|
Log-Analyse und Auswertung: Win7 - Regelmäßige SystemabstürzeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
14.04.2014, 17:17 | #1 |
| Win7 - Regelmäßige Systemabstürze Hey, seit gar nicht mal so langer Zeit stürzt mein PC regelmäßig ab. Das äußert sich dann meistens so, dass zuerst meine Internetverbindung verschwindet, kurz darauf meine Tastatur hängt (wenn ich gerade etwas schreibe und ich z.B. die Taste "a" zuletzt gedrückt habe, hängt die Tastatur da quasi und schreibt "aaaaaaaaaaaaaaaa" o.ä.) und / oder meine Maus hakt, bis ich dann weder etwas bewegen, noch sonst etwas tun kann. Musik etc. wird dann auch angehalten, der Rechner stürzt also komplett ab und ich kann ihn nur mit einem Hard Reset neustarten. Während ich den GMER habe scannen lassen, habe ich übrigens auch seit Ewigkeiten mal wieder einen Bluescreen mit der Beschreibung IRQL_NOT_LESS_OR_EQUAL bekommen. Das letzte mal sind mir diese Bluescreens mit meiner alten Grafikkarte sehr oft begegnet. Zu dem Zeitpunkt hatte ich die Vermutung, dass die Treiber von Nvidia einfach schlecht waren, da es erst seit einem Treiberupdate vorgekommen ist. Ich habe mir dann nach langem hin-und-her mit dem Nvidia-Support eine neue Grafikkarte gekauft und dann war alles gut. Defogger hat keine Fehlermeldung ausgegeben, also poste ich den Log nicht (?). FRST64 gibt folgendes aus: FRST.txt Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-04-2014 01 Ran by Deep (administrator) on BENS-TEN on 14-04-2014 17:57:10 Running from C:\Users\Deep\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Users\Deep\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Spotify Ltd) C:\Users\Deep\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Dropbox, Inc.) C:\Users\Deep\AppData\Roaming\Dropbox\bin\Dropbox.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (Adobe Systems Inc.) E:\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (CyberLink Corp.) E:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\Cyberlink\Shared files\brs.exe () E:\Program Files (x86)\Drakonia Configurator\hid.exe () E:\Program Files (x86)\Drakonia Configurator\trayicon.exe (TeamSpeak Systems GmbH) E:\Program Files\TeamSpeak\ts3client_win64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Valve Corporation) D:\Steam\Steam.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-03] (Adobe Systems Incorporated) HKLM\...\Run: [BCSSync] => E:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8292120 2013-11-14] (Logitech Inc.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation) HKLM-x32\...\Run: [avgnt] => E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => E:\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2013-12-18] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => E:\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2013-12-18] (Adobe Systems Inc.) HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-27] (Intel Corporation) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-08-09] (VIA) HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [RemoteControl10] => E:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe [87336 2011-03-30] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2011-09-28] (cyberlink) HKLM-x32\...\Run: [UCam_Menu] => E:\Program Files (x86)\Cyberlink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [GamingMouse] => E:\Program Files (x86)\Drakonia Configurator\hid.exe [248832 2013-10-29] () HKU\S-1-5-19\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation) HKU\S-1-5-20\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation) HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\Run: [Spotify Web Helper] => C:\Users\Deep\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-05] (Spotify Ltd) HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\Run: [Google Update] => C:\Users\Deep\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-02-06] (Google Inc.) HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\MountPoints2: G - G:\pushinst.exe HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\MountPoints2: H - H:\pushinst.exe HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\MountPoints2: {feb4d95f-27ed-11e3-88da-806e6f6e6963} - F:\CDSETUP.EXE Startup: C:\Users\Deep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Deep\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - E:\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default FF Homepage: hxxp://www.facebook.com/ FF Keyword.URL: hxxp://www.google.com/search?sourceid=navclient&hl=de&q= FF NetworkProxy: "ftp", "95.211.129.32" FF NetworkProxy: "ftp_port", 3128 FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "95.211.129.32" FF NetworkProxy: "socks_port", 3128 FF NetworkProxy: "ssl", "95.211.129.32" FF NetworkProxy: "ssl_port", 3128 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Acrobat - E:\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Deep\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Deep\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Deep\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Deep\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin ProgramFiles/Appdata: C:\Users\Deep\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Deep\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\googlede-pws.xml FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\leo-fra-deu.xml FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\youtube-videosuche.xml FF Extension: Разпознаване на устройство Logitech - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\DeviceDetection@logitech.com [2013-06-30] FF Extension: ProxTube - Unblock YouTube - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7} [2013-12-05] FF Extension: ChatZilla - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2013-07-15] FF Extension: WOT - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-27] FF Extension: DownloadHelper - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-28] FF Extension: Firebug - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\firebug@software.joehewitt.com.xpi [2013-06-30] FF Extension: Grooveshark Unlocker - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2013-06-30] FF Extension: Stealthy - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\stealthyextension@gmail.com.xpi [2013-06-30] FF Extension: Ask Toolbar - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\toolbar_CLM-V7@apn.ask.com.xpi [2013-06-17] FF Extension: Flagfox - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-16] FF Extension: NoScript - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-30] FF Extension: SoundCloud Downloader - Technowise - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{c8d3bc80-0810-4d21-a2c2-be5f2b2832ac}.xpi [2013-06-30] FF Extension: Adblock Plus - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-30] FF Extension: Tab Mix Plus - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-06-30] FF Extension: Greasemonkey - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013-06-30] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - E:\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - E:\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-07-01] FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - E:\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} FF Extension: Adobe Contribute Toolbar - E:\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2013-07-01] FF StartMenuInternet: FIREFOX.EXE - E:\Program Files (x86)\Mozilla Firefox\firefox.exe Chrome: ======= CHR Extension: (Adblock Plus) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-27] CHR Extension: (Foxish live RSS) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgagcapnkccceppgljfpoadahaopjdb [2014-03-02] CHR Extension: (Google Wallet) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-13] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S2 CLKMSVC10_F47B619C; E:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-04-20] (CyberLink) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-09] () R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2013-12-09] () S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-03] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-14] (Avira Operations GmbH & Co. KG) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-22] (AVM GmbH) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-12-08] () R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [42016 2013-11-27] (Visicom Media Inc.) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35232 2013-12-06] (Visicom Media Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) R3 umpusbvista; C:\Windows\System32\DRIVERS\umpusbvista.sys [64872 2012-09-13] (Texas Instruments Inc) S3 vhidmini; C:\Windows\System32\DRIVERS\vjoy.sys [15544 2013-04-18] (Headsoft) R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [231112 2013-01-03] (VIA Technologies, Inc.) S3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [35344 2014-01-23] () R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [301256 2013-01-03] (VIA Technologies, Inc.) S3 dgderdrv; System32\drivers\dgderdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-14 17:56 - 2014-04-14 17:57 - 00023089 _____ () C:\Users\Deep\Desktop\FRST.txt 2014-04-14 17:55 - 2014-04-14 17:55 - 02157568 _____ (Farbar) C:\Users\Deep\Downloads\FRST64.exe 2014-04-14 17:55 - 2014-04-14 17:55 - 02157568 _____ (Farbar) C:\Users\Deep\Desktop\FRST64.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00050477 _____ () C:\Users\Deep\Downloads\Defogger.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00050477 _____ () C:\Users\Deep\Desktop\Defogger.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00000470 _____ () C:\Users\Deep\Desktop\defogger_disable.log 2014-04-14 17:50 - 2014-04-14 17:50 - 00000000 _____ () C:\Users\Deep\defogger_reenable 2014-04-12 18:07 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-04-12 18:07 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-04-12 18:04 - 2014-04-14 17:48 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-12 18:04 - 2014-04-12 18:06 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA 2014-04-12 18:04 - 2014-04-02 15:27 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-12 18:04 - 2014-04-02 15:27 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-04-12 18:04 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-04-12 18:03 - 2014-03-04 16:35 - 00062408 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-04-12 18:03 - 2014-03-04 16:35 - 00054216 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-04-12 18:03 - 2014-03-04 15:06 - 06714312 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-04-12 18:03 - 2014-03-04 15:06 - 03497816 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 03649185 _____ () C:\Windows\system32\nvcoproc.bin 2014-04-12 18:03 - 2014-03-04 15:05 - 02558808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 00922968 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-04-12 18:03 - 2014-03-04 15:05 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 00064968 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-04-12 18:02 - 2014-03-21 21:43 - 00037320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 18302384 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 14709720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-04-12 18:02 - 2014-03-04 16:35 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 03093280 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02715264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00947808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00832936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00484296 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00409544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00377688 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00333600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00024544 _____ () C:\Windows\system32\nvinfo.pb 2014-04-12 18:02 - 2013-11-28 15:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-04-12 18:02 - 2013-11-28 15:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-04-12 18:02 - 2013-11-22 10:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2014-04-12 18:01 - 2014-04-12 18:01 - 00000000 ____D () C:\NVIDIA 2014-04-12 17:57 - 2014-04-14 17:48 - 00003557 _____ () C:\Windows\setupact.log 2014-04-12 17:57 - 2014-04-12 17:57 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-12 17:45 - 2014-04-12 22:17 - 00000000 ____D () C:\Windows\System32\Tasks\Aufgaben der Ereignisanzeige 2014-04-12 17:41 - 2014-04-12 17:41 - 00143170 _____ () C:\Users\Deep\Desktop\cc_20140412_174133.reg 2014-04-11 20:51 - 2014-04-11 20:51 - 00000000 ____D () C:\Users\Deep\Documents\Gaslamp Games 2014-04-11 17:20 - 2014-04-14 17:52 - 00559968 _____ () C:\Windows\WindowsUpdate.log 2014-04-11 14:21 - 2014-04-11 14:21 - 00000074 _____ () C:\Users\Deep\Desktop\arbeit montag.txt 2014-04-11 13:40 - 2014-04-11 13:40 - 06812228 _____ () C:\Users\Deep\Downloads\wordpress-3.8.2-de_DE.zip 2014-04-10 14:15 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 14:15 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 14:15 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 14:15 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 14:15 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 14:15 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 14:15 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 14:15 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 14:15 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 14:15 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 14:15 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 14:15 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 14:15 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 14:15 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 14:15 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 14:15 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 02:33 - 2014-04-09 02:33 - 00000020 _____ () C:\Users\Deep\Desktop\lkmnnklnklnl.txt 2014-04-07 13:17 - 2014-04-07 13:17 - 00001250 _____ () C:\Users\Deep\Desktop\poker night 2.txt 2014-04-03 15:37 - 2014-04-03 15:37 - 00000000 ____D () C:\Users\Deep\Documents\Reus 2014-04-01 14:31 - 2014-04-01 14:31 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-04-01 14:31 - 2014-03-19 03:27 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2014-04-01 14:31 - 2014-03-19 03:27 - 00109056 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2014-04-01 13:46 - 2014-04-01 14:25 - 00000000 ____D () C:\Users\Deep\Desktop\bu 2014-04-01 13:42 - 2014-04-01 13:43 - 00000000 __SHD () C:\AI_RecycleBin 2014-04-01 13:16 - 2014-04-01 13:16 - 00000000 ____D () C:\Users\Deep\Documents\SelfMV 2014-04-01 13:12 - 2014-01-23 18:23 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\Windows\SysWOW64\secman.dll 2014-03-29 23:58 - 2014-03-29 23:58 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\com.valve.FTP 2014-03-28 12:36 - 2014-03-28 12:42 - 00000000 ____D () C:\ProgramData\BlueStacksSetup 2014-03-25 02:04 - 2014-03-25 02:04 - 00000860 _____ () C:\Users\Deep\Downloads\social-gallery-wordpress-photo-viewer-plugin-license.txt 2014-03-21 02:14 - 2014-03-21 02:14 - 00000000 _____ () C:\Users\Deep\Desktop\13.4. mtv movie awards.txt 2014-03-18 20:45 - 2014-03-18 22:37 - 00000068 _____ () C:\Users\Deep\Desktop\bücher.txt 2014-03-17 18:57 - 2014-03-17 22:45 - 01246037 _____ () C:\Users\Deep\Desktop\Zeugnisse.zip 2014-03-16 21:18 - 2014-03-16 21:18 - 00003176 _____ () C:\Windows\System32\Tasks\{51082A01-2654-4B14-86E4-8EF0FE809968} ==================== One Month Modified Files and Folders ======= 2014-04-14 17:57 - 2014-04-14 17:56 - 00023089 _____ () C:\Users\Deep\Desktop\FRST.txt 2014-04-14 17:57 - 2014-03-07 16:00 - 00000000 ____D () C:\FRST 2014-04-14 17:56 - 2009-07-14 06:45 - 00026864 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-14 17:56 - 2009-07-14 06:45 - 00026864 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-14 17:55 - 2014-04-14 17:55 - 02157568 _____ (Farbar) C:\Users\Deep\Downloads\FRST64.exe 2014-04-14 17:55 - 2014-04-14 17:55 - 02157568 _____ (Farbar) C:\Users\Deep\Desktop\FRST64.exe 2014-04-14 17:52 - 2014-04-11 17:20 - 00559968 _____ () C:\Windows\WindowsUpdate.log 2014-04-14 17:50 - 2014-04-14 17:50 - 00050477 _____ () C:\Users\Deep\Downloads\Defogger.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00050477 _____ () C:\Users\Deep\Desktop\Defogger.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00000470 _____ () C:\Users\Deep\Desktop\defogger_disable.log 2014-04-14 17:50 - 2014-04-14 17:50 - 00000000 _____ () C:\Users\Deep\defogger_reenable 2014-04-14 17:50 - 2013-06-30 17:26 - 00000000 ____D () C:\Users\Deep 2014-04-14 17:49 - 2013-06-30 20:26 - 00000000 ___RD () C:\Users\Deep\Dropbox 2014-04-14 17:49 - 2013-06-30 20:24 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Dropbox 2014-04-14 17:48 - 2014-04-12 18:04 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-14 17:48 - 2014-04-12 17:57 - 00003557 _____ () C:\Windows\setupact.log 2014-04-14 17:48 - 2014-01-13 19:37 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-14 17:48 - 2013-06-30 18:51 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\TS3Client 2014-04-14 17:48 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-14 17:47 - 2013-07-01 03:18 - 00765588 _____ () C:\Windows\system32\perfh007.dat 2014-04-14 17:47 - 2013-07-01 03:18 - 00174818 _____ () C:\Windows\system32\perfc007.dat 2014-04-14 17:47 - 2009-07-14 07:13 - 01807338 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-14 17:36 - 2013-07-07 14:13 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\FileZilla 2014-04-14 17:33 - 2013-06-30 19:34 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-14 17:17 - 2014-02-11 17:06 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA.job 2014-04-14 17:03 - 2013-06-30 19:03 - 00000000 ____D () C:\Users\Deep\AppData\Local\Spotify 2014-04-14 17:03 - 2013-06-30 19:02 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Spotify 2014-04-14 16:58 - 2014-01-13 19:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-14 02:00 - 2013-06-30 19:33 - 00000000 ____D () C:\Users\Deep\AppData\Local\Adobe 2014-04-12 22:17 - 2014-04-12 17:45 - 00000000 ____D () C:\Windows\System32\Tasks\Aufgaben der Ereignisanzeige 2014-04-12 18:07 - 2013-11-29 13:16 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA Corporation 2014-04-12 18:07 - 2013-09-28 00:36 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-04-12 18:07 - 2013-06-30 17:39 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-12 18:06 - 2014-04-12 18:04 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA 2014-04-12 18:04 - 2013-07-01 00:36 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-04-12 18:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-04-12 18:02 - 2013-09-28 00:42 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\NVIDIA 2014-04-12 18:01 - 2014-04-12 18:01 - 00000000 ____D () C:\NVIDIA 2014-04-12 17:57 - 2014-04-12 17:57 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-12 17:41 - 2014-04-12 17:41 - 00143170 _____ () C:\Users\Deep\Desktop\cc_20140412_174133.reg 2014-04-12 17:27 - 2013-06-30 18:54 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Skype 2014-04-11 20:51 - 2014-04-11 20:51 - 00000000 ____D () C:\Users\Deep\Documents\Gaslamp Games 2014-04-11 17:18 - 2013-12-02 22:24 - 00000000 ____D () C:\Users\Deep\AppData\Local\CrashDumps 2014-04-11 14:21 - 2014-04-11 14:21 - 00000074 _____ () C:\Users\Deep\Desktop\arbeit montag.txt 2014-04-11 13:40 - 2014-04-11 13:40 - 06812228 _____ () C:\Users\Deep\Downloads\wordpress-3.8.2-de_DE.zip 2014-04-11 03:02 - 2013-08-16 00:11 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 03:02 - 2013-07-01 19:10 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-11 03:00 - 2013-07-01 17:02 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-10 14:27 - 2014-01-03 16:40 - 00000000 ____D () C:\Users\Deep\Desktop\stip n study 2014-04-09 13:17 - 2014-02-11 17:06 - 00001064 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core.job 2014-04-09 02:33 - 2014-04-09 02:33 - 00000020 _____ () C:\Users\Deep\Desktop\lkmnnklnklnl.txt 2014-04-07 13:17 - 2014-04-07 13:17 - 00001250 _____ () C:\Users\Deep\Desktop\poker night 2.txt 2014-04-06 01:05 - 2013-06-30 19:07 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\vlc 2014-04-05 15:11 - 2014-01-13 16:41 - 00000000 ____D () C:\Users\Deep\Arbeit 2014-04-03 15:37 - 2014-04-03 15:37 - 00000000 ____D () C:\Users\Deep\Documents\Reus 2014-04-03 14:46 - 2013-08-08 17:30 - 00001794 _____ () C:\Users\Deep\Desktop\steam keys.txt 2014-04-02 17:14 - 2013-10-17 07:31 - 00000000 ____D () C:\Users\Deep\Documents\samsung 2014-04-02 15:27 - 2014-04-12 18:04 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-02 15:27 - 2014-04-12 18:04 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-04-02 01:57 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-04-01 14:31 - 2014-04-01 14:31 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-04-01 14:30 - 2013-10-01 16:07 - 00000000 ____D () C:\ProgramData\Samsung 2014-04-01 14:25 - 2014-04-01 13:46 - 00000000 ____D () C:\Users\Deep\Desktop\bu 2014-04-01 13:45 - 2013-09-30 19:45 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Samsung 2014-04-01 13:45 - 2013-06-30 17:37 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-01 13:43 - 2014-04-01 13:42 - 00000000 __SHD () C:\AI_RecycleBin 2014-04-01 13:43 - 2013-06-30 19:27 - 00000000 ____D () C:\Program Files (x86)\LOLReplay 2014-04-01 13:43 - 2013-06-30 18:56 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-04-01 13:16 - 2014-04-01 13:16 - 00000000 ____D () C:\Users\Deep\Documents\SelfMV 2014-04-01 13:14 - 2013-10-17 07:31 - 00000000 ____D () C:\Users\Deep\AppData\Local\Samsung 2014-04-01 13:11 - 2013-10-01 16:05 - 00000000 ____D () C:\Users\Deep\AppData\Local\Downloaded Installations 2014-03-31 19:01 - 2013-07-02 19:52 - 00000132 _____ () C:\Users\Deep\AppData\Roaming\Adobe PNG Format CS5 Prefs 2014-03-31 13:12 - 2014-02-11 17:06 - 00004088 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA 2014-03-31 13:12 - 2014-02-11 17:06 - 00003692 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core 2014-03-31 03:16 - 2014-04-10 14:15 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 14:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 14:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 14:15 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-29 23:58 - 2014-03-29 23:58 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\com.valve.FTP 2014-03-28 23:35 - 2013-12-05 02:17 - 00001456 _____ () C:\Users\Deep\AppData\Local\Adobe Für Web speichern 12.0 Prefs 2014-03-28 17:53 - 2014-01-13 19:37 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-28 17:53 - 2014-01-13 19:37 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-28 12:42 - 2014-03-28 12:36 - 00000000 ____D () C:\ProgramData\BlueStacksSetup 2014-03-25 02:04 - 2014-03-25 02:04 - 00000860 _____ () C:\Users\Deep\Downloads\social-gallery-wordpress-photo-viewer-plugin-license.txt 2014-03-24 17:26 - 2014-02-28 12:41 - 00000000 ____D () C:\Users\Deep\Desktop\reisen 2014-03-21 21:43 - 2014-04-12 18:07 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-03-21 21:43 - 2014-04-12 18:07 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-03-21 21:43 - 2014-04-12 18:02 - 00037320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-03-21 02:14 - 2014-03-21 02:14 - 00000000 _____ () C:\Users\Deep\Desktop\13.4. mtv movie awards.txt 2014-03-20 22:29 - 2013-06-30 18:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-19 17:13 - 2013-06-30 17:54 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Mozilla 2014-03-19 03:27 - 2014-04-01 14:31 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2014-03-19 03:27 - 2014-04-01 14:31 - 00109056 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2014-03-18 22:37 - 2014-03-18 20:45 - 00000068 _____ () C:\Users\Deep\Desktop\bücher.txt 2014-03-17 22:45 - 2014-03-17 18:57 - 01246037 _____ () C:\Users\Deep\Desktop\Zeugnisse.zip 2014-03-16 23:33 - 2013-10-05 01:54 - 00000057 _____ () C:\Users\Deep\Desktop\filme.txt 2014-03-16 21:18 - 2014-03-16 21:18 - 00003176 _____ () C:\Windows\System32\Tasks\{51082A01-2654-4B14-86E4-8EF0FE809968} 2014-03-16 00:22 - 2014-01-24 00:10 - 00000132 _____ () C:\Users\Deep\AppData\Roaming\Adobe GIF Format CS5 Prefs 2014-03-15 15:32 - 2013-06-30 18:54 - 00000000 ____D () C:\ProgramData\Skype Some content of TEMP: ==================== C:\Users\Deep\AppData\Local\Temp\avgnt.exe C:\Users\Deep\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Deep\AppData\Local\Temp\nvStInst.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-11 15:03 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-04-2014 01 Ran by Deep at 2014-04-14 17:57:25 Running from C:\Users\Deep\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== @BIOS (HKLM-x32\...\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}) (Version: 2.30 - GIGABYTE) A Virus Named TOM (HKLM-x32\...\Steam App 207650) (Version: - Misfits Attic) AaaaaAAaaaAAAaaAAAAaAAAAA!!! for the Awesome (HKLM-x32\...\Steam App 15560) (Version: - Dejobaan Games, LLC) Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.9 - Adobe Systems) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.7.0.2090 - Adobe Systems Incorporated) Hidden Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.) Adobe Community Help (x32 Version: 3.4.980 - Adobe Systems Incorporated.) Hidden Adobe Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 1.4.0 - Adobe Systems Incorporated) Adobe Content Viewer (x32 Version: 1.4.0 - Adobe Systems Incorporated) Hidden Adobe Creative Suite 5.5 Master Collection (HKLM-x32\...