exe" = C:\WINDOWS\TEMP\qrfij.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winakiv.exe" = C:\WINDOWS\TEMP\winakiv.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\kibpp.exe" = C:\WINDOWS\TEMP\kibpp.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\hchxwa.exe" = C:\WINDOWS\TEMP\hchxwa.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\windwwr.exe" = C:\WINDOWS\TEMP\windwwr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winbxkx.exe" = C:\WINDOWS\TEMP\winbxkx.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winxvvjb.exe" = C:\WINDOWS\TEMP\winxvvjb.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winngag.exe" = C:\WINDOWS\TEMP\winngag.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winkmyit.exe" = C:\WINDOWS\TEMP\winkmyit.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wincjnpp.exe" = C:\WINDOWS\TEMP\wincjnpp.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\windciuin.exe" = C:\WINDOWS\TEMP\windciuin.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\nxfvi.exe" = C:\WINDOWS\TEMP\nxfvi.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winvijby.exe" = C:\WINDOWS\TEMP\winvijby.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\rrhpj.exe" = C:\WINDOWS\TEMP\rrhpj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winxqwk.exe" = C:\WINDOWS\TEMP\winxqwk.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\evdyom.exe" = C:\WINDOWS\TEMP\evdyom.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\rgmhrh.exe" = C:\WINDOWS\TEMP\rgmhrh.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wincvofst.exe" = C:\WINDOWS\TEMP\wincvofst.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wincdfu.exe" = C:\WINDOWS\TEMP\wincdfu.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wail.exe" = C:\WINDOWS\TEMP\wail.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wineftw.exe" = C:\WINDOWS\TEMP\wineftw.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winbkbdfp.exe" = C:\WINDOWS\TEMP\winbkbdfp.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w760ac.exe" = C:\WINDOWS\TEMP\w760ac.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winfnfaj.exe" = C:\WINDOWS\TEMP\winfnfaj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\srykfa.exe" = C:\WINDOWS\TEMP\srykfa.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\nissoq.exe" = C:\WINDOWS\TEMP\nissoq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winqfxd.exe" = C:\WINDOWS\TEMP\winqfxd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winjiyn.exe" = C:\WINDOWS\TEMP\winjiyn.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\hqsspf.exe" = C:\WINDOWS\TEMP\hqsspf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winuiymcq.exe" = C:\WINDOWS\TEMP\winuiymcq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wincnoy.exe" = C:\WINDOWS\TEMP\wincnoy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winvdxww.exe" = C:\WINDOWS\TEMP\winvdxww.exe:*:Enabled:ipsec -- () "C:\WINDOWS\TEMP\winvgxq.exe" = C:\WINDOWS\TEMP\winvgxq.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ddxhd.exe" = C:\WINDOWS\TEMP\ddxhd.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winiljum.exe" = C:\WINDOWS\TEMP\winiljum.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\w71386.exe" = C:\WINDOWS\TEMP\w71386.exe:*:Enabled:ipsec -- () "C:\WINDOWS\TEMP\windxajcl.exe" = C:\WINDOWS\TEMP\windxajcl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winmyvin.exe" = C:\WINDOWS\TEMP\winmyvin.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winoqub.exe" = C:\WINDOWS\TEMP\winoqub.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\hicf.exe" = C:\WINDOWS\TEMP\hicf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\xkjjy.exe" = C:\WINDOWS\TEMP\xkjjy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\nbim.exe" = C:\WINDOWS\TEMP\nbim.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winpjed.exe" = C:\WINDOWS\TEMP\winpjed.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winokgwn.exe" = C:\WINDOWS\TEMP\winokgwn.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\windrpf.exe" = C:\WINDOWS\TEMP\windrpf.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\phpenn.exe" = C:\WINDOWS\TEMP\phpenn.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winxwtv.exe" = C:\WINDOWS\TEMP\winxwtv.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\mfqj.exe" = C:\WINDOWS\TEMP\mfqj.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winviej.exe" = C:\WINDOWS\TEMP\winviej.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ssmcks.exe" = C:\WINDOWS\TEMP\ssmcks.