Undine R | 23.04.2015 21:43 | In Ordnung, hier geht es weiter 1. Teil:
Addition.txt - Logfilekopie
(sorry wegen der ganzen Spiele und massenweise Spiel-Ergänzungskarten - "Mapperteam" und andere -, dadurch wird das hier ewig lang ...)
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-04-2015 01
Ran by Ute at 2015-04-23 16:42:45
Running from C:\Users\Ute\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Emsisoft Anti-Malware (Enabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
AbenteuerInMirquidiMapperteam 2-1-0 (HKLM\...\AbenteuerInMirquidiMapperteam) (Version: - )
Acey Deucy Backgammon (HKLM\...\Acey Deucy Backgammon) (Version: - )
Adobe Digital Editions (HKLM\...\Digital Editions) (Version: - )
Adobe Flash Player 11 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 11.7.700.202 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 11.3.300.270 - Adobe Systems Incorporated)
Adobe Reader 9.5.4 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-A95000000001}) (Version: 9.5.4 - Adobe Systems Incorporated)
AlixCatanlogik 2-1-0 (HKLM\...\AlixCatanlogik) (Version: - )
AlixDerletzteBaum 2-1-0 (HKLM\...\AlixDerletzteBaum) (Version: - )
AlixDie10Schwestern 2-1-0 (HKLM\...\AlixDie10Schwestern) (Version: - )
AlixDieDrittePisastudie 2-1-0 (HKLM\...\AlixDieDrittePisastudie) (Version: - )
AlixDiePerlenkette 2-1-0 (HKLM\...\AlixDiePerlenkette) (Version: - )
AlixDieVerbannung 2-1-0 (HKLM\...\AlixDieVerbannung) (Version: - )
AlixDieZweitePisastudie 2-1-0 (HKLM\...\AlixDieZweitePisastudie) (Version: - )
AlixEinigkeit 2-1-0 (HKLM\...\AlixEinigkeit) (Version: - )
AlixEinPiratenleben 2-1-0 (HKLM\...\AlixEinPiratenleben) (Version: - )
AlixFerienlager 2-1-0 (HKLM\...\AlixFerienlager) (Version: - )
AlixGarion1 2-1-0 (HKLM\...\AlixGarion1) (Version: - )
AlixGarion2 2-1-0 (HKLM\...\AlixGarion2) (Version: - )
AlixGarion3 2-1-0 (HKLM\...\AlixGarion3) (Version: - )
AlixGarion4 2-1-0 (HKLM\...\AlixGarion4) (Version: - )
AlixGarion5 2-1-0 (HKLM\...\AlixGarion5) (Version: - )
AlixGarion6 2-1-0 (HKLM\...\AlixGarion6) (Version: - )
AlixGarion7 2-1-0 (HKLM\...\AlixGarion7) (Version: - )
AlixGespaltenesLand 2-1-0 (HKLM\...\AlixGespaltenesLand) (Version: - )
AlixHochzeit 2-1-0 (HKLM\...\AlixHochzeit) (Version: - )
AlixLogikhochzeiten 2-1-0 (HKLM\...\AlixLogikhochzeiten) (Version: - )
AlixMeisterdruide 2-1-0 (HKLM\...\AlixMeisterdruide) (Version: - )
AlixMorgana1 2-1-0 (HKLM\...\AlixMorgana1) (Version: - )
AlixMorgana2 2-1-0 (HKLM\...\AlixMorgana2) (Version: - )
AlixMorgana3 2-1-0 (HKLM\...\AlixMorgana3) (Version: - )
AlixMorgana4 2-1-0 (HKLM\...\AlixMorgana4) (Version: - )
AlixMorgana5 2-1-0 (HKLM\...\AlixMorgana5) (Version: - )
AlixMorgana6 2-1-0 (HKLM\...\AlixMorgana6) (Version: - )
AlixNeueInseln 2-1-0 (HKLM\...\AlixNeueInseln) (Version: - )
AlixOstern08Freitag 2-1-0 (HKLM\...\AlixOstern08Freitag) (Version: - )
AlixPisastudie 2-1-0 (HKLM\...\AlixPisastudie) (Version: - )
AlixPossibilities3 2-1-0 (HKLM\...\AlixPossibilities3) (Version: - )
AlixStreithammel 2-1-0 (HKLM\...\AlixStreithammel) (Version: - )
AlixSturmflu 2-1-0 (HKLM\...\AlixSturmflu) (Version: - )
AlixVulkanausbruch 2-1-0 (HKLM\...\AlixVulkanausbruch) (Version: - )
AlixWege1 2-1-0 (HKLM\...\AlixWege1) (Version: - )
AlixWege2 2-1-0 (HKLM\...\AlixWege2) (Version: - )
AlixWege3 2-1-0 (HKLM\...\AlixWege3) (Version: - )
AlixWeihnachts-b-engel 2-1-0 (HKLM\...\AlixWeihnachts-b-engel) (Version: - )
AlixWeihnachtslogik 2-1-0 (HKLM\...\AlixWeihnachtslogik) (Version: - )
AlixWeihnachtslogistik 2-1-0 (HKLM\...\AlixWeihnachtslogistik) (Version: - )
AlixWeihnachtsproduktion 2-1-0 (HKLM\...\AlixWeihnachtsproduktion) (Version: - )
AlixWeihversandhandel 2-1-0 (HKLM\...\AlixWeihversandhandel) (Version: - )
angeldragonZweiBrueder 2-1-0 (HKLM\...\angeldragonZweiBrueder) (Version: - )
AnguaEasterbunnysearch 2-1-0 (HKLM\...\AnguaEasterbunnysearch) (Version: - )
AnguaTommyDesertTrading 2-1-0 (HKLM\...\AnguaTommyDesertTrading) (Version: - )
AnguaTommyLibellulesKindergarden 2-1-0 (HKLM\...\AnguaTommyLibellulesKindergarden) (Version: - )
AnguaTommyTradingEmpire 2-1-1 (HKLM\...\AnguaTommyTradingEmpire) (Version: - )
AnguaTommyVikingsRecipe 2-1-0 (HKLM\...\AnguaTommyVikingsRecipe) (Version: - )
AnonymusDerTraeumer 2-1-0 (HKLM\...\AnonymusDerTraeumer) (Version: - )
AnonymusNeueHeimat 2-1-0 (HKLM\...\AnonymusNeueHeimat) (Version: - )
AntheaAufDerWalz 2-1-0 (HKLM\...\AntheaAufDerWalz) (Version: - )
AntheaDieEntscheidung 2-1-0 (HKLM\...\AntheaDieEntscheidung) (Version: - )
AntheaDuerre 2-1-0 (HKLM\...\AntheaDuerre) (Version: - )
AntheaFroheOstern 2-1-0 (HKLM\...\AntheaFroheOstern) (Version: - )
AntheaSilbermonBeMyValentine 2-1-0 (HKLM\...\AntheaSilbermonBeMyValentine) (Version: - )
AntheaSilbermonRobinson 2-1-0 (HKLM\...\AntheaSilbermonRobinson) (Version: - )
AntheaWintereinbruch 2-1-0 (HKLM\...\AntheaWintereinbruch) (Version: - )
Arcade Bubbles (HKLM\...\Arcade Bubbles) (Version: - )
Atheros WLAN Client (HKLM\...\{3832FA99-2EDD-41E0-94AD-FBF9FABAFEF9}) (Version: 14.00.0000 - WLAN)
Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.9.504 - Avira Operations GmbH & Co. KG)
Bärenbrüder (HKLM\...\{B489D5F8-D960-4399-9286-C59BF21991B5}) (Version: 1.0 - )
basssChainOfLife 2-1-0 (HKLM\...\basssChainOfLife) (Version: - )
basssValleyoftheTribes 2-1-0 (HKLM\...\basssValleyoftheTribes) (Version: - )
BatteryLifeExtender (HKLM\...\{AA16A9E5-40E9-44F5-801E-6B3D3CFE79E5}) (Version: 1.0.0 - Samsung)
Bjarni2Einsiedler 2-1-1 (HKLM\...\Bjarni2Einsiedler) (Version: - )
BjarniLakeDistrictMP 2-1-0 (HKLM\...\BjarniLakeDistrictMP) (Version: - )
BjarniLakeDistrictSP 2-1-0 (HKLM\...\BjarniLakeDistrictSP) (Version: - )
BuffaloFliegendeWildsau 2-1-0 (HKLM\...\BuffaloFliegendeWildsau) (Version: - )
Butterfly Magic (HKLM\...\Butterfly Magic) (Version: - )
Canon Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - )
Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data (HKLM\...\Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data) (Version: - )
Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data (HKLM\...\Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data) (Version: - )
Canon Easy-PhotoPrint Pro (HKLM\...\Easy-PhotoPrint Pro) (Version: - )
Canon Easy-WebPrint EX (HKLM\...\Easy-WebPrint EX) (Version: - )
Canon MG6200 series Benutzerregistrierung (HKLM\...\Canon MG6200 series Benutzerregistrierung) (Version: - )
Canon MG6200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6200_series) (Version: - )
Canon MG6200 series On-screen Manual (HKLM\...\Canon MG6200 series On-screen Manual) (Version: - )
Canon MP Navigator EX 5.0 (HKLM\...\MP Navigator EX 5.0) (Version: - )
Canon My Printer (HKLM\...\CanonMyPrinter) (Version: - )
Canon Solution Menu EX (HKLM\...\CanonSolutionMenuEX) (Version: - )
CarlieVonSchwedSkaergaerden 2-1-0 (HKLM\...\CarlieVonSchwedSkaergaerden) (Version: - )
Catan - Die erste Insel (HKLM\...\Catan) (Version: - )
ChavaDieBlaueLagune 2-1-0 (HKLM\...\ChavaDieBlaueLagune) (Version: - )
CobaReisezumMPderErde1 2-1-0 (HKLM\...\CobaReisezumMPderErde1) (Version: - )
CobaReisezumMPderErde2 2-1-0 (HKLM\...\CobaReisezumMPderErde2) (Version: - )
CobaReisezumMPderErde3 2-1-0 (HKLM\...\CobaReisezumMPderErde3) (Version: - )
CobaReisezumMPderErde4 2-1-0 (HKLM\...\CobaReisezumMPderErde4) (Version: - )
CobaReisezumMPderErde5 2-1-0 (HKLM\...\CobaReisezumMPderErde5) (Version: - )
Collector's Edition 251 (HKLM\...\Collector's Edition 251) (Version: - )
ConanFrohesFest 2-1-0 (HKLM\...\ConanFrohesFest) (Version: - )
Corel Applications (HKLM\...\Corel Applications) (Version: - )
crassusAK2012PostVonRuprecht 2-1-0 (HKLM\...\crassusAK2012PostVonRuprecht) (Version: - )
CrassusDieHeimkehr 2-1-0 (HKLM\...\CrassusDieHeimkehr) (Version: - )
CrassusFrau gesucht 2-1-0 (HKLM\...\CrassusFrau gesucht) (Version: - )
CrassusTaugenichts 2-1-0 (HKLM\...\CrassusTaugenichts) (Version: - )
CrassusWuestenwikinger 2-1-0 (HKLM\...\CrassusWuestenwikinger) (Version: - )
CrocutaSonnenland 2-1-0 (HKLM\...\CrocutaSonnenland) (Version: - )
CultiSilberDerKleineHobbit1 2-1-0 (HKLM\...\CultiSilberDerKleineHobbit1) (Version: - )
CultiSilberDerKleineHobbit2 2-1-0 (HKLM\...\CultiSilberDerKleineHobbit2) (Version: - )
CultiSilberDerKleineHobbit3 2-1-0 (HKLM\...\CultiSilberDerKleineHobbit3) (Version: - )
CultiSilberDerKleineHobbit4 2-1-0 (HKLM\...\CultiSilberDerKleineHobbit4) (Version: - )
CultiSilberDerKleineHobbit5 2-1-0 (HKLM\...\CultiSilberDerKleineHobbit5) (Version: - )
CultiSilberDerKleineHobbit6 2-1-0 (HKLM\...\CultiSilberDerKleineHobbit6) (Version: - )
CultiSilberDerKleineHobbit7 2-1-0 (HKLM\...\CultiSilberDerKleineHobbit7) (Version: - )
CultiSilberDerKleineHobbit8 2-1-0 (HKLM\...\CultiSilberDerKleineHobbit8) (Version: - )
Cultures - Die Entdeckung Vinlands (HKLM\...\Cultures - Die Entdeckung Vinlands) (Version: - )
Cultures (HKLM\...\Cultures) (Version: - )
'Cultures Saga' (HKLM\...\'Cultures Saga') (Version: - )
CulturianerCultureshausen001 2-1-0 (HKLM\...\CulturianerCultureshausen001) (Version: - )
CulturianerCultureshausen002 2-1-0 (HKLM\...\CulturianerCultureshausen002) (Version: - )
CulturianerCultureshausen003 2-1-0 (HKLM\...\CulturianerCultureshausen003) (Version: - )
CulturianerCultureshausen004 2-1-0 (HKLM\...\CulturianerCultureshausen004) (Version: - )
CulturianerCultureshausen005 2-1-0 (HKLM\...\CulturianerCultureshausen005) (Version: - )
CyberLink DVD Suite (HKLM\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.2604 - CyberLink Corp.)