\{D8D2B468-8342-411A-8760-BCC362C3408F}) (Version: 5.5 - Adobe Systems Incorporated) Adobe Flash Media Live Encoder 3.2 (HKLM-x32\...\{0659E943-DDF4-44FC-9FEE-A13B09F8BB08}) (Version: 3.2.0 - Adobe Systems Incorporated) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Photoshop Lightroom 5.2 64-bit (HKLM\...\{54E6C675-3AD4-42E4-957F-31666ABF1603}) (Version: 5.2.1 - Adobe) Adobe Story (HKLM-x32\...\com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.0.571 - Adobe Systems Incorporated) Adobe Story (x32 Version: 1.0.571 - Adobe Systems Incorporated) Hidden Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1) (Version: 2.0 Build 230 - Adobe Systems Incorporated.) Adobe Widget Browser (x32 Version: 2.0.230 - Adobe Systems Incorporated.) Hidden Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version: - Hidden Path Entertainment, Ensemble Studios) Air Conflicts: Pacific Carriers (HKLM-x32\...\Steam App 214910) (Version: - Games Farm s.r.o.) Alan Wake (HKLM-x32\...\Steam App 108710) (Version: - Remedy Entertainment) Alan Wake's American Nightmare (HKLM-x32\...\Steam App 202750) (Version: - Remedy Entertainment) Alien Breed 2: Assault (HKLM-x32\...\Steam App 22650) (Version: - Team17 Software Ltd.) Alien Breed 3: Descent (HKLM-x32\...\Steam App 22670) (Version: - Team17 Software Ltd.) Alien Breed: Impact (HKLM-x32\...\Steam App 22610) (Version: - Team17 Software Ltd. ) Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.4.0.26 - Amazon Services LLC) Amazon Kindle (HKLM-x32\...\Amazon Kindle) (Version: - Amazon) Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version: - Frictional Games) Anno 2070 (HKLM-x32\...\Steam App 48240) (Version: - BlueByte) Anomaly 2 (HKLM-x32\...\Steam App 236730) (Version: - 11 bit studios) Anomaly Korea (HKLM-x32\...\Steam App 251530) (Version: - 11 bit studios) Anomaly Warzone Earth (HKLM-x32\...\Steam App 91200) (Version: - 11 bit studios) Anomaly Warzone Earth Mobile Campaign (HKLM-x32\...\Steam App 252170) (Version: - 11 bit studios) Antichamber (HKLM-x32\...\Steam App 219890) (Version: - Alexander Bruce) Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Aquaria (HKLM-x32\...\Steam App 24420) (Version: - Bit Blot, LLC) Arma Tactics (HKLM-x32\...\Steam App 224860) (Version: - Bohemia Interactive) Assassin's Creed (HKLM-x32\...\Steam App 15100) (Version: - Ubisoft Montreal) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.) Audiosurf (HKLM-x32\...\Steam App 12900) (Version: - Dylan Fitterer) AutoGreen B12.0206.1 (HKLM-x32\...\InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE) AutoGreen B12.0206.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden Avadon: The Black Fortress (HKLM-x32\...\Steam App 112100) (Version: - Spiderweb Software) Avernum: Escape From the Pit (HKLM-x32\...\Steam App 208400) (Version: - Spiderweb Software) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version: - AVM Berlin) Awesomenauts (HKLM-x32\...\Steam App 204300) (Version: - Ronimo Games) Bad Hotel (HKLM-x32\...\Steam App 231720) (Version: - Lucky Frame) Bastion (HKLM-x32\...\Steam App 107100) (Version: - Supergiant Games) Batman: Arkham Asylum GOTY Edition (HKLM-x32\...\Steam App 35140) (Version: - Rocksteady Studios) Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version: - Rocksteady Studios) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Beat Hazard (HKLM-x32\...\Steam App 49600) (Version: - Cold Beam Games) BioShock (HKLM-x32\...\Steam App 7670) (Version: - 2K Boston) BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version: - Irrational Games) BIT.TRIP BEAT (HKLM-x32\...\Steam App 63700) (Version: - Gaijin Games) BIT.TRIP RUNNER (HKLM-x32\...\Steam App 63710) (Version: - Gaijin Games) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) Botanicula (HKLM-x32\...\Steam App 207690) (Version: - Amanita Design) Braid (HKLM-x32\...\Steam App 26800) (Version: - Number None) Bridge Project (HKLM-x32\...\Steam App 232950) (Version: - Halycon Media GmbH & Co. KG) Brothers - A Tale of Two Sons (HKLM-x32\...\Steam App 225080) (Version: - Starbreeze Studios AB) Brütal Legend (HKLM-x32\...\Steam App 225260) (Version: - Double Fine Productions) Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version: - Infinity Ward) Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version: - Infinity Ward) Canon RAW Codec (HKLM-x32\...\Canon RAW Codec) (Version: 1.11.0.75 - Canon Inc.) Canon Utilities Digital Photo Professional (HKLM-x32\...\Digital Photo Professional) (Version: 3.13.10.0 - Canon Inc.) Canon Utilities EOS Utility (HKLM-x32\...\EOS Utility) (Version: 2.13.10.0 - Canon Inc.) Canon Utilities Picture Style Editor (HKLM-x32\...\Picture Style Editor) (Version: 1.13.10.0 - Canon Inc.) Capsized (HKLM-x32\...\Steam App 95300) (Version: - Alientrap Games Inc) Cave Story+ (HKLM-x32\...\Steam App 200900) (Version: - Nicalis) CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.4003 - CDBurnerXP) Cities in Motion 2 (HKLM-x32\...\Steam App 225420) (Version: - Colossal Order Ltd.) Confrontation (HKLM-x32\...\Steam App 204560) (Version: - Cyanide Studios) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) CPUID CPU-Z 1.65.1 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) Crysis® 2 (HKLM-x32\...\{6033673D-2530-4587-8AD0-EB059FC263F9}) (Version: 1.9.0.0 - Electronic Arts) Darksiders (HKLM-x32\...\Steam App 50620) (Version: - Vigil Games) Darksiders II (HKLM-x32\...\Steam App 50650) (Version: - Vigil Games) Dead Island (HKLM-x32\...\Steam App 91310) (Version: - Techland) Dead Space™ (HKLM-x32\...\{4D87DC92-C328-46EC-A7B4-9C88129DC696}) (Version: 1.0.222.0 - Electronic Arts) DeathSpank (HKLM-x32\...\Steam App 18040) (Version: - Hothead Games) DeathSpank: Thongs Of Virtue (HKLM-x32\...\Steam App 18050) (Version: - Hothead Games) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{AC53C6A4-1CC4-48A5-91F3-565BB7978B22}) (Version: - Microsoft) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{AC53C6A4-1CC4-48A5-91F3-565BB7978B22}) (Version: - Microsoft) Deponia (HKLM-x32\...\Steam App 214340) (Version: - Daedalic Entertainment) DH Driver Cleaner Professional Edition (HKLM-x32\...\Driver Cleaner Pro) (Version: Version 1.5 - Ruud Ketelaars) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve ) Drakonia Configurator (HKLM-x32\...\{2EAD3327-2F92-455F-A675-E5CC4980B67A}}_is1) (Version: - ) Droid Assault (HKLM-x32\...\Steam App 219200) (Version: - Puppygames) Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.) Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD) Duke Nukem 3D: Megaton Edition (HKLM-x32\...\Steam App 225140) (Version: - 3D Realms) Dungeon Defenders (HKLM-x32\...\Steam App 65800) (Version: - Trendy Entertainment) Dungeonland (HKLM-x32\...\Steam App 218130) (Version: - Critical Studio) Dungeons of Dredmor (HKLM-x32\...\Steam App 98800) (Version: - Gaslamp Games, Inc.) Dust: An Elysian Tail (HKLM-x32\...\Steam App 236090) (Version: - Humble Hearts LLC) Dwarfs!? (HKLM-x32\...\Steam App 35480) (Version: - Power of 2) Dxtory 2.0.104 (HKLM-x32\...\Dxtory2.0_is1) (Version: 2.0.104 - Dxtory Software) Easy Tune 6 B12.1121.1 (HKLM-x32\...\InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}) (Version: 1.00.0000 - GIGABYTE) Easy Tune 6 B12.1121.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden EDGE (HKLM-x32\...\Steam App 38740) (Version: - Two Tribes) Edna & Harvey: Harvey's New Eyes (HKLM-x32\...\Steam App 219910) (Version: - Daedalic Entertainment) Expeditions: Conquistador (HKLM-x32\...\Steam App 237430) (Version: - Logic Artists) F.E.A.R. 3 (HKLM-x32\...\Steam App 21100) (Version: - Day 1 Studios) Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version: - Obsidian Entertainment) FEZ (HKLM-x32\...\Steam App 224760) (Version: - Polytron Corporation) Fieldrunners (HKLM-x32\...\Steam App 209690) (Version: - Subatomic Studios LLC) FileZilla Client 3.7.1 (HKCU\...\FileZilla Client) (Version: 3.7.1 - FileZilla Project) Free YouTube to MP3 Converter version 3.12.17.1127 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.17.1127 - DVDVideoSoft Ltd.) Frozen Synapse (HKLM-x32\...\Steam App 98200) (Version: - Mode 7) Galaxy on Fire 2™ Full HD (HKLM-x32\...\Steam App 212010) (Version: - Fishlabs Entertainment GmbH) Game of Thrones (HKLM-x32\...\Steam App 208730) (Version: - Cyanide Studios) Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Garry) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.) Google Talk Plugin (HKLM-x32\...\{E121A4FE-009B-385B-BB0D-B934E2A88288}) (Version: 5.2.4.18058 - Google) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden GoPro Studio 2.0.1 (HKLM-x32\...\GoPro Studio) (Version: 2.0.1 - WoodmanLabs Inc. d.b.a. GoPro) Gratuitous Tank Battles (HKLM-x32\...\Steam App 205530) (Version: - Positech Games) Guardians of Middle-earth (HKLM-x32\...\Steam App 111900) (Version: - Zombie Studios) Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve) Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version: - Valve) Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version: - Valve) Hard Reset (HKLM-x32\...\Steam App 98400) (Version: - Flying Wild Hog) Heroes of Might and Magic V (HKLM-x32\...\Steam App 15170) (Version: - Nival) Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version: - IO Interactive) HOARD (HKLM-x32\...\Steam App 63000) (Version: - Big Sandwich Games) Hotline Miami (HKLM-x32\...\Steam App 219150) (Version: - Dennaton Games) Indie Game: The Movie (HKLM-x32\...\Steam App 207080) (Version: - BlinkWorks Media) Intake (HKLM-x32\...\Steam App 237760) (Version: - Cipher Prime Studios) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.225 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden Intrusion 2 (HKLM-x32\...\Steam App 214970) (Version: - Aleksey Abramenko) Jagged Alliance - Back in Action (HKLM-x32\...\Steam App 57740) (Version: - Coreplay GmbH) Jagged Alliance: Crossfire (HKLM-x32\...\Steam App 205810) (Version: - Coreplay GmbH) Jamestown (HKLM-x32\...\Steam App 94200) (Version: - Final Form Games) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Joe Danger 2: The Movie (HKLM-x32\...\Steam App 242110) (Version: - Hello Games) Journey of a Roach (HKLM-x32\...\Steam App 255300) (Version: - Koboldgames) Killing Floor (HKLM-x32\...\Steam App 1250) (Version: - Tripwire Interactive) Knytt Underground (HKLM-x32\...\Steam App 248190) (Version: - Nifflas' Games) Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - ) Lara Croft and the Guardian of Light (HKLM-x32\...\Steam App 35130) (Version: - Crystal Dynamics Inc.) Lead and Gold - Gangs of the Wild West (HKLM-x32\...\Steam App 42120) (Version: - Fatshark) Left 4 Dead (HKLM-x32\...\Steam App 500) (Version: - Valve) Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve) Legend of Grimrock (HKLM-x32\...\Steam App 207170) (Version: - Almost Human Games) Leviathan: Warships (HKLM-x32\...\Steam App 202270) (Version: - Pieces Interactive) LG CyberLink Blu-ray Disc Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2820 - CyberLink Corp.) LG CyberLink Blu-ray Disc Suite (x32 Version: 8.0.2820 - CyberLink Corp.) Hidden LG CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.3712.52 - CyberLink Corp.) LG CyberLink PowerDVD (x32 Version: 10.0.3712.52 - CyberLink Corp.) Hidden LG CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.3718 - CyberLink Corp.) LG CyberLink YouCam (x32 Version: 2.0.3718 - CyberLink Corp.) Hidden LIMBO (HKLM-x32\...\Steam App 48000) (Version: - Playdead) Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden Logitech Gaming Software 8.51 (HKLM\...\Logitech Gaming Software) (Version: 8.51.5 - Logitech Inc.) Magicka (HKLM-x32\...\Steam App 42910) (Version: - Arrowhead Game Studios) MakeMKV v1.8.7 (HKLM-x32\...\MakeMKV) (Version: v1.8.7 - GuinpinSoft inc) ManyCam 4.0.44 (HKLM-x32\...\ManyCam) (Version: 4.0.44 - Visicom Media Inc.) Mark of the Ninja (HKLM-x32\...\Steam App 214560) (Version: - Klei Entertainment) marvell 91xx driver (HKLM-x32\...\MagniDriver) (Version: 1.2.0.1020 - Marvell) Medal of Honor (TM) (HKLM-x32\...\{415030B8-3E8B-462A-8C03-41D95AA3AB3B}) (Version: 1.0.0.0 - Electronic Arts) Men of War: Assault Squad (HKLM-x32\...\Steam App 64000) (Version: - Digitalmindsoft) Metro 2033 (HKLM-x32\...\Steam App 43110) (Version: - 4A Games) Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Access 2010 (HKLM\...\Office14.AccessR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{8FB1B528-E260-451E-9B55-E9152F94B80B}) (Version: 3.2.3.0 - Microsoft Corporation) Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.0 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.0 Language Pack - DEU) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Office Access 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2008 (64-bit) (HKLM\...\Microsoft SQL Server 10 Release) (Version: - Microsoft Corporation) Microsoft SQL Server 2008 (64-bit) (Version: - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Browser (HKLM-x32\...\{4AF2248C-B3DF-46FB-9596-87F5DB193689}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 Common Files (Version: 10.0.1600.22 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Common Files (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Services (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Shared (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Native Client (HKLM\...\{8325FD0C-2FDB-46C3-921A-3A78385EA972}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{A106D33E-6B43-42C0-9BFC-D03303261FA7}) (Version: 10.50.1447.4 - Microsoft Corporation) Microsoft SQL Server 2008 RsFx Driver (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{0125D081-30D0-4A97-82A8-C28D444B6256}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (HKLM\...\{C3EAE456-7E7A-451F-80EF-F34C7A13C558}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server System CLR Types (HKLM-x32\...\{5A08C9D1-37AD-4A8D-90D3-33F92C578AA5}) (Version: 10.50.1447.4 - Microsoft Corporation) Microsoft SQL Server VSS Writer (HKLM\...\{28D06854-572C-4A65-83E5-F8CAF26B9FDC}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft Visual C# 2010 Express - DEU (HKLM-x32\...\Microsoft Visual C# 2010 Express - DEU) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C# 2010 Express - DEU (x32 Version: 10.0.30319 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319 (HKLM\...\{94D70749-4281-39AC-AD90-B56A0E0A402E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{616C6F39-4CE1-3434-A665-2F6A04C09A7F}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (HKLM\...\{3C983A67-DFB2-3D3D-AD9E-CA1A5A09FD18}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.0 (HKLM-x32\...\{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}) (Version: 3.0.11010.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft XNA Game Studio 4.0 (XnaLiveProxy) (x32 Version: 4.0.20823.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (ARP entry) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (HKLM-x32\...\XNA Game Studio 4.0) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft XNA Game Studio 4.0 Refresh (Redists) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (Shared Components) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (Visual Studio) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio Platform Tools (HKLM-x32\...\{89690B51-2E21-4E93-914E-F9CAC5B24A84}) (Version: 1.4.0.0 - Microsoft Corporation) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Might & Magic ® Heroes ® VI (HKLM-x32\...\Steam App 48220) (Version: - Blackhole) Might & Magic: Duel of Champions (HKLM-x32\...\Steam App 256410) (Version: - Ubisoft Quebec) ModifyRegistry version 0.1 (HKLM-x32\...\{1D5BE6B5-7FD4-4A78-90F2-AF6B53BC8C1C}_is1) (Version: 0.1 - VIA Technologies, Inc.) Monaco (HKLM-x32\...\Steam App 113020) (Version: - Pocketwatch Games) Mozilla Firefox 27.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.4.0 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) Mp3tag v2.58 (HKLM-x32\...\Mp3tag) (Version: v2.58 - Florian Heidenreich) My Game Long Name (HKLM\...\UDK-9de14894-7b74-4153-a2a9-67eeff60f423) (Version: - Epic Games, Inc.) MyFreeCodec (HKCU\...\MyFreeCodec) (Version: - ) NVIDIA 3D Vision Controller-Treiber 335.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 335.21 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation) NVIDIA GeForce Experience 2.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.0 - NVIDIA Corporation) NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.151.1095 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden Nvidia Omega Drivers v1.169.25 Setup Files and Tools (HKLM-x32\...\Nvidia Omega Drivers for Windows Vistav1.169.25) (Version: v1.169.25 - Omegadrivers.net) NVIDIA PhysX (Legacy) (HKLM-x32\...\{FAAC26AD-73BA-40CE-86AA-C9213F9E064A}) (Version: 9.13.0604 - NVIDIA Corporation) NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3523 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden NVIDIA Update 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.22 (Version: 1.2.22 - NVIDIA Corporation) Hidden Oddworld: Munch's Oddysee (HKLM-x32\...\Steam App 15740) (Version: - Oddworld Inhabitants) Oddworld: Stranger's Wrath HD (HKLM-x32\...\Steam App 15750) (Version: - Oddworld Inhabitants) Offspring Fling! (HKLM-x32\...\Steam App 211360) (Version: - Kyle Pulver) On the Rain-Slick Precipice of Darkness, Episode One (HKLM-x32\...\Steam App 18000) (Version: - Hothead Games) On the Rain-Slick Precipice of Darkness, Episode Two (HKLM-x32\...\Steam App 18020) (Version: - Hothead Games) ON_OFF Charge B12.1025.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Orcs Must Die! (HKLM-x32\...\Steam App 102600) (Version: - Robot Entertainment) Organ Trail: Director's Cut (HKLM-x32\...\Steam App 233740) (Version: - The Men Who Wear Many Hats) Origin (HKLM-x32\...\Origin) (Version: 9.3.1.4482 - Electronic Arts, Inc.) Osmos (HKLM-x32\...\Steam App 29180) (Version: - Hemisphere Games) Painkiller Hell & Damnation (HKLM-x32\...\Steam App 214870) (Version: - The Farm 51) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.) PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden Pinball FX2 (HKLM-x32\...\Steam App 226980) (Version: - Zen Studios) Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden Poker Night 2 (HKLM-x32\...\Steam App 234710) (Version: - Telltale Games) Poker Night at the Inventory (HKLM-x32\...\Steam App 31280) (Version: - Telltale Games) Portal (HKLM-x32\...\Steam App 400) (Version: - Valve) Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.) PxMergeModule (x32 Version: 1.00.0000 - Your Company Name) Hidden QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) RAW - Realms of Ancient War (HKLM-x32\...\Steam App 209730) (Version: - Wizarbox) Really Big Sky (HKLM-x32\...\Steam App 201570) (Version: - Boss Baddie) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.) Red Faction: Armageddon (HKLM-x32\...\Steam App 55110) (Version: - Volition) Red Orchestra: Ostfront 41-45 (HKLM-x32\...\Steam App 1200) (Version: - Tripwire Interactive) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.30.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.30.0 - Renesas Electronics Corporation) Hidden Retro City Rampage™ (HKLM-x32\...\Steam App 204630) (Version: - Vblank Entertainment, Inc.) Reus (HKLM-x32\...\Steam App 222730) (Version: - Abbey Games) Revenge of the Titans (HKLM-x32\...\Steam App 93200) (Version: - Puppygames) Risen 2 - Dark Waters (HKLM-x32\...\Steam App 40390) (Version: - Piranha Bytes) Rising Storm/Red Orchestra 2 Multiplayer (HKLM-x32\...\Steam App 35450) (Version: - Tripwire Interactive) Rochard (HKLM-x32\...\Steam App 107800) (Version: - Recoil Games) Rock of Ages (HKLM-x32\...\Steam App 22230) (Version: - ACE Team) Rocketbirds: Hardboiled Chicken (HKLM-x32\...\Steam App 215510) (Version: - Ratloop Asia) Sacred Citadel (HKLM-x32\...\Steam App 207930) (Version: - Southend) Saints Row: The Third (HKLM-x32\...\Steam App 55230) (Version: - Volition) Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14034.12 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.14034.12 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.40.0 - SAMSUNG Electronics Co., Ltd.) Sanctum 2 (HKLM-x32\...\Steam App 210770) (Version: - Coffee Stain Studios) Screen Split (HKLM-x32\...\{7F0C2357-33B0-4408-A9AD-A7623FAA22B1}) (Version: 6.1 - LG Electronics Inc.) Scribblenauts Unlimited (HKLM-x32\...\Steam App 218680) (Version: - 5th Cell Media) Serious Sam 3: BFE (HKLM-x32\...\Steam App 41070) (Version: - Croteam) Serious Sam Double D (HKLM-x32\...\Steam App 111600) (Version: - Mommy's Best Games) Serious Sam HD: The First Encounter (HKLM-x32\...\Steam App 41000) (Version: - Croteam) Serious Sam HD: The Second Encounter (HKLM-x32\...\Steam App 41010) (Version: - Croteam) Service Pack 1 für SQL Server 2008 (KB 968369) (64-bit) (HKLM\...\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden Shadow Warrior Classic Redux (HKLM-x32\...\Steam App 225160) (Version: - 3D Realms) Shank (HKLM-x32\...\Steam App 6120) (Version: - Klei Entertainment) Shank 2 (HKLM-x32\...\Steam App 102840) (Version: - Klei Entertainment) Shatter (HKLM-x32\...\Steam App 20820) (Version: - Sidhe) SHIELD Streaming (Version: 1.8.323 - NVIDIA Corporation) Hidden Sid Meier’s Ace Patrol: Pacific Skies (HKLM-x32\...\Steam App 244090) (Version: - Firaxis) Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Sine Mora (HKLM-x32\...\Steam App 207040) (Version: - Digital Reality) SkyDrift (HKLM-x32\...\Steam App 91100) (Version: - Digital Reality) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Snapshot (HKLM-x32\...\Steam App 204220) (Version: - Retro Affect) Solar 2 (HKLM-x32\...\Steam App 97000) (Version: - Murudai) Space Pirates and Zombies (HKLM-x32\...\Steam App 107200) (Version: - MinMax Games Ltd.) SpaceChem (HKLM-x32\...\Steam App 92800) (Version: - Zachtronics Industries) Speccy (HKLM\...\Speccy) (Version: 1.22 - Piriform) Splice (HKLM-x32\...\Steam App 209790) (Version: - Cipher Prime Studios) Spotify (HKCU\...\Spotify) (Version: 0.9.8.296.g91f68827 - Spotify AB) Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden StarCraft II (HKLM-x32\...\StarCraft II) (Version: 2.0.11.26825 - Blizzard Entertainment) StarUML 5.0.2.1570 (HKLM-x32\...\StarUML_is1) (Version: - Plastic Software, Inc.) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Strike Suit Zero (HKLM-x32\...\Steam App 209540) (Version: - Born Ready Games Ltd.) Superfrog HD (HKLM-x32\...\Steam App 234000) (Version: - Team17 Digital Ltd.) Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.24951 - TeamViewer) Texas Instruments TUSB3410 drivers. (HKLM-x32\...\InstallShield_{FA66245E-0E77-40D5-94A4-CB7AB753034F}) (Version: 6.5.9019.1 - Texas Instruments Inc.) The Baconing (HKLM-x32\...\Steam App 18070) (Version: - Hothead Games) The Basement Collection (HKLM-x32\...\Steam App 214790) (Version: - Edmund McMillen, Tyler Glaiel) The Binding of Isaac (HKLM-x32\...\Steam App 113200) (Version: - Edmund McMillen and Florian Himsl) The Bridge (HKLM-x32\...\Steam App 204240) (Version: - Ty Taylor and Mario Castañeda) The Dark Eye: Chains of Satinav (HKLM-x32\...\Steam App 203830) (Version: - Daedalic Entertainment) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) The Lord of the Rings: War in the North (HKLM-x32\...\Steam App 32800) (Version: - Snowblind Studios) The Raven - Legacy of a Master Thief (HKLM-x32\...\Steam App 233370) (Version: - KING Art) The Stanley Parable (HKLM-x32\...\Steam App 221910) (Version: - Galactic Cafe) The Walking Dead (HKLM-x32\...\Steam App 207610) (Version: - ) Thunder Wolves (HKLM-x32\...\Steam App 232970) (Version: - Most Wanted Entertainment) Ticket to Ride (HKLM-x32\...\Steam App 108200) (Version: - Days of Wonder) Tiny and Big: Grandpa's Leftovers (HKLM-x32\...\Steam App 205910) (Version: - Black Pants Game Studio) Titan Attacks (HKLM-x32\...\Steam App 203210) (Version: - Puppygames) To the Moon (HKLM-x32\...\Steam App 206440) (Version: - Freebird Games) Toki Tori (HKLM-x32\...\Steam App 38700) (Version: - Two Tribes) Toki Tori 2+ (HKLM-x32\...\Steam App 201420) (Version: - Two Tribes) Tomb Raider (HKLM-x32\...\Steam App 203160) (Version: - Crystal Dynamics) Tomb Raider II (HKLM-x32\...\Steam App 225300) (Version: - Core Design) Torchlight II (HKLM-x32\...\Steam App 200710) (Version: - Runic Games) Tropico 4 (HKLM-x32\...\Steam App 57690) (Version: - Haemimont Games) TUSB3410 (x32 Version: 6.5.9019.1 - Texas Instruments Inc.) Hidden Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Ultratron (HKLM-x32\...\Steam App 219190) (Version: - Puppygames) Unterstützungsdateien für Microsoft SQL Server 2008-Setup (HKLM\...\{6AF73222-EE90-434C-AE7E-B96F70A68D89}) (Version: 10.1.2731.0 - Microsoft Corporation) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{FEF4C57D-0975-4D3C-ACC7-DCD038C3788F}) (Version: - Microsoft) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{FEF4C57D-0975-4D3C-ACC7-DCD038C3788F}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{99A0DB9A-71FC-4F98-BC1F-78A18195C677}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{DB0B0CDF-77EC-47B0-94E2-4738573A1E58}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.AccessR_{64D96F30-CF4C-4CCE-AAF2-F8909348BF35}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.SingleImage_{64D96F30-CF4C-4CCE-AAF2-F8909348BF35}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (HKLM\...\{90140000-001F-040C-1000-0000000FF1CE}_Office14.AccessR_{9F6507AC-7D8F-46C1-B90F-59C7828E0E0D}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (HKLM\...