Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Programme brauchen lange zum starten (https://www.trojaner-board.de/131184-programme-brauchen-lange-starten.html)

ryuk 17.02.2013 18:00

Programme brauchen lange zum starten
 
Hallo,
seit geraumer Zeit habe ich ein Problem, alle Programme, welche vorher ganz normal innerhalb wenig Sekunden gestartet haben, benötigen jetzt 40-60 Sekunden. Einen Virus o.ä. hat mein KIS nicht gefunden, trotzdem ist das nicht normal.
Die Logs sind im Anhang.

markusg 17.02.2013 18:06

Hi,
besuch bitte mal die Kaspersky Homepage und upgrade auf 2013

otl fix

Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.

Code:

:OTL
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
:files
:Commands
[emptytemp]

  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread

ryuk 17.02.2013 18:34

Vielen dank für die schnelle Antwort!
Das Upgrade downloade ich mir jetzt, dauert nur etwas bei meinem Internet, aber trotzdem ist hier die gewünschte Log Datei nach dem Fix.
Code:

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
========== FILES ==========
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56475 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Kabraxis
 
User: LogMeInRemoteUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56475 bytes
 
User: Public
 
User: Root
->Temp folder emptied: 1085622994 bytes
->Temporary Internet Files folder emptied: 99696457 bytes
->Java cache emptied: 551215 bytes
->FireFox cache emptied: 123490209 bytes
->Google Chrome cache emptied: 380074866 bytes
->Opera cache emptied: 56970633 bytes
->Flash cache emptied: 99015 bytes
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56475 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 243370388 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 46356772 bytes
RecycleBin emptied: 199800761 bytes
 
Total Files Cleaned = 2.133.00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 02172013_182634

Files\Folders moved on Reboot...
C:\Users\Root\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\vmware-SYSTEM\vmauthd.log scheduled to be moved on reboot.
C:\Windows\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-2804.log moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


markusg 17.02.2013 18:41

Hi,
mach erst mal das Upgrade, dann wird evtl. ein Scan laufen, wenns da Funde gibt, poste die.
Also, immer mit der Ruhe, keiner hätzt dich hier.

Dann:
[OTLFIX]

ryuk 17.02.2013 19:36

Zitat:

Zitat von markusg (Beitrag 1014057)
Dann:
[OTLFIX]

Was genau meinst du damit? Den Fix aus deinem vorherigen Post habe ich bereits gemacht und die Logdatei gepostet.
Bin jetzt fertig mit dem Upgraden und eine Untersuchung wichtiger Bereiche habe ich auch durchgeführt - keine Funde.

markusg 17.02.2013 20:29

Sorry,
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

ryuk 17.02.2013 20:40

Code:

20:37:35.0963 3396  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
20:37:36.0530 3396  ============================================================
20:37:36.0530 3396  Current date / time: 2013/02/17 20:37:36.0530
20:37:36.0530 3396  SystemInfo:
20:37:36.0530 3396 
20:37:36.0530 3396  OS Version: 6.1.7601 ServicePack: 1.0
20:37:36.0530 3396  Product type: Workstation
20:37:36.0530 3396  ComputerName: SYSTEMROOT
20:37:36.0530 3396  UserName: Root
20:37:36.0530 3396  Windows directory: C:\Windows
20:37:36.0530 3396  System windows directory: C:\Windows
20:37:36.0530 3396  Running under WOW64
20:37:36.0530 3396  Processor architecture: Intel x64
20:37:36.0530 3396  Number of processors: 8
20:37:36.0530 3396  Page size: 0x1000
20:37:36.0530 3396  Boot type: Normal boot
20:37:36.0530 3396  ============================================================
20:37:37.0482 3396  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:37:37.0490 3396  ============================================================
20:37:37.0490 3396  \Device\Harddisk0\DR0:
20:37:37.0490 3396  MBR partitions:
20:37:37.0490 3396  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
20:37:37.0490 3396  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x255A800, BlocksNum 0x2E935000
20:37:37.0490 3396  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x30E8F824, BlocksNum 0x4387619D
20:37:37.0490 3396  ============================================================
20:37:37.0517 3396  C: <-> \Device\Harddisk0\DR0\Partition2
20:37:37.0629 3396  D: <-> \Device\Harddisk0\DR0\Partition3
20:37:37.0629 3396  ============================================================
20:37:37.0629 3396  Initialize success
20:37:37.0629 3396  ============================================================
20:38:14.0783 4016  ============================================================
20:38:14.0783 4016  Scan started
20:38:14.0783 4016  Mode: Manual; SigCheck; TDLFS;
20:38:14.0783 4016  ============================================================
20:38:16.0062 4016  ================ Scan system memory ========================
20:38:16.0062 4016  System memory - ok
20:38:16.0062 4016  ================ Scan services =============================
20:38:16.0187 4016  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
20:38:16.0281 4016  1394ohci - ok
20:38:16.0312 4016  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
20:38:16.0343 4016  ACPI - ok
20:38:16.0374 4016  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
20:38:16.0437 4016  AcpiPmi - ok
20:38:16.0562 4016  [ 62B7936F9036DD6ED36E6A7EFA805DC0 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:38:16.0577 4016  AdobeARMservice - ok
20:38:16.0718 4016  [ EC807244904FA170C299AB06D87FBDBE ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
20:38:16.0733 4016  AdobeFlashPlayerUpdateSvc - ok
20:38:16.0764 4016  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx        C:\Windows\system32\DRIVERS\adp94xx.sys
20:38:16.0796 4016  adp94xx - ok
20:38:16.0796 4016  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci        C:\Windows\system32\DRIVERS\adpahci.sys
20:38:16.0811 4016  adpahci - ok
20:38:16.0827 4016  [ E109549C90F62FB570B9540C4B148E54 ] adpu320        C:\Windows\system32\DRIVERS\adpu320.sys
20:38:16.0827 4016  adpu320 - ok
20:38:16.0858 4016  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
20:38:16.0967 4016  AeLookupSvc - ok
20:38:17.0014 4016  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD            C:\Windows\system32\drivers\afd.sys
20:38:17.0076 4016  AFD - ok
20:38:17.0108 4016  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
20:38:17.0123 4016  agp440 - ok
20:38:17.0139 4016  [ 3290D6946B5E30E70414990574883DDB ] ALG            C:\Windows\System32\alg.exe
20:38:17.0186 4016  ALG - ok
20:38:17.0201 4016  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
20:38:17.0217 4016  aliide - ok
20:38:17.0232 4016  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
20:38:17.0248 4016  amdide - ok
20:38:17.0264 4016  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8          C:\Windows\system32\DRIVERS\amdk8.sys
20:38:17.0310 4016  AmdK8 - ok
20:38:17.0326 4016  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
20:38:17.0357 4016  AmdPPM - ok
20:38:17.0388 4016  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
20:38:17.0404 4016  amdsata - ok
20:38:17.0420 4016  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
20:38:17.0435 4016  amdsbs - ok
20:38:17.0451 4016  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata        C:\Windows\system32\drivers\amdxata.sys
20:38:17.0451 4016  amdxata - ok
20:38:17.0513 4016  [ 4FC6E2C2FC50445450651F42E90CC0BD ] Apowersoft_AudioDevice C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys
20:38:17.0529 4016  Apowersoft_AudioDevice - ok
20:38:17.0560 4016  [ 89A69C3F2F319B43379399547526D952 ] AppID          C:\Windows\system32\drivers\appid.sys
20:38:17.0669 4016  AppID - ok
20:38:17.0700 4016  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
20:38:17.0716 4016  AppIDSvc - ok
20:38:17.0763 4016  [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo        C:\Windows\System32\appinfo.dll
20:38:17.0810 4016  Appinfo - ok
20:38:17.0966 4016  [ F401929EE0CC92BFE7F15161CA535383 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:38:17.0981 4016  Apple Mobile Device - ok
20:38:18.0044 4016  [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt        C:\Windows\System32\appmgmts.dll
20:38:18.0075 4016  AppMgmt - ok
20:38:18.0090 4016  [ C484F8CEB1717C540242531DB7845C4E ] arc            C:\Windows\system32\DRIVERS\arc.sys
20:38:18.0122 4016  arc - ok
20:38:18.0137 4016  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
20:38:18.0153 4016  arcsas - ok
20:38:18.0215 4016  [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
20:38:18.0231 4016  aspnet_state - ok
20:38:18.0278 4016  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
20:38:18.0340 4016  AsyncMac - ok
20:38:18.0371 4016  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi          C:\Windows\system32\drivers\atapi.sys
20:38:18.0387 4016  atapi - ok
20:38:18.0434 4016  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
20:38:18.0496 4016  AudioEndpointBuilder - ok
20:38:18.0496 4016  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
20:38:18.0527 4016  AudioSrv - ok
20:38:18.0668 4016  AVP - ok
20:38:18.0699 4016  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
20:38:18.0777 4016  AxInstSV - ok
20:38:18.0808 4016  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv        C:\Windows\system32\DRIVERS\bxvbda.sys
20:38:18.0870 4016  b06bdrv - ok
20:38:18.0902 4016  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
20:38:18.0933 4016  b57nd60a - ok
20:38:18.0964 4016  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
20:38:19.0011 4016  BDESVC - ok
20:38:19.0026 4016  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
20:38:19.0089 4016  Beep - ok
20:38:19.0151 4016  [ 06C1E887BF34C0E31EB8E2C999E4842F ] BEService      C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
20:38:19.0167 4016  BEService ( UnsignedFile.Multi.Generic ) - warning
20:38:19.0167 4016  BEService - detected UnsignedFile.Multi.Generic (1)
20:38:19.0214 4016  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE            C:\Windows\System32\bfe.dll
20:38:19.0260 4016  BFE - ok
20:38:19.0276 4016  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\System32\qmgr.dll
20:38:19.0323 4016  BITS - ok
20:38:19.0338 4016  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
20:38:19.0370 4016  blbdrive - ok
20:38:19.0448 4016  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
20:38:19.0463 4016  Bonjour Service - ok
20:38:19.0494 4016  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
20:38:19.0510 4016  bowser - ok
20:38:19.0541 4016  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
20:38:19.0604 4016  BrFiltLo - ok
20:38:19.0604 4016  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
20:38:19.0619 4016  BrFiltUp - ok
20:38:19.0666 4016  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser        C:\Windows\System32\browser.dll
20:38:19.0697 4016  Browser - ok
20:38:19.0713 4016  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
20:38:19.0760 4016  Brserid - ok
20:38:19.0760 4016  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
20:38:19.0806 4016  BrSerWdm - ok
20:38:19.0806 4016  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
20:38:19.0822 4016  BrUsbMdm - ok
20:38:19.0853 4016  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
20:38:19.0869 4016  BrUsbSer - ok
20:38:19.0884 4016  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
20:38:19.0900 4016  BTHMODEM - ok
20:38:19.0931 4016  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv        C:\Windows\system32\bthserv.dll
20:38:19.0994 4016  bthserv - ok
20:38:20.0009 4016  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
20:38:20.0040 4016  cdfs - ok
20:38:20.0072 4016  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom          C:\Windows\system32\drivers\cdrom.sys
20:38:20.0103 4016  cdrom - ok
20:38:20.0134 4016  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc    C:\Windows\System32\certprop.dll
20:38:20.0181 4016  CertPropSvc - ok
20:38:20.0196 4016  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
20:38:20.0212 4016  circlass - ok
20:38:20.0228 4016  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
20:38:20.0243 4016  CLFS - ok
20:38:20.0306 4016  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:38:20.0306 4016  clr_optimization_v2.0.50727_32 - ok
20:38:20.0352 4016  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:38:20.0368 4016  clr_optimization_v2.0.50727_64 - ok
20:38:20.0430 4016  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:38:20.0446 4016  clr_optimization_v4.0.30319_32 - ok
20:38:20.0446 4016  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:38:20.0446 4016  clr_optimization_v4.0.30319_64 - ok
20:38:20.0477 4016  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
20:38:20.0477 4016  CmBatt - ok
20:38:20.0493 4016  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
20:38:20.0493 4016  cmdide - ok
20:38:20.0540 4016  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG            C:\Windows\system32\Drivers\cng.sys
20:38:20.0571 4016  CNG - ok
20:38:20.0586 4016  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
20:38:20.0586 4016  Compbatt - ok
20:38:20.0633 4016  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
20:38:20.0664 4016  CompositeBus - ok
20:38:20.0664 4016  COMSysApp - ok
20:38:20.0680 4016  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk        C:\Windows\system32\DRIVERS\crcdisk.sys
20:38:20.0696 4016  crcdisk - ok
20:38:20.0727 4016  [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc        C:\Windows\system32\cryptsvc.dll
20:38:20.0774 4016  CryptSvc - ok
20:38:20.0805 4016  [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC            C:\Windows\system32\drivers\csc.sys
20:38:20.0867 4016  CSC - ok
20:38:20.0898 4016  [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService      C:\Windows\System32\cscsvc.dll
20:38:20.0930 4016  CscService - ok
20:38:20.0945 4016  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
20:38:21.0008 4016  DcomLaunch - ok
20:38:21.0039 4016  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc      C:\Windows\System32\defragsvc.dll
20:38:21.0086 4016  defragsvc - ok
20:38:21.0117 4016  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
20:38:21.0148 4016  DfsC - ok
20:38:21.0164 4016  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
20:38:21.0195 4016  Dhcp - ok
20:38:21.0210 4016  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
20:38:21.0226 4016  discache - ok
20:38:21.0257 4016  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\DRIVERS\disk.sys
20:38:21.0273 4016  Disk - ok
20:38:21.0304 4016  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
20:38:21.0351 4016  Dnscache - ok
20:38:21.0366 4016  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc        C:\Windows\System32\dot3svc.dll
20:38:21.0413 4016  dot3svc - ok
20:38:21.0444 4016  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS            C:\Windows\system32\dps.dll
20:38:21.0476 4016  DPS - ok
20:38:21.0491 4016  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
20:38:21.0522 4016  drmkaud - ok
20:38:21.0585 4016  dump_wmimmc - ok
20:38:21.0616 4016  [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
20:38:21.0647 4016  DXGKrnl - ok
20:38:21.0694 4016  EagleX64 - ok
20:38:21.0710 4016  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost        C:\Windows\System32\eapsvc.dll
20:38:21.0772 4016  EapHost - ok
20:38:21.0819 4016  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv          C:\Windows\system32\DRIVERS\evbda.sys
20:38:21.0912 4016  ebdrv - ok
20:38:21.0944 4016  [ C118A82CD78818C29AB228366EBF81C3 ] EFS            C:\Windows\System32\lsass.exe
20:38:21.0990 4016  EFS - ok
20:38:22.0022 4016  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
20:38:22.0053 4016  ehRecvr - ok
20:38:22.0084 4016  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched        C:\Windows\ehome\ehsched.exe
20:38:22.0131 4016  ehSched - ok
20:38:22.0162 4016  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor        C:\Windows\system32\DRIVERS\elxstor.sys
20:38:22.0193 4016  elxstor - ok
20:38:22.0224 4016  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
20:38:22.0256 4016  ErrDev - ok
20:38:22.0287 4016  [ 932C05033053ADA2404FD836C9AB2C70 ] EuMusDesignVirtualAudioCableWdm C:\Windows\system32\DRIVERS\vrtaucbl.sys
20:38:22.0302 4016  EuMusDesignVirtualAudioCableWdm - ok
20:38:22.0318 4016  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem    C:\Windows\system32\es.dll
20:38:22.0380 4016  EventSystem - ok
20:38:22.0396 4016  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat          C:\Windows\system32\drivers\exfat.sys
20:38:22.0427 4016  exfat - ok
20:38:22.0427 4016  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat        C:\Windows\system32\drivers\fastfat.sys
20:38:22.0458 4016  fastfat - ok
20:38:22.0505 4016  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax            C:\Windows\system32\fxssvc.exe
20:38:22.0536 4016  Fax - ok
20:38:22.0552 4016  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
20:38:22.0583 4016  fdc - ok
20:38:22.0599 4016  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost        C:\Windows\system32\fdPHost.dll
20:38:22.0646 4016  fdPHost - ok
20:38:22.0661 4016  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
20:38:22.0677 4016  FDResPub - ok
20:38:22.0708 4016  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
20:38:22.0724 4016  FileInfo - ok
20:38:22.0739 4016  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
20:38:22.0755 4016  Filetrace - ok
20:38:22.0770 4016  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
20:38:22.0786 4016  flpydisk - ok
20:38:22.0817 4016  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
20:38:22.0848 4016  FltMgr - ok
20:38:22.0880 4016  [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache      C:\Windows\system32\FntCache.dll
20:38:22.0942 4016  FontCache - ok
20:38:22.0989 4016  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:38:23.0004 4016  FontCache3.0.0.0 - ok
20:38:23.0020 4016  [ D43703496149971890703B4B1B723EAC ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
20:38:23.0036 4016  FsDepends - ok
20:38:23.0067 4016  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
20:38:23.0082 4016  Fs_Rec - ok
20:38:23.0098 4016  [ 1F7B25B858FA27015169FE95E54108ED ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
20:38:23.0129 4016  fvevol - ok
20:38:23.0129 4016  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
20:38:23.0145 4016  gagp30kx - ok
20:38:23.0192 4016  [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
20:38:23.0207 4016  GEARAspiWDM - ok
20:38:23.0238 4016  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc          C:\Windows\System32\gpsvc.dll
20:38:23.0285 4016  gpsvc - ok
20:38:23.0316 4016  [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi        C:\Windows\system32\DRIVERS\hamachi.sys
20:38:23.0332 4016  hamachi - ok
20:38:23.0441 4016  [ 785FD63B74B30986A9F2C7D965CA509F ] Hamachi2Svc    C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
20:38:23.0519 4016  Hamachi2Svc - ok
20:38:23.0535 4016  [ ADB4348DA1345877B04E22203AFC8993 ] hcmon          C:\Windows\system32\drivers\hcmon.sys
20:38:23.0550 4016  hcmon - ok
20:38:23.0550 4016  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
20:38:23.0597 4016  hcw85cir - ok
20:38:23.0644 4016  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
20:38:23.0675 4016  HdAudAddService - ok
20:38:23.0691 4016  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
20:38:23.0738 4016  HDAudBus - ok
20:38:23.0753 4016  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt        C:\Windows\system32\DRIVERS\HidBatt.sys
20:38:23.0784 4016  HidBatt - ok
20:38:23.0800 4016  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
20:38:23.0816 4016  HidBth - ok
20:38:23.0847 4016  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
20:38:23.0878 4016  HidIr - ok
20:38:23.0894 4016  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv        C:\Windows\system32\hidserv.dll
20:38:23.0956 4016  hidserv - ok
20:38:23.0987 4016  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\drivers\hidusb.sys
20:38:24.0003 4016  HidUsb - ok
20:38:24.0034 4016  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
20:38:24.0050 4016  hkmsvc - ok
20:38:24.0096 4016  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
20:38:24.0143 4016  HomeGroupListener - ok
20:38:24.0159 4016  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
20:38:24.0206 4016  HomeGroupProvider - ok
20:38:24.0237 4016  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
20:38:24.0252 4016  HpSAMD - ok
20:38:24.0284 4016  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
20:38:24.0346 4016  HTTP - ok
20:38:24.0377 4016  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
20:38:24.0377 4016  hwpolicy - ok
20:38:24.0393 4016  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
20:38:24.0408 4016  i8042prt - ok
20:38:24.0424 4016  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
20:38:24.0424 4016  iaStorV - ok
20:38:24.0471 4016  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:38:24.0502 4016  idsvc - ok
20:38:24.0518 4016  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp          C:\Windows\system32\DRIVERS\iirsp.sys
20:38:24.0518 4016  iirsp - ok
20:38:24.0549 4016  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
20:38:24.0580 4016  IKEEXT - ok
20:38:24.0596 4016  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
20:38:24.0611 4016  intelide - ok
20:38:24.0611 4016  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
20:38:24.0627 4016  intelppm - ok
20:38:24.0642 4016  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
20:38:24.0658 4016  IPBusEnum - ok
20:38:24.0689 4016  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:38:24.0720 4016  IpFilterDriver - ok
20:38:24.0752 4016  [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
20:38:24.0783 4016  iphlpsvc - ok
20:38:24.0798 4016  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
20:38:24.0830 4016  IPMIDRV - ok
20:38:24.0830 4016  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
20:38:24.0892 4016  IPNAT - ok
20:38:24.0939 4016  [ A9AB99EE7D39725EAFEC82732D2B3271 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
20:38:24.0954 4016  iPod Service - ok
20:38:24.0970 4016  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
20:38:25.0001 4016  IRENUM - ok
20:38:25.0017 4016  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
20:38:25.0032 4016  isapnp - ok
20:38:25.0032 4016  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
20:38:25.0048 4016  iScsiPrt - ok
20:38:25.0064 4016  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\drivers\kbdclass.sys
20:38:25.0079 4016  kbdclass - ok
20:38:25.0095 4016  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
20:38:25.0110 4016  kbdhid - ok
20:38:25.0126 4016  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
20:38:25.0142 4016  KeyIso - ok
20:38:25.0188 4016  [ 8B5219318DF5895ABD230C373F2DF18A ] KL1            C:\Windows\system32\DRIVERS\kl1.sys
20:38:25.0220 4016  KL1 - ok
20:38:25.0235 4016  [ 65F3B81FA285EAB641F5E6EF7AEB984D ] KLIF            C:\Windows\system32\DRIVERS\klif.sys
20:38:25.0251 4016  KLIF - ok
20:38:25.0282 4016  [ 9BD99E1AB3F664120AB95C35F9EC1EB0 ] KLIM6          C:\Windows\system32\DRIVERS\klim6.sys
20:38:25.0298 4016  KLIM6 - ok
20:38:25.0344 4016  [ 2C43FD500522EF3B8C283A5846B7FC41 ] klkbdflt        C:\Windows\system32\DRIVERS\klkbdflt.sys
20:38:25.0360 4016  klkbdflt - ok
20:38:25.0360 4016  [ 70A6D2E292017EC47949696F51ABE18D ] klmouflt        C:\Windows\system32\DRIVERS\klmouflt.sys
20:38:25.0376 4016  klmouflt - ok
20:38:25.0391 4016  [ A8081ED8D48FA611D11DB97F49A5343D ] kltdi          C:\Windows\system32\DRIVERS\kltdi.sys
20:38:25.0407 4016  kltdi - ok
20:38:25.0438 4016  [ 185D21CB8F10CFB351FF65DA88C18BC9 ] kneps          C:\Windows\system32\DRIVERS\kneps.sys
20:38:25.0438 4016  kneps - ok
20:38:25.0469 4016  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
20:38:25.0485 4016  KSecDD - ok
20:38:25.0500 4016  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
20:38:25.0500 4016  KSecPkg - ok
20:38:25.0516 4016  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
20:38:25.0547 4016  ksthunk - ok
20:38:25.0563 4016  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm          C:\Windows\system32\msdtckrm.dll
20:38:25.0610 4016  KtmRm - ok
20:38:25.0656 4016  [ CE4347E2D90DB2E5517B6F2BC720A862 ] LADF_CaptureOnly C:\Windows\system32\DRIVERS\ladfGSCamd64.sys
20:38:25.0672 4016  LADF_CaptureOnly - ok
20:38:25.0688 4016  [ 85A9D21D3AE2EA963E111CB150895877 ] LADF_RenderOnly C:\Windows\system32\DRIVERS\ladfGSRamd64.sys
20:38:25.0703 4016  LADF_RenderOnly - ok
20:38:25.0734 4016  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\system32\srvsvc.dll
20:38:25.0797 4016  LanmanServer - ok
20:38:25.0828 4016  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
20:38:25.0859 4016  LanmanWorkstation - ok
20:38:25.0890 4016  [ FA529FB35694C24BF98A9EF67C1CD9D0 ] LGBusEnum      C:\Windows\system32\drivers\LGBusEnum.sys
20:38:25.0906 4016  LGBusEnum - ok
20:38:25.0922 4016  [ 94B29CE153765E768F004FB3440BE2B0 ] LGVirHid        C:\Windows\system32\drivers\LGVirHid.sys
20:38:25.0937 4016  LGVirHid - ok
20:38:25.0968 4016  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
20:38:26.0031 4016  lltdio - ok
20:38:26.0062 4016  [ C1185803384AB3FEED115F79F109427F ] lltdsvc        C:\Windows\System32\lltdsvc.dll
20:38:26.0124 4016  lltdsvc - ok
20:38:26.0124 4016  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts        C:\Windows\System32\lmhsvc.dll
20:38:26.0156 4016  lmhosts - ok
20:38:26.0202 4016  [ 7109163D8027076D2680CFC4E80E2A28 ] LMIGuardianSvc  C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
20:38:26.0218 4016  LMIGuardianSvc - ok
20:38:26.0249 4016  [ 0317335B15FF3BDA8E10197E3434CFC0 ] LMIInfo        C:\Program Files (x86)\LogMeIn\x64\rainfo.sys
20:38:26.0265 4016  LMIInfo - ok
20:38:26.0312 4016  [ 8054CE1FC8B417691960D00F931516A7 ] LMIMaint        C:\Program Files (x86)\LogMeIn\x64\ramaint.exe
20:38:26.0312 4016  LMIMaint - ok
20:38:26.0358 4016  [ D3760BC17E1755091B7120CF32DBF56B ] LogMeIn        C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
20:38:26.0374 4016  LogMeIn - ok
20:38:26.0421 4016  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
20:38:26.0436 4016  LSI_FC - ok
20:38:26.0452 4016  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS        C:\Windows\system32\DRIVERS\lsi_sas.sys
20:38:26.0468 4016  LSI_SAS - ok
20:38:26.0468 4016  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
20:38:26.0483 4016  LSI_SAS2 - ok
20:38:26.0499 4016  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
20:38:26.0514 4016  LSI_SCSI - ok
20:38:26.0546 4016  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv          C:\Windows\system32\drivers\luafv.sys
20:38:26.0592 4016  luafv - ok
20:38:26.0624 4016  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
20:38:26.0639 4016  Mcx2Svc - ok
20:38:26.0655 4016  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas        C:\Windows\system32\DRIVERS\megasas.sys
20:38:26.0670 4016  megasas - ok
20:38:26.0686 4016  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
20:38:26.0702 4016  MegaSR - ok
20:38:26.0717 4016  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS          C:\Windows\system32\mmcss.dll
20:38:26.0748 4016  MMCSS - ok
20:38:26.0764 4016  [ 800BA92F7010378B09F9ED9270F07137 ] Modem          C:\Windows\system32\drivers\modem.sys
20:38:26.0795 4016  Modem - ok
20:38:26.0826 4016  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
20:38:26.0858 4016  monitor - ok
20:38:26.0873 4016  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\drivers\mouclass.sys
20:38:26.0889 4016  mouclass - ok
20:38:26.0920 4016  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
20:38:26.0920 4016  mouhid - ok
20:38:26.0967 4016  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
20:38:26.0982 4016  mountmgr - ok
20:38:27.0029 4016  [ 8C7336950F1E69CDFD811CBBD9CF00A2 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
20:38:27.0045 4016  MozillaMaintenance - ok
20:38:27.0092 4016  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
20:38:27.0107 4016  mpio - ok
20:38:27.0107 4016  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
20:38:27.0154 4016  mpsdrv - ok
20:38:27.0185 4016  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
20:38:27.0216 4016  MpsSvc - ok
20:38:27.0248 4016  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
20:38:27.0263 4016  MRxDAV - ok
20:38:27.0279 4016  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
20:38:27.0326 4016  mrxsmb - ok
20:38:27.0341 4016  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:38:27.0372 4016  mrxsmb10 - ok
20:38:27.0404 4016  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:38:27.0435 4016  mrxsmb20 - ok
20:38:27.0450 4016  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
20:38:27.0466 4016  msahci - ok
20:38:27.0482 4016  [ DB801A638D011B9633829EB6F663C900 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
20:38:27.0497 4016  msdsm - ok
20:38:27.0513 4016  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC          C:\Windows\System32\msdtc.exe
20:38:27.0544 4016  MSDTC - ok
20:38:27.0560 4016  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
20:38:27.0591 4016  Msfs - ok
20:38:27.0638 4016  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
20:38:27.0684 4016  mshidkmdf - ok
20:38:27.0716 4016  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
20:38:27.0731 4016  msisadrv - ok
20:38:27.0747 4016  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
20:38:27.0809 4016  MSiSCSI - ok
20:38:27.0809 4016  msiserver - ok
20:38:27.0825 4016  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
20:38:27.0856 4016  MSKSSRV - ok
20:38:27.0856 4016  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
20:38:27.0903 4016  MSPCLOCK - ok
20:38:27.0903 4016  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
20:38:27.0934 4016  MSPQM - ok
20:38:27.0965 4016  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
20:38:27.0981 4016  MsRPC - ok
20:38:27.0981 4016  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
20:38:27.0996 4016  mssmbios - ok
20:38:27.0996 4016  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
20:38:28.0043 4016  MSTEE - ok
20:38:28.0043 4016  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
20:38:28.0059 4016  MTConfig - ok
20:38:28.0074 4016  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup            C:\Windows\system32\Drivers\mup.sys