CyberLink LabelPrint (HKLM\...\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.20.3605 - CyberLink Corp.)
CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.2809 - CyberLink Corp.)
CyberLink PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2426 - CyberLink Corp.)
CyberLink PowerDVD 8 (HKLM\...\InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}) (Version: 8.0.2815 - CyberLink Corp.)
CyberLink PowerProducer (HKLM\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0.1.1410 - CyberLink Corp.)
Dajana84LibEaPMaerchenland 2-1-0 (HKLM\...\Dajana84LibEaPMaerchenland) (Version: - )
DECAdry Express Business Cards 3.52 (HKLM\...\DECAdry Express Business Cards 3) (Version: - )
Deinstallation der Arcor Online Software (HKLM\...\{262DA23B-4BAB-463F-B1DC-9B5287CAB5CA}}_is1) (Version: 5.0.0.8 - Vodafone D2 GmbH)
Diamond Fall (HKLM\...\Diamond Fall) (Version: - )
Digital Advertising Alliance Protect My Choices (Beta) (HKLM\...\{2E4543DD-1526-408D-8B58-D3A2BFE322D0}) (Version: 1.4.0.0 - Digital Advertising Alliance)
DistelfinkEismeerAdvent 2-1-0 (HKLM\...\DistelfinkEismeerAdvent) (Version: - )
DistelfinkGrandauntGreta 2-1-0 (HKLM\...\DistelfinkGrandauntGreta) (Version: - )
dodieDerFreund 2-1-1 (HKLM\...\dodieDerFreund) (Version: - )
Drakensang (HKLM\...\Drakensang_is1) (Version: - dtp)
Easy Battery Manager (HKLM\...\{6F730513-8688-4C3C-90A3-6B9792CE2EF3}) (Version: 3.2.1.7 - Samsung)
Easy Display Manager (HKLM\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 2.3 - Samsung Electronics Co., Ltd.)
Easy Network Manager (HKLM\...\{A7581D39-EA20-4883-A480-80C21047052B}) (Version: 4.0.2 - Samsung)
Easy SpeedUp Manager (HKLM\...\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 2.0.2.6 - )
ElsterFormular (HKLM\...\ElsterFormular) (Version: 15.1.13904 - Landesfinanzdirektion Thüringen)
Emsisoft Anti-Malware (HKLM\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 9.0 - Emsisoft Ltd.)
EngelastraFeentaler 2-1-0 (HKLM\...\EngelastraFeentaler) (Version: - )
EngelastraOsternInGefahr 2-1-0 (HKLM\...\EngelastraOsternInGefahr) (Version: - )
ExtraLines (HKLM\...\ExtraLines_is1) (Version: - )
FiereDoveTheMaze 2-1-0 (HKLM\...\FiereDoveTheMaze) (Version: - )
FlodderBoesesErwachen 2-1-0 (HKLM\...\FlodderBoesesErwachen) (Version: - )
FlodderDEV1Aufbruch 2-1-0 (HKLM\...\FlodderDEV1Aufbruch) (Version: - )
FlodderDEV2Helluland 2-1-0 (HKLM\...\FlodderDEV2Helluland) (Version: - )
FlodderDEV3Markland 2-1-1 (HKLM\...\FlodderDEV3Markland) (Version: - )
FlodderDEV4Vinland 2-1-0 (HKLM\...\FlodderDEV4Vinland) (Version: - )
FlodderOnceUponATime 2-1-0 (HKLM\...\FlodderOnceUponATime) (Version: - ) <==== ATTENTION
FloPechMussManHaben1 2-1-0 (HKLM\...\FloPechMussManHaben1) (Version: - )
FloPechMussManHaben2 2-1-0 (HKLM\...\FloPechMussManHaben2) (Version: - )
FreyaBoloBolo 2-1-0 (HKLM\...\FreyaBoloBolo) (Version: - )
G*Power 3.1.3 (HKLM\...\{26A39957-0BE3-449B-BA6F-922C8713AB2B}) (Version: 3.1.3 - Franz Faul, Uni Kiel, Germany)
Galswin (HKLM\...\{F131DCE7-7D20-11D5-BC42-00A0C9E23766}) (Version: - )
GelbeSeiten Für Berlin 2009 (HKLM\...\{720C39E1-E698-46AA-8B81-13400AD1AC40}) (Version: - )
Google Chrome (HKU\S-1-5-21-3319244995-2461475978-946539677-1000\...\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
Google Chrome (HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
Google Chrome (HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
Google Chrome (HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\...\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
Google Chrome (HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\...\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
GoToMeeting 5.5.0.1133 (HKU\S-1-5-21-3319244995-2461475978-946539677-1000\...\GoToMeeting) (Version: 5.5.0.1133 - CitrixOnline)
GoToMeeting 5.5.0.1133 (HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\GoToMeeting) (Version: 5.5.0.1133 - CitrixOnline)
GoToMeeting 5.5.0.1133 (HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\GoToMeeting) (Version: 5.5.0.1133 - CitrixOnline)
GoToMeeting 5.5.0.1133 (HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\...\GoToMeeting) (Version: 5.5.0.1133 - CitrixOnline)
GoToMeeting 5.5.0.1133 (HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\...\GoToMeeting) (Version: 5.5.0.1133 - CitrixOnline)
Herz77Waldschule 2-1-0 (HKLM\...\Herz77Waldschule) (Version: - )
HP Driver Diagnostics (HKLM\...\{0EC7C406-B592-4686-BAC1-AD29A85EAE6A}) (Version: 1.03.0005 - Ihr Firmenname)
HubergerDasAmulett 2-1-0 (HKLM\...\HubergerDasAmulett) (Version: - )
HubergerKalterNorden 2-1-0 (HKLM\...\HubergerKalterNorden) (Version: - )
HubergerVerfeindeteBrueder 2-1-0 (HKLM\...\HubergerVerfeindeteBrueder) (Version: - )
imagine digital freedom - Samsung (HKLM\...\{8E106A57-A17E-431D-B48F-175E42EB9F74}) (Version: 1.0.2.2 - Samsung Electronics Co. Ltd.,)
ImperatorchenWieAllesBegann 2-1-0 (HKLM\...\ImperatorchenWieAllesBegann) (Version: - )
Indeo® software (HKLM\...\Indeo® software) (Version: - )
Indiana Jack (HKLM\...\IndianaJack) (Version: - )
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
IrmchenFreundschaft 2-1-0 (HKLM\...\IrmchenFreundschaft) (Version: - )
IrmchenHubergerAmbush 2-1-0 (HKLM\...\IrmchenHubergerAmbush) (Version: - )
IrmchenHubergerFriedensmelodie 2-1-0 (HKLM\...\IrmchenHubergerFriedensmelodie) (Version: - )
IrmchenKundschafterPauli 2-1-0 (HKLM\...\IrmchenKundschafterPauli) (Version: - )
IrmchenRaubritter 2-1-0 (HKLM\...\IrmchenRaubritter) (Version: - )
IronBjarniDasCulturesWintermaerchen 2-1-3 (HKLM\...\IronBjarniDasCulturesWintermaerchen) (Version: - )
IronCedriDasSchneehorn 2-1-1 (HKLM\...\IronCedriDasSchneehorn) (Version: - )
IronMaebheOk09Donnerstag 2-1-1 (HKLM\...\IronMaebheOk09Donnerstag) (Version: - )
JamalGoldsonne 2-1-0 (HKLM\...\JamalGoldsonne) (Version: - )
JamalHilfestellung 2-1-0 (HKLM\...\JamalHilfestellung) (Version: - )
JamalKaertchen 2-1-0 (HKLM\...\JamalKaertchen) (Version: - )
Java 7 Update 55 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle)
Johnnnie21ArenaShopping 2-1-0 (HKLM\...\Johnnnie21ArenaShopping) (Version: - )
Katharina157Glueckskinder1 2-1-0 (HKLM\...\Katharina157Glueckskinder1) (Version: - )
Katharina157Glueckskinder2 2-1-0 (HKLM\...\Katharina157Glueckskinder2) (Version: - )
Katharina157Glueckskinder3 2-1-0 (HKLM\...\Katharina157Glueckskinder3) (Version: - )
KraeuterBelleIle 2-1-0 (HKLM\...\KraeuterBelleIle) (Version: - )
KraeutergBeautifulWorld 2-1-0 (HKLM\...\KraeutergBeautifulWorld) (Version: - )
KraeutergDasAbgelegeneTal 2-1-0 (HKLM\...\KraeutergDasAbgelegeneTal) (Version: - )
KraeutergDerGrosseFlussMP 2-1-0 (HKLM\...\KraeutergDerGrosseFlussMP) (Version: - )
KraeutergDerGrosseFlussSP 2-1-0 (HKLM\...\KraeutergDerGrosseFlussSP) (Version: - )
KraeutergDerWegZuDenDreiBirke 2-1-0 (HKLM\...\KraeutergDerWegZuDenDreiBirke) (Version: - )
KraeutergDieGaertnerdesSultan 2-1-0 (HKLM\...\KraeutergDieGaertnerdesSultan) (Version: - )
KraeutergDieWaben 2-1-0 (HKLM\...\KraeutergDieWaben) (Version: - )
KraeutergDieWikingerinGroenla 2-1-0 (HKLM\...\KraeutergDieWikingerinGroenla) (Version: - )
KraeutergEinerFuerAlles 2-1-0 (HKLM\...\KraeutergEinerFuerAlles) (Version: - )
KraeutergEinUnwirklichesLand 2-1-0 (HKLM\...\KraeutergEinUnwirklichesLand) (Version: - )
KraeutergEinWintertraum 2-1-0 (HKLM\...\KraeutergEinWintertraum) (Version: - )
KraeutergHaithabu 2-1-0 (HKLM\...\KraeutergHaithabu) (Version: - )
KraeutergInderNiederlande 2-1-0 (HKLM\...\KraeutergInderNiederlande) (Version: - )
KraeutergInselwelt 2-1-0 (HKLM\...\KraeutergInselwelt) (Version: - )
KraeutergJardisdeGiverny 2-1-0 (HKLM\...\KraeutergJardisdeGiverny) (Version: - )
KraeutergMeinParadies 2-1-0 (HKLM\...\KraeutergMeinParadies) (Version: - )
KraeutergRuhigeZeiten 2-1-0 (HKLM\...\KraeutergRuhigeZeiten) (Version: - )
KraeutergWikingerAufDenKanare 2-1-0 (HKLM\...\KraeutergWikingerAufDenKanare) (Version: - )
KraeutergWikingerIn Daenemark 2-1-0 (HKLM\...\KraeutergWikingerIn Daenemark) (Version: - )
KraeutergWikingerInDerSchweiz 2-1-0 (HKLM\...\KraeutergWikingerInDerSchweiz) (Version: - )
KraeutergWikingerInEngland 2-1-0 (HKLM\...\KraeutergWikingerInEngland) (Version: - )
KraeutergWikingerInFinnland 2-1-0 (HKLM\...\KraeutergWikingerInFinnland) (Version: - )
KraeutergWikingerInFrance 2-1-0 (HKLM\...\KraeutergWikingerInFrance) (Version: - )
KraeutergWikingerInGermany 2-1-0 (HKLM\...\KraeutergWikingerInGermany) (Version: - )
KraeutergWikingerInGriechenla 2-1-0 (HKLM\...\KraeutergWikingerInGriechenla) (Version: - )
KraeutergWikingerInIrland 2-1-0 (HKLM\...\KraeutergWikingerInIrland) (Version: - )
KraeutergWikingerInIsland 2-1-0 (HKLM\...\KraeutergWikingerInIsland) (Version: - )
KraeutergWikingerInItalien 2-1-0 (HKLM\...\KraeutergWikingerInItalien) (Version: - )
KraeutergWikingerInMadagaskar 2-1-0 (HKLM\...\KraeutergWikingerInMadagaskar) (Version: - )
KraeutergWikingerInNorwegen 2-1-0 (HKLM\...\KraeutergWikingerInNorwegen) (Version: - )
KraeutergWikingerInOesterreic 2-1-0 (HKLM\...\KraeutergWikingerInOesterreic) (Version: - )
KraeutergWikingerInPortugal 2-1-0 (HKLM\...\KraeutergWikingerInPortugal) (Version: - )
KraeutergWikingerInSchwedenL 2-1-0 (HKLM\...\KraeutergWikingerInSchwedenL) (Version: - )
KraeutergWikingerInSpanien 2-1-0 (HKLM\...\KraeutergWikingerInSpanien) (Version: - )
KraeuterInselderTraeume 2-1-1 (HKLM\...\KraeuterInselderTraeume) (Version: - )
L&H TTS3000 Deutsch (HKLM\...\LHTTSGED) (Version: - )
Lexicon Special Edition (HKLM\...\Lexicon Special Edition) (Version: - )
LibelleEaPAdventskalender 2-1-0 (HKLM\...\LibelleEaPAdventskalender) (Version: - )
LibelleEaPAiW1Zauberer 2-1-0 (HKLM\...\LibelleEaPAiW1Zauberer) (Version: - )
LibelleEaPAiW2Urfin 2-1-0 (HKLM\...\LibelleEaPAiW2Urfin) (Version: - )
LibelleEaPAiWu4DerFeuergottDerMarranen 2-1-0 (HKLM\...\LibelleEaPAiWu4DerFeuergottDerMarranen) (Version: - )
LibelleEaPAiWu5Arachna 2-1-0 (HKLM\...\LibelleEaPAiWu5Arachna) (Version: - )