\{90140000-001F-040C-1000-0000000FF1CE}_Office14.SingleImage_{9F6507AC-7D8F-46C1-B90F-59C7828E0E0D}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.AccessR_{A9C4BE58-07E0-473D-AE68-ECBA13FBF77E}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.SingleImage_{A9C4BE58-07E0-473D-AE68-ECBA13FBF77E}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{8A6BDA63-4D23-4485-A466-8979E10BCF49}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{8A6BDA63-4D23-4485-A466-8979E10BCF49}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{8A6BDA63-4D23-4485-A466-8979E10BCF49}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{8A6BDA63-4D23-4485-A466-8979E10BCF49}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-001A-0407-1000-0000000FF1CE}_Office14.SingleImage_{6164E0E5-C903-488C-93AF-1B7AF7EBC331}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{DDDC32A5-9528-4771-B91A-97A8E1D7957B}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0018-0407-1000-0000000FF1CE}_Office14.SingleImage_{FD360122-6829-4497-97C1-1BF578EF695B}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{A20A650C-F820-4CE4-AEA5-EC140192FAFB}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2553444) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{8E076AE6-4E29-4056-A13F-70CC8F433FB5}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{DF33B92A-5381-4F03-AB54-2D67086B357E}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{CFCB8616-A5D1-4281-80E8-389F685BFAE2}) (Version: 4.0.8080.0 - Microsoft Corporation) VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN) War of the Roses (HKLM-x32\...\Steam App 42160) (Version: - Fatshark) Wargame: European Escalation (HKLM-x32\...\Steam App 58610) (Version: - Eugen Systems) Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices (03/07/2012 ) (HKLM\...\0B624A43DD66DBF5CF3EDFA9741A364E688062A4) (Version: 03/07/2012 - GoPro) WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) Wizorb (HKLM-x32\...\Steam App 207420) (Version: - Tribute Games) World of Goo (HKLM-x32\...\Steam App 22000) (Version: - 2D BOY ) Worms Crazy Golf (HKLM-x32\...\Steam App 70620) (Version: - Team17 Software Ltd.) Worms Reloaded (HKLM-x32\...\Steam App 22600) (Version: - Team17 Software Ltd.) Worms Ultimate Mayhem (HKLM-x32\...\Steam App 70600) (Version: - Team17 Software Ltd.) X3: Albion Prelude (HKLM-x32\...\Steam App 201310) (Version: - Egosoft) X3: Terran Conflict (HKLM-x32\...\Steam App 2820) (Version: - Egosoft) Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team) Youtube Downloader HD v. 2.9.9.8 (HKLM-x32\...\Youtube Downloader HD_is1) (Version: - YoutubeDownloaderHD.com) Zeno Clash (HKLM-x32\...\Steam App 22200) (Version: - ACE Team) Zeno Clash 2 (HKLM-x32\...\Steam App 215690) (Version: - ACE Team) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1DF22E0D-37D9-43C5-B87B-81DCCCDC9455} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core => C:\Users\Deep\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-06] (Google Inc.) Task: {215D7890-B45A-4E9B-8189-76023F5FEF4D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-13] (Google Inc.) Task: {3E743F57-96B2-453F-8CA2-57D62A6B55F8} - System32\Tasks\AdobeAAMUpdater-1.0-YoloSwag-PC-Deep => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-03] (Adobe Systems Incorporated) Task: {A0D86BA9-1CE8-4206-820E-E99833851EA9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {A2482288-742F-4FBB-B563-24A3FF662130} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-13] (Google Inc.) Task: {AC0B757F-AEFD-4F97-A1F2-DFACC15F29A1} - System32\Tasks\Amazon Music Helper => C:\Users\Deep\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [2014-03-07] () Task: {BECADCDB-C741-4B30-8E41-B49D040AEDBB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA => C:\Users\Deep\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-06] (Google Inc.) Task: {F85F09CE-F80F-4DBF-9047-7FF3B3B40E0B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core.job => C:\Users\Deep\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA.job => C:\Users\Deep\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-04-12 18:03 - 2014-03-04 15:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () E:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2014-03-11 14:17 - 2014-03-07 22:39 - 03168576 _____ () C:\Users\Deep\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe 2013-10-05 01:56 - 2013-12-09 13:50 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2013-10-05 01:56 - 2013-12-09 13:50 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2013-09-28 05:52 - 2012-08-09 12:55 - 00078480 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll 2013-09-28 05:52 - 2012-08-09 12:55 - 00386192 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll 2013-07-28 21:25 - 2013-10-29 14:43 - 00248832 _____ () E:\Program Files (x86)\Drakonia Configurator\hid.exe 2013-07-28 21:25 - 2012-12-11 12:14 - 00240640 _____ () E:\Program Files (x86)\Drakonia Configurator\trayicon.exe 2014-03-30 23:42 - 2014-03-30 23:42 - 00173568 _____ () E:\Program Files\TeamSpeak\quazip.dll 2014-03-30 23:42 - 2014-03-30 23:42 - 01080832 _____ () E:\Program Files\TeamSpeak\platforms\qwindows.dll 2014-03-30 23:42 - 2014-03-30 23:42 - 00833024 _____ () E:\Program Files\TeamSpeak\sqldrivers\qsqlite.dll 2013-04-04 10:38 - 2014-03-30 23:42 - 00102344 _____ () E:\Program Files\TeamSpeak\soundbackends\directsound_win64.dll 2013-04-04 10:38 - 2014-03-30 23:42 - 00108488 _____ () E:\Program Files\TeamSpeak\soundbackends\windowsaudiosession_win64.dll 2014-03-30 23:42 - 2014-03-30 23:42 - 00030208 _____ () E:\Program Files\TeamSpeak\imageformats\qgif.dll 2014-03-30 23:42 - 2014-03-30 23:42 - 00233984 _____ () E:\Program Files\TeamSpeak\imageformats\qjpeg.dll 2013-04-04 10:38 - 2014-03-30 23:42 - 00563656 _____ () E:\Program Files\TeamSpeak\plugins\clientquery_plugin.dll 2013-09-14 23:32 - 2014-03-30 23:42 - 00577480 _____ () E:\Program Files\TeamSpeak\plugins\teamspeak_control_plugin.dll 2014-03-30 23:42 - 2014-03-30 23:42 - 00159232 _____ () E:\Program Files\TeamSpeak\accessible\qtaccessiblewidgets.dll 2013-06-30 18:43 - 2013-06-30 18:41 - 00397704 _____ () E:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\Deep\AppData\Roaming\Dropbox\bin\libcef.dll 2013-12-18 20:43 - 2013-12-18 20:43 - 00019968 _____ () E:\Adobe\Acrobat 10.0\Acrobat\locale\de_de\acrotray.deu 2013-07-28 21:25 - 2013-01-15 18:06 - 00061952 _____ () E:\Program Files (x86)\Drakonia Configurator\HidDevice.dll 2013-07-28 21:25 - 2011-11-22 14:18 - 00249856 _____ () E:\Program Files (x86)\Drakonia Configurator\language.dll 2014-04-09 22:00 - 2014-04-02 03:57 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll 2013-06-18 22:08 - 2013-06-18 22:08 - 00093696 _____ () E:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2014-04-09 22:00 - 2014-04-02 03:57 - 00674632 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libglesv2.dll 2014-04-09 22:00 - 2014-04-02 03:57 - 00093000 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libegl.dll 2014-04-09 22:00 - 2014-04-02 03:57 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll 2014-04-09 22:00 - 2014-04-02 03:58 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll 2014-04-09 22:00 - 2014-04-02 03:57 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll 2014-01-09 00:20 - 2013-12-13 00:19 - 00142848 _____ () D:\Steam\libavresample-1.dll 2014-01-09 00:20 - 2013-11-05 03:12 - 00890592 _____ () D:\Steam\libavutil-52.dll 2013-05-06 17:05 - 2014-02-11 04:34 - 00751616 _____ () D:\Steam\SDL2.dll 2013-06-06 14:06 - 2014-02-25 23:57 - 01135296 _____ () D:\Steam\bin\chromehtml.DLL 2013-03-26 16:16 - 2014-01-11 01:33 - 20625832 _____ () D:\Steam\bin\libcef.dll 2012-12-11 09:51 - 2013-06-15 01:49 - 01100800 _____ () D:\Steam\bin\avcodec-53.dll 2012-12-11 09:51 - 2013-06-15 01:49 - 00124416 _____ () D:\Steam\bin\avutil-51.dll 2012-12-11 09:51 - 2013-06-15 01:49 - 00192000 _____ () D:\Steam\bin\avformat-53.dll 2014-04-09 22:00 - 2014-04-02 03:58 - 13691720 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll 2013-09-28 05:51 - 2012-06-25 10:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Windows:nlsPreferences AlternateDataStreams: C:\ProgramData\TEMP:9A870F8B AlternateDataStreams: C:\Users\Deep\Cookies:VZnhKSjowdmOXaCA4OGT1S AlternateDataStreams: C:\Users\Deep\AppData\Local\Temp:0QqIywsH7jaF7EctsHZ ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CineForm Status.lnk => C:\Windows\pss\CineForm Status.lnk.CommonStartup MSCONFIG\startupreg: Amazon Cloud Player => "C:\Users\Deep\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: KiesAirMessage => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup MSCONFIG\startupreg: KiesPreload => C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/14/2014 05:54:22 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Der Textzeichenfolgenwert zur Beschreibung des Leistungsindikators in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten. Error: (04/14/2014 05:54:19 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (04/14/2014 05:54:19 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (04/14/2014 05:54:19 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (04/14/2014 05:50:13 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2014 05:43:18 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2014 04:31:13 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2014 03:29:37 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2014 05:06:57 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2014 03:48:53 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (04/14/2014 05:49:18 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (04/14/2014 05:49:18 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (04/14/2014 05:49:18 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (04/14/2014 05:49:18 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (04/14/2014 05:49:18 PM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (04/14/2014 05:49:18 PM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (04/14/2014 05:49:02 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (04/14/2014 05:49:02 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (04/14/2014 05:49:02 PM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (04/14/2014 05:48:22 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 14.04.2014 um 17:46:28 unerwartet heruntergefahren. Microsoft Office Sessions: ========================= Error: (04/14/2014 05:54:22 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: 1600000000A3690000A3690000980B0000 Error: (04/14/2014 05:54:19 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl8F20300004D070000 Error: (04/14/2014 05:54:19 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (04/14/2014 05:54:19 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (04/14/2014 05:50:13 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2014 05:43:18 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2014 04:31:13 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2014 03:29:37 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2014 05:06:57 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2014 03:48:53 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 36% Total physical RAM: 8152.04 MB Available physical RAM: 5205.98 MB Total Pagefile: 16302.26 MB Available Pagefile: 12917.04 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.79 GB) (Free:6.04 GB) NTFS Drive d: (Volume) (Fixed) (Total:1863.01 GB) (Free:385.48 GB) NTFS Drive e: () (Fixed) (Total:465.66 GB) (Free:145.88 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 272F7E4B) Partition 1: (Not Active) - (Size=-198626508800) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: FB64ED2D) Partition: GPT Partition Type. ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 3EC88F1B) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Ich hoffe, ihr könnt mir helfen. |
14.04.2014, 18:26 | #2 |
/// the machine /// TB-Ausbilder | Win7 - Regelmäßige Systemabstürze hi,
__________________Scan mit Combofix
__________________ |
15.04.2014, 00:49 | #3 |
| Win7 - Regelmäßige Systemabstürze So, getan, was du mir aufgetragen hast.
__________________Combofix hat in dem ganzen Durchgang nicht offensichtlich gemeckert, Avira allerdings schon, obwohl ich es soweit es mir möglich war beendet habe. Es hat wohl einige Zugriffe auf Registrydateien blockiert, hoffe das stört nicht weiter.. Der Log hier: Code:
ATTFilter ComboFix 14-04-12.01 - Deep 15.04.2014 1:41.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8152.5952 [GMT 2:00] ausgeführt von:: c:\users\Deep\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ADS - Windows: deleted 0 bytes in 1 streams. . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Public\sdelevURL.tmp c:\windows\WINDOWS D:\install.exe . . ((((((((((((((((((((((( Dateien erstellt von 2014-03-14 bis 2014-04-14 )))))))))))))))))))))))))))))) . . 2014-04-12 16:07 . 2014-03-21 19:43 40392 ----a-w- c:\windows\system32\drivers\nvvad64v.sys 2014-04-12 16:07 . 2014-03-21 19:43 33568 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll 2014-04-12 16:04 . 2014-04-02 13:27 1081112 ----a-w- c:\windows\SysWow64\nvspcap.dll 2014-04-12 16:04 . 2014-04-02 13:27 1225920 ----a-w- c:\windows\system32\nvspcap64.dll 2014-04-12 16:04 . 2014-04-12 16:06 -------- d-----w- c:\users\Deep\AppData\Local\NVIDIA 2014-04-12 16:04 . 2014-03-04 11:32 599840 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2014-04-12 16:04 . 2014-04-14 17:19 -------- d-----w- c:\programdata\NVIDIA 2014-04-12 16:03 . 2014-03-04 13:06 6714312 ----a-w- c:\windows\system32\nvcpl.dll 2014-04-12 16:03 . 2014-03-04 13:06 3497816 ----a-w- c:\windows\system32\nvsvc64.dll 2014-04-12 16:03 . 2014-03-04 13:05 922968 ----a-w- c:\windows\system32\nvvsvc.exe 2014-04-12 16:03 . 2014-03-04 13:05 64968 ----a-w- c:\windows\system32\nvshext.dll 2014-04-12 16:03 . 2014-03-04 13:05 2558808 ----a-w- c:\windows\system32\nvsvcr.dll 2014-04-12 16:03 . 2014-03-04 13:05 386336 ----a-w- c:\windows\system32\nvmctray.dll 2014-04-12 16:03 . 2014-03-04 13:05 3649185 ----a-w- c:\windows\system32\nvcoproc.bin 2014-04-12 16:03 . 2014-03-04 14:35 62408 ----a-w- c:\windows\system32\OpenCL.dll 2014-04-12 16:03 . 2014-03-04 14:35 54216 ----a-w- c:\windows\SysWow64\OpenCL.dll 2014-04-12 16:01 . 2014-04-12 16:01 -------- d-----w- C:\NVIDIA 2014-04-11 11:38 . 2014-03-07 04:43 10521840 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9C0E7F74-C895-4E28-AF06-81DF71C049C8}\mpengine.dll 2014-04-01 12:31 . 2014-03-19 01:27 206080 ----a-w- c:\windows\system32\drivers\ssudmdm.sys 2014-04-01 12:31 . 2014-03-19 01:27 109056 ----a-w- c:\windows\system32\drivers\ssudbus.sys 2014-04-01 12:31 . 2014-04-01 12:31 -------- d-----w- c:\program files\SAMSUNG 2014-04-01 11:42 . 2014-04-01 11:43 -------- d-----w- C:\AI_RecycleBin 2014-04-01 11:12 . 2014-01-23 16:23 144664 ----a-w- c:\windows\SysWow64\secman.dll 2014-03-29 21:58 . 2014-03-29 21:58 -------- d-----w- c:\users\Deep\AppData\Roaming\com.valve.FTP 2014-03-28 10:36 . 2014-03-28 10:42 -------- d-----w- c:\programdata\BlueStacksSetup . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-04-11 01:00 . 2013-07-01 15:02 90655440 ----a-w- c:\windows\system32\MRT.exe 2014-03-14 16:43 . 2014-03-14 16:43 1186161 ----a-w- c:\windows\unins002.exe 2014-03-12 19:35 . 2013-06-30 17:34 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-03-12 19:35 . 2013-06-30 17:34 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-03-07 13:32 . 2014-03-07 13:33 1192533 ----a-w- c:\windows\unins001.exe 2014-03-04 09:17 . 2014-04-10 12:15 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2014-03-01 05:16 . 2014-03-12 19:04 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-03-01 04:58 . 2014-03-12 19:04 2765824 ----a-w- c:\windows\system32\iertutil.dll 2014-03-01 04:52 . 2014-03-12 19:04 66048 ----a-w- c:\windows\system32\iesetup.dll 2014-03-01 04:51 . 2014-03-12 19:04 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-03-01 04:42 . 2014-03-12 19:04 53760 ----a-w- c:\windows\system32\jsproxy.dll 2014-03-01 04:40 . 2014-03-12 19:04 33792 ----a-w- c:\windows\system32\iernonce.dll 2014-03-01 04:37 . 2014-03-12 19:04 574976 ----a-w- c:\windows\system32\ieui.dll 2014-03-01 04:33 . 2014-03-12 19:04 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2014-03-01 04:33 . 2014-03-12 19:04 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-03-01 04:32 . 2014-03-12 19:04 708608 ----a-w- c:\windows\system32\jscript9diag.dll 2014-03-01 04:23 . 2014-03-12 19:04 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-03-01 04:17 . 2014-03-12 19:04 218624 ----a-w- c:\windows\system32\ie4uinit.exe 2014-03-01 04:02 . 2014-03-12 19:04 195584 ----a-w- c:\windows\system32\msrating.dll 2014-03-01 03:54 . 2014-03-12 19:04 5768704 ----a-w- c:\windows\system32\jscript9.dll 2014-03-01 03:52 . 2014-03-12 19:04 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-03-01 03:51 . 2014-03-12 19:04 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-03-01 03:42 . 2014-03-12 19:04 627200 ----a-w- c:\windows\system32\msfeeds.dll 2014-03-01 03:38 . 2014-03-12 19:04 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-03-01 03:37 . 2014-03-12 19:04 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-03-01 03:35 . 2014-03-12 19:04 2041856 ----a-w- c:\windows\system32\inetcpl.cpl 2014-03-01 03:18 . 2014-03-12 19:04 13051904 ----a-w- c:\windows\system32\ieframe.dll 2014-03-01 03:14 . 2014-03-12 19:04 4244480 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-03-01 03:10 . 2014-03-12 19:04 2334208 ----a-w- c:\windows\system32\wininet.dll 2014-03-01 03:00 . 2014-03-12 19:04 1964032 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-03-01 02:38 . 2014-03-12 19:04 1393664 ----a-w- c:\windows\system32\urlmon.dll 2014-03-01 02:32 . 2014-03-12 19:04 1820160 ----a-w- c:\windows\SysWow64\wininet.dll 2014-03-01 02:25 . 2014-03-12 19:04 817664 ----a-w- c:\windows\system32\ieapfltr.dll 2014-02-08 23:24 . 2013-07-08 11:05 466456 ----a-w- c:\windows\system32\wrap_oal.dll 2014-02-08 23:24 . 2013-07-08 11:05 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll 2014-02-08 23:24 . 2013-07-08 11:05 122904 ----a-w- c:\windows\system32\OpenAL32.dll 2014-02-08 23:24 . 2013-07-08 11:05 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll 2014-02-07 01:23 . 2014-03-12 19:04 3156480 ----a-w- c:\windows\system32\win32k.sys 2014-02-04 02:32 . 2014-03-12 19:02 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-02-04 02:32 . 2014-03-12 19:02 624128 ----a-w- c:\windows\system32\qedit.dll 2014-02-04 02:04 . 2014-03-12 19:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2014-02-04 02:04 . 2014-03-12 19:02 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2014-01-29 18:55 . 2014-01-29 18:55 1443328 ----a-w- c:\windows\system32\CFHD.dll 2014-01-29 18:52 . 2014-01-29 18:52 1474560 ----a-w- c:\windows\SysWow64\CFHD.dll 2014-01-29 02:32 . 2014-03-12 19:04 484864 ----a-w- c:\windows\system32\wer.dll 2014-01-29 02:06 . 2014-03-12 19:04 381440 ----a-w- c:\windows\SysWow64\wer.dll 2014-01-28 02:32 . 2014-03-12 19:04 228864 ----a-w- c:\windows\system32\wwansvc.dll 2014-01-24 17:58 . 2014-01-24 17:54 29480 ----a-w- c:\windows\SysWow64\msxml3a.dll 2014-01-24 17:58 . 2010-10-25 13:13 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll 2014-01-24 17:58 . 2010-10-25 13:13 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll 2014-01-22 22:19 . 2014-01-22 22:19 35344 ----a-w- c:\windows\system32\drivers\WPRO_41_2001.sys 2014-01-22 16:06 . 2014-01-22 16:06 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2014-01-22 16:04 . 2014-01-22 16:04 0 ----a-w- c:\windows\SysWow64\REN47F8.tmp 2014-01-22 16:04 . 2014-01-22 16:04 0 ----a-w- c:\windows\SysWow64\REN47F7.tmp . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\Deep\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\Deep\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\Deep\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\Deep\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="c:\users\Deep\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-04-05 1171000] "ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avgnt"="e:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-02-20 689744] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "Adobe Acrobat Speed Launcher"="e:\adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2013-12-18 41336] "Acrobat Assistant 8.0"="e:\adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2013-12-18 840568] "AVMWlanClient"="c:\program files (x86)\avmwlanstick\wlangui.exe" [2010-10-22 2105344] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288] "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-03-27 291608] "HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2012-08-09 5263504] "ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632] "amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "RemoteControl10"="e:\program files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe" [2011-03-30 87336] "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2011-09-28 75048] "UCam_Menu"="e:\program files (x86)\Cyberlink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "GamingMouse"="e:\program files (x86)\Drakonia Configurator\hid.exe" [2013-10-29 248832] . c:\users\Deep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Deep\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-1-3 30714328] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux7"=wdmaud.drv . R2 CLKMSVC10_F47B619C;CyberLink Product - 2014/01/24 18:59;e:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe;e:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x] R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys;c:\windows\SYSNATIVE\drivers\avmeject.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys;c:\windows\SYSNATIVE\drivers\dgderdrv.sys [x] R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x] R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x] R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WPRO_41_2001;WinPcap Packet Driver (WPRO_41_2001);c:\windows\system32\drivers\WPRO_41_2001.sys;c:\windows\SYSNATIVE\drivers\WPRO_41_2001.sys [x] R4 MSSQLServerADHelper100;SQL Server Hilfsdienst für Active Directory;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [x] R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys;c:\windows\SYSNATIVE\DRIVERS\RsFx0103.sys [x] R4 SQLAgent$SQLEXPRESS;SQL Server-Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE;c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [x] S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AntiVirSchedulerService;Avira Planer;e:\program files (x86)\Avira\AntiVir Desktop\sched.exe;e:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe;c:\windows\SYSNATIVE\viakaraokesrv.exe [x] S3 fwlanusb4;FRITZ!WLAN N/G;c:\windows\system32\DRIVERS\fwlanusb4.sys;c:\windows\SYSNATIVE\DRIVERS\fwlanusb4.sys [x] S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x] S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x] S3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv.sys [x] S3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 umpusbvista;Texas Instruments USB Serial Driver;c:\windows\system32\DRIVERS\umpusbvista.sys;c:\windows\SYSNATIVE\DRIVERS\umpusbvista.sys [x] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x] S3 VUSB3HUB;VIA USB 3 Root Hub Service;c:\windows\system32\DRIVERS\ViaHub3.sys;c:\windows\SYSNATIVE\DRIVERS\ViaHub3.sys [x] S3 xhcdrv;VIA USB eXtensible Host Controller Service;c:\windows\system32\DRIVERS\xhcdrv.sys;c:\windows\SYSNATIVE\DRIVERS\xhcdrv.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *Deregistered* - CLKMDRV10_F47B619C . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-04-09 19:58 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-04-14 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-30 19:35] . 2014-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-13 17:37] . 2014-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-13 17:37] . 2014-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core.job - c:\users\Deep\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-11 19:47] . 2014-04-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA.job - c:\users\Deep\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-11 19:47] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\Deep\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\Deep\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\Deep\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\Deep\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-06-03 472984] "BCSSync"="e:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-03-29 13513288] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2013-11-14 8292120] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-04-02 2201032] "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-04-02 1225920] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.de/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: An OneNote s&enden - e:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105 IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Nach Microsoft E&xcel exportieren - e:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=de&q= . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-AdobeBridge - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.12" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-04-15 01:45:08 ComboFix-quarantined-files.txt 2014-04-14 23:45 . Vor Suchlauf: 5.889.101.824 Bytes frei Nach Suchlauf: 5.900.156.928 Bytes frei . - - End Of File - - C84D187B7C5F757B5BCF5D0E8F2C36A2 A36C5E4F47E84449FF07ED3517B43A31 |
15.04.2014, 14:38 | #4 |
/// the machine /// TB-Ausbilder | Win7 - Regelmäßige Systemabstürze Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.04.2014, 15:34 | #5 |