20:38:28.0074 4016  Mup - ok
20:38:28.0090 4016  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
20:38:28.0121 4016  napagent - ok
20:38:28.0152 4016  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
20:38:28.0184 4016  NativeWifiP - ok
20:38:28.0215 4016  [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS            C:\Windows\system32\drivers\ndis.sys
20:38:28.0230 4016  NDIS - ok
20:38:28.0230 4016  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
20:38:28.0262 4016  NdisCap - ok
20:38:28.0293 4016  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
20:38:28.0340 4016  NdisTapi - ok
20:38:28.0371 4016  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
20:38:28.0386 4016  Ndisuio - ok
20:38:28.0418 4016  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
20:38:28.0480 4016  NdisWan - ok
20:38:28.0496 4016  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
20:38:28.0527 4016  NDProxy - ok
20:38:28.0605 4016  [ B90E093E7A7250906F1054418B5339C0 ] Nero BackItUp Scheduler 4.0 C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
20:38:28.0620 4016  Nero BackItUp Scheduler 4.0 - ok
20:38:28.0620 4016  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
20:38:28.0652 4016  NetBIOS - ok
20:38:28.0667 4016  [ 09594D1089C523423B32A4229263F068 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
20:38:28.0698 4016  NetBT - ok
20:38:28.0698 4016  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
20:38:28.0714 4016  Netlogon - ok
20:38:28.0730 4016  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
20:38:28.0745 4016  Netman - ok
20:38:28.0776 4016  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:38:28.0792 4016  NetMsmqActivator - ok
20:38:28.0792 4016  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:38:28.0792 4016  NetPipeActivator - ok
20:38:28.0808 4016  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
20:38:28.0854 4016  netprofm - ok
20:38:28.0854 4016  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:38:28.0854 4016  NetTcpActivator - ok
20:38:28.0854 4016  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:38:28.0870 4016  NetTcpPortSharing - ok
20:38:28.0886 4016  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960        C:\Windows\system32\DRIVERS\nfrd960.sys
20:38:28.0886 4016  nfrd960 - ok
20:38:28.0917 4016  [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc          C:\Windows\System32\nlasvc.dll
20:38:28.0979 4016  NlaSvc - ok
20:38:28.0995 4016  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
20:38:29.0026 4016  Npfs - ok
20:38:29.0073 4016  npggsvc - ok
20:38:29.0073 4016  NPPTNT2 - ok
20:38:29.0104 4016  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi            C:\Windows\system32\nsisvc.dll
20:38:29.0166 4016  nsi - ok
20:38:29.0182 4016  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
20:38:29.0213 4016  nsiproxy - ok
20:38:29.0244 4016  [ A2F74975097F52A00745F9637451FDD8 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
20:38:29.0276 4016  Ntfs - ok
20:38:29.0291 4016  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
20:38:29.0322 4016  Null - ok
20:38:29.0354 4016  [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA          C:\Windows\system32\drivers\nvhda64v.sys
20:38:29.0369 4016  NVHDA - ok
20:38:29.0603 4016  [ 5104BAC2DA2A5BDD86AC6B0708B00F06 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
20:38:29.0728 4016  nvlddmkm - ok
20:38:29.0759 4016  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
20:38:29.0775 4016  nvraid - ok
20:38:29.0790 4016  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
20:38:29.0790 4016  nvstor - ok
20:38:29.0822 4016  [ DDFAFCE89A5C93D04712B86F94E9FCBA ] NVSvc          C:\Windows\system32\nvvsvc.exe
20:38:29.0853 4016  NVSvc - ok
20:38:29.0946 4016  [ 84E035225474E48CD3A6A3CE52332095 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
20:38:29.0993 4016  nvUpdatusService - ok
20:38:30.0009 4016  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
20:38:30.0009 4016  nv_agp - ok
20:38:30.0024 4016  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
20:38:30.0040 4016  ohci1394 - ok
20:38:30.0087 4016  [ EC322186D8FCE3D632F3F597D67747DD ] OpenVPNService  C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe
20:38:30.0118 4016  OpenVPNService ( UnsignedFile.Multi.Generic ) - warning
20:38:30.0118 4016  OpenVPNService - detected UnsignedFile.Multi.Generic (1)
20:38:30.0149 4016  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
20:38:30.0196 4016  p2pimsvc - ok
20:38:30.0243 4016  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
20:38:30.0258 4016  p2psvc - ok
20:38:30.0290 4016  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport        C:\Windows\system32\DRIVERS\parport.sys
20:38:30.0305 4016  Parport - ok
20:38:30.0336 4016  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr        C:\Windows\system32\drivers\partmgr.sys
20:38:30.0352 4016  partmgr - ok
20:38:30.0368 4016  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
20:38:30.0399 4016  PcaSvc - ok
20:38:30.0430 4016  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci            C:\Windows\system32\drivers\pci.sys
20:38:30.0430 4016  pci - ok
20:38:30.0446 4016  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
20:38:30.0446 4016  pciide - ok
20:38:30.0477 4016  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
20:38:30.0477 4016  pcmcia - ok
20:38:30.0492 4016  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw            C:\Windows\system32\drivers\pcw.sys
20:38:30.0508 4016  pcw - ok
20:38:30.0524 4016  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
20:38:30.0555 4016  PEAUTH - ok
20:38:30.0586 4016  [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc    C:\Windows\system32\peerdistsvc.dll
20:38:30.0664 4016  PeerDistSvc - ok
20:38:30.0726 4016  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
20:38:30.0758 4016  PerfHost - ok
20:38:30.0804 4016  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla            C:\Windows\system32\pla.dll
20:38:30.0882 4016  pla - ok
20:38:30.0898 4016  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
20:38:30.0929 4016  PlugPlay - ok
20:38:30.0929 4016  PnkBstrA - ok
20:38:30.0945 4016  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
20:38:30.0960 4016  PNRPAutoReg - ok
20:38:30.0960 4016  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
20:38:30.0976 4016  PNRPsvc - ok
20:38:30.0992 4016  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
20:38:31.0038 4016  PolicyAgent - ok
20:38:31.0054 4016  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power          C:\Windows\system32\umpo.dll
20:38:31.0101 4016  Power - ok
20:38:31.0148 4016  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
20:38:31.0179 4016  PptpMiniport - ok
20:38:31.0194 4016  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor      C:\Windows\system32\DRIVERS\processr.sys
20:38:31.0194 4016  Processor - ok
20:38:31.0226 4016  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc        C:\Windows\system32\profsvc.dll
20:38:31.0288 4016  ProfSvc - ok
20:38:31.0288 4016  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
20:38:31.0304 4016  ProtectedStorage - ok
20:38:31.0335 4016  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
20:38:31.0366 4016  Psched - ok
20:38:31.0444 4016  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
20:38:31.0460 4016  ql2300 - ok
20:38:31.0491 4016  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
20:38:31.0506 4016  ql40xx - ok
20:38:31.0522 4016  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE          C:\Windows\system32\qwave.dll
20:38:31.0569 4016  QWAVE - ok
20:38:31.0569 4016  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
20:38:31.0600 4016  QWAVEdrv - ok
20:38:31.0631 4016  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
20:38:31.0647 4016  RasAcd - ok
20:38:31.0662 4016  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
20:38:31.0694 4016  RasAgileVpn - ok
20:38:31.0709 4016  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto        C:\Windows\System32\rasauto.dll
20:38:31.0725 4016  RasAuto - ok
20:38:31.0756 4016  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
20:38:31.0818 4016  Rasl2tp - ok
20:38:31.0834 4016  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
20:38:31.0865 4016  RasMan - ok
20:38:31.0896 4016  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
20:38:31.0943 4016  RasPppoe - ok
20:38:31.0974 4016  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
20:38:31.0990 4016  RasSstp - ok
20:38:32.0006 4016  [ 77F665941019A1594D887A74F301FA2F ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
20:38:32.0037 4016  rdbss - ok
20:38:32.0052 4016  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
20:38:32.0068 4016  rdpbus - ok
20:38:32.0084 4016  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
20:38:32.0099 4016  RDPCDD - ok
20:38:32.0115 4016  [ 1B6163C503398B23FF8B939C67747683 ] RDPDR          C:\Windows\system32\drivers\rdpdr.sys
20:38:32.0146 4016  RDPDR - ok
20:38:32.0162 4016  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
20:38:32.0208 4016  RDPENCDD - ok
20:38:32.0240 4016  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
20:38:32.0255 4016  RDPREFMP - ok
20:38:32.0286 4016  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
20:38:32.0333 4016  RDPWD - ok
20:38:32.0380 4016  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
20:38:32.0396 4016  rdyboost - ok
20:38:32.0411 4016  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
20:38:32.0458 4016  RemoteAccess - ok
20:38:32.0489 4016  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
20:38:32.0536 4016  RemoteRegistry - ok
20:38:32.0536 4016  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
20:38:32.0583 4016  RpcEptMapper - ok
20:38:32.0614 4016  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
20:38:32.0630 4016  RpcLocator - ok
20:38:32.0661 4016  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs          C:\Windows\system32\rpcss.dll
20:38:32.0708 4016  RpcSs - ok
20:38:32.0723 4016  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
20:38:32.0754 4016  rspndr - ok
20:38:32.0786 4016  [ F4C374B1C46DE294B573BB43723AC3F6 ] RTL8167        C:\Windows\system32\DRIVERS\Rt64win7.sys
20:38:32.0801 4016  RTL8167 - ok
20:38:32.0817 4016  [ E60C0A09F997826C7627B244195AB581 ] s3cap          C:\Windows\system32\drivers\vms3cap.sys
20:38:32.0832 4016  s3cap - ok
20:38:32.0848 4016  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs          C:\Windows\system32\lsass.exe
20:38:32.0848 4016  SamSs - ok
20:38:32.0864 4016  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
20:38:32.0864 4016  sbp2port - ok
20:38:32.0879 4016  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
20:38:32.0910 4016  SCardSvr - ok
20:38:32.0942 4016  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
20:38:32.0988 4016  scfilter - ok
20:38:33.0020 4016  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
20:38:33.0051 4016  Schedule - ok
20:38:33.0082 4016  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc    C:\Windows\System32\certprop.dll
20:38:33.0098 4016  SCPolicySvc - ok
20:38:33.0113 4016  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
20:38:33.0144 4016  SDRSVC - ok
20:38:33.0176 4016  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
20:38:33.0207 4016  secdrv - ok
20:38:33.0238 4016  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
20:38:33.0269 4016  seclogon - ok
20:38:33.0285 4016  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\System32\sens.dll
20:38:33.0316 4016  SENS - ok
20:38:33.0347 4016  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
20:38:33.0378 4016  SensrSvc - ok
20:38:33.0394 4016  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
20:38:33.0425 4016  Serenum - ok
20:38:33.0441 4016  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
20:38:33.0472 4016  Serial - ok
20:38:33.0488 4016  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
20:38:33.0503 4016  sermouse - ok
20:38:33.0550 4016  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
20:38:33.0597 4016  SessionEnv - ok
20:38:33.0612 4016  [ A554811BCD09279536440C964AE35BBF ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
20:38:33.0644 4016  sffdisk - ok
20:38:33.0644 4016  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
20:38:33.0659 4016  sffp_mmc - ok
20:38:33.0659 4016  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
20:38:33.0690 4016  sffp_sd - ok
20:38:33.0706 4016  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy        C:\Windows\system32\DRIVERS\sfloppy.sys
20:38:33.0722 4016  sfloppy - ok
20:38:33.0753 4016  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
20:38:33.0800 4016  SharedAccess - ok
20:38:33.0831 4016  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
20:38:33.0862 4016  ShellHWDetection - ok
20:38:33.0893 4016  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
20:38:33.0893 4016  SiSRaid2 - ok
20:38:33.0909 4016  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
20:38:33.0924 4016  SiSRaid4 - ok
20:38:33.0956 4016  [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
20:38:33.0971 4016  SkypeUpdate - ok
20:38:34.0002 4016  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
20:38:34.0049 4016  Smb - ok
20:38:34.0080 4016  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
20:38:34.0112 4016  SNMPTRAP - ok
20:38:34.0112 4016  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr          C:\Windows\system32\drivers\spldr.sys
20:38:34.0127 4016  spldr - ok
20:38:34.0158 4016  [ B96C17B5DC1424D56EEA3A99E97428CD ] Spooler        C:\Windows\System32\spoolsv.exe
20:38:34.0190 4016  Spooler - ok
20:38:34.0268 4016  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
20:38:34.0330 4016  sppsvc - ok
20:38:34.0346 4016  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
20:38:34.0392 4016  sppuinotify - ok
20:38:34.0408 4016  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv            C:\Windows\system32\DRIVERS\srv.sys
20:38:34.0439 4016  srv - ok
20:38:34.0455 4016  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
20:38:34.0486 4016  srv2 - ok
20:38:34.0502 4016  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
20:38:34.0533 4016  srvnet - ok
20:38:34.0548 4016  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
20:38:34.0580 4016  SSDPSRV - ok
20:38:34.0611 4016  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc        C:\Windows\system32\sstpsvc.dll
20:38:34.0626 4016  SstpSvc - ok
20:38:34.0658 4016  Steam Client Service - ok
20:38:34.0720 4016  [ F0359F7CE712D69ACEF0886BDB4792ED ] Stereo Service  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
20:38:34.0736 4016  Stereo Service - ok
20:38:34.0751 4016  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
20:38:34.0767 4016  stexstor - ok
20:38:34.0814 4016  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
20:38:34.0860 4016  stisvc - ok
20:38:34.0876 4016  [ 7785DC213270D2FC066538DAF94087E7 ] storflt        C:\Windows\system32\drivers\vmstorfl.sys
20:38:34.0892 4016  storflt - ok
20:38:34.0907 4016  [ C40841817EF57D491F22EB103DA587CC ] StorSvc        C:\Windows\system32\storsvc.dll
20:38:34.0938 4016  StorSvc - ok
20:38:34.0938 4016  [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc        C:\Windows\system32\drivers\storvsc.sys
20:38:34.0954 4016  storvsc - ok
20:38:34.0970 4016  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\drivers\swenum.sys
20:38:34.0970 4016  swenum - ok
20:38:35.0079 4016  [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard    C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
20:38:35.0110 4016  SwitchBoard ( UnsignedFile.Multi.Generic ) - warning
20:38:35.0110 4016  SwitchBoard - detected UnsignedFile.Multi.Generic (1)
20:38:35.0126 4016  [ E08E46FDD841B7184194011CA1955A0B ] swprv          C:\Windows\System32\swprv.dll
20:38:35.0172 4016  swprv - ok
20:38:35.0219 4016  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain        C:\Windows\system32\sysmain.dll
20:38:35.0282 4016  SysMain - ok
20:38:35.0313 4016  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
20:38:35.0328 4016  TabletInputService - ok
20:38:35.0360 4016  [ F9BE29D5E097F03F81D3CD12B794CB66 ] tap0901        C:\Windows\system32\DRIVERS\tap0901.sys
20:38:35.0406 4016  tap0901 - ok
20:38:35.0438 4016  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv        C:\Windows\System32\tapisrv.dll
20:38:35.0500 4016  TapiSrv - ok
20:38:35.0500 4016  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS            C:\Windows\System32\tbssvc.dll
20:38:35.0547 4016  TBS - ok
20:38:35.0594 4016  [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
20:38:35.0625 4016  Tcpip - ok
20:38:35.0687 4016  [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
20:38:35.0718 4016  TCPIP6 - ok
20:38:35.0750 4016  [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
20:38:35.0781 4016  tcpipreg - ok
20:38:35.0812 4016  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
20:38:35.0828 4016  TDPIPE - ok
20:38:35.0859 4016  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
20:38:35.0890 4016  TDTCP - ok
20:38:35.0906 4016  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
20:38:35.0952 4016  tdx - ok
20:38:35.0984 4016  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\drivers\termdd.sys
20:38:35.0984 4016  TermDD - ok
20:38:36.0015 4016  [ 2E648163254233755035B46DD7B89123 ] TermService    C:\Windows\System32\termsrv.dll
20:38:36.0062 4016  TermService - ok
20:38:36.0077 4016  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
20:38:36.0093 4016  Themes - ok
20:38:36.0124 4016  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER    C:\Windows\system32\mmcss.dll
20:38:36.0140 4016  THREADORDER - ok
20:38:36.0155 4016  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
20:38:36.0186 4016  TrkWks - ok
20:38:36.0233 4016  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
20:38:36.0296 4016  TrustedInstaller - ok
20:38:36.0311 4016  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
20:38:36.0342 4016  tssecsrv - ok
20:38:36.0374 4016  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
20:38:36.0389 4016  TsUsbFlt - ok
20:38:36.0436 4016  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
20:38:36.0467 4016  tunnel - ok
20:38:36.0483 4016  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
20:38:36.0498 4016  uagp35 - ok
20:38:36.0514 4016  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
20:38:36.0530 4016  udfs - ok
20:38:36.0545 4016  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
20:38:36.0576 4016  UI0Detect - ok
20:38:36.0592 4016  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
20:38:36.0608 4016  uliagpkx - ok
20:38:36.0623 4016  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus          C:\Windows\system32\drivers\umbus.sys
20:38:36.0639 4016  umbus - ok
20:38:36.0654 4016  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
20:38:36.0654 4016  UmPass - ok
20:38:36.0686 4016  [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService    C:\Windows\System32\umrdp.dll
20:38:36.0701 4016  UmRdpService - ok
20:38:36.0717 4016  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
20:38:36.0748 4016  upnphost - ok
20:38:36.0779 4016  [ FB251567F41BC61988B26731DEC19E4B ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
20:38:36.0810 4016  USBAAPL64 - ok
20:38:36.0842 4016  [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
20:38:36.0873 4016  usbaudio - ok
20:38:36.0904 4016  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
20:38:36.0951 4016  usbccgp - ok
20:38:36.0982 4016  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
20:38:37.0013 4016  usbcir - ok
20:38:37.0013 4016  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
20:38:37.0044 4016  usbehci - ok
20:38:37.0060 4016  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
20:38:37.0107 4016  usbhub - ok
20:38:37.0122 4016  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
20:38:37.0154 4016  usbohci - ok
20:38:37.0185 4016  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
20:38:37.0216 4016  usbprint - ok
20:38:37.0232 4016  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR        C:\Windows\system32\drivers\USBSTOR.SYS
20:38:37.0278 4016  USBSTOR - ok
20:38:37.0294 4016  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci        C:\Windows\system32\drivers\usbuhci.sys
20:38:37.0310 4016  usbuhci - ok
20:38:37.0341 4016  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms          C:\Windows\System32\uxsms.dll
20:38:37.0372 4016  UxSms - ok
20:38:37.0388 4016  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
20:38:37.0403 4016  VaultSvc - ok
20:38:37.0419 4016  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
20:38:37.0434 4016  vdrvroot - ok
20:38:37.0481 4016  [ 8D6B481601D01A456E75C3210F1830BE ] vds            C:\Windows\System32\vds.exe
20:38:37.0528 4016  vds - ok
20:38:37.0544 4016  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
20:38:37.0559 4016  vga - ok
20:38:37.0559 4016  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave        C:\Windows\System32\drivers\vga.sys
20:38:37.0590 4016  VgaSave - ok
20:38:37.0622 4016  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
20:38:37.0622 4016  vhdmp - ok
20:38:37.0637 4016  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
20:38:37.0653 4016  viaide - ok
20:38:37.0700 4016  [ 3ACCF0C817A2BB34EFBFB72B57B00252 ] VMAuthdService  C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
20:38:37.0715 4016  VMAuthdService ( UnsignedFile.Multi.Generic ) - warning
20:38:37.0715 4016  VMAuthdService - detected UnsignedFile.Multi.Generic (1)
20:38:37.0731 4016  [ 86EA3E79AE350FEA5331A1303054005F ] vmbus          C:\Windows\system32\drivers\vmbus.sys
20:38:37.0762 4016  vmbus - ok
20:38:37.0778 4016  [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
20:38:37.0793 4016  VMBusHID - ok
20:38:37.0824 4016  [ 87FC1DD880E8CAC4FAEBB84AF61A87C4 ] vmci            C:\Windows\system32\DRIVERS\vmci.sys
20:38:37.0840 4016  vmci - ok
20:38:37.0887 4016  [ B259C31378BC855AFD1B53F59311C251 ] VMnetAdapter    C:\Windows\system32\DRIVERS\vmnetadapter.sys
20:38:37.0902 4016  VMnetAdapter - ok
20:38:37.0949 4016  [ DEC4CE720FFEDA939CF1BA315CFBD993 ] VMnetBridge    C:\Windows\system32\DRIVERS\vmnetbridge.sys
20:38:37.0965 4016  VMnetBridge - ok
20:38:37.0965 4016  VMnetDHCP - ok
20:38:37.0965 4016  [ 1E74142DED099DE7ADA258042F891A8D ] VMnetuserif    C:\Windows\system32\drivers\vmnetuserif.sys
20:38:37.0980 4016  VMnetuserif - ok
20:38:37.0996 4016  [ 18903CA7936912C337C9D28858880CF2 ] VMUSBArbService C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
20:38:38.0012 4016  VMUSBArbService - ok
20:38:38.0012 4016  VMware NAT Service - ok
20:38:38.0183 4016  [ F95C4DEFCC06A1C9E3E1699C845980F1 ] VMwareHostd    C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
20:38:38.0292 4016  VMwareHostd ( UnsignedFile.Multi.Generic ) - warning
20:38:38.0292 4016  VMwareHostd - detected UnsignedFile.Multi.Generic (1)
20:38:38.0308 4016  [ 18A28EDA522B6C0560E59D5BE638D076 ] vmx86          C:\Windows\system32\drivers\vmx86.sys
20:38:38.0308 4016  vmx86 - ok
20:38:38.0339 4016  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
20:38:38.0355 4016  volmgr - ok
20:38:38.0386 4016  [ A255814907C89BE58B79EF2F189B843B ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
20:38:38.0402 4016  volmgrx - ok
20:38:38.0417 4016  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
20:38:38.0433 4016  volsnap - ok
20:38:38.0464 4016  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid        C:\Windows\system32\DRIVERS\vsmraid.sys
20:38:38.0480 4016  vsmraid - ok
20:38:38.0526 4016  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS            C:\Windows\system32\vssvc.exe
20:38:38.0573 4016  VSS - ok
20:38:38.0636 4016  [ 6107E33A30C0B923F31C872E1980D2D1 ] vstor2-mntapi10-shared C:\Windows\syswow64\drivers\vstor2-mntapi10-shared.sys
20:38:38.0651 4016  vstor2-mntapi10-shared - ok
20:38:38.0651 4016  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
20:38:38.0682 4016  vwifibus - ok
20:38:38.0714 4016  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time        C:\Windows\system32\w32time.dll
20:38:38.0760 4016  W32Time - ok
20:38:38.0776 4016  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
20:38:38.0792 4016  WacomPen - ok
20:38:38.0807 4016  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
20:38:38.0838 4016  WANARP - ok
20:38:38.0838 4016  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
20:38:38.0854 4016  Wanarpv6 - ok
20:38:38.0948 4016  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
20:38:38.0994 4016  wbengine - ok
20:38:39.0026 4016  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
20:38:39.0026 4016  WbioSrvc - ok
20:38:39.0057 4016  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc        C:\Windows\System32\wcncsvc.dll
20:38:39.0072 4016  wcncsvc - ok
20:38:39.0088 4016  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
20:38:39.0104 4016  WcsPlugInService - ok
20:38:39.0119 4016  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\DRIVERS\wd.sys
20:38:39.0119 4016  Wd - ok
20:38:39.0150 4016  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
20:38:39.0150 4016  Wdf01000 - ok
20:38:39.0166 4016  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
20:38:39.0244 4016  WdiServiceHost - ok
20:38:39.0244 4016  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost  C:\Windows\system32\wdi.dll
20:38:39.0260 4016  WdiSystemHost - ok
20:38:39.0291 4016  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient      C:\Windows\System32\webclnt.dll
20:38:39.0322 4016  WebClient - ok
20:38:39.0338 4016  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
20:38:39.0384 4016  Wecsvc - ok
20:38:39.0400 4016  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
20:38:39.0447 4016  wercplsupport - ok
20:38:39.0462 4016  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
20:38:39.0494 4016  WerSvc - ok
20:38:39.0494 4016  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
20:38:39.0525 4016  WfpLwf - ok
20:38:39.0525 4016  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
20:38:39.0540 4016  WIMMount - ok
20:38:39.0556 4016  WinDefend - ok
20:38:39.0556 4016  WinHttpAutoProxySvc - ok
20:38:39.0572 4016  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
20:38:39.0603 4016  Winmgmt - ok
20:38:39.0634 4016  [ BCB1310604AA415C4508708975B3931E ] WinRM          C:\Windows\system32\WsmSvc.dll
20:38:39.0696 4016  WinRM - ok
20:38:39.0728 4016  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
20:38:39.0743 4016  WinUsb - ok
20:38:39.0759 4016  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc        C:\Windows\System32\wlansvc.dll
20:38:39.0774 4016  Wlansvc - ok
20:38:39.0899 4016  [ 98F138897EF4246381D197CB81846D62 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
20:38:39.0977 4016  wlidsvc - ok
20:38:40.0008 4016  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
20:38:40.0024 4016  WmiAcpi - ok
20:38:40.0055 4016  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
20:38:40.0086 4016  wmiApSrv - ok
20:38:40.0102 4016  WMPNetworkSvc - ok
20:38:40.0118 4016  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
20:38:40.0149 4016  WPCSvc - ok
20:38:40.0180 4016  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
20:38:40.0211 4016  WPDBusEnum - ok
20:38:40.0227 4016  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
20:38:40.0274 4016  ws2ifsl - ok
20:38:40.0289 4016  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\System32\wscsvc.dll
20:38:40.0320 4016  wscsvc - ok
20:38:40.0320 4016  WSearch - ok
20:38:40.0383 4016  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
20:38:40.0430 4016  wuauserv - ok
20:38:40.0461 4016  [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
20:38:40.0492 4016  WudfPf - ok
20:38:40.0508 4016  [ CF8D590BE3373029D57AF80914190682 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
20:38:40.0554 4016  WUDFRd - ok
20:38:40.0586 4016  [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
20:38:40.0617 4016  wudfsvc - ok
20:38:40.0632 4016  [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc        C:\Windows\System32\wwansvc.dll
20:38:40.0664 4016  WwanSvc - ok
20:38:40.0695 4016  [ 2EE48CFCE7CA8E0DB4C44C7476C0943B ] xusb21          C:\Windows\system32\DRIVERS\xusb21.sys
20:38:40.0726 4016  xusb21 - ok
20:38:40.0742 4016  ================ Scan global ===============================
20:38:40.0773 4016  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
20:38:40.0788 4016  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
20:38:40.0804 4016  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
20:38:40.0835 4016  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
20:38:40.0835 4016  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
20:38:40.0851 4016  [Global] - ok
20:38:40.0851 4016  ================ Scan MBR ==================================
20:38:40.0866 4016  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
20:38:41.0100 4016  \Device\Harddisk0\DR0 - ok
20:38:41.0100 4016  ================ Scan VBR ==================================
20:38:41.0100 4016  [ 27330CE5587F4B8384A5B4A8E3F8E1C0 ] \Device\Harddisk0\DR0\Partition1
20:38:41.0100 4016  \Device\Harddisk0\DR0\Partition1 - ok
20:38:41.0116 4016  [ C4083F17E9AE8CAE86A346D2A696522A ] \Device\Harddisk0\DR0\Partition2
20:38:41.0116 4016  \Device\Harddisk0\DR0\Partition2 - ok
20:38:41.0132 4016  [ 270C92CE01DB73430C4F6501D50BDB2E ] \Device\Harddisk0\DR0\Partition3
20:38:41.0132 4016  \Device\Harddisk0\DR0\Partition3 - ok
20:38:41.0132 4016  ============================================================
20:38:41.0132 4016  Scan finished
20:38:41.0132 4016  ============================================================
20:38:41.0147 5404  Detected object count: 5
20:38:41.0147 5404  Actual detected object count: 5
20:38:58.0619 5404  BEService ( UnsignedFile.Multi.Generic ) - skipped by user
20:38:58.0619 5404  BEService ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:38:58.0619 5404  OpenVPNService ( UnsignedFile.Multi.Generic ) - skipped by user
20:38:58.0619 5404  OpenVPNService ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:38:58.0619 5404  SwitchBoard ( UnsignedFile.Multi.Generic ) - skipped by user
20:38:58.0619 5404  SwitchBoard ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:38:58.0619 5404  VMAuthdService ( UnsignedFile.Multi.Generic ) - skipped by user
20:38:58.0619 5404  VMAuthdService ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:38:58.0619 5404  VMwareHostd ( UnsignedFile.Multi.Generic ) - skipped by user
20:38:58.0619 5404  VMwareHostd ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:39:02.0816 5468  Deinitialize success