LibelleEaPAK2012KlausDummling 2-1-0 (HKLM\...\LibelleEaPAK2012KlausDummling) (Version: - )
LibelleEaPBeiDen7Zwergen 2-1-0 (HKLM\...\LibelleEaPBeiDen7Zwergen) (Version: - )
LibelleEaPDasWolkenschaf 2-1-0 (HKLM\...\LibelleEaPDasWolkenschaf) (Version: - )
LibelleEaPDerVerzauberteNussknacker 2-1-0 (HKLM\...\LibelleEaPDerVerzauberteNussknacker) (Version: - )
LibelleEaPDie7UnterirdischenKoenige 2-1-0 (HKLM\...\LibelleEaPDie7UnterirdischenKoenige) (Version: - )
LibelleEaPDieverlorenenWunschz 2-1-0 (HKLM\...\LibelleEaPDieverlorenenWunschz) (Version: - )
LibelleEaPEinDutzendAlles 2-1-0 (HKLM\...\LibelleEaPEinDutzendAlles) (Version: - )
LibelleEaPHerrscherVonMandala 2-1-0 (HKLM\...\LibelleEaPHerrscherVonMandala) (Version: - )
LibelleEaPKleineInselKerkyra 2-1-0 (HKLM\...\LibelleEaPKleineInselKerkyra) (Version: - )
LibelleEaPMerkFixUndDieMagischenKisten 2-1-0 (HKLM\...\LibelleEaPMerkFixUndDieMagischenKisten) (Version: - )
LibelleEaPSiedelnnachWunsch 2-1-0 (HKLM\...\LibelleEaPSiedelnnachWunsch) (Version: - )
LibelleEaPStonehenge 2-1-0 (HKLM\...\LibelleEaPStonehenge) (Version: - )
LibelleFelixBlumen fuerPuenky 2-1-1 (HKLM\...\LibelleFelixBlumen fuerPuenky) (Version: - )
LunaticHandelskarte 2-1-0 (HKLM\...\LunaticHandelskarte) (Version: - )
LunaticInselkarteHandel 2-1-0 (HKLM\...\LunaticInselkarteHandel) (Version: - )
MaebheAlleJahreWieder 2-1-0 (HKLM\...\MaebheAlleJahreWieder) (Version: - )
MaebheDerPfefferkuchenmann 2-1-0 (HKLM\...\MaebheDerPfefferkuchenmann) (Version: - )
MagicflameDergroessteSchatz 2-1-0 (HKLM\...\MagicflameDergroessteSchatz) (Version: - )
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MannyDie6HeiligenSteine 2-1-0 (HKLM\...\MannyDie6HeiligenSteine) (Version: - )
MannyDievergesseneInsel 2-1-0 (HKLM\...\MannyDievergesseneInsel) (Version: - )
MannyNeueWelt 2-1-0 (HKLM\...\MannyNeueWelt) (Version: - )
MannyTupacAmaru 2-1-0 (HKLM\...\MannyTupacAmaru) (Version: - )
Mapperteam07. Drachenland 2-1-0 (HKLM\...\Mapperteam07. Drachenland) (Version: - )
MapperteamAegypten 2-1-1 (HKLM\...\MapperteamAegypten) (Version: - )
MapperteamAmazonen 2-1-0 (HKLM\...\MapperteamAmazonen) (Version: - )
MapperteamAmRandDerWelt 2-1-0 (HKLM\...\MapperteamAmRandDerWelt) (Version: - )
MapperteamAtlantis 2-1-0 (HKLM\...\MapperteamAtlantis) (Version: - )
MapperteamAufDemDachDerWelt 2-1-0 (HKLM\...\MapperteamAufDemDachDerWelt) (Version: - )
MapperteamAufUndDavon 2-1-0 (HKLM\...\MapperteamAufUndDavon) (Version: - )
MapperteamAustralien 2-1-0 (HKLM\...\MapperteamAustralien) (Version: - )
MapperteamAuswanderer 2-1-0 (HKLM\...\MapperteamAuswanderer) (Version: - )
MapperteamBeiMani 2-1-0 (HKLM\...\MapperteamBeiMani) (Version: - )
MapperteamBjarniInEngland 2-1-0 (HKLM\...\MapperteamBjarniInEngland) (Version: - )
MapperteamBjarnisVerhaengnis 2-1-0 (HKLM\...\MapperteamBjarnisVerhaengnis) (Version: - )
MapperteamBombenstimmungInMarburg 2-1-0 (HKLM\...\MapperteamBombenstimmungInMarburg) (Version: - )
MapperteamChaosUmsBockbier 2-1-0 (HKLM\...\MapperteamChaosUmsBockbier) (Version: - )
MapperteamCyraunddieMapper 2-1-0 (HKLM\...\MapperteamCyraunddieMapper) (Version: - )
MapperteamDasFehlendePasswort 2-1-1 (HKLM\...\MapperteamDasFehlendePasswort) (Version: - )
MapperteamDasFest 2-1-0 (HKLM\...\MapperteamDasFest) (Version: - )
MapperteamDasGeheimnisderMaya 2-1-0 (HKLM\...\MapperteamDasGeheimnisderMaya) (Version: - )
MapperteamDasGrosseGwerchVonNaermberch 2-1-0 (HKLM\...\MapperteamDasGrosseGwerchVonNaermberch) (Version: - )
MapperteamDasImpressum 2-1-0 (HKLM\...\MapperteamDasImpressum) (Version: - )
MapperteamDerFjord 2-1-0 (HKLM\...\MapperteamDerFjord) (Version: - )
MapperteamDerMeisterdieb 2-1-2 (HKLM\...\MapperteamDerMeisterdieb) (Version: - )
MapperteamDerSchwarzeTod 2-1-0 (HKLM\...\MapperteamDerSchwarzeTod) (Version: - )
MapperteamDie10Gebote 2-1-0 (HKLM\...\MapperteamDie10Gebote) (Version: - )
MapperteamDieSavannenOstafrika 2-1-0 (HKLM\...\MapperteamDieSavannenOstafrika) (Version: - )
MapperteamDjinne 2-1-0 (HKLM\...\MapperteamDjinne) (Version: - )
MapperteamEntfuehrtundGetrennt 2-1-0 (HKLM\...\MapperteamEntfuehrtundGetrennt) (Version: - )
MapperteamEroberer 2-1-0 (HKLM\...\MapperteamEroberer) (Version: - )
MapperteamExcalibur 2-1-1 (HKLM\...\MapperteamExcalibur) (Version: - )
MapperteamHansebundUndLikedeelers 2-1-0 (HKLM\...\MapperteamHansebundUndLikedeelers) (Version: - )
MapperteamHeldOhneErinnerung 2-1-0 (HKLM\...\MapperteamHeldOhneErinnerung) (Version: - )
MapperteamImElbtal 2-1-0 (HKLM\...\MapperteamImElbtal) (Version: - )
MapperteamImpressum 2-1-0 (HKLM\...\MapperteamImpressum) (Version: - )
MapperteamImpressum08 2-1-0 (HKLM\...\MapperteamImpressum08) (Version: - )
MapperteamImpressum2010 2-1-0 (HKLM\...\MapperteamImpressum2010) (Version: - )
MapperteamInBavaria 2-1-0 (HKLM\...\MapperteamInBavaria) (Version: - )
MapperteamInDubai 2-1-0 (HKLM\...\MapperteamInDubai) (Version: - )
MapperteamInFranken 2-1-0 (HKLM\...\MapperteamInFranken) (Version: - )
MapperteamInKuba 2-1-0 (HKLM\...\MapperteamInKuba) (Version: - )
MapperteamKatastrophentalEifel 2-1-0 (HKLM\...\MapperteamKatastrophentalEifel) (Version: - )
MapperteamLandDesRot 2-1-0 (HKLM\...\MapperteamLandDesRot) (Version: - )
MapperteamLangerLulatschInBredullje 2-1-0 (HKLM\...\MapperteamLangerLulatschInBredullje) (Version: - )
MapperteamLondon 2-1-0 (HKLM\...\MapperteamLondon) (Version: - )
MapperteamManibeidenDrachen 2-1-0 (HKLM\...\MapperteamManibeidenDrachen) (Version: - )
MapperteamManibeimHoehlengeist 2-1-0 (HKLM\...\MapperteamManibeimHoehlengeist) (Version: - )
MapperteamMexiko 2-1-0 (HKLM\...\MapperteamMexiko) (Version: - )
MapperteamNachVinland 2-1-0 (HKLM\...\MapperteamNachVinland) (Version: - )
MapperteamOrakelsuche 2-1-0 (HKLM\...\MapperteamOrakelsuche) (Version: - )
MapperteamPiratenbraeute 2-1-0 (HKLM\...\MapperteamPiratenbraeute) (Version: - )
MapperteamRaeuberspukImHuy 2-1-0 (HKLM\...\MapperteamRaeuberspukImHuy) (Version: - )
MapperteamReisemitHindernissen 2-1-0 (HKLM\...\MapperteamReisemitHindernissen) (Version: - )
MapperteamSchaetzederKaribik 2-1-0 (HKLM\...\MapperteamSchaetzederKaribik) (Version: - )
MapperteamSigurdsReiseDurchTirol 2-1-0 (HKLM\...\MapperteamSigurdsReiseDurchTirol) (Version: - )
MapperteamStadtrundgang 2-1-0 (HKLM\...\MapperteamStadtrundgang) (Version: - )
MapperteamSuchenachHeimdall 2-1-0 (HKLM\...\MapperteamSuchenachHeimdall) (Version: - )
MapperteamSuedamerika 2-1-0 (HKLM\...\MapperteamSuedamerika) (Version: - )
MapperteamSuedlichVom GlamourGuelleGranaten 2-1-0 (HKLM\...\MapperteamSuedlichVom GlamourGuelleGranaten) (Version: - )
MapperteamSuedlichVom SigurdUndDerKaiser 2-1-0 (HKLM\...\MapperteamSuedlichVom SigurdUndDerKaiser) (Version: - )
MapperteamSuedlichVom TreffpunktAirport 2-1-0 (HKLM\...\MapperteamSuedlichVom TreffpunktAirport) (Version: - )
MapperteamSuedlichVom WeisswurstAequator 2-1-0 (HKLM\...\MapperteamSuedlichVom WeisswurstAequator) (Version: - )
MapperteamUnterNordlichtern 2-1-0 (HKLM\...\MapperteamUnterNordlichtern) (Version: - )
MapperteamVerraeterundVerbuendete 2-1-1 (HKLM\...\MapperteamVerraeterundVerbuendete) (Version: - )
MapperteamVordemFest 2-1-0 (HKLM\...\MapperteamVordemFest) (Version: - )
MapperteamWaehrendBjarnischlie 2-1-0 (HKLM\...\MapperteamWaehrendBjarnischlie) (Version: - )
MapperteamZufluchtbeiFreunden 2-1-0 (HKLM\...\MapperteamZufluchtbeiFreunden) (Version: - )
MapperteamZwischenstop 2-1-0 (HKLM\...\MapperteamZwischenstop) (Version: - )
Max Mix Foto (HKLM\...\Max Mix Foto) (Version: - )
Megamind (HKLM\...\Megamind) (Version: - )
Melisendre3Haselnuesse 2-1-0 (HKLM\...\Melisendre3Haselnuesse) (Version: - )
MelisendreSterntaler 2-1-0 (HKLM\...\MelisendreSterntaler) (Version: - )
MelisendreUnglueckKomplett 2-1-1 (HKLM\...\MelisendreUnglueckKomplett) (Version: - )
MessiCulturianerOK10Montag 2-1-0 (HKLM\...\MessiCulturianerOK10Montag) (Version: - )
messiGoldsuche 2-1-2 (HKLM\...\messiGoldsuche) (Version: - )
MessiOk09Samstag 2-1-0 (HKLM\...\MessiOk09Samstag) (Version: - )
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft AutoRoute 2002 (HKLM\...\{F7F2DC0A-C22E-49AD-AD37-797309A54E7B}) (Version: 9.00.17.0200 - Microsoft)
Microsoft Encarta Professional 2005 (HKLM\...\{054400C0-64A6-4248-A026-9745C1E9E159}) (Version: 2005 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Picture It! Foto 7.0 (HKLM\...\{369B36BE-3D64-4641-9AEA-808D436FE132}) (Version: 7.0.0.0000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft SQL Server Native Client (HKLM\...\{1D1D8ADC-BF08-4E61-9393-5FA305B16864}) (Version: 9.00.3042.00 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\...\{5C759B74-34F4-43C6-A5D9-039CB754C5E9}) (Version: 9.00.3042.00 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Word 2002 (HKLM\...\{911B0407-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2701.01 - Microsoft Corporation)
Microsoft Works 2003-Setup-Start (HKLM\...\Works2003Setup) (Version: - )
Microsoft Works 7.0 (HKLM\...\{EDDDC607-91D9-4758-9F57-265FDCD8A772}) (Version: 07.02.0702 - Microsoft Corporation)
Microsoft Works Suite-Add-Ins für Microsoft Word (HKLM\...\{7CDBE27D-87EC-434E-AFE4-D0116AE876BB}) (Version: 2.0.0.0000 - Microsoft Corporation)
Minigolf Pro (HKLM\...\Minigolf Pro) (Version: - )
MoltWinterWonderland 2-1-0 (HKLM\...\MoltWinterWonderland) (Version: - )
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MuseScore 2 (HKLM\...\{36F8DD90-CE12-11E4-8830-0800200C9A66}) (Version: 2.0.0 - Werner Schweer and Others)
NeisianMaebheOstern08Montag 2-1-0 (HKLM\...\NeisianMaebheOstern08Montag) (Version: - )
NeoBall (HKLM\...\NeoBall) (Version: - )
NoLimitDie5Amulette 2-1-0 (HKLM\...\NoLimitDie5Amulette) (Version: - )
OK10FreitagSommersprosseNejira 2-1-0 (HKLM\...\OK10FreitagSommersprosseNejira) (Version: - )
OK10SonntagSaCoMa 2-1-0 (HKLM\...\OK10SonntagSaCoMa) (Version: - )
Ostern08DonnersPuenkyDodie 2-1-0 (HKLM\...\Ostern08DonnersPuenkyDodie) (Version: - )
PCTroubleshooting (HKLM\...\{68CAE442-579C-4D84-AA5F-253852522ED5}) (Version: 2.0.0.4 - Samsung Electronics Co.,LTD.)