| Win7 - Regelmäßige Systemabstürze Hi, hier die mbam.txt: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 15.04.2014 Suchlauf-Zeit: 16:11:31 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.15.06 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Deep Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 329781 Verstrichene Zeit: 8 Min, 33 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 15/04/2014 um 16:15:58 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Deep - BENS-TEN # Gestartet von : C:\Users\Deep\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\AI_RecycleBin Ordner Gelöscht : C:\ProgramData\apn Ordner Gelöscht : C:\ProgramData\AskPartnerNetwork Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Ordner Gelöscht : C:\Program Files (x86)\myfree codec Ordner Gelöscht : C:\Windows\SysWOW64\AI_RecycleBin Ordner Gelöscht : C:\Users\Deep\AppData\Local\CrashRpt ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKCU\Software\APN PIP Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\TENCENT Schlüssel Gelöscht : HKLM\Software\Myfree Codec Schlüssel Gelöscht : HKLM\Software\TENCENT Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v27.0.1 (de) [ Datei : C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\prefs.js ] Zeile gelöscht : user_pref("extensions.toolbar_CLM-V7@apn.ask.com.install-event-fired", true); -\\ Google Chrome v34.0.1847.116 [ Datei : C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [3356 octets] - [15/04/2014 16:13:48] AdwCleaner[S0].txt - [3070 octets] - [15/04/2014 16:15:58] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3130 octets] ########## Und den Log vom JRT würde ich gerne posten, allerdings gibt es da ein Problem. Nach 10 Minuten hat er wohl ein "bad module" gefunden, und wollte den Rechner gerne neustarten, was ich dann auch getan habe. Nach dem Neustart öffnete sich die Konsole mit einem blinkendem "_", das dann auch eine halbe Stunde so geblieben ist. Bisher hat sich das Programm nicht beendet und es hat auch keinen Log ausgespuckt.. JRT noch einmal durchlaufen lassen? Hier ein frischer FRST FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-04-2014 Ran by Deep (administrator) on BENS-TEN on 15-04-2014 16:28:10 Running from C:\Users\Deep\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Users\Deep\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Spotify Ltd) C:\Users\Deep\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Dropbox, Inc.) C:\Users\Deep\AppData\Roaming\Dropbox\bin\Dropbox.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (Adobe Systems Inc.) E:\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (CyberLink Corp.) E:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\Cyberlink\Shared files\brs.exe () E:\Program Files (x86)\Drakonia Configurator\hid.exe () E:\Program Files (x86)\Drakonia Configurator\trayicon.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\system32\wbem\WMIADAP.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-03] (Adobe Systems Incorporated) HKLM\...\Run: [BCSSync] => E:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8292120 2013-11-14] (Logitech Inc.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation) HKLM-x32\...\Run: [avgnt] => E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => E:\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2013-12-18] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => E:\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2013-12-18] (Adobe Systems Inc.) HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-27] (Intel Corporation) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-08-09] (VIA) HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [RemoteControl10] => E:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe [87336 2011-03-30] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2011-09-28] (cyberlink) HKLM-x32\...\Run: [UCam_Menu] => E:\Program Files (x86)\Cyberlink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [GamingMouse] => E:\Program Files (x86)\Drakonia Configurator\hid.exe [248832 2013-10-29] () HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\Run: [Spotify Web Helper] => C:\Users\Deep\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-05] (Spotify Ltd) HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) Startup: C:\Users\Deep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Deep\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - E:\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default FF Homepage: hxxp://www.facebook.com/ FF Keyword.URL: hxxp://www.google.com/search?sourceid=navclient&hl=de&q= FF NetworkProxy: "ftp", "95.211.129.32" FF NetworkProxy: "ftp_port", 3128 FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "95.211.129.32" FF NetworkProxy: "socks_port", 3128 FF NetworkProxy: "ssl", "95.211.129.32" FF NetworkProxy: "ssl_port", 3128 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Acrobat - E:\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Deep\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Deep\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Deep\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Deep\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin ProgramFiles/Appdata: C:\Users\Deep\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Deep\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\googlede-pws.xml FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\leo-fra-deu.xml FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\youtube-videosuche.xml FF Extension: Разпознаване на устройство Logitech - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\DeviceDetection@logitech.com [2013-06-30] FF Extension: ProxTube - Unblock YouTube - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7} [2013-12-05] FF Extension: ChatZilla - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2013-07-15] FF Extension: WOT - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-27] FF Extension: DownloadHelper - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-28] FF Extension: Firebug - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\firebug@software.joehewitt.com.xpi [2013-06-30] FF Extension: Grooveshark Unlocker - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2013-06-30] FF Extension: Stealthy - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\stealthyextension@gmail.com.xpi [2013-06-30] FF Extension: Ask Toolbar - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\toolbar_CLM-V7@apn.ask.com.xpi [2013-06-17] FF Extension: Flagfox - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-16] FF Extension: NoScript - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-30] FF Extension: SoundCloud Downloader - Technowise - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{c8d3bc80-0810-4d21-a2c2-be5f2b2832ac}.xpi [2013-06-30] FF Extension: Adblock Plus - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-30] FF Extension: Tab Mix Plus - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-06-30] FF Extension: Greasemonkey - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013-06-30] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - E:\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - E:\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-07-01] FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - E:\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} FF Extension: Adobe Contribute Toolbar - E:\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2013-07-01] FF StartMenuInternet: FIREFOX.EXE - E:\Program Files (x86)\Mozilla Firefox\firefox.exe Chrome: ======= CHR Extension: (Adblock Plus) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-27] CHR Extension: (Foxish live RSS) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgagcapnkccceppgljfpoadahaopjdb [2014-03-02] CHR Extension: (Google Wallet) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-13] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S2 CLKMSVC10_F47B619C; E:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-04-20] (CyberLink) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-09] () R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2013-12-09] () S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-03] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-14] (Avira Operations GmbH & Co. KG) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-22] (AVM GmbH) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-12-08] () R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [42016 2013-11-27] (Visicom Media Inc.) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35232 2013-12-06] (Visicom Media Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) R3 umpusbvista; C:\Windows\System32\DRIVERS\umpusbvista.sys [64872 2012-09-13] (Texas Instruments Inc) S3 vhidmini; C:\Windows\System32\DRIVERS\vjoy.sys [15544 2013-04-18] (Headsoft) R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [231112 2013-01-03] (VIA Technologies, Inc.) S3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [35344 2014-01-23] () R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [301256 2013-01-03] (VIA Technologies, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 dgderdrv; System32\drivers\dgderdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-15 16:27 - 2014-04-15 16:27 - 00000000 ____D () C:\Users\Deep\Desktop\FRST-OlderVersion 2014-04-15 16:20 - 2014-04-15 16:20 - 00000000 ____D () C:\Windows\ERUNT 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Downloads\JRT.exe 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Desktop\JRT.exe 2014-04-15 16:18 - 2014-04-15 16:18 - 00003226 _____ () C:\Users\Deep\Desktop\AdwCleaner[S0].txt 2014-04-15 16:13 - 2014-04-15 16:17 - 00000000 ____D () C:\AdwCleaner 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Downloads\adwcleaner.exe 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Desktop\adwcleaner.exe 2014-04-15 16:12 - 2014-04-15 16:12 - 00001147 _____ () C:\Users\Deep\Desktop\mbam.txt 2014-04-15 16:01 - 2014-04-15 16:02 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-15 16:01 - 2014-04-15 16:01 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-15 16:01 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-15 16:01 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-15 16:01 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-15 16:00 - 2014-04-15 16:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Deep\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-15 13:15 - 2014-04-15 13:15 - 00000552 _____ () C:\Windows\PFRO.log 2014-04-15 04:08 - 2014-04-15 04:09 - 75260759 _____ () C:\Users\Deep\Downloads\template_48244_Y46OQQ6Hold2I9B9y0i4.zip 2014-04-15 01:52 - 2014-04-15 01:52 - 00000502 _____ () C:\Users\Deep\Desktop\JOBBÖRSE - Stellenangebot.url 2014-04-15 01:50 - 2014-04-15 16:01 - 00000064 _____ () C:\Users\Deep\Desktop\01635854984.txt 2014-04-15 01:45 - 2014-04-15 01:45 - 00030706 _____ () C:\Users\Deep\Desktop\ComboFix.txt 2014-04-15 01:39 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-15 01:39 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-15 01:39 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-15 01:38 - 2014-04-15 01:45 - 00000000 ____D () C:\Qoobox 2014-04-15 01:38 - 2014-04-15 01:44 - 00000000 ____D () C:\Windows\erdnt 2014-04-14 21:04 - 2014-04-14 21:05 - 05194807 ____R (Swearware) C:\Users\Deep\Desktop\ComboFix.exe 2014-04-14 18:05 - 2014-04-14 18:05 - 00005381 _____ () C:\Users\Deep\Desktop\gmer.log 2014-04-14 18:02 - 2014-04-14 18:02 - 00000000 _____ () C:\Users\Deep\Desktop\irql not less or equal.txt 2014-04-14 18:00 - 2014-04-14 18:00 - 00292904 _____ () C:\Users\Deep\Desktop\041414-5319-01.dmp 2014-04-14 17:57 - 2014-04-14 17:57 - 00380416 _____ () C:\Users\Deep\Desktop\479hej3m.exe 2014-04-14 17:57 - 2014-04-14 17:57 - 00068534 _____ () C:\Users\Deep\Desktop\Addition.txt 2014-04-14 17:56 - 2014-04-15 16:28 - 00022784 _____ () C:\Users\Deep\Desktop\FRST.txt 2014-04-14 17:55 - 2014-04-15 16:27 - 02054144 _____ (Farbar) C:\Users\Deep\Desktop\FRST64.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00050477 _____ () C:\Users\Deep\Desktop\Defogger.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00000470 _____ () C:\Users\Deep\Desktop\defogger_disable.log 2014-04-14 17:50 - 2014-04-14 17:50 - 00000000 _____ () C:\Users\Deep\defogger_reenable 2014-04-12 18:07 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-04-12 18:07 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-04-12 18:04 - 2014-04-15 16:21 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-12 18:04 - 2014-04-12 18:06 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA 2014-04-12 18:04 - 2014-04-02 15:27 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-12 18:04 - 2014-04-02 15:27 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-04-12 18:04 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-04-12 18:03 - 2014-03-04 16:35 - 00062408 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-04-12 18:03 - 2014-03-04 16:35 - 00054216 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-04-12 18:03 - 2014-03-04 15:06 - 06714312 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-04-12 18:03 - 2014-03-04 15:06 - 03497816 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 03649185 _____ () C:\Windows\system32\nvcoproc.bin 2014-04-12 18:03 - 2014-03-04 15:05 - 02558808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 00922968 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-04-12 18:03 - 2014-03-04 15:05 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 00064968 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-04-12 18:02 - 2014-03-21 21:43 - 00037320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 18302384 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 14709720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-04-12 18:02 - 2014-03-04 16:35 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 03093280 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02715264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00947808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00832936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00484296 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00409544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00377688 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00333600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00024544 _____ () C:\Windows\system32\nvinfo.pb 2014-04-12 18:02 - 2013-11-28 15:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-04-12 18:02 - 2013-11-28 15:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-04-12 18:02 - 2013-11-22 10:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2014-04-12 18:01 - 2014-04-12 18:01 - 00000000 ____D () C:\NVIDIA 2014-04-12 17:57 - 2014-04-15 16:22 - 00005237 _____ () C:\Windows\setupact.log 2014-04-12 17:57 - 2014-04-12 17:57 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-12 17:45 - 2014-04-12 22:17 - 00000000 ____D () C:\Windows\System32\Tasks\Aufgaben der Ereignisanzeige 2014-04-12 17:41 - 2014-04-12 17:41 - 00143170 _____ () C:\Users\Deep\Desktop\cc_20140412_174133.reg 2014-04-11 20:51 - 2014-04-11 20:51 - 00000000 ____D () C:\Users\Deep\Documents\Gaslamp Games 2014-04-11 17:20 - 2014-04-15 16:26 - 00909157 _____ () C:\Windows\WindowsUpdate.log 2014-04-11 14:21 - 2014-04-11 14:21 - 00000074 _____ () C:\Users\Deep\Desktop\arbeit montag.txt 2014-04-11 13:40 - 2014-04-11 13:40 - 06812228 _____ () C:\Users\Deep\Downloads\wordpress-3.8.2-de_DE.zip 2014-04-10 14:15 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 14:15 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 14:15 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 14:15 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 14:15 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 14:15 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 14:15 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 14:15 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 14:15 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 14:15 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 14:15 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 14:15 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 14:15 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 14:15 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 14:15 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 14:15 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 02:33 - 2014-04-09 02:33 - 00000020 _____ () C:\Users\Deep\Desktop\lkmnnklnklnl.txt 2014-04-07 13:17 - 2014-04-07 13:17 - 00001250 _____ () C:\Users\Deep\Desktop\poker night 2.txt 2014-04-03 15:37 - 2014-04-03 15:37 - 00000000 ____D () C:\Users\Deep\Documents\Reus 2014-04-01 14:31 - 2014-04-01 14:31 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-04-01 14:31 - 2014-03-19 03:27 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2014-04-01 14:31 - 2014-03-19 03:27 - 00109056 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2014-04-01 13:46 - 2014-04-01 14:25 - 00000000 ____D () C:\Users\Deep\Desktop\bu 2014-04-01 13:16 - 2014-04-01 13:16 - 00000000 ____D () C:\Users\Deep\Documents\SelfMV 2014-04-01 13:12 - 2014-01-23 18:23 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\Windows\SysWOW64\secman.dll 2014-03-29 23:58 - 2014-03-29 23:58 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\com.valve.FTP 2014-03-28 12:36 - 2014-03-28 12:42 - 00000000 ____D () C:\ProgramData\BlueStacksSetup 2014-03-25 02:04 - 2014-03-25 02:04 - 00000860 _____ () C:\Users\Deep\Downloads\social-gallery-wordpress-photo-viewer-plugin-license.txt 2014-03-21 02:14 - 2014-03-21 02:14 - 00000000 _____ () C:\Users\Deep\Desktop\13.4. mtv movie awards.txt 2014-03-18 20:45 - 2014-03-18 22:37 - 00000068 _____ () C:\Users\Deep\Desktop\bücher.txt 2014-03-17 18:57 - 2014-03-17 22:45 - 01246037 _____ () C:\Users\Deep\Desktop\Zeugnisse.zip 2014-03-16 21:18 - 2014-03-16 21:18 - 00003176 _____ () C:\Windows\System32\Tasks\{51082A01-2654-4B14-86E4-8EF0FE809968} ==================== One Month Modified Files and Folders ======= 2014-04-15 16:28 - 2014-04-14 17:56 - 00022784 _____ () C:\Users\Deep\Desktop\FRST.txt 2014-04-15 16:28 - 2014-03-07 16:00 - 00000000 ____D () C:\FRST 2014-04-15 16:27 - 2014-04-15 16:27 - 00000000 ____D () C:\Users\Deep\Desktop\FRST-OlderVersion 2014-04-15 16:27 - 2014-04-14 17:55 - 02054144 _____ (Farbar) C:\Users\Deep\Desktop\FRST64.exe 2014-04-15 16:26 - 2014-04-11 17:20 - 00909157 _____ () C:\Windows\WindowsUpdate.log 2014-04-15 16:22 - 2014-04-12 17:57 - 00005237 _____ () C:\Windows\setupact.log 2014-04-15 16:21 - 2014-04-12 18:04 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-15 16:21 - 2014-01-13 19:37 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-15 16:21 - 2013-06-30 20:24 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Dropbox 2014-04-15 16:21 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-15 16:21 - 2009-07-14 06:45 - 00026864 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-15 16:21 - 2009-07-14 06:45 - 00026864 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-15 16:20 - 2014-04-15 16:20 - 00000000 ____D () C:\Windows\ERUNT 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Downloads\JRT.exe 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Desktop\JRT.exe 2014-04-15 16:18 - 2014-04-15 16:18 - 00003226 _____ () C:\Users\Deep\Desktop\AdwCleaner[S0].txt 2014-04-15 16:18 - 2013-06-30 20:26 - 00000000 ___RD () C:\Users\Deep\Dropbox 2014-04-15 16:17 - 2014-04-15 16:13 - 00000000 ____D () C:\AdwCleaner 2014-04-15 16:17 - 2014-02-11 17:06 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA.job 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Downloads\adwcleaner.exe 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Desktop\adwcleaner.exe 2014-04-15 16:12 - 2014-04-15 16:12 - 00001147 _____ () C:\Users\Deep\Desktop\mbam.txt 2014-04-15 16:02 - 2014-04-15 16:01 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-15 16:01 - 2014-04-15 16:01 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-15 16:01 - 2014-04-15 01:50 - 00000064 _____ () C:\Users\Deep\Desktop\01635854984.txt 2014-04-15 16:00 - 2014-04-15 16:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Deep\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-15 15:58 - 2014-01-13 19:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-15 15:33 - 2013-06-30 19:34 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-15 14:58 - 2013-07-07 14:13 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\FileZilla 2014-04-15 13:17 - 2014-02-11 17:06 - 00001064 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core.job 2014-04-15 13:15 - 2014-04-15 13:15 - 00000552 _____ () C:\Windows\PFRO.log 2014-04-15 04:17 - 2014-01-03 16:40 - 00000000 ____D () C:\Users\Deep\Desktop\stip n study 2014-04-15 04:09 - 2014-04-15 04:08 - 75260759 _____ () C:\Users\Deep\Downloads\template_48244_Y46OQQ6Hold2I9B9y0i4.zip 2014-04-15 04:09 - 2014-01-13 16:41 - 00000000 ____D () C:\Users\Deep\Arbeit 2014-04-15 03:36 - 2013-06-30 18:51 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\TS3Client 2014-04-15 02:00 - 2013-06-30 19:33 - 00000000 ____D () C:\Users\Deep\AppData\Local\Adobe 2014-04-15 01:52 - 2014-04-15 01:52 - 00000502 _____ () C:\Users\Deep\Desktop\JOBBÖRSE - Stellenangebot.url 2014-04-15 01:45 - 2014-04-15 01:45 - 00030706 _____ () C:\Users\Deep\Desktop\ComboFix.txt 2014-04-15 01:45 - 2014-04-15 01:38 - 00000000 ____D () C:\Qoobox 2014-04-15 01:45 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-04-15 01:44 - 2014-04-15 01:38 - 00000000 ____D () C:\Windows\erdnt 2014-04-15 01:44 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-14 21:05 - 2014-04-14 21:04 - 05194807 ____R (Swearware) C:\Users\Deep\Desktop\ComboFix.exe 2014-04-14 18:05 - 2014-04-14 18:05 - 00005381 _____ () C:\Users\Deep\Desktop\gmer.log 2014-04-14 18:02 - 2014-04-14 18:02 - 00000000 _____ () C:\Users\Deep\Desktop\irql not less or equal.txt 2014-04-14 18:01 - 2014-01-07 13:45 - 00000000 ____D () C:\Users\Deep\Documents\Visual Studio 2010 2014-04-14 18:01 - 2013-07-01 16:34 - 00000000 ____D () C:\Windows\Minidump 2014-04-14 18:00 - 2014-04-14 18:00 - 00292904 _____ () C:\Users\Deep\Desktop\041414-5319-01.dmp 2014-04-14 17:57 - 2014-04-14 17:57 - 00380416 _____ () C:\Users\Deep\Desktop\479hej3m.exe 2014-04-14 17:57 - 2014-04-14 17:57 - 00068534 _____ () C:\Users\Deep\Desktop\Addition.txt 2014-04-14 17:50 - 2014-04-14 17:50 - 00050477 _____ () C:\Users\Deep\Desktop\Defogger.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00000470 _____ () C:\Users\Deep\Desktop\defogger_disable.log 2014-04-14 17:50 - 2014-04-14 17:50 - 00000000 _____ () C:\Users\Deep\defogger_reenable 2014-04-14 17:50 - 2013-06-30 17:26 - 00000000 ____D () C:\Users\Deep 2014-04-14 17:47 - 2013-07-01 03:18 - 00765588 _____ () C:\Windows\system32\perfh007.dat 2014-04-14 17:47 - 2013-07-01 03:18 - 00174818 _____ () C:\Windows\system32\perfc007.dat 2014-04-14 17:47 - 2009-07-14 07:13 - 01807338 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-14 17:03 - 2013-06-30 19:03 - 00000000 ____D () C:\Users\Deep\AppData\Local\Spotify 2014-04-14 17:03 - 2013-06-30 19:02 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Spotify 2014-04-12 22:17 - 2014-04-12 17:45 - 00000000 ____D () C:\Windows\System32\Tasks\Aufgaben der Ereignisanzeige 2014-04-12 18:07 - 2013-11-29 13:16 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA Corporation 2014-04-12 18:07 - 2013-09-28 00:36 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-04-12 18:07 - 2013-06-30 17:39 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-12 18:06 - 2014-04-12 18:04 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA 2014-04-12 18:04 - 2013-07-01 00:36 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-04-12 18:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-04-12 18:02 - 2013-09-28 00:42 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\NVIDIA 2014-04-12 18:01 - 2014-04-12 18:01 - 00000000 ____D () C:\NVIDIA 2014-04-12 17:57 - 2014-04-12 17:57 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-12 17:41 - 2014-04-12 17:41 - 00143170 _____ () C:\Users\Deep\Desktop\cc_20140412_174133.reg 2014-04-12 17:27 - 2013-06-30 18:54 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Skype 2014-04-11 20:51 - 2014-04-11 20:51 - 00000000 ____D () C:\Users\Deep\Documents\Gaslamp Games 2014-04-11 17:18 - 2013-12-02 22:24 - 00000000 ____D () C:\Users\Deep\AppData\Local\CrashDumps 2014-04-11 14:21 - 2014-04-11 14:21 - 00000074 _____ () C:\Users\Deep\Desktop\arbeit montag.txt 2014-04-11 13:40 - 2014-04-11 13:40 - 06812228 _____ () C:\Users\Deep\Downloads\wordpress-3.8.2-de_DE.zip 2014-04-11 03:02 - 2013-08-16 00:11 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 03:02 - 2013-07-01 19:10 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-11 03:00 - 2013-07-01 17:02 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 02:33 - 2014-04-09 02:33 - 00000020 _____ () C:\Users\Deep\Desktop\lkmnnklnklnl.txt 2014-04-07 13:17 - 2014-04-07 13:17 - 00001250 _____ () C:\Users\Deep\Desktop\poker night 2.txt 2014-04-06 01:05 - 2013-06-30 19:07 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\vlc 2014-04-03 15:37 - 2014-04-03 15:37 - 00000000 ____D () C:\Users\Deep\Documents\Reus 2014-04-03 14:46 - 2013-08-08 17:30 - 00001794 _____ () C:\Users\Deep\Desktop\steam keys.txt 2014-04-03 09:51 - 2014-04-15 16:01 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-15 16:01 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-15 16:01 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 17:14 - 2013-10-17 07:31 - 00000000 ____D () C:\Users\Deep\Documents\samsung 2014-04-02 15:27 - 2014-04-12 18:04 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-02 15:27 - 2014-04-12 18:04 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-04-02 01:57 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-04-01 14:31 - 2014-04-01 14:31 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-04-01 14:30 - 2013-10-01 16:07 - 00000000 ____D () C:\ProgramData\Samsung 2014-04-01 14:25 - 2014-04-01 13:46 - 00000000 ____D () C:\Users\Deep\Desktop\bu 2014-04-01 13:45 - 2013-09-30 19:45 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Samsung 2014-04-01 13:45 - 2013-06-30 17:37 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-01 13:43 - 2013-06-30 19:27 - 00000000 ____D () C:\Program Files (x86)\LOLReplay 2014-04-01 13:16 - 2014-04-01 13:16 - 00000000 ____D () C:\Users\Deep\Documents\SelfMV 2014-04-01 13:14 - 2013-10-17 07:31 - 00000000 ____D () C:\Users\Deep\AppData\Local\Samsung 2014-04-01 13:11 - 2013-10-01 16:05 - 00000000 ____D () C:\Users\Deep\AppData\Local\Downloaded Installations 2014-03-31 19:01 - 2013-07-02 19:52 - 00000132 _____ () C:\Users\Deep\AppData\Roaming\Adobe PNG Format CS5 Prefs 2014-03-31 13:12 - 2014-02-11 17:06 - 00004088 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA 2014-03-31 13:12 - 2014-02-11 17:06 - 00003692 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core 2014-03-31 03:16 - 2014-04-10 14:15 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 14:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 14:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 14:15 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-29 23:58 - 2014-03-29 23:58 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\com.valve.FTP 2014-03-28 23:35 - 2013-12-05 02:17 - 00001456 _____ () C:\Users\Deep\AppData\Local\Adobe Für Web speichern 12.0 Prefs 2014-03-28 17:53 - 2014-01-13 19:37 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-28 17:53 - 2014-01-13 19:37 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-28 12:42 - 2014-03-28 12:36 - 00000000 ____D () C:\ProgramData\BlueStacksSetup 2014-03-25 02:04 - 2014-03-25 02:04 - 00000860 _____ () C:\Users\Deep\Downloads\social-gallery-wordpress-photo-viewer-plugin-license.txt 2014-03-24 17:26 - 2014-02-28 12:41 - 00000000 ____D () C:\Users\Deep\Desktop\reisen 2014-03-21 21:43 - 2014-04-12 18:07 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-03-21 21:43 - 2014-04-12 18:07 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-03-21 21:43 - 2014-04-12 18:02 - 00037320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-03-21 02:14 - 2014-03-21 02:14 - 00000000 _____ () C:\Users\Deep\Desktop\13.4. mtv movie awards.txt 2014-03-20 22:29 - 2013-06-30 18:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-19 17:13 - 2013-06-30 17:54 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Mozilla 2014-03-19 03:27 - 2014-04-01 14:31 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2014-03-19 03:27 - 2014-04-01 14:31 - 00109056 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2014-03-18 22:37 - 2014-03-18 20:45 - 00000068 _____ () C:\Users\Deep\Desktop\bücher.txt 2014-03-17 22:45 - 2014-03-17 18:57 - 01246037 _____ () C:\Users\Deep\Desktop\Zeugnisse.zip 2014-03-16 23:33 - 2013-10-05 01:54 - 00000057 _____ () C:\Users\Deep\Desktop\filme.txt 2014-03-16 21:18 - 2014-03-16 21:18 - 00003176 _____ () C:\Windows\System32\Tasks\{51082A01-2654-4B14-86E4-8EF0FE809968} 2014-03-16 00:22 - 2014-01-24 00:10 - 00000132 _____ () C:\Users\Deep\AppData\Roaming\Adobe GIF Format CS5 Prefs Some content of TEMP: ==================== C:\Users\Deep\AppData\Local\Temp\avgnt.exe C:\Users\Deep\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-11 15:03 ==================== End Of Log ============================ |