markusg 18.02.2013 15:31

Hi,
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


ryuk 18.02.2013 15:51

Code:

ComboFix 13-02-18.01 - Root 18.02.2013  15:43:40.1.8 - x64
Microsoft Windows 7 Professional  6.1.7601.1.1252.49.1031.18.8174.5307 [GMT 1:00]
ausgeführt von:: c:\users\Root\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
FW: Kaspersky Internet Security *Disabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
SP: Kaspersky Internet Security *Disabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Root\AppData\Roaming\Microsoft\~DFK1aa9e2a.tmp
c:\users\Root\AppData\Roaming\Microsoft\1eaadjc.dll
c:\users\Root\AppData\Roaming\Microsoft\bass.dll
c:\users\Root\AppData\Roaming\Microsoft\engine_vx.dll
c:\users\Root\AppData\Roaming\Microsoft\kfgresk.dll
c:\users\Root\AppData\Roaming\Microsoft\peaadje.dll
c:\users\Root\AppData\Roaming\Microsoft\qwadjb.dll
c:\users\Root\AppData\Roaming\Microsoft\rsaadjd.dll
c:\windows\SysWow64\DEBUG.log
c:\windows\SysWow64\logs
c:\windows\SysWow64\logs\Game - R3d Logs\2012-05-02_12-06-47_r3dlog.txt
D:\install.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-01-18 bis 2013-02-18  ))))))))))))))))))))))))))))))
.
.
2013-02-17 17:52 . 2012-07-11 16:09        64856        ----a-w-        c:\windows\system32\klfphc.dll
2013-02-17 17:51 . 2013-02-17 17:51        --------        d-----w-        c:\windows\ELAMBKUP
2013-02-17 17:26 . 2013-02-17 17:26        --------        d-----w-        C:\_OTL
2013-02-16 23:11 . 2013-01-09 01:10        996352        ----a-w-        c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-16 23:11 . 2013-01-08 22:01        768000        ----a-w-        c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-16 19:14 . 2013-02-16 19:14        --------        d-----w-        c:\program files (x86)\Common Files\BattlEye
2013-02-16 18:34 . 2013-02-16 18:34        --------        d-----w-        c:\programdata\Bohemia Interactive Studio
2013-02-16 18:28 . 2013-02-16 18:28        --------        d-----w-        c:\program files (x86)\SIX Networks
2013-02-16 18:28 . 2013-01-08 05:32        9161176        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{67B08B11-C400-420D-B765-C8F02F90236C}\mpengine.dll
2013-02-15 19:09 . 2013-02-15 19:09        --------        d-----w-        c:\users\Root\AppData\Roaming\DivX
2013-02-15 13:13 . 2013-02-16 20:54        --------        d-----w-        c:\users\Root\AppData\Roaming\ftblauncher
2013-02-10 18:23 . 2013-02-16 18:21        --------        d-----w-        c:\users\Root\AppData\Roaming\ts3overlay
2013-02-09 13:21 . 2013-02-09 13:21        --------        d-----w-        c:\users\Root\AppData\Local\DDMSettings
2013-02-09 13:20 . 2013-02-09 13:20        --------        d-----w-        c:\program files\DivX
2013-02-09 13:20 . 2013-02-09 13:20        --------        d-----w-        c:\program files (x86)\Common Files\DivX Shared
2013-02-09 13:18 . 2013-02-09 13:20        --------        d-----w-        c:\program files (x86)\DivX
2013-02-09 13:17 . 2013-02-09 13:20        --------        d-----w-        c:\programdata\DivX
2013-02-09 13:14 . 2013-02-09 13:14        --------        d-----w-        c:\program files (x86)\Xvid
2013-02-09 13:14 . 2011-05-30 13:42        240640        ----a-w-        c:\windows\SysWow64\xvidvfw.dll
2013-02-09 13:14 . 2011-05-30 13:42        255488        ----a-w-        c:\windows\system32\xvidvfw.dll
2013-02-09 13:14 . 2011-05-23 09:52        153088        ----a-w-        c:\windows\SysWow64\xvid.ax
2013-02-09 13:14 . 2011-05-23 07:49        173568        ----a-w-        c:\windows\system32\xvid.ax
2013-02-09 13:14 . 2011-05-23 07:46        645632        ----a-w-        c:\windows\SysWow64\xvidcore.dll
2013-02-09 13:14 . 2011-05-23 07:45        696832        ----a-w-        c:\windows\system32\xvidcore.dll
2013-02-04 14:56 . 2013-02-04 14:56        --------        d-----w-        c:\program files (x86)\0xRH
2013-02-02 23:43 . 2013-02-02 23:43        --------        d-----w-        c:\program files (x86)\PWUnmask
2013-01-28 19:53 . 2013-01-28 19:53        --------        d-----w-        c:\users\Root\AppData\Roaming\tor
2013-01-28 19:53 . 2013-01-28 19:53        --------        d-----w-        c:\users\Root\AppData\Roaming\Vidalia
2013-01-19 21:45 . 2013-01-20 14:41        --------        d-----w-        c:\users\Root\AppData\Local\kJKxc2SrE2J0FNouaB
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-17 18:20 . 2012-06-08 10:38        54104        ----a-w-        c:\windows\system32\drivers\kltdi.sys
2013-02-17 18:20 . 2012-10-25 11:42        613720        ----a-w-        c:\windows\system32\drivers\klif.sys
2013-02-17 01:54 . 2012-11-25 19:48        70004024        ----a-w-        c:\windows\system32\MRT.exe
2013-02-09 11:14 . 2012-04-16 12:15        697712        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-02-09 11:14 . 2012-03-09 19:32        74096        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-17 00:28 . 2012-03-09 19:25        273840        ------w-        c:\windows\system32\MpSigStub.exe
2013-01-10 15:08 . 2009-07-14 02:36        175616        ----a-w-        c:\windows\system32\msclmd.dll
2013-01-10 15:08 . 2009-07-14 02:36        152576        ----a-w-        c:\windows\SysWow64\msclmd.dll
2013-01-08 20:53 . 2012-08-30 20:14        188064        ----a-w-        c:\programdata\Microsoft\VCSExpress\10.0\1033\ResourceCache.dll
2013-01-08 20:53 . 2012-03-29 17:13        191456        ----a-w-        c:\programdata\Microsoft\VCSExpress\10.0\1031\ResourceCache.dll
2013-01-08 20:53 . 2012-04-10 22:10        113440        ----a-w-        c:\programdata\Microsoft\VCExpress\10.0\1031\ResourceCache.dll
2013-01-08 20:52 . 2012-03-30 09:12        207008        ----a-w-        c:\programdata\Microsoft\VBExpress\10.0\1031\ResourceCache.dll
2013-01-08 17:08 . 2009-08-18 11:49        564632        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2013-01-08 17:08 . 2009-08-18 10:24        19696        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-01-04 04:43 . 2013-02-16 18:29        44032        ----a-w-        c:\windows\apppatch\acwow64.dll
2012-12-16 17:11 . 2013-01-08 20:47        46080        ----a-w-        c:\windows\system32\atmlib.dll
2012-12-16 14:45 . 2013-01-08 20:47        367616        ----a-w-        c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2013-01-08 20:47        295424        ----a-w-        c:\windows\SysWow64\atmfd.dll
2012-12-16 14:13 . 2013-01-08 20:47        34304        ----a-w-        c:\windows\SysWow64\atmlib.dll
2012-12-06 18:35 . 2012-12-06 18:35        95208        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-12-06 18:34 . 2012-12-06 18:35        821736        ----a-w-        c:\windows\SysWow64\npDeployJava1.dll
2012-12-06 18:34 . 2012-03-10 11:58        746984        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-12-02 17:05 . 2012-03-17 18:15        281520        ----a-w-        c:\windows\SysWow64\PnkBstrB.xtr
2012-12-02 17:05 . 2012-03-16 19:06        281520        ----a-w-        c:\windows\SysWow64\PnkBstrB.exe
2012-12-02 17:04 . 2012-03-16 19:06        280904        ----a-w-        c:\windows\SysWow64\PnkBstrB.ex0
2012-11-28 14:05 . 2012-03-16 19:06        76888        ----a-w-        c:\windows\SysWow64\PnkBstrA.exe
2012-11-23 03:13 . 2013-01-11 13:03        68608        ----a-w-        c:\windows\system32\taskhost.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{6e47d688-85ec-465a-9946-ec58220f14fc}]
2012-09-24 22:12        89288        ----a-w-        c:\progra~2\BEARSH~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{B939CF93-F2CB-443d-956C-DC523D85C9DB}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{6e47d688-85ec-465a-9946-ec58220f14fc}"= "c:\progra~2\BEARSH~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll" [2012-09-24 89288]
.
[HKEY_CLASSES_ROOT\clsid\{6e47d688-85ec-465a-9946-ec58220f14fc}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2012-11-30 1263512]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" [2013-02-17 356376]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\BEARSH~1\Mediabar\Datamngr\datamngr.dll c:\progra~2\BEARSH~1\Mediabar\Datamngr\IEBHO.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer8"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe [2013-02-16 49152]
R3 dump_wmimmc;dump_wmimmc;c:\program files\gPotato.eu\Rappelz\GameGuard\dump_wmimmc.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-24 16008]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-04-25 52736]
R3 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2012-01-18 11839488]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 116336]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2012-08-02 28504]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys [2013-02-17 54104]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys [2012-08-13 178008]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-10-19 375728]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\rainfo.sys [2012-08-24 15928]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-29 846448]
S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x]
S3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys [2012-10-08 31968]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2012-07-03 66728]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys [2012-10-25 29016]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2012-10-25 29528]
S3 LADF_CaptureOnly;LADF Capture Filter Driver;c:\windows\system32\DRIVERS\ladfGSCamd64.sys [2011-04-11 410184]
S3 LADF_RenderOnly;LADF Render Filter Driver;c:\windows\system32\DRIVERS\ladfGSRamd64.sys [2011-04-11 341832]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-24 22408]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-04-22 471144]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-02-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-16 11:14]
.
2012-12-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2467767842-2809315797-3914323744-1000Core.job
- c:\users\Root\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-01 19:42]
.
2012-12-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2467767842-2809315797-3914323744-1000UA.job
- c:\users\Root\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-01 19:42]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\BEARSH~1\Mediabar\Datamngr\x64\datamngr.dll c:\progra~2\BEARSH~1\Mediabar\Datamngr\x64\IEBHO.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Hinzufügen zu Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe
LSP: %SystemRoot%\system32\vsocklib.dll
Trusted Zone: samsungsetup.com\www
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Root\AppData\Roaming\Mozilla\Firefox\Profiles\02ptezpp.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-HijackThis - c:\users\Root\AppData\Local\Opera\Opera\temporary_downloads\HijackThis.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2467767842-2809315797-3914323744-1000\Software\SecuROM\License information*]
"datasecu"=hex:ae,1f,37,9b,d1,6a,71,e7,bd,94,95,7e,95,13,f1,7a,c9,55,4c,8e,89,
  02,97,25,ca,66,a8,b6,fa,ff,cc,35,8e,93,82,40,b8,b5,df,ef,0a,d5,e6,00,b1,c4,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-02-18  15:51:02
ComboFix-quarantined-files.txt  2013-02-18 14:51
.
Vor Suchlauf: 18 Verzeichnis(se), 219.144.671.232 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 218.994.323.456 Bytes frei
.
- - End Of File - - 32A4CFB066AF7D4655D72796F6BB4A62


markusg 18.02.2013 16:01

Hi,
malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.

ryuk 18.02.2013 16:32

Code:

Malwarebytes Anti-Malware 1.70.0.1100
Malwarebytes : Free anti-malware download

Datenbank Version: v2013.02.18.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Root :: SYSTEMROOT [Administrator]

18.02.2013 16:28:39
MBAM-log-2013-02-18 (16-30-55).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 263948
Laufzeit: 1 Minute(n), 41 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\Root\Desktop\OperaPassView.exe (PUP.OperaPasswordTool) -> Keine Aktion durchgeführt.
C:\Users\Root\Desktop\Winject.exe (HackTool.Agent.H) -> Keine Aktion durchgeführt.

(Ende)

Ich bin mir sicher, dass diese 2 gefundenen Dateien keine Viren sind, deswegen habe ich diese nicht entfernt :/.

markusg 18.02.2013 17:01

ich wollte einen vollständigen scan.
bitte noch mal updaten und ausführen

ryuk 18.02.2013 18:52

sorry, habe ich ganz überlesen. hier nochmal der vollständige scan:
Code:

Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Datenbank Version: v2013.02.18.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Root :: SYSTEMROOT [Administrator]

18.02.2013 17:08:41
mbam-log-2013-02-18 (17-08-41).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 967266
Laufzeit: 1 Stunde(n), 39 Minute(n), 1 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 8
C:\Users\Root\Desktop\OperaPassView.exe (PUP.OperaPasswordTool) -> Keine Aktion durchgeführt.
C:\Users\Root\Desktop\Winject.exe (HackTool.Agent.H) -> Keine Aktion durchgeführt.
C:\Users\Root\Desktop\WPE\WPE PRO - modified.exe (HackTool.Sniffer.WpePro) -> Keine Aktion durchgeführt.
C:\Users\Root\Desktop\WPE\WpeSpy.dll (HackTool.Sniffer.WpePro) -> Keine Aktion durchgeführt.
D:\Riot Games\League of Legends\rads\solutions\lol_game_client_sln\releases\0.0.0.212\deploy\Winject.exe (HackTool.Agent.H) -> Keine Aktion durchgeführt.
D:\Riot Games\League of Legends - Kopie\rads\solutions\lol_game_client_sln\releases\0.0.0.154\deploy\Winject.exe (HackTool.Agent.H) -> Keine Aktion durchgeführt.
D:\Riot Games\PBE\rads\solutions\lol_game_client_sln\releases\0.0.1.6\deploy\Winject.exe (HackTool.Agent.H) -> Keine Aktion durchgeführt.
D:\Steam\SteamApps\common\the binding of isaac\TDU.exe (Packer.ModifiedUPX) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

diese TDU exe war mir unbekannt, deswegen habe ich die gelöscht und bin gerade dabei das spiel neu von steam zu downloaden :o

markusg 18.02.2013 18:53

Hi,
könnte n Falschalarm gewesen sein.
lade den CCleaner standard:
CCleaner - Download - Filepony
falls der CCleaner
bereits instaliert, überspringen.
öffnen, Tools (extras),uninstall Llist, als txt speichern. öffnen.
hinter, jedes von dir benötigte programm, schreibe notwendig.
hinter, jedes, von dir nicht benötigte, unnötig.
hinter, dir unbekannte, unbekannt.
liste posten.

ryuk 18.02.2013 19:10

Code:

3ivx MPEG-4 5.0.4 (remove only)        3ivx Technologies, Pty. Ltd.        10.06.2012                5.0.4 unbekannt
4Story DE 3.9.154                11.08.2012        2.37GB        nötog
Adobe After Effects CS5.5        Adobe Systems Incorporated        21.03.2012        2.56GB        10.5.1 nötig
Adobe After Effects CS5.5 Third Party Content        Adobe Systems Incorporated        31.07.2012        213MB        10.5.1 nözig
Adobe AIR        Adobe Systems Incorporated        21.03.2012                3.1.0.4880 unbekannt
Adobe Community Help        Adobe Systems Incorporated.        21.03.2012                3.4.980 unbekannt
Adobe Download Assistant        Adobe Systems Incorporated        21.03.2012                1.0.6 unbekannt
Adobe Flash Player 11 ActiveX        Adobe Systems Incorporated        08.10.2012        6.00MB        11.4.402.287 nötig
Adobe Flash Player 11 Plugin        Adobe Systems Incorporated        09.02.2013        6.00MB        11.5.502.149 nötig
Adobe Media Player        Adobe Systems Incorporated        31.07.2012                1.8 unbekannt
Adobe Photoshop CS5        Adobe Systems Incorporated        31.07.2012        2.92GB        12.0 unnötig
Adobe Photoshop CS5.1        Adobe Systems Incorporated        24.03.2012        2.96GB        12.1 nötig
Adobe Reader X (10.1.3) - Deutsch        Adobe Systems Incorporated        17.04.2012        121MB        10.1.3 unbekannt
Adobe Story        Adobe Systems Incorporated        21.03.2012                1.0.571 unbekannt
ANNO 1503 Königs- Edition                27.08.2012                3.05.042.00 nötig
APB Reloaded                20.08.2012                1.4.1.587574 nötog
Apple Application Support        Apple Inc.        03.01.2013        65.0MB        2.3 unbekannt
Apple Mobile Device Support        Apple Inc.        03.09.2012        24.9MB        5.2.0.6 unbekannt
Apple Software Update        Apple Inc.        23.03.2012        2.38MB        2.1.3.127 unbekannt
aTube Catcher        DsNET Corp        03.01.2013                2.9.1347 nötig
Audiograbber 1.83 SE        Audiograbber        03.07.2012                1.83 SE nötig
Audiograbber MP3-Plugin (64 bit)        AG        03.07.2012                1.0 nötig
AutoHotkey 1.0.48.05        Chris Mallett        05.10.2012                1.0.48.05 nötig
AutoIt v3.3.8.1        AutoIt Team        06.05.2012                nötig
AviSynth 2.5                14.11.2012                unbekannt
Battlefield 3™        Electronic Arts        27.11.2012                1.4.0.0 nötig
Battlelog Web Plugins        EA Digital Illusions CE AB        27.11.2012                2.1.2 nötig
BattlEye for OA Uninstall                16.02.2013                unbekannt (?, bin mir nicht sicher, ob das jetzt nur BE ist oder was genau das bewirk)
Bonjour        Apple Inc.        03.09.2012        2.04MB        3.0.0.10 unbekannt
CamStudio                31.05.2012        nötig       
Camtasia Studio 8        TechSmith Corporation        05.10.2012        209MB        8.0.2.964 nötig
CCleaner        Piriform        25.11.2012                3.25 nötig
Cheat Engine 6.1        Dark Byte        24.03.2012        23.5MB        unnötig
Cheat Engine 6.2        Dark Byte        11.11.2012        27.0MB        nötig
Citron 2.5        ClickTwice Software        07.10.2012        8.85MB        unnötig
ControlSpy        Microsoft        10.05.2012        1.66MB        1.0.0 unbekannt
Crysis®3 MP Alpha        Electronic Arts        02.11.2012        2.45GB        1.0.0.0 nötig
Dark Souls: Prepare to Die Edition                07.01.2013                nötig
DayZ Commander        Dotjosh Studios        16.09.2012        3.50MB        0.9.84 unnötig
Detours Express 3.0        Microsoft Research        11.04.2012        2.62MB        1.0.000 unnötig
Deus Ex: Human Revolution        Eidos Montreal        22.11.2012                nötig
Dev-C++ 5 beta 9 release (4.9.9.2)                10.04.2012                unbekannt
DivX-Setup        DivX, LLC        09.02.2013                2.6.1.22 unbekannt
DriverTuner 3.1.0.0        LionSea SoftWare        09.03.2012        24.7MB        3.1.0.0 unbekannt
Eets        Klei Entertainment        30.01.2013                nötig
ESN Sonar        ESN Social Software AB        27.11.2012                0.70.4 unbekannt
Flare 0.6        Igor Kogan        24.09.2012                0.6 nötig
Flyff        Gala Networks Europe Limited        30.01.2013                Flyff  nötig
Fraps (remove only)                31.05.2012                unnötig
Free FLV Converter V 7.4.0        Koyote Soft        10.06.2012        17.5MB        7.4.0.0 unnötig
Free Video Dub version 2.0.8.504        DVDVideoSoft Ltd.        09.06.2012        65.6MB        2.0.8.504 unnötig
Game Booster 3        IObit        17.04.2012        15.7MB        3.3.1 unnötig
GamersFirst LIVE!        GamersFirst        14.07.2012                nötig
GameSpy Comrade        GameSpy        16.03.2012        5.95MB        2.1.1.214 nötig
GhostMouse        AutomaticSolution Software        06.04.2012        1.44MB        Free V3.1 nötig
glu 1.0.22        steelspace        07.10.2012                1.0.22 unnötog
Google Chrome        Google Inc.        10.05.2012                23.0.1271.95 nötig
GraphicsGale FreeEdition version 1.93.20        HUMANBALANCE Co.,Ltd.        04.07.2012        4.13MB        unbekannt
Hex-Editor MX        NEXT-Soft        26.09.2012                6.0 nötig
HijackThis 2.0.2        TrendMicro        17.02.2013                2.0.2 unnötig
ICQ7M        ICQ        30.11.2012                7.8 nötig
iFunbox (v2.1.2228.731), iFunbox DevTeam                13.01.2013        40.6MB        v2.1.2228.731 unnötig
iTunes        Apple Inc.        03.09.2012        184MB        10.6.3.25 leider nötig
Java 7 Update 9        Oracle        06.12.2012        128MB        7.0.90 unbekannt
Java(TM) 6 Update 22        Oracle        20.04.2012        97.0MB        6.0.220unbekannt
Java(TM) 6 Update 31        Oracle        10.03.2012        97.2MB        6.0.310unbekannt
Java(TM) 7 Update 4 (64-bit)        Oracle        27.05.2012        95.0MB        7.0.40unbekannt
Kaspersky Internet Security 2013        Kaspersky Lab        17.02.2013                13.0.1.4190 nötig
LAV Filters 0.50.5        Hendrik Leppkes        10.06.2012        11.4MB        0.50.5 unbekannt
League of Legends        Riot Games        09.03.2012                1.02.0000 nötig
Logitech Gaming Software 8.35        Logitech Inc.        06.11.2012        81.2MB        8.35.18 nötig
LogMeIn        LogMeIn, Inc.        25.10.2012        49.1MB        4.1.2600 nötig
LogMeIn Hamachi        LogMeIn, Inc.        12.12.2012                2.1.0.294 nötig
LOLReplay        www.leaguereplays.com        07.04.2012                0.7.6.7 nötig
Malwarebytes Anti-Malware Version 1.70.0.1100        Malwarebytes Corporation        18.02.2013        18.4MB        1.70.0.1100 nötig
Microsoft .NET Framework 4 Client Profile        Microsoft Corporation        10.03.2012        38.8MB        4.0.30319 .NET Framework 4 ist nötig, nur weiß ich davon nicht, was dies ist.
Microsoft .NET Framework 4 Client Profile DEU Language Pack        Microsoft Corporation        10.03.2012        2.93MB        4.0.30319 unbekannt
Microsoft .NET Framework 4 Extended        Microsoft Corporation        10.03.2012        51.9MB        4.0.30319 unbekanntunbekannt
Microsoft .NET Framework 4 Extended DEU Language Pack        Microsoft Corporation        10.03.2012        10.6MB        4.0.30319unbekannt
Microsoft .NET Framework 4 Multi-Targeting Pack        Microsoft Corporation        29.03.2012        83.4MB        4.0.30319unbekannt
Microsoft DirectX SDK (June 2010)        Microsoft Corporation        17.09.2012                9.29.1962.0 nötig
Microsoft Games for Windows - LIVE Redistributable        Microsoft Corporation        08.01.2013        31.3MB        3.5.92.0 nötig
Microsoft Games for Windows Marketplace        Microsoft Corporation        08.01.2013        6.03MB        3.5.50.0 nötig
Microsoft Help Viewer 1.0        Microsoft Corporation        29.03.2012        3.97MB        1.0.30319 unbekannt
Microsoft Help Viewer 1.0 Language Pack - DEU        Microsoft Corporation        29.03.2012        1.95MB        1.0.30319 unbekannt
Microsoft Silverlight        Microsoft Corporation        25.11.2012        34.6MB        4.1.10329.0 unbekannt
Microsoft SQL Server 2008 R2 Management Objects        Microsoft Corporation        30.08.2012        5.89MB        10.50.1447.4 unbekannt
Microsoft SQL Server Compact 3.5 SP2 DEU        Microsoft Corporation        29.03.2012        3.69MB        3.5.8080.0 unbekannt
Microsoft SQL Server Compact 3.5 SP2 ENU        Microsoft Corporation        30.08.2012        3.38MB        3.5.8080.0 unbekannt
Microsoft SQL Server Compact 3.5 SP2 x64 DEU        Microsoft Corporation        29.03.2012        4.81MB        3.5.8080.0 unbekannt
Microsoft SQL Server Compact 3.5 SP2 x64 ENU        Microsoft Corporation        30.08.2012        4.50MB        3.5.8080.0 unbekannt
Microsoft SQL Server System CLR Types        Microsoft Corporation        30.08.2012        625KB        10.50.1447.4 unbekannt
Microsoft Team Foundation Server 2010-Objektmodell - DEU        Microsoft Corporation        10.05.2012                10.0.30319
Microsoft Visual Basic 2010 Express - DEU        Microsoft Corporation        08.01.2013                10.0.30319 nötig
Microsoft Visual C# 2010 Express - DEU        Microsoft Corporation        08.01.2013                10.0.30319 nötig
Microsoft Visual C# 2010 Express - ENU        Microsoft Corporation        08.01.2013                10.0.30319 2. mal vorhanden :o
Microsoft Visual C++ 2005 Redistributable        Microsoft Corporation        01.06.2012        298KB        8.0.59193 nötig
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022        Microsoft Corporation        08.04.2012        1.42MB        9.0.21022 unbekannt
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17        Microsoft Corporation        09.03.2012        788KB        9.0.30729 unbekannt
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148        Microsoft Corporation        17.04.2012        788KB        9.0.30729.4148 unbekannt
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161        Microsoft Corporation        01.06.2012        788KB        9.0.30729.6161 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022        Microsoft Corporation        30.03.2012        2.86MB        9.0.21022 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17        Microsoft Corporation        11.03.2012        596KB        9.0.30729 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148        Microsoft Corporation        17.04.2012        226KB        9.0.30729.4148 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974        Microsoft Corporation        29.03.2012        599KB        9.0.30729.4974 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161        Microsoft Corporation        01.06.2012        600KB        9.0.30729.6161 unbekannt
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219        Microsoft Corporation        17.09.2012        13.8MB        10.0.40219 unbekannt
Microsoft Visual C++ 2010  x64 Runtime - 10.0.30319        Microsoft Corporation        01.06.2012        20.2MB        10.0.30319 unbekannt
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219        Microsoft Corporation        17.09.2012        11.1MB        10.0.40219 unbekannt
Microsoft Visual C++ 2010  x86 Runtime - 10.0.30319        Microsoft Corporation        01.06.2012        15.7MB        10.0.30319 unbekannt
Microsoft Visual C++ 2010 Express - DEU        Microsoft Corporation        10.04.2012                10.0.30319 nötig
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools        Microsoft Corporation        29.03.2012        35.2MB        10.0.30319 unbekannt
Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU        Microsoft Corporation        29.03.2012        4.31MB        10.0.30319 unbekannt
Microsoft Visual Studio Macro Tools        Microsoft Corporation        10.05.2012                9.0.30729 unbekannt
Microsoft Visual Studio Macro Tools - DEU Language Pack        Microsoft Corporation        10.05.2012                9.0.30729 unbekannt
Microsoft XNA Framework Redistributable 3.1        Microsoft Corporation        25.03.2012        7.48MB        3.1.10527.0 unnötig
Microsoft XNA Framework Redistributable 4.0        Microsoft Corporation        24.03.2012        8.03MB        4.0.20823.0 unnötog
Microsoft XNA Game Studio 4.0        Microsoft Corporation        30.08.2012                4.0.20823.0 unnötig
Microsoft XNA Game Studio Platform Tools        Microsoft Corporation        30.08.2012        14.1MB        1.3.0.0
Mozilla Firefox 17.0.1 (x86 de)        Mozilla        06.12.2012        41.0MB        17.0.1unnötig
Mozilla Maintenance Service        Mozilla        06.12.2012        329KB        17.0.1 unnötig
MSXML 4.0 SP2 (KB954430)        Microsoft Corporation        12.03.2012        1.27MB        4.20.9870.0 unbekannt
MSXML 4.0 SP2 (KB973688)        Microsoft Corporation        12.03.2012        1.33MB        4.20.9876.0 unbekannt
MySQL-Front                09.11.2012        12.6MB        5.3 unbekannt
Nero 9 Essentials        Nero AG        09.03.2012                nötig
No23 Recorder        No23        03.07.2012                2.1.0.3 unnötig
Notepad++                03.06.2012                6.1.3 nötig
NVIDIA 3D Vision Controller-Treiber 306.97        NVIDIA Corporation        13.11.2012                306.97 nötig
NVIDIA 3D Vision Treiber 306.97        NVIDIA Corporation        13.11.2012                306.97 nötig
NVIDIA Grafiktreiber 306.97        NVIDIA Corporation        13.11.2012                306.97nötig
NVIDIA HD-Audiotreiber 1.3.18.0        NVIDIA Corporation        13.11.2012                1.3.18.0nötig
NVIDIA PhysX        NVIDIA Corporation        20.10.2012        111MB        9.12.0613nötig
NVIDIA Update 1.10.8        NVIDIA Corporation        13.11.2012                1.10.8nötig
OnlineControl 1.2        Deutsche Telekom AG T-Com        20.12.2012                1.2.23 nötig
OpenAL                30.03.2012                unbekannt
OpenOffice.org 3.3        OpenOffice.org        20.04.2012        374MB        3.3.9567 nötig
OpenVPN 2.2.2                22.11.2012                2.2.2 nötig
Opera 12.11        Opera Software ASA        21.11.2012                12.11.1661 nötog
Origin        Electronic Arts, Inc.        01.10.2012                9.0.13.2142nötig
Pando Media Booster        Pando Networks Inc.        09.03.2012        5.46MB        2.6.0.6nötig
Password Unmask 2.0                03.02.2013                nötig
PE Explorer 1.99 R6        Heaventools Software        10.05.2012                1.99.6 nötig
Pidgin                07.10.2012                2.10.6 nötig
Play withSIX        SIX Networks        16.02.2013        14.8MB        1.20.0330 nötig
Pokemon Game Editor        0xRH        04.02.2013        1.93MB        1.0.0.0 nötig
ProxySwitcher Standard        V-Tech LLC        16.12.2012        9.23MB        5.6.1 unnötig
Psi (remove only)                07.10.2012                unbekannt
PSP Video 9 6        Red Kawa        14.11.2012                6 unbekannt
PunkBuster Services        Even Balance, Inc.        27.11.2012                0.991 nötig
QuickTime        Apple Inc.        03.01.2013        73.1MB        7.73.80.64nötig
Rainmeter                10.09.2012                2.3.3 r1522 unnötig
Rappelz        gPotato.eu        13.10.2012                Rappelz nötig
Realtek Ethernet Controller Driver        Realtek        09.03.2012                7.44.421.2011 unbekannt
RPG MAKER VX Ace        Enterbrain        08.09.2012        44.5MB        1.01a nötig
RPG MAKER VX Ace RTP        Enterbrain        08.09.2012        194MB        1.00 nötig
Sacred Underworld        Ascaron Entertainment GmbH        17.04.2012        nötig       
Schriftenbibliothek                22.12.2012        574MB        unbekannt
SciTE4AutoIt3 12/29/2011        Jos van der Zande        06.05.2012                12/29/2011 nötig
Screen Recording Suite V2.5.0        Apowersoft        05.12.2012        76.5MB        2.5.0 nötig
Search-Results Toolbar        APN LLC        02.10.2012                1.0.0.12 unnötig
SecurityKISS Tunnel v0.2.2                03.07.2012        8.61MB        unbekannt
ShiftWindow 1.02        Grismar        27.07.2012                nötig
Skype™ 5.10        Skype Technologies S.A.        08.01.2013        19.3MB        5.10.116 nötig
Sonarca Sound Recorder Free 3.8.3        Accmeware Corporation        03.07.2012        2.11MB unbekannt       
SpongeBob SquarePants Employee of the Month                29.08.2012                nötig
SPORE™        Electronic Arts        15.09.2012                1.02.0000nötig
SPORE™ Süß & Schrecklich Ergänzungs-Pack        Electronic Arts        15.09.2012                1.00.0000 nötig
StarCraft II        Blizzard Entertainment        03.10.2012                1.5.3.23260 nötig
Steam        Valve Corporation        09.03.2012        35.4MB        1.0.0.0 nötig
Steganos Password Manager 2012        Steganos Software GmbH        10.12.2012                13.0.2 unnötig
SWF Scanner                24.09.2012                unbekannt
TeamSpeak 3 Client        TeamSpeak Systems GmbH        26.12.2012                3.0.9.2 nötig
Techne        ZeuX and r4wk        10.03.2012                1.3.0.15 nötig
TERA        Frogster Online Gaming GmbH        13.03.2012        39.4MB        16.04 nötig
Total War: SHOGUN 2        The Creative Assembly        23.11.2012                nötig
Vegas Pro 11.0        Sony        09.06.2012        423MB        11.0.682 nötig
Virtual Audio Cable 4.10                03.07.2012                nötig
Visual Studio 2010 Prerequisites - English        Microsoft Corporation        10.05.2012        5.87MB        10.0.30319 unbekannt
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU        Microsoft Corporation        29.03.2012        11.1MB        4.0.8080.0 unbekannt
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU        Microsoft Corporation        30.08.2012        10.7MB        4.0.8080.0 unbekannt
VLC media player 2.0.0        VideoLAN        15.03.2012                2.0.0 nötig
VMware Workstation        VMware, Inc        17.04.2012        3.25GB        8.0.2.28060 nötig
VoiceOver Kit        Apple Inc.        31.12.2012        41.7MB        1.42.128.0 unbekannt
Warmux                09.09.2012                11.04 nötig
Windows Live ID Sign-in Assistant        Microsoft Corporation        08.01.2013        10.0MB        6.500.3165.0 nötig
WinRAR 4.11 (64-bit)        win.rar GmbH        01.06.2012                4.11.0nötig
Winspector        GipsySoft.com        23.05.2012                unbekannt
Wireshark 1.6.6        The Wireshark developer community, hxxp://www.wireshark.org        04.04.2012                1.6.6 unnötig
World of Tanks        Wargaming.net        20.05.2012        15.0MB        nötig
World of Warcraft        Blizzard Entertainment        21.04.2012                4.3.4.15595nötig
WorldPainter 0.8.7        pepsoft.org        02.06.2012                0.8.7 nötig
Xvid Video Codec        Xvid Team        09.02.2013                1.3.2 nötig
µTorrent        BitTorrent Inc.        02.11.2012                3.2.1.28086 nötig


markusg 18.02.2013 19:17

deinstaliere:
3ivx
Adobe Media
Adobe Reader
Adobe Flash Player alle
Adobe - Adobe Flash Player installieren
neueste version laden, instalieren.
adobe reader:
Adobe - Adobe Reader herunterladen - Alle Versionen
haken bei mcafee security scan raus nehmen

bitte auch mal den adobe reader wie folgt konfigurieren:
adobe reader öffnen, bearbeiten, voreinstellungen.
allgemein:
nur zertifizierte zusatz module verwenden, anhaken.
Sicherheit (erweitert)
Erweiterte Sicherheit anhaken
und alle Dateien auswählen.
internet:
hier sollte alles deaktiviert werden, es ist sehr unsicher pdfs automatisch zu öffnen, zu downloaden etc.
es ist immer besser diese direkt abzuspeichern da man nur so die kontrolle hat was auf dem pc vor geht.
bei javascript den haken bei java script verwenden raus nehmen
bei updater, automatisch instalieren wählen.
übernehmen /ok



deinstaliere:
Adobe Story
AviSynth
Citron
ControlSpy
DayZ
Detours
DivX
DriverTuner
ESN
Fraps
Free FLV
Free Video
Game
glu
HijackThis
iFunbox
Java : alle
downloade Java jre:
Java-Downloads für alle Betriebssysteme
klicke:
Download der Java-Software für Windows Offline
laden, und instalieren
deinstaliere:
No23
ProxySwitcher
Psi
PSP
Rainmeter
Search-Results
SecurityKISS
Sonarca
Steganos
SWF
Winspector
Wireshark

Öffne CCleaner, analysieren, starten, PC neustarten.
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

ryuk 18.02.2013 19:35

also 1. habe ich gerade festgestellt das Opera keine 2 Minuten zum starten gebraucht hat, scheinbar ist jetzt alles wieder gut. Danke für deine schnelle und kompetente Hilfe!
Hier ist noch der Log
Code:

# AdwCleaner v2.112 - Datei am 18/02/2013 um 19:30:26 erstellt
# Aktualisiert am 10/02/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzer : Root - SYSTEMROOT
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Root\Desktop\adwcleaner0.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\boost_interprocess
Ordner Gelöscht : C:\Users\Root\AppData\Local\Babylon
Ordner Gelöscht : C:\Users\Root\AppData\LocalLow\boost_interprocess
Ordner Gelöscht : C:\Users\Root\AppData\Roaming\Babylon

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\DataMngr
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Headlight
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\Software\PIP
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Search Results Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B37B4BA6-334E-72C1-B57E-6AFE8F8A5AF3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B77AD4AC-C1C2-B293-7737-71E13A11FFEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E773F2CF-5E6E-FF2B-81A1-AC581A26B2B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16464

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v17.0.1 (de)

Datei : C:\Users\Root\AppData\Roaming\Mozilla\Firefox\Profiles\02ptezpp.default\prefs.js

[OK] Die Datei ist sauber.