Pearl Poppers (HKLM\...\Pearl Poppers) (Version: - )
Phoenix21Inselhopper 2-1-1 (HKLM\...\Phoenix21Inselhopper) (Version: - )
phoenix21Steinhagel 2-1-0 (HKLM\...\phoenix21Steinhagel) (Version: - )
PimpfiBlumeVonOstaria 2-1-0 (HKLM\...\PimpfiBlumeVonOstaria) (Version: - )
PimpfiNirvana 2-1-0 (HKLM\...\PimpfiNirvana) (Version: - )
PimpfiundIchSeitGenerationen 2-1-0 (HKLM\...\PimpfiundIchSeitGenerationen) (Version: - )
PirateVille (HKLM\...\PirateVille) (Version: - )
PowerDirector (Version: 7.00.0000 - CyberLink Corp.) Hidden
pronto pummelBlaukaeppchen 2-1-0 (HKLM\...\pronto pummelBlaukaeppchen) (Version: - )
ProntoPummelDerverrueckteDruide 2-1-0 (HKLM\...\ProntoPummelDerverrueckteDruide) (Version: - )
prontopummelKlimawandel 2-1-0 (HKLM\...\prontopummelKlimawandel) (Version: - )
prontopummelWassermann 2-1-0 (HKLM\...\prontopummelWassermann) (Version: - )
ProtectDisc Driver, Version 11 (HKLM\...\ProtectDisc Driver 11) (Version: 11.0.0.13 - ProtectDisc Software GmbH)
RandallFlaggDieMafia 2-1-4 (HKLM\...\RandallFlaggDieMafia) (Version: - )
RatinaZAllesWichtelOderWas 2-1-0 (HKLM\...\RatinaZAllesWichtelOderWas) (Version: - )
RatinaZDasSchicksalHacons 2-1-0 (HKLM\...\RatinaZDasSchicksalHacons) (Version: - )
RatinaZDreiBrueder 2-1-0 (HKLM\...\RatinaZDreiBrueder) (Version: - )
RatinaZEineGrosseAufgabe 2-1-0 (HKLM\...\RatinaZEineGrosseAufgabe) (Version: - )
RatinaZHaconGegenDieRiesen 2-1-0 (HKLM\...\RatinaZHaconGegenDieRiesen) (Version: - )
RatinaZHaconInAsgard 2-1-0 (HKLM\...\RatinaZHaconInAsgard) (Version: - )
RatinaZHomeSweetHome 2-1-0 (HKLM\...\RatinaZHomeSweetHome) (Version: - )
RatinaZNeuerAnfang 2-1-0 (HKLM\...\RatinaZNeuerAnfang) (Version: - )
RatinaZStreikderWichtel 2-1-0 (HKLM\...\RatinaZStreikderWichtel) (Version: - )
RatinaZWilliWichtel 2-1-0 (HKLM\...\RatinaZWilliWichtel) (Version: - )
RatinaZWuestensand 2-1-0 (HKLM\...\RatinaZWuestensand) (Version: - )
Readiris 7.5 (HKLM\...\{9BFFB382-0B2C-11D6-AB3E-000102B0F79A}) (Version: - )
RealDownloader (Version: 1.3.2 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\...\RealPlayer 16.0) (Version: 16.0.2 - RealNetworks)
Realtek 8136 8168 8169 Ethernet Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0004 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5837 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
ReddyMidisOk10Samstag 2-1-0 (HKLM\...\ReddyMidisOk10Samstag) (Version: - )
Reversi (HKLM\...\Reversi) (Version: - )
Roxio CinePlayer (HKLM\...\{26792CA7-D87A-4DBE-896B-C2F66B344511}) (Version: 2.2.0 - Roxio)
SaCoMaAufbruchMitHindernissen 2-1-0 (HKLM\...\SaCoMaAufbruchMitHindernissen) (Version: - )
SaCoMaDieBrueckeAmRhein 2-1-0 (HKLM\...\SaCoMaDieBrueckeAmRhein) (Version: - )
SaCoMaFreundschaftshilfe 2-1-1 (HKLM\...\SaCoMaFreundschaftshilfe) (Version: - )
SaCoMaGrosseTauschaktion 2-1-0 (HKLM\...\SaCoMaGrosseTauschaktion) (Version: - )
SaCoMaHeimatlos 2-1-0 (HKLM\...\SaCoMaHeimatlos) (Version: - )
SaCoMaIrland 2-1-0 (HKLM\...\SaCoMaIrland) (Version: - )
SaCoMaIsland 2-1-0 (HKLM\...\SaCoMaIsland) (Version: - )
SaCoMaLehnsherr 2-1-0 (HKLM\...\SaCoMaLehnsherr) (Version: - )
SaCoMaMaennerAlleinZuHaus 2-1-0 (HKLM\...\SaCoMaMaennerAlleinZuHaus) (Version: - )
SaCoMaOdW10Ausgesetzt 2-1-0 (HKLM\...\SaCoMaOdW10Ausgesetzt) (Version: - )
SaCoMaOdW11DieOase 2-1-0 (HKLM\...\SaCoMaOdW11DieOase) (Version: - )
SaCoMaOdW12Wuestenvolk 2-1-0 (HKLM\...\SaCoMaOdW12Wuestenvolk) (Version: - )
SaCoMaOdW13Zickzackkurs 2-1-0 (HKLM\...\SaCoMaOdW13Zickzackkurs) (Version: - )
SaCoMaOdW14Goetterheimat 2-1-0 (HKLM\...\SaCoMaOdW14Goetterheimat) (Version: - )
SaCoMaOdW15LokisEiland 2-1-0 (HKLM\...\SaCoMaOdW15LokisEiland) (Version: - )
SaCoMaOdW16Gestrandet 2-1-0 (HKLM\...\SaCoMaOdW16Gestrandet) (Version: - )
SaCoMaOdW17DieRueckkehr 2-1-1 (HKLM\...\SaCoMaOdW17DieRueckkehr) (Version: - )
SaCoMaOdW7Alpen 2-1-0 (HKLM\...\SaCoMaOdW7Alpen) (Version: - )
SaCoMaOdW9InDerNeuenWelt 2-1-0 (HKLM\...\SaCoMaOdW9InDerNeuenWelt) (Version: - )
SaCoMaRS1AufbruchNachVinland 2-1-0 (HKLM\...\SaCoMaRS1AufbruchNachVinland) (Version: - )
SaCoMaRS2MissionInVinland 2-1-1 (HKLM\...\SaCoMaRS2MissionInVinland) (Version: - )
SaCoMaRS3DieSpurDerVerwuestung 2-1-0 (HKLM\...\SaCoMaRS3DieSpurDerVerwuestung) (Version: - )
SaCoMaRS4ImLabyrinthdesweisenSchamanen 2-1-0 (HKLM\...\SaCoMaRS4ImLabyrinthdesweisenSchamanen) (Version: - )
SaCoMaRS5ImAngesichtDesFeindes 2-1-0 (HKLM\...\SaCoMaRS5ImAngesichtDesFeindes) (Version: - )
SaCoMaRS6DieBastionDesSchreckens 2-1-0 (HKLM\...\SaCoMaRS6DieBastionDesSchreckens) (Version: - )
SaCoMaRS7DieEntscheidungsschlacht 2-1-0 (HKLM\...\SaCoMaRS7DieEntscheidungsschlacht) (Version: - )
SaCoMaSindbad 2-1-0 (HKLM\...\SaCoMaSindbad) (Version: - )
SaCoMaWildschweinplage 2-1-0 (HKLM\...\SaCoMaWildschweinplage) (Version: - )
Samsung Magic Doctor (HKLM\...\{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}) (Version: 5.0 - Samsung Electronics Co., LTD)
Samsung Recovery Solution III (HKLM\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 3.0.0.9 - Samsung)
Samsung Update Plus (HKLM\...\{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}) (Version: 2.0 - Samsung Electronics Co., Ltd.)