16.04.2014, 18:42 | #6 |
/// the machine /// TB-Ausbilder | Win7 - Regelmäßige SystemabstürzeESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Win7 - Regelmäßige Systemabstürze |
18.04.2014, 00:06 | #7 |
| Win7 - Regelmäßige Systemabstürze Nach ganzen 9 Stunden und 24 Minuten (und mein Rechner ist wirklich schnell!) war ESET dann fertig und hat 0 Bedrohungen gefunden. Hier der Log: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=98cbdbaf75d4dd45a7fdbaa7fe101139 # engine=17925 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-17 09:49:03 # local_time=2014-04-17 11:49:03 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 96 70922 25160960 63703 0 # compatibility_mode=5893 16776573 100 94 90636 149401193 0 0 # scanned=981204 # found=0 # cleaned=0 # scan_time=34945 Code:
ATTFilter Results of screen317's Security Check version 0.99.81 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` DH Driver Cleaner Professional Edition Java 7 Update 51 Adobe Flash Player 12.0.0.77 Mozilla Firefox (28.0) Mozilla Thunderbird (24.4.0) Google Chrome 33.0.1750.154 Google Chrome 34.0.1847.116 ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01 Ran by Deep (administrator) on BENS-TEN on 18-04-2014 01:04:44 Running from C:\Users\Deep\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Users\Deep\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Spotify Ltd) C:\Users\Deep\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Visicom Media Inc.) C:\Program Files (x86)\ManyCam\ManyCam.exe (Dropbox, Inc.) C:\Users\Deep\AppData\Roaming\Dropbox\bin\Dropbox.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Adobe Systems Inc.) E:\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (CyberLink Corp.) E:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\Cyberlink\Shared files\brs.exe () E:\Program Files (x86)\Drakonia Configurator\hid.exe () E:\Program Files (x86)\Drakonia Configurator\trayicon.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (TeamSpeak Systems GmbH) E:\Program Files\TeamSpeak\ts3client_win64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-03] (Adobe Systems Incorporated) HKLM\...\Run: [BCSSync] => E:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8292120 2013-11-14] (Logitech Inc.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation) HKLM-x32\...\Run: [avgnt] => E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => E:\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2013-12-18] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => E:\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2013-12-18] (Adobe Systems Inc.) HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-27] (Intel Corporation) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-08-09] (VIA) HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [RemoteControl10] => E:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe [87336 2011-03-30] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2011-09-28] (cyberlink) HKLM-x32\...\Run: [GamingMouse] => E:\Program Files (x86)\Drakonia Configurator\hid.exe [248832 2013-10-29] () HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\Run: [Spotify Web Helper] => C:\Users\Deep\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-05] (Spotify Ltd) HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\Run: [ManyCam] => C:\Program Files (x86)\ManyCam\ManyCam.exe [8473064 2014-03-26] (Visicom Media Inc.) Startup: C:\Users\Deep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Deep\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - E:\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default FF Homepage: hxxp://www.facebook.com/ FF Keyword.URL: hxxp://www.google.com/search?sourceid=navclient&hl=de&q= FF NetworkProxy: "ftp", "95.211.129.32" FF NetworkProxy: "ftp_port", 3128 FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "95.211.129.32" FF NetworkProxy: "socks_port", 3128 FF NetworkProxy: "ssl", "95.211.129.32" FF NetworkProxy: "ssl_port", 3128 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Acrobat - E:\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Deep\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Deep\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Deep\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Deep\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin ProgramFiles/Appdata: C:\Users\Deep\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Deep\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\googlede-pws.xml FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\leo-fra-deu.xml FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\youtube-videosuche.xml FF Extension: Разпознаване на устройство Logitech - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\DeviceDetection@logitech.com [2013-06-30] FF Extension: ProxTube - Unblock YouTube - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7} [2013-12-05] FF Extension: ChatZilla - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2013-07-15] FF Extension: WOT - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-27] FF Extension: DownloadHelper - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-28] FF Extension: Firebug - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\firebug@software.joehewitt.com.xpi [2013-06-30] FF Extension: Grooveshark Unlocker - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2013-06-30] FF Extension: Stealthy - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\stealthyextension@gmail.com.xpi [2013-06-30] FF Extension: Ask Toolbar - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\toolbar_CLM-V7@apn.ask.com.xpi [2013-06-17] FF Extension: Flagfox - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-16] FF Extension: NoScript - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-30] FF Extension: SoundCloud Downloader - Technowise - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{c8d3bc80-0810-4d21-a2c2-be5f2b2832ac}.xpi [2013-06-30] FF Extension: Adblock Plus - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-30] FF Extension: Tab Mix Plus - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-06-30] FF Extension: Greasemonkey - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013-06-30] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - E:\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - E:\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-07-01] FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - E:\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} FF Extension: Adobe Contribute Toolbar - E:\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2013-07-01] FF StartMenuInternet: FIREFOX.EXE - E:\Program Files (x86)\Mozilla Firefox\firefox.exe Chrome: ======= CHR StartupUrls: "hxxp://www.facebook.com/" CHR Extension: (Adblock Plus) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-27] CHR Extension: (Foxish live RSS) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgagcapnkccceppgljfpoadahaopjdb [2014-03-02] CHR Extension: (Google Wallet) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-13] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S2 CLKMSVC10_F47B619C; E:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-04-20] (CyberLink) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-09] () R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2013-12-09] () S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-03] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-14] (Avira Operations GmbH & Co. KG) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-22] (AVM GmbH) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-12-08] () R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [42016 2013-11-27] (Visicom Media Inc.) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35232 2013-12-06] (Visicom Media Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) R3 umpusbvista; C:\Windows\System32\DRIVERS\umpusbvista.sys [64872 2012-09-13] (Texas Instruments Inc) S3 vhidmini; C:\Windows\System32\DRIVERS\vjoy.sys [15544 2013-04-18] (Headsoft) R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [231112 2013-01-03] (VIA Technologies, Inc.) S3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [35344 2014-01-23] () R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [301256 2013-01-03] (VIA Technologies, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 dgderdrv; System32\drivers\dgderdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-18 01:01 - 2014-04-18 01:00 - 00987448 _____ () C:\Users\Deep\Desktop\SecurityCheck.exe 2014-04-18 01:00 - 2014-04-18 01:00 - 00987448 _____ () C:\Users\Deep\Downloads\SecurityCheck.exe 2014-04-17 14:05 - 2014-04-17 14:05 - 02347384 _____ (ESET) C:\Users\Deep\Downloads\esetsmartinstaller_enu.exe 2014-04-17 14:05 - 2014-04-17 14:05 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-17 04:43 - 2014-04-17 04:43 - 02185139 _____ () C:\Users\Deep\Downloads\CherryFramework_v3.1.1.zip 2014-04-16 22:50 - 2014-04-16 22:50 - 00613200 _____ (Chip Digital GmbH) C:\Users\Deep\Downloads\ManyCam - CHIP-Downloader.exe 2014-04-15 16:27 - 2014-04-18 01:04 - 00000000 ____D () C:\Users\Deep\Desktop\FRST-OlderVersion 2014-04-15 16:20 - 2014-04-15 16:20 - 00000000 ____D () C:\Windows\ERUNT 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Downloads\JRT.exe 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Desktop\JRT.exe 2014-04-15 16:18 - 2014-04-15 16:18 - 00003226 _____ () C:\Users\Deep\Desktop\AdwCleaner[S0].txt 2014-04-15 16:13 - 2014-04-15 16:17 - 00000000 ____D () C:\AdwCleaner 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Downloads\adwcleaner.exe 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Desktop\adwcleaner.exe 2014-04-15 16:12 - 2014-04-15 16:12 - 00001147 _____ () C:\Users\Deep\Desktop\mbam.txt 2014-04-15 16:01 - 2014-04-15 16:02 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-15 16:01 - 2014-04-15 16:01 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-15 16:01 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-15 16:01 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-15 16:01 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-15 16:00 - 2014-04-15 16:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Deep\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-15 13:15 - 2014-04-15 13:15 - 00000552 _____ () C:\Windows\PFRO.log 2014-04-15 04:08 - 2014-04-15 04:09 - 75260759 _____ () C:\Users\Deep\Downloads\template_48244_Y46OQQ6Hold2I9B9y0i4.zip 2014-04-15 01:50 - 2014-04-15 16:57 - 00000102 _____ () C:\Users\Deep\Desktop\01635854984.txt 2014-04-15 01:45 - 2014-04-15 01:45 - 00030706 _____ () C:\Users\Deep\Desktop\ComboFix.txt 2014-04-15 01:39 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-15 01:39 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-15 01:39 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-15 01:38 - 2014-04-15 01:45 - 00000000 ____D () C:\Qoobox 2014-04-15 01:38 - 2014-04-15 01:44 - 00000000 ____D () C:\Windows\erdnt 2014-04-14 21:04 - 2014-04-14 21:05 - 05194807 ____R (Swearware) C:\Users\Deep\Desktop\ComboFix.exe 2014-04-14 18:05 - 2014-04-14 18:05 - 00005381 _____ () C:\Users\Deep\Desktop\gmer.log 2014-04-14 18:02 - 2014-04-14 18:02 - 00000000 _____ () C:\Users\Deep\Desktop\irql not less or equal.txt 2014-04-14 18:00 - 2014-04-14 18:00 - 00292904 _____ () C:\Users\Deep\Desktop\041414-5319-01.dmp 2014-04-14 17:57 - 2014-04-14 17:57 - 00380416 _____ () C:\Users\Deep\Desktop\479hej3m.exe 2014-04-14 17:57 - 2014-04-14 17:57 - 00068534 _____ () C:\Users\Deep\Desktop\Addition.txt 2014-04-14 17:56 - 2014-04-18 01:04 - 00022829 _____ () C:\Users\Deep\Desktop\FRST.txt 2014-04-14 17:55 - 2014-04-18 01:04 - 02158592 _____ (Farbar) C:\Users\Deep\Desktop\FRST64.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00050477 _____ () C:\Users\Deep\Desktop\Defogger.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00000470 _____ () C:\Users\Deep\Desktop\defogger_disable.log 2014-04-14 17:50 - 2014-04-14 17:50 - 00000000 _____ () C:\Users\Deep\defogger_reenable 2014-04-12 18:07 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-04-12 18:07 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-04-12 18:04 - 2014-04-17 14:02 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-12 18:04 - 2014-04-12 18:06 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA 2014-04-12 18:04 - 2014-04-02 15:27 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-12 18:04 - 2014-04-02 15:27 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-04-12 18:04 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-04-12 18:03 - 2014-03-04 16:35 - 00062408 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-04-12 18:03 - 2014-03-04 16:35 - 00054216 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-04-12 18:03 - 2014-03-04 15:06 - 06714312 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-04-12 18:03 - 2014-03-04 15:06 - 03497816 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 03649185 _____ () C:\Windows\system32\nvcoproc.bin 2014-04-12 18:03 - 2014-03-04 15:05 - 02558808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 00922968 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-04-12 18:03 - 2014-03-04 15:05 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 00064968 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-04-12 18:02 - 2014-03-21 21:43 - 00037320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 18302384 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 14709720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-04-12 18:02 - 2014-03-04 16:35 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 03093280 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02715264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00947808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00832936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00484296 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00409544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00377688 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00333600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00024544 _____ () C:\Windows\system32\nvinfo.pb 2014-04-12 18:02 - 2013-11-28 15:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-04-12 18:02 - 2013-11-28 15:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-04-12 18:02 - 2013-11-22 10:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2014-04-12 18:01 - 2014-04-12 18:01 - 00000000 ____D () C:\NVIDIA 2014-04-12 17:57 - 2014-04-17 14:02 - 00008709 _____ () C:\Windows\setupact.log 2014-04-12 17:57 - 2014-04-12 17:57 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-12 17:45 - 2014-04-12 22:17 - 00000000 ____D () C:\Windows\System32\Tasks\Aufgaben der Ereignisanzeige 2014-04-12 17:41 - 2014-04-12 17:41 - 00143170 _____ () C:\Users\Deep\Desktop\cc_20140412_174133.reg 2014-04-11 20:51 - 2014-04-11 20:51 - 00000000 ____D () C:\Users\Deep\Documents\Gaslamp Games 2014-04-11 17:20 - 2014-04-18 00:20 - 01319609 _____ () C:\Windows\WindowsUpdate.log 2014-04-10 14:15 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 14:15 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 14:15 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 14:15 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 14:15 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 14:15 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 14:15 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 14:15 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 14:15 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 14:15 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 14:15 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 14:15 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 14:15 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 14:15 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 14:15 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 14:15 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 02:33 - 2014-04-09 02:33 - 00000020 _____ () C:\Users\Deep\Desktop\lkmnnklnklnl.txt 2014-04-07 13:17 - 2014-04-07 13:17 - 00001250 _____ () C:\Users\Deep\Desktop\poker night 2.txt 2014-04-03 15:37 - 2014-04-03 15:37 - 00000000 ____D () C:\Users\Deep\Documents\Reus 2014-04-01 14:31 - 2014-04-01 14:31 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-04-01 14:31 - 2014-03-19 03:27 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2014-04-01 14:31 - 2014-03-19 03:27 - 00109056 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2014-04-01 13:46 - 2014-04-01 14:25 - 00000000 ____D () C:\Users\Deep\Desktop\bu 2014-04-01 13:16 - 2014-04-01 13:16 - 00000000 ____D () C:\Users\Deep\Documents\SelfMV 2014-04-01 13:12 - 2014-01-23 18:23 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\Windows\SysWOW64\secman.dll 2014-03-29 23:58 - 2014-03-29 23:58 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\com.valve.FTP 2014-03-28 12:36 - 2014-03-28 12:42 - 00000000 ____D () C:\ProgramData\BlueStacksSetup 2014-03-25 02:04 - 2014-03-25 02:04 - 00000860 _____ () C:\Users\Deep\Downloads\social-gallery-wordpress-photo-viewer-plugin-license.txt 2014-03-21 02:14 - 2014-03-21 02:14 - 00000000 _____ () C:\Users\Deep\Desktop\13.4. mtv movie awards.txt ==================== One Month Modified Files and Folders ======= 2014-04-18 01:04 - 2014-04-15 16:27 - 00000000 ____D () C:\Users\Deep\Desktop\FRST-OlderVersion 2014-04-18 01:04 - 2014-04-14 17:56 - 00022829 _____ () C:\Users\Deep\Desktop\FRST.txt 2014-04-18 01:04 - 2014-04-14 17:55 - 02158592 _____ (Farbar) C:\Users\Deep\Desktop\FRST64.exe 2014-04-18 01:04 - 2014-03-07 16:00 - 00000000 ____D () C:\FRST 2014-04-18 01:00 - 2014-04-18 01:01 - 00987448 _____ () C:\Users\Deep\Desktop\SecurityCheck.exe 2014-04-18 01:00 - 2014-04-18 01:00 - 00987448 _____ () C:\Users\Deep\Downloads\SecurityCheck.exe 2014-04-18 01:00 - 2013-06-30 20:24 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Dropbox 2014-04-18 00:58 - 2014-01-13 19:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-18 00:58 - 2013-06-30 18:51 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\TS3Client 2014-04-18 00:33 - 2013-06-30 19:34 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-18 00:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-18 00:20 - 2014-04-11 17:20 - 01319609 _____ () C:\Windows\WindowsUpdate.log 2014-04-18 00:17 - 2014-02-11 17:06 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA.job 2014-04-17 18:59 - 2013-08-08 17:30 - 00001801 _____ () C:\Users\Deep\Desktop\steam keys.txt 2014-04-17 18:57 - 2013-06-30 19:07 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\vlc 2014-04-17 16:58 - 2014-01-13 19:37 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-17 14:46 - 2013-07-07 14:13 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\FileZilla 2014-04-17 14:09 - 2009-07-14 06:45 - 00026864 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-17 14:09 - 2009-07-14 06:45 - 00026864 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-17 14:05 - 2014-04-17 14:05 - 02347384 _____ (ESET) C:\Users\Deep\Downloads\esetsmartinstaller_enu.exe 2014-04-17 14:05 - 2014-04-17 14:05 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-17 14:03 - 2013-06-30 20:26 - 00000000 ___RD () C:\Users\Deep\Dropbox 2014-04-17 14:02 - 2014-04-12 18:04 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-17 14:02 - 2014-04-12 17:57 - 00008709 _____ () C:\Windows\setupact.log 2014-04-17 14:02 - 2013-06-30 18:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-17 14:02 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-17 04:43 - 2014-04-17 04:43 - 02185139 _____ () C:\Users\Deep\Downloads\CherryFramework_v3.1.1.zip 2014-04-17 04:01 - 2013-06-30 19:02 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Spotify 2014-04-17 03:56 - 2014-01-13 16:41 - 00000000 ____D () C:\Users\Deep\Arbeit 2014-04-17 02:45 - 2013-06-30 19:03 - 00000000 ____D () C:\Users\Deep\AppData\Local\Spotify 2014-04-17 02:00 - 2013-06-30 19:33 - 00000000 ____D () C:\Users\Deep\AppData\Local\Adobe 2014-04-16 23:43 - 2013-06-30 18:54 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Skype 2014-04-16 22:51 - 2014-02-01 22:30 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\ManyCam 2014-04-16 22:51 - 2014-02-01 22:30 - 00000000 ____D () C:\Users\Deep\AppData\Local\ManyCam 2014-04-16 22:51 - 2014-02-01 22:29 - 00000000 ____D () C:\Program Files (x86)\ManyCam 2014-04-16 22:51 - 2014-02-01 22:26 - 00000000 ____D () C:\Users\Deep\Documents\Youcam 2014-04-16 22:50 - 2014-04-16 22:50 - 00613200 _____ (Chip Digital GmbH) C:\Users\Deep\Downloads\ManyCam - CHIP-Downloader.exe 2014-04-15 16:57 - 2014-04-15 01:50 - 00000102 _____ () C:\Users\Deep\Desktop\01635854984.txt 2014-04-15 16:20 - 2014-04-15 16:20 - 00000000 ____D () C:\Windows\ERUNT 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Downloads\JRT.exe 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Desktop\JRT.exe 2014-04-15 16:18 - 2014-04-15 16:18 - 00003226 _____ () C:\Users\Deep\Desktop\AdwCleaner[S0].txt 2014-04-15 16:17 - 2014-04-15 16:13 - 00000000 ____D () C:\AdwCleaner 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Downloads\adwcleaner.exe 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Desktop\adwcleaner.exe 2014-04-15 16:12 - 2014-04-15 16:12 - 00001147 _____ () C:\Users\Deep\Desktop\mbam.txt 2014-04-15 16:02 - 2014-04-15 16:01 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-15 16:01 - 2014-04-15 16:01 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-15 16:00 - 2014-04-15 16:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Deep\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-15 13:17 - 2014-02-11 17:06 - 00001064 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core.job 2014-04-15 13:15 - 2014-04-15 13:15 - 00000552 _____ () C:\Windows\PFRO.log 2014-04-15 04:17 - 2014-01-03 16:40 - 00000000 ____D () C:\Users\Deep\Desktop\stip n study 2014-04-15 04:09 - 2014-04-15 04:08 - 75260759 _____ () C:\Users\Deep\Downloads\template_48244_Y46OQQ6Hold2I9B9y0i4.zip 2014-04-15 01:45 - 2014-04-15 01:45 - 00030706 _____ () C:\Users\Deep\Desktop\ComboFix.txt 2014-04-15 01:45 - 2014-04-15 01:38 - 00000000 ____D () C:\Qoobox 2014-04-15 01:45 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-04-15 01:44 - 2014-04-15 01:38 - 00000000 ____D () C:\Windows\erdnt 2014-04-15 01:44 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-14 21:05 - 2014-04-14 21:04 - 05194807 ____R (Swearware) C:\Users\Deep\Desktop\ComboFix.exe 2014-04-14 18:05 - 2014-04-14 18:05 - 00005381 _____ () C:\Users\Deep\Desktop\gmer.log 2014-04-14 18:02 - 2014-04-14 18:02 - 00000000 _____ () C:\Users\Deep\Desktop\irql not less or equal.txt 2014-04-14 18:01 - 2014-01-07 13:45 - 00000000 ____D () C:\Users\Deep\Documents\Visual Studio 2010 2014-04-14 18:01 - 2013-07-01 16:34 - 00000000 ____D () C:\Windows\Minidump 2014-04-14 18:00 - 2014-04-14 18:00 - 00292904 _____ () C:\Users\Deep\Desktop\041414-5319-01.dmp 2014-04-14 17:57 - 2014-04-14 17:57 - 00380416 _____ () C:\Users\Deep\Desktop\479hej3m.exe 2014-04-14 17:57 - 2014-04-14 17:57 - 00068534 _____ () C:\Users\Deep\Desktop\Addition.txt 2014-04-14 17:50 - 2014-04-14 17:50 - 00050477 _____ () C:\Users\Deep\Desktop\Defogger.