-\\ Google Chrome v23.0.1271.95

Datei : C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Preferences

Gelöscht [l.70] : search_url = "hxxp://dts.search-results.com/sr?src=crb&gct=ds&appid=343&systemid=2&apn_dtid=I[...]

-\\ Opera v12.11.1661.0

Datei : C:\Users\Root\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] Die Datei ist sauber.

*************************

AdwCleaner[S1].txt - [2645 octets] - [18/02/2013 19:30:26]

########## EOF - C:\AdwCleaner[S1].txt - [2705 octets] ##########


markusg 18.02.2013 19:54

Hi,
das is ja schon mal was.
Lade bitte Hitmanpro:
HitmanPro - Download - Filepony
Doppelklicken, Lizenz, Testlizenz.
Dann auf Scan, nichts löschen.
Auf weiter, Log als XML exportieren, und posten, bzw packen und anhängen.

ryuk 18.02.2013 20:12

also ich habe irgendwas falsch gemacht beim 1. versuch. das mit logdatei speichern habe ich zuerst nicht gefunden und einfach auf weiter gedrückt, da ich dachte das dieser knopf später kommt aber dann wurden alle gefärlichen dateien gelöscht :/.
hier ist die logdatei nach dem 2. anlauf
Code:

HitmanPro 3.7.2.188
www.hitmanpro.com

  Computer name . . . . : SYSTEMROOT
  Windows . . . . . . . : 6.1.1.7601.X64/8
  User name . . . . . . : Systemroot\Root
  UAC . . . . . . . . . : Disabled
  License . . . . . . . : Trial (30 days left)

  Scan date . . . . . . : 2013-02-18 20:05:18
  Scan mode . . . . . . : Normal
  Scan duration . . . . : 4m 5s
  Disk access mode  . . : Direct disk access (SRB)
  Cloud . . . . . . . . : Internet
  Reboot  . . . . . . . : No

  Threats . . . . . . . : 0
  Traces  . . . . . . . : 14

  Objects scanned . . . : 2.759.489
  Files scanned . . . . : 64.611
  Remnants scanned  . . : 1.511.863 files / 1.183.015 keys

Suspicious files ____________________________________________________________

  C:\Users\Root\AppData\Local\PunkBuster\APB\pb\pbcl.dll
      Size . . . . . . . : 953.905 bytes
      Age  . . . . . . . : 182.2 days (2012-08-20 15:40:05)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 9A5BDD44D0817FE21A154412B5989E157455BC24ADBCB238376F73FCEFB14696
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Root\AppData\Local\PunkBuster\APB\pb\PnkBstrK.sys
      Size . . . . . . . : 138.992 bytes
      Age  . . . . . . . : 182.2 days (2012-08-20 15:40:19)
      Entropy  . . . . . : 7.7
      SHA-256  . . . . . : 17E604316606C999C87C896508B3525E4897DFA1522FEE01B86524F46B3D9B3D
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Root\AppData\Local\PunkBuster\BF2\pb\pbcl.dll
      Size . . . . . . . : 910.029 bytes
      Age  . . . . . . . : 338.0 days (2012-03-17 19:19:08)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 03A037A66ECE5964E3F2915BC6C807D3A74F9F1160405FE1CF446ECE78887A69
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Root\AppData\Local\PunkBuster\BF2\pb\PnkBstrK.sys
      Size . . . . . . . : 138.520 bytes
      Age  . . . . . . . : 338.0 days (2012-03-17 19:15:51)
      Entropy  . . . . . : 7.7
      SHA-256  . . . . . : 787381760B879F39B06762B4AB4B7EB2D9C61FCCEF1C88769BF0C44B67AC1612
      RSA Key Size . . . : 1024
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Root\AppData\Local\PunkBuster\BF3\pb\dll\wc002317.dll
      Size . . . . . . . : 949.613 bytes
      Age  . . . . . . . : 82.2 days (2012-11-28 15:05:38)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 15059F09B1D62DEA6B5D22EF9E0D062411C167378D870AE339AAB50B0BDC7FC0
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Root\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
      Size . . . . . . . : 949.613 bytes
      Age  . . . . . . . : 78.1 days (2012-12-02 18:04:55)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 15059F09B1D62DEA6B5D22EF9E0D062411C167378D870AE339AAB50B0BDC7FC0
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Root\AppData\Local\PunkBuster\BF3\pb\pbclold.dll
      Size . . . . . . . : 949.613 bytes
      Age  . . . . . . . : 82.2 days (2012-11-28 15:05:12)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 15059F09B1D62DEA6B5D22EF9E0D062411C167378D870AE339AAB50B0BDC7FC0
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Root\AppData\Local\PunkBuster\BF3\pb\PnkBstrK.sys
      Size . . . . . . . : 139.328 bytes
      Age  . . . . . . . : 82.2 days (2012-11-28 15:05:27)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : F6552C37C04FD92554BD715F9E98B41E3D711C8AC37C757FBCFDDD69738FBE5E
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Root\AppData\Local\PunkBuster\COD4\pb\dll\wc002318.dll
      Size . . . . . . . : 967.165 bytes
      Age  . . . . . . . : 150.0 days (2012-09-21 19:58:36)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : B1B32990F47ED2E39EB18AEA0839D9521B87E9ED18C0BCA8E2C6873FBA9D6494
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Root\AppData\Local\PunkBuster\COD4\pb\pbcl.dll
      Size . . . . . . . : 967.165 bytes
      Age  . . . . . . . : 92.9 days (2012-11-17 22:01:47)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : B1B32990F47ED2E39EB18AEA0839D9521B87E9ED18C0BCA8E2C6873FBA9D6494
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Root\AppData\Local\PunkBuster\COD4\pb\pbclold.dll
      Size . . . . . . . : 967.165 bytes
      Age  . . . . . . . : 233.5 days (2012-06-30 09:04:27)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : B1B32990F47ED2E39EB18AEA0839D9521B87E9ED18C0BCA8E2C6873FBA9D6494
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Root\AppData\Local\PunkBuster\COD4\pb\pbcls.dll
      Size . . . . . . . : 967.213 bytes
      Age  . . . . . . . : 233.5 days (2012-06-30 09:04:27)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 4BD30C84D354E3B8B5236F48F62718D6E4F2A6DAA303365B6DFCE45D21DFE853
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Root\AppData\Local\PunkBuster\COD4\pb\PnkBstrK.sys
      Size . . . . . . . : 139.832 bytes
      Age  . . . . . . . : 233.5 days (2012-06-30 09:14:14)
      Entropy  . . . . . : 7.7
      SHA-256  . . . . . : 3CB5C8CB071375FDE6E9269000B78E65DB29D585B2775E66C8B9F6E47E0012D1
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.


Potential Unwanted Programs _________________________________________________

  HKU\S-1-5-21-2467767842-2809315797-3914323744-1005\Software\Datamngr\ (SearchQU)


markusg 18.02.2013 20:15

lösch mal noch den Fund:
HKU\S-1-5-21-2467767842-2809315797-3914323744-1005\Software\Datamngr
smit hitmanpro
starte neu,poste ein neues OTL log.
evtl. fehlen dir dann Dateien,falls es Fehlalarme beim Scan gab musst du mal nachprüfen und sie evtl. neu laden

poste mir ein neues otl log.

ryuk 18.02.2013 20:41

habe ein log nachdieser anleitung erstellt, http://www.trojaner-board.de/85104-o...-oldtimer.html
OLT
Code:

OTL logfile created on: 18.02.2013 20:25:07 - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Root\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7.98 Gb Total Physical Memory | 5.82 Gb Available Physical Memory | 72.93% Memory free
15.96 Gb Paging File | 13.84 Gb Available in Paging File | 86.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372.60 Gb Total Space | 205.29 Gb Free Space | 55.10% Space Free | Partition Type: NTFS
Drive D: | 540.23 Gb Total Space | 157.70 Gb Free Space | 29.19% Space Free | Partition Type: NTFS
Drive E: | 100.74 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: SYSTEMROOT | User Name: Root | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Users\Root\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Opera\opera.exe (Opera Software)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\IObit\Game Booster 3\gbtray.exe (IObit)
PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_168.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\Opera\gstreamer\gstreamer.dll ()
MOD - C:\Program Files (x86)\Opera\gstreamer\plugins\gstoggdec.dll ()
MOD - C:\Program Files (x86)\Opera\gstreamer\plugins\gstffmpegcolorspace.dll ()
MOD - C:\Program Files (x86)\Opera\gstreamer\plugins\gstwebmdec.dll ()
MOD - C:\Program Files (x86)\Opera\gstreamer\plugins\gstcoreplugins.dll ()
MOD - C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioresample.dll ()
MOD - C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioconvert.dll ()
MOD - C:\Program Files (x86)\Opera\gstreamer\plugins\gstwavparse.dll ()
MOD - C:\Program Files (x86)\Opera\gstreamer\plugins\gstdirectsound.dll ()
MOD - C:\Program Files (x86)\Opera\gstreamer\plugins\gstdecodebin2.dll ()
MOD - C:\Program Files (x86)\Opera\gstreamer\plugins\gstautodetect.dll ()
MOD - C:\Program Files (x86)\Opera\gstreamer\plugins\gstwaveform.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll ()
MOD - C:\Program Files (x86)\IObit\Game Booster 3\sqlite3.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AVP) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Kaspersky Lab ZAO)
SRV - (BEService) -- C:\Program Files (x86)\Common Files\BattlEye\BEService.exe ()
SRV - (Hamachi2Svc) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (VMware NAT Service) -- C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
SRV - (VMnetDHCP) -- C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMwareHostd) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe ()
SRV - (VMAuthdService) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (OpenVPNService) -- C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe ()
SRV - (VMUSBArbService) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe (VMware, Inc.)
SRV - (npggsvc) -- C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (dump_wmimmc) -- C:\Program Files\gPotato.eu\Rappelz\GameGuard\dump_wmimmc.sys File not found
DRV:64bit: - (kltdi) -- C:\Windows\SysNative\drivers\kltdi.sys (Kaspersky Lab)
DRV:64bit: - (KLIF) -- C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (klmouflt) -- C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (klkbdflt) -- C:\Windows\SysNative\drivers\klkbdflt.sys (Kaspersky Lab)
DRV:64bit: - (Apowersoft_AudioDevice) -- C:\Windows\SysNative\drivers\Apowersoft_AudioDevice.sys (Wondershare)
DRV:64bit: - (kneps) -- C:\Windows\SysNative\drivers\kneps.sys (Kaspersky Lab)
DRV:64bit: - (KLIM6) -- C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (EuMusDesignVirtualAudioCableWdm) -- C:\Windows\SysNative\drivers\vrtaucbl.sys (Eugene V. Muzychenko)
DRV:64bit: - (KL1) -- C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (vmx86) -- C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.)
DRV:64bit: - (VMnetuserif) -- C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.)
DRV:64bit: - (VMnetBridge) -- C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.)
DRV:64bit: - (VMnetAdapter) -- C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.)
DRV:64bit: - (tap0901) -- C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV:64bit: - (hcmon) -- C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.)
DRV:64bit: - (vmci) -- C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (LADF_RenderOnly) -- C:\Windows\SysNative\drivers\ladfGSRamd64.sys (Logitech)
DRV:64bit: - (LADF_CaptureOnly) -- C:\Windows\SysNative\drivers\ladfGSCamd64.sys (Logitech)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (LGVirHid) -- C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.)
DRV:64bit: - (LGBusEnum) -- C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.)
DRV:64bit: - (xusb21) -- C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (NPPTNT2) -- C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-2467767842-2809315797-3914323744-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2467767842-2809315797-3914323744-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-2467767842-2809315797-3914323744-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D0 5D 8C C3 0E 02 CD 01  [binary data]
IE - HKU\S-1-5-21-2467767842-2809315797-3914323744-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2467767842-2809315797-3914323744-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2467767842-2809315797-3914323744-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: %7B8f8fe09b-0bd3-4470-bc1b-8cad42b8203a%7D:0.17
FF - prefs.js..extensions.enabledAddons: %7Be968fc70-8f95-4ab9-9e79-304de2a71ee1%7D:0.7.3
FF - prefs.js..extensions.enabledAddons: %7B563e4790-7e70-11da-a72b-0800200c9a66%7D:0.9f
FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68
FF - prefs.js..extensions.enabledAddons: %7B99B98C2C-7274-45a3-A640-D9DF1A1C8460%7D:1.4
FF - prefs.js..extensions.enabledAddons: admin%40proxy-listen.de:1.0.4.5
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.7.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_168.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@gamersfirst.com/LiveLauncher: C:\Program Files (x86)\GamersFirst\LIVE!\nplivelauncher.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Root\AppData\Local\Google\Update\1.3.21.129\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Root\AppData\Local\Google\Update\1.3.21.129\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{00F0643E-B367-4779-B45D-7046EBA37A88}: C:\Program Files (x86)\Steganos Password Manager 2012\spmplugin3
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013.02.09 14:20:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\url_advisor@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013.02.17 19:20:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtual_keyboard@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013.02.17 19:20:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\content_blocker@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013.02.17 19:20:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\anti_banner@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013.02.17 19:20:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\online_banking@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013.02.17 19:20:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.03 14:30:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.02.18 19:25:41 | 000,000,000 | ---D | M]
 
[2012.10.17 15:54:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Root\AppData\Roaming\mozilla\Extensions
[2013.01.26 12:46:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Root\AppData\Roaming\mozilla\Firefox\Profiles\02ptezpp.default\extensions
[2012.10.17 15:57:44 | 000,000,000 | ---D | M] (Live HTTP Headers) -- C:\Users\Root\AppData\Roaming\mozilla\Firefox\Profiles\02ptezpp.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
[2012.12.16 13:20:02 | 000,013,955 | ---- | M] () (No name found) -- C:\Users\Root\AppData\Roaming\mozilla\firefox\profiles\02ptezpp.default\extensions\admin@proxy-listen.de.xpi
[2012.12.13 14:45:11 | 002,151,598 | ---- | M] () (No name found) -- C:\Users\Root\AppData\Roaming\mozilla\firefox\profiles\02ptezpp.default\extensions\firebug@software.joehewitt.com.xpi
[2012.12.14 14:46:50 | 000,010,707 | ---- | M] () (No name found) -- C:\Users\Root\AppData\Roaming\mozilla\firefox\profiles\02ptezpp.default\extensions\{563e4790-7e70-11da-a72b-0800200c9a66}.xpi
[2012.12.14 14:53:17 | 000,030,926 | ---- | M] () (No name found) -- C:\Users\Root\AppData\Roaming\mozilla\firefox\profiles\02ptezpp.default\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}.xpi
[2012.12.14 14:51:53 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\Root\AppData\Roaming\mozilla\firefox\profiles\02ptezpp.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
[2013.01.26 12:46:26 | 000,242,136 | ---- | M] () (No name found) -- C:\Users\Root\AppData\Roaming\mozilla\firefox\profiles\02ptezpp.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012.12.05 14:34:49 | 000,042,336 | ---- | M] () (No name found) -- C:\Users\Root\AppData\Roaming\mozilla\firefox\profiles\02ptezpp.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi
[2012.12.06 15:45:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.12.06 15:45:30 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.03.10 12:58:11 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.10.11 03:10:32 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.10.11 03:10:32 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.10.11 03:10:32 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.10.11 03:10:32 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.10.11 03:10:32 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.10.11 03:10:32 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - homepage: hxxp://search.bearshare.net
CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url =
CHR - homepage: hxxp://search.bearshare.net
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Root\AppData\Local\Google\Chrome\Application\23.0.1271.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Root\AppData\Local\Google\Chrome\Application\23.0.1271.95\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Root\AppData\Local\Google\Chrome\Application\23.0.1271.95\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Kaspersky Anti-Virus (Enabled) = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.0.374_0\plugin/npABPlugin.dll
CHR - plugin: Kaspersky Anti-Virus (Enabled) = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.0.477_0\plugin/npVKPlugin.dll
CHR - plugin: Kaspersky Anti-Virus (Enabled) = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.0.477_0\plugin/npUrlAdvisor.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - Extension: Media Hint = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\anepbdekljkmmimmhbniglnnanmmkoja\0.1.12_0\
CHR - Extension: YouTube = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google-Suche = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Modul zur Link-Untersuchung = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0\
CHR - Extension: Grooveshark Germany unlocker = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\docdgimmdejoiemdafcgeodchlbllgac\2.3.4_0\
CHR - Extension: Grooveshark Germany unlocker = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\docdgimmdejoiemdafcgeodchlbllgac\2.3.4_0\.orig
CHR - Extension: AdBlock = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.60_0\
CHR - Extension: Sicherer Zahlungsverkehr = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.1.4190_0\
CHR - Extension: Modul f\u00FCr das Blockieren gef\u00E4hrlicher Webseiten = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0\
CHR - Extension: Linkbucks skip = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjpndobkiolgpnpagkhnknhinnpoajmd\1.6_0\
CHR - Extension: HTTP Headers = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\hplfkkmefamockhligfdcfgfnbcdddbg\1.0.0.2_0\
CHR - Extension: Virtuelle Tastatur = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4190_0\
CHR - Extension: Linkbucks Bypass = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfjdbebcogpgoffmnpkbpelaindeedjn\1.1_0\
CHR - Extension: billiger.de Sparberater = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbifbkkajempdkfhlidjfmbfaoihageg\1.4.9_0\
CHR - Extension: Autofill = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmmgnhgdeffjkdckmikfpnddkbbfkkk\5.5_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Google Mail = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: Anti-Banner = C:\Users\Root\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0\
 
O1 HOSTS File: ([2013.02.18 15:49:38 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKU\S-1-5-21-2467767842-2809315797-3914323744-1005..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2467767842-2809315797-3914323744-1006..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2467767842-2809315797-3914323744-1005..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-2467767842-2809315797-3914323744-1006..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2467767842-2809315797-3914323744-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2467767842-2809315797-3914323744-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2467767842-2809315797-3914323744-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2467767842-2809315797-3914323744-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2467767842-2809315797-3914323744-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:64bit: - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm ()
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm ()
O9:64bit: - Extra Button: Virtuelle Tastatur - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: Links untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Virtuelle Tastatur - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Links untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2467767842-2809315797-3914323744-1000\..Trusted Domains: samsungsetup.com ([www] http in Vertrauenswürdige Sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1AE6F90E-32AB-46D3-ABA6-31FC2CE7A67C}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.10.01 01:18:53 | 000,000,047 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (bootdelete)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.02.18 20:04:28 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2013.02.18 19:55:42 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2013.02.18 19:33:22 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.02.18 19:27:36 | 000,310,688 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
[2013.02.18 19:27:30 | 000,188,832 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2013.02.18 19:27:30 | 000,188,320 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2013.02.18 19:27:30 | 000,108,448 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013.02.18 16:27:35 | 000,000,000 | ---D | C] -- C:\Users\Root\AppData\Roaming\Malwarebytes
[2013.02.18 16:27:27 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.02.18 16:27:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.02.18 16:27:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.02.18 16:27:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.02.18 15:41:52 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.02.18 15:41:52 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.02.18 15:41:52 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.02.18 15:41:48 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.02.18 15:41:37 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.02.18 15:40:39 | 005,033,910 | R--- | C] (Swearware) -- C:\Users\Root\Desktop\ComboFix.exe
[2013.02.17 20:36:13 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Root\Desktop\tdsskiller.exe
[2013.02.17 18:53:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2013
[2013.02.17 18:52:27 | 000,064,856 | ---- | C] (Kaspersky Lab) -- C:\Windows\SysNative\klfphc.dll
[2013.02.17 18:51:43 | 000,000,000 | ---D | C] -- C:\Windows\ELAMBKUP
[2013.02.17 18:26:34 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.02.17 12:47:23 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Root\Desktop\OTL.exe
[2013.02.17 00:10:38 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013.02.17 00:10:38 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013.02.17 00:10:37 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.02.17 00:10:37 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013.02.17 00:10:37 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013.02.17 00:10:37 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.02.17 00:10:37 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.02.17 00:10:37 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013.02.17 00:10:37 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013.02.17 00:10:37 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.02.17 00:10:37 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013.02.17 00:10:37 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013.02.17 00:10:36 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.02.17 00:10:36 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.02.17 00:10:36 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013.02.16 20:14:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\BattlEye
[2013.02.16 20:09:45 | 011,216,224 | ---- | C] (Igor Pavlov) -- C:\Users\Root\Desktop\ARMA2_OA_Build_101480.exe
[2013.02.16 19:35:05 | 000,000,000 | ---D | C] -- C:\Users\Root\Documents\BIS Core Engine Other Profiles
[2013.02.16 19:34:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Bohemia Interactive Studio
[2013.02.16 19:34:53 | 000,000,000 | ---D | C] -- C:\Users\Root\Documents\BIS Core Engine
[2013.02.16 19:30:51 | 005,553,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013.02.16 19:30:50 | 003,967,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2013.02.16 19:30:50 | 003,913,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2013.02.16 19:29:57 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2013.02.16 19:29:57 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2013.02.16 19:29:57 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2013.02.16 19:29:57 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2013.02.16 19:29:57 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2013.02.16 19:29:57 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2013.02.16 19:29:45 | 000,288,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013.02.16 19:29:07 | 000,000,000 | ---D | C] -- C:\Users\Root\AppData\Local\Play withSIX
[2013.02.16 19:28:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIX Networks
[2013.02.16 19:28:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SIX Networks
[2013.02.15 20:09:44 | 000,000,000 | ---D | C] -- C:\Users\Root\AppData\Roaming\DivX
[2013.02.15 14:13:48 | 000,000,000 | ---D | C] -- C:\Users\Root\Desktop\FTB
[2013.02.15 14:13:29 | 000,000,000 | ---D | C] -- C:\Users\Root\AppData\Roaming\ftblauncher
[2013.02.10 19:23:49 | 000,000,000 | ---D | C] -- C:\Users\Root\AppData\Roaming\ts3overlay_hook_win64
[2013.02.10 19:23:48 | 000,000,000 | ---D | C] -- C:\Users\Root\AppData\Roaming\ts3overlay
[2013.02.09 14:21:13 | 000,000,000 | ---D | C] -- C:\Users\Root\AppData\Local\DDMSettings
[2013.02.09 14:20:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
[2013.02.09 14:20:04 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2013.02.09 14:20:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DivX Shared
[2013.02.09 14:18:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX
[2013.02.09 14:17:26 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2013.02.09 14:14:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
[2013.02.09 14:14:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xvid
[2013.02.06 15:46:50 | 000,000,000 | ---D | C] -- C:\Users\Root\Desktop\VariableTriggers
[2013.02.06 15:46:47 | 000,000,000 | ---D | C] -- C:\Users\Root\Desktop\SNAP
[2013.02.06 15:46:45 | 000,000,000 | ---D | C] -- C:\Users\Root\Desktop\BATTERY
[2013.02.06 15:46:39 | 000,000,000 | ---D | C] -- C:\Users\Root\Desktop\SLOT
[2013.02.05 14:32:07 | 001,757,264 | ---- | C] (None) -- C:\Users\Root\Desktop\VisualBoyAdvance.exe
[2013.02.04 16:45:06 | 000,000,000 | ---D | C] -- C:\Users\Root\Desktop\BackUp
[2013.02.04 15:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\0xRH
[2013.02.04 15:56:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\0xRH
[2013.02.03 14:16:54 | 000,000,000 | ---D | C] -- C:\Users\Root\Desktop\pokemon
[2013.02.03 00:43:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PWUnmask
[2013.02.03 00:43:49 | 000,000,000 | ---D | C] -- C:\Users\Root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Password Unmask
[2013.02.03 00:43:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Password Unmask
[2013.02.03 00:36:24 | 000,483,328 | ---- | C] (Simon Tatham) -- C:\Users\Root\Desktop\putty.exe
[2013.02.02 12:47:06 | 000,000,000 | ---D | C] -- C:\Users\Root\Desktop\TERA Guides
[2013.02.01 11:57:10 | 000,000,000 | ---D | C] -- C:\Users\Root\Desktop\kavkisfile.com-01-Feb-2013
[2013.01.31 18:21:07 | 000,040,448 | ---- | C] (NirSoft) -- C:\Users\Root\Desktop\OperaPassView.exe
[2013.01.30 23:38:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flyff
[2013.01.30 23:23:00 | 000,000,000 | ---D | C] -- C:\Users\Root\Desktop\Cave Story+
[2013.01.28 20:53:44 | 000,000,000 | ---D | C] -- C:\Users\Root\AppData\Roaming\tor
[2013.01.28 20:53:38 | 000,000,000 | ---D | C] -- C:\Users\Root\AppData\Roaming\Vidalia
[2013.01.28 20:49:33 | 000,000,000 | ---D | C] -- C:\Users\Root\Desktop\SciLorsGrooveshark.comDownloaderV0.4.9.7
[2013.01.19 22:45:04 | 000,000,000 | ---D | C] -- C:\Users\Root\AppData\Local\kJKxc2SrE2J0FNouaB
[2012.07.14 20:51:23 | 086,400,840 | ---- | C] (K2 Network, Inc.) -- C:\Users\Root\APB_Reloaded_Installer.exe
 
========== Files - Modified Within 30 Days ==========
 
[2013.02.18 19:40:22 | 000,014,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.02.18 19:40:22 | 000,014,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.02.18 19:33:16 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.02.18 19:33:13 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.02.18 19:33:12 | 2133,561,343 | -HS- | M] () -- C:\hiberfil.sys
[2013.02.18 19:29:56 | 000,587,671 | ---- | M] () -- C:\Users\Root\Desktop\adwcleaner0.exe
[2013.02.18 19:27:28 | 001,085,344 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll
[2013.02.18 19:27:28 | 000,963,488 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll
[2013.02.18 19:27:28 | 000,310,688 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
[2013.02.18 19:27:28 | 000,188,832 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2013.02.18 19:27:28 | 000,188,320 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2013.02.18 19:27:28 | 000,108,448 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013.02.18 19:21:51 | 000,691,568 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.02.18 19:21:51 | 000,071,024 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.02.18 16:27:27 | 000,001,117 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.02.18 15:49:38 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013.02.18 15:41:21 | 005,033,910 | R--- | M] (Swearware) -- C:\Users\Root\Desktop\ComboFix.exe
[2013.02.18 14:05:24 | 000,002,348 | ---- | M] () -- C:\Users\Root\Desktop\Sicherer Zahlungsverkehr.lnk
[2013.02.17 20:36:13 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Root\Desktop\tdsskiller.exe
[2013.02.17 19:20:13 | 000,054,104 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\kltdi.sys
[2013.02.17 19:20:12 | 000,613,720 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2013.02.17 18:52:28 | 000,001,150 | ---- | M] () -- C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk
[2013.02.17 17:59:32 | 000,044,914 | ---- | M] () -- C:\Users\Root\Desktop\logs.zip
[2013.02.17 13:27:18 | 000,374,784 | ---- | M] () -- C:\Users\Root\Desktop\GMER_2.1.18952.exe
[2013.02.17 13:10:53 | 000,000,000 | ---- | M] () -- C:\Users\Root\defogger_reenable
[2013.02.17 12:47:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Root\Desktop\OTL.exe
[2013.02.17 12:47:09 | 000,050,477 | ---- | M] () -- C:\Users\Root\Desktop\Defogger.exe
[2013.02.17 11:46:20 | 005,478,824 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.02.17 01:06:52 | 001,641,818 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.02.17 01:06:52 | 000,699,342 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.02.17 01:06:52 | 000,654,660 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.02.17 01:06:52 | 000,149,164 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.02.17 01:06:52 | 000,122,118 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.02.16 21:50:44 | 000,537,171 | ---- | M] () -- C:\Users\Root\Desktop\FTB_Launcher.exe
[2013.02.12 20:37:07 | 000,000,872 | ---- | M] () -- C:\Users\Root\Desktop\InVisible.bat
[2013.02.10 10:53:09 | 000,000,097 | ---- | M] () -- C:\Users\Root\Documents\aw.swr
[2013.02.06 16:05:16 | 000,000,762 | ---- | M] () -- C:\Users\Root\Desktop\desmume.ini
[2013.02.06 15:48:18 | 000,001,536 | ---- | M] () -- C:\Users\Root\Desktop\NO$GBA.INP
[2013.02.05 20:31:13 | 000,116,370 | ---- | M] () -- C:\Users\Root\530033_335463309876823_1442398377_n.jpg
[2013.02.05 14:59:22 | 000,075,378 | ---- | M] () -- C:\Users\Root\Documents\poke1.SNA
[2013.02.05 14:34:51 | 000,065,536 | ---- | M] () -- C:\Users\Root\Desktop\Pokemon - Smaragd-Edition (G).sav
[2013.02.05 14:34:51 | 000,002,019 | ---- | M] () -- C:\Users\Root\Desktop\vba.ini
[2013.02.04 16:45:06 | 000,000,570 | ---- | M] () -- C:\Users\Root\Desktop\slot machine.au3
[2013.02.04 16:44:23 | 000,000,259 | ---- | M] () -- C:\Users\Root\SciTE.session
[2013.02.04 16:42:08 | 000,301,989 | ---- | M] () -- C:\Users\Root\Desktop\slot machine.exe
[2013.02.04 15:56:37 | 000,002,779 | ---- | M] () -- C:\Users\Public\Desktop\GBA Pokemon Game Editor.lnk
[2013.02.03 19:23:34 | 000,000,600 | ---- | M] () -- C:\Users\Root\AppData\Local\PUTTY.RND
[2013.02.03 00:40:22 | 000,000,600 | ---- | M] () -- C:\Users\Root\AppData\Roaming\winscp.rnd
[2013.02.03 00:40:01 | 000,013,993 | ---- | M] () -- C:\Users\Root\Desktop\WinSCP.ini
[2013.02.03 00:36:24 | 000,483,328 | ---- | M] (Simon Tatham) -- C:\Users\Root\Desktop\putty.exe
[2013.02.02 12:50:05 | 000,001,178 | ---- | M] () -- C:\Users\Root\Desktop\TERA-Launcher.exe - Verknüpfung.lnk
[2013.01.31 19:36:51 | 000,000,384 | ---- | M] () -- C:\Users\Root\Desktop\OperaPassView.cfg
[2013.01.31 13:11:11 | 000,000,681 | ---- | M] () -- C:\Users\Root\Desktop\Flyff.lnk
[2013.01.31 10:26:47 | 011,216,224 | ---- | M] (Igor Pavlov) -- C:\Users\Root\Desktop\ARMA2_OA_Build_101480.exe
[2013.01.28 20:49:26 | 011,040,791 | ---- | M] () -- C:\Users\Root\Desktop\SciLorsGrooveshark.comDownloaderV0.4.9.7.zip
[2013.01.28 10:39:37 | 127,061,846 | ---- | M] () -- C:\Users\Root\Desktop\Uplink Source.rar
[2013.01.27 20:01:56 | 000,000,132 | ---- | M] () -- C:\Users\Root\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2013.01.27 15:31:24 | 000,011,326 | ---- | M] () -- C:\Users\Root\Desktop\lastlogin-decoder.jar
[2013.01.26 23:10:20 | 000,000,342 | ---- | M] () -- C:\Users\Root\Desktop\RECONNECT.bat
[2013.01.25 22:23:03 | 000,642,377 | ---- | M] () -- C:\Users\Root\Desktop\Unbenannt.PNG
[2013.01.22 18:23:06 | 000,000,076 | ---- | M] () -- C:\Users\Root\Desktop\Cursor_Invisible.swf.url
 
