![]() |
alle daten verschlüßelt hallo, ich habe das problem das ich meine daten nicht entschlüßelt bekomme. hatte den trojaner drauf wo nach dem start des rechners windowos gespert war. habe dann im gesichertem modus gestartet und mit sys-wiederherstellung den rechner ans laufen gebracht. mußte aber feststellen das alle dateien von mir (bilder, musik vidios) verschlüßelt sind. wie bekomme ich die wieder frei??? habe schon die hier angegebenen tool versucht. nix geht. ich bin echt nur anwender und wie man bestimmt aus der schreibweise erkennen kann habe ich keinerlei ahnung was ich tun soll. bitte helft mir..... hier mal das ergebnis Malwarebytes Anti-Malware (Test) 1.62.0.1300 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Datenbank Version: v2012.07.14.03 Windows 7 x86 NTFS Internet Explorer 8.0.7600.16385 1_Sascha :: SASCHAHP [Administrator] Schutz: Deaktiviert 14.07.2012 12:43:59 mbam-log-2012-07-14 (12-43-59).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 342369 Laufzeit: 45 Minute(n), 40 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 1 HKCR\.fsharproj (Trojan.BHO) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 4 C:\Windows\System32\020000008bfe8d1a1111C.manifest (Malware.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\020000008bfe8d1a1111O.manifest (Malware.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\020000008bfe8d1a1111P.manifest (Malware.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\System32\020000008bfe8d1a1111S.manifest (Malware.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) |
hi Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code: activex
|
PM - Run 1 OTL by OldTimer - Version 3.2.53.1 Folder = C:\1_internet\Download Professional (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 1.63 Gb Available Physical Memory | 54.41% Memory free 6.00 Gb Paging File | 4.59 Gb Available in Paging File | 76.55% Paging File free Paging file location(s): c:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 455.86 Gb Total Space | 306.39 Gb Free Space | 67.21% Space Free | Partition Type: NTFS Drive D: | 9.80 Gb Total Space | 1.20 Gb Free Space | 12.28% Space Free | Partition Type: NTFS Computer Name: SASCHAHP | User Name: 1_Sascha | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\programme_1\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\programme_1\Office_2003\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\programme_1\Office_2003\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- Reg Error: Key error. https [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\programme_1\vlc player\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\programme_1\vlc player\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{060FC726-52CF-4CC6-8CB6-32C313013FE3}" = lport=10243 | protocol=6 | dir=in | app=system | "{0C6168CF-DBBB-437C-BA4A-7139FF21712E}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{0E5C005E-4006-421D-82CB-5FC466D050D6}" = lport=2869 | protocol=6 | dir=in | app=system | "{190A0678-C413-4F3A-AD42-62D11B6C839A}" = lport=139 | protocol=6 | dir=in | app=system | "{2FD84458-3BBA-4819-B7E6-AF41FBE2BF07}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{366F75F8-657F-4E42-8424-8E2D2BDE545D}" = rport=138 | protocol=17 | dir=out | app=system | "{41B320FF-5839-4197-8F58-24C7135F1A1C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{44753531-C96C-485A-BDAC-1BB38D8CD31A}" = rport=445 | protocol=6 | dir=out | app=system | "{47D26CEC-4514-419E-8BC5-DDCC244D809D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{4EC48E33-C11A-4C94-BD34-469B0F49D8C1}" = rport=137 | protocol=17 | dir=out | app=system | "{55800334-A651-443D-A16B-69DA468361AB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{6BD884DE-E7F5-4B4F-A00A-DE6398FF4780}" = rport=139 | protocol=6 | dir=out | app=system | "{8843BDEB-E763-4256-B9B5-31415A9D4A61}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{8DC837E8-7543-46A7-8C3A-BCE68A9725F7}" = lport=445 | protocol=6 | dir=in | app=system | "{93F3D1F5-3CDB-4B96-BFF8-A1770F5E8170}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{9B74E38B-4BF4-4486-989C-166631047D79}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BA78E729-1C5F-479F-BD31-BAC4E24F2FCD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C9068ADC-E372-4C96-9AD8-B17BC8D2E2CE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{DA0B046D-FABB-49F3-8A78-AEF2E3847A79}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{EB3FCA22-2B92-44F5-B241-D04E99BBC732}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe | "{ED9942D7-C8CC-4562-A20C-B52E7EE05E0D}" = rport=10243 | protocol=6 | dir=out | app=system | "{EEEB38CA-13F8-46B3-B248-7A6ED7955F57}" = lport=138 | protocol=17 | dir=in | app=system | "{F2123DF4-452F-4D57-A170-864B9CD07CE5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F5BDF41B-27E7-4966-A458-6F46CC049084}" = lport=137 | protocol=17 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{009FDABC-577B-4AD9-AF89-6FDEC0E56927}" = dir=in | app=c:\windows\usbceipwow.exe | "{00CA1109-68F6-4479-8EF0-D6959B9FEEBA}" = dir=in | app=c:\windows\api-ms-win-core-fibers-l1-1-032wow.exe | "{021CC107-E49A-4111-886E-2025A04C638E}" = dir=in | app=c:\programdata\api-ms-win-core-fibers-l1-1-032.exe | "{0243BB65-63D2-4C63-839D-9FE000FEEED2}" = dir=in | app=c:\windows\api-ms-win-core-fibers-l1-1-0wow.exe | "{02AA839E-78AC-4C0A-B672-F55C4FE49CF3}" = dir=in | app=c:\windows\perftrackwow.exe | "{03034271-8702-4B21-B229-8847BC96E0A0}" = dir=in | app=c:\windows\snmpapiwow.exe | "{0423C034-A227-426D-87CE-90E5329E8450}" = dir=in | app=c:\windows\rdpd3dwow.exe | "{043CC49B-A67E-481B-9558-2A33F262BE4F}" = dir=in | app=c:\windows\amxreadwow.exe | "{049E8DD4-BCE0-48CB-86C3-A45639779CDA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{0510646D-CB64-4630-AD59-D2D05E46B192}" = dir=in | app=c:\windows\bitsprx5wow.exe | "{057605B1-D9A9-4342-B31F-ACAE573683EC}" = dir=in | app=c:\windows\amxreadwow.exe | "{076E67B1-93C3-4B95-9978-AF3824814D79}" = dir=in | app=c:\windows\rtmwow.exe | "{09939E62-426D-43C9-B9A0-BFC48BB4AD64}" = dir=in | app=c:\windows\difxapiwow.exe | "{0AF99692-DA0A-45B5-ACF5-1598F34B1E74}" = dir=in | app=c:\windows\drtprovwow.exe | "{0C9D4F86-3422-43FD-906B-7BAE84A0EA07}" = dir=in | app=c:\windows\dpxwow.exe | "{0D25E5B3-2EE7-46BA-B95C-EA9F9B51D864}" = dir=in | app=c:\windows\fxstiffwow.exe | "{0E1D8D02-5ED2-45CF-AF5C-7A6E00DDFF21}" = dir=in | app=c:\windows\wmadmodwow.exe | "{0EF18DDB-9BC4-4346-BC30-FC0415A55D2D}" = dir=in | app=c:\windows\msscntrswow.exe | "{0F9F1F4F-1E00-42C6-8486-693A1F04D69D}" = dir=in | app=c:\windows\d3d10_1corewow.exe | "{10B37A98-1004-4000-B4BD-FF081390B735}" = dir=in | app=c:\windows\kbda1wow.exe | "{10EEBB32-9F57-4821-8834-2BF02D27DCB7}" = dir=in | app=c:\windows\iglhcp32wow.exe | "{12D80F7D-9EE0-471A-9500-22FD9BB11CB9}" = dir=in | app=c:\windows\snmpapiwow.exe | "{1447C417-B739-4E16-937A-3AD072D1071B}" = dir=in | app=c:\windows\rdpd3dwow.exe | "{145326E2-06A4-4E13-AEDA-2A8BBE0F35C0}" = dir=in | app=c:\windows\msprpdewow.exe | "{151CF45D-D831-44BB-A0C3-FA8D3381FB0A}" = dir=in | app=c:\windows\iprtrmgrwow.exe | "{16835C89-B243-4F73-B1FA-41E49C088C3A}" = dir=in | app=c:\programdata\shellwow.exe | "{17643BF0-D2C5-4C4B-B197-F52B77565173}" = dir=in | app=c:\windows\api-ms-win-core-misc-l1-1-0wow.exe | "{1815DE83-8555-4F1A-8173-3BAAC0026BBC}" = dir=in | app=c:\windows\msacmwow.exe | "{19ADFD0A-FC1A-46B8-9041-0C445775EC7A}" = dir=in | app=c:\windows\iglhcp32wow.exe | "{1ADB188E-E2A3-4DA6-B038-F7E573C549EE}" = dir=in | app=c:\windows\mssip32wow.exe | "{1CE47FCC-AE7D-4D4B-AFE6-906059560D98}" = dir=in | app=c:\windows\iglhcp32wow.exe | "{1D15BEC6-1CC5-4FF9-883D-4F6A1926879D}" = dir=in | app=c:\windows\msscntrswow.exe | "{1D6A4DD0-1514-49AA-A8F8-3C8716E8B057}" = dir=in | app=c:\windows\azroleuiwow.exe | "{1D91DBD8-E0CF-4524-B834-7982128A9ED7}" = dir=in | app=c:\windows\usbceipwow.exe | "{1E7F578E-F033-457C-9371-463EFAA69091}" = dir=in | app=c:\windows\wlanhlpwow.exe | "{1EEFACC5-B62B-4C90-A4C0-A6AC52E4710C}" = dir=in | app=c:\windows\difxapiwow.exe | "{202BBF0A-B6F2-491E-8BA4-53511BFA3EE4}" = dir=in | app=c:\windows\amxreadwow.exe | "{203F00C6-D918-4957-80FE-B1655FBCCA84}" = dir=in | app=c:\windows\api-ms-win-core-misc-l1-1-0wow.exe | "{21431522-3B74-4A2E-AD0F-D332290101FF}" = dir=in | app=c:\windows\msscntrswow.exe | "{2175EBE1-C0F6-4E53-8BAC-711AA764D17F}" = dir=in | app=c:\windows\api-ms-win-core-fibers-l1-1-032wow.exe | "{21D0392C-B673-4ED0-B8D2-7A215994793D}" = dir=in | app=c:\windows\vdsbaswow.exe | "{23335475-014A-46A5-BFF7-8B5BF58CC389}" = dir=in | app=c:\windows\msscntrswow.exe | "{234234EC-FDB6-4C61-BC0B-72FCACC7FEDE}" = dir=in | app=c:\windows\provsvcwow.exe | "{2419CFAD-AD9A-480F-844D-96A322545B4D}" = dir=in | app=c:\windows\sdrsvcwow.exe | "{263363AF-22D9-4C81-BED3-1343F5909547}" = dir=in | app=c:\windows\localsecwow.exe | "{268859C1-FB63-4CFF-A44B-58C488272ADF}" = dir=in | app=c:\windows\msacmwow.exe | "{2833CCA6-99AB-4460-B2CE-5AAA1D19E59F}" = dir=in | app=c:\programdata\adsnt32.exe | "{28FADACE-484D-4AD3-8C5F-8D56C1C99BC9}" = dir=in | app=c:\windows\trkwkswow.exe | "{2962A70E-0391-481E-8FE0-BFF0E51DBE23}" = dir=in | app=c:\windows\displaywow.exe | "{2B2FCE4F-0C06-4A3A-950A-9E046D4A4553}" = dir=in | app=c:\windows\kernelceipwow.exe | "{2C0BEEC0-CA0D-4F84-AE4B-43780224139F}" = dir=in | app=c:\windows\naphlprwow.exe | "{2C6CDF0D-A85C-4CA7-9C96-4DDF3972860E}" = dir=in | app=c:\programdata\wmadmoe32.exe | "{2C9E2874-B957-4B20-BE01-115503C231D8}" = dir=in | app=c:\windows\drtprovwow.exe | "{2EC900D2-C852-4B88-96CD-E38BB53747B4}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | "{2F77E0CD-0253-4D6B-83F2-B73036ECADF9}" = dir=in | app=c:\windows\vdsbaswow.exe | "{30B301E6-A075-4AF4-AA90-638E12CEB3BA}" = dir=in | app=c:\windows\hpbmiapiwow.exe | "{317884AC-47DC-4BF3-9836-B49E48538911}" = dir=in | app=c:\windows\difxapiwow.exe | "{31CD70BB-E0B9-4D0C-B527-715CE2E33E81}" = dir=in | app=c:\windows\untfswow.exe | "{32CF1C8A-14E3-449B-8780-C82AD6122FB4}" = dir=in | app=c:\windows\msscntrswow.exe | "{3305D8EE-4B83-4F05-9779-34B7154D5B8D}" = dir=in | app=c:\windows\wintrustwow.exe | "{330B29AF-019D-4583-9CCD-F27D6F88C6B8}" = dir=in | app=c:\windows\usbceipwow.exe | "{33E2768B-2193-4A20-BECD-2832AB11FC2A}" = dir=in | app=c:\windows\iasmigpluginwow.exe | "{33F3E751-4965-478E-8DF2-68DDAFC1F194}" = dir=in | app=c:\windows\bitsprx5wow.exe | "{36A15F91-FB72-4B59-87C1-E24AAB2D0B9D}" = dir=in | app=c:\windows\wmadmodwow.exe | "{377FCE5A-088A-487F-8B15-A8FD6AACF777}" = dir=in | app=c:\windows\avifilewow.exe | "{38232804-41ED-4383-B349-955A60B472BF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{382E338A-77CC-4236-8E7C-1C3B3A63DF95}" = dir=in | app=c:\windows\snmpapiwow.exe | "{38AB983A-60E3-4CD7-B1A8-870CDB4A044A}" = dir=in | app=c:\windows\perftrackwow.exe | "{396455D5-5540-4F27-AF24-91A004C147D9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{3B3CA830-1397-43D1-A36A-1EFC827A897A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{3BD5E4CE-AE39-454A-872C-0D7EE2AFB576}" = dir=in | app=c:\windows\msscntrswow.exe | "{3BEECB12-A204-4E44-ADD0-842F75F796B0}" = dir=in | app=c:\windows\wmipropwow.exe | "{3D73FBAD-A733-4772-9957-1AA9868FAA27}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{3D932CDF-F6A4-4B2A-BCFC-1A33767C963F}" = dir=in | app=c:\windows\msprpdewow.exe | "{3DA74DDD-9240-4CAE-B418-4BFA38D2F26D}" = dir=in | app=c:\windows\iglhcp32wow.exe | "{3E1724E1-BB48-4728-B5D8-CBCA72D3FBED}" = dir=in | app=c:\windows\rdpd3dwow.exe | "{3E332DA7-DCCD-4579-B1A5-1217F591DB06}" = protocol=6 | dir=out | app=system | "{3EE7AF9F-D173-4FB1-AF3F-F5917AE9E839}" = dir=in | app=c:\windows\iprtrmgrwow.exe | "{3F3668A5-2DC9-4E4C-AF47-2BDF8E070203}" = dir=in | app=c:\windows\pidwow.exe | "{3F51D86F-454A-432C-96F4-CB912876D34D}" = dir=in | app=c:\windows\sdrsvcwow.exe | "{3F69E673-EBD2-424C-8787-B3C3074916F8}" = dir=in | app=c:\windows\cmipnpinstallwow.exe | "{413103B5-8D35-4ECD-95AA-825B54223D90}" = dir=in | app=c:\programdata\xwizards32.exe | "{41AE8C8D-EDF0-49B3-A205-672A092DE2C9}" = dir=in | app=c:\windows\snmpapiwow.exe | "{43D7170D-674C-4E93-848F-31F00152FF31}" = dir=in | app=c:\windows\kbdnec95wow.exe | "{442CE4C4-5961-4C44-A603-E5CD997BD0BA}" = dir=in | app=c:\windows\msprpdewow.exe | "{44701039-5EC1-473C-8CB4-78BF62119C02}" = dir=in | app=c:\windows\iprtrmgrwow.exe | "{44CFA98E-8D0F-4244-A9D0-DDE32892CA99}" = dir=in | app=c:\windows\amxreadwow.exe | "{45F61917-C15C-4AF8-A4AB-1C99B6912843}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{46E8916D-A4D5-4E92-9029-ED21528F44B7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{46FCF906-33F8-4F26-82A4-8268F67B6EA3}" = dir=in | app=c:\windows\iglhcp32wow.exe | "{47372A17-66D7-478E-8B35-38F8921D1FAA}" = dir=in | app=c:\windows\iscsiumwow.exe | "{4773F0BF-B4F9-4E9B-85EB-5AE0F1BBA26D}" = dir=in | app=c:\windows\provsvcwow.exe | "{4829CC13-0DC1-480B-8A32-2AFFFB4D7BE5}" = dir=in | app=c:\windows\comdlg32wow.exe | "{49145F63-96C0-4CDB-B100-7513420F8535}" = dir=in | app=c:\windows\snmpapiwow.exe | "{49CC05FF-B846-42A1-9648-FD6AE9535515}" = dir=in | app=c:\windows\api-ms-win-core-fibers-l1-1-032wow.exe | "{4AC15F42-E410-4B0F-889E-503DB65792A6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{4AE5B782-173B-4308-9015-9E87B80019EA}" = dir=in | app=c:\windows\kbda1wow.exe | "{4B175B4E-0EE4-4A8D-8669-094D0349634C}" = dir=in | app=c:\windows\bitsprx5wow.exe | "{4BC3EF09-6E43-483F-9233-7B4374314335}" = dir=in | app=c:\windows\kbda1wow.exe | "{4C550E77-1D74-4442-A1E4-B4DE7EFF6081}" = dir=in | app=c:\windows\d3d10_1corewow.exe | "{4C72570A-B65B-40FF-B8D8-1DB105D877D4}" = dir=in | app=c:\windows\azroleuiwow.exe | "{4D03FFFD-3AB7-406B-BD80-04B2676AA0F5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{4EB5CAA3-F9D5-438A-A0F2-7C21DE787AA0}" = dir=in | app=c:\windows\vdsbaswow.exe | "{4F04FA4C-538F-4855-A9E1-DB9758E989A9}" = dir=in | app=c:\windows\drtprovwow.exe | "{507D61CB-1616-4DE9-9124-F7973DD50DB3}" = dir=in | app=c:\windows\firewallcontrolpanelwow.exe | "{51563F94-03B4-4A27-954C-63EC42A9FE2D}" = dir=in | app=c:\windows\iasmigpluginwow.exe | "{562B50F2-AC48-484C-8250-139BC976332B}" = dir=in | app=c:\windows\msprpdewow.exe | "{56D8EE1C-E8B8-4FAF-BB5F-107E0A99D5D9}" = dir=in | app=c:\windows\kbdtiprcwow.exe | "{574CEFF6-1C60-4E9A-85FB-53D02CA7B9DE}" = dir=in | app=c:\windows\usbceipwow.exe | "{577DEF6B-B757-49A7-9C9E-3B48A789BEBC}" = dir=in | app=c:\windows\rdpd3dwow.exe | "{58A0CCAE-7029-4E68-9A21-4C78C8CC6058}" = dir=in | app=c:\windows\wlanhlpwow.exe | "{58A72812-87FC-4035-9F9E-D594BAE10C3A}" = dir=in | app=c:\windows\winrnrwow.exe | "{5B445AFE-8D73-4C55-98EC-FCBA65D37D6F}" = dir=in | app=c:\windows\iscsiumwow.exe | "{5C0EB712-0105-4C90-88AD-9D52A47E8D49}" = dir=in | app=c:\windows\msprpdewow.exe | "{5C36D0E7-0493-490F-82B1-269B66602CCF}" = dir=in | app=c:\programdata\xwizards32.exe | "{5C667C32-9A29-4C76-A884-A387F8656F4D}" = dir=in | app=c:\windows\bitsprx5wow.exe | "{5C871E1E-D140-4F23-A2A1-ACC56428F6E6}" = dir=in | app=c:\windows\winrnrwow.exe | "{5D3F1750-B401-4A34-A43D-631B3951E8B6}" = dir=in | app=c:\windows\imagereswow.exe | "{5E96D639-1C6B-4739-AE2E-4524E1D43B11}" = dir=in | app=c:\windows\wmipropwow.exe | "{5EB515BB-78DF-4D6D-8DA4-A365C545D26A}" = dir=in | app=c:\windows\odbccu32wow.exe | "{5EC04B35-41B5-4E3A-81A6-90A33BC8288C}" = dir=in | app=c:\windows\cmipnpinstallwow.exe | "{5F7B1831-605B-4859-A68E-6DC86EB85CA5}" = dir=in | app=c:\windows\azroleuiwow.exe | "{5FBB7BD5-8651-44A3-A6E0-55E46012F050}" = dir=in | app=c:\windows\kernelceipwow.exe | "{60B37B43-F1DF-4BDF-B9E6-1EB88E5FE101}" = dir=in | app=c:\programdata\wmadmoe32.exe | "{615E36B5-BB1B-48A9-BC0D-2EE99C6C764C}" = dir=in | app=c:\windows\kbda1wow.exe | "{622A65E1-A28B-4D3D-B0FC-3770074CCB37}" = dir=in | app=c:\windows\hpbmiapiwow.exe | "{62565260-32BC-4197-A108-2E424A6ABF3F}" = dir=in | app=c:\programdata\api-ms-win-core-fibers-l1-1-032.exe | "{62EFAE22-4C46-42CE-B41D-791E71A086C0}" = dir=in | app=c:\windows\provsvcwow.exe | "{62FF4717-7643-4C4F-B01D-2A8F995D4E79}" = dir=in | app=c:\programdata\api-ms-win-core-fibers-l1-1-032.exe | "{6396442B-D230-4F66-B3A6-AA9AA262EB41}" = dir=in | app=c:\windows\displaywow.exe | "{64CC5DFD-94BF-44FC-9451-C65070C61AB6}" = dir=in | app=c:\windows\msprpdewow.exe | "{66671D98-151B-4FE0-B629-96364B3C741A}" = dir=in | app=c:\windows\kbdnec95wow.exe | "{675C1301-32D4-4DF5-8C4D-967BBE58F1E6}" = dir=in | app=c:\windows\azroleuiwow.exe | "{679104D2-E6F6-4254-94EE-43A67F726BD7}" = dir=in | app=c:\windows\setbcdlocalewow.exe | "{684678A0-C2BB-4F1B-B790-0F981B959019}" = dir=in | app=c:\programdata\shellwow.exe | "{685D3137-AA82-4740-A1CF-06A37B233A4A}" = dir=in | app=c:\windows\oleaccrcwow.exe | "{68EE9E65-2482-4A2B-BF06-110AB8600279}" = dir=in | app=c:\windows\mssip32wow.exe | "{69016619-A6F7-4A1F-9066-500427F8AC7E}" = dir=in | app=c:\windows\api-ms-win-core-fibers-l1-1-032wow.exe | "{6D8861EA-93E9-4C17-82A1-43980B66AA46}" = dir=in | app=c:\windows\dpxwow.exe | "{6EB22242-CD33-4335-870F-56726F604BA7}" = dir=in | app=c:\windows\firewallcontrolpanelwow.exe | "{6F8D5AED-AD27-4046-AF50-ED4B80A98F96}" = dir=in | app=c:\windows\iprtrmgrwow.exe | "{718C5CEE-048D-43D7-A499-6FB3B6B0B032}" = dir=in | app=c:\windows\setbcdlocalewow.exe | "{72352C41-4BF0-4974-8E58-6B3A7CE19FCF}" = dir=in | app=c:\programdata\olewin.exe | "{7498CE2D-C1B3-405E-BFA5-5940D59D7D5D}" = dir=in | app=c:\windows\firewallcontrolpanelwow.exe | "{74F6767D-84CF-44D0-A026-8816D57B659F}" = dir=in | app=c:\windows\hpbmiapiwow.exe | "{74FE1477-3C2E-4DD7-9E71-34C9C9E82B40}" = dir=in | app=c:\windows\rtmwow.exe | "{751EAF91-0912-4FA6-99DE-6930E64B139C}" = dir=in | app=c:\windows\winrnrwow.exe | "{761ACD17-6DFF-41BC-AE8A-47985C704E54}" = dir=in | app=c:\windows\dmdlgswow.exe | "{76EB76A3-686A-4749-A1AB-0C062B12E453}" = dir=in | app=c:\windows\lpksetupproxyservwow.exe | "{77042E63-77E2-4E13-BCF4-C0598E9F6B9C}" = dir=in | app=c:\windows\wlanhlpwow.exe | "{772004AF-6083-4FC8-B1BD-054AD6E70BBD}" = dir=in | app=c:\windows\avifilewow.exe | "{774C45F2-4DF2-49A2-89AD-9D8F2ABF8FB8}" = dir=in | app=c:\windows\firewallcontrolpanelwow.exe | "{79195ABD-3EC5-4B71-9F7B-92B98EA36CC1}" = dir=in | app=c:\windows\system32\odbcjt3232.exe | "{797D50AC-8CC9-4E09-88D9-463511C2E582}" = dir=in | app=c:\windows\provsvcwow.exe | "{79B66F01-2CD0-41F8-98E1-836412FC2915}" = dir=in | app=c:\windows\d3d10_1corewow.exe | "{79D8D82E-1F47-46BF-A8F9-AAA94C75AE16}" = dir=in | app=c:\windows\api-ms-win-core-fibers-l1-1-032wow.exe | "{7A616ECE-29EE-488E-B002-B07940894728}" = dir=in | app=c:\windows\iscsiumwow.exe | "{7B74722B-CCE8-405F-8E90-3A1077B10401}" = dir=in | app=c:\windows\iscsiumwow.exe | "{7BF69D3F-B12D-4CA8-9B64-818AEA948D03}" = dir=in | app=c:\windows\vdsbaswow.exe | "{7C517983-B1C8-4E7A-B29D-5764453A95F9}" = dir=in | app=c:\windows\trkwkswow.exe | "{7C838F01-3B4C-452C-B75F-5FA6DAFAFB7B}" = dir=in | app=c:\windows\bitsprx5wow.exe | "{7CAE47CB-0B3F-4BA9-BD38-B219BFF36B78}" = dir=in | app=c:\windows\firewallcontrolpanelwow.exe | "{7E4ED3BB-E217-4390-9E99-AC65A5670142}" = dir=in | app=c:\windows\uudfwow.exe | "{7FDC7EBC-7236-4838-ACAD-3F7777F0C23F}" = dir=in | app=c:\windows\system32\odbcjt3232.exe | "{8025173B-DFF1-45C6-9506-835E2F611540}" = dir=in | app=c:\windows\sdrsvcwow.exe | "{80EFC137-5B27-4A1F-9CBD-F3867A677F4F}" = dir=in | app=c:\windows\displaywow.exe | "{827DB6B6-EF22-40A5-A73E-8902A1212E0E}" = dir=in | app=c:\windows\usbceipwow.exe | "{83CC3A3D-0D72-4212-B843-AD20563A1CD3}" = dir=in | app=c:\windows\fxstiffwow.exe | "{853C84CD-1991-4C18-8AF7-51753E454241}" = dir=in | app=c:\windows\untfswow.exe | "{858A9567-555D-4C9E-9236-933BAFFBFD93}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{866C4E59-16B9-474A-9211-38C1F0A3F080}" = dir=in | app=c:\windows\win32splwow.exe | "{88DA6C58-8760-4379-8E1A-6D6C1EBEDD19}" = dir=in | app=c:\windows\imagereswow.exe | "{88EBE9B5-9CD6-4F70-8505-FD22EB881981}" = dir=in | app=c:\windows\kbdnec95wow.exe | "{8AAAC8E2-46AD-4FA1-97A7-5797034E3E01}" = dir=in | app=c:\windows\api-ms-win-core-fibers-l1-1-0wow.exe | "{8AEC7FB7-B0EA-4648-A7BF-6286D033071B}" = dir=in | app=c:\windows\winrnrwow.exe | "{8C0358C8-A204-4F55-8F34-4E056DFAB0C1}" = dir=in | app=c:\windows\setbcdlocalewow.exe | "{8CE3D90B-6E53-498C-A334-71483AD5EBDB}" = dir=in | app=c:\windows\imagereswow.exe | "{8EE42271-B4F7-44C9-8C0F-40613C33D59B}" = dir=in | app=c:\programdata\wmadmoe32.exe | "{901A44D8-F76A-48E1-9252-5C8FD9AF7F24}" = dir=in | app=c:\windows\difxapiwow.exe | "{930C4732-74B9-4B8A-936D-24065E0EED26}" = dir=in | app=c:\windows\firewallcontrolpanelwow.exe | "{93953430-37CB-4E5D-BCB8-5CE0D10AAB76}" = dir=in | app=c:\windows\win32splwow.exe | "{93D9D9BB-AC07-4F4F-872F-EEE68FCC8539}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{94527443-0926-4B5E-8B8E-6CFF0AB2C528}" = dir=in | app=c:\windows\untfswow.exe | "{945CC633-1871-43F6-A251-B68FF29ECA30}" = dir=in | app=c:\windows\vdsbaswow.exe | "{95FE9811-BF4E-4558-BF6C-8FB747E93348}" = dir=in | app=c:\windows\imagereswow.exe | "{96D0E022-065E-4F2A-9FB8-CE2850D59000}" = dir=in | app=c:\windows\pidwow.exe | "{96F1E7BC-C3E0-4E0C-8A3C-C793E840ADC3}" = dir=in | app=c:\programdata\olewin.exe | "{988DDAD4-1CDC-47EE-ADE6-1E0EAE47CAF2}" = dir=in | app=c:\windows\d3d10_1corewow.exe | "{9B04C0F6-00D3-4A06-B2FE-B7940DE50068}" = dir=in | app=c:\windows\dmscriptwow.exe | "{9B6453A5-1F24-4CD3-9674-C2C1E79C9071}" = dir=in | app=c:\windows\cmipnpinstallwow.exe | "{9C830F2B-72DE-421A-A297-9DF7C295ADD1}" = dir=in | app=c:\windows\winrnrwow.exe | "{9D0210E0-B453-4814-AC25-C370238D8722}" = dir=in | app=c:\windows\difxapiwow.exe | "{A06D4BDB-B22E-4FC4-89F9-20B5678D3D4F}" = dir=in | app=c:\windows\difxapiwow.exe | "{A0E12599-67B3-4DE4-BA69-19FD934CEB3E}" = dir=in | app=c:\programdata\batt32.exe | "{A10FFACA-EB18-45AD-8FAA-8D346C9CB434}" = dir=in | app=c:\windows\api-ms-win-core-fibers-l1-1-0wow.exe | "{A11C37BA-BDCA-4135-9134-BEC1380D5E05}" = dir=in | app=c:\programdata\shellwow.exe | "{A1622998-F704-4EA7-BA5F-69147ED33682}" = dir=in | app=c:\windows\wintrustwow.exe | "{A3BF874D-8E6B-42E1-880D-ADBF234DF281}" = dir=in | app=c:\windows\odbccu32wow.exe | "{A45C0001-5134-4354-A38C-E59FB53C81D4}" = dir=in | app=c:\windows\kbdtiprcwow.exe | "{A45DD038-23F2-4333-8505-8679CF1DA7E9}" = dir=in | app=c:\windows\fntcachewow.exe | "{A6656D33-25E9-4472-B55A-B89D53195E2D}" = dir=in | app=c:\windows\kernelceipwow.exe | "{A6805E5F-D580-4EFD-A53A-4A67BCC6D3C1}" = dir=in | app=c:\windows\displaywow.exe | "{A6A2A99E-14C8-4D9B-B897-E48EF9789FFD}" = dir=in | app=c:\windows\dmdlgswow.exe | "{A75250FF-8DEF-4FFC-AF25-0262D46C1EE7}" = dir=in | app=c:\windows\dmdlgswow.exe | "{A92D3C40-9C8B-449F-9E7C-9EF5F265E1F0}" = dir=in | app=c:\windows\kernelceipwow.exe | "{AC250382-7CEC-4E21-BCE2-A03D4E8AD8BD}" = dir=in | app=c:\windows\trkwkswow.exe | "{ACEEE0BE-8C27-4406-9229-E00E276BFDA6}" = dir=in | app=c:\windows\iglhcp32wow.exe | "{AE681016-1944-4163-BFEA-7F600F4287FE}" = dir=in | app=c:\programdata\olewin.exe | "{AFEA4699-4DE5-45DC-9A5A-803E4B20F2A7}" = dir=in | app=c:\windows\provsvcwow.exe | "{B2B1605B-3D07-4BCE-BBBD-DE2D94A9E068}" = dir=in | app=c:\windows\winrnrwow.exe | "{B32513BA-9A10-4394-8CB1-F1E116BA5C49}" = dir=in | app=c:\windows\sdrsvcwow.exe | "{B450BF79-A1C5-4B2A-9D5E-63829757C64C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{B509477D-A775-45F1-B82C-7F5015FCF13D}" = dir=in | app=c:\windows\odbccu32wow.exe | "{B57B6D23-9237-4274-A3AD-369334A21375}" = dir=in | app=c:\windows\iprtrmgrwow.exe | "{B5FC0199-7994-4F16-BB09-0171CACC66C5}" = dir=in | app=c:\windows\oleaccrcwow.exe | "{B6FACE27-D36F-4742-86BE-2B063D73B8D8}" = dir=in | app=c:\windows\amxreadwow.exe | "{B757AB49-8E7A-4A2C-BAAA-4B5BFA9D8A23}" = dir=in | app=c:\programdata\adsnt32.exe | "{B771CA78-F985-428F-B134-CCF445A1691A}" = dir=in | app=c:\windows\fxstiffwow.exe | "{B796D5F8-C4E9-4726-BD51-2D9C35394844}" = dir=in | app=c:\programdata\xwizards32.exe | "{B7A0362E-EEBE-486F-84A1-B18054C8DA6C}" = dir=in | app=c:\windows\drtprovwow.exe | "{B7D274D8-41F5-4141-B362-596B39D8F7DD}" = dir=in | app=c:\windows\api-ms-win-core-misc-l1-1-0wow.exe | "{B7DD3BE1-1577-4DB9-A7E4-14ED6C62CEA7}" = dir=in | app=c:\windows\dmscriptwow.exe | "{B87F2C6A-7F8D-4885-A3D6-600F9B9D08F2}" = dir=in | app=c:\programdata\batt32.exe | "{BACA52A7-36EF-41FD-A30A-86E4EC90038F}" = dir=in | app=c:\windows\provsvcwow.exe | "{BB1B3511-2E6C-43A3-86C6-C651EDBFFE01}" = dir=in | app=c:\windows\dmdlgswow.exe | "{BBD33AE8-89BD-4CF9-98D8-6B39F8D82C2B}" = dir=in | app=c:\windows\kbda1wow.exe | "{BBD4EF70-C28D-4289-B4CA-6E79C7D28565}" = dir=in | app=c:\windows\lpksetupproxyservwow.exe | "{BC077A5E-AE0C-45C1-AE47-EBFC9F6DA0EB}" = dir=in | app=c:\windows\mssip32wow.exe | "{BC10242B-29EE-4D82-AD8F-CAD24E5BD996}" = dir=in | app=c:\windows\iprtrmgrwow.exe | "{BC870B2A-D0E6-4681-9CFF-547BD516EED3}" = dir=in | app=c:\windows\avifilewow.exe | "{BDF8A2A4-2121-48EB-9942-7F442FBC5F87}" = dir=in | app=c:\windows\dpxwow.exe | "{BEC8F0AF-1FDB-41F7-9163-07725D8EF38B}" = dir=in | app=c:\windows\imagereswow.exe | "{BF265958-FBEA-4887-B70B-B22CAA9CD8FA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{C11CA15E-7E2F-4A22-80F7-458174929EC9}" = dir=in | app=c:\windows\sdrsvcwow.exe | "{C1E6280A-92AE-479B-B3FD-BC83F0A0BE2D}" = dir=in | app=c:\windows\dmscriptwow.exe | "{C359DDB6-32A2-460E-86A2-7702509E3242}" = dir=in | app=c:\windows\oleaccrcwow.exe | "{C3724C71-72F1-4CAA-B76F-0646B4111244}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C378965E-9DBE-4884-B736-DFE4D6B1B3ED}" = dir=in | app=c:\windows\msacmwow.exe | "{C3B8B061-A459-480E-AAFC-F4CB241499AF}" = dir=in | app=c:\windows\lpksetupproxyservwow.exe | "{C40669E1-3817-48BA-A5C2-8C10E790E2BF}" = dir=in | app=c:\windows\api-ms-win-core-fibers-l1-1-032wow.exe | "{C50D6A61-1DE0-4523-B895-EAE64BB448C1}" = dir=in | app=c:\windows\fntcachewow.exe | "{C68BC996-7FEF-49FA-BE27-DCD59535E919}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{C76DD763-6A98-4111-9069-24E0F937CA0E}" = dir=in | app=c:\windows\fntcachewow.exe | "{C8E3E478-1562-4A30-B27D-1886DD371C49}" = dir=in | app=c:\windows\dmdlgswow.exe | "{CAD3CD94-26D5-4D06-B392-7C2D9DDA72DC}" = dir=in | app=c:\windows\system32\odbcjt3232.exe | "{CB087F8B-04B3-4922-AC61-032AA14229DC}" = dir=in | app=c:\windows\drtprovwow.exe | "{CB9F4201-666E-4E6B-A7C7-6B5BD73CB442}" = dir=in | app=c:\windows\perftrackwow.exe | "{CCEF8896-97FB-4361-A9A0-71B1ED3F79CF}" = dir=in | app=c:\windows\naphlprwow.exe | "{CE1D49F1-C8FF-46B3-B0A2-18D20EF3B73F}" = dir=in | app=c:\windows\d3d10_1corewow.exe | "{D10E2889-4CB0-44D5-AB5C-8A9BC0CA87F1}" = dir=in | app=c:\windows\vdsbaswow.exe | "{D14E30F5-53EE-41A3-9E42-6A33C3F932F0}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | "{D1FDB4AA-7739-4233-BFA8-FAFE035433C9}" = dir=in | app=c:\windows\wmipropwow.exe | "{D2BD5238-C2F2-4711-ACC7-3A89020EE9F0}" = dir=in | app=c:\windows\snmpapiwow.exe | "{D476300E-3594-4CCF-BE60-011FB4111E63}" = dir=in | app=c:\windows\odbccu32wow.exe | "{D6243559-B565-46FB-81CB-F780D9848AAB}" = dir=in | app=c:\windows\wintrustwow.exe | "{D7DD9FD1-D67D-46A8-9A94-7A052ADC1B09}" = dir=in | app=c:\windows\oleaccrcwow.exe | "{D8C1D12D-0F8B-466A-AA03-42C64185F87D}" = dir=in | app=c:\windows\pidwow.exe | "{D93069D5-02D5-4C67-A503-20FB4A7D38DE}" = protocol=6 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe | "{D98209ED-D560-419A-B70A-5CB6EA34647C}" = dir=in | app=c:\windows\iscsiumwow.exe | "{DB541935-3E4C-4CD7-A446-442201C7DCE0}" = dir=in | app=c:\windows\kbda1wow.exe | "{DBCD2E6E-D095-4A2E-85BB-1CBE056E1CD9}" = dir=in | app=c:\windows\difxapiwow.exe | "{DD2ABC13-79A9-4646-9F41-3E38D6F4007F}" = dir=in | app=c:\windows\localsecwow.exe | "{DE817469-9D18-4F05-A94F-46D0DD3584AE}" = dir=in | app=c:\windows\rtmwow.exe | "{DFB24E63-5042-4BF6-AF49-DF308B4A4DE7}" = dir=in | app=c:\windows\amxreadwow.exe | "{E1C288B2-B0D8-4080-AA43-6F3118D3A371}" = dir=in | app=c:\windows\kbdtiprcwow.exe | "{E254AEE7-CC4D-4C0F-B8A4-EF7A4A835748}" = dir=in | app=c:\windows\oleaccrcwow.exe | "{E28617A2-332F-458F-9A6A-A92537434A29}" = protocol=17 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe | "{E4C171B8-A633-4887-97BE-5741801A17AC}" = dir=in | app=c:\windows\oleaccrcwow.exe | "{E602280D-DF09-4592-A216-2B04B7D03180}" = dir=in | app=c:\windows\usbceipwow.exe | "{E606B0B8-E972-475A-B924-0EAC4523CE10}" = dir=in | app=c:\windows\displaywow.exe | "{E72DA7AB-B7DB-4E68-AB52-DF5381E7FEFB}" = dir=in | app=c:\windows\wmadmodwow.exe | "{E75D00C5-DA77-4DA8-8EE5-17D516BDAC02}" = dir=in | app=c:\windows\sdrsvcwow.exe | "{E776DCF0-3B35-4CBD-AD1F-D34E54D536F4}" = dir=in | app=c:\windows\lpksetupproxyservwow.exe | "{E8544291-0352-4ED7-B984-ABF1488ECE8E}" = dir=in | app=c:\programdata\batt32.exe | "{E870F0C8-1BF0-4813-B9BD-FDC851A225EC}" = dir=in | app=c:\windows\d3d10_1corewow.exe | "{E873A305-4E16-4FC4-B313-26F42303D553}" = dir=in | app=c:\windows\azroleuiwow.exe | "{E8C6D26E-953D-4B1C-8B3A-7E0D84571F0B}" = protocol=6 | dir=in | app=c:\windows\system32\msiexec.exe | "{E9D04736-DAB8-42B5-88EE-AA5A6449C938}" = dir=in | app=c:\programdata\adsnt32.exe | "{EACA4E06-0596-44FC-877C-5622D2A23DA1}" = dir=in | app=c:\windows\difxapiwow.exe | "{EC8C63FC-E712-463E-9641-154502EA6CD2}" = dir=in | app=c:\windows\lpksetupproxyservwow.exe | "{ED477DD6-538F-4AA7-BA15-A253398612E7}" = dir=in | app=c:\windows\naphlprwow.exe | "{EE4919C7-B755-4E95-8D1A-5B6661F9FE7D}" = dir=in | app=c:\windows\dmdlgswow.exe | "{F05D63EF-BFF9-4A73-8BEA-7C8AFF90C833}" = dir=in | app=c:\windows\odbccu32wow.exe | "{F143AE93-2211-4299-A9ED-4E7F549E9F27}" = dir=in | app=c:\windows\azroleuiwow.exe | "{F2D85E13-DCA8-433F-9FBE-A8D5EF381EA9}" = dir=in | app=c:\windows\localsecwow.exe | "{F46335BA-44C8-4138-BB35-38582A4244F6}" = dir=in | app=c:\windows\kernelceipwow.exe | "{F59D8CA8-8E7E-43D8-9DDB-BDA53618DD6D}" = dir=in | app=c:\windows\kernelceipwow.exe | "{F636FA46-C7E6-4329-B3A3-C3D93BE27234}" = dir=in | app=c:\windows\odbccu32wow.exe | "{F6B6636A-BC2A-402E-B914-5E824E6312A8}" = dir=in | app=c:\windows\rdpd3dwow.exe | "{F79500E2-A624-4426-967A-F38AF9FEE7B2}" = dir=in | app=c:\windows\bitsprx5wow.exe | "{F8753B48-0750-44C8-9D6A-7ED48775BC72}" = dir=in | app=c:\windows\comdlg32wow.exe | "{F94EEA51-20D4-4E45-827D-2E0C45ECA6E4}" = dir=in | app=c:\windows\iasmigpluginwow.exe | "{F967D381-E187-416B-A73F-3415A2C43FBE}" = dir=in | app=c:\windows\win32splwow.exe | "{FB6B881E-0643-42A3-949F-8F4BC7EA3D9B}" = dir=in | app=c:\windows\difxapiwow.exe | "{FB7519B4-974B-425A-B242-5E772AA3444E}" = dir=in | app=c:\windows\imagereswow.exe | "{FBA267CC-517B-466D-A84C-70D4AEB33F23}" = dir=in | app=c:\windows\displaywow.exe | "{FBF1D0C5-842C-47E2-8269-B4685A785017}" = dir=in | app=c:\windows\drtprovwow.exe | "{FC51568C-5E4F-47FA-BC1A-2CF675F2BA85}" = dir=in | app=c:\windows\lpksetupproxyservwow.exe | "{FCA91314-A34A-44E2-BD38-756C5BB1D4D0}" = dir=in | app=c:\windows\rdpd3dwow.exe | "{FCBC3FA9-EDDE-4B5C-9408-F91D74685D1F}" = dir=in | app=c:\windows\uudfwow.exe | "{FD39E757-71E1-4222-B5FC-09A1F92EC615}" = dir=in | app=c:\windows\iscsiumwow.exe | "{FED61701-F405-4DE2-B19A-46248822D670}" = dir=in | app=c:\windows\uudfwow.exe | "{FED8C923-6EE1-4728-B145-31C8EC5E1F6A}" = protocol=17 | dir=in | app=c:\windows\system32\msiexec.exe | "{FEE59800-D9FD-4DD8-84ED-2A29ED3D97CA}" = dir=in | app=c:\windows\comdlg32wow.exe | "TCP Query User{2AA9DECA-5A7B-4A5F-9877-509A96747A18}C:\programme_1\grand prix 3\gp3.icd" = protocol=6 | dir=in | app=c:\programme_1\grand prix 3\gp3.icd | "TCP Query User{3CFCD221-E431-445F-B562-4505147D4392}C:\programme_1\emule\emule.exe" = protocol=6 | dir=in | app=c:\programme_1\emule\emule.exe | "TCP Query User{601D34F3-56FE-4743-80ED-310C876A8EFF}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "TCP Query User{9178615A-8516-4FCB-97A8-68AB9EC84BC0}C:\programme_1\vlc player\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\programme_1\vlc player\vlc\vlc.exe | "TCP Query User{9516109A-1BF6-4AE6-A11B-5ED31BD077A0}E:\grand prix 3\gp3.icd" = protocol=6 | dir=in | app=e:\grand prix 3\gp3.icd | "TCP Query User{E0F5282C-F1C4-4093-8C6D-CAE7B39C3AF3}C:\programme_1\emule\emule.exe" = protocol=6 | dir=in | app=c:\programme_1\emule\emule.exe | "UDP Query User{12011441-65B4-4A74-BE0F-414144E68548}E:\grand prix 3\gp3.icd" = protocol=17 | dir=in | app=e:\grand prix 3\gp3.icd | "UDP Query User{1B737E48-0EA4-46E0-BF8B-B9B002D9F339}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "UDP Query User{2E1FF224-1180-4350-8553-1059DAD68FEE}C:\programme_1\emule\emule.exe" = protocol=17 | dir=in | app=c:\programme_1\emule\emule.exe | "UDP Query User{360ED211-96A0-4CDB-B55C-093F9EDCD68F}C:\programme_1\vlc player\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\programme_1\vlc player\vlc\vlc.exe | "UDP Query User{952580C7-4A6A-4078-881C-8D1639E28389}C:\programme_1\emule\emule.exe" = protocol=17 | dir=in | app=c:\programme_1\emule\emule.exe | "UDP Query User{AAF6A848-AC68-42B9-8FCD-026507B21643}C:\programme_1\grand prix 3\gp3.icd" = protocol=17 | dir=in | app=c:\programme_1\grand prix 3\gp3.icd | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended "{0CA1005F-B640-0354-EC82-F8F7447A8E8A}" = CCC Help Hungarian "{0FC472C3-6A2A-969F-10E7-E8F61B18117C}" = Catalyst Control Center Localization All "{12076C90-4A78-7241-F633-4D2B019D5611}" = CCC Help Thai "{15B2BC56-D179-4450-84B9-7A8D7F4CE1B9}" = Lexware Info Service "{17E11EC2-3736-10A1-330C-CC7EB6CAC6B3}" = CCC Help Turkish "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31 "{31B75145-DF24-C759-E735-9C129956961E}" = CCC Help Spanish "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager "{4785CED6-73B3-45FA-AFE6-EDEDFDE67842}" = Steuer 2011 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4B526075-AF27-47A2-860D-3DA92928A051}" = Steuer 2010 "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{59F5C54C-ED39-58B4-42DA-3F20AB440E49}" = CCC Help Czech "{60F641EA-DFFB-4419-A1A7-4FF575BA87BE}" = HP Setup "{641C1B16-FD4C-0F97-47AE-76637FC64225}" = CCC Help English "{64B157C9-C291-2535-8177-237BC2D37EBF}" = CCC Help Korean "{658DE1DF-D156-DD5A-800E-20C693806F65}" = Catalyst Control Center InstallProxy "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.2.0 "{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}" = HP Support Assistant "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71790311-0C42-B5BC-AF01-97BFFEF2A30B}" = ATI Catalyst Install Manager "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{79C2D7F9-3BF8-52C1-6A7A-84C9296171F8}" = CCC Help German "{7B29E627-71A5-6824-3F85-DBEF19624BD0}" = ccc-core-static "{7E5C379D-035B-815D-E087-4CEA06C76A08}" = AMD Drag and Drop Transcoding "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{85C3024B-A974-450C-4D46-C031F801F5EC}" = ccc-utility "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{87323561-58BA-4D5B-BADA-A791B69D1705}" = Catalyst Control Center - Branding "{88B2BB7B-A684-E8E3-65C6-DDC5DC152C2A}" = CCC Help French "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8CB77076-DB66-5D92-7886-807226C9CE4B}" = CCC Help Italian "{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{90A455A7-0FC8-4508-B7FA-8F135B8F041A}" = DSL-Manager "{94F4B1D4-0BCC-E5C6-4EAE-F1A287383D5B}" = CCC Help Finnish "{98838C21-AD83-77AA-3B09-F437C6F24F8F}" = CCC Help Dutch "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C6F56DA-7051-6677-4E5A-9DC6C573F2B5}" = CCC Help Portuguese "{9FE051B0-39BC-F5DD-C99B-0D4793184C2A}" = CCC Help Chinese Standard "{AA6B96C4-7AF5-3F6A-E630-4096508A9C47}" = CCC Help Danish "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch "{ACFB6965-D714-3786-6B50-58E21223CB96}" = ATI AVIVO Codecs "{B40D7926-AE5F-41EA-8AC6-56C0E2F00E9D}" = HP MAINSTREAM KEYBOARD "{B48E87FE-A8D9-EE14-B607-3FA1ACEF218E}" = CCC Help Norwegian "{B4FA8E67-D299-485A-407B-05A2681BAF47}" = CCC Help Japanese "{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer "{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information "{BB05BC7D-BEF8-7A7B-C62E-F1BE381E70BB}" = CCC Help Swedish "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{C3FA3CCE-2A88-0976-B875-4B3E9D41204D}" = Catalyst Control Center Graphics Previews Common "{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86 "{D34F0251-1C96-09B3-EE29-2A9148413252}" = CCC Help Chinese Traditional "{D54A0D86-35B0-BFC8-174B-D991EDF903B8}" = Catalyst Control Center Graphics Previews Vista "{D5610369-AF78-386F-4985-9822654973A3}" = CCC Help Polish "{D79A02E9-6713-4335-9668-AAC7474C0C0E}" = HP Vision Hardware Diagnostics "{D7EC8A27-CDA2-46AE-8A26-4104A04FA5BE}" = 32 Bit HP CIO Components Installer "{E3723A04-A894-4036-A78E-282E18F43C0A}_is1" = Tinypic 3.17a "{E937F8DA-8C7F-ADFE-7EA5-7C1CAAB23C05}" = HydraVision "{ECD129A4-5A21-1977-0849-6913BA6BA29C}" = CCC Help Russian "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5 "{F77D44EB-2A6E-E2EE-7C30-40A5409B2650}" = CCC Help Greek "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "CCleaner" = CCleaner "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "HP Keyboard_is1" = HP Desktop Keyboard "HP Remote Solution" = HP Remote Solution "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.62.0.1300 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Mozilla Firefox 4.0 (x86 de)" = Mozilla Firefox 4.0 (x86 de) "Mozilla Thunderbird (3.1.4)" = Mozilla Thunderbird (3.1.4) "My HP Game Console" = HP Game Console "NAV" = Norton AntiVirus "PDF Complete" = PDF Complete Special Edition "VLC media player" = VLC media player 1.1.10 "WildTangent hp Master Uninstall" = HP Games "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR "WT087361" = FATE "WT087380" = John Deere Drive Green "WT087394" = Penguins! "WT087396" = Polar Bowler "WT087420" = Agatha Christie - Death on the Nile "WT087428" = Bejeweled 2 Deluxe "WT087453" = Chuzzle Deluxe "WT087480" = Insaniquarium Deluxe "WT087485" = Jewel Quest II "WT087490" = Jewel Quest Solitaire "WT087501" = Plants vs. Zombies "WT087510" = Slingo Deluxe "WT087513" = Virtual Villagers - The Secret City "WT087519" = Wedding Dash "WT087533" = Zuma Deluxe "WT087536" = Diner Dash 2 Restaurant Rescue "Yahoo! Messenger" = Yahoo! Messenger ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Mozilla Firefox 13.0.1 (x86 de)" = Mozilla Firefox 13.0.1 (x86 de) "Mozilla Thunderbird 12.0.1 (x86 de)" = Mozilla Thunderbird 12.0.1 (x86 de) ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 14.07.2012 11:14:04 | Computer Name = Saschahp | Source = MsiInstaller | ID = 10005 Description = Error - 14.07.2012 11:14:25 | Computer Name = Saschahp | Source = MsiInstaller | ID = 10005 Description = Error - 14.07.2012 11:14:29 | Computer Name = Saschahp | Source = MsiInstaller | ID = 10005 Description = Error - 14.07.2012 11:14:33 | Computer Name = Saschahp | Source = MsiInstaller | ID = 10005 Description = Error - 14.07.2012 11:23:52 | Computer Name = Saschahp | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error - 14.07.2012 11:23:53 | Computer Name = Saschahp | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error - 14.07.2012 11:23:53 | Computer Name = Saschahp | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error - 14.07.2012 11:36:09 | Computer Name = Saschahp | Source = MsiInstaller | ID = 1043 Description = Error - 14.07.2012 11:42:19 | Computer Name = Saschahp | Source = MsiInstaller | ID = 1043 Description = Error - 14.07.2012 11:43:54 | Computer Name = Saschahp | Source = MsiInstaller | ID = 11706 Description = [ Hewlett-Packard Events ] Error - 27.07.2011 02:34:19 | Computer Name = Saschahp | Source = Hewlett-Packard | ID = 0 Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\071127083417.xml File not created by asset agent Error - 07.09.2011 02:27:15 | Computer Name = Saschahp | Source = Hewlett-Packard | ID = 0 Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\091107082712.xml File not created by asset agent Error - 26.10.2011 15:18:58 | Computer Name = Saschahp | Source = hpsa_service.exe | ID = 2000 Description = HP Error ID: -2146233088 bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateDetail(String category) bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetectCore() bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Message: Failed to perform update. StackTrace: bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateDetail(String category) bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetectCore() bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager InnerException.Message: Das Objekt "/9db6f88f_e877_4068_b98e_90dc92447915/ly9kpdybqohbesarpnhe78us_5.rem" wurde getrennt oder ist nicht auf dem Server vorhanden. Name: hpsa_service.exe Version: 06.00.01.01 Path: C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format: de-DE RAM: 3071 Ram Utilization: TargetSite: Void UpdateDetail(System.String) Error - 14.12.2011 11:21:29 | Computer Name = Saschahp | Source = HPSF.exe | ID = 4000 Description = Error - 04.01.2012 11:07:51 | Computer Name = Saschahp | Source = hpsa_service.exe | ID = 2000 Description = HP Error ID: -2146233088 bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace: bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe Version: 06.00.01.01 Path: C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format: de-DE RAM: 3071 Ram Utilization: 30 TargetSite: Void UpdateAndDetect() Error - 05.01.2012 18:21:37 | Computer Name = Saschahp | Source = hpsa_service.exe | ID = 2000 Description = HP Error ID: -2146233088 bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace: bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe Version: 06.00.01.01 Path: C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format: de-DE RAM: 3071 Ram Utilization: 40 TargetSite: Void UpdateAndDetect() Error - 12.01.2012 15:33:09 | Computer Name = Saschahp | Source = hpsa_service.exe | ID = 2000 Description = HP Error ID: -2146233088 bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace: bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe Version: 06.00.01.01 Path: C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format: de-DE RAM: 3071 Ram Utilization: 30 TargetSite: Void UpdateAndDetect() Error - 18.01.2012 11:20:08 | Computer Name = Saschahp | Source = hpsa_service.exe | ID = 2000 Description = HP Error ID: -2146233088 bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace: bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe Version: 06.00.01.01 Path: C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format: de-DE RAM: 3071 Ram Utilization: 60 TargetSite: Void UpdateAndDetect() Error - 25.01.2012 11:53:45 | Computer Name = Saschahp | Source = hpsa_service.exe | ID = 2000 Description = HP Error ID: -2146233088hpsa_service.exe bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace: bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe Version: 06.00.01.01 Path: C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format: de-DE RAM: 3071 Ram Utilization: 60 TargetSite: Void UpdateAndDetect() Error - 01.02.2012 11:43:53 | Computer Name = Saschahp | Source = hpsa_service.exe | ID = 2000 Description = HP Error ID: -2146233088 bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace: bei HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect() bei HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan, Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe Version: 06.00.01.01 Path: C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format: de-DE RAM: 3071 Ram Utilization: 60 TargetSite: Void UpdateAndDetect() [ Media Center Events ] Error - 04.01.2012 21:16:20 | Computer Name = Saschahp | Source = MCUpdate | ID = 0 Description = 02:16:20 - Fehler beim Herstellen der Internetverbindung. 02:16:20 - Serververbindung konnte nicht hergestellt werden.. Error - 04.01.2012 21:16:32 | Computer Name = Saschahp | Source = MCUpdate | ID = 0 Description = 02:16:31 - Fehler beim Herstellen der Internetverbindung. 02:16:31 - Serververbindung konnte nicht hergestellt werden.. Error - 05.01.2012 18:49:49 | Computer Name = Saschahp | Source = MCUpdate | ID = 0 Description = 23:49:49 - Fehler beim Herstellen der Internetverbindung. 23:49:49 - Serververbindung konnte nicht hergestellt werden.. Error - 05.01.2012 18:50:04 | Computer Name = Saschahp | Source = MCUpdate | ID = 0 Description = 23:50:01 - Fehler beim Herstellen der Internetverbindung. 23:50:01 - Serververbindung konnte nicht hergestellt werden.. Error - 08.01.2012 04:24:57 | Computer Name = Saschahp | Source = MCUpdate | ID = 0 Description = 09:24:57 - Fehler beim Herstellen der Internetverbindung. 09:24:57 - Serververbindung konnte nicht hergestellt werden.. Error - 08.01.2012 04:25:32 | Computer Name = Saschahp | Source = MCUpdate | ID = 0 Description = 09:25:27 - Fehler beim Herstellen der Internetverbindung. 09:25:27 - Serververbindung konnte nicht hergestellt werden.. Error - 11.01.2012 01:21:23 | Computer Name = Saschahp | Source = MCUpdate | ID = 0 Description = 06:21:23 - Fehler beim Herstellen der Internetverbindung. 06:21:23 - Serververbindung konnte nicht hergestellt werden.. Error - 11.01.2012 01:21:57 | Computer Name = Saschahp | Source = MCUpdate | ID = 0 Description = 06:21:52 - Fehler beim Herstellen der Internetverbindung. 06:21:52 - Serververbindung konnte nicht hergestellt werden.. Error - 12.01.2012 15:25:41 | Computer Name = Saschahp | Source = MCUpdate | ID = 0 Description = 20:25:41 - Fehler beim Herstellen der Internetverbindung. 20:25:41 - Serververbindung konnte nicht hergestellt werden.. Error - 12.01.2012 15:26:15 | Computer Name = Saschahp | Source = MCUpdate | ID = 0 Description = 20:26:10 - Fehler beim Herstellen der Internetverbindung. 20:26:10 - Serververbindung konnte nicht hergestellt werden.. [ System Events ] Error - 14.07.2012 11:03:57 | Computer Name = Saschahp | Source = SRTSP | ID = 524293 Description = Error loading Symantec real time Anti-Virus driver. Error - 14.07.2012 11:04:31 | Computer Name = Saschahp | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: BHDrvx86 SRTSP UimBus Uim_IM Error - 14.07.2012 11:37:53 | Computer Name = Saschahp | Source = DCOM | ID = 10010 Description = Error - 14.07.2012 11:39:34 | Computer Name = Saschahp | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: UimBus Uim_IM Error - 14.07.2012 13:56:28 | Computer Name = Saschahp | Source = DCOM | ID = 10010 Description = Error - 14.07.2012 13:58:20 | Computer Name = Saschahp | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: UimBus Uim_IM Error - 14.07.2012 14:01:13 | Computer Name = Saschahp | Source = DCOM | ID = 10010 Description = Error - 14.07.2012 14:02:35 | Computer Name = Saschahp | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: UimBus Uim_IM Error - 14.07.2012 14:44:15 | Computer Name = Saschahp | Source = DCOM | ID = 10010 Description = Error - 14.07.2012 14:45:34 | Computer Name = Saschahp | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: UimBus Uim_IM < End of report > OTL Logfile: Code: OTL logfile created on: 7/15/2012 11:19:55 PM - Run 1 |
sehe doch, dass du schon shadow explorer etc genutzt hast, erfolgreich? |
zum teil.... es sind noch einige dateien (bilder) verschlüßelt. ich habe sie auf eine externe platte geschoben. habe hier gelesen das ich was warten soll bis es vieleicht eine rückschlüsselung gibt. ich hoffe ja nur das ich den trojaner los bin.... kann man das auch erkennen aus dem bericht? |
mal hier lesen: http://www.trojaner-board.de/116851-...tml#post851585 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 11:34 Uhr. |
Copyright ©2000-2025, Trojaner-Board