SchnuckiWickiOstern08Ostersonntag 2-1-0 (HKLM\...\SchnuckiWickiOstern08Ostersonntag) (Version: - )
SchreibfederFrost 2-1-0 (HKLM\...\SchreibfederFrost) (Version: - )
SeaBounty (HKLM\...\SeaBounty) (Version: - )
ShaminoHammerfest 2-1-0 (HKLM\...\ShaminoHammerfest) (Version: - )
ShaminoInselspringenWS 2-1-0 (HKLM\...\ShaminoInselspringenWS) (Version: - )
Shockwave (HKLM\...\Shockwave) (Version: - )
SilbermondAlchimistin 2-1-0 (HKLM\...\SilbermondAlchimistin) (Version: - )
SilbermondFionaFionaunddieWikingerf 2-1-0 (HKLM\...\SilbermondFionaFionaunddieWikingerf) (Version: - )
SilbermondSilvermonnsGeheimnis 2-1-0 (HKLM\...\SilbermondSilvermonnsGeheimnis) (Version: - )
SilbermondStrohzuGold 2-1-0 (HKLM\...\SilbermondStrohzuGold) (Version: - )
SimonDerFinsterwald 2-1-0 (HKLM\...\SimonDerFinsterwald) (Version: - )
sprMappertea 2-1-0 (HKLM\...\sprMappertea) (Version: - )
StefanAlleZusammen 2-1-0 (HKLM\...\StefanAlleZusammen) (Version: - )
StefanAufNachTakatuka 2-1-0 (HKLM\...\StefanAufNachTakatuka) (Version: - )
StefanDerHilferuf 2-1-0 (HKLM\...\StefanDerHilferuf) (Version: - )
StefanDerHoehleneingang 2-1-0 (HKLM\...\StefanDerHoehleneingang) (Version: - )
StefanDerOffeneOzean 2-1-0 (HKLM\...\StefanDerOffeneOzean) (Version: - )
StefanDieExplosion 2-1-0 (HKLM\...\StefanDieExplosion) (Version: - )
StefanDieZollbeamten 2-1-0 (HKLM\...\StefanDieZollbeamten) (Version: - )
StefanWinterzeit 2-1-0 (HKLM\...\StefanWinterzeit) (Version: - )
Sunken Treasure (HKLM\...\Sunken Treasure) (Version: - )
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 11.1.3.2 - Synaptics)
ThomasOasedesHaendlers 2-1-0 (HKLM\...\ThomasOasedesHaendlers) (Version: - )
thschlumpfAK2012Wintermaerchen 2-1-0 (HKLM\...\thschlumpfAK2012Wintermaerchen) (Version: - )
thschlumpfBummelnmitPoppy 2-1-0 (HKLM\...\thschlumpfBummelnmitPoppy) (Version: - )
timanfaya99Zaubermeister 2-1-0 (HKLM\...\timanfaya99Zaubermeister) (Version: - )
TMPlay3Home (HKLM\...\{57931112-46C4-44C9-9A5A-66A593CEDCCD}) (Version: 3.20.6000 - mdlsoft.co.uk / TaskMagic)
TommyAlleingeblieben 2-1-0 (HKLM\...\TommyAlleingeblieben) (Version: - )
TommyAnguaEineSchoeneBescherun 2-1-0 (HKLM\...\TommyAnguaEineSchoeneBescherun) (Version: - )
TommyAnguaNannyOggStreetOfLive 2-1-0 (HKLM\...\TommyAnguaNannyOggStreetOfLive) (Version: - )
TommyDatingAgencyLibellule 2-1-0 (HKLM\...\TommyDatingAgencyLibellule) (Version: - )
TommyGestrandet 2-1-0 (HKLM\...\TommyGestrandet) (Version: - )
TommyGrippewelle 2-1-0 (HKLM\...\TommyGrippewelle) (Version: - )
TommyHandelswahn 2-1-0 (HKLM\...\TommyHandelswahn) (Version: - )
TommyIslandJumping 2-1-0 (HKLM\...\TommyIslandJumping) (Version: - )
TommyMexicoCanyon 2-1-0 (HKLM\...\TommyMexicoCanyon) (Version: - )
TommyNachdemFest 2-1-0 (HKLM\...\TommyNachdemFest) (Version: - )
TommyWedding 2-1-0 (HKLM\...\TommyWedding) (Version: - )
TommyWickiAnguaFreezes 2-1-0 (HKLM\...\TommyWickiAnguaFreezes) (Version: - )
TommyWickiKalikantzari 2-1-0 (HKLM\...\TommyWickiKalikantzari) (Version: - )
Treasure Mines (HKLM\...\Treasure Mines) (Version: - )
truckerDie12Monate 2-1-0 (HKLM\...\truckerDie12Monate) (Version: - )
TruckerDrachenland 2-1-0 (HKLM\...\TruckerDrachenland) (Version: - )
TruckerDrachenland2 2-1-2 (HKLM\...\TruckerDrachenland2) (Version: - )
TruckerDrachenland3 2-1-0 (HKLM\...\TruckerDrachenland3) (Version: - )
TruckerDrachenland4 2-1-0 (HKLM\...\TruckerDrachenland4) (Version: - )
TruckerDrachenland5 2-1-1 (HKLM\...\TruckerDrachenland5) (Version: - )
TruckerDrachenland6 2-1-0 (HKLM\...\TruckerDrachenland6) (Version: - )
TruckerOk09Montag 2-1-0 (HKLM\...\TruckerOk09Montag) (Version: - )
TurmwacheDerAnfang1 2-1-0 (HKLM\...\TurmwacheDerAnfang1) (Version: - )
TurmwacheDerHafen3 2-1-0 (HKLM\...\TurmwacheDerHafen3) (Version: - )
TurmwacheDerHansebund 2-1-0 (HKLM\...\TurmwacheDerHansebund) (Version: - )
TurmwacheDerTempel8 2-1-0 (HKLM\...\TurmwacheDerTempel8) (Version: - )
TurmwacheDerWald6 2-1-0 (HKLM\...\TurmwacheDerWald6) (Version: - )
TurmwacheKamp2DieWueste 2-1-0 (HKLM\...\TurmwacheKamp2DieWueste) (Version: - )
TurmwacheKamp4Kaufrausch 2-1-0 (HKLM\...\TurmwacheKamp4Kaufrausch) (Version: - )
TurmwacheKamp5Haendlersmann 2-1-0 (HKLM\...\TurmwacheKamp5Haendlersmann) (Version: - )
TurmwacheKamp7Vorbereitung 2-1-0 (HKLM\...\TurmwacheKamp7Vorbereitung) (Version: - )
UlfDieGoldsucher 2-1-0 (HKLM\...\UlfDieGoldsucher) (Version: - )
UlfFriedlicheWeihnachte 2-1-0 (HKLM\...\UlfFriedlicheWeihnachte) (Version: - )
Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (HKLM\...\{07629207-FAA0-4F1A-8092-BF5085BE511F}) (Version: 9.00.3042.00 - Microsoft Corporation)
User Guide (HKLM\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.0 - )
Veoh Giraffic Video Accelerator (HKLM\...\Giraffic) (Version: 0.86.412.230 - Giraffic)
Veoh Web Player (HKLM\...\Veoh Web Player Beta) (Version: 1.1.2.0000 - Veoh Networks, Inc.)
VroFlintsErbeTeil1 2-1-0 (HKLM\...\VroFlintsErbeTeil1) (Version: - )
VroFlintsErbeTeil2 2-1-0 (HKLM\...\VroFlintsErbeTeil2) (Version: - )
VroIronWiToOk09Sonntag 2-1-0 (HKLM\...\VroIronWiToOk09Sonntag) (Version: - )
WickiTiefschlaf 2-1-0 (HKLM\...\WickiTiefschlaf) (Version: - )
WickiTommyFriedersWunsch 2-1-0 (HKLM\...\WickiTommyFriedersWunsch) (Version: - )
WickiTommyOk09Freitag 2-1-0 (HKLM\...\WickiTommyOk09Freitag) (Version: - )
WietiaCulturianerOK10Donnerstag 2-1-0 (HKLM\...\WietiaCulturianerOK10Donnerstag) (Version: - )
WiSchnuMarzipania 2-1-0 (HKLM\...\WiSchnuMarzipania) (Version: - )
WolfsrudelOdinsGeschenk 2-1-0 (HKLM\...\WolfsrudelOdinsGeschenk) (Version: - )
Works Suite-Betriebssystem-Pack (Version: 3.0.0.0000 - Microsoft Corporation) Hidden
WuselBadespassmit Folgen 2-1-1 (HKLM\...\WuselBadespassmit Folgen) (Version: - )
WuselDerTagNull 2-1-0 (HKLM\...\WuselDerTagNull) (Version: - )
XP-Games JRE (HKLM\...\XP-Games JRE) (Version: - )
XP-Spiele Ishido (HKLM\...\XP-Spiele Ishido) (Version: - )
XP-Spiele Shisen Metall (HKLM\...\XP-Spiele Shisen Metall) (Version: - )
xxxx 2-1-0 (HKLM\...\xxxx) (Version: - )
YaNRaeubergeschichten 2-1-0 (HKLM\...\YaNRaeubergeschichten) (Version: - )
YogiDieKameltreiber 2-1-0 (HKLM\...\YogiDieKameltreiber) (Version: - )
YTD Video Downloader 4.0 (HKLM\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.0 - GreenTree Applications SRL) <==== ATTENTION
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Ute\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.21.135\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{0C378864-D5C4-4D9C-854C-432E3BEC9CCB}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.25.5\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{17764098-F985-44E2-93C3-DF9B49F1CC19}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{17E67D4A-23A1-40D8-A049-EE34C0AF756A}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.26.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\InprocServer32 -> C:\Program Files\Hp\Common\RulesEngine.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.26.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.23.9\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{42C68651-1700-4750-A81F-A1F5110E0F66}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{4774922A-8983-4ECC-94FD-7235F06F53A1}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{51240B37-45D0-413C-BAE0-D8F3ACDC15E6}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.26.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{54BE6B6F-3056-470B-97E1-BB92E051B6C4}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\InprocServer32 -> C:\Program Files\Hp\Common\RulesEngine.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\Ute\AppData\Local\Google\Chrome\Application\42.0.2311.90\delegate_execute.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\InprocServer32 -> C:\Program Files\Hp\Common\HPScripting.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{60178279-6D62-43AF-A336-77925651A4C6}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.21.145\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{6470DE80-1635-4B5D-93A3-3701CE148A79}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{64CB8178-1A77-4443-BE13-30BE889B99BB}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\InprocServer32 -> C:\Program Files\Hp\Common\RulesEngine.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{6B75345B-AA36-438A-BBE6-4078B4C6984D}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{784F2933-6BDD-4E5F-B1BA-A8D99B603649}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\InprocServer32 -> C:\Program Files\Hp\Common\RulesEngine.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{7D4CF499-32EC-4E8E-8714-7E74303869F0}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Program Files\Citrix\GoToMeeting\1133\G2MOutlookAddin.dll (Citrix Online, a division of Citrix Systems, Inc.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{8877F3CD-3C29-4E2D-B7DD-70B24DF4EBD1}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.24.15\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{910E7ADE-7F75-402D-A4A6-BB1A82362FCA}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.21.149\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{93441C07-E57E-4086-B912-F323D741A9D8}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\InprocServer32 -> C:\Program Files\Hp\Common\RulesEngine.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{9E1DDDD2-0638-4607-B266-13FE69EDFFD3}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{9E3A85FC-1E59-4C57-ACEA-17E7D61000F1}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.22.3\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.21.165\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{A95845D8-8463-4605-B5FB-4F8CFBAC5C47}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{AA6A5B54-2ACF-4FDB-A82B-E505A5E0B65E}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{AAFBE339-5BEE-417C-BE98-218DA8512B43}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{AB049B11-607B-46C8-BBF7-F4D6AF301046}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{AB237044-8A3B-42BB-9EE1-9BFA6721D9ED}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{B2CD4730-67E7-401C-A2CB-D74715E05FA4}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{B5201019-B9A8-411C-A7AC-CEA856A63C00}\InprocServer32 -> C:\Program Files\Hp\Common\HPScripting.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{B9C13CD0-5A97-4C6B-8A50-7638020E2462}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{BC2971B9-2A4F-44C8-8D7F-04E027544828}\InprocServer32 -> C:\Program Files\Hp\Common\HPScripting.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\InprocServer32 -> C:\Program Files\Hp\Common\RulesEngine.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{BF931895-AF82-467A-8819-917C6EE2D1F3}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.26.9\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.21.115\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{C70D0641-DDE1-4FD7-A4D4-DA187B80741D}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{C94188F6-0F9F-46B3-8B78-D71907BD8B77}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{CDAF9CEC-F3EC-4B22-ABA3-9726713560F8}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{CF6866F9-B67C-4B24-9957-F91E91E788DC}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.25.11\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{D057CD8F-1469-4A41-B24C-7EED6B1DDCD2}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{DC4F9DA0-DB05-4BB0-8FB2-03A80FE98772}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{DE233AFF-8BD5-457E-B7F0-702DBEA5A828}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{DF1F1C17-6A29-45FB-A3C6-9825908E062E}\InprocServer32 -> C:\Program Files\Hp\Common\RulesEngine.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{E12DA4F2-BDFB-4EAD-B12F-2725251FA6B0}\InprocServer32 -> C:\Program Files\Hp\Common\HPeDiag.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.26.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.26.9\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{E975F61C-2C2B-4FE8-A4CD-24C52969CE12}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.22.5\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{FA9C5110-071C-4964-9DD0-610806FF0F81}\InprocServer32 -> C:\Program Files\Hp\Common\HPDeviceDetection.dll (Hewlett-Packard)
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.21.111\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-3319244995-2461475978-946539677-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Ute\AppData\Local\Google\Update\1.3.24.7\psuser.dll No File
==================== Restore Points =========================
23-04-2015 03:00:19 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {01A0F024-4AB0-4E24-9668-183E458A0987} - System32\Tasks\{2432882A-C10E-46FA-B4B5-65B10217C9DB} => pcalua.exe -a C:\Users\Ute\Documents\SeaBounty\mapper\mapper\AlixMapperlehrling_v2-1-0.exe -d C:\Users\Ute\Documents\SeaBounty\mapper\mapper
Task: {01C0BE4D-6ED3-45D1-82FF-128C767D7489} - System32\Tasks\{E4B2C65C-775A-4A46-8459-0E511945618C} => pcalua.exe -a "C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\32YCHNZ3\SaCoMaOk10Sonntag_v2-1-0[1].exe" -d C:\Users\Ute\Desktop
Task: {02307148-A4C1-4C65-B6EB-7F6E87FA625B} - System32\Tasks\{76D477F9-0BD3-4BAD-A096-CA5230E741CB} => pcalua.exe -a "C:\Users\Ute\Documents\zu Spielen u. Sonstiges\BonusKarten[1]\CulturesBonuskarten.exe" -d "C:\Users\Ute\Documents\zu Spielen u. Sonstiges\BonusKarten[1]"
Task: {0C44EB63-9084-4969-A730-1B4012E0E0F2} - System32\Tasks\{A1AD830B-85D8-4915-8A16-9EA6C3D2CDC7} => pcalua.exe -a C:\Users\Ute\Documents\SeaBounty\LibelleEaPVeraergerteJahreszeiten_v2-1-0.exe -d C:\Users\Ute\Documents\SeaBounty
Task: {0CF84A71-CC9C-4D25-A61C-0935D07193EB} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3319244995-2461475978-946539677-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.)