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\opsedl.exe" = C:\WINDOWS\TEMP\opsedl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winpnup.exe" = C:\WINDOWS\TEMP\winpnup.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winlacve.exe" = C:\WINDOWS\TEMP\winlacve.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\juyl.exe" = C:\WINDOWS\TEMP\juyl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winassh.exe" = C:\WINDOWS\TEMP\winassh.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qrfdep.exe" = C:\WINDOWS\TEMP\qrfdep.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\rboru.exe" = C:\WINDOWS\TEMP\rboru.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winxntkfl.exe" = C:\WINDOWS\TEMP\winxntkfl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\dlbkqx.exe" = C:\WINDOWS\TEMP\dlbkqx.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\windimy.exe" = C:\WINDOWS\TEMP\windimy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\ywctr.exe" = C:\WINDOWS\TEMP\ywctr.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winapve.exe" = C:\WINDOWS\TEMP\winapve.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\windeeaho.exe" = C:\WINDOWS\TEMP\windeeaho.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wintsao.exe" = C:\WINDOWS\TEMP\wintsao.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winmrbwhl.exe" = C:\WINDOWS\TEMP\winmrbwhl.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\rtdhh.exe" = C:\WINDOWS\TEMP\rtdhh.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winwlpkgo.exe" = C:\WINDOWS\TEMP\winwlpkgo.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\xkkfbt.exe" = C:\WINDOWS\TEMP\xkkfbt.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wincxcro.exe" = C:\WINDOWS\TEMP\wincxcro.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winryiloy.exe" = C:\WINDOWS\TEMP\winryiloy.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\mnva.exe" = C:\WINDOWS\TEMP\mnva.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\yuoldv.exe" = C:\WINDOWS\TEMP\yuoldv.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\qpyjh.exe" = C:\WINDOWS\TEMP\qpyjh.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winqeag.exe" = C:\WINDOWS\TEMP\winqeag.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winmpypki.exe" = C:\WINDOWS\TEMP\winmpypki.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winnqsked.exe" = C:\WINDOWS\TEMP\winnqsked.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wincvurp.exe" = C:\WINDOWS\TEMP\wincvurp.exe:*:Enabled:ipsec -- () "C:\WINDOWS\TEMP\anqs.exe" = C:\WINDOWS\TEMP\anqs.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\winjqim.exe" = C:\WINDOWS\TEMP\winjqim.exe:*:Enabled:ipsec "C:\WINDOWS\TEMP\wintjrq.exe" = C:\WINDOWS\TEMP\wintjrq.exe:*:Enabled:ipsec ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{03496F77-5835-D529-1ED8-044FCD372E0F}" = HydraVision "{1370D655-9DA3-EF82-FB57-BC5A2DCCD020}" = CCC Help Japanese "{17D6207F-F9F4-1FDE-3F6B-C5B67CFD87C9}" = Catalyst Control Center Graphics Full New "{1BF4CB15-6055-452A-8487-021AE2D91208}" = Crysis® 2 Demo "{1DA18566-1084-CE33-5BC5-A214B8FC0CA4}" = CCC Help Norwegian "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B4D0B5-81C5-ACE0-94CB-72E875B447A4}" = Catalyst Control Center Graphics Previews Common "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3D4AEA8C-3FD2-AB03-9E3A-F040B42E0BA3}" = CCC Help Portuguese "{41785C66-90F2-40CE-8CB5-1C94BFC97280}" = Microsoft Chart Controls for Microsoft .NET Framework 3.5 "{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth "{44136AFD-2559-F68C-10E3-AC269CE942A7}" = CCC Help Danish "{45410935-3E72-472B-8C35-AB1000008200}" = Bulletstorm "{45410935-B52C-468A-A836-0D1000018201}" = BulletStorm "{46942F53-F6B5-E272-6989-0C75BBDF2668}" = CCC Help Chinese Standard "{4B4DDF19-F79C-3C68-CAF2-BD67843E4D19}" = Catalyst Control Center InstallProxy "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{53C7F89D-D6C7-F2CD-497D-C030A30140DB}" = ccc-core-preinstall "{53EBA2A9-50F2-16EB-3A44-C99BFF927032}" = Catalyst Control Center Graphics Light "{5629D545-08E1-516E-F498-082A72A5269D}" = CCC Help Polish "{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync "{5C329FB8-04D8-D32B-18B8-FA7594040FC0}" = CCC Help Dutch "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{62733593-6322-4C89-8B50-F714305A4DC6}" = TubeBox! "{6A0AEB7F-E55B-809B-0D05-F843032B75F7}" = Catalyst Control Center Graphics Full