========== Files Created - No Company Name ==========
 
[2013.02.18 19:29:56 | 000,587,671 | ---- | C] () -- C:\Users\Root\Desktop\adwcleaner0.exe
[2013.02.18 16:27:27 | 000,001,117 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.02.18 15:41:52 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.02.18 15:41:52 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.02.18 15:41:52 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.02.18 15:41:52 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.02.18 15:41:52 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.02.17 18:57:59 | 000,002,348 | ---- | C] () -- C:\Users\Root\Desktop\Sicherer Zahlungsverkehr.lnk
[2013.02.17 18:53:18 | 000,001,150 | ---- | C] () -- C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk
[2013.02.17 17:59:32 | 000,044,914 | ---- | C] () -- C:\Users\Root\Desktop\logs.zip
[2013.02.17 13:27:18 | 000,374,784 | ---- | C] () -- C:\Users\Root\Desktop\GMER_2.1.18952.exe
[2013.02.17 13:10:53 | 000,000,000 | ---- | C] () -- C:\Users\Root\defogger_reenable
[2013.02.17 12:47:09 | 000,050,477 | ---- | C] () -- C:\Users\Root\Desktop\Defogger.exe
[2013.02.16 21:50:44 | 000,537,171 | ---- | C] () -- C:\Users\Root\Desktop\FTB_Launcher.exe
[2013.02.12 20:36:34 | 000,000,872 | ---- | C] () -- C:\Users\Root\Desktop\InVisible.bat
[2013.02.09 14:14:12 | 000,696,832 | ---- | C] () -- C:\Windows\SysNative\xvidcore.dll
[2013.02.09 14:14:12 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2013.02.09 14:14:12 | 000,255,488 | ---- | C] () -- C:\Windows\SysNative\xvidvfw.dll
[2013.02.09 14:14:12 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2013.02.09 14:14:12 | 000,173,568 | ---- | C] () -- C:\Windows\SysNative\xvid.ax
[2013.02.09 14:14:12 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax
[2013.02.06 16:05:14 | 000,000,762 | ---- | C] () -- C:\Users\Root\Desktop\desmume.ini
[2013.02.06 15:48:18 | 000,001,536 | ---- | C] () -- C:\Users\Root\Desktop\NO$GBA.INP
[2013.02.05 20:31:13 | 000,116,370 | ---- | C] () -- C:\Users\Root\530033_335463309876823_1442398377_n.jpg
[2013.02.05 14:59:22 | 000,075,378 | ---- | C] () -- C:\Users\Root\Documents\poke1.SNA
[2013.02.05 14:38:37 | 000,170,646 | ---- | C] () -- C:\Users\Root\Desktop\NO$GBA.EXE
[2013.02.05 14:34:51 | 000,065,536 | ---- | C] () -- C:\Users\Root\Desktop\Pokemon - Smaragd-Edition (G).sav
[2013.02.05 14:32:14 | 016,777,216 | ---- | C] () -- C:\Users\Root\Desktop\Pokemon - Smaragd-Edition (G).gba
[2013.02.05 14:32:09 | 000,002,019 | ---- | C] () -- C:\Users\Root\Desktop\vba.ini
[2013.02.04 16:42:02 | 000,301,989 | ---- | C] () -- C:\Users\Root\Desktop\slot machine.exe
[2013.02.04 16:41:32 | 000,000,259 | ---- | C] () -- C:\Users\Root\SciTE.session
[2013.02.04 16:40:29 | 000,000,570 | ---- | C] () -- C:\Users\Root\Desktop\slot machine.au3
[2013.02.04 15:56:37 | 000,002,779 | ---- | C] () -- C:\Users\Public\Desktop\GBA Pokemon Game Editor.lnk
[2013.02.02 12:50:05 | 000,001,178 | ---- | C] () -- C:\Users\Root\Desktop\TERA-Launcher.exe - Verknüpfung.lnk
[2013.01.31 18:33:37 | 000,000,384 | ---- | C] () -- C:\Users\Root\Desktop\OperaPassView.cfg
[2013.01.31 18:21:07 | 000,014,874 | ---- | C] () -- C:\Users\Root\Desktop\OperaPassView.chm
[2013.01.31 13:11:11 | 000,000,681 | ---- | C] () -- C:\Users\Root\Desktop\Flyff.lnk
[2013.01.28 20:45:58 | 011,040,791 | ---- | C] () -- C:\Users\Root\Desktop\SciLorsGrooveshark.comDownloaderV0.4.9.7.zip
[2013.01.28 10:38:15 | 127,061,846 | ---- | C] () -- C:\Users\Root\Desktop\Uplink Source.rar
[2013.01.27 15:31:24 | 000,011,326 | ---- | C] () -- C:\Users\Root\Desktop\lastlogin-decoder.jar
[2013.01.26 23:09:24 | 000,000,342 | ---- | C] () -- C:\Users\Root\Desktop\RECONNECT.bat
[2013.01.25 14:04:12 | 000,642,377 | ---- | C] () -- C:\Users\Root\Desktop\Unbenannt.PNG
[2013.01.22 18:23:07 | 000,000,076 | ---- | C] () -- C:\Users\Root\Desktop\Cursor_Invisible.swf.url
[2013.01.20 15:40:48 | 000,413,696 | ---- | C] () -- C:\Users\Root\Desktop\Champion Picker.exe
[2012.12.05 14:11:15 | 000,065,536 | -H-- | C] () -- C:\Windows\SysWow64\WebCamLib.dll
[2012.11.14 20:57:50 | 000,004,466 | ---- | C] () -- C:\Users\Root\hallway_640x360 - Kopie.jpg
[2012.11.14 20:56:18 | 041,122,986 | ---- | C] () -- C:\Users\Root\hallway_640x360 - Kopie.mp4
[2012.11.09 19:00:55 | 000,000,600 | ---- | C] () -- C:\Users\Root\AppData\Local\PUTTY.RND
[2012.10.30 18:59:03 | 000,001,456 | ---- | C] () -- C:\Users\Root\AppData\Local\Adobe Für Web speichern 12.0 Prefs
[2012.10.30 14:48:05 | 000,000,600 | ---- | C] () -- C:\Users\Root\AppData\Roaming\winscp.rnd
[2012.10.14 13:45:33 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2012.10.08 17:52:28 | 000,854,510 | ---- | C] () -- C:\Users\Root\NHC106.rar
[2012.10.07 18:19:49 | 000,000,218 | ---- | C] () -- C:\Users\Root\.recently-used.xbel
[2012.10.05 20:24:34 | 000,003,584 | ---- | C] () -- C:\Users\Root\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.24 14:17:33 | 000,000,046 | ---- | C] () -- C:\Windows\sys2-6scan.ini
[2012.09.24 14:15:25 | 000,001,489 | ---- | C] () -- C:\Windows\swfscanner.INI
[2012.08.27 21:00:50 | 000,000,132 | ---- | C] () -- C:\Users\Root\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012.08.27 15:42:53 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2012.07.14 20:51:23 | 3999,925,254 | ---- | C] () -- C:\Users\Root\Client1.7.0.586601.7z
[2012.07.05 18:11:44 | 000,084,226 | ---- | C] () -- C:\Users\Root\AppData\Roaming\icarus-dxdiag.xml
[2012.07.03 14:53:32 | 000,000,484 | RHS- | C] () -- C:\Users\Root\ntuser.pol
[2012.07.03 14:16:11 | 000,000,034 | ---- | C] () -- C:\Windows\cdplayer.ini
[2012.07.03 13:41:18 | 000,000,197 | ---- | C] () -- C:\Users\Root\SecurityKISSTunnel.config
[2012.06.25 13:15:12 | 000,000,000 | ---- | C] () -- C:\Users\Root\SET
[2012.04.17 14:45:39 | 000,007,603 | ---- | C] () -- C:\Users\Root\AppData\Local\Resmon.ResmonCfg
[2012.04.04 16:25:41 | 000,000,337 | ---- | C] () -- C:\Windows\WPE PRO - modified.INI
[2012.03.16 20:06:31 | 000,281,520 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.03.16 20:06:26 | 000,794,408 | ---- | C] () -- C:\Windows\SysWow64\Pbsvc.exe
[2012.03.16 20:06:26 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.03.10 00:09:07 | 001,597,720 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.03.09 22:32:26 | 000,017,408 | ---- | C] () -- C:\Users\Root\AppData\Local\WebpageIcons.db
[2012.03.09 20:14:09 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011.12.29 12:40:20 | 000,000,018 | ---- | C] () -- C:\Users\Root\abbrev.properties
[2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010.03.27 16:22:54 | 000,014,905 | ---- | C] () -- C:\Users\Root\au3abbrev.properties
 
========== ZeroAccess Check ==========
 
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013.02.17 18:40:30 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\.minecraft
[2012.06.05 19:51:26 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\.minecraft - Kopie
[2012.06.10 12:10:38 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\.minecraft - Kopie (aeter)
[2012.09.09 12:01:46 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\.Nitrous
[2013.01.22 20:25:21 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\.purple
[2012.05.12 18:06:56 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\.spoutcraft
[2012.08.26 18:12:26 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\.tshock
[2012.12.05 14:11:15 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Apowersoft
[2012.05.12 22:01:12 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\AtomZombieData
[2012.05.12 21:47:32 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Braid
[2012.10.14 13:45:34 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Broken Rules
[2012.03.21 15:23:55 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012.08.12 01:32:08 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Crayon Physics Deluxe
[2012.04.10 19:03:32 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Dev-Cpp
[2012.04.08 13:31:02 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\dll-files.com
[2013.02.18 19:26:09 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\DVDVideoSoft
[2012.09.08 16:43:38 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Enterbrain
[2012.04.01 21:26:18 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Faerie Solitaire
[2012.05.29 12:43:44 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\FORGE.minecraft
[2012.06.10 16:36:51 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\FreeFLVConverter
[2013.02.16 21:54:20 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\ftblauncher
[2012.12.17 19:09:54 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\GetRightToGo
[2012.10.07 17:07:30 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\gtk-2.0
[2013.02.05 14:35:57 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\ICQ
[2012.08.30 21:20:30 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\ICSharpCode
[2013.01.13 21:04:39 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\iFunbox_UserCache
[2012.11.06 16:02:35 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Leadertech
[2012.03.09 23:38:57 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\LolClient
[2012.05.20 11:44:59 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\LolClient2
[2012.07.29 22:11:01 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\LolMatches Client
[2012.11.09 18:18:46 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\MySQL-Front
[2012.03.28 12:32:39 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Nicalis
[2012.10.14 10:23:03 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Nifflas
[2012.06.03 19:22:08 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Notepad++
[2012.04.20 19:57:28 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\OpenOffice.org
[2012.03.09 20:16:58 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Opera
[2012.12.01 14:17:52 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Origin
[2012.05.10 15:40:37 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\PE Explorer
[2013.02.16 19:27:56 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Play withSIX
[2012.10.07 12:48:27 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Psi
[2012.03.23 20:13:34 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Publish Providers
[2012.11.09 14:32:57 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Rainmeter
[2012.09.03 14:19:17 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\redsn0w
[2013.01.13 21:08:11 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\SharePod
[2012.09.15 21:14:39 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\six-zsync
[2012.07.03 14:38:39 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Sonarca Sound Recorder Free
[2012.06.09 18:53:17 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Sony
[2013.01.03 14:29:32 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Sony Creative Software Inc
[2012.09.15 15:41:23 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\SPORE
[2013.02.18 19:28:48 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Steganos
[2012.03.15 19:16:15 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\TeamViewer
[2012.10.05 20:12:13 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\TechSmith
[2012.04.29 20:46:49 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Teeworlds
[2013.02.18 15:50:08 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\TS3Client
[2013.02.16 19:21:55 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\ts3overlay
[2013.02.16 19:21:55 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\ts3overlay_hook_win64
[2012.06.05 19:15:16 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\TunkDesign Inc
[2013.01.01 01:12:24 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\uTorrent
[2012.05.21 10:24:15 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\wargaming.net
[2012.04.04 16:51:46 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\Wireshark
[2012.12.16 13:23:13 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\WNR
[2012.06.02 21:53:09 | 000,000,000 | ---D | M] -- C:\Users\Root\AppData\Roaming\WorldPainter
 
========== Purity Check ==========
 
 

< End of report >


ryuk 18.02.2013 20:43

extras
Code:

OTL Extras logfile created on: 17.02.2013 13:15:58 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Root\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7.98 Gb Total Physical Memory | 5.58 Gb Available Physical Memory | 69.92% Memory free
15.96 Gb Paging File | 13.73 Gb Available in Paging File | 85.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372.60 Gb Total Space | 201.81 Gb Free Space | 54.16% Space Free | Partition Type: NTFS
Drive D: | 540.23 Gb Total Space | 157.66 Gb Free Space | 29.18% Space Free | Partition Type: NTFS
Drive E: | 100.74 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: SYSTEMROOT | User Name: Root | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- D:\Program Files (x86)\Photoshop\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- D:\Program Files (x86)\Photoshop\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0439A57E-F778-434A-ADAA-3C1E8D6444BB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0C739BDD-93C2-4691-A888-4C9EA63B56FC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{15990194-2BD8-4156-893C-E070592F2800}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1C0FF142-4BB7-4AAD-B267-2122BB975023}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{246A3150-1CAC-4CC3-ADE4-F0D5F8C3F178}" = rport=138 | protocol=17 | dir=out | app=system |
"{36A5B7F2-26D8-447E-B308-9AB1E8C8425D}" = rport=10243 | protocol=6 | dir=out | app=system |
"{3AAF451F-E979-4023-B46A-56E9EFB7E55F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3BA9C3CD-5A50-458E-A769-67D4D0AE8C97}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{426BF746-6B16-4DBC-A361-2208539F2B07}" = lport=56567 | protocol=6 | dir=in | name=pando media booster |
"{44D69EF4-6FD8-4FDA-9DB7-56D03AE9A3D6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4A5219B3-C197-49A4-84E3-7D69D2080933}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4FAAC0B8-7C61-44B4-9EFB-66E21A1BF560}" = lport=10243 | protocol=6 | dir=in | app=system |
"{58FF5002-CCC7-4EE5-A58F-440E1D2CD11C}" = lport=3074 | protocol=17 | dir=in | name=aw3 |
"{5BB322C6-43FF-4BD4-AAFD-D4C11116BE6F}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{5CA8AEA8-E477-45E4-80AA-63F8AF955B56}" = lport=139 | protocol=6 | dir=in | app=system |
"{66BADAFC-86BB-430E-97D8-7FD850FE535F}" = lport=445 | protocol=6 | dir=in | app=system |
"{68A12417-7938-42EB-B3F1-F8A2E50DB488}" = rport=139 | protocol=6 | dir=out | app=system |
"{6D02405C-0A5B-497F-A6E3-B40F21A9F91B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{70B7BE5A-C154-4433-AE75-ABC4B6926F8C}" = lport=56567 | protocol=6 | dir=in | name=pando media booster |
"{72E3EC6D-84C8-484D-AECF-0EFCB22B6B69}" = lport=123 | protocol=17 | dir=in | name=udp |
"{7701055E-C72C-4C49-BBA2-AB6F7C517FDA}" = lport=137 | protocol=17 | dir=in | app=system |
"{89A3BF0E-902F-4609-A159-4CD68E96B777}" = rport=3074 | protocol=6 | dir=out | name=aw34 |
"{91B900E0-FCC2-480F-8B3A-2FABE9BCFC1E}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{92646C34-B24D-4F6B-A70A-F122058E92CD}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{96723A7F-931C-48B5-B574-4321AA0DC8A3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9EBB3907-3AC6-44B9-9B22-6117339D14DF}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A06BC328-3F9C-4023-A29E-7725ECD11C24}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A171F65D-CCFE-4704-B59F-95402CF4877A}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{A28CC37E-703F-46D7-8F9C-D8A305D18B47}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{A670E57B-53FD-464D-92DB-CB988307E582}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AC650E14-C489-46D5-B758-1ECE644F5643}" = lport=138 | protocol=17 | dir=in | app=system |
"{B043957F-210C-4A74-9549-82F1C60DB689}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C6599D56-E95C-41D9-833B-D942DE87C79B}" = lport=3074 | protocol=6 | dir=in | name=aw |
"{CD854E81-83CB-47CA-AFDE-A43F58201741}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DE2E87DC-9965-4539-A1AB-AC391FAFBA49}" = lport=56567 | protocol=17 | dir=in | name=pando media booster |
"{E18C69C3-A85B-4EE3-8905-A609A2C7BEEE}" = lport=7777 | protocol=17 | dir=in | name=terraria2 |
"{E22EEE62-11B3-4306-B6C4-453414823BD1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E6594A62-D678-4ECB-8714-73E0E4AD5065}" = rport=3074 | protocol=17 | dir=out | name=awe |
"{F0BA44E2-A92B-40EE-B812-3B26A5C62E71}" = lport=7777 | protocol=6 | dir=in | name=terraria |
"{F344232C-0225-474B-BA1D-2F110B3B3703}" = rport=445 | protocol=6 | dir=out | app=system |
"{F5A75B57-7CEE-4E7D-8AB6-34E02F2DB317}" = lport=56567 | protocol=17 | dir=in | name=pando media booster |
"{F9A6003C-8D8D-48A9-BEEA-68F805C5EC8E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FF798233-6E4C-44FB-97E6-A62F76145D0D}" = rport=137 | protocol=17 | dir=out | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0274CCBF-C0EF-4DAE-B3AD-C43623143CA8}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\saira\settings.exe |
"{02873699-CDD4-4758-B49B-B730A5EDB2A6}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\ride carnival tycoon\ridecarnivaltycoon.exe |
"{02BE42B7-F39D-46E5-867D-7A15F1D5F84F}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{0446BA9F-F13A-48C4-A59E-769727F4DACE}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\call of duty 4\iw3sp.exe |
"{05164584-C909-468E-B912-5439E96CF2ED}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe |
"{0540E063-4D65-4C45-9582-9E85F9911AF0}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{054A20EB-1EA5-41EE-867B-E027B462D33C}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\hacker evolution untold\hacker evolution untold.exe |
"{06F3B063-0AB0-4F9F-B37A-55D0C74B849D}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\revenge of the titans\revengeofthetitans.exe |
"{084F3503-ADC1-4665-A8AA-C62B5EDE45C0}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{0BC6C1C9-A610-497C-81BC-326EF4B712B2}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\saira\settings.exe |
"{0BC89BA2-C427-4591-96F8-9118C257DC57}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\battlefield 2\support\ea help\electronic_arts_technical_support.htm |
"{0C3BC281-24B5-4F98-A069-CC6708AEF8BB}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{0CEEAEDC-1F0D-4534-88E0-CB8096334542}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{0E000579-2885-4D6B-81DB-1465D66482A1}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{0E3A6992-4F4B-4DFE-A98A-A4E4585AB345}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\defcon\defcon.exe |
"{1048DAF6-9B1D-488B-AEA4-F4EB28921E63}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\zombie shooter 2\zombieshooter2.exe |
"{139B64BB-6A5B-4CFE-ADB2-7F98B1C63EFE}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\bit.trip runner\runner.exe |
"{15AE7777-5A42-4BE7-9C49-4E3A24BF500B}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\jamestown\jamestown.exe |
"{17BEE1C1-DAF4-4231-9D2F-E67CAC4F341F}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\battlefield 2\bf2.exe |
"{1B6750C0-529A-465A-9622-283441B5794D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1BE5CBB6-D0C6-4CC8-B6D9-DB776F49FAAE}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\jamestown\jamestown.exe |
"{1DA0BABF-F91B-4DFA-B3FA-A321BD166A23}" = protocol=6 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe |
"{1F432BAD-31E6-4B29-86E0-308BC5FD9DC8}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\cogs\cogs.exe |
"{200DBFE2-D84D-43A5-AEEE-E1E0B36C21ED}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{21355465-597D-4FBE-B8F4-E3A337D80B01}" = protocol=6 | dir=in | app=c:\users\root\documents\arma 2\expansion\beta\arma2oa.exe |
"{21980604-4283-4625-A668-E407F86E7226}" = protocol=6 | dir=in | app=d:\program files (x86)\gamersfirst\apb reloaded\binaries\apb.exe |
"{21C2983D-5837-417B-A08C-658AD38F8D66}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\faerie solitaire\faeriesolitaire.exe |
"{21D0016D-6B61-4DD2-A62E-1CA07F3E0CD4}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{227F3AFA-E2B6-4A3E-B564-C86A9B4623BC}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\hacker evolution duality\hacker evolution duality.exe |
"{22CB156C-5DE1-405D-AA8A-8A19C47F432B}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{23F929CC-7617-4B44-948C-E36A9C99BE19}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\vvvvvv\vvvvvv.exe |
"{240820DC-2967-4290-9BD3-AE13152C8098}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\bit.trip runner\runner.exe |
"{249AF563-CB17-41C0-8943-2E67C858A67F}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\crayon physics deluxe\launcher.exe |
"{24DDE494-6D41-4416-8AB9-FECF2AA74956}" = protocol=6 | dir=out | app=system |
"{25FCB631-FCE3-4F48-A418-D0F911221B8D}" = protocol=17 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe |
"{2751B081-8107-4B33-A4FA-437FE8CE2335}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{2791B497-E053-4A6B-A9CE-7DDE84402CC4}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\uplink\uplink.exe |
"{287C625C-FFDE-43C1-B0C6-65161D571397}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{28AF3830-0CC4-420D-866D-CA559D690C51}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2A9B23B4-E371-436F-B1A3-6AB34A7830DD}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{2AFB23D7-A37B-43F1-82F8-481B50CD93E8}" = dir=in | app=c:\program files (x86)\apowersoft\screen recording suite\screen-recording-suite.exe |
"{2B9A046F-CA88-46E8-8ECE-D5BD67B0357E}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{2C8DE4CF-CAA2-4B09-B2F6-0470032AB418}" = protocol=6 | dir=in | app=d:\steam\steamapps\itsme258\counter-strike source\hl2.exe |
"{2D67AE1B-D65C-4756-AEC0-24E3A4CB8EDE}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\machinarium\machinarium.exe |
"{2F257971-ECCA-4991-B8CE-B408B64F3A66}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\your doodles are bugged!\yourdoodlesarebugged.exe |
"{3172A4A5-E90A-4D90-9AD9-25EBD86F88F0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{31818FA2-2D31-4F7C-A88E-F800945ECA18}" = protocol=17 | dir=in | app=d:\program files (x86)\tera - kopie\tera-launcher.exe |
"{319AD6FA-9797-47E0-905D-27925D9AC5ED}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\payday the heist\payday_win32_release.exe |
"{33A3136C-3B6E-4698-BE73-9C897CD62AEA}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{3708D12F-AC79-4979-ADA6-CB3885D6003F}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\cogs\cogs.exe |
"{370EAFD5-FF2A-458B-98CE-BAEB15D8D3FD}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\nightsky\nightsky.exe |
"{37CEC898-1F36-4C89-95B7-180477463700}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{384E26BB-44AC-4570-B779-1A91F6D47F91}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\defcon\defcon.exe |
"{387F1DDB-105B-423F-827B-D5FB0F59D376}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"{39FC0F17-DAB8-4677-9694-644394C64086}" = protocol=17 | dir=in | app=c:\program files (x86)\psi\psi.exe |
"{3A51AC3A-5A52-4E7F-8D10-A545E1534E75}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\osmos\osmos.exe |
"{3BB1AFEA-3ABF-43A3-984B-3E7746085AF7}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{3ED25736-684F-4A39-B55C-65579AAF43CF}" = protocol=6 | dir=in | app=d:\steam\steamapps\itsme258\garrysmod\hl2.exe |
"{41919680-A0DC-4F52-AD6F-40678429F295}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{43789E1B-EDD0-4D8A-A56C-9E9C9BEBC8DC}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{467B3ECD-4124-444C-944E-66864B557577}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{488DC317-A2B0-4B7C-AF58-DB9CD2FDE4E3}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\hacker evolution duality\hacker evolution duality.exe |
"{4895AA1C-F7DD-4EDC-A17C-DC057159567D}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |
"{490F62D2-3079-4180-91E6-8D6EAEE93836}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{4961BDF0-5746-4BE9-BEC3-6B37996896AF}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{497FED08-46D7-418F-B1CA-003CEF2144C1}" = protocol=17 | dir=in | app=d:\program files (x86)\gamersfirst\apb reloaded\binaries\apb.exe |
"{4AFAA329-7487-4158-B4D4-3744475B803D}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{4CED581B-8585-462A-BEA2-EB731F3502D7}" = protocol=17 | dir=in | app=d:\program files (x86)\tera\tera-launcher.exe |
"{4D3C088F-BF8C-481C-BD0F-7F8F8F2E6E25}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\dragon age ultimate edition\daoriginslauncher.exe |
"{4EF24508-0EA9-4B8B-9A18-5F84379EF3B2}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\terraria\terraria.exe |
"{512D2596-B52F-4F0B-AE7D-352ECA8D6CEE}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\hammerfight\hammerfight.exe |
"{5131F2B3-17C0-4FCC-B16C-D0CD38BC1916}" = protocol=17 | dir=in | app=d:\origin\crysis 3 mp alpha\bin32\crysis 3 mp alpha.exe |
"{52DE77F2-7131-43D3-B203-99035D25D0A2}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{53949BC2-259F-46CB-AFB8-1098A65C95A7}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\terraria\terraria.exe |
"{5464C83D-C7F0-413E-85F8-277794558A25}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{55B158C1-3C47-45CF-BFAC-ECE3A1C02612}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{55F63C71-1D2C-4AE3-BF08-D4969128802D}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\rainbow six vegas\binaries\runme.exe |
"{561DF159-55A4-46E0-96B1-12511B0E285A}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\call of duty 4\iw3mp.exe |
"{565BA135-3765-44E1-A966-A921D584F010}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\machinarium\machinarium.exe |
"{56BBBBD2-5D23-4643-AEF9-A165C8C512CB}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5750FD25-5E81-43A7-983F-633DBADF7519}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\bully scholarship edition\bully.exe |
"{57B7CCCE-E4DF-41EA-B105-FCA9A37041FD}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\metro 2033\metro2033.exe |
"{58FE3854-2650-457E-B7CC-70B646A40AA5}" = protocol=6 | dir=in | app=d:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe |
"{591804B4-5717-4D1B-A363-5A2E738E24A8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{593417F8-9776-423A-87E2-A0B9E54E3DAC}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{5C32207F-BCA5-4248-8C6C-0438B4369AEE}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\frozen synapse\frozensynapse.exe |
"{5C6F9509-9DF9-4869-A545-444A5D3C2247}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\hacker evolution duality\hacker evolution duality.exe |
"{5CAFCD08-66FF-412D-AA54-72355B653527}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{5CF52534-846E-4BBE-A1DD-9C39CB514F2F}" = protocol=6 | dir=in | app=c:\program files (x86)\warmux\warmux.exe |
"{5DA17866-E9DB-4057-AE48-79C9BFC13811}" = protocol=6 | dir=in | app=c:\program files (x86)\bearshare applications\mediabar\datamngr\srtool~1\dtuser.exe |
"{5EC7DDE5-188B-4DA7-BD14-1612DF7AF7D0}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{5EFB52E4-DD5F-4A0A-BFE6-B18712652535}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"{614D22AB-AA47-4E48-99FF-44182462E4FD}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{61BD5734-F0E5-4E0C-B410-F7DC1BFE17BC}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6379ACB9-FBFB-45E3-85C9-E4783A4198D0}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"{65AD1F77-8FDC-4378-AAC5-4B2E2ED364F5}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\mafia\setup.exe |
"{65C35695-D5A5-4B60-A1EB-847C9CB2A174}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\eets\eets.exe |
"{6670EBE3-9EF3-4FAE-A05B-7260E36BA31F}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\mafia\setup.exe |
"{66A56320-3215-4A2D-9ADB-BA97EFA95A9E}" = protocol=6 | dir=in | app=d:\steam\steamapps\itsme258\bloody good time\bgt.exe |
"{66B6AEE2-AE50-4B65-B3C8-D9ADB238977E}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\saira\saira.exe |
"{6C4ED7D7-C7B0-4EBA-8F3D-08C0AB33C947}" = protocol=6 | dir=in | app=c:\program files (x86)\psi\psi.exe |
"{6C5AFF04-2871-428B-ABA9-B1ACF7F21955}" = protocol=17 | dir=in | app=d:\origin\battlefield 3\bf3.exe |
"{6DE5843F-B96F-4C1B-AD42-D6EEE96BA45B}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\saira\saira.exe |
"{6FE8A48E-E348-4B95-8D7A-ABF2FC670936}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{70EB797D-7F94-49A1-9663-79042AA36BAA}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe |
"{72180012-25A7-49B1-AA22-20D6A1010D5F}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\dragon age ultimate edition\daoriginslauncher.exe |
"{73FA75B6-FB39-4DD1-B4BE-C83A7BAB6DE8}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe |
"{74C3554E-4B01-4C24-BBDC-9BCB08052BB5}" = protocol=6 | dir=in | app=c:\windows\system32\java.exe |
"{75484A20-8F89-42BD-9D98-137159F46AE6}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{7723FB12-E561-40A3-AB67-ADEDC964D6DC}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{78C56B9E-24FB-4811-BD4F-E39B05F514CE}" = protocol=6 | dir=in | app=c:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe |
"{797225E3-667A-404D-AF1D-B271F9768A68}" = protocol=6 | dir=in | app=c:\program files (x86)\proxy switcher standard\proxyswitcher.exe |
"{79B09B81-488E-4289-BEDE-5748C943EC53}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe |
"{7ABCF600-E3D0-4F3D-9A17-4C36A06B6D92}" = protocol=17 | dir=in | app=c:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe |
"{7BC28C8C-39E3-4B03-BACB-78B0759D5176}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\uplink\uplink.exe |
"{7C5665A1-9CB9-45BF-998E-23756649E33C}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{7F631A5E-2075-4888-AE9E-B02A7951CC78}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
"{8046C012-ADF8-4B90-BDD0-02BCF042CC1F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8096F998-A83C-4834-B729-4D1F1ABD567D}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\mafia\game.exe |
"{8194F9F6-0926-47EA-AC2A-1553FFE06D22}" = protocol=17 | dir=in | app=c:\program files (x86)\proxy switcher standard\proxyswitcher.exe |
"{82BB46DB-F50B-4A63-9953-FF2295C8C1A3}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{85EA01FB-F058-4BA9-ABC3-20DF7E995186}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{87E5AC28-B569-4EB7-924E-C4D353C64BAC}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\hacker evolution untold\hacker evolution mod editor.exe |
"{88AE57C2-71A5-4EFD-96EF-2ADC13CCC97C}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\darwinia\darwinia.exe |
"{895297F0-EF68-49B1-84A2-66FD017342C2}" = protocol=58 | dir=in | app=system |
"{8AC21160-3F15-4D90-9A72-6C587695938C}" = dir=in | app=%programfiles%\securitykiss tunnel\securitykisstunnel.exe |
"{8CAB0B54-73A3-4E81-9394-D957756AC31A}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\the binding of isaac\isaac.exe |
"{8D5E0AF5-44AE-4A57-8249-0B08C1C211FE}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\battlefield 2\bf2.exe |
"{8D9C7953-1059-4E7F-8C26-70CDCF243B1D}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\magicka\magicka.exe |
"{8E158EC7-C5D3-4170-9479-F55ED7E2E56A}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{8F2A93DE-3680-47F2-A377-5A26B77CB014}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{8F72D7C5-9977-4847-A40E-DBE339F1F666}" = dir=in | app=c:\program files (x86)\apowersoft\screen recording suite\screenrecordingsuite.exe |
"{8FDCDA0F-9DA6-46EA-9CFB-85E9F4A63B38}" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"{91800F63-E427-4386-8A76-993C95777C64}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"{921AA8A4-ADC0-4594-94D8-99BF1E824B1E}" = protocol=6 | dir=in | app=d:\origin\battlefield 3\bf3.exe |
"{94EB04DE-A984-4C7C-8051-861603EFA1FF}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{952569F5-0B34-4A4E-B336-55BE75ED3DF3}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\frozen synapse\frozensynapse.exe |
"{96C48538-BEAD-4E6C-9B2B-84370D33C7AA}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\swordsandsoldiershd\swords and soldiers launcher.exe |
"{96F9B6FC-0C6E-4BD9-A3AC-7E3B922CC43B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{979DC9A2-3269-4941-B959-793BA73EDC3F}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\hacker evolution untold\hacker evolution untold.exe |
"{98655337-2A8E-473F-AC57-6D7B27C9E313}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"{9976243F-A53F-4FC3-B3F5-DEEC1FBB8269}" = protocol=6 | dir=in | app=d:\program files (x86)\gamersfirst\apb reloaded\binaries\vivoxvoiceservice.exe |
"{9B1E943C-F360-4431-8E45-371E714309E8}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{9C104835-7AEE-4736-B2A8-52B8F73DE8D7}" = protocol=17 | dir=in | app=c:\users\root\documents\arma 2\expansion\beta\arma2oa.exe |
"{9C45355C-2EFD-4C03-82AD-59FF82FF0627}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"{9C5DE694-0B5D-4338-87DF-3D8EBE79007C}" = protocol=17 | dir=in | app=d:\steam\steamapps\itsme258\bloody good time\bgt.exe |
"{9C645DEA-05FE-41CD-8C4E-2B0AC820B04A}" = protocol=6 | dir=in | app=d:\program files (x86)\tera\tera-launcher.exe |
"{9C70D444-ABFA-4C75-A780-424A6BA55BDD}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\and yet it moves\and yet it moves.exe |
"{9CB7CA17-6F5D-406D-8653-D854FB20F8AF}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\sega classics\segagenesisclassics.exe |
"{9D8938EA-94CB-4B93-9AFD-4BEDCE9FFBC8}" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"{9EB463DB-0D25-4166-BC01-078D9580912C}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"{A1A66095-0796-4112-80E9-C52435B2E5ED}" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"{A4D4C1A4-3677-4F1E-84F0-3F9AA77AF80C}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\swordsandsoldiershd\swords and soldiers launcher.exe |
"{A52F0F25-CD48-4BD9-9172-C7AB9C269343}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{A5B96BFF-880B-46F5-B015-13B735056AB0}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{A8B5728D-2C4E-41AF-B3F2-DFB8F077027D}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\payday the heist\payday_win32_release.exe |
"{A93541B9-EDA1-4C6A-A2D3-40D4F558D6B0}" = protocol=17 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe |
"{AB634519-1CC7-4069-8751-5680330A0EB0}" = protocol=6 | dir=in | app=d:\origin\crysis 3 mp alpha\bin32\crysis 3 mp alpha.exe |
"{AC904FE9-43BC-416D-AF09-86CFE7C4B3BF}" = protocol=17 | dir=in | app=d:\steam\steam.exe |
"{AF913184-4EF0-4280-9E30-8C18DF78F4B4}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B0109AC3-B436-49AD-8683-82C5950D3B82}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B22C988F-A4D2-4D45-909D-30AC6607B00A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B28C091F-428B-4A66-9F33-7D08B0643FCC}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\your doodles are bugged!\yourdoodlesarebugged.exe |
"{B421A1C2-9926-4EAF-BDDE-BE2677C7C9D3}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{B42E3CE4-2214-427D-9E8A-3A09B71329F8}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"{B4AC15D8-AB96-4830-B9CE-79352EEEF1ED}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\metro 2033\metro2033.exe |
"{B55DE12C-BE78-4264-8E5E-7E95791F2F3C}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\the binding of isaac\isaac.exe |
"{B7086384-7F29-4E2F-8E7C-0F80A8343DCC}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\vvvvvv\vvvvvv.exe |
"{B756E767-4171-4B17-B875-87D352C38D3E}" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"{B83353EB-124E-44F6-8DD0-258B66A11CE0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B862A80B-2429-4C03-AF5D-128DA7C1F68F}" = protocol=6 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe |
"{BC57D389-C9C6-49B3-91C2-549C518C2CC8}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{BE370A41-1FE4-48F6-B24F-0776A5C52F64}" = protocol=17 | dir=in | app=c:\program files (x86)\warmux\warmux.exe |
"{C0AF0DA5-B2FD-4ECA-A893-2BFEB6FAC6CF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C287C26B-A828-43E6-A109-A21944FE1193}" = protocol=6 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe |
"{C2FE0BC6-A231-4831-9E10-66B5626A678A}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\zombie shooter\zombieshooter.exe |
"{C3E99012-F322-4CCA-BD4B-11D669B345D6}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\hacker evolution untold\hacker evolution mod editor.exe |
"{C43740AB-82D5-474B-ABDC-53E952B17C94}" = protocol=17 | dir=in | app=c:\program files (x86)\bearshare applications\mediabar\datamngr\srtool~1\dtuser.exe |
"{C4FD8624-AAAA-4752-BD3A-CAE65D5E2556}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{C64FE86C-8B9F-4741-8C28-35619CF386B7}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\and yet it moves\and yet it moves.exe |
"{C845F630-D897-4880-AECD-BEEA8EDCDD00}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{C8A300E2-7BC3-4687-BC8C-1F6E93D20F58}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\eets\eets.exe |
"{C9505DA9-4693-47D6-8BBF-5559938E7CBC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{CA161B75-23B7-4D38-AC64-76B357D3C586}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\zombie shooter 2\zombieshooter2.exe |
"{CA1BBBDE-C1FB-410D-86F1-602413C4CF90}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\revenge of the titans\revengeofthetitans.exe |
"{CB0DD9CB-A5EF-43FD-8494-B4D29920B04B}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\dota 2 beta\dota.exe |
"{CB694EE8-F9E4-457B-AC4B-5496AAB4FCF2}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\call of duty 4\iw3mp.exe |
"{CC28745C-4F89-44BD-A72A-A99541D49F71}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{CC6AFBCB-9225-400A-AD30-9FC3442771FC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{CD1D1AF8-3712-46C6-9A44-6CA084DA671D}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\mafia\game.exe |
"{CE1EA41F-57CD-4385-A709-93E71286B8D7}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\sega classics\segagenesisclassics.exe |
"{D0975BC7-419A-4B66-B7AB-8519E427E227}" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"{D0A8F65D-2EDC-482E-8037-7D0654470FE8}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{D238AD07-256D-4C33-B1D5-0575C91723C9}" = protocol=17 | dir=in | app=d:\steam\steamapps\itsme258\counter-strike source\hl2.exe |
"{D28478C4-4579-48C8-9ACC-27639815215C}" = protocol=17 | dir=in | app=d:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe |
"{D490CC74-24CE-46BE-A26D-203F7EAC22B5}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\crayon physics deluxe\launcher.exe |
"{D4D29440-5DF9-4740-9CA5-1747F3A5C78F}" = protocol=17 | dir=in | app=d:\program files (x86)\gamersfirst\apb reloaded\binaries\vivoxvoiceservice.exe |
"{D645ACB6-6F44-4730-9A73-B8C5E7B4AF86}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
"{D6E2FD80-A852-4768-B8A9-38AEEF87AA5D}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{D7E98BE2-A6EC-4A1F-9EF6-9DA61B279117}" = protocol=17 | dir=in | app=c:\windows\system32\java.exe |
"{D8AA2460-C10E-48B3-AC1E-F19048AE28EE}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\faerie solitaire\faeriesolitaire.exe |
"{D90AB94E-C040-464B-A2D2-E6A4CBBAD4A6}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\rainbow six vegas\binaries\runme.exe |
"{DAAD5E21-EB2B-4ADB-9F04-422A3F53800F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DBB4C754-21B4-402F-BC3C-A06F68DACCCF}" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"{DC1C45C0-AD79-4B67-9182-3FB2B27DD6CC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DCE318CC-D9A9-43E5-A101-89CBC41EDE7B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{DEA3E19C-C26D-4A32-9C9B-D9314531CE1A}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\call of duty 4\iw3sp.exe |
"{E0E70AD8-D280-458B-BF3A-DEB6AC7D8CCD}" = protocol=6 | dir=in | app=d:\steam\steam.exe |
"{E23405B1-61FC-4823-BB7B-62F9FEC3715B}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\bully scholarship edition\bully.exe |
"{E3BF47D2-1BDC-48E9-A461-564D541614DF}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{E4331CD0-A6EB-4FCC-9BDD-44B5E6E8A11D}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe |
"{E51FBF71-9621-40F6-AC37-06E25AEC39BF}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |
"{E7129F65-5BF3-41DA-B7FD-CF0817C8AAEE}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\hammerfight\hammerfight.exe |
"{E7EB217C-A5C9-4368-B764-6456E5D44712}" = protocol=6 | dir=in | app=d:\program files (x86)\tera - kopie\tera-launcher.exe |
"{EA034642-E35F-410A-A8DB-8A31F0E01EDD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{EB146ED6-628E-413D-B40E-0298F5C32F50}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\zombie shooter\zombieshooter.exe |
"{EB874236-3166-4518-9568-D28A2602F624}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe |
"{ED218D14-E3A3-4691-82D4-C4B684E9A272}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\magicka\magicka.exe |
"{EDFF83CD-2D07-4E44-98F5-AEB60D47D817}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\darwinia\darwinia.exe |
"{EE7DB023-80C7-46E0-953D-1F8D2C6F5846}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{EFF1DC77-9A45-42BC-849C-84D01BCFDA44}" = protocol=17 | dir=in | app=d:\steam\steamapps\itsme258\garrysmod\hl2.exe |
"{F19410E4-E27D-42D9-BDB2-3E6C53336468}" = protocol=17 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe |
"{F1A01D61-31AB-4EEE-BC53-0968C27372CF}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{F32444E7-D95F-4E32-8DC2-784E2173800B}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\hacker evolution duality\hacker evolution duality.exe |
"{F386A3DD-CA19-413F-84C6-71D19273F7E3}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F3ACFEF1-B99C-429C-94A4-FECB83F37C9E}" = protocol=17 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe |
"{F401CFAD-02B6-4148-9483-E7F3FECAAEFB}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{F628FC0B-A4BA-473B-89E3-3BBBA9204241}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\ride carnival tycoon\ridecarnivaltycoon.exe |
"{F6437B0A-BD07-45D2-96D6-276345F4131B}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\battlefield 2\support\ea help\electronic_arts_technical_support.htm |
"{F7EFC87E-6470-434D-B6FB-D14BBC48B2D9}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{F81EA130-EE3A-4A1D-BA76-DD0EF32ABEBF}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\osmos\osmos.exe |
"{F86E60AC-1D41-4774-8855-DD6DDE96AC65}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F89A9FCB-93AA-4B53-BDC2-0D0A77672D2E}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\nightsky\nightsky.exe |
"{FDBEF573-D3EB-488D-A262-A589DFFD7DC1}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FE44B46B-0B35-4373-9E4B-BEB32D54B65C}" = protocol=6 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe |
"{FF310BA4-F045-437C-ABBF-A44FF358C6FA}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\dota 2 beta\dota.exe |
"{FF851D28-B99A-49DE-8C9F-77B9D9D32BE6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{1075CD2D-A097-4677-A315-2BA980D0998C}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"TCP Query User{18380749-5BB4-4F38-8993-88FF8A572BC7}C:\program files (x86)\psi\psi.exe" = protocol=6 | dir=in | app=c:\program files (x86)\psi\psi.exe |
"TCP Query User{29DE6719-C246-40C3-8A4C-C4E31B467E99}C:\users\root\documents\arma 2\expansion\beta\arma2oa.exe" = protocol=6 | dir=in | app=c:\users\root\documents\arma 2\expansion\beta\arma2oa.exe |
"TCP Query User{2E68FD53-87D8-440F-AF39-74ECC5DA7E85}C:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe" = protocol=6 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe |
"TCP Query User{3854B33A-44BA-4493-887E-96D23FAB951C}D:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe" = protocol=6 | dir=in | app=d:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe |
"TCP Query User{3B3CA2D2-7953-48DE-BEDF-E21F6B6CEEDF}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{3D25C8D5-B9E5-4168-983D-20B5E95D9520}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"TCP Query User{4134F468-55B4-40BF-AAF0-D373D1F32B7B}C:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe |
"TCP Query User{4662B24F-93AD-4AFF-ACF8-52E1680F940C}C:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"TCP Query User{66B5B9DD-659C-47AE-9862-FCD3667A6170}D:\program files (x86)\tera\tera-launcher.exe" = protocol=6 | dir=in | app=d:\program files (x86)\tera\tera-launcher.exe |
"TCP Query User{7BA52CD0-ACE5-4182-9DBB-043A29011253}C:\program files (x86)\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"TCP Query User{7D113FD4-4E4B-4D24-943B-2F51E45D9C22}C:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe |
"TCP Query User{83872114-B5CC-42D3-88CB-80804D21226D}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"TCP Query User{84591BC8-D755-4DE5-9E2F-C21479C0EC5D}C:\games\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"TCP Query User{958AC8B0-9F18-4077-A498-1F20CA9C1CAC}C:\windows\system32\java.exe" = protocol=6 | dir=in | app=c:\windows\system32\java.exe |
"TCP Query User{97046C55-237D-49AA-9AFC-BC002FB16831}D:\program files (x86)\tera - kopie\tera-launcher.exe" = protocol=6 | dir=in | app=d:\program files (x86)\tera - kopie\tera-launcher.exe |
"TCP Query User{C7E7ACB1-B222-43C6-A297-680EC01095E9}C:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe" = protocol=6 | dir=in | app=c:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe |
"TCP Query User{CED1292D-7F33-4A00-B7C6-E298675342C5}C:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe" = protocol=6 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe |
"TCP Query User{D9C86890-97E6-4D21-AD63-5CBCCFCC211F}C:\program files (x86)\warmux\warmux.exe" = protocol=6 | dir=in | app=c:\program files (x86)\warmux\warmux.exe |
"TCP Query User{DC3F0AC3-1122-4853-8AC0-C885E90D474C}D:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe" = protocol=6 | dir=in | app=d:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe |
"TCP Query User{E80510C1-6584-48C3-9B2B-0EB2F3DAC5A6}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"TCP Query User{EB1F7ADD-4165-4A3E-B47F-A0BCE374A2F1}D:\steam\steamapps\itsme258\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=d:\steam\steamapps\itsme258\counter-strike source\hl2.exe |
"TCP Query User{F30A40C9-8B5E-4EBF-845A-43E9AFEB3805}D:\steam\steam.exe" = protocol=6 | dir=in | app=d:\steam\steam.exe |
"TCP Query User{FFF77245-0C75-44DC-BB99-2626A4745483}C:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe |
"UDP Query User{008D68AF-2206-430D-A507-F8EE45013D6F}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{03C6AA6D-90AE-4D82-9686-7E0402BCF90D}C:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe |
"UDP Query User{0F7C9701-E03E-48F5-B177-5C61F71BD12E}D:\steam\steam.exe" = protocol=17 | dir=in | app=d:\steam\steam.exe |
"UDP Query User{136C63DA-3D1D-4225-AF27-B489E3FD634E}C:\program files (x86)\psi\psi.exe" = protocol=17 | dir=in | app=c:\program files (x86)\psi\psi.exe |
"UDP Query User{305085DF-9A30-400B-BA67-0B6815A814E8}C:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe" = protocol=17 | dir=in | app=c:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe |
"UDP Query User{37443BE9-7CEF-440E-A926-C51E185A7DAA}C:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"UDP Query User{39D93847-9B07-4735-A98C-B0D040A1BE25}D:\program files (x86)\tera - kopie\tera-launcher.exe" = protocol=17 | dir=in | app=d:\program files (x86)\tera - kopie\tera-launcher.exe |
"UDP Query User{42428FC1-ED32-4EAB-B8E0-8597A4CCFEEC}C:\users\root\documents\arma 2\expansion\beta\arma2oa.exe" = protocol=17 | dir=in | app=c:\users\root\documents\arma 2\expansion\beta\arma2oa.exe |
"UDP Query User{43DF9178-3930-434B-BA96-CD6F5F440577}C:\program files (x86)\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"UDP Query User{56D43E4D-D546-4DBC-9C47-C00C2133EF89}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"UDP Query User{5FB8585E-BD7F-4770-B65F-98F62B5A2108}C:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe" = protocol=17 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe |
"UDP Query User{8A3C7692-A7B3-4964-AF4B-064A5625CEA0}C:\games\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"UDP Query User{994C31C5-37DA-4C63-9C52-DD79F2C05B64}C:\windows\system32\java.exe" = protocol=17 | dir=in | app=c:\windows\system32\java.exe |
"UDP Query User{9BDF97F3-48B0-46BD-A880-D618627FFF84}D:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe" = protocol=17 | dir=in | app=d:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe |
"UDP Query User{9BE41905-27D0-48A7-A589-71D68383FFDA}C:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe" = protocol=17 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe |
"UDP Query User{A02CA608-B817-4F29-9779-E18E92979897}C:\program files (x86)\warmux\warmux.exe" = protocol=17 | dir=in | app=c:\program files (x86)\warmux\warmux.exe |
"UDP Query User{ABEE0700-4ADF-4251-A010-78FB04A6BCB1}C:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe |
"UDP Query User{C7C203AF-AF35-495C-96A6-77F792294513}C:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe |
"UDP Query User{C9E9E2D7-5595-46C5-A10B-CBD5D8DC8B7A}D:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe" = protocol=17 | dir=in | app=d:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe |
"UDP Query User{E25D2E04-73A6-4BED-BFA2-73DA2B0A7C79}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{E882B72D-243D-43EC-8485-4CFE7313C5D3}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"UDP Query User{ECF2B4A2-70FB-4E67-95A9-846693B534FD}D:\steam\steamapps\itsme258\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=d:\steam\steamapps\itsme258\counter-strike source\hl2.exe |
"UDP Query User{EFC09190-1740-493D-A4CD-D11C269E7415}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{FDD5DDC9-478A-4F87-A2C4-EC22C56AFCA3}D:\program files (x86)\tera\tera-launcher.exe" = protocol=17 | dir=in | app=d:\program files (x86)\tera\tera-launcher.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{26A24AE4-039D-4CA4-87B4-2F86417004FF}" = Java(TM) 7 Update 4 (64-bit)
"{2DF4C5DD-7417-301D-935D-939D3B7B5997}" = Microsoft Help Viewer 1.0 Language Pack - DEU
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{3C983A67-DFB2-3D3D-AD9E-CA1A5A09FD18}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4FF5C7C9-86CC-41ED-B93B-0B51AB4FED24}" = VmciSockets
"{53952792-BF16-300E-ADF2-E7E4367E00CF}" = Visual Studio 2010 Prerequisites - English
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{94D70749-4281-39AC-AD90-B56A0E0A402E}" = Microsoft Visual C++ 2010  x64 Runtime - 10.0.30319
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{A1F50E06-E514-393D-AAEB-2F989F0B7C68}" = Microsoft Team Foundation Server 2010 Object Model - DEU
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 306.97
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{C3EAE456-7E7A-451F-80EF-F34C7A13C558}" = Microsoft SQL Server Compact 3.5 SP2 x64 DEU
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0
"4144-4862-0472-7103" = WorldPainter 0.8.7
"CCleaner" = CCleaner
"Logitech Gaming Software" = Logitech Gaming Software 8.35
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft Help Viewer 1.0 Language Pack - DEU" = Microsoft Help Viewer 1.0 Language Pack - DEU
"Microsoft Team Foundation Server 2010 Object Model - DEU" = Microsoft Team Foundation Server 2010-Objektmodell - DEU
"SecurityKISS Tunnel_is1" = SecurityKISS Tunnel v0.2.2
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Virtual Audio Cable 4.10" = Virtual Audio Cable 4.10
"WinRAR archiver" = WinRAR 4.11 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd
"{0125D081-30D0-4A97-82A8-C28D444B6256}" = Microsoft SQL Server Compact 3.5 SP2 DEU
"{01C79EF3-DE84-4B56-B638-8BEA0D507506}" = Microsoft XNA Game Studio 4.0 (XnaLiveProxy)
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0666E46E-A860-4353-BE6D-13AA72FABB57}" = Microsoft XNA Game Studio Platform Tools
"{08C84CC6-E7FD-4B2D-BBF9-B02CC90EE031}" = Microsoft XNA Game Studio 4.0 (Shared Components)
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}" = VMware Workstation
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{106B4413-ACBB-4CDE-8707-587DB9BD77EC}" = LogMeIn Hamachi
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{147894EE-5ED4-11E1-A8FF-F04DA23A5C58}" = MSVCRT Redists
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{15D44296-62E0-4979-BFF5-1E09ABFE49E0}" = DayZ Commander
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1" = World of Tanks
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool Help
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9
"{2A2F3AE8-246A-4252-BB26-1BEB45627074}" = Microsoft SQL Server System CLR Types
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2C0622F2-2E68-468C-AA43-0CF81D3ACF14}" = Detours Express 3.0
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3F4EB5FE-B5BE-4069-A5A8-6D9262E1B379}" = Microsoft XNA Game Studio 4.0 Documentation
"{42DCB650-F003-4535-A5CD-32AD815CD2DD}" = Play withSIX
"{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C278A1B-D7CA-4F9D-A74D-CB9866EB137A}" = Steganos Password Manager 2012
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{4E968D9C-21A7-4915-B698-F7AEB913541D}" = Microsoft SQL Server 2008 R2 Management Objects
"{520C1D80-935C-42B9-9340-E883849D804F}_is1" = DriverTuner 3.1.0.0
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{59F24743-2EA1-3A45-B8C2-6E0E1E078FA8}" = Microsoft Visual C# 2010 Express - ENU
"{5C5778DB-3E5A-499D-865D-740E67D1F165}" = LogMeIn
"{616C6F39-4CE1-3434-A665-2F6A04C09A7F}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}" = NVIDIA PhysX
"{64BFBE7A-886C-4CA2-A9B4-0C2B5A5942BC}" = Battlefield 3™
"{68BD57D3-D606-411E-A7E0-3EB6EA5660F6}" = Microsoft XNA Game Studio 4.0 (Redists)
"{6A86554B-8928-30E4-A53C-D7337689134D}" = Microsoft Visual C++ 2010  x86 Runtime - 10.0.30319
"{6B2847D2-E3DD-44C0-BAC2-58D12221691F}" = TechSmith Screen Capture Codec
"{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}" = VoiceOver Kit
"{6BE7495E-8DF1-11E1-BB7D-F04DA23A5C58}" = Vegas Pro 11.0
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{6DED41BC-C9EF-4330-B4E5-46CB2C5C6E2D}" = No23 Recorder
"{70CB6C40-8DF1-11E1-BDCF-F04DA23A5C58}" = MSVCRT Redists
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73BE04D9-BA0E-4BAF-9C9D-677278BDB3DC}" = Microsoft XNA Game Studio 4.0 (ARP entry)
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{781B39EC-2E18-41FC-9B00-B84E4FFCA85F}" = ICQ7M
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7E210E1C-52A1-40E3-817B-D504E9F64DFA}_is1" = Flyff
"{7FC7AD70-1DF3-4B84-9AA2-4FB680F45572}_is1" = Hex-Editor MX
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84DEB7DB-5DDD-456f-AEC6-4D09A2D3A75F}_is1" = Citron 2.5
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{894084B6-BC69-43B7-BF06-B93AECFEA520}" = GameSpy Comrade
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C496FBF-DB4A-468D-A3A1-15E127382218}" = Microsoft XNA Game Studio 4.0 (Visual Studio)
"{90877318-0BD0-4BDE-BFC0-C4BB12DAC86A}_is1" = Rappelz
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{969E11AA-8F3A-F162-1A5A-0965E216B6CE}" = Adobe Download Assistant
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D811B72-D54C-47D9-B14B-1506E5E89B50}" = Crysis®3 MP Alpha
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{A2S166A0-F031-4E27-A057-C69733219434}_is1" = TERA
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris
"{ABFBF663-741E-4792-B2E7-04B8E6C0A84B}" = ControlSpy
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch
"{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{BA61C81A-124F-432D-8042-E32E98A9BE97}" = Detours Express 3.0
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BE9C28A5-2098-466E-9F52-1AE9DA155E4F}" = Adobe After Effects CS5.5 Third Party Content
"{C07F8D75-7A8D-400E-A8F9-A3F396B49BB1}" = SPORE™ Süß & Schrecklich Ergänzungs-Pack
"{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
"{CB04D8E1-7B9C-4F35-B2E2-E87CBE520805}" = Adobe After Effects CS5.5
"{CB2B4C2B-0805-4E06-873D-CECB046A5BE8}" = Camtasia Studio 8
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed Help
"{CCAC7E52-ECCE-3C4D-B1BE-BC2ACF1C1C0E}" = Microsoft Visual Basic 2010 Express - DEU
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{CFCB8616-A5D1-4281-80E8-389F685BFAE2}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D5B7B2BB-6B7E-4AD4-9F2F-7CCF2B48AA58}" = Pokemon Game Editor
"{D81641E8-ABF1-3D07-803B-60E8FC619368}" = Microsoft Visual C# 2010 Express - DEU
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DB833EF9-A198-49BE-970A-BD46F30BFBB4}" = ANNO 1503 Königs- Edition
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{dd50af03-2381-49ad-933d-7a30a6ca9e33}" = Nero 9 Essentials
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DEEB5FE3-40F5-3C5B-8F85-5306EF3C08F4}" = Microsoft Visual C++ 2010 Express - DEU
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed Help
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EB9F3F92-4857-4121-AA6F-1C424AC6C266}_is1" = Screen Recording Suite V2.5.0
"{EC66418E-DAA2-36D5-809E-40BEC94E622A}" = Microsoft Visual Studio Macro Tools - DEU Language Pack
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights Help
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
"3ivx MPEG-4 5.0.4" = 3ivx MPEG-4 5.0.4 (remove only)
"4Story_DE_is1" = 4Story DE 3.9.154
"655B116F-5CF5-4376-9A36-9FB163ED609F_is1" = Sonarca Sound Recorder Free 3.8.3
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"APB Reloaded" = APB Reloaded
"aTube Catcher" = aTube Catcher
"Audiograbber" = Audiograbber 1.83 SE
"Audiograbber-Lame" = Audiograbber MP3-Plugin (64 bit)
"AutoHotkey" = AutoHotkey 1.0.48.05
"AutoItv3" = AutoIt v3.3.8.1
"AviSynth" = AviSynth 2.5
"Battlelog Web Plugins" = Battlelog Web Plugins
"BattlEye for OA" = BattlEye for OA Uninstall
"bearsharetoolbarguid" = Search-Results Toolbar
"CamStudio" = CamStudio
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cheat Engine 6.1_is1" = Cheat Engine 6.1
"Cheat Engine 6.2_is1" = Cheat Engine 6.2
"com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)
"DivX Setup" = DivX-Setup
"ESN Sonar-0.70.4" = ESN Sonar
"Flare" = Flare 0.6
"Fraps" = Fraps (remove only)
"Free FLV Converter_is1" = Free FLV Converter V 7.4.0
"Free Video Dub_is1" = Free Video Dub version 2.0.8.504
"Game Booster_is1" = Game Booster 3
"GamersFirst LIVE!" = GamersFirst LIVE!
"GhostMouse_is1" = GhostMouse
"glu" = glu 1.0.22
"GraphicsGale FreeEdition_is1" = GraphicsGale FreeEdition version 1.93.20
"HijackThis" = HijackThis 2.0.2
"iFunbox_is1" = iFunbox (v2.1.2228.731), iFunbox DevTeam
"InstallWIX_{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"lavfilters_is1" = LAV Filters 0.50.5
"LogMeIn Hamachi" = LogMeIn Hamachi
"LOLReplay" = LOLReplay
"Microsoft DirectX SDK (June 2010)" = Microsoft DirectX SDK (June 2010)
"Microsoft Visual Basic 2010 Express - DEU" = Microsoft Visual Basic 2010 Express - DEU
"Microsoft Visual C# 2010 Express - DEU" = Microsoft Visual C# 2010 Express - DEU
"Microsoft Visual C# 2010 Express - ENU" = Microsoft Visual C# 2010 Express - ENU
"Microsoft Visual C++ 2010 Express - DEU" = Microsoft Visual C++ 2010 Express - DEU
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"Microsoft Visual Studio Macro Tools - DEU Language Pack" = Microsoft Visual Studio Macro Tools - DEU Language Pack
"Mozilla Firefox 17.0.1 (x86 de)" = Mozilla Firefox 17.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MySQL-Front_is1" = MySQL-Front
"No23 Recorder" = No23 Recorder
"Notepad++" = Notepad++
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OnlineControl_is1" = OnlineControl 1.2
"OpenAL" = OpenAL
"OpenVPN" = OpenVPN 2.2.2
"Opera 12.11.1661" = Opera 12.11
"Origin" = Origin
"Password Unmask 2.0" = Password Unmask 2.0
"PE Explorer_is1" = PE Explorer 1.99 R6
"Pidgin" = Pidgin
"ProxySwitcher Standard_is1" = ProxySwitcher Standard
"Psi" = Psi (remove only)
"PSP Video 9" = PSP Video 9 6
"PunkBusterSvc" = PunkBuster Services
"Rainmeter" = Rainmeter
"RPGVXAce_E_is1" = RPG MAKER VX Ace
"RPGVXAce_RTP_is1" = RPG MAKER VX Ace RTP
"Sacred Underworld_is1" = Sacred Underworld
"Schriftenbibliothek_is1" = Schriftenbibliothek
"SciTE4AutoIt3" = SciTE4AutoIt3 12/29/2011
"ShiftWindow_is1" = ShiftWindow 1.02
"SpongeBob SquarePants Employee of the Month" = SpongeBob SquarePants Employee of the Month
"StarCraft II" = StarCraft II
"Steam App 211420" = Dark Souls: Prepare to Die Edition
"Steam App 28050" = Deus Ex: Human Revolution
"Steam App 34330" = Total War: SHOGUN 2
"Steam App 6100" = Eets
"SWF Scanner" = SWF Scanner
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.0
"VMware_Workstation" = VMware Workstation
"Warmux" = Warmux
"Winspector - Ultimate Windows Spy Utility_is1" = Winspector
"Wireshark" = Wireshark 1.6.6
"World of Warcraft" = World of Warcraft
"XNA Game Studio 4.0" = Microsoft XNA Game Studio 4.0
"Xvid Video Codec 1.3.2" = Xvid Video Codec
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"244a1e8693fd9c7e" = Techne
"Google Chrome" = Google Chrome
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 15.02.2013 17:00:02 | Computer Name = Systemroot | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: schtasks.exe, Version: 6.1.7601.17514,
 Zeitstempel: 0x4ce79da3  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec4aa8e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000000000009970a
ID
 des fehlerhaften Prozesses: 0x1630  Startzeit der fehlerhaften Anwendung: 0x01ce0bbf6be54790
Pfad
 der fehlerhaften Anwendung: C:\Windows\system32\schtasks.exe  Pfad des fehlerhaften
 Moduls: C:\Windows\SYSTEM32\ntdll.dll  Berichtskennung: a9f894aa-77b2-11e2-8258-c860008cd582
 
Error - 16.02.2013 05:57:50 | Computer Name = Systemroot | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: WLIDSvcM.exe, Version: 6.500.3165.0,
 Zeitstempel: 0x4a8b055b  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec4aa8e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000000000009970a
ID
 des fehlerhaften Prozesses: 0xaa0  Startzeit der fehlerhaften Anwendung: 0x01ce0c2c10885adc
Pfad
 der fehlerhaften Anwendung: C:\Program Files\Common Files\Microsoft Shared\Windows
 Live\WLIDSvcM.exe  Pfad des fehlerhaften Moduls: C:\Windows\SYSTEM32\ntdll.dll  Berichtskennung:
 528c885c-781f-11e2-add2-c860008cd582
 
Error - 17.02.2013 06:47:07 | Computer Name = Systemroot | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: mscorsvw.exe, Version: 4.0.30319.1,
 Zeitstempel: 0x4ba21f5d  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec4aa8e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000000000009970a
ID
 des fehlerhaften Prozesses: 0x10d8  Startzeit der fehlerhaften Anwendung: 0x01ce0cfc20f79ef8
Pfad
 der fehlerhaften Anwendung: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
Pfad
 des fehlerhaften Moduls: C:\Windows\SYSTEM32\ntdll.dll  Berichtskennung: 5f544fad-78ef-11e2-803c-c860008cd582
 
[ System Events ]
Error - 17.02.2013 08:17:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "DATA" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:18:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "D:" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:18:52 | Computer Name = Systemroot | Source = Ntfs | ID = 131
Description = Die Dateisystemstruktur auf Volume "D:" kann nicht korrigiert werden.
Führen
 Sie das Dienstprogramm CHKDSK auf Volume "D:" aus.
 