Task: {0D0306AD-A754-4D2E-920D-AC1F54EBFBD3} - System32\Tasks\{82DA9831-0913-444B-A138-81FAC7FCF73A} => pcalua.exe -a "C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWGLMU0P\KraeutergDerGrosseFlussMP_v2-1-0[1].exe" -d C:\Users\Ute\Desktop
Task: {15F9F7E1-EC79-4A33-A971-1CCA5AF82AF1} - System32\Tasks\{CB09B9A0-6267-46BF-9ED5-D8F422D8B3E7} => pcalua.exe -a "C:\Program Files\eGames\Collector's Edition 251\gbrowser.exe" -d C:\PROGRA~1\eGames\COLLEC~1
Task: {19D4039D-5E6B-4F99-BFF9-63177728BF9B} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe [2008-12-10] (SAMSUNG Electronics co., LTD.)
Task: {19E46472-CA40-4549-9C15-C5EA706841E2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3319244995-2461475978-946539677-1000UA => C:\Users\Ute\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-11] (Google Inc.)
Task: {1D471684-0982-4BAE-AED2-8356D0FF9941} - System32\Tasks\{ECFF52B0-5E98-45EC-B390-A563540B90F8} => pcalua.exe -a C:\Users\Ute\Documents\SeaBounty\LibelleEaPAiW1Zauberer_v2-1-1.exe -d C:\Users\Ute\Documents\SeaBounty
Task: {22660A55-A79C-456A-968D-F16B3A606F38} - System32\Tasks\{3A6C636B-8F8E-48D3-9FFD-05FF6F15E948} => pcalua.exe -a C:\Users\Ute\Documents\SeaBounty\RatinaZNeuerAnfang_v2-1-0.exe -d C:\Users\Ute\Documents\SeaBounty
Task: {296567A4-45E9-4451-B1E6-D1541D1545A8} - System32\Tasks\{E07D4F2E-1D23-4F79-B89B-EDC976FA674D} => pcalua.exe -a C:\Users\Ute\Documents\SeaBounty\LibelleEaPAiW2Urfin_v2-1-0.exe -d C:\Users\Ute\Documents\SeaBounty
Task: {3CA93DF4-8B23-4E77-9EE8-1946C7B5E61D} - System32\Tasks\{803935D4-C84F-4A5D-9937-AB4E1D7BC668} => pcalua.exe -a E:\SETUP.EXE -d E:\
Task: {45E4780F-D05F-45B8-9981-5B1C2B819E5F} - System32\Tasks\{969F8821-AD74-4783-93ED-FA72A4D7D122} => pcalua.exe -a C:\Users\Ute\AppData\Local\Temp\Temp1_CulturesMemory.zip\AnguaCulturesMemory_v2-1-1.exe
Task: {53900DC5-DA25-4626-8A43-A73FB9D174CF} - System32\Tasks\{2284FDE9-81C5-41BC-BB5D-D1E912E5B427} => pcalua.exe -a "C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\32YCHNZ3\KraeutergWikingerInSpanien_v2-1-0[1].exe" -d C:\Users\Ute\Desktop
Task: {646AC055-A380-4725-8CF0-12454A65DD20} - System32\Tasks\{EE3C3404-B594-47AF-85C9-852EFCB44B7E} => pcalua.exe -a C:\Users\Ute\Documents\SeaBounty\RatinaZSinnlosSiedeln_v2-1-0.exe -d C:\Users\Ute\Documents\SeaBounty
Task: {64B4A6D6-8DAF-4160-B459-69852B2B24E2} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3319244995-2461475978-946539677-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.)
Task: {66272A2A-7C9A-4A74-99A6-BA34D3111465} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe [2009-05-20] ()
Task: {72BE2131-C30D-4303-ACC9-BDE24C4902AA} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2009-05-15] (Samsung Electronics Co., Ltd.)
Task: {73A257FE-6364-485A-8C32-B784B91915CA} - System32\Tasks\{B415D688-ADB9-458E-9C69-2D83D12F0122} => pcalua.exe -a C:\Users\Ute\Documents\BonusKarten[1]\CulturesBonuskarten.exe -d C:\Users\Ute\Documents\BonusKarten[1]
Task: {7A5CDB55-3310-48A1-A6E1-C81AEE00CC4D} - System32\Tasks\{C1BB8EEE-BA4E-457E-AD56-2A402EE83B48} => pcalua.exe -a C:\Users\Ute\Documents\SeaBounty\RatinaZHomeSweetHome_v2-1-0.exe -d C:\Users\Ute\Documents\SeaBounty
Task: {7CE71C52-B95A-4C9B-90A8-0DBA260545FC} - System32\Tasks\{83200B3F-9570-4D67-A688-82D5E9C537E1} => pcalua.exe -a E:\start.exe -d E:\
Task: {808A38B6-5350-4480-A5BE-DBB12269E7EC} - System32\Tasks\{9F30057C-0078-44C2-9E91-3483F6DF9BCA} => pcalua.exe -a E:\Setup.exe -d E:\
Task: {83675BD7-3552-48D7-A75A-8F9439A1F0AD} - System32\Tasks\{71E10746-3F35-4EF1-8114-9907D7EFA508} => pcalua.exe -a "C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\05Y4WL9J\AlixBildungsreise_v2-1-0[1].exe" -d C:\Users\Ute\Desktop
Task: {9CE94216-7118-4F87-8B84-E65C8EDA0BBF} - System32\Tasks\{D64C2172-9683-42AD-8555-73CF862B8F06} => pcalua.exe -a "C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L0ZCJJL4\c1_bonus_teufelsinsel[1].exe" -d C:\Users\Ute\Desktop
Task: {9D245785-4BCE-4599-909A-4288886144A6} - System32\Tasks\{A068C69F-C221-4601-BDEF-067C8EE72437} => pcalua.exe -a "C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\32YCHNZ3\KraeutergWikingerinGroenland_v2-1-0[1].exe" -d C:\Users\Ute\Desktop
Task: {ABCF425F-1515-49A3-BD10-B45D154C2B85} - System32\Tasks\advSRSIII => C:\Program Files\Samsung\Samsung Recovery Solution III\WCScheduler.exe [2009-03-11] ()
Task: {B0ECE529-7897-4BE0-B344-29BFBABD5EE2} - System32\Tasks\{FB52CB05-3A30-4002-ABAB-6D797FDD75D3} => pcalua.exe -a E:\setup.exe -d E:\
Task: {B58C9339-67B3-4424-A02B-31E8C8CA6140} - System32\Tasks\{D3383E7E-8CCD-49FC-9DA1-88CDC9D5B805} => pcalua.exe -a "C:\Users\Ute\Saved Games\MapperteamDerMeisterdieb_v2-1-2.exe" -d "C:\Users\Ute\Saved Games"
Task: {BD6AA34F-4839-455B-A927-A1BE582253C6} - System32\Tasks\SamsungMagicDoctor => C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe [2008-08-26] (Samsung Electronics Co., Ltd.)
Task: {BF14ECCE-D5F9-4FFA-9EAD-22841440DEF7} - System32\Tasks\{92999C05-0DD6-4462-801A-2166EAD75D19} => pcalua.exe -a "C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L0ZCJJL4\Bonus_C1_Schlangenfluss[1].exe" -d C:\Users\Ute\Desktop
Task: {CDACB262-3097-4069-97AC-F1E929C8A871} - System32\Tasks\{B5E3924E-C3ED-4DE8-9311-F99B265AF501} => pcalua.exe -a C:\Windows\UbiSoft\SetupUbi.exe -d C:\Windows\UbiSoft -c -play rayman2
Task: {D217FBC2-F525-482F-A2B3-DAFAD43A906C} - System32\Tasks\{8D5AC651-81B0-4B88-AF51-E806D2D87D81} => pcalua.exe -a "C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWGLMU0P\KraeutergBeautifulWorld_v2-1-0[1].exe" -d C:\Users\Ute\Desktop
Task: {D47BB5DB-B061-4C3B-A93C-65F76F3C3C87} - System32\Tasks\{3C82C23A-3A19-49B3-B305-C768F1325792} => pcalua.exe -a "C:\Program Files\eGames\GameButler\gbrowser.exe" -d "C:\Program Files\eGames\GameButler"
Task: {E1B0D4B6-1FE2-44C3-BB2C-FE7DB7895890} - System32\Tasks\{4FC8DE94-0DC3-4CE7-B9DC-878CBC6B9661} => pcalua.exe -a "C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UT96S05R\MapperteamSigurdUndDerKaiser_v2-1-0[1].exe" -d C:\Users\Ute\Desktop
Task: {E2B51B7C-59C4-43F7-BC8E-5CF6691533FF} - System32\Tasks\BatteryLifeExtender => C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2009-03-13] (Samsung Electronics. Co. Ltd.)
Task: {E84FD642-6327-4FF0-A3AA-C0E1657E3A99} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3319244995-2461475978-946539677-1000Core => C:\Users\Ute\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-11] (Google Inc.)
Task: {EC04A0AA-C1A8-4A41-BA8D-6BBC1515AFAB} - System32\Tasks\RunAsStdUser Task for VeohWebPlayer => C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe [2011-11-28] (Veoh Networks)
Task: {F0794984-29E7-4E64-B814-9728B072B284} - System32\Tasks\EasySpeedUpManager => C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [2009-05-28] (Samsung Electronics Co., Ltd.)
Task: {F097A079-5DEC-4294-94EF-D0E2CF5E98A8} - System32\Tasks\{25DF7638-DC80-4086-8346-7F49D918FDFD} => pcalua.exe -a C:\Users\Ute\Documents\SeaBounty\maebheWintermaeuse_v2-1-0.exe -d C:\Users\Ute\Documents\SeaBounty
Task: {F78452E9-97C4-44F7-9BB7-F5B04C78DE07} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Ute => C:\Program Files\Windows Calendar\WinCal.exe [2008-01-21] (Microsoft Corporation)
Task: {F920EDBE-F12C-4CE3-872E-103C40A2B669} - System32\Tasks\{A3CBA11F-6984-4255-9911-808C2A597A9F} => pcalua.exe -a C:\Users\Ute\Documents\SeaBounty\RatinaZFrostigeHeimat_v2-1-0.exe -d C:\Users\Ute\Documents\SeaBounty
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3319244995-2461475978-946539677-1000Core1cf90203bcaf9e2.job => C:\Users\Ute\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3319244995-2461475978-946539677-1000Core1cfed7e8f27647.job => C:\Users\Ute\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3319244995-2461475978-946539677-1000Core1cfff15c2bc780b.job => C:\Users\Ute\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3319244995-2461475978-946539677-1000Core1d041b41fc10145.job => C:\Users\Ute\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3319244995-2461475978-946539677-1000UA.job => C:\Users\Ute\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3319244995-2461475978-946539677-1000.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\Windows\Tasks\ReclaimerResumeInstall_Ute.job => C:\Users\Ute\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\11.02\agent\rnupgagent.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{0A1A3F3F-E741-4716-89DA-54FD6F86772A}.job => C:\Windows\system32\msfeedssync.exe
==================== Loaded Modules (whitelisted) ==============
2008-12-24 13:29 - 2008-12-24 13:29 - 00619816 ____N () C:\Program Files\CyberLink\Power2Go\CLMediaLibrary.dll
2008-12-24 13:30 - 2008-12-24 13:30 - 00013096 ____N () C:\Program Files\CyberLink\Power2Go\CLMLSvcPS.dll
2013-04-16 03:07 - 2013-04-16 03:07 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
2009-08-25 15:51 - 2008-11-25 16:27 - 00247152 ____N () C:\Program Files\CyberLink\Shared files\RichVideo.exe
2000-11-06 10:15 - 2000-11-06 10:15 - 00126976 _____ () C:\Program Files\Microsoft Office\Office10\intldate.dll
2015-04-18 14:53 - 2015-04-13 23:55 - 14980424 _____ () C:\Users\Ute\AppData\Local\Google\Chrome\Application\42.0.2311.90\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-3319244995-2461475978-946539677-1000\...\elsteronline.de -> hxxps://www.elsteronline.de
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-21-3319244995-2461475978-946539677-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Ute\Pictures\Bilder für Bildschirm\März 2014 002 bearb Ute.JPG
HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Ute\Pictures\Bilder für Bildschirm\März 2014 002 bearb Ute.JPG
HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Control Panel\Desktop\\Wallpaper -> C:\Users\Ute\Pictures\Bilder für Bildschirm\März 2014 002 bearb Ute.JPG
HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Control Panel\Desktop\\Wallpaper -> C:\Users\Ute\Pictures\Bilder für Bildschirm\März 2014 002 bearb Ute.JPG
HKU\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Control Panel\Desktop\\Wallpaper -> C:\Users\Ute\Pictures\Bilder für Bildschirm\März 2014 002 bearb Ute.JPG
DNS Servers: 195.50.140.180 - 195.50.140.114
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-3319244995-2461475978-946539677-500 - Administrator - Disabled)
Gast (S-1-5-21-3319244995-2461475978-946539677-501 - Limited - Disabled)
Ute (S-1-5-21-3319244995-2461475978-946539677-1000 - Administrator - Enabled) => C:\Users\Ute
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/23/2015 11:47:40 AM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoID={5BC0E34F-C805-44A6-B563-58DD0C2CAAAC}: Der Benutzer "Ute-PC\Ute" hat eine Verbindung mit dem Namen "ArcorOnline" gewählt, die Verbindung konnte jedoch nicht hergestellt werden. Der durch den Fehler zurückgegebene Ursachencode lautet: 815.