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00000470 _____ () C:\Users\Deep\Desktop\defogger_disable.log 2014-04-14 17:50 - 2014-04-14 17:50 - 00000000 _____ () C:\Users\Deep\defogger_reenable 2014-04-14 17:50 - 2013-06-30 17:26 - 00000000 ____D () C:\Users\Deep 2014-04-14 17:47 - 2013-07-01 03:18 - 00765588 _____ () C:\Windows\system32\perfh007.dat 2014-04-14 17:47 - 2013-07-01 03:18 - 00174818 _____ () C:\Windows\system32\perfc007.dat 2014-04-14 17:47 - 2009-07-14 07:13 - 01807338 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-12 22:17 - 2014-04-12 17:45 - 00000000 ____D () C:\Windows\System32\Tasks\Aufgaben der Ereignisanzeige 2014-04-12 18:07 - 2013-11-29 13:16 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA Corporation 2014-04-12 18:07 - 2013-09-28 00:36 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-04-12 18:07 - 2013-06-30 17:39 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-12 18:06 - 2014-04-12 18:04 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA 2014-04-12 18:04 - 2013-07-01 00:36 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-04-12 18:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-04-12 18:02 - 2013-09-28 00:42 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\NVIDIA 2014-04-12 18:01 - 2014-04-12 18:01 - 00000000 ____D () C:\NVIDIA 2014-04-12 17:57 - 2014-04-12 17:57 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-12 17:41 - 2014-04-12 17:41 - 00143170 _____ () C:\Users\Deep\Desktop\cc_20140412_174133.reg 2014-04-11 20:51 - 2014-04-11 20:51 - 00000000 ____D () C:\Users\Deep\Documents\Gaslamp Games 2014-04-11 17:18 - 2013-12-02 22:24 - 00000000 ____D () C:\Users\Deep\AppData\Local\CrashDumps 2014-04-11 03:02 - 2013-08-16 00:11 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 03:02 - 2013-07-01 19:10 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-11 03:00 - 2013-07-01 17:02 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 02:33 - 2014-04-09 02:33 - 00000020 _____ () C:\Users\Deep\Desktop\lkmnnklnklnl.txt 2014-04-07 13:17 - 2014-04-07 13:17 - 00001250 _____ () C:\Users\Deep\Desktop\poker night 2.txt 2014-04-03 15:37 - 2014-04-03 15:37 - 00000000 ____D () C:\Users\Deep\Documents\Reus 2014-04-03 09:51 - 2014-04-15 16:01 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-15 16:01 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-15 16:01 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 17:14 - 2013-10-17 07:31 - 00000000 ____D () C:\Users\Deep\Documents\samsung 2014-04-02 15:27 - 2014-04-12 18:04 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-02 15:27 - 2014-04-12 18:04 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-04-02 01:57 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-04-01 14:31 - 2014-04-01 14:31 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-04-01 14:30 - 2013-10-01 16:07 - 00000000 ____D () C:\ProgramData\Samsung 2014-04-01 14:25 - 2014-04-01 13:46 - 00000000 ____D () C:\Users\Deep\Desktop\bu 2014-04-01 13:45 - 2013-09-30 19:45 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Samsung 2014-04-01 13:45 - 2013-06-30 17:37 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-01 13:43 - 2013-06-30 19:27 - 00000000 ____D () C:\Program Files (x86)\LOLReplay 2014-04-01 13:16 - 2014-04-01 13:16 - 00000000 ____D () C:\Users\Deep\Documents\SelfMV 2014-04-01 13:14 - 2013-10-17 07:31 - 00000000 ____D () C:\Users\Deep\AppData\Local\Samsung 2014-04-01 13:11 - 2013-10-01 16:05 - 00000000 ____D () C:\Users\Deep\AppData\Local\Downloaded Installations 2014-03-31 19:01 - 2013-07-02 19:52 - 00000132 _____ () C:\Users\Deep\AppData\Roaming\Adobe PNG Format CS5 Prefs 2014-03-31 13:12 - 2014-02-11 17:06 - 00004088 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA 2014-03-31 13:12 - 2014-02-11 17:06 - 00003692 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core 2014-03-31 03:16 - 2014-04-10 14:15 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 14:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 14:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 14:15 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-29 23:58 - 2014-03-29 23:58 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\com.valve.FTP 2014-03-28 23:35 - 2013-12-05 02:17 - 00001456 _____ () C:\Users\Deep\AppData\Local\Adobe Für Web speichern 12.0 Prefs 2014-03-28 17:53 - 2014-01-13 19:37 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-28 17:53 - 2014-01-13 19:37 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-28 12:42 - 2014-03-28 12:36 - 00000000 ____D () C:\ProgramData\BlueStacksSetup 2014-03-25 02:04 - 2014-03-25 02:04 - 00000860 _____ () C:\Users\Deep\Downloads\social-gallery-wordpress-photo-viewer-plugin-license.txt 2014-03-24 17:26 - 2014-02-28 12:41 - 00000000 ____D () C:\Users\Deep\Desktop\reisen 2014-03-21 21:43 - 2014-04-12 18:07 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-03-21 21:43 - 2014-04-12 18:07 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-03-21 21:43 - 2014-04-12 18:02 - 00037320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-03-21 02:14 - 2014-03-21 02:14 - 00000000 _____ () C:\Users\Deep\Desktop\13.4. mtv movie awards.txt 2014-03-19 17:13 - 2013-06-30 17:54 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Mozilla 2014-03-19 03:27 - 2014-04-01 14:31 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2014-03-19 03:27 - 2014-04-01 14:31 - 00109056 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys Some content of TEMP: ==================== C:\Users\Deep\AppData\Local\Temp\avgnt.exe C:\Users\Deep\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\Deep\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-11 15:03 ==================== End Of Log ============================ --- --- --- --- --- --- Und leider habe ich anscheinend noch Probleme. Ich hatte zwischenzeitlich gedacht, es hätte sich erledigt, aber dann stürzte mein Rechner leider wieder ab, allerdings ist es bisher nur einmal wieder passiert.. Geändert von Deepabysm (18.04.2014 um 00:13 Uhr) |
18.04.2014, 17:03 | #8 |
/// the machine /// TB-Ausbilder | Win7 - Regelmäßige Systemabstürze Rechner ist jetzt sauber. Wann genau stürzt er ab?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.04.2014, 19:00 | #9 |
| Win7 - Regelmäßige Systemabstürze Ich berichte, wenn es wieder passieren sollte! Vielen Dank dafür. Kann man erfahren, woran es lag? Und eben ist es wieder passiert.. Dazu im Eventlog "Das System wurde zuvor am 18.04.2014 um 19:55:02 unerwartet heruntergefahren." mit Ereignis-ID etc. etc. pp. Davor finde ich keine ungewöhnlichen Ereignisse im Eventlog.. Scheint also leider nicht behoben zu sein. |
19.04.2014, 12:17 | #10 |
/// the machine /// TB-Ausbilder | Win7 - Regelmäßige Systemabstürze Kopier diese Meldung mal bitte komplett hier rein.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.04.2014, 20:13 | #11 |
| Win7 - Regelmäßige Systemabstürze Tut mir leid, dass es über Ostern keine Antwort von mir gab, ich war verreist.. Die Meldung ist die folgende: Code:
ATTFilter - <Event xmlns="hxxp://schemas.microsoft.com/win/2004/08/events/event"> - <System> <Provider Name="EventLog" /> <EventID Qualifiers="32768">6008</EventID> <Level>2</Level> <Task>0</Task> <Keywords>0x80000000000000</Keywords> <TimeCreated SystemTime="2014-04-18T17:55:56.000000000Z" /> <EventRecordID>129270</EventRecordID> <Channel>System</Channel> <Computer>Bens-Ten</Computer> <Security /> </System> - <EventData> <Data>19:55:02</Data> <Data>18.04.2014</Data> <Data /> <Data /> <Data>18065</Data> <Data /> <Data /> <Binary>DE070400050012001300370002004903DE0704000500120011003700020049033C0000003C000000000000000000000000000000000000000100000000000000</Binary> </EventData> </Event> |
25.04.2014, 18:49 | #12 |
/// the machine /// TB-Ausbilder | Win7 - Regelmäßige Systemabstürze Öffne mal bitte FRST, setz nen Haken bei Additional und scanne, poste bitte beide Logfiles.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
25.04.2014, 20:14 | #13 |
| Win7 - Regelmäßige Systemabstürze FRST hier: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-04-2014 03 Ran by Deep (administrator) on BENS-TEN on 25-04-2014 21:12:59 Running from C:\Users\Deep\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Users\Deep\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Spotify Ltd) C:\Users\Deep\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Dropbox, Inc.) C:\Users\Deep\AppData\Roaming\Dropbox\bin\Dropbox.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (Adobe Systems Inc.) E:\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (CyberLink Corp.) E:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\Cyberlink\Shared files\brs.exe () E:\Program Files (x86)\Drakonia Configurator\hid.exe () E:\Program Files (x86)\Drakonia Configurator\trayicon.exe (TeamSpeak Systems GmbH) E:\Program Files\TeamSpeak\ts3client_win64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Valve Corporation) D:\Steam\Steam.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) E:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-03] (Adobe Systems Incorporated) HKLM\...\Run: [BCSSync] => E:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8292120 2013-11-14] (Logitech Inc.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation) HKLM-x32\...\Run: [avgnt] => E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => E:\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2013-12-18] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => E:\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2013-12-18] (Adobe Systems Inc.) HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-27] (Intel Corporation) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-08-09] (VIA) HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [RemoteControl10] => E:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe [87336 2011-03-30] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2011-09-28] (cyberlink) HKLM-x32\...\Run: [GamingMouse] => E:\Program Files (x86)\Drakonia Configurator\hid.exe [248832 2013-10-29] () HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\Run: [Spotify Web Helper] => C:\Users\Deep\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-05] (Spotify Ltd) HKU\S-1-5-21-2155462486-2137830924-635027668-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) Startup: C:\Users\Deep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Deep\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - E:\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default FF Homepage: hxxp://www.facebook.com/ FF Keyword.URL: hxxp://www.google.com/search?sourceid=navclient&hl=de&q= FF NetworkProxy: "ftp", "95.211.129.32" FF NetworkProxy: "ftp_port", 3128 FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "95.211.129.32" FF NetworkProxy: "socks_port", 3128 FF NetworkProxy: "ssl", "95.211.129.32" FF NetworkProxy: "ssl_port", 3128 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Acrobat - E:\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Deep\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Deep\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Deep\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Deep\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin ProgramFiles/Appdata: C:\Users\Deep\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Deep\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\googlede-pws.xml FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\leo-fra-deu.xml FF SearchPlugin: C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\searchplugins\youtube-videosuche.xml FF Extension: Разпознаване на устройство Logitech - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\DeviceDetection@logitech.com [2013-06-30] FF Extension: ProxTube - Unblock YouTube - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7} [2013-12-05] FF Extension: ChatZilla - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2013-07-15] FF Extension: WOT - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-27] FF Extension: DownloadHelper - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-28] FF Extension: Firebug - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\firebug@software.joehewitt.com.xpi [2013-06-30] FF Extension: Grooveshark Unlocker - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2013-06-30] FF Extension: Stealthy - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\stealthyextension@gmail.com.xpi [2013-06-30] FF Extension: Ask Toolbar - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\toolbar_CLM-V7@apn.ask.com.xpi [2013-06-17] FF Extension: Flagfox - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-16] FF Extension: NoScript - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-30] FF Extension: SoundCloud Downloader - Technowise - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{c8d3bc80-0810-4d21-a2c2-be5f2b2832ac}.xpi [2013-06-30] FF Extension: Adblock Plus - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-30] FF Extension: Tab Mix Plus - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-06-30] FF Extension: Greasemonkey - C:\Users\Deep\AppData\Roaming\Mozilla\Firefox\Profiles\pfy7b6vy.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013-06-30] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - E:\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - E:\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-07-01] FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - E:\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} FF Extension: Adobe Contribute Toolbar - E:\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2013-07-01] FF StartMenuInternet: FIREFOX.EXE - E:\Program Files (x86)\Mozilla Firefox\firefox.exe Chrome: ======= CHR StartupUrls: "hxxp://www.facebook.com/" CHR Extension: (Adblock Plus) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-27] CHR Extension: (Foxish live RSS) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgagcapnkccceppgljfpoadahaopjdb [2014-03-02] CHR Extension: (Google Wallet) - C:\Users\Deep\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-13] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S2 CLKMSVC10_F47B619C; E:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-04-20] (CyberLink) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-09] () R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2013-12-09] () S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-03] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-14] (Avira Operations GmbH & Co. KG) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-22] (AVM GmbH) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-12-08] () R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [42016 2013-11-27] (Visicom Media Inc.) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35232 2013-12-06] (Visicom Media Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) R3 umpusbvista; C:\Windows\System32\DRIVERS\umpusbvista.sys [64872 2012-09-13] (Texas Instruments Inc) S3 vhidmini; C:\Windows\System32\DRIVERS\vjoy.sys [15544 2013-04-18] (Headsoft) R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [231112 2013-01-03] (VIA Technologies, Inc.) S3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [35344 2014-01-23] () R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [301256 2013-01-03] (VIA Technologies, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 dgderdrv; System32\drivers\dgderdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-18 17:01 - 2014-04-18 17:01 - 00000000 ____D () C:\Users\Deep\AppData\Local\Chromium 2014-04-18 01:01 - 2014-04-18 01:00 - 00987448 _____ () C:\Users\Deep\Desktop\SecurityCheck.exe 2014-04-18 01:00 - 2014-04-18 01:00 - 00987448 _____ () C:\Users\Deep\Downloads\SecurityCheck.exe 2014-04-17 14:05 - 2014-04-17 14:05 - 02347384 _____ (ESET) C:\Users\Deep\Downloads\esetsmartinstaller_enu.exe 2014-04-17 04:43 - 2014-04-17 04:43 - 02185139 _____ () C:\Users\Deep\Downloads\CherryFramework_v3.1.1.zip 2014-04-16 22:51 - 2014-04-16 22:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManyCam 2014-04-16 22:50 - 2014-04-16 22:50 - 00613200 _____ (Chip Digital GmbH) C:\Users\Deep\Downloads\ManyCam - CHIP-Downloader.exe 2014-04-15 16:27 - 2014-04-25 21:12 - 00000000 ____D () C:\Users\Deep\Desktop\FRST-OlderVersion 2014-04-15 16:20 - 2014-04-15 16:20 - 00000000 ____D () C:\Windows\ERUNT 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Downloads\JRT.exe 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Desktop\JRT.exe 2014-04-15 16:18 - 2014-04-15 16:18 - 00003226 _____ () C:\Users\Deep\Desktop\AdwCleaner[S0].txt 2014-04-15 16:13 - 2014-04-15 16:17 - 00000000 ____D () C:\AdwCleaner 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Downloads\adwcleaner.exe 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Desktop\adwcleaner.exe 2014-04-15 16:12 - 2014-04-15 16:12 - 00001147 _____ () C:\Users\Deep\Desktop\mbam.txt 2014-04-15 16:01 - 2014-04-15 16:02 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-15 16:01 - 2014-04-15 16:01 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-15 16:01 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-15 16:01 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-15 16:01 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-15 16:00 - 2014-04-15 16:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Deep\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-15 13:15 - 2014-04-15 13:15 - 00000552 _____ () C:\Windows\PFRO.log 2014-04-15 04:08 - 2014-04-15 04:09 - 75260759 _____ () C:\Users\Deep\Downloads\template_48244_Y46OQQ6Hold2I9B9y0i4.zip 2014-04-15 01:50 - 2014-04-15 16:57 - 00000102 _____ () C:\Users\Deep\Desktop\01635854984.txt 2014-04-15 01:45 - 2014-04-15 01:45 - 00030706 _____ () C:\Users\Deep\Desktop\ComboFix.txt 2014-04-15 01:39 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-15 01:39 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-15 01:39 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-15 01:39 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-15 01:38 - 2014-04-15 01:45 - 00000000 ____D () C:\Qoobox 2014-04-15 01:38 - 2014-04-15 01:44 - 00000000 ____D () C:\Windows\erdnt 2014-04-14 21:04 - 2014-04-14 21:05 - 05194807 ____R (Swearware) C:\Users\Deep\Desktop\ComboFix.exe 2014-04-14 18:05 - 2014-04-14 18:05 - 00005381 _____ () C:\Users\Deep\Desktop\gmer.log 2014-04-14 18:02 - 2014-04-14 18:02 - 00000000 _____ () C:\Users\Deep\Desktop\irql not less or equal.txt 2014-04-14 18:00 - 2014-04-14 18:00 - 00292904 _____ () C:\Users\Deep\Desktop\041414-5319-01.dmp 2014-04-14 17:57 - 2014-04-14 17:57 - 00380416 _____ () C:\Users\Deep\Desktop\479hej3m.exe 2014-04-14 17:57 - 2014-04-14 17:57 - 00068534 _____ () C:\Users\Deep\Desktop\Addition.txt 2014-04-14 17:56 - 2014-04-25 21:13 - 00022369 _____ () C:\Users\Deep\Desktop\FRST.txt 2014-04-14 17:55 - 2014-04-25 21:12 - 02061824 _____ (Farbar) C:\Users\Deep\Desktop\FRST64.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00050477 _____ () C:\Users\Deep\Desktop\Defogger.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00000470 _____ () C:\Users\Deep\Desktop\defogger_disable.log 2014-04-14 17:50 - 2014-04-14 17:50 - 00000000 _____ () C:\Users\Deep\defogger_reenable 2014-04-12 18:07 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-04-12 18:07 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-04-12 18:04 - 2014-04-25 21:09 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-12 18:04 - 2014-04-12 18:06 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA 2014-04-12 18:04 - 2014-04-12 18:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2014-04-12 18:04 - 2014-04-02 15:27 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-12 18:04 - 2014-04-02 15:27 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-04-12 18:04 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-04-12 18:03 - 2014-03-04 16:35 - 00062408 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-04-12 18:03 - 2014-03-04 16:35 - 00054216 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-04-12 18:03 - 2014-03-04 15:06 - 06714312 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-04-12 18:03 - 2014-03-04 15:06 - 03497816 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 03649185 _____ () C:\Windows\system32\nvcoproc.bin 2014-04-12 18:03 - 2014-03-04 15:05 - 02558808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 00922968 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-04-12 18:03 - 2014-03-04 15:05 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-04-12 18:03 - 2014-03-04 15:05 - 00064968 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-04-12 18:02 - 2014-03-21 21:43 - 00037320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 18302384 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 14709720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-04-12 18:02 - 2014-03-04 16:35 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 03093280 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02715264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00947808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00832936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00484296 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00409544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00377688 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00333600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-04-12 18:02 - 2014-03-04 16:35 - 00024544 _____ () C:\Windows\system32\nvinfo.pb 2014-04-12 18:02 - 2013-11-28 15:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-04-12 18:02 - 2013-11-28 15:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-04-12 18:02 - 2013-11-22 10:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2014-04-12 18:01 - 2014-04-12 18:01 - 00000000 ____D () C:\NVIDIA 2014-04-12 17:57 - 2014-04-25 21:10 - 00010389 _____ () C:\Windows\setupact.log 2014-04-12 17:57 - 2014-04-12 17:57 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-12 17:45 - 2014-04-12 22:17 - 00000000 ____D () C:\Windows\System32\Tasks\Aufgaben der Ereignisanzeige 2014-04-12 17:41 - 2014-04-12 17:41 - 00143170 _____ () C:\Users\Deep\Desktop\cc_20140412_174133.reg 2014-04-11 20:51 - 2014-04-11 20:51 - 00000000 ____D () C:\Users\Deep\Documents\Gaslamp Games 2014-04-11 17:20 - 2014-04-25 18:23 - 01745951 _____ () C:\Windows\WindowsUpdate.log 2014-04-10 14:15 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-10 14:15 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-10 14:15 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-10 14:15 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 14:15 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 14:15 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 14:15 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 14:15 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 14:15 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 14:15 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 14:15 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 14:15 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 14:15 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 14:15 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 14:15 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 14:15 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 14:15 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 02:33 - 2014-04-09 02:33 - 00000020 _____ () C:\Users\Deep\Desktop\lkmnnklnklnl.txt 2014-04-07 13:17 - 2014-04-07 13:17 - 00001250 _____ () C:\Users\Deep\Desktop\poker night 2.txt 2014-04-03 15:37 - 2014-04-03 15:37 - 00000000 ____D () C:\Users\Deep\Documents\Reus 2014-04-01 14:31 - 2014-04-01 14:31 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-04-01 14:31 - 2014-03-19 03:27 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2014-04-01 14:31 - 2014-03-19 03:27 - 00109056 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2014-04-01 13:46 - 2014-04-01 14:25 - 00000000 ____D () C:\Users\Deep\Desktop\bu 2014-04-01 13:16 - 2014-04-01 13:16 - 00000000 ____D () C:\Users\Deep\Documents\SelfMV 2014-04-01 13:12 - 2014-04-01 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2014-04-01 13:12 - 2014-01-23 18:23 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\Windows\SysWOW64\secman.dll 2014-03-29 23:58 - 2014-03-29 23:58 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\com.valve.FTP 2014-03-28 