Error - 17.02.2013 08:18:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "DATA" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:19:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "D:" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:19:52 | Computer Name = Systemroot | Source = Ntfs | ID = 131
Description = Die Dateisystemstruktur auf Volume "D:" kann nicht korrigiert werden.
Führen
 Sie das Dienstprogramm CHKDSK auf Volume "D:" aus.
 
Error - 17.02.2013 08:19:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "DATA" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:20:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "D:" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:20:52 | Computer Name = Systemroot | Source = Ntfs | ID = 131
Description = Die Dateisystemstruktur auf Volume "D:" kann nicht korrigiert werden.
Führen
 Sie das Dienstprogramm CHKDSK auf Volume "D:" aus.
 
Error - 17.02.2013 08:20:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "DATA" den Befehl "chkdsk" aus.
 
 
< End of report >


ryuk 18.02.2013 20:50

extras
Code:

OTL Extras logfile created on: 17.02.2013 13:15:58 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Root\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7.98 Gb Total Physical Memory | 5.58 Gb Available Physical Memory | 69.92% Memory free
15.96 Gb Paging File | 13.73 Gb Available in Paging File | 85.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372.60 Gb Total Space | 201.81 Gb Free Space | 54.16% Space Free | Partition Type: NTFS
Drive D: | 540.23 Gb Total Space | 157.66 Gb Free Space | 29.18% Space Free | Partition Type: NTFS
Drive E: | 100.74 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: SYSTEMROOT | User Name: Root | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- D:\Program Files (x86)\Photoshop\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- D:\Program Files (x86)\Photoshop\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0439A57E-F778-434A-ADAA-3C1E8D6444BB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0C739BDD-93C2-4691-A888-4C9EA63B56FC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{15990194-2BD8-4156-893C-E070592F2800}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1C0FF142-4BB7-4AAD-B267-2122BB975023}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{246A3150-1CAC-4CC3-ADE4-F0D5F8C3F178}" = rport=138 | protocol=17 | dir=out | app=system |
"{36A5B7F2-26D8-447E-B308-9AB1E8C8425D}" = rport=10243 | protocol=6 | dir=out | app=system |
"{3AAF451F-E979-4023-B46A-56E9EFB7E55F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3BA9C3CD-5A50-458E-A769-67D4D0AE8C97}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{426BF746-6B16-4DBC-A361-2208539F2B07}" = lport=56567 | protocol=6 | dir=in | name=pando media booster |
"{44D69EF4-6FD8-4FDA-9DB7-56D03AE9A3D6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4A5219B3-C197-49A4-84E3-7D69D2080933}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4FAAC0B8-7C61-44B4-9EFB-66E21A1BF560}" = lport=10243 | protocol=6 | dir=in | app=system |
"{58FF5002-CCC7-4EE5-A58F-440E1D2CD11C}" = lport=3074 | protocol=17 | dir=in | name=aw3 |
"{5BB322C6-43FF-4BD4-AAFD-D4C11116BE6F}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{5CA8AEA8-E477-45E4-80AA-63F8AF955B56}" = lport=139 | protocol=6 | dir=in | app=system |
"{66BADAFC-86BB-430E-97D8-7FD850FE535F}" = lport=445 | protocol=6 | dir=in | app=system |
"{68A12417-7938-42EB-B3F1-F8A2E50DB488}" = rport=139 | protocol=6 | dir=out | app=system |
"{6D02405C-0A5B-497F-A6E3-B40F21A9F91B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{70B7BE5A-C154-4433-AE75-ABC4B6926F8C}" = lport=56567 | protocol=6 | dir=in | name=pando media booster |
"{72E3EC6D-84C8-484D-AECF-0EFCB22B6B69}" = lport=123 | protocol=17 | dir=in | name=udp |
"{7701055E-C72C-4C49-BBA2-AB6F7C517FDA}" = lport=137 | protocol=17 | dir=in | app=system |
"{89A3BF0E-902F-4609-A159-4CD68E96B777}" = rport=3074 | protocol=6 | dir=out | name=aw34 |
"{91B900E0-FCC2-480F-8B3A-2FABE9BCFC1E}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{92646C34-B24D-4F6B-A70A-F122058E92CD}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{96723A7F-931C-48B5-B574-4321AA0DC8A3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9EBB3907-3AC6-44B9-9B22-6117339D14DF}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A06BC328-3F9C-4023-A29E-7725ECD11C24}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A171F65D-CCFE-4704-B59F-95402CF4877A}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{A28CC37E-703F-46D7-8F9C-D8A305D18B47}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{A670E57B-53FD-464D-92DB-CB988307E582}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AC650E14-C489-46D5-B758-1ECE644F5643}" = lport=138 | protocol=17 | dir=in | app=system |
"{B043957F-210C-4A74-9549-82F1C60DB689}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C6599D56-E95C-41D9-833B-D942DE87C79B}" = lport=3074 | protocol=6 | dir=in | name=aw |
"{CD854E81-83CB-47CA-AFDE-A43F58201741}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DE2E87DC-9965-4539-A1AB-AC391FAFBA49}" = lport=56567 | protocol=17 | dir=in | name=pando media booster |
"{E18C69C3-A85B-4EE3-8905-A609A2C7BEEE}" = lport=7777 | protocol=17 | dir=in | name=terraria2 |
"{E22EEE62-11B3-4306-B6C4-453414823BD1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E6594A62-D678-4ECB-8714-73E0E4AD5065}" = rport=3074 | protocol=17 | dir=out | name=awe |
"{F0BA44E2-A92B-40EE-B812-3B26A5C62E71}" = lport=7777 | protocol=6 | dir=in | name=terraria |
"{F344232C-0225-474B-BA1D-2F110B3B3703}" = rport=445 | protocol=6 | dir=out | app=system |
"{F5A75B57-7CEE-4E7D-8AB6-34E02F2DB317}" = lport=56567 | protocol=17 | dir=in | name=pando media booster |
"{F9A6003C-8D8D-48A9-BEEA-68F805C5EC8E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FF798233-6E4C-44FB-97E6-A62F76145D0D}" = rport=137 | protocol=17 | dir=out | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0274CCBF-C0EF-4DAE-B3AD-C43623143CA8}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\saira\settings.exe |
"{02873699-CDD4-4758-B49B-B730A5EDB2A6}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\ride carnival tycoon\ridecarnivaltycoon.exe |
"{02BE42B7-F39D-46E5-867D-7A15F1D5F84F}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{0446BA9F-F13A-48C4-A59E-769727F4DACE}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\call of duty 4\iw3sp.exe |
"{05164584-C909-468E-B912-5439E96CF2ED}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe |
"{0540E063-4D65-4C45-9582-9E85F9911AF0}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{054A20EB-1EA5-41EE-867B-E027B462D33C}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\hacker evolution untold\hacker evolution untold.exe |
"{06F3B063-0AB0-4F9F-B37A-55D0C74B849D}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\revenge of the titans\revengeofthetitans.exe |
"{084F3503-ADC1-4665-A8AA-C62B5EDE45C0}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{0BC6C1C9-A610-497C-81BC-326EF4B712B2}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\saira\settings.exe |
"{0BC89BA2-C427-4591-96F8-9118C257DC57}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\battlefield 2\support\ea help\electronic_arts_technical_support.htm |
"{0C3BC281-24B5-4F98-A069-CC6708AEF8BB}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{0CEEAEDC-1F0D-4534-88E0-CB8096334542}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{0E000579-2885-4D6B-81DB-1465D66482A1}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{0E3A6992-4F4B-4DFE-A98A-A4E4585AB345}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\defcon\defcon.exe |
"{1048DAF6-9B1D-488B-AEA4-F4EB28921E63}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\zombie shooter 2\zombieshooter2.exe |
"{139B64BB-6A5B-4CFE-ADB2-7F98B1C63EFE}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\bit.trip runner\runner.exe |
"{15AE7777-5A42-4BE7-9C49-4E3A24BF500B}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\jamestown\jamestown.exe |
"{17BEE1C1-DAF4-4231-9D2F-E67CAC4F341F}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\battlefield 2\bf2.exe |
"{1B6750C0-529A-465A-9622-283441B5794D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1BE5CBB6-D0C6-4CC8-B6D9-DB776F49FAAE}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\jamestown\jamestown.exe |
"{1DA0BABF-F91B-4DFA-B3FA-A321BD166A23}" = protocol=6 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe |
"{1F432BAD-31E6-4B29-86E0-308BC5FD9DC8}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\cogs\cogs.exe |
"{200DBFE2-D84D-43A5-AEEE-E1E0B36C21ED}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{21355465-597D-4FBE-B8F4-E3A337D80B01}" = protocol=6 | dir=in | app=c:\users\root\documents\arma 2\expansion\beta\arma2oa.exe |
"{21980604-4283-4625-A668-E407F86E7226}" = protocol=6 | dir=in | app=d:\program files (x86)\gamersfirst\apb reloaded\binaries\apb.exe |
"{21C2983D-5837-417B-A08C-658AD38F8D66}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\faerie solitaire\faeriesolitaire.exe |
"{21D0016D-6B61-4DD2-A62E-1CA07F3E0CD4}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{227F3AFA-E2B6-4A3E-B564-C86A9B4623BC}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\hacker evolution duality\hacker evolution duality.exe |
"{22CB156C-5DE1-405D-AA8A-8A19C47F432B}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{23F929CC-7617-4B44-948C-E36A9C99BE19}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\vvvvvv\vvvvvv.exe |
"{240820DC-2967-4290-9BD3-AE13152C8098}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\bit.trip runner\runner.exe |
"{249AF563-CB17-41C0-8943-2E67C858A67F}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\crayon physics deluxe\launcher.exe |
"{24DDE494-6D41-4416-8AB9-FECF2AA74956}" = protocol=6 | dir=out | app=system |
"{25FCB631-FCE3-4F48-A418-D0F911221B8D}" = protocol=17 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe |
"{2751B081-8107-4B33-A4FA-437FE8CE2335}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{2791B497-E053-4A6B-A9CE-7DDE84402CC4}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\uplink\uplink.exe |
"{287C625C-FFDE-43C1-B0C6-65161D571397}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{28AF3830-0CC4-420D-866D-CA559D690C51}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2A9B23B4-E371-436F-B1A3-6AB34A7830DD}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{2AFB23D7-A37B-43F1-82F8-481B50CD93E8}" = dir=in | app=c:\program files (x86)\apowersoft\screen recording suite\screen-recording-suite.exe |
"{2B9A046F-CA88-46E8-8ECE-D5BD67B0357E}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{2C8DE4CF-CAA2-4B09-B2F6-0470032AB418}" = protocol=6 | dir=in | app=d:\steam\steamapps\itsme258\counter-strike source\hl2.exe |
"{2D67AE1B-D65C-4756-AEC0-24E3A4CB8EDE}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\machinarium\machinarium.exe |
"{2F257971-ECCA-4991-B8CE-B408B64F3A66}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\your doodles are bugged!\yourdoodlesarebugged.exe |
"{3172A4A5-E90A-4D90-9AD9-25EBD86F88F0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{31818FA2-2D31-4F7C-A88E-F800945ECA18}" = protocol=17 | dir=in | app=d:\program files (x86)\tera - kopie\tera-launcher.exe |
"{319AD6FA-9797-47E0-905D-27925D9AC5ED}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\payday the heist\payday_win32_release.exe |
"{33A3136C-3B6E-4698-BE73-9C897CD62AEA}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{3708D12F-AC79-4979-ADA6-CB3885D6003F}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\cogs\cogs.exe |
"{370EAFD5-FF2A-458B-98CE-BAEB15D8D3FD}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\nightsky\nightsky.exe |
"{37CEC898-1F36-4C89-95B7-180477463700}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{384E26BB-44AC-4570-B779-1A91F6D47F91}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\defcon\defcon.exe |
"{387F1DDB-105B-423F-827B-D5FB0F59D376}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"{39FC0F17-DAB8-4677-9694-644394C64086}" = protocol=17 | dir=in | app=c:\program files (x86)\psi\psi.exe |
"{3A51AC3A-5A52-4E7F-8D10-A545E1534E75}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\osmos\osmos.exe |
"{3BB1AFEA-3ABF-43A3-984B-3E7746085AF7}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{3ED25736-684F-4A39-B55C-65579AAF43CF}" = protocol=6 | dir=in | app=d:\steam\steamapps\itsme258\garrysmod\hl2.exe |
"{41919680-A0DC-4F52-AD6F-40678429F295}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{43789E1B-EDD0-4D8A-A56C-9E9C9BEBC8DC}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{467B3ECD-4124-444C-944E-66864B557577}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{488DC317-A2B0-4B7C-AF58-DB9CD2FDE4E3}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\hacker evolution duality\hacker evolution duality.exe |
"{4895AA1C-F7DD-4EDC-A17C-DC057159567D}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |
"{490F62D2-3079-4180-91E6-8D6EAEE93836}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{4961BDF0-5746-4BE9-BEC3-6B37996896AF}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{497FED08-46D7-418F-B1CA-003CEF2144C1}" = protocol=17 | dir=in | app=d:\program files (x86)\gamersfirst\apb reloaded\binaries\apb.exe |
"{4AFAA329-7487-4158-B4D4-3744475B803D}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{4CED581B-8585-462A-BEA2-EB731F3502D7}" = protocol=17 | dir=in | app=d:\program files (x86)\tera\tera-launcher.exe |
"{4D3C088F-BF8C-481C-BD0F-7F8F8F2E6E25}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\dragon age ultimate edition\daoriginslauncher.exe |
"{4EF24508-0EA9-4B8B-9A18-5F84379EF3B2}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\terraria\terraria.exe |
"{512D2596-B52F-4F0B-AE7D-352ECA8D6CEE}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\hammerfight\hammerfight.exe |
"{5131F2B3-17C0-4FCC-B16C-D0CD38BC1916}" = protocol=17 | dir=in | app=d:\origin\crysis 3 mp alpha\bin32\crysis 3 mp alpha.exe |
"{52DE77F2-7131-43D3-B203-99035D25D0A2}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{53949BC2-259F-46CB-AFB8-1098A65C95A7}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\terraria\terraria.exe |
"{5464C83D-C7F0-413E-85F8-277794558A25}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{55B158C1-3C47-45CF-BFAC-ECE3A1C02612}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{55F63C71-1D2C-4AE3-BF08-D4969128802D}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\rainbow six vegas\binaries\runme.exe |
"{561DF159-55A4-46E0-96B1-12511B0E285A}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\call of duty 4\iw3mp.exe |
"{565BA135-3765-44E1-A966-A921D584F010}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\machinarium\machinarium.exe |
"{56BBBBD2-5D23-4643-AEF9-A165C8C512CB}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5750FD25-5E81-43A7-983F-633DBADF7519}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\bully scholarship edition\bully.exe |
"{57B7CCCE-E4DF-41EA-B105-FCA9A37041FD}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\metro 2033\metro2033.exe |
"{58FE3854-2650-457E-B7CC-70B646A40AA5}" = protocol=6 | dir=in | app=d:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe |
"{591804B4-5717-4D1B-A363-5A2E738E24A8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{593417F8-9776-423A-87E2-A0B9E54E3DAC}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{5C32207F-BCA5-4248-8C6C-0438B4369AEE}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\frozen synapse\frozensynapse.exe |
"{5C6F9509-9DF9-4869-A545-444A5D3C2247}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\hacker evolution duality\hacker evolution duality.exe |
"{5CAFCD08-66FF-412D-AA54-72355B653527}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{5CF52534-846E-4BBE-A1DD-9C39CB514F2F}" = protocol=6 | dir=in | app=c:\program files (x86)\warmux\warmux.exe |
"{5DA17866-E9DB-4057-AE48-79C9BFC13811}" = protocol=6 | dir=in | app=c:\program files (x86)\bearshare applications\mediabar\datamngr\srtool~1\dtuser.exe |
"{5EC7DDE5-188B-4DA7-BD14-1612DF7AF7D0}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{5EFB52E4-DD5F-4A0A-BFE6-B18712652535}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"{614D22AB-AA47-4E48-99FF-44182462E4FD}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{61BD5734-F0E5-4E0C-B410-F7DC1BFE17BC}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6379ACB9-FBFB-45E3-85C9-E4783A4198D0}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"{65AD1F77-8FDC-4378-AAC5-4B2E2ED364F5}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\mafia\setup.exe |
"{65C35695-D5A5-4B60-A1EB-847C9CB2A174}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\eets\eets.exe |
"{6670EBE3-9EF3-4FAE-A05B-7260E36BA31F}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\mafia\setup.exe |
"{66A56320-3215-4A2D-9ADB-BA97EFA95A9E}" = protocol=6 | dir=in | app=d:\steam\steamapps\itsme258\bloody good time\bgt.exe |
"{66B6AEE2-AE50-4B65-B3C8-D9ADB238977E}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\saira\saira.exe |
"{6C4ED7D7-C7B0-4EBA-8F3D-08C0AB33C947}" = protocol=6 | dir=in | app=c:\program files (x86)\psi\psi.exe |
"{6C5AFF04-2871-428B-ABA9-B1ACF7F21955}" = protocol=17 | dir=in | app=d:\origin\battlefield 3\bf3.exe |
"{6DE5843F-B96F-4C1B-AD42-D6EEE96BA45B}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\saira\saira.exe |
"{6FE8A48E-E348-4B95-8D7A-ABF2FC670936}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{70EB797D-7F94-49A1-9663-79042AA36BAA}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe |
"{72180012-25A7-49B1-AA22-20D6A1010D5F}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\dragon age ultimate edition\daoriginslauncher.exe |
"{73FA75B6-FB39-4DD1-B4BE-C83A7BAB6DE8}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe |
"{74C3554E-4B01-4C24-BBDC-9BCB08052BB5}" = protocol=6 | dir=in | app=c:\windows\system32\java.exe |
"{75484A20-8F89-42BD-9D98-137159F46AE6}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{7723FB12-E561-40A3-AB67-ADEDC964D6DC}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{78C56B9E-24FB-4811-BD4F-E39B05F514CE}" = protocol=6 | dir=in | app=c:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe |
"{797225E3-667A-404D-AF1D-B271F9768A68}" = protocol=6 | dir=in | app=c:\program files (x86)\proxy switcher standard\proxyswitcher.exe |
"{79B09B81-488E-4289-BEDE-5748C943EC53}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe |
"{7ABCF600-E3D0-4F3D-9A17-4C36A06B6D92}" = protocol=17 | dir=in | app=c:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe |
"{7BC28C8C-39E3-4B03-BACB-78B0759D5176}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\uplink\uplink.exe |
"{7C5665A1-9CB9-45BF-998E-23756649E33C}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{7F631A5E-2075-4888-AE9E-B02A7951CC78}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
"{8046C012-ADF8-4B90-BDD0-02BCF042CC1F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8096F998-A83C-4834-B729-4D1F1ABD567D}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\mafia\game.exe |
"{8194F9F6-0926-47EA-AC2A-1553FFE06D22}" = protocol=17 | dir=in | app=c:\program files (x86)\proxy switcher standard\proxyswitcher.exe |
"{82BB46DB-F50B-4A63-9953-FF2295C8C1A3}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{85EA01FB-F058-4BA9-ABC3-20DF7E995186}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{87E5AC28-B569-4EB7-924E-C4D353C64BAC}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\hacker evolution untold\hacker evolution mod editor.exe |
"{88AE57C2-71A5-4EFD-96EF-2ADC13CCC97C}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\darwinia\darwinia.exe |
"{895297F0-EF68-49B1-84A2-66FD017342C2}" = protocol=58 | dir=in | app=system |
"{8AC21160-3F15-4D90-9A72-6C587695938C}" = dir=in | app=%programfiles%\securitykiss tunnel\securitykisstunnel.exe |
"{8CAB0B54-73A3-4E81-9394-D957756AC31A}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\the binding of isaac\isaac.exe |
"{8D5E0AF5-44AE-4A57-8249-0B08C1C211FE}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\battlefield 2\bf2.exe |
"{8D9C7953-1059-4E7F-8C26-70CDCF243B1D}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\magicka\magicka.exe |
"{8E158EC7-C5D3-4170-9479-F55ED7E2E56A}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{8F2A93DE-3680-47F2-A377-5A26B77CB014}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{8F72D7C5-9977-4847-A40E-DBE339F1F666}" = dir=in | app=c:\program files (x86)\apowersoft\screen recording suite\screenrecordingsuite.exe |
"{8FDCDA0F-9DA6-46EA-9CFB-85E9F4A63B38}" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"{91800F63-E427-4386-8A76-993C95777C64}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"{921AA8A4-ADC0-4594-94D8-99BF1E824B1E}" = protocol=6 | dir=in | app=d:\origin\battlefield 3\bf3.exe |
"{94EB04DE-A984-4C7C-8051-861603EFA1FF}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{952569F5-0B34-4A4E-B336-55BE75ED3DF3}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\frozen synapse\frozensynapse.exe |
"{96C48538-BEAD-4E6C-9B2B-84370D33C7AA}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\swordsandsoldiershd\swords and soldiers launcher.exe |
"{96F9B6FC-0C6E-4BD9-A3AC-7E3B922CC43B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{979DC9A2-3269-4941-B959-793BA73EDC3F}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\hacker evolution untold\hacker evolution untold.exe |
"{98655337-2A8E-473F-AC57-6D7B27C9E313}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"{9976243F-A53F-4FC3-B3F5-DEEC1FBB8269}" = protocol=6 | dir=in | app=d:\program files (x86)\gamersfirst\apb reloaded\binaries\vivoxvoiceservice.exe |
"{9B1E943C-F360-4431-8E45-371E714309E8}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{9C104835-7AEE-4736-B2A8-52B8F73DE8D7}" = protocol=17 | dir=in | app=c:\users\root\documents\arma 2\expansion\beta\arma2oa.exe |
"{9C45355C-2EFD-4C03-82AD-59FF82FF0627}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"{9C5DE694-0B5D-4338-87DF-3D8EBE79007C}" = protocol=17 | dir=in | app=d:\steam\steamapps\itsme258\bloody good time\bgt.exe |
"{9C645DEA-05FE-41CD-8C4E-2B0AC820B04A}" = protocol=6 | dir=in | app=d:\program files (x86)\tera\tera-launcher.exe |
"{9C70D444-ABFA-4C75-A780-424A6BA55BDD}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\and yet it moves\and yet it moves.exe |
"{9CB7CA17-6F5D-406D-8653-D854FB20F8AF}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\sega classics\segagenesisclassics.exe |
"{9D8938EA-94CB-4B93-9AFD-4BEDCE9FFBC8}" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"{9EB463DB-0D25-4166-BC01-078D9580912C}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"{A1A66095-0796-4112-80E9-C52435B2E5ED}" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"{A4D4C1A4-3677-4F1E-84F0-3F9AA77AF80C}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\swordsandsoldiershd\swords and soldiers launcher.exe |
"{A52F0F25-CD48-4BD9-9172-C7AB9C269343}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{A5B96BFF-880B-46F5-B015-13B735056AB0}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{A8B5728D-2C4E-41AF-B3F2-DFB8F077027D}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\payday the heist\payday_win32_release.exe |
"{A93541B9-EDA1-4C6A-A2D3-40D4F558D6B0}" = protocol=17 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe |
"{AB634519-1CC7-4069-8751-5680330A0EB0}" = protocol=6 | dir=in | app=d:\origin\crysis 3 mp alpha\bin32\crysis 3 mp alpha.exe |
"{AC904FE9-43BC-416D-AF09-86CFE7C4B3BF}" = protocol=17 | dir=in | app=d:\steam\steam.exe |
"{AF913184-4EF0-4280-9E30-8C18DF78F4B4}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B0109AC3-B436-49AD-8683-82C5950D3B82}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B22C988F-A4D2-4D45-909D-30AC6607B00A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B28C091F-428B-4A66-9F33-7D08B0643FCC}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\your doodles are bugged!\yourdoodlesarebugged.exe |
"{B421A1C2-9926-4EAF-BDDE-BE2677C7C9D3}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{B42E3CE4-2214-427D-9E8A-3A09B71329F8}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"{B4AC15D8-AB96-4830-B9CE-79352EEEF1ED}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\metro 2033\metro2033.exe |
"{B55DE12C-BE78-4264-8E5E-7E95791F2F3C}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\the binding of isaac\isaac.exe |
"{B7086384-7F29-4E2F-8E7C-0F80A8343DCC}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\vvvvvv\vvvvvv.exe |
"{B756E767-4171-4B17-B875-87D352C38D3E}" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"{B83353EB-124E-44F6-8DD0-258B66A11CE0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B862A80B-2429-4C03-AF5D-128DA7C1F68F}" = protocol=6 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe |
"{BC57D389-C9C6-49B3-91C2-549C518C2CC8}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{BE370A41-1FE4-48F6-B24F-0776A5C52F64}" = protocol=17 | dir=in | app=c:\program files (x86)\warmux\warmux.exe |
"{C0AF0DA5-B2FD-4ECA-A893-2BFEB6FAC6CF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C287C26B-A828-43E6-A109-A21944FE1193}" = protocol=6 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe |
"{C2FE0BC6-A231-4831-9E10-66B5626A678A}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\zombie shooter\zombieshooter.exe |
"{C3E99012-F322-4CCA-BD4B-11D669B345D6}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\hacker evolution untold\hacker evolution mod editor.exe |
"{C43740AB-82D5-474B-ABDC-53E952B17C94}" = protocol=17 | dir=in | app=c:\program files (x86)\bearshare applications\mediabar\datamngr\srtool~1\dtuser.exe |
"{C4FD8624-AAAA-4752-BD3A-CAE65D5E2556}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{C64FE86C-8B9F-4741-8C28-35619CF386B7}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\and yet it moves\and yet it moves.exe |
"{C845F630-D897-4880-AECD-BEEA8EDCDD00}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{C8A300E2-7BC3-4687-BC8C-1F6E93D20F58}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\eets\eets.exe |
"{C9505DA9-4693-47D6-8BBF-5559938E7CBC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{CA161B75-23B7-4D38-AC64-76B357D3C586}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\zombie shooter 2\zombieshooter2.exe |
"{CA1BBBDE-C1FB-410D-86F1-602413C4CF90}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\revenge of the titans\revengeofthetitans.exe |
"{CB0DD9CB-A5EF-43FD-8494-B4D29920B04B}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\dota 2 beta\dota.exe |
"{CB694EE8-F9E4-457B-AC4B-5496AAB4FCF2}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\call of duty 4\iw3mp.exe |
"{CC28745C-4F89-44BD-A72A-A99541D49F71}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{CC6AFBCB-9225-400A-AD30-9FC3442771FC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{CD1D1AF8-3712-46C6-9A44-6CA084DA671D}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\mafia\game.exe |
"{CE1EA41F-57CD-4385-A709-93E71286B8D7}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\sega classics\segagenesisclassics.exe |
"{D0975BC7-419A-4B66-B7AB-8519E427E227}" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"{D0A8F65D-2EDC-482E-8037-7D0654470FE8}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{D238AD07-256D-4C33-B1D5-0575C91723C9}" = protocol=17 | dir=in | app=d:\steam\steamapps\itsme258\counter-strike source\hl2.exe |
"{D28478C4-4579-48C8-9ACC-27639815215C}" = protocol=17 | dir=in | app=d:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe |
"{D490CC74-24CE-46BE-A26D-203F7EAC22B5}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\crayon physics deluxe\launcher.exe |
"{D4D29440-5DF9-4740-9CA5-1747F3A5C78F}" = protocol=17 | dir=in | app=d:\program files (x86)\gamersfirst\apb reloaded\binaries\vivoxvoiceservice.exe |
"{D645ACB6-6F44-4730-9A73-B8C5E7B4AF86}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
"{D6E2FD80-A852-4768-B8A9-38AEEF87AA5D}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{D7E98BE2-A6EC-4A1F-9EF6-9DA61B279117}" = protocol=17 | dir=in | app=c:\windows\system32\java.exe |
"{D8AA2460-C10E-48B3-AC1E-F19048AE28EE}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\faerie solitaire\faeriesolitaire.exe |
"{D90AB94E-C040-464B-A2D2-E6A4CBBAD4A6}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\rainbow six vegas\binaries\runme.exe |
"{DAAD5E21-EB2B-4ADB-9F04-422A3F53800F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DBB4C754-21B4-402F-BC3C-A06F68DACCCF}" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"{DC1C45C0-AD79-4B67-9182-3FB2B27DD6CC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DCE318CC-D9A9-43E5-A101-89CBC41EDE7B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{DEA3E19C-C26D-4A32-9C9B-D9314531CE1A}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\call of duty 4\iw3sp.exe |
"{E0E70AD8-D280-458B-BF3A-DEB6AC7D8CCD}" = protocol=6 | dir=in | app=d:\steam\steam.exe |
"{E23405B1-61FC-4823-BB7B-62F9FEC3715B}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\bully scholarship edition\bully.exe |
"{E3BF47D2-1BDC-48E9-A461-564D541614DF}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{E4331CD0-A6EB-4FCC-9BDD-44B5E6E8A11D}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe |
"{E51FBF71-9621-40F6-AC37-06E25AEC39BF}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |
"{E7129F65-5BF3-41DA-B7FD-CF0817C8AAEE}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\hammerfight\hammerfight.exe |
"{E7EB217C-A5C9-4368-B764-6456E5D44712}" = protocol=6 | dir=in | app=d:\program files (x86)\tera - kopie\tera-launcher.exe |
"{EA034642-E35F-410A-A8DB-8A31F0E01EDD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{EB146ED6-628E-413D-B40E-0298F5C32F50}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\zombie shooter\zombieshooter.exe |
"{EB874236-3166-4518-9568-D28A2602F624}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe |
"{ED218D14-E3A3-4691-82D4-C4B684E9A272}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\magicka\magicka.exe |
"{EDFF83CD-2D07-4E44-98F5-AEB60D47D817}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\darwinia\darwinia.exe |
"{EE7DB023-80C7-46E0-953D-1F8D2C6F5846}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{EFF1DC77-9A45-42BC-849C-84D01BCFDA44}" = protocol=17 | dir=in | app=d:\steam\steamapps\itsme258\garrysmod\hl2.exe |
"{F19410E4-E27D-42D9-BDB2-3E6C53336468}" = protocol=17 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe |
"{F1A01D61-31AB-4EEE-BC53-0968C27372CF}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{F32444E7-D95F-4E32-8DC2-784E2173800B}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\hacker evolution duality\hacker evolution duality.exe |
"{F386A3DD-CA19-413F-84C6-71D19273F7E3}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F3ACFEF1-B99C-429C-94A4-FECB83F37C9E}" = protocol=17 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe |
"{F401CFAD-02B6-4148-9483-E7F3FECAAEFB}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{F628FC0B-A4BA-473B-89E3-3BBBA9204241}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\ride carnival tycoon\ridecarnivaltycoon.exe |
"{F6437B0A-BD07-45D2-96D6-276345F4131B}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\battlefield 2\support\ea help\electronic_arts_technical_support.htm |
"{F7EFC87E-6470-434D-B6FB-D14BBC48B2D9}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7m\icq.exe |
"{F81EA130-EE3A-4A1D-BA76-DD0EF32ABEBF}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\osmos\osmos.exe |
"{F86E60AC-1D41-4774-8855-DD6DDE96AC65}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F89A9FCB-93AA-4B53-BDC2-0D0A77672D2E}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\nightsky\nightsky.exe |
"{FDBEF573-D3EB-488D-A262-A589DFFD7DC1}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FE44B46B-0B35-4373-9E4B-BEB32D54B65C}" = protocol=6 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe |
"{FF310BA4-F045-437C-ABBF-A44FF358C6FA}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\dota 2 beta\dota.exe |
"{FF851D28-B99A-49DE-8C9F-77B9D9D32BE6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{1075CD2D-A097-4677-A315-2BA980D0998C}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"TCP Query User{18380749-5BB4-4F38-8993-88FF8A572BC7}C:\program files (x86)\psi\psi.exe" = protocol=6 | dir=in | app=c:\program files (x86)\psi\psi.exe |
"TCP Query User{29DE6719-C246-40C3-8A4C-C4E31B467E99}C:\users\root\documents\arma 2\expansion\beta\arma2oa.exe" = protocol=6 | dir=in | app=c:\users\root\documents\arma 2\expansion\beta\arma2oa.exe |
"TCP Query User{2E68FD53-87D8-440F-AF39-74ECC5DA7E85}C:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe" = protocol=6 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe |
"TCP Query User{3854B33A-44BA-4493-887E-96D23FAB951C}D:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe" = protocol=6 | dir=in | app=d:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe |
"TCP Query User{3B3CA2D2-7953-48DE-BEDF-E21F6B6CEEDF}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{3D25C8D5-B9E5-4168-983D-20B5E95D9520}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"TCP Query User{4134F468-55B4-40BF-AAF0-D373D1F32B7B}C:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe |
"TCP Query User{4662B24F-93AD-4AFF-ACF8-52E1680F940C}C:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"TCP Query User{66B5B9DD-659C-47AE-9862-FCD3667A6170}D:\program files (x86)\tera\tera-launcher.exe" = protocol=6 | dir=in | app=d:\program files (x86)\tera\tera-launcher.exe |
"TCP Query User{7BA52CD0-ACE5-4182-9DBB-043A29011253}C:\program files (x86)\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"TCP Query User{7D113FD4-4E4B-4D24-943B-2F51E45D9C22}C:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe |
"TCP Query User{83872114-B5CC-42D3-88CB-80804D21226D}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"TCP Query User{84591BC8-D755-4DE5-9E2F-C21479C0EC5D}C:\games\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"TCP Query User{958AC8B0-9F18-4077-A498-1F20CA9C1CAC}C:\windows\system32\java.exe" = protocol=6 | dir=in | app=c:\windows\system32\java.exe |
"TCP Query User{97046C55-237D-49AA-9AFC-BC002FB16831}D:\program files (x86)\tera - kopie\tera-launcher.exe" = protocol=6 | dir=in | app=d:\program files (x86)\tera - kopie\tera-launcher.exe |
"TCP Query User{C7E7ACB1-B222-43C6-A297-680EC01095E9}C:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe" = protocol=6 | dir=in | app=c:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe |
"TCP Query User{CED1292D-7F33-4A00-B7C6-E298675342C5}C:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe" = protocol=6 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe |
"TCP Query User{D9C86890-97E6-4D21-AD63-5CBCCFCC211F}C:\program files (x86)\warmux\warmux.exe" = protocol=6 | dir=in | app=c:\program files (x86)\warmux\warmux.exe |
"TCP Query User{DC3F0AC3-1122-4853-8AC0-C885E90D474C}D:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe" = protocol=6 | dir=in | app=d:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe |
"TCP Query User{E80510C1-6584-48C3-9B2B-0EB2F3DAC5A6}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"TCP Query User{EB1F7ADD-4165-4A3E-B47F-A0BCE374A2F1}D:\steam\steamapps\itsme258\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=d:\steam\steamapps\itsme258\counter-strike source\hl2.exe |
"TCP Query User{F30A40C9-8B5E-4EBF-845A-43E9AFEB3805}D:\steam\steam.exe" = protocol=6 | dir=in | app=d:\steam\steam.exe |
"TCP Query User{FFF77245-0C75-44DC-BB99-2626A4745483}C:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe |
"UDP Query User{008D68AF-2206-430D-A507-F8EE45013D6F}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{03C6AA6D-90AE-4D82-9686-7E0402BCF90D}C:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\sacred.exe |
"UDP Query User{0F7C9701-E03E-48F5-B177-5C61F71BD12E}D:\steam\steam.exe" = protocol=17 | dir=in | app=d:\steam\steam.exe |
"UDP Query User{136C63DA-3D1D-4225-AF27-B489E3FD634E}C:\program files (x86)\psi\psi.exe" = protocol=17 | dir=in | app=c:\program files (x86)\psi\psi.exe |
"UDP Query User{305085DF-9A30-400B-BA67-0B6815A814E8}C:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe" = protocol=17 | dir=in | app=c:\users\root\appdata\local\play withsix\tools\mingw\bin\rsync.exe |
"UDP Query User{37443BE9-7CEF-440E-A926-C51E185A7DAA}C:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"UDP Query User{39D93847-9B07-4735-A98C-B0D040A1BE25}D:\program files (x86)\tera - kopie\tera-launcher.exe" = protocol=17 | dir=in | app=d:\program files (x86)\tera - kopie\tera-launcher.exe |
"UDP Query User{42428FC1-ED32-4EAB-B8E0-8597A4CCFEEC}C:\users\root\documents\arma 2\expansion\beta\arma2oa.exe" = protocol=17 | dir=in | app=c:\users\root\documents\arma 2\expansion\beta\arma2oa.exe |
"UDP Query User{43DF9178-3930-434B-BA96-CD6F5F440577}C:\program files (x86)\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"UDP Query User{56D43E4D-D546-4DBC-9C47-C00C2133EF89}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"UDP Query User{5FB8585E-BD7F-4770-B65F-98F62B5A2108}C:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe" = protocol=17 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\xampp\apache\bin\httpd.exe |
"UDP Query User{8A3C7692-A7B3-4964-AF4B-064A5625CEA0}C:\games\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"UDP Query User{994C31C5-37DA-4C63-9C52-DD79F2C05B64}C:\windows\system32\java.exe" = protocol=17 | dir=in | app=c:\windows\system32\java.exe |
"UDP Query User{9BDF97F3-48B0-46BD-A880-D618627FFF84}D:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe" = protocol=17 | dir=in | app=d:\steam\steamapps\common\arma 2 operation arrowhead - kopie\expansion\beta\arma2oa.exe |
"UDP Query User{9BE41905-27D0-48A7-A589-71D68383FFDA}C:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe" = protocol=17 | dir=in | app=c:\users\root\desktop\all the shit\moar shit\the real shit\xampp\xampp\apache\bin\httpd.exe |
"UDP Query User{A02CA608-B817-4F29-9779-E18E92979897}C:\program files (x86)\warmux\warmux.exe" = protocol=17 | dir=in | app=c:\program files (x86)\warmux\warmux.exe |
"UDP Query User{ABEE0700-4ADF-4251-A010-78FB04A6BCB1}C:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ascaron entertainment\sacred underworld\gameserver.exe |
"UDP Query User{C7C203AF-AF35-495C-96A6-77F792294513}C:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe |
"UDP Query User{C9E9E2D7-5595-46C5-A10B-CBD5D8DC8B7A}D:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe" = protocol=17 | dir=in | app=d:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe |
"UDP Query User{E25D2E04-73A6-4BED-BFA2-73DA2B0A7C79}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{E882B72D-243D-43EC-8485-4CFE7313C5D3}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"UDP Query User{ECF2B4A2-70FB-4E67-95A9-846693B534FD}D:\steam\steamapps\itsme258\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=d:\steam\steamapps\itsme258\counter-strike source\hl2.exe |
"UDP Query User{EFC09190-1740-493D-A4CD-D11C269E7415}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{FDD5DDC9-478A-4F87-A2C4-EC22C56AFCA3}D:\program files (x86)\tera\tera-launcher.exe" = protocol=17 | dir=in | app=d:\program files (x86)\tera\tera-launcher.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{26A24AE4-039D-4CA4-87B4-2F86417004FF}" = Java(TM) 7 Update 4 (64-bit)
"{2DF4C5DD-7417-301D-935D-939D3B7B5997}" = Microsoft Help Viewer 1.0 Language Pack - DEU
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{3C983A67-DFB2-3D3D-AD9E-CA1A5A09FD18}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4FF5C7C9-86CC-41ED-B93B-0B51AB4FED24}" = VmciSockets
"{53952792-BF16-300E-ADF2-E7E4367E00CF}" = Visual Studio 2010 Prerequisites - English
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{94D70749-4281-39AC-AD90-B56A0E0A402E}" = Microsoft Visual C++ 2010  x64 Runtime - 10.0.30319
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{A1F50E06-E514-393D-AAEB-2F989F0B7C68}" = Microsoft Team Foundation Server 2010 Object Model - DEU
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 306.97
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{C3EAE456-7E7A-451F-80EF-F34C7A13C558}" = Microsoft SQL Server Compact 3.5 SP2 x64 DEU
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0
"4144-4862-0472-7103" = WorldPainter 0.8.7
"CCleaner" = CCleaner
"Logitech Gaming Software" = Logitech Gaming Software 8.35
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft Help Viewer 1.0 Language Pack - DEU" = Microsoft Help Viewer 1.0 Language Pack - DEU
"Microsoft Team Foundation Server 2010 Object Model - DEU" = Microsoft Team Foundation Server 2010-Objektmodell - DEU
"SecurityKISS Tunnel_is1" = SecurityKISS Tunnel v0.2.2
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Virtual Audio Cable 4.10" = Virtual Audio Cable 4.10
"WinRAR archiver" = WinRAR 4.11 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd
"{0125D081-30D0-4A97-82A8-C28D444B6256}" = Microsoft SQL Server Compact 3.5 SP2 DEU
"{01C79EF3-DE84-4B56-B638-8BEA0D507506}" = Microsoft XNA Game Studio 4.0 (XnaLiveProxy)
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0666E46E-A860-4353-BE6D-13AA72FABB57}" = Microsoft XNA Game Studio Platform Tools
"{08C84CC6-E7FD-4B2D-BBF9-B02CC90EE031}" = Microsoft XNA Game Studio 4.0 (Shared Components)
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}" = VMware Workstation
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{106B4413-ACBB-4CDE-8707-587DB9BD77EC}" = LogMeIn Hamachi
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{147894EE-5ED4-11E1-A8FF-F04DA23A5C58}" = MSVCRT Redists
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{15D44296-62E0-4979-BFF5-1E09ABFE49E0}" = DayZ Commander
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1" = World of Tanks
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool Help
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9
"{2A2F3AE8-246A-4252-BB26-1BEB45627074}" = Microsoft SQL Server System CLR Types
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2C0622F2-2E68-468C-AA43-0CF81D3ACF14}" = Detours Express 3.0
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3F4EB5FE-B5BE-4069-A5A8-6D9262E1B379}" = Microsoft XNA Game Studio 4.0 Documentation
"{42DCB650-F003-4535-A5CD-32AD815CD2DD}" = Play withSIX
"{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C278A1B-D7CA-4F9D-A74D-CB9866EB137A}" = Steganos Password Manager 2012
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{4E968D9C-21A7-4915-B698-F7AEB913541D}" = Microsoft SQL Server 2008 R2 Management Objects
"{520C1D80-935C-42B9-9340-E883849D804F}_is1" = DriverTuner 3.1.0.0
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{59F24743-2EA1-3A45-B8C2-6E0E1E078FA8}" = Microsoft Visual C# 2010 Express - ENU
"{5C5778DB-3E5A-499D-865D-740E67D1F165}" = LogMeIn
"{616C6F39-4CE1-3434-A665-2F6A04C09A7F}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}" = NVIDIA PhysX
"{64BFBE7A-886C-4CA2-A9B4-0C2B5A5942BC}" = Battlefield 3™
"{68BD57D3-D606-411E-A7E0-3EB6EA5660F6}" = Microsoft XNA Game Studio 4.0 (Redists)
"{6A86554B-8928-30E4-A53C-D7337689134D}" = Microsoft Visual C++ 2010  x86 Runtime - 10.0.30319
"{6B2847D2-E3DD-44C0-BAC2-58D12221691F}" = TechSmith Screen Capture Codec
"{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}" = VoiceOver Kit
"{6BE7495E-8DF1-11E1-BB7D-F04DA23A5C58}" = Vegas Pro 11.0
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{6DED41BC-C9EF-4330-B4E5-46CB2C5C6E2D}" = No23 Recorder
"{70CB6C40-8DF1-11E1-BDCF-F04DA23A5C58}" = MSVCRT Redists
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73BE04D9-BA0E-4BAF-9C9D-677278BDB3DC}" = Microsoft XNA Game Studio 4.0 (ARP entry)
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{781B39EC-2E18-41FC-9B00-B84E4FFCA85F}" = ICQ7M
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7E210E1C-52A1-40E3-817B-D504E9F64DFA}_is1" = Flyff
"{7FC7AD70-1DF3-4B84-9AA2-4FB680F45572}_is1" = Hex-Editor MX
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84DEB7DB-5DDD-456f-AEC6-4D09A2D3A75F}_is1" = Citron 2.5
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{894084B6-BC69-43B7-BF06-B93AECFEA520}" = GameSpy Comrade
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C496FBF-DB4A-468D-A3A1-15E127382218}" = Microsoft XNA Game Studio 4.0 (Visual Studio)
"{90877318-0BD0-4BDE-BFC0-C4BB12DAC86A}_is1" = Rappelz
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{969E11AA-8F3A-F162-1A5A-0965E216B6CE}" = Adobe Download Assistant
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D811B72-D54C-47D9-B14B-1506E5E89B50}" = Crysis®3 MP Alpha
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{A2S166A0-F031-4E27-A057-C69733219434}_is1" = TERA
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris
"{ABFBF663-741E-4792-B2E7-04B8E6C0A84B}" = ControlSpy
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch
"{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{BA61C81A-124F-432D-8042-E32E98A9BE97}" = Detours Express 3.0
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BE9C28A5-2098-466E-9F52-1AE9DA155E4F}" = Adobe After Effects CS5.5 Third Party Content
"{C07F8D75-7A8D-400E-A8F9-A3F396B49BB1}" = SPORE™ Süß & Schrecklich Ergänzungs-Pack
"{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
"{CB04D8E1-7B9C-4F35-B2E2-E87CBE520805}" = Adobe After Effects CS5.5
"{CB2B4C2B-0805-4E06-873D-CECB046A5BE8}" = Camtasia Studio 8
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed Help
"{CCAC7E52-ECCE-3C4D-B1BE-BC2ACF1C1C0E}" = Microsoft Visual Basic 2010 Express - DEU
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{CFCB8616-A5D1-4281-80E8-389F685BFAE2}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D5B7B2BB-6B7E-4AD4-9F2F-7CCF2B48AA58}" = Pokemon Game Editor
"{D81641E8-ABF1-3D07-803B-60E8FC619368}" = Microsoft Visual C# 2010 Express - DEU
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DB833EF9-A198-49BE-970A-BD46F30BFBB4}" = ANNO 1503 Königs- Edition
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{dd50af03-2381-49ad-933d-7a30a6ca9e33}" = Nero 9 Essentials
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DEEB5FE3-40F5-3C5B-8F85-5306EF3C08F4}" = Microsoft Visual C++ 2010 Express - DEU
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed Help
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EB9F3F92-4857-4121-AA6F-1C424AC6C266}_is1" = Screen Recording Suite V2.5.0
"{EC66418E-DAA2-36D5-809E-40BEC94E622A}" = Microsoft Visual Studio Macro Tools - DEU Language Pack
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights Help
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2 = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
008 Redistributable - x86 9.0.21022
"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
"3ivx MPEG-4 5.0.4" = 3ivx MPEG-4 5.0.4 (remove only)
"4Story_DE_is1" = 4Story DE 3.9.154
"655B116F-5CF5-4376-9A36-9FB163ED609F_is1" = Sonarca Sound Recorder Free 3.8.3
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"APB Reloaded" = APB Reloaded
"aTube Catcher" = aTube Catcher
"Audiograbber" = Audiograbber 1.83 SE
"Audiograbber-Lame" = Audiograbber MP3-Plugin (64 bit)
"AutoHotkey" = AutoHotkey 1.0.48.05
"AutoItv3" = AutoIt v3.3.8.1
"AviSynth" = AviSynth 2.5
"Battlelog Web Plugins" = Battlelog Web Plugins
"BattlEye for OA" = BattlEye for OA Uninstall
"bearsharetoolbarguid" = Search-Results Toolbar
"CamStudio" = CamStudio
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cheat Engine 6.1_is1" = Cheat Engine 6.1
"Cheat Engine 6.2_is1" = Cheat Engine 6.2
"com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)
"DivX Setup" = DivX-Setup
"ESN Sonar-0.70.4" = ESN Sonar
"Flare" = Flare 0.6
"Fraps" = Fraps (remove only)
"Free FLV Converter_is1" = Free FLV Converter V 7.4.0
"Free Video Dub_is1" = Free Video Dub version 2.0.8.504
"Game Booster_is1" = Game Booster 3
"GamersFirst LIVE!" = GamersFirst LIVE!
"GhostMouse_is1" = GhostMouse
"glu" = glu 1.0.22
"GraphicsGale FreeEdition_is1" = GraphicsGale FreeEdition version 1.93.20
"HijackThis" = HijackThis 2.0.2
"iFunbox_is1" = iFunbox (v2.1.2228.731), iFunbox DevTeam
"InstallWIX_{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"lavfilters_is1" = LAV Filters 0.50.5
"LogMeIn Hamachi" = LogMeIn Hamachi
"LOLReplay" = LOLReplay
"Microsoft DirectX SDK (June 2010)" = Microsoft DirectX SDK (June 2010)
"Microsoft Visual Basic 2010 Express - DEU" = Microsoft Visual Basic 2010 Express - DEU
"Microsoft Visual C# 2010 Express - DEU" = Microsoft Visual C# 2010 Express - DEU
"Microsoft Visual C# 2010 Express - ENU" = Microsoft Visual C# 2010 Express - ENU
"Microsoft Visual C++ 2010 Express - DEU" = Microsoft Visual C++ 2010 Express - DEU
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"Microsoft Visual Studio Macro Tools - DEU Language Pack" = Microsoft Visual Studio Macro Tools - DEU Language Pack
"Mozilla Firefox 17.0.1 (x86 de)" = Mozilla Firefox 17.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MySQL-Front_is1" = MySQL-Front
"No23 Recorder" = No23 Recorder
"Notepad++" = Notepad++
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OnlineControl_is1" = OnlineControl 1.2
"OpenAL" = OpenAL
"OpenVPN" = OpenVPN 2.2.2
"Opera 12.11.1661" = Opera 12.11
"Origin" = Origin
"Password Unmask 2.0" = Password Unmask 2.0
"PE Explorer_is1" = PE Explorer 1.99 R6
"Pidgin" = Pidgin
"ProxySwitcher Standard_is1" = ProxySwitcher Standard
"Psi" = Psi (remove only)
"PSP Video 9" = PSP Video 9 6
"PunkBusterSvc" = PunkBuster Services
"Rainmeter" = Rainmeter
"RPGVXAce_E_is1" = RPG MAKER VX Ace
"RPGVXAce_RTP_is1" = RPG MAKER VX Ace RTP
"Sacred Underworld_is1" = Sacred Underworld
"Schriftenbibliothek_is1" = Schriftenbibliothek
"SciTE4AutoIt3" = SciTE4AutoIt3 12/29/2011
"ShiftWindow_is1" = ShiftWindow 1.02
"SpongeBob SquarePants Employee of the Month" = SpongeBob SquarePants Employee of the Month
"StarCraft II" = StarCraft II
"Steam App 211420" = Dark Souls: Prepare to Die Edition
"Steam App 28050" = Deus Ex: Human Revolution
"Steam App 34330" = Total War: SHOGUN 2
"Steam App 6100" = Eets
"SWF Scanner" = SWF Scanner
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.0
"VMware_Workstation" = VMware Workstation
"Warmux" = Warmux
"Winspector - Ultimate Windows Spy Utility_is1" = Winspector
"Wireshark" = Wireshark 1.6.6
"World of Warcraft" = World of Warcraft
"XNA Game Studio 4.0" = Microsoft XNA Game Studio 4.0
"Xvid Video Codec 1.3.2" = Xvid Video Codec
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"244a1e8693fd9c7e" = Techne
"Google Chrome" = Google Chrome
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 15.02.2013 17:00:02 | Computer Name = Systemroot | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: schtasks.exe, Version: 6.1.7601.17514,
 Zeitstempel: 0x4ce79da3  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec4aa8e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000000000009970a
ID
 des fehlerhaften Prozesses: 0x1630  Startzeit der fehlerhaften Anwendung: 0x01ce0bbf6be54790
Pfad
 der fehlerhaften Anwendung: C:\Windows\system32\schtasks.exe  Pfad des fehlerhaften
 Moduls: C:\Windows\SYSTEM32\ntdll.dll  Berichtskennung: a9f894aa-77b2-11e2-8258-c860008cd582
 