Error: (04/23/2015 00:51:50 AM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\UTE\DOCUMENTS\CFS\CFS UND ICH\SCHLAF U. ARBEIT 6 III.XLR> in der Hash-Zuordnung kann nicht aktualisiert werden.
Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
Error: (04/22/2015 00:00:22 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung veohwebplayer.exe, Version 1.3.8.1112, Zeitstempel 0x4ed38024, fehlerhaftes Modul QtCore4.dll, Version 4.7.0.0, Zeitstempel 0x4dff2959, Ausnahmecode 0xc0000005, Fehleroffset 0x00051ae6,
Prozess-ID 0x67c, Anwendungsstartzeit veohwebplayer.exe0.
Error: (04/21/2015 09:49:41 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/21/2015 09:39:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/21/2015 09:38:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/21/2015 07:28:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/21/2015 07:27:36 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/21/2015 07:27:36 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/21/2015 04:41:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (01/28/2011 06:21:33 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 28.01.2011 um 17:20:12 unerwartet heruntergefahren.
Error: (01/28/2011 05:04:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: SQL Server VSS Writer1
Error: (01/28/2011 05:04:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
Error: (01/28/2011 05:04:19 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032
Error: (01/28/2011 05:03:15 PM) (Source: HTTP) (EventID: 15016) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (01/28/2011 05:01:54 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: 30000Netman
Error: (01/28/2011 03:28:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: SQL Server VSS Writer1
Error: (01/28/2011 03:28:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
Error: (01/28/2011 03:28:35 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032
Error: (01/28/2011 03:27:19 PM) (Source: HTTP) (EventID: 15016) (User: )
Description: \Device\Http\ReqQueueKerberos
Microsoft Office Sessions:
=========================
Error: (04/23/2015 11:47:40 AM) (Source: RasClient) (EventID: 20227) (User: )
Description: {5BC0E34F-C805-44A6-B563-58DD0C2CAAAC}Ute-PC\UteArcorOnline815
Error: (04/23/2015 00:51:50 AM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext: Anwendung, SystemIndex Katalog
Details:
Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f)
C:\USERS\UTE\DOCUMENTS\CFS\CFS UND ICH\SCHLAF U. ARBEIT 6 III.XLR
Error: (04/22/2015 00:00:22 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: veohwebplayer.exe1.3.8.11124ed38024QtCore4.dll4.7.0.04dff2959c000000500051ae667c01d07c6c1addda24
Error: (04/21/2015 09:49:41 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/21/2015 09:39:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/21/2015 09:38:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe
Error: (04/21/2015 07:28:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/21/2015 07:27:36 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe
Error: (04/21/2015 07:27:36 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe
Error: (04/21/2015 04:41:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
CodeIntegrity Errors:
===================================
Date: 2015-04-23 16:42:26.246
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-04-23 16:42:25.869
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-04-23 16:42:25.505
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-04-23 16:42:25.086
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-04-23 16:42:24.420
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-04-23 16:42:23.998
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-04-23 16:42:23.485
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-04-23 16:42:23.066
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-04-23 16:41:49.483
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-04-23 16:41:49.050
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz
Percentage of memory in use: 58%
Total physical RAM: 3031.88 MB
Available physical RAM: 1256.42 MB
Total Pagefile: 6292.16 MB
Available Pagefile: 4116.72 MB
Total Virtual: 2047.88 MB
Available Virtual: 1903.14 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:169.88 GB) (Free:72.43 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:50 GB) (Free:30.98 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: D4BD9B58)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=169.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS)
==================== End Of Log ============================ --- --- ---
Gleich geht es noch weiter ...
Hier geht es weiter 2.Teil:
3. Gmer.txt-Logfile-Kopie: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-04-23 17:56:40
Windows 6.0.6001 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST925031 rev.0001 232,89GB
Running: d3tj1l52.exe; Driver: C:\Users\Ute\AppData\Local\Temp\uwldapow.sys
---- System - GMER 2.1 ----
SSDT 8D1F98E6 ZwCreateSection
SSDT 8D1F98BE ZwCreateSymbolicLinkObject
SSDT 8D1F98C3 ZwLoadDriver
SSDT 8D1F98B9 ZwOpenSection
SSDT 8D1F98F0 ZwRequestWaitReplyPort
SSDT 8D1F98EB ZwSetContextThread
SSDT 8D1F98F5 ZwSetSecurityObject
SSDT 8D1F98C8 ZwSetSystemInformation
SSDT 8D1F98FA ZwSystemDebugControl
SSDT 8D1F9887 ZwTerminateProcess
SSDT 8D1F9882 ZwWriteVirtualMemory
---- Kernel code sections - GMER 2.1 ----
.text ntoskrnl.exe!KeInsertQueue + 405 820799CC 4 Bytes [E6, 98, 1F, 8D]
.text ntoskrnl.exe!KeInsertQueue + 40D 820799D4 4 Bytes [BE, 98, 1F, 8D]
.text ntoskrnl.exe!KeInsertQueue + 56D 82079B34 4 Bytes [C3, 98, 1F, 8D]
.text ntoskrnl.exe!KeInsertQueue + 5ED 82079BB4 4 Bytes [B9, 98, 1F, 8D]
.text ntoskrnl.exe!KeInsertQueue + 729 82079CF0 4 Bytes [F0, 98, 1F, 8D]
.text ...
.reloc C:\Windows\system32\drivers\acedrv11.sys section is executable [0xB6822580, 0x29E04, 0xE0000060]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Emsisoft Anti-Malware\a2service.exe[4448] ntdll.dll!TpCheckTerminateWorker + 56 77ACE90C 7 Bytes JMP 0706883C C:\Program Files\Emsisoft Anti-Malware\a2update.dll
.text C:\Program Files\Emsisoft Anti-Malware\a2service.exe[4448] kernel32.dll!CreateEventExW + 7E 77C548DB 7 Bytes JMP 0706866C C:\Program Files\Emsisoft Anti-Malware\a2update.dll
.text C:\Program Files\Emsisoft Anti-Malware\a2service.exe[4448] kernel32.dll!CreateFileW + 31E 77C5D16C 7 Bytes JMP 070181B4 C:\Program Files\Emsisoft Anti-Malware\a2update.dll
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtCreateFile 77AE7C78 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtCreateFile + 4 77AE7C7C 2 Bytes [86, 71]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtDeleteValueKey 77AE8098 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtDeleteValueKey + 4 77AE809C 2 Bytes [8C, 71]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtOpenFile 77AE8458 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtOpenFile + 4 77AE845C 2 Bytes [83, 71]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtOpenProcess 77AE84D8 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtOpenProcess + 4 77AE84DC 2 Bytes [89, 71]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtSetContextThread 77AE8AC8 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtSetContextThread + 4 77AE8ACC 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtSetInformationFile 77AE8B88 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtSetInformationFile + 4 77AE8B8C 2 Bytes [80, 71]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtSetValueKey 77AE8CF8 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[10252] ntdll.dll!NtSetValueKey + 4 77AE8CFC 2 Bytes [8F, 71]
.text C:\Windows\system32\wuauclt.exe[10252] kernel32.dll!GetConsoleScreenBufferInfoEx + 132 77C331BD 4 Bytes JMP 71AF000A
.text C:\Windows\system32\wuauclt.exe[10252] kernel32.dll!CreateProcessInternalW 77C39AD0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[10252] kernel32.dll!CreateProcessInternalW + 4 77C39AD4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Windows\system32\wuauclt.exe[10252] USER32.dll!SendInput 76F8BEE7 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[10252] USER32.dll!SendInput + 4 76F8BEEB 2 Bytes [A4, 71]
.text C:\Windows\system32\wuauclt.exe[10252] USER32.dll!SendMessageA 76F90459 6 Bytes JMP 71A2000A
.text C:\Windows\system32\wuauclt.exe[10252] USER32.dll!PostMessageA 76F911CE 6 Bytes JMP 719C000A
.text C:\Windows\system32\wuauclt.exe[10252] USER32.dll!PostMessageW 76F9A064 6 Bytes JMP 7199000A
.text C:\Windows\system32\wuauclt.exe[10252] USER32.dll!SendMessageW 76FA0AB1 6 Bytes JMP 719F000A
.text C:\Windows\system32\wuauclt.exe[10252] USER32.dll!mouse_event 76FB1305 6 Bytes JMP 71AB000A
.text C:\Windows\system32\wuauclt.exe[10252] USER32.dll!keybd_event 76FDD93C 6 Bytes JMP 71A8000A
.text C:\Windows\system32\wuauclt.exe[10252] ADVAPI32.dll!CreateServiceW 774338FF 6 Bytes JMP 7193000A
.text C:\Windows\system32\wuauclt.exe[10252] ADVAPI32.dll!CreateServiceA 77476C71 6 Bytes JMP 7196000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtCreateFile 77AE7C78 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtCreateFile + 4 77AE7C7C 2 Bytes [86, 71]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtDeleteValueKey 77AE8098 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtDeleteValueKey + 4 77AE809C 2 Bytes [8C, 71]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtOpenFile 77AE8458 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtOpenFile + 4 77AE845C 2 Bytes [83, 71]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtOpenProcess 77AE84D8 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtOpenProcess + 4 77AE84DC 2 Bytes [89, 71]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtSetContextThread 77AE8AC8 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtSetContextThread + 4 77AE8ACC 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtSetInformationFile 77AE8B88 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtSetInformationFile + 4 77AE8B8C 2 Bytes [80, 71]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtSetValueKey 77AE8CF8 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ntdll.dll!NtSetValueKey + 4 77AE8CFC 2 Bytes [8F, 71]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] kernel32.dll!GetConsoleScreenBufferInfoEx + 132 77C331BD 4 Bytes JMP 71AF000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] kernel32.dll!SetUnhandledExceptionFilter 77C3700D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] kernel32.dll!CreateProcessInternalW 77C39AD0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] kernel32.dll!CreateProcessInternalW + 4 77C39AD4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] USER32.dll!SendInput 76F8BEE7 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] USER32.dll!SendInput + 4 76F8BEEB 2 Bytes [A4, 71]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] USER32.dll!SendMessageA 76F90459 6 Bytes JMP 71A2000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] USER32.dll!PostMessageA 76F911CE 6 Bytes JMP 719C000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] USER32.dll!PostMessageW 76F9A064 6 Bytes JMP 7199000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] USER32.dll!SendMessageW 76FA0AB1 6 Bytes JMP 719F000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] USER32.dll!mouse_event 76FB1305 6 Bytes JMP 71AB000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] USER32.dll!keybd_event 76FDD93C 6 Bytes JMP 71A8000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ADVAPI32.dll!CreateServiceW 774338FF 6 Bytes JMP 7193000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] ADVAPI32.dll!CreateServiceA 77476C71 6 Bytes JMP 7196000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] WS2_32.dll!connect 774C40D9 6 Bytes JMP 7178000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] WS2_32.dll!WSALookupServiceBeginW 774C4E93 6 Bytes JMP 716F000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] WS2_32.dll!listen 774C8CD7 6 Bytes JMP 7172000A
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[10896] WS2_32.dll!WSAConnect 774CD7B0 6 Bytes JMP 7175000A
.text C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2guard.exe[15900] ntdll.dll!TpCheckTerminateWorker + 56 77ACE90C 7 Bytes JMP 02B6CA84 C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2framework.dll
.text C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2guard.exe[15900] kernel32.dll!CreateEventExW + 7E 77C548DB 7 Bytes JMP 02B6C8B4 C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2framework.dll
.text C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2guard.exe[15900] kernel32.dll!CreateFileW + 31E 77C5D16C 7 Bytes JMP 02B1860C C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2framework.dll