Existing "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{6F05FB49-2086-2FED-E2CC-824C189E9C75}" = CCC Help Russian "{70AA9B4F-64F7-4B0D-ADD8-05802D61AF72}" = Windows Live Toolbar "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{75F440C9-C292-1BA6-9755-C94F800657E9}" = ccc-core-static "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{77FD4E2C-EDDA-D622-6DAA-6DDE7B17DE85}" = Catalyst Control Center Localization All "{7ACC5E2B-B543-2E93-F37D-A1390847FF29}" = CCC Help Thai "{832C9764-D951-059D-05C7-E8EC41A5E510}" = ATI Problem Report Wizard "{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie "{87323561-58BA-4D5B-BADA-A791B69D1705}" = Catalyst Control Center - Branding "{878C6821-18F9-F6A2-42A7-1ACB1A14AF5C}" = CCC Help Hungarian "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update "{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable "{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch "{946CC1D8-6E30-2A7C-3AC1-D433ED4FB00B}" = CCC Help Finnish "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{96D06FDD-6AF4-4309-BC1B-1C9588B0575E}" = Dead Space™ 2 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack "{9CDF34B4-B53E-54B5-9BA9-7FAA41693BF0}" = CCC Help Czech "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{A29549FD-65F3-440C-A552-6B8114CF319D}" = Skype Toolbars "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A60ABB01-915B-E5A4-5120-0976C0D7697F}" = CCC Help English "{A7238DAD-BF6A-3D96-8436-065A1175B39A}" = CCC Help Chinese Traditional "{AE4668DF-BE40-4316-9AFF-E82E3F5A7CC3}" = ccc-utility "{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{C05290B3-B125-2481-BC4D-7C4BE5126DD5}" = CCC Help Korean "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C310995F-B785-4252-6A3B-333BA411DE6B}" = CCC Help French "{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail "{C7817822-57E6-7564-8400-CEF1C8DEF7CA}" = ATI AVIVO Codecs "{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call "{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer "{E2082A6B-2334-2533-A5ED-41B537ECD02A}" = CCC Help German "{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM) "{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1 "{E84FA784-3305-5E34-16C8-51949D03C059}" = Catalyst Control Center InstallProxy "{E9A28E0B-F85A-FFDA-C486-C0D34AD506AF}" = CCC Help Turkish "{EC318F8C-CECC-B31E-44C4-55A1A63E41D5}" = CCC Help Greek "{ECAD020B-3418-E868-FC8D-668FA6C6A019}" = Catalyst Control Center HydraVision Full "{EFCEF949-9821-4759-A573-3EB8C857DF46}" = Windows Live Family Safety "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F2C757C9-C40E-07A0-9397-56A7C66F84F3}" = ATI Catalyst Install Manager "{F4B6FE67-B077-472E-1B06-0D50C8B05206}" = CCC Help Swedish "{F4B70AA9-AA91-4894-4AC5-61A6934CD85B}" = Catalyst Control Center Core Implementation "{F525FDB5-C9D4-6505-ACB9-90C921C83ACD}" = CCC Help Italian "{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE "{FE83F56A-D87F-E70E-AE6E-749DFBE27666}" = CCC Help Spanish "3B18191663CDFABAA2A93D4267E54D683153FF60" = Windows-Treiberpaket - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "DAEMON Tools Pro" = DAEMON Tools Pro "DivX Setup.divx.com" = DivX-Setup "EVEREST Home Edition_is1" = EVEREST Home Edition v2.20 "Fraps" = Fraps "GFWL_{45410935-3E72-472B-8C35-AB1000008200}" = Bulletstorm "ie8" = Windows Internet Explorer 8 "InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch "InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch "InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM) "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MSNINST" = MSN "NVIDIA Drivers" = NVIDIA Drivers "PCI Audio Driver" = PCI Audio Driver "PunkBusterSvc" = PunkBuster Services "SevenMizer" = SevenMizer 2.0.0.0 "Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2 "TeamSpeak 3 Client" = TeamSpeak 3 Client "TeamViewer 6" = TeamViewer 6 "Tunngle beta_is1" = Tunngle beta "uTorrent" = µTorrent "VirtualCloneDrive" = VirtualCloneDrive "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "Xfire" = Xfire (remove only) ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 02.03.2011 03:56:46 | Computer Name = MAURICE | Source = Application Error | ID = 1000 Description = Fehlgeschlagene Anwendung explorer.exe, Version 6.0.2900.5512, fehlgeschlagenes Modul , Version 0.0.0.0, Fehleradresse 0x00000000. Error - 02.03.2011 03:57:00 | Computer Name = MAURICE | Source = VSS | ID = 8193 Description = Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070006. Error - 02.03.2011 03:57:06 | Computer Name = MAURICE | Source = Application Error | ID = 1000 Description = Fehlgeschlagene Anwendung drwtsn32.exe, Version 5.1.2600.0, fehlgeschlagenes Modul dbghelp.dll, Version 5.1.2600.5512, Fehleradresse 0x0001295d. Error - 02.03.2011 04:04:58 | Computer Name = MAURICE | Source = Application Error | ID = 1000 Description = Fehlgeschlagene Anwendung mbam.exe, Version 1.50.1.3, fehlgeschlagenes Modul unknown, Version 0.0.0.0, Fehleradresse 0x00f02f33. Error - 02.03.2011 04:18:21 | Computer Name = MAURICE | Source = EventSystem | ID = 4609 Description = Das COM+-Ereignissystem hat einen ungültigen Rückgabecode während der internen Verarbeitung erkannt. HRESULT war 800706BA von Zeile 44 von f:\xpsp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Wenden Sie sich an den Microsoft-Produktsuppor Error - 03.03.2011 14:42:14 | Computer Name = MAURICE | Source = Application Error | ID = 1000 Description = Fehlgeschlagene Anwendung bioshock2launcher.exe, Version 0.1.0.0, fehlgeschlagenes Modul unknown, Version 0.0.0.0, Fehleradresse 0x00000000. Error - 03.03.2006 15:22:11 | Computer Name = MAURICE | Source = .NET Runtime Optimization Service | ID = 1101 Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: C:\Programme\Windows Live\Writer\WindowsLiveWriter.exe . Error code = 0x8007000b Error - 03.03.2006 17:04:21 | Computer Name = MAURICE | Source = crypt32 | ID = 131083 Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> ist fehlgeschlagen mit dem Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error - 03.03.2006 17:04:21 | Computer Name = MAURICE | Source = crypt32 | ID = 131083 Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> ist fehlgeschlagen mit dem Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error - 03.03.2006 17:04:21 | Computer Name = MAURICE | Source = crypt32 | ID = 131080 Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> ist fehlgeschlagen mit dem Fehler: The server name or address could not be resolved . [ System Events ] Error - 06.03.2011 08:36:30 | Computer Name = MAURICE | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Avira AntiVir Guard" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Starten Sie den Dienst neu.. Error - 06.03.2011 08:36:38 | Computer Name = MAURICE | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Avira AntiVir Guard" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Starten Sie den Dienst neu.. Error - 06.03.2011 08:36:46 | Computer Name = MAURICE | Source = Service Control Manager | ID = 7034 Description = Dienst "Avira AntiVir Guard" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. Error - 07.03.2011 06:04:36 | Computer Name = MAURICE | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Avira AntiVir Guard" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Starten Sie den Dienst neu.. Error - 07.03.2011 06:04:46 | Computer Name = MAURICE | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Avira AntiVir Guard" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Starten Sie den Dienst neu.. Error - 07.03.2011 06:04:58 | Computer Name = MAURICE | Source = Service Control Manager | ID = 7034 Description = Dienst "Avira AntiVir Guard" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. Error - 07.03.2011 07:56:12 | Computer Name = MAURICE | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Avira AntiVir Guard" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Starten Sie den Dienst neu.. Error - 07.03.2011 07:56:20 | Computer Name = MAURICE | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Avira AntiVir Guard" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Starten Sie den Dienst neu.. Error - 07.03.2011 07:56:30 | Computer Name = MAURICE | Source = Service Control Manager | ID = 7034 Description = Dienst "Avira AntiVir Guard" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. < End of report > |
08.03.2011, 09:20 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Viren blocken Security Center Das andere OTL-Log brauch ich auch
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Viren blocken Security Center |
aktiv, anti-malware, avira, blocken, bösartige, center, control, dateien, direkt, explorer, grund, löschen, malwarebytes, microsoft, minute, möcht, neu, recht, riskware.tool.ck, schließt, security, security center, service, software, trojan.agent.ge, trojan.fakems, version, viren, warum, wissen |