Error - 16.02.2013 05:57:50 | Computer Name = Systemroot | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: WLIDSvcM.exe, Version: 6.500.3165.0,
 Zeitstempel: 0x4a8b055b  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec4aa8e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000000000009970a
ID
 des fehlerhaften Prozesses: 0xaa0  Startzeit der fehlerhaften Anwendung: 0x01ce0c2c10885adc
Pfad
 der fehlerhaften Anwendung: C:\Program Files\Common Files\Microsoft Shared\Windows
 Live\WLIDSvcM.exe  Pfad des fehlerhaften Moduls: C:\Windows\SYSTEM32\ntdll.dll  Berichtskennung:
 528c885c-781f-11e2-add2-c860008cd582
 
Error - 17.02.2013 06:47:07 | Computer Name = Systemroot | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: mscorsvw.exe, Version: 4.0.30319.1,
 Zeitstempel: 0x4ba21f5d  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec4aa8e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000000000009970a
ID
 des fehlerhaften Prozesses: 0x10d8  Startzeit der fehlerhaften Anwendung: 0x01ce0cfc20f79ef8
Pfad
 der fehlerhaften Anwendung: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
Pfad
 des fehlerhaften Moduls: C:\Windows\SYSTEM32\ntdll.dll  Berichtskennung: 5f544fad-78ef-11e2-803c-c860008cd582
 
[ System Events ]
Error - 17.02.2013 08:17:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "DATA" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:18:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "D:" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:18:52 | Computer Name = Systemroot | Source = Ntfs | ID = 131
Description = Die Dateisystemstruktur auf Volume "D:" kann nicht korrigiert werden.
Führen
 Sie das Dienstprogramm CHKDSK auf Volume "D:" aus.
 
Error - 17.02.2013 08:18:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "DATA" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:19:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "D:" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:19:52 | Computer Name = Systemroot | Source = Ntfs | ID = 131
Description = Die Dateisystemstruktur auf Volume "D:" kann nicht korrigiert werden.
Führen
 Sie das Dienstprogramm CHKDSK auf Volume "D:" aus.
 
Error - 17.02.2013 08:19:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "DATA" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:20:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "D:" den Befehl "chkdsk" aus.
 
Error - 17.02.2013 08:20:52 | Computer Name = Systemroot | Source = Ntfs | ID = 131
Description = Die Dateisystemstruktur auf Volume "D:" kann nicht korrigiert werden.
Führen
 Sie das Dienstprogramm CHKDSK auf Volume "D:" aus.
 
Error - 17.02.2013 08:20:52 | Computer Name = Systemroot | Source = Ntfs | ID = 262199
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen
 Sie auf dem Volume "DATA" den Befehl "chkdsk" aus.
 
 
< End of report >


markusg 18.02.2013 20:59

Hi,
otl fix

Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.

Code:

:OTL
CHR - homepage: hxxp://search.bearshare.net
CHR - default_search_provider: Search Results (Enabled)
CHR - homepage: hxxp://search.bearshare.net
:files
:Commands
[emptytemp]

  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread


Starte neu, teste, wie der PC läuft.
Programme Wie Browser, vom Firefox, über Internetexplorer, auf ungewollte Toolbars und weiterleitung bzw sonstige Probleme testen.
Teste auch sonstige Programme.

ryuk 18.02.2013 21:12

Code:

All processes killed
========== OTL ==========
Use Chrome's Settings page to change the HomePage.
Use Chrome's Settings page to remove the default_search_provider items.
Use Chrome's Settings page to change the HomePage.
========== FILES ==========
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Kabraxis
->Temp folder emptied: 0 bytes
 
User: LogMeInRemoteUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: Root
->Temp folder emptied: 2702513 bytes
->Temporary Internet Files folder emptied: 2325711 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 9589992 bytes
->Opera cache emptied: 60507481 bytes
->Flash cache emptied: 882 bytes
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10587 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 72.00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 02182013_210650

Files\Folders moved on Reboot...
C:\Users\Root\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Windows\temp\vmware-SYSTEM-2874014982\vmauthd.log moved successfully.
C:\Windows\temp\vmware-SYSTEM-2874014982\vmware-usbarb-SYSTEM-2280.log moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

die log vom fix, für heute mache ich erstmal schluss, werde mich morgen nochmal melden ob noch weitere probleme auftreten.

markusg 18.02.2013 21:13

ok wir müssen das gerät nämlich noch absichern.

ryuk 19.02.2013 15:03

okay, scheinbar ist jetzt alles wie es sein sollte.

markusg 19.02.2013 17:02

Hi,
otl öffnen, bereinigen, pc startet neu, remover werden gelöscht.
Lösche übrig gebliebene Remover, Setups, Logs, leere den Papierkorb.

PC absichern:

http://www.trojaner-board.de/96344-a...-rechners.html
Starte bitte mit der Passage, Windows Vista und Windows 7
Bitte beginne damit, Windows Updates zu instalieren.
Am besten geht dies, wenn du über Start, Suchen gehst, und dort Windows Updates eingibst.
Prüfe unter "Einstellungen ändern" dass folgendes ausgewählt ist:
- Updates automatisch Instalieren,
- Täglich
- Uhrzeit wählen
- Bitte den gesammten rest anhaken, außer:
- detailierte benachichtungen anzeigen, wenn neue Microsoft software verfügbar ist.
Klicke jetzt die Schaltfläche "OK"
Klicke jetzt "nach Updates suchen".
Bitte instaliere zunächst wichtige Updates.
Es wird nötig sein, den PC zwischendurch neu zu starten. falls dies der Fall ist, musst du erneut über Start, Suchen, Windows Update aufrufen, auf Updates suchen klicken und die nächsten instalieren.
Mache das selbe bitte mit den optionalen Updates.
Bitte übernimm den rest so, wie es im Abschnitt windows 7 / Vista zu lesen ist.
aus dem Abschnitt xp, bitte den punkt "datenausführungsverhinderung, dep" übernehmen.
als browser rate ich dir zu chrome:
Installation von Google Chrome für mehrere Nutzerkonten - Google Chrome-Hilfe
anleitung lesen bitte
falls du nen andern nutzen willst, sags mir dann muss ich teile der nun folgenden anleitung anpassen.


Sandboxie
Die devinition einer Sandbox ist hier nachzulesen:
Sandbox
Kurz gesagt, man kann Programme fast 100 %ig isuliert vom System ausführen.

Der Vorteil liegt klar auf der Hand, wenn über den Browser Schadcode eingeschläust wird, kann dieser nicht nach außen dringen.
Download Link:
Sandboxie - Download - Filepony

anleitung:
http://www.trojaner-board.de/71542-a...sandboxie.html
ausführliche anleitung als pdf, auch abarbeiten:
Sandbox Einstellungen |

bitte folgende zusatz konfiguration machen:
sandboxie control öffnen, menü sandbox anklicken, defauldbox wählen.
dort klicke auf sandbox einstellungen.
beschrenkungen, bei programm start und internet zugriff schreibe:
chrome.exe
dann gehe auf anwendungen, webbrowser, chrome.
dort aktiviere alles außer gesammten profil ordner freigeben.
Wie du evtl. schon gesehen hast, kannst du einige Funktionen nicht nutzen.
Dies ist nur in der Vollversion nötig, zu deren Kauf ich dir rate.
Du kannst zb unter "Erzwungene Programmstarts" festlegen, dass alle Browser in der Sandbox starten.
Ansonsten musst du immer auf "Sandboxed webbrowser" klicken bzw Rechtsklick, in Sandboxie starten.
Eine lebenslange Lizenz kostet 30 €, und ist auf allen deinen PC's nutzbar.

Weiter mit:
Maßnahmen für ALLE Windows-Versionen
alles komplett durcharbeiten
anmerkung zu file hippo.
in den settings zusätzlich auswählen:
hide beta updates.
Run updateChecker when Windows starts

Backup Programm:
in meiner Anleitung ist bereits ein Backup Programm verlinkt, als Alternative bietet sich auch das Windows eigene Backup Programm an:
http://www.trojaner-board.de/82962-w...en-backup.html
Dies ist aber leider nur für Windows 7 Nutzer vernünftig nutzbar.
Alle Anderen sollten sich aber auf jeden fall auch ein Backup Programm instalieren, denn dies kann unter Umständen sehr wichtig sein, zum Beispiel, wenn die Festplatte einmal kaputt ist.

Zum Schluss, die allgemeinen sicherheitstipps beachten, wenn es dich betrifft, den Tipp zum Onlinebanking beachten und alle Passwörter ändern
bitte auch lesen, wie mache ich programme für alle sichtbar:
Programme für alle Konten nutzbar machen - PCtipp.ch - Praxis & Hilfe
surfe jetzt also nur noch im standard nutzer konto und dort in der sandbox.
wenn du die kostenlose version nutzt, dann mit klick auf sandboxed web browser, wenn du die bezahlversion hast, kannst du erzwungene programm starts festlegen, dann wird sandboxie immer gestartet wenn du nen browser aufrufst.
wenn du mit der maus über den browser fährst sollte der eingerahmt sein, dann bist du im sandboxed web browser

passwort sicherheit:
jeder dienst benötigt ein eigenes, mindestens 12-stelliges passwort
bei der passwort verwaltung und erstellung hilft roboform
Passwort Manager, Formular Ausfueller, Passwort Management | RoboForm Passwort Manager
anleitung:
RoboForm-Bedienungsanleitung: Passwort-Manager, Verwalten von Passwörtern und persönlichen Daten


Alle Zeitangaben in WEZ +1. Es ist jetzt 02:36 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19