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtCreateFile 77AE7C78 3 Bytes [FF, 25, 1E]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtCreateFile + 4 77AE7C7C 2 Bytes [86, 71]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtDeleteValueKey 77AE8098 3 Bytes [FF, 25, 1E]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtDeleteValueKey + 4 77AE809C 2 Bytes [8C, 71]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtOpenFile 77AE8458 3 Bytes [FF, 25, 1E]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtOpenFile + 4 77AE845C 2 Bytes [83, 71]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtOpenProcess 77AE84D8 3 Bytes [FF, 25, 1E]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtOpenProcess + 4 77AE84DC 2 Bytes [89, 71]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtSetContextThread 77AE8AC8 3 Bytes [FF, 25, 1E]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtSetContextThread + 4 77AE8ACC 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtSetInformationFile 77AE8B88 3 Bytes [FF, 25, 1E]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtSetInformationFile + 4 77AE8B8C 2 Bytes [80, 71]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtSetValueKey 77AE8CF8 3 Bytes [FF, 25, 1E]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ntdll.dll!NtSetValueKey + 4 77AE8CFC 2 Bytes [8F, 71]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] kernel32.dll!GetConsoleScreenBufferInfoEx + 132 77C331BD 4 Bytes JMP 71AF000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] kernel32.dll!CreateProcessInternalW 77C39AD0 3 Bytes [FF, 25, 1E]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] kernel32.dll!CreateProcessInternalW + 4 77C39AD4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] USER32.dll!SendInput 76F8BEE7 3 Bytes [FF, 25, 1E]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] USER32.dll!SendInput + 4 76F8BEEB 2 Bytes [A4, 71]
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] USER32.dll!SendMessageA 76F90459 6 Bytes JMP 71A2000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] USER32.dll!PostMessageA 76F911CE 6 Bytes JMP 719C000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] USER32.dll!PostMessageW 76F9A064 6 Bytes JMP 7199000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] USER32.dll!SendMessageW 76FA0AB1 6 Bytes JMP 719F000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] USER32.dll!mouse_event 76FB1305 6 Bytes JMP 71AB000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] USER32.dll!keybd_event 76FDD93C 6 Bytes JMP 71A8000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ADVAPI32.dll!CreateServiceW 774338FF 6 Bytes JMP 7193000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] ADVAPI32.dll!CreateServiceA 77476C71 6 Bytes JMP 7196000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] WS2_32.dll!connect 774C40D9 6 Bytes JMP 7178000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] WS2_32.dll!WSALookupServiceBeginW 774C4E93 6 Bytes JMP 716F000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] WS2_32.dll!listen 774C8CD7 6 Bytes JMP 7172000A
.text C:\Users\Ute\Downloads\d3tj1l52.exe[20644] WS2_32.dll!WSAConnect 774CD7B0 6 Bytes JMP 7175000A
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys
---- Processes - GMER 2.1 ----
Process (*** hidden *** ) [4] 8464BD90
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
4. Letzte Scan-Ergebnisse mit Funden
Scan mit ESET onlinescanner am 22.4.2015 über Mittag (Alle aus Quarantäne gelöscht! Kam der Trojaner über Veho (wegen C:\Program Files\Veoh Networks\VeohWebPlayer\ConduitInstaller_veoh.exe Win32/Toolbar.Conduit) ?) Code:
C:\Program Files\Conduit\Community Alerts\Alert.dll Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Program Files\Conduit\Community Alerts\Alert0.dll Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Program Files\Veoh Networks\VeohWebPlayer\ConduitInstaller_veoh.exe Win32/Toolbar.Conduit evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Program Files\Veoh Networks\VeohWebPlayer\qlps-qlipso-sntb.exe Win32/Toolbar.Zugo evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Ute\AppData\Local\Conduit\APISupport\APISupport.dll Variante von Win32/Conduit.SearchProtect.P evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Ute\Documents\zu Spielen u. Sonstiges\VeohWebPlayer122Setup_eng.exe Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Ute\Videos\Veoh\1157_VeohWebPlayerSetup_other_upgrade.exe Win32/Toolbar.Conduit.M evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Ute\Videos\Veoh\1_VeohWebPlayerSetup_other_upgrade.exe Win32/Toolbar.Zugo evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Ute\Videos\Veoh\VeohWebPlayerSetup_other_upgrade.exe Win32/Toolbar.Zugo evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
Scan mit Emsisoft Anti-Malware. Das Programm blieb bei 67 % des Datei-Scans stecken. Bei einem weiteren, vollständigen Suchlauf wurde aber nichts Zusätzliches gefunden. Einiges, das eindeutig mit Conduit oder SearchProtect in Verbindung stand, habe ich schon aus der Quarantäne gelöscht. Bei Folgendem bin ich mir aber nicht sicher, habe ich dringelassen in der Quarantäne:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader gefunden: Application.AdStart (A)
C:\ProgramData\ytd video downloader gefunden: Application.AppInstall (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PROTECTOR_DLL.PROTECTORBHO gefunden: Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PROTECTOR_DLL.PROTECTORBHO.1 gefunden: Application.AdReg (A)
Value: HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN -> VEOHPLUGIN gefunden: Application.AdStart (A)
Value: HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN -> VEOHPLUGIN gefunden: Application.AdStart (A)
Value: HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN -> VEOHPLUGIN gefunden: Application.AdStart (A)
(Die von EMSI in der Avira-Quarantäne gefundenen Sachen waren ca. zwei Jahre alt … ich hatte mich damals nicht getraut, sie ganz zu löschen :crazy: …)
Logfiles der EMSI Anti-Malware-Scans: Code:
Emsisoft Anti-Malware - Version 9.0
Letztes Update: 22.04.2015 16:08:29
Benutzerkonto: Ute-PC\Ute
Scan-Einstellungen:
Scan Methode: Detail-Scan
Objekte: Rootkits, Speicher, Traces, C:\, D:\
PUPs-Erkennung: An
Archiv-Scan: An
ADS Scan: An
Dateitypen-Filter: Aus
Erweitertes Caching: An
Direkter Festplattenzugriff: Aus
Scan-Beginn: 22.04.2015 16:09:58
C:\Program Files\Conduit gefunden: Application.AppInstall (A)
C:\Program Files\Searchprotect gefunden: Application.AppInstall (A)
C:\Users\Ute\AppData\Roaming\Searchprotect gefunden: Application.AppInstall (A)
C:\Users\Ute\AppData\Roaming\Searchprotect gefunden: Application.AppInstall (A)
C:\Users\Ute\AppData\Roaming\Searchprotect gefunden: Application.AppInstall (A)
C:\Users\Ute\AppData\Local\Conduit gefunden: Application.AppInstall (A)
C:\Users\Ute\AppData\Local\Conduit gefunden: Application.AppInstall (A)
C:\Users\Ute\AppData\Local\Conduit gefunden: Application.AppInstall (A)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader gefunden: Application.AdStart (A)
C:\ProgramData\ytd video downloader gefunden: Application.AppInstall (A)
Key: HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000\SOFTWARE\CONDUIT gefunden: Application.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT gefunden: Application.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\CONDUIT gefunden: Application.InstallAd (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CONDUIT gefunden: Application.InstallAd (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\SEARCHPROTECT gefunden: Application.InstallAd (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PROTECTOR_DLL.PROTECTORBHO gefunden: Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PROTECTOR_DLL.PROTECTORBHO.1 gefunden: Application.AdReg (A)
Value: HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN -> VEOHPLUGIN gefunden: Application.AdStart (A)
Value: HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN -> VEOHPLUGIN gefunden: Application.AdStart (A)
Value: HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN -> VEOHPLUGIN gefunden: Application.AdStart (A)
C:\ProgramData\Avira\Antivirus\INFECTED\4e3ef3db.qua -> (Quarantine-8) gefunden: Trojan.Generic.12317037 (B)
C:\ProgramData\Avira\Antivirus\INFECTED\50d55fd5.qua -> (Quarantine-8) gefunden: Trojan.Generic.12317037 (B)
C:\ProgramData\Avira\Antivirus\INFECTED\568ed276.qua -> (Quarantine-8) gefunden: Trojan.Generic.12317037 (B)
C:\ProgramData\Avira\Antivirus\INFECTED\56a9d9d4.qua -> (Quarantine-8) gefunden: Trojan.Generic.12317037 (B)
Gescannt 147436
Gefunden 24
Scan-Ende: 22.04.2015 17:34:37
Scan-Zeit: 1:24:39
Hat sich nach 67% der Dateien „aufgehängt“
Emsisoft Anti-Malware - Version 9.0
Letztes Update: 22.04.2015 18:09:05
Benutzerkonto: Ute-PC\Ute
Scan-Einstellungen:
Scan Methode: Detail-Scan
Objekte: Rootkits, Speicher, Traces, C:\, D:\
PUPs-Erkennung: An
Archiv-Scan: An
ADS Scan: An
Dateitypen-Filter: Aus
Erweitertes Caching: An
Direkter Festplattenzugriff: Aus
Scan-Beginn: 22.04.2015 18:13:12
Gescannt 298167
Gefunden 0
Scan-Ende: 22.04.2015 21:12:20
Scan-Zeit: 2:59:08
RKill – Logfile (Hosts-perm.bat habe ich probiert, der bekam aber offensichtlich keinen Zugriff): Code:
Rkill 2.7.0 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
hxxp://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 04/23/2015 11:53:55 AM in x86 mode.
Windows Version: Windows Vista (TM) Home Basic Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* Cannot edit the HOSTS file.
* Permissions could not be fixed. Use Hosts-perm.bat to fix permissions: hxxp://www.bleepingcomputer.com/download/hosts-permbat/
* HOSTS file entries found:
127.0.0.1 localhost
::1 localhost
Program finished at: 04/23/2015 11:55:40 AM
Execution time: 0 hours(s), 1 minute(s), and 45 seconds(s) Logfile des RogueKillers (davon habe ich noch gar nichts gelöscht, bin mir zu unsicher und will nicht noch zusätzlichen Schaden anrichten): Code:
RogueKiller V10.6.0.0 [Apr 17 2015] by Adlice Software
Mail : hxxp://www.adlice.com/contact/
Feedback : hxxp://forum.adlice.com
Website : hxxp://www.adlice.com/softwares/roguekiller/
Blog : hxxp://www.adlice.com
Betriebssystem : Windows Vista (6.0.6001 Service Pack 1) 32 bits version
gestarted in : normaler Modus
User : Ute [Administrator]
Started from : c:\Users\Ute\Documents\RogueKiller_bundle_10.6[1]\RogueKiller.exe
Modus : Scannen -- Datum : 04/23/2015 15:36:17
¤¤¤ Prozesse : 0 ¤¤¤
¤¤¤ Registry : 24 ¤¤¤
[PUM.HomePage] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : hxxp://www.arcor.de -> Gefunden
[PUM.SearchPage] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : hxxp://www.arcor.de -> Gefunden
[PUM.SearchPage] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000\Software\Microsoft\Internet Explorer\Main | Search Page : hxxp://www.arcor.de -> Gefunden
[PUM.SearchPage] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main | Search Page : hxxp://www.arcor.de -> Gefunden
[PUM.SearchPage] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Internet Explorer\Main | Search Page : hxxp://www.arcor.de -> Gefunden
[PUM.SearchPage] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Internet Explorer\Main | Search Page : hxxp://www.arcor.de -> Gefunden
[PUM.SearchPage] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Software\Microsoft\Internet Explorer\Main | Search Page : hxxp://www.arcor.de -> Gefunden
[PUM.StartMenu] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> Gefunden
[PUM.StartMenu] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> Gefunden
[PUM.StartMenu] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> Gefunden
[PUM.StartMenu] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> Gefunden
[PUM.StartMenu] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> Gefunden
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3319244995-2461475978-946539677-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
¤¤¤ Aufgaben : 0 ¤¤¤
¤¤¤ Dateien : 0 ¤¤¤
¤¤¤ Host Dateien : 2 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost
[C:\Windows\System32\drivers\etc\hosts] ::1 localhost
¤¤¤ Antirootkit : 2 (Driver: geladen) ¤¤¤
[ShwSSDT:Addr(Hook.Shadow)] NtUserSetWindowsHookEx[573] : Unknown @ 0x8d1f990e
[ShwSSDT:Addr(Hook.Shadow)] NtUserSetWinEventHook[576] : Unknown @ 0x8d1f9913
¤¤¤ Web Browser : 0 ¤¤¤
¤¤¤ MBR Überprüfung : ¤¤¤
+++++ PhysicalDrive0: ST9250315AS +++++
--- User ---
[MBR] 878857e21ffee71d492207ab3c5df340
[BSP] 01a1ee4cb5dea573b534737dec1835d1 : Kiwi|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 13312 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 27265024 | Size: 173959 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 383533056 | Size: 51202 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_04212015_225552.log - RKreport_DEL_04212015_232215.log Soweit erstmal, vielen Dank für die Mühe!
Undine |