12:36 - 2014-03-28 12:42 - 00000000 ____D () C:\ProgramData\BlueStacksSetup ==================== One Month Modified Files and Folders ======= 2014-04-25 21:13 - 2014-04-14 17:56 - 00022369 _____ () C:\Users\Deep\Desktop\FRST.txt 2014-04-25 21:12 - 2014-04-15 16:27 - 00000000 ____D () C:\Users\Deep\Desktop\FRST-OlderVersion 2014-04-25 21:12 - 2014-04-14 17:55 - 02061824 _____ (Farbar) C:\Users\Deep\Desktop\FRST64.exe 2014-04-25 21:12 - 2014-03-07 16:00 - 00000000 ____D () C:\FRST 2014-04-25 21:12 - 2013-06-30 18:51 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\TS3Client 2014-04-25 21:10 - 2014-04-12 17:57 - 00010389 _____ () C:\Windows\setupact.log 2014-04-25 21:10 - 2013-06-30 20:26 - 00000000 ___RD () C:\Users\Deep\Dropbox 2014-04-25 21:10 - 2013-06-30 20:24 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Dropbox 2014-04-25 21:09 - 2014-04-12 18:04 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-25 21:09 - 2014-01-13 19:37 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-25 21:09 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-25 18:23 - 2014-04-11 17:20 - 01745951 _____ () C:\Windows\WindowsUpdate.log 2014-04-25 18:17 - 2014-02-11 17:06 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA.job 2014-04-25 17:58 - 2014-01-13 19:37 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-25 17:33 - 2013-06-30 19:34 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-25 16:58 - 2013-06-30 19:02 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Spotify 2014-04-25 16:31 - 2013-07-07 14:13 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\FileZilla 2014-04-25 13:47 - 2013-09-20 14:14 - 00000000 ____D () C:\Users\Deep\Wichtiger Stuff 2014-04-25 13:25 - 2013-06-30 19:34 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-25 13:25 - 2013-06-30 19:34 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-25 13:25 - 2013-06-30 19:34 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-25 13:25 - 2013-06-30 19:33 - 00000000 ____D () C:\Users\Deep\AppData\Local\Adobe 2014-04-25 13:17 - 2014-02-11 17:06 - 00001064 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core.job 2014-04-25 13:12 - 2009-07-14 06:45 - 00026864 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-25 13:12 - 2009-07-14 06:45 - 00026864 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-24 21:22 - 2013-06-30 19:03 - 00000000 ____D () C:\Users\Deep\AppData\Local\Spotify 2014-04-24 21:16 - 2014-02-01 22:30 - 00000000 ____D () C:\Users\Deep\AppData\Local\ManyCam 2014-04-18 17:33 - 2014-01-23 19:08 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Might & Magic Heroes VI 2014-04-18 17:01 - 2014-04-18 17:01 - 00000000 ____D () C:\Users\Deep\AppData\Local\Chromium 2014-04-18 01:00 - 2014-04-18 01:01 - 00987448 _____ () C:\Users\Deep\Desktop\SecurityCheck.exe 2014-04-18 01:00 - 2014-04-18 01:00 - 00987448 _____ () C:\Users\Deep\Downloads\SecurityCheck.exe 2014-04-18 00:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-17 18:59 - 2013-08-08 17:30 - 00001801 _____ () C:\Users\Deep\Desktop\steam keys.txt 2014-04-17 18:57 - 2013-06-30 19:07 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\vlc 2014-04-17 14:05 - 2014-04-17 14:05 - 02347384 _____ (ESET) C:\Users\Deep\Downloads\esetsmartinstaller_enu.exe 2014-04-17 14:02 - 2013-06-30 18:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-17 04:43 - 2014-04-17 04:43 - 02185139 _____ () C:\Users\Deep\Downloads\CherryFramework_v3.1.1.zip 2014-04-17 03:56 - 2014-01-13 16:41 - 00000000 ____D () C:\Users\Deep\Arbeit 2014-04-16 23:43 - 2013-06-30 18:54 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Skype 2014-04-16 22:51 - 2014-04-16 22:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManyCam 2014-04-16 22:51 - 2014-02-01 22:30 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\ManyCam 2014-04-16 22:51 - 2014-02-01 22:29 - 00000000 ____D () C:\Program Files (x86)\ManyCam 2014-04-16 22:51 - 2014-02-01 22:26 - 00000000 ____D () C:\Users\Deep\Documents\Youcam 2014-04-16 22:50 - 2014-04-16 22:50 - 00613200 _____ (Chip Digital GmbH) C:\Users\Deep\Downloads\ManyCam - CHIP-Downloader.exe 2014-04-15 16:57 - 2014-04-15 01:50 - 00000102 _____ () C:\Users\Deep\Desktop\01635854984.txt 2014-04-15 16:20 - 2014-04-15 16:20 - 00000000 ____D () C:\Windows\ERUNT 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Downloads\JRT.exe 2014-04-15 16:19 - 2014-04-15 16:19 - 01016261 _____ (Thisisu) C:\Users\Deep\Desktop\JRT.exe 2014-04-15 16:18 - 2014-04-15 16:18 - 00003226 _____ () C:\Users\Deep\Desktop\AdwCleaner[S0].txt 2014-04-15 16:17 - 2014-04-15 16:13 - 00000000 ____D () C:\AdwCleaner 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Downloads\adwcleaner.exe 2014-04-15 16:13 - 2014-04-15 16:13 - 01426178 _____ () C:\Users\Deep\Desktop\adwcleaner.exe 2014-04-15 16:12 - 2014-04-15 16:12 - 00001147 _____ () C:\Users\Deep\Desktop\mbam.txt 2014-04-15 16:02 - 2014-04-15 16:01 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-15 16:01 - 2014-04-15 16:01 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-15 16:01 - 2014-04-15 16:01 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-15 16:00 - 2014-04-15 16:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Deep\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-15 13:15 - 2014-04-15 13:15 - 00000552 _____ () C:\Windows\PFRO.log 2014-04-15 04:17 - 2014-01-03 16:40 - 00000000 ____D () C:\Users\Deep\Desktop\stip n study 2014-04-15 04:09 - 2014-04-15 04:08 - 75260759 _____ () C:\Users\Deep\Downloads\template_48244_Y46OQQ6Hold2I9B9y0i4.zip 2014-04-15 01:45 - 2014-04-15 01:45 - 00030706 _____ () C:\Users\Deep\Desktop\ComboFix.txt 2014-04-15 01:45 - 2014-04-15 01:38 - 00000000 ____D () C:\Qoobox 2014-04-15 01:45 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-04-15 01:44 - 2014-04-15 01:38 - 00000000 ____D () C:\Windows\erdnt 2014-04-15 01:44 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-14 21:05 - 2014-04-14 21:04 - 05194807 ____R (Swearware) C:\Users\Deep\Desktop\ComboFix.exe 2014-04-14 18:05 - 2014-04-14 18:05 - 00005381 _____ () C:\Users\Deep\Desktop\gmer.log 2014-04-14 18:02 - 2014-04-14 18:02 - 00000000 _____ () C:\Users\Deep\Desktop\irql not less or equal.txt 2014-04-14 18:01 - 2014-01-07 13:45 - 00000000 ____D () C:\Users\Deep\Documents\Visual Studio 2010 2014-04-14 18:01 - 2013-07-01 16:34 - 00000000 ____D () C:\Windows\Minidump 2014-04-14 18:00 - 2014-04-14 18:00 - 00292904 _____ () C:\Users\Deep\Desktop\041414-5319-01.dmp 2014-04-14 17:57 - 2014-04-14 17:57 - 00380416 _____ () C:\Users\Deep\Desktop\479hej3m.exe 2014-04-14 17:57 - 2014-04-14 17:57 - 00068534 _____ () C:\Users\Deep\Desktop\Addition.txt 2014-04-14 17:50 - 2014-04-14 17:50 - 00050477 _____ () C:\Users\Deep\Desktop\Defogger.exe 2014-04-14 17:50 - 2014-04-14 17:50 - 00000470 _____ () C:\Users\Deep\Desktop\defogger_disable.log 2014-04-14 17:50 - 2014-04-14 17:50 - 00000000 _____ () C:\Users\Deep\defogger_reenable 2014-04-14 17:50 - 2013-06-30 17:26 - 00000000 ____D () C:\Users\Deep 2014-04-14 17:47 - 2013-07-01 03:18 - 00765588 _____ () C:\Windows\system32\perfh007.dat 2014-04-14 17:47 - 2013-07-01 03:18 - 00174818 _____ () C:\Windows\system32\perfc007.dat 2014-04-14 17:47 - 2009-07-14 07:13 - 01807338 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-12 22:17 - 2014-04-12 17:45 - 00000000 ____D () C:\Windows\System32\Tasks\Aufgaben der Ereignisanzeige 2014-04-12 18:07 - 2013-11-29 13:16 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA Corporation 2014-04-12 18:07 - 2013-09-28 00:36 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-04-12 18:07 - 2013-06-30 17:39 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-12 18:06 - 2014-04-12 18:04 - 00000000 ____D () C:\Users\Deep\AppData\Local\NVIDIA 2014-04-12 18:04 - 2014-04-12 18:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2014-04-12 18:04 - 2013-07-01 00:36 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-04-12 18:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-04-12 18:02 - 2013-09-28 00:42 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\NVIDIA 2014-04-12 18:01 - 2014-04-12 18:01 - 00000000 ____D () C:\NVIDIA 2014-04-12 17:57 - 2014-04-12 17:57 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-12 17:41 - 2014-04-12 17:41 - 00143170 _____ () C:\Users\Deep\Desktop\cc_20140412_174133.reg 2014-04-11 20:51 - 2014-04-11 20:51 - 00000000 ____D () C:\Users\Deep\Documents\Gaslamp Games 2014-04-11 17:18 - 2013-12-02 22:24 - 00000000 ____D () C:\Users\Deep\AppData\Local\CrashDumps 2014-04-11 03:02 - 2013-08-16 00:11 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 03:02 - 2013-07-01 19:10 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-11 03:00 - 2013-07-01 17:02 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 02:33 - 2014-04-09 02:33 - 00000020 _____ () C:\Users\Deep\Desktop\lkmnnklnklnl.txt 2014-04-07 13:17 - 2014-04-07 13:17 - 00001250 _____ () C:\Users\Deep\Desktop\poker night 2.txt 2014-04-03 15:37 - 2014-04-03 15:37 - 00000000 ____D () C:\Users\Deep\Documents\Reus 2014-04-03 09:51 - 2014-04-15 16:01 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-15 16:01 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-15 16:01 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 17:14 - 2013-10-17 07:31 - 00000000 ____D () C:\Users\Deep\Documents\samsung 2014-04-02 15:27 - 2014-04-12 18:04 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-02 15:27 - 2014-04-12 18:04 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-04-02 01:57 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-04-01 14:31 - 2014-04-01 14:31 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-04-01 14:30 - 2013-10-01 16:07 - 00000000 ____D () C:\ProgramData\Samsung 2014-04-01 14:25 - 2014-04-01 13:46 - 00000000 ____D () C:\Users\Deep\Desktop\bu 2014-04-01 13:45 - 2014-04-01 13:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2014-04-01 13:45 - 2013-09-30 19:45 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\Samsung 2014-04-01 13:45 - 2013-06-30 17:37 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-01 13:43 - 2013-06-30 19:27 - 00000000 ____D () C:\Program Files (x86)\LOLReplay 2014-04-01 13:16 - 2014-04-01 13:16 - 00000000 ____D () C:\Users\Deep\Documents\SelfMV 2014-04-01 13:14 - 2013-10-17 07:31 - 00000000 ____D () C:\Users\Deep\AppData\Local\Samsung 2014-04-01 13:11 - 2013-10-01 16:05 - 00000000 ____D () C:\Users\Deep\AppData\Local\Downloaded Installations 2014-03-31 19:01 - 2013-07-02 19:52 - 00000132 _____ () C:\Users\Deep\AppData\Roaming\Adobe PNG Format CS5 Prefs 2014-03-31 13:12 - 2014-02-11 17:06 - 00004088 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA 2014-03-31 13:12 - 2014-02-11 17:06 - 00003692 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-31 03:16 - 2014-04-10 14:15 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-10 14:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-10 14:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-10 14:15 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-29 23:58 - 2014-03-29 23:58 - 00000000 ____D () C:\Users\Deep\AppData\Roaming\com.valve.FTP 2014-03-28 23:35 - 2013-12-05 02:17 - 00001456 _____ () C:\Users\Deep\AppData\Local\Adobe Für Web speichern 12.0 Prefs 2014-03-28 17:53 - 2014-01-13 19:37 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-28 17:53 - 2014-01-13 19:37 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-28 12:42 - 2014-03-28 12:36 - 00000000 ____D () C:\ProgramData\BlueStacksSetup Some content of TEMP: ==================== C:\Users\Deep\AppData\Local\Temp\avgnt.exe C:\Users\Deep\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\Deep\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-11 15:03 ==================== End Of Log ============================ Addition hier: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-04-2014 03 Ran by Deep at 2014-04-25 21:13:15 Running from C:\Users\Deep\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== @BIOS (HKLM-x32\...\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}) (Version: 2.30 - GIGABYTE) A Virus Named TOM (HKLM-x32\...\Steam App 207650) (Version: - Misfits Attic) AaaaaAAaaaAAAaaAAAAaAAAAA!!! for the Awesome (HKLM-x32\...\Steam App 15560) (Version: - Dejobaan Games, LLC) Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.9 - Adobe Systems) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.7.0.2090 - Adobe Systems Incorporated) Hidden Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.) Adobe Community Help (x32 Version: 3.4.980 - Adobe Systems Incorporated.) Hidden Adobe Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 1.4.0 - Adobe Systems Incorporated) Adobe Content Viewer (x32 Version: 1.4.0 - Adobe Systems Incorporated) Hidden Adobe Creative Suite 5.5 Master Collection (HKLM-x32\...\{D8D2B468-8342-411A-8760-BCC362C3408F}) (Version: 5.5 - Adobe Systems Incorporated) Adobe Flash Media Live Encoder 3.2 (HKLM-x32\...\{0659E943-DDF4-44FC-9FEE-A13B09F8BB08}) (Version: 3.2.0 - Adobe Systems Incorporated) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.182 - Adobe Systems Incorporated) Adobe Photoshop Lightroom 5.2 64-bit (HKLM\...\{54E6C675-3AD4-42E4-957F-31666ABF1603}) (Version: 5.2.1 - Adobe) Adobe Story (HKLM-x32\...\com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.0.571 - Adobe Systems Incorporated) Adobe Story (x32 Version: 1.0.571 - Adobe Systems Incorporated) Hidden Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1) (Version: 2.0 Build 230 - Adobe Systems Incorporated.) Adobe Widget Browser (x32 Version: 2.0.230 - Adobe Systems Incorporated.) Hidden Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version: - Hidden Path Entertainment, Ensemble Studios) Air Conflicts: Pacific Carriers (HKLM-x32\...\Steam App 214910) (Version: - Games Farm s.r.o.) Alan Wake (HKLM-x32\...\Steam App 108710) (Version: - Remedy Entertainment) Alan Wake's American Nightmare (HKLM-x32\...\Steam App 202750) (Version: - Remedy Entertainment) Alien Breed 2: Assault (HKLM-x32\...\Steam App 22650) (Version: - Team17 Software Ltd.) Alien Breed 3: Descent (HKLM-x32\...\Steam App 22670) (Version: - Team17 Software Ltd.) Alien Breed: Impact (HKLM-x32\...\Steam App 22610) (Version: - Team17 Software Ltd. ) Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.4.0.26 - Amazon Services LLC) Amazon Kindle (HKLM-x32\...\Amazon Kindle) (Version: - Amazon) Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version: - Frictional Games) Anno 2070 (HKLM-x32\...\Steam App 48240) (Version: - BlueByte) Anomaly 2 (HKLM-x32\...\Steam App 236730) (Version: - 11 bit studios) Anomaly Korea (HKLM-x32\...\Steam App 251530) (Version: - 11 bit studios) Anomaly Warzone Earth (HKLM-x32\...\Steam App 91200) (Version: - 11 bit studios) Anomaly Warzone Earth Mobile Campaign (HKLM-x32\...\Steam App 252170) (Version: - 11 bit studios) Antichamber (HKLM-x32\...\Steam App 219890) (Version: - Alexander Bruce) Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Aquaria (HKLM-x32\...\Steam App 24420) (Version: - Bit Blot, LLC) Arma Tactics (HKLM-x32\...\Steam App 224860) (Version: - Bohemia Interactive) Assassin's Creed (HKLM-x32\...\Steam App 15100) (Version: - Ubisoft Montreal) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.) Audiosurf (HKLM-x32\...\Steam App 12900) (Version: - Dylan Fitterer) AutoGreen B12.0206.1 (HKLM-x32\...\InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE) AutoGreen B12.0206.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden Avadon: The Black Fortress (HKLM-x32\...\Steam App 112100) (Version: - Spiderweb Software) Avernum: Escape From the Pit (HKLM-x32\...\Steam App 208400) (Version: - Spiderweb Software) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version: - AVM Berlin) Awesomenauts (HKLM-x32\...\Steam App 204300) (Version: - Ronimo Games) Bad Hotel (HKLM-x32\...\Steam App 231720) (Version: - Lucky Frame) Bastion (HKLM-x32\...\Steam App 107100) (Version: - Supergiant Games) Batman: Arkham Asylum GOTY Edition (HKLM-x32\...\Steam App 35140) (Version: - Rocksteady Studios) Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version: - Rocksteady Studios) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Beat Hazard (HKLM-x32\...\Steam App 49600) (Version: - Cold Beam Games) BioShock (HKLM-x32\...\Steam App 7670) (Version: - 2K Boston) BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version: - Irrational Games) BIT.TRIP BEAT (HKLM-x32\...\Steam App 63700) (Version: - Gaijin Games) BIT.TRIP RUNNER (HKLM-x32\...\Steam App 63710) (Version: - Gaijin Games) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) Botanicula (HKLM-x32\...\Steam App 207690) (Version: - Amanita Design) Braid (HKLM-x32\...\Steam App 26800) (Version: - Number None) Bridge Project (HKLM-x32\...\Steam App 232950) (Version: - Halycon Media GmbH & Co. KG) Brothers - A Tale of Two Sons (HKLM-x32\...\Steam App 225080) (Version: - Starbreeze Studios AB) Brütal Legend (HKLM-x32\...\Steam App 225260) (Version: - Double Fine Productions) Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version: - Infinity Ward) Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version: - Infinity Ward) Canon RAW Codec (HKLM-x32\...\Canon RAW Codec) (Version: 1.11.0.75 - Canon Inc.) Canon Utilities Digital Photo Professional (HKLM-x32\...\Digital Photo Professional) (Version: 3.13.10.0 - Canon Inc.) Canon Utilities EOS Utility (HKLM-x32\...\EOS Utility) (Version: 2.13.10.0 - Canon Inc.) Canon Utilities Picture Style Editor (HKLM-x32\...\Picture Style Editor) (Version: 1.13.10.0 - Canon Inc.) Capsized (HKLM-x32\...\Steam App 95300) (Version: - Alientrap Games Inc) Cave Story+ (HKLM-x32\...\Steam App 200900) (Version: - Nicalis) CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.4003 - CDBurnerXP) Cities in Motion 2 (HKLM-x32\...\Steam App 225420) (Version: - Colossal Order Ltd.) Confrontation (HKLM-x32\...\Steam App 204560) (Version: - Cyanide Studios) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) CPUID CPU-Z 1.65.1 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) Crysis® 2 (HKLM-x32\...\{6033673D-2530-4587-8AD0-EB059FC263F9}) (Version: 1.9.0.0 - Electronic Arts) Darksiders (HKLM-x32\...\Steam App 50620) (Version: - Vigil Games) Darksiders II (HKLM-x32\...\Steam App 50650) (Version: - Vigil Games) Dead Island (HKLM-x32\...\Steam App 91310) (Version: - Techland) Dead Space™ (HKLM-x32\...\{4D87DC92-C328-46EC-A7B4-9C88129DC696}) (Version: 1.0.222.0 - Electronic Arts) DeathSpank (HKLM-x32\...\Steam App 18040) (Version: - Hothead Games) DeathSpank: Thongs Of Virtue (HKLM-x32\...\Steam App 18050) (Version: - Hothead Games) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{AC53C6A4-1CC4-48A5-91F3-565BB7978B22}) (Version: - Microsoft) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{AC53C6A4-1CC4-48A5-91F3-565BB7978B22}) (Version: - Microsoft) Deponia (HKLM-x32\...\Steam App 214340) (Version: - Daedalic Entertainment) DH Driver Cleaner Professional Edition (HKLM-x32\...\Driver Cleaner Pro) (Version: Version 1.5 - Ruud Ketelaars) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve ) Drakonia Configurator (HKLM-x32\...\{2EAD3327-2F92-455F-A675-E5CC4980B67A}}_is1) (Version: - ) Droid Assault (HKLM-x32\...\Steam App 219200) (Version: - Puppygames) Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.) Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD) Duke Nukem 3D: Megaton Edition (HKLM-x32\...\Steam App 225140) (Version: - 3D Realms) Dungeon Defenders (HKLM-x32\...\Steam App 65800) (Version: - Trendy Entertainment) Dungeonland (HKLM-x32\...\Steam App 218130) (Version: - Critical Studio) Dungeons of Dredmor (HKLM-x32\...\Steam App 98800) (Version: - Gaslamp Games, Inc.) Dust: An Elysian Tail (HKLM-x32\...\Steam App 236090) (Version: - Humble Hearts LLC) Dwarfs!? (HKLM-x32\...\Steam App 35480) (Version: - Power of 2) Dxtory 2.0.104 (HKLM-x32\...\Dxtory2.0_is1) (Version: 2.0.104 - Dxtory Software) Easy Tune 6 B12.1121.1 (HKLM-x32\...\InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}) (Version: 1.00.0000 - GIGABYTE) Easy Tune 6 B12.1121.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden EDGE (HKLM-x32\...\Steam App 38740) (Version: - Two Tribes) Edna & Harvey: Harvey's New Eyes (HKLM-x32\...\Steam App 219910) (Version: - Daedalic Entertainment) Expeditions: Conquistador (HKLM-x32\...\Steam App 237430) (Version: - Logic Artists) F.E.A.R. 3 (HKLM-x32\...\Steam App 21100) (Version: - Day 1 Studios) Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version: - Obsidian Entertainment) FEZ (HKLM-x32\...\Steam App 224760) (Version: - Polytron Corporation) Fieldrunners (HKLM-x32\...\Steam App 209690) (Version: - Subatomic Studios LLC) FileZilla Client 3.7.1 (HKCU\...\FileZilla Client) (Version: 3.7.1 - FileZilla Project) Free YouTube to MP3 Converter version 3.12.17.1127 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.17.1127 - DVDVideoSoft Ltd.) Frozen Synapse (HKLM-x32\...\Steam App 98200) (Version: - Mode 7) Galaxy on Fire 2™ Full HD (HKLM-x32\...\Steam App 212010) (Version: - Fishlabs Entertainment GmbH) Game of Thrones (HKLM-x32\...\Steam App 208730) (Version: - Cyanide Studios) Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Garry) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.) Google Talk Plugin (HKLM-x32\...\{E121A4FE-009B-385B-BB0D-B934E2A88288}) (Version: 5.2.4.18058 - Google) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden GoPro Studio 2.0.1 (HKLM-x32\...\GoPro Studio) (Version: 2.0.1 - WoodmanLabs Inc. d.b.a. GoPro) Gratuitous Tank Battles (HKLM-x32\...\Steam App 205530) (Version: - Positech Games) Guardians of Middle-earth (HKLM-x32\...\Steam App 111900) (Version: - Zombie Studios) Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve) Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version: - Valve) Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version: - Valve) Hard Reset (HKLM-x32\...\Steam App 98400) (Version: - Flying Wild Hog) Heroes of Might and Magic V (HKLM-x32\...\Steam App 15170) (Version: - Nival) Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version: - IO Interactive) HOARD (HKLM-x32\...\Steam App 63000) (Version: - Big Sandwich Games) Hotline Miami (HKLM-x32\...\Steam App 219150) (Version: - Dennaton Games) Indie Game: The Movie (HKLM-x32\...\Steam App 207080) (Version: - BlinkWorks Media) Intake (HKLM-x32\...\Steam App 237760) (Version: - Cipher Prime Studios) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.225 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden Intrusion 2 (HKLM-x32\...\Steam App 214970) (Version: - Aleksey Abramenko) Jagged Alliance - Back in Action (HKLM-x32\...\Steam App 57740) (Version: - Coreplay GmbH) Jagged Alliance: Crossfire (HKLM-x32\...\Steam App 205810) (Version: - Coreplay GmbH) Jamestown (HKLM-x32\...\Steam App 94200) (Version: - Final Form Games) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Joe Danger 2: The Movie (HKLM-x32\...\Steam App 242110) (Version: - Hello Games) Journey of a Roach (HKLM-x32\...\Steam App 255300) (Version: - Koboldgames) Killing Floor (HKLM-x32\...\Steam App 1250) (Version: - Tripwire Interactive) Knytt Underground (HKLM-x32\...\Steam App 248190) (Version: - Nifflas' Games) Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - ) Lara Croft and the Guardian of Light (HKLM-x32\...\Steam App 35130) (Version: - Crystal Dynamics Inc.) Lead and Gold - Gangs of the Wild West (HKLM-x32\...\Steam App 42120) (Version: - Fatshark) Left 4 Dead (HKLM-x32\...\Steam App 500) (Version: - Valve) Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve) Legend of Grimrock (HKLM-x32\...\Steam App 207170) (Version: - Almost Human Games) Leviathan: Warships (HKLM-x32\...\Steam App 202270) (Version: - Pieces Interactive) LG CyberLink Blu-ray Disc Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2820 - CyberLink Corp.) LG CyberLink Blu-ray Disc Suite (x32 Version: 8.0.2820 - CyberLink Corp.) Hidden LG CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.3712.52 - CyberLink Corp.) LG CyberLink PowerDVD (x32 Version: 10.0.3712.52 - CyberLink Corp.) Hidden LIMBO (HKLM-x32\...\Steam App 48000) (Version: - Playdead) Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden Logitech Gaming Software 8.51 (HKLM\...\Logitech Gaming Software) (Version: 8.51.5 - Logitech Inc.) Magicka (HKLM-x32\...\Steam App 42910) (Version: - Arrowhead Game Studios) MakeMKV v1.8.7 (HKLM-x32\...\MakeMKV) (Version: v1.8.7 - GuinpinSoft inc) Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) ManyCam 4.0.77 (HKLM-x32\...\ManyCam) (Version: 4.0.77 - Visicom Media Inc.) Mark of the Ninja (HKLM-x32\...\Steam App 214560) (Version: - Klei Entertainment) marvell 91xx driver (HKLM-x32\...\MagniDriver) (Version: 1.2.0.1020 - Marvell) Medal of Honor (TM) (HKLM-x32\...\{415030B8-3E8B-462A-8C03-41D95AA3AB3B}) (Version: 1.0.0.0 - Electronic Arts) Men of War: Assault Squad (HKLM-x32\...\Steam App 64000) (Version: - Digitalmindsoft) Metro 2033 (HKLM-x32\...\Steam App 43110) (Version: - 4A Games) Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Access 2010 (HKLM\...\Office14.AccessR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{8FB1B528-E260-451E-9B55-E9152F94B80B}) (Version: 3.2.3.0 - Microsoft Corporation) Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.0 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.0 Language Pack - DEU) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Office Access 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2008 (64-bit) (HKLM\...\Microsoft SQL Server 10 Release) (Version: - Microsoft Corporation) Microsoft SQL Server 2008 (64-bit) (Version: - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Browser (HKLM-x32\...\{4AF2248C-B3DF-46FB-9596-87F5DB193689}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 Common Files (Version: 10.0.1600.22 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Common Files (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Services (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Shared (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Native Client (HKLM\...\{8325FD0C-2FDB-46C3-921A-3A78385EA972}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{A106D33E-6B43-42C0-9BFC-D03303261FA7}) (Version: 10.50.1447.4 - Microsoft Corporation) Microsoft SQL Server 2008 RsFx Driver (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{0125D081-30D0-4A97-82A8-C28D444B6256}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (HKLM\...\{C3EAE456-7E7A-451F-80EF-F34C7A13C558}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server System CLR Types (HKLM-x32\...\{5A08C9D1-37AD-4A8D-90D3-33F92C578AA5}) (Version: 10.50.1447.4 - Microsoft Corporation) Microsoft SQL Server VSS Writer (HKLM\...\{28D06854-572C-4A65-83E5-F8CAF26B9FDC}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft Visual C# 2010 Express - DEU (HKLM-x32\...\Microsoft Visual C# 2010 Express - DEU) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C# 2010 Express - DEU (x32 Version: 10.0.30319 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319 (HKLM\...\{94D70749-4281-39AC-AD90-B56A0E0A402E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{616C6F39-4CE1-3434-A665-2F6A04C09A7F}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (HKLM\...\{3C983A67-DFB2-3D3D-AD9E-CA1A5A09FD18}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.0 (HKLM-x32\...\{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}) (Version: 3.0.11010.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft XNA Game Studio 4.0 (XnaLiveProxy) (x32 Version: 4.0.20823.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (ARP entry) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (HKLM-x32\...\XNA Game Studio 4.0) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft XNA Game Studio 4.0 Refresh (Redists) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (Shared Components) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio 4.0 Refresh (Visual Studio) (x32 Version: 4.0.30901.0 - Microsoft Corporation) Hidden Microsoft XNA Game Studio Platform Tools (HKLM-x32\...\{89690B51-2E21-4E93-914E-F9CAC5B24A84}) (Version: 1.4.0.0 - Microsoft Corporation) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Might & Magic ® Heroes ® VI (HKLM-x32\...\Steam App 48220) (Version: - Blackhole) Might & Magic: Duel of Champions (HKLM-x32\...\Steam App 256410) (Version: - Ubisoft Quebec) ModifyRegistry version 0.1 (HKLM-x32\...\{1D5BE6B5-7FD4-4A78-90F2-AF6B53BC8C1C}_is1) (Version: 0.1 - VIA Technologies, Inc.) Monaco (HKLM-x32\...\Steam App 113020) (Version: - Pocketwatch Games) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) Mp3tag v2.58 (HKLM-x32\...\Mp3tag) (Version: v2.58 - Florian Heidenreich) My Game Long Name (HKLM\...\UDK-9de14894-7b74-4153-a2a9-67eeff60f423) (Version: - Epic Games, Inc.) NVIDIA 3D Vision Controller-Treiber 335.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 335.21 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation) NVIDIA GeForce Experience 2.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.0 - NVIDIA Corporation) NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.151.1095 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden Nvidia Omega Drivers v1.169.25 Setup Files and Tools (HKLM-x32\...\Nvidia Omega Drivers for Windows Vistav1.169.25) (Version: v1.169.25 - Omegadrivers.net) NVIDIA PhysX (Legacy) (HKLM-x32\...\{FAAC26AD-73BA-40CE-86AA-C9213F9E064A}) (Version: 9.13.0604 - NVIDIA Corporation) NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3523 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden NVIDIA Update 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.22 (Version: 1.2.22 - NVIDIA Corporation) Hidden Oddworld: Munch's Oddysee (HKLM-x32\...\Steam App 15740) (Version: - Oddworld Inhabitants) Oddworld: Stranger's Wrath HD (HKLM-x32\...\Steam App 15750) (Version: - Oddworld Inhabitants) Offspring Fling! (HKLM-x32\...\Steam App 211360) (Version: - Kyle Pulver) On the Rain-Slick Precipice of Darkness, Episode One (HKLM-x32\...\Steam App 18000) (Version: - Hothead Games) On the Rain-Slick Precipice of Darkness, Episode Two (HKLM-x32\...\Steam App 18020) (Version: - Hothead Games) ON_OFF Charge B12.1025.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Orcs Must Die! (HKLM-x32\...\Steam App 102600) (Version: - Robot Entertainment) Organ Trail: Director's Cut (HKLM-x32\...\Steam App 233740) (Version: - The Men Who Wear Many Hats) Origin (HKLM-x32\...\Origin) (Version: 9.3.1.4482 - Electronic Arts, Inc.) Osmos (HKLM-x32\...\Steam App 29180) (Version: - Hemisphere Games) Painkiller Hell & Damnation (HKLM-x32\...\Steam App 214870) (Version: - The Farm 51) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.) PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden Pinball FX2 (HKLM-x32\...\Steam App 226980) (Version: - Zen Studios) Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden Poker Night 2 (HKLM-x32\...\Steam App 234710) (Version: - Telltale Games) Poker Night at the Inventory (HKLM-x32\...\Steam App 31280) (Version: - Telltale Games) Portal (HKLM-x32\...\Steam App 400) (Version: - Valve) Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.) PxMergeModule (x32 Version: 1.00.0000 - Your Company Name) Hidden QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) RAW - Realms of Ancient War (HKLM-x32\...\Steam App 209730) (Version: - Wizarbox) Really Big Sky (HKLM-x32\...\Steam App 201570) (Version: - Boss Baddie) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.) Red Faction: Armageddon (HKLM-x32\...\Steam App 55110) (Version: - Volition) Red Orchestra: Ostfront 41-45 (HKLM-x32\...\Steam App 1200) (Version: - Tripwire Interactive) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.30.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.30.0 - Renesas Electronics Corporation) Hidden Retro City Rampage™ (HKLM-x32\...\Steam App 204630) (Version: - Vblank Entertainment, Inc.) Reus (HKLM-x32\...\Steam App 222730) (Version: - Abbey Games) Revenge of the Titans (HKLM-x32\...\Steam App 93200) (Version: - Puppygames) Risen 2 - Dark Waters (HKLM-x32\...\Steam App 40390) (Version: - Piranha Bytes) Rochard (HKLM-x32\...\Steam App 107800) (Version: - Recoil Games) Rock of Ages (HKLM-x32\...\Steam App 22230) (Version: - ACE Team) Rocketbirds: Hardboiled Chicken (HKLM-x32\...\Steam App 215510) (Version: - Ratloop Asia) Sacred Citadel (HKLM-x32\...\Steam App 207930) (Version: - Southend) Saints Row: The Third (HKLM-x32\...\Steam App 55230) (Version: - Volition) Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14034.12 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.14034.12 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.40.0 - SAMSUNG Electronics Co., Ltd.) Sanctum 2 (HKLM-x32\...\Steam App 210770) (Version: - Coffee Stain Studios) Screen Split (HKLM-x32\...\{7F0C2357-33B0-4408-A9AD-A7623FAA22B1}) (Version: 6.1 - LG Electronics Inc.) Scribblenauts Unlimited (HKLM-x32\...\Steam App 218680) (Version: - 5th Cell Media) Serious Sam 3: BFE (HKLM-x32\...\Steam App 41070) (Version: - Croteam) Serious Sam Double D (HKLM-x32\...\Steam App 111600) (Version: - Mommy's Best Games) Serious Sam HD: The First Encounter (HKLM-x32\...\Steam App 41000) (Version: - Croteam) Serious Sam HD: The Second Encounter (HKLM-x32\...\Steam App 41010) (Version: - Croteam) Service Pack 1 für SQL Server 2008 (KB 968369) (64-bit) (HKLM\...\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden Shadow Warrior Classic Redux (HKLM-x32\...\Steam App 225160) (Version: - 3D Realms) Shank (HKLM-x32\...\Steam App 6120) (Version: - Klei Entertainment) Shank 2 (HKLM-x32\...\Steam App 102840) (Version: - Klei Entertainment) Shatter (HKLM-x32\...\Steam App 20820) (Version: - Sidhe) SHIELD Streaming (Version: 1.8.323 - NVIDIA Corporation) Hidden Sid Meier’s Ace Patrol: Pacific Skies (HKLM-x32\...\Steam App 244090) (Version: - Firaxis) Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Sine Mora (HKLM-x32\...\Steam App 207040) (Version: - Digital Reality) SkyDrift (HKLM-x32\...\Steam App 91100) (Version: - Digital Reality) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Snapshot (HKLM-x32\...\Steam App 204220) (Version: - Retro Affect) Solar 2 (HKLM-x32\...\Steam App 97000) (Version: - Murudai) Space Pirates and Zombies (HKLM-x32\...\Steam App 107200) (Version: - MinMax Games Ltd.) SpaceChem (HKLM-x32\...\Steam App 92800) (Version: - Zachtronics Industries) Speccy (HKLM\...\Speccy) (Version: 1.22 - Piriform) Splice (HKLM-x32\...\Steam App 209790) (Version: - Cipher Prime Studios) Spotify (HKCU\...\Spotify) (Version: 0.9.8.296.g91f68827 - Spotify AB) Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden StarCraft II (HKLM-x32\...\StarCraft II) (Version: 2.0.11.26825 - Blizzard Entertainment) StarUML 5.0.2.1570 (HKLM-x32\...\StarUML_is1) (Version: - Plastic Software, Inc.) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Strike Suit Zero (HKLM-x32\...\Steam App 209540) (Version: - Born Ready Games Ltd.) Superfrog HD (HKLM-x32\...\Steam App 234000) (Version: - Team17 Digital Ltd.) Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.24951 - TeamViewer) Texas Instruments TUSB3410 drivers. (HKLM-x32\...\InstallShield_{FA66245E-0E77-40D5-94A4-CB7AB753034F}) (Version: 6.5.9019.1 - Texas Instruments Inc.) The Baconing (HKLM-x32\...\Steam App 18070) (Version: - Hothead Games) The Basement Collection (HKLM-x32\...\Steam App 214790) (Version: - Edmund McMillen, Tyler Glaiel) The Binding of Isaac (HKLM-x32\...\Steam App 113200) (Version: - Edmund McMillen and Florian Himsl) The Bridge (HKLM-x32\...\Steam App 204240) (Version: - Ty Taylor and Mario Castañeda) The Dark Eye: Chains of Satinav (HKLM-x32\...\Steam App 203830) (Version: - Daedalic Entertainment) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) The Lord of the Rings: War in the North (HKLM-x32\...\Steam App 32800) (Version: - Snowblind Studios) The Raven - Legacy of a Master Thief (HKLM-x32\...\Steam App 233370) (Version: - KING Art) The Stanley Parable (HKLM-x32\...\Steam App 221910) (Version: - Galactic Cafe) The Walking Dead (HKLM-x32\...\Steam App 207610) (Version: - ) Thunder Wolves (HKLM-x32\...\Steam App 232970) (Version: - Most Wanted Entertainment) Ticket to Ride (HKLM-x32\...\Steam App 108200) (Version: - Days of Wonder) Tiny and Big: Grandpa's Leftovers (HKLM-x32\...\Steam App 205910) (Version: - Black Pants Game Studio) Titan Attacks (HKLM-x32\...\Steam App 203210) (Version: - Puppygames) To the Moon (HKLM-x32\...\Steam App 206440) (Version: - Freebird Games) Toki Tori (HKLM-x32\...\Steam App 38700) (Version: - Two Tribes) Toki Tori 2+ (HKLM-x32\...\Steam App 201420) (Version: - Two Tribes) Tomb Raider (HKLM-x32\...\Steam App 203160) (Version: - Crystal Dynamics) Tomb Raider II (HKLM-x32\...\Steam App 225300) (Version: - Core Design) Torchlight II (HKLM-x32\...\Steam App 200710) (Version: - Runic Games) Tropico 4 (HKLM-x32\...\Steam App 57690) (Version: - Haemimont Games) TUSB3410 (x32 Version: 6.5.9019.1 - Texas Instruments Inc.) Hidden Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Ultratron (HKLM-x32\...\Steam App 219190) (Version: - Puppygames) Unterstützungsdateien für Microsoft SQL Server 2008-Setup (HKLM\...\{6AF73222-EE90-434C-AE7E-B96F70A68D89}) (Version: 10.1.2731.0 - Microsoft Corporation) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{FEF4C57D-0975-4D3C-ACC7-DCD038C3788F}) (Version: - Microsoft) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{FEF4C57D-0975-4D3C-ACC7-DCD038C3788F}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{99A0DB9A-71FC-4F98-BC1F-78A18195C677}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{DB0B0CDF-77EC-47B0-94E2-4738573A1E58}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.AccessR_{64D96F30-CF4C-4CCE-AAF2-F8909348BF35}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.SingleImage_{64D96F30-CF4C-4CCE-AAF2-F8909348BF35}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (HKLM\...\{90140000-001F-040C-1000-0000000FF1CE}_Office14.AccessR_{9F6507AC-7D8F-46C1-B90F-59C7828E0E0D}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (HKLM\...\{90140000-001F-040C-1000-0000000FF1CE}_Office14.SingleImage_{9F6507AC-7D8F-46C1-B90F-59C7828E0E0D}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.AccessR_{A9C4BE58-07E0-473D-AE68-ECBA13FBF77E}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.SingleImage_{A9C4BE58-07E0-473D-AE68-ECBA13FBF77E}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{8A6BDA63-4D23-4485-A466-8979E10BCF49}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{8A6BDA63-4D23-4485-A466-8979E10BCF49}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{8A6BDA63-4D23-4485-A466-8979E10BCF49}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 64-Bit Edition (HKLM\...\{91140000-0015-0000-1000-0000000FF1CE}_Office14.AccessR_{8A6BDA63-4D23-4485-A466-8979E10BCF49}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-001A-0407-1000-0000000FF1CE}_Office14.SingleImage_{6164E0E5-C903-488C-93AF-1B7AF7EBC331}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{DDDC32A5-9528-4771-B91A-97A8E1D7957B}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0018-0407-1000-0000000FF1CE}_Office14.SingleImage_{FD360122-6829-4497-97C1-1BF578EF695B}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{A20A650C-F820-4CE4-AEA5-EC140192FAFB}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.AccessR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2553444) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{8E076AE6-4E29-4056-A13F-70CC8F433FB5}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{DF33B92A-5381-4F03-AB54-2D67086B357E}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{CFCB8616-A5D1-4281-80E8-389F685BFAE2}) (Version: 4.0.8080.0 - Microsoft Corporation) VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN) War of the Roses (HKLM-x32\...\Steam App 42160) (Version: - Fatshark) Wargame: European Escalation (HKLM-x32\...\Steam App 58610) (Version: - Eugen Systems) Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices (03/07/2012 ) (HKLM\...\0B624A43DD66DBF5CF3EDFA9741A364E688062A4) (Version: 03/07/2012 - GoPro) WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) Wizorb (HKLM-x32\...\Steam App 207420) (Version: - Tribute Games) World of Goo (HKLM-x32\...\Steam App 22000) (Version: - 2D BOY ) Worms Crazy Golf (HKLM-x32\...\Steam App 70620) (Version: - Team17 Software Ltd.) Worms Reloaded (HKLM-x32\...\Steam App 22600) (Version: - Team17 Software Ltd.) Worms Ultimate Mayhem (HKLM-x32\...\Steam App 70600) (Version: - Team17 Software Ltd.) X3: Albion Prelude (HKLM-x32\...\Steam App 201310) (Version: - Egosoft) X3: Terran Conflict (HKLM-x32\...\Steam App 2820) (Version: - Egosoft) Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team) Youtube Downloader HD v. 2.9.9.8 (HKLM-x32\...\Youtube Downloader HD_is1) (Version: - YoutubeDownloaderHD.com) Zeno Clash (HKLM-x32\...\Steam App 22200) (Version: - ACE Team) Zeno Clash 2 (HKLM-x32\...\Steam App 215690) (Version: - ACE Team) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-04-15 01:43 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1DF22E0D-37D9-43C5-B87B-81DCCCDC9455} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core => C:\Users\Deep\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-06] (Google Inc.) Task: {215D7890-B45A-4E9B-8189-76023F5FEF4D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-13] (Google Inc.) Task: {3E743F57-96B2-453F-8CA2-57D62A6B55F8} - System32\Tasks\AdobeAAMUpdater-1.0-YoloSwag-PC-Deep => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-03] (Adobe Systems Incorporated) Task: {A0D86BA9-1CE8-4206-820E-E99833851EA9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-25] (Adobe Systems Incorporated) Task: {A2482288-742F-4FBB-B563-24A3FF662130} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-13] (Google Inc.) Task: {AC0B757F-AEFD-4F97-A1F2-DFACC15F29A1} - System32\Tasks\Amazon Music Helper => C:\Users\Deep\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [2014-03-07] () Task: {BECADCDB-C741-4B30-8E41-B49D040AEDBB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA => C:\Users\Deep\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-06] (Google Inc.) Task: {F85F09CE-F80F-4DBF-9047-7FF3B3B40E0B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000Core.job => C:\Users\Deep\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155462486-2137830924-635027668-1000UA.job => C:\Users\Deep\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-04-12 18:03 - 2014-03-04 15:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () E:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2014-03-11 14:17 - 2014-03-07 22:39 - 03168576 _____ () C:\Users\Deep\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe 2013-10-05 01:56 - 2013-12-09 13:50 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2013-10-05 01:56 - 2013-12-09 13:50 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2013-09-28 05:52 - 2012-08-09 12:55 - 00078480 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll 2013-09-28 05:52 - 2012-08-09 12:55 - 00386192 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll 2013-07-28 21:25 - 2013-10-29 14:43 - 00248832 _____ () E:\Program Files (x86)\Drakonia Configurator\hid.exe 2013-07-28 21:25 - 2012-12-11 12:14 - 00240640 _____ () E:\Program Files (x86)\Drakonia Configurator\trayicon.exe 2014-03-30 23:42 - 2014-03-30 23:42 - 00173568 _____ () E:\Program Files\TeamSpeak\quazip.dll 2014-03-30 23:42 - 2014-03-30 23:42 - 01080832 _____ () E:\Program Files\TeamSpeak\platforms\qwindows.dll 2014-03-30 23:42 - 2014-03-30 23:42 - 00833024 _____ () E:\Program Files\TeamSpeak\sqldrivers\qsqlite.dll 2013-04-04 10:38 - 2014-03-30 23:42 - 00102344 _____ () E:\Program Files\TeamSpeak\soundbackends\directsound_win64.dll 2013-04-04 10:38 - 2014-03-30 23:42 - 00108488 _____ () E:\Program Files\TeamSpeak\soundbackends\windowsaudiosession_win64.dll 2014-03-30 23:42 - 2014-03-30 23:42 - 00030208 _____ () E:\Program Files\TeamSpeak\imageformats\qgif.dll 2014-03-30 23:42 - 2014-03-30 23:42 - 00233984 _____ () E:\Program Files\TeamSpeak\imageformats\qjpeg.dll 2013-04-04 10:38 - 2014-03-30 23:42 - 00563656 _____ () E:\Program Files\TeamSpeak\plugins\clientquery_plugin.dll 2013-09-14 23:32 - 2014-03-30 23:42 - 00577480 _____ () E:\Program Files\TeamSpeak\plugins\teamspeak_control_plugin.dll 2014-03-30 23:42 - 2014-03-30 23:42 - 00159232 _____ () E:\Program Files\TeamSpeak\accessible\qtaccessiblewidgets.dll 2013-06-30 18:43 - 2013-06-30 18:41 - 00397704 _____ () E:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\Deep\AppData\Roaming\Dropbox\bin\libcef.dll 2013-12-18 20:43 - 2013-12-18 20:43 - 00019968 _____ () E:\Adobe\Acrobat 10.0\Acrobat\locale\de_de\acrotray.deu 2013-07-28 21:25 - 2013-01-15 18:06 - 00061952 _____ () E:\Program Files (x86)\Drakonia Configurator\HidDevice.dll 2013-07-28 21:25 - 2011-11-22 14:18 - 00249856 _____ () E:\Program Files (x86)\Drakonia Configurator\language.dll 2014-04-09 22:00 - 2014-04-02 03:57 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll 2013-06-18 22:08 - 2013-06-18 22:08 - 00093696 _____ () E:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2014-04-09 22:00 - 2014-04-02 03:57 - 00674632 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libglesv2.dll 2014-04-09 22:00 - 2014-04-02 03:57 - 00093000 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libegl.dll 2014-04-09 22:00 - 2014-04-02 03:57 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll 2014-04-09 22:00 - 2014-04-02 03:58 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll 2014-04-09 22:00 - 2014-04-02 03:57 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll 2014-01-09 00:20 - 2014-04-22 00:55 - 00340480 _____ () D:\Steam\libavresample-1.dll 2014-04-24 21:14 - 2014-04-22 00:55 - 00471552 _____ () D:\Steam\libavutil-53.dll 2013-05-06 17:05 - 2014-04-01 00:09 - 00754688 _____ () D:\Steam\SDL2.dll 2013-06-06 14:06 - 2014-04-24 00:01 - 01092288 _____ () D:\Steam\bin\chromehtml.DLL 2013-03-26 16:16 - 2014-03-03 21:15 - 20626624 _____ () D:\Steam\bin\libcef.dll 2012-12-11 09:51 - 2013-06-15 01:49 - 01100800 _____ () D:\Steam\bin\avcodec-53.dll 2012-12-11 09:51 - 2013-06-15 01:49 - 00124416 _____ () D:\Steam\bin\avutil-51.dll 2012-12-11 09:51 - 2013-06-15 01:49 - 00192000 _____ () D:\Steam\bin\avformat-53.dll 2014-04-09 22:00 - 2014-04-02 03:58 - 13691720 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll 2013-09-28 05:51 - 2012-06-25 10:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:9A870F8B AlternateDataStreams: C:\Users\Deep\Cookies:VZnhKSjowdmOXaCA4OGT1S AlternateDataStreams: C:\Users\Deep\AppData\Local\Temp:0QqIywsH7jaF7EctsHZ ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CineForm Status.lnk => C:\Windows\pss\CineForm Status.lnk.CommonStartup MSCONFIG\startupreg: Amazon Cloud Player => "C:\Users\Deep\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: KiesAirMessage => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup MSCONFIG\startupreg: KiesPreload => C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/25/2014 09:11:43 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/25/2014 01:10:42 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Der Textzeichenfolgenwert zur Beschreibung des Leistungsindikators in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten. Error: (04/25/2014 01:06:36 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/24/2014 09:10:57 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Der Textzeichenfolgenwert zur Beschreibung des Leistungsindikators in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten. Error: (04/24/2014 09:06:34 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/18/2014 10:47:05 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Der Textzeichenfolgenwert zur Beschreibung des Leistungsindikators in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten. Error: (04/18/2014 10:42:57 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/18/2014 10:41:10 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (04/18/2014 10:41:10 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (04/18/2014 10:41:10 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] System errors: ============= Error: (04/25/2014 09:10:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (04/25/2014 09:10:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (04/25/2014 09:10:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (04/25/2014 09:10:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (04/25/2014 09:10:47 PM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (04/25/2014 09:10:47 PM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (04/25/2014 09:10:31 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (04/25/2014 09:10:31 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (04/25/2014 09:10:31 PM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (04/25/2014 09:10:29 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Avira Echtzeit-Scanner" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Microsoft Office Sessions: ========================= Error: (04/25/2014 09:11:43 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/25/2014 01:10:42 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: 1600000000A3690000A3690000980B0000 Error: (04/25/2014 01:06:36 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/24/2014 09:10:57 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: 1600000000A3690000A3690000980B0000 Error: (04/24/2014 09:06:34 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/18/2014 10:47:05 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: 1600000000A3690000A3690000980B0000 Error: (04/18/2014 10:42:57 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/18/2014 10:41:10 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (04/18/2014 10:41:10 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (04/18/2014 10:41:10 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] CodeIntegrity Errors: =================================== Date: 2014-04-15 01:43:44.680 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-04-15 01:43:44.645 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 39% Total physical RAM: 8152.04 MB Available physical RAM: 4909.95 MB Total Pagefile: 16302.26 MB Available Pagefile: 12981.46 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.79 GB) (Free:4.61 GB) NTFS Drive d: (Volume) (Fixed) (Total:1863.01 GB) (Free:406.26 GB) NTFS Drive e: () (Fixed) (Total:465.66 GB) (Free:146.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: FB64ED2D) Partition 1: (Not Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 272F7E4B) Partition 1: (Not Active) - (Size=-198626508800) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 3EC88F1B) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
26.04.2014, 15:47 | #14 |
/// the machine /// TB-Ausbilder | Win7 - Regelmäßige Systemabstürze Sieht alles gut aus.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.04.2014, 23:32 | #15 |
| Win7 - Regelmäßige Systemabstürze Hatte bislang keine Abstürze mehr. Magst du mir verraten, woran es wahrscheinlich gelegen hat? |
Themen zu Win7 - Regelmäßige Systemabstürze |
antivir, antivirus, avira, blackhole, bluescreen, browser, converter, cpu-z, downloader, dvdvideosoft ltd., error, excel, flash player, google, home, homepage, hängt, launch, maus, mp3, pirates, realtek, refresh, registry, robot, scan, security, software, spotify web helper, svchost.exe, system, teamspeak, virus |