Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 7: angeklickt flash player nicht aktuell

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 05.06.2014, 18:47   #1
Seppiro
 
Windows 7: angeklickt flash player nicht aktuell - Standard

Windows 7: angeklickt flash player nicht aktuell



Hallo,

meine Freundin hat leider auf diese irreführende "Werbung" geklickt die besagt das der Flash player nicht mehr aktuell ist oder java nicht mehr aktuell ist und hat sich damit leider ganz schön viel mist installiert habe bisher adwcleaner und mbam durchlaufen lassen und avira nicht komplett. ich hoffe ihr könnt mir helfen da sicher zu gehen das alles weg ist. Anbei die ganzen logfiles. Da die logfile von mbam viel zu groß ist hab ich sie mal angehängt als zip. Danke schonmal für die hilfe.



Avira
Code:
ATTFilter
Exported events:

05.06.2014 19:25 [System Scanner] Malware found
      The file 'C:\AdwCleaner\Quarantine\C\Program Files 
      (x86)\ScanTack\bin\ScanTackBAApp.dll.vir'
      contained a virus or unwanted program 'TR/Trash.Gen' [trojan]
      Action(s) taken:
      The file was moved to the quarantine directory under the name '0efb0cd8.qua'!
         
FRT
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014
Ran by Rike (administrator) on RIKE-PC on 05-06-2014 19:24:51
Running from E:\Downloads
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ 
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Fuyu LIMITED) C:\ProgramData\WindowsProtectManger\wprotectmanager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIHTU.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202008 2013-10-17] (Realtek Semiconductor)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [GrooveMonitor] => E:\Programme\Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [182352 2014-05-05] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Windows Servelet System Component] => C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe [640512 2014-05-23] ()
HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE [241280 2014-04-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\MountPoints2: H - H:\Autorun.exe
HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\MountPoints2: {0d5449de-b3bf-11e3-8de3-448a5b5dbd6b} - F:\pushinst.exe
HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\MountPoints2: {0da6ec01-bcc1-11e3-89fa-448a5b5dbd6b} - H:\autorun.exe
HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [DAEMON Tools Lite] => E:\Programme\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE [241280 2014-04-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: H - H:\Autorun.exe
HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {0d5449de-b3bf-11e3-8de3-448a5b5dbd6b} - F:\pushinst.exe
HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {0da6ec01-bcc1-11e3-89fa-448a5b5dbd6b} - H:\autorun.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Programme\Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Programme\Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.0.2 - C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.0.2 - C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - E:\Programme\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

Chrome: 
=======
CHR HomePage: about:newtab?source=home
CHR RestoreOnStartup: "about:newtab?source=home"
CHR StartupUrls: "about:newtab?source=home"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
CHR Extension: (Google Docs) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-20]
CHR Extension: (Google Drive) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-20]
CHR Extension: (YouTube) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-20]
CHR Extension: (Google-Suche) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-20]
CHR Extension: (Google Mail) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-20]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-03] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [124496 2014-05-05] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 Microsoft Office Groove Audit Service; E:\Programme\Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation)
R2 WindowsProtectManger; C:\ProgramData\WindowsProtectManger\wprotectmanager.exe [573344 2014-05-27] (Fuyu LIMITED)

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-04-05] (Disc Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-05] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64; C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys [61112 2014-05-22] (StdLib)
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-05 19:24 - 2014-06-05 19:24 - 00000000 ____D () C:\FRST
2014-06-05 19:23 - 2014-06-05 19:23 - 00000148 _____ () C:\Users\Rike\defogger_reenable
2014-06-05 19:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-05 19:05 - 2014-06-05 19:14 - 00000000 ____D () C:\AdwCleaner
2014-06-05 19:00 - 2014-06-05 19:08 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-05 18:59 - 2014-06-05 18:59 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-05 18:59 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-05 18:59 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-05 18:59 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-05 18:55 - 2014-06-05 19:24 - 01101824 _____ () C:\Users\Rike\AppData\Local\ChromeHitoryDB
2014-06-05 18:53 - 2014-04-09 17:39 - 00000426 _____ () C:\AVScanner.ini
2014-06-03 22:52 - 2014-06-03 22:52 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-03 22:21 - 2014-05-22 18:19 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys
2014-06-03 18:24 - 2014-06-03 18:24 - 01350991 _____ (Openersoft ) C:\Users\Rike\Downloads\Flash-3-Update5232014.exe
2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Component Manager
2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\Program Files (x86)\Flash Component Manager
2014-06-03 17:23 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-03 17:23 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-03 17:08 - 2014-06-05 18:59 - 00105580 _____ () C:\Windows\SysWOW64\console.log
2014-06-02 21:14 - 2014-06-02 21:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér
2014-05-29 19:28 - 2014-06-05 19:07 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch
2014-05-29 19:28 - 2014-06-05 19:07 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater
2014-05-29 19:28 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets
2014-05-29 19:28 - 2014-04-09 07:55 - 00034376 _____ () C:\Windows\Launcher.exe
2014-05-27 22:30 - 2014-06-03 18:07 - 00000444 __RSH () C:\ProgramData\ntuser.pol
2014-05-27 22:29 - 2014-05-27 22:29 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Macromedia
2014-05-27 22:23 - 2014-05-27 22:23 - 00003112 _____ () C:\Windows\System32\Tasks\{094D1062-7EF6-4178-B435-6D5112E30493}
2014-05-27 22:19 - 2014-05-27 22:19 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-05-27 22:17 - 2014-05-27 22:17 - 00000000 ____D () C:\Users\Rike\AppData\Local\com
2014-05-27 22:15 - 2014-06-05 19:06 - 00000000 ____D () C:\temp
2014-05-16 19:08 - 2014-05-16 19:08 - 00000000 ____D () C:\Users\Rike\AppData\Local\Microsoft Corporation
2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieUserList
2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieSiteList
2014-05-15 23:41 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 23:41 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 23:41 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 23:41 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 23:41 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 23:41 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 18:25 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 18:25 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 18:25 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 18:25 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 18:25 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 18:25 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 18:25 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 18:25 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-15 18:25 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-15 18:25 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 18:25 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-15 18:25 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 18:25 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 18:25 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 18:25 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 18:25 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 18:25 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 18:25 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 18:25 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 18:25 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 18:25 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 18:25 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 18:25 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 18:25 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 18:25 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 18:25 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 18:25 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-15 18:25 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 18:25 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 18:25 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 18:25 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-15 18:25 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll

==================== One Month Modified Files and Folders =======

2014-06-05 19:24 - 2014-06-05 19:24 - 00000000 ____D () C:\FRST
2014-06-05 19:24 - 2014-06-05 18:55 - 01101824 _____ () C:\Users\Rike\AppData\Local\ChromeHitoryDB
2014-06-05 19:24 - 2014-03-20 07:29 - 00000000 ____D () C:\Users\Rike\AppData\Local\Temp
2014-06-05 19:23 - 2014-06-05 19:23 - 00000148 _____ () C:\Users\Rike\defogger_reenable
2014-06-05 19:23 - 2014-03-20 07:29 - 00000000 ____D () C:\Users\Rike
2014-06-05 19:15 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-05 19:15 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-05 19:14 - 2014-06-05 19:05 - 00000000 ____D () C:\AdwCleaner
2014-06-05 19:12 - 2014-03-20 14:58 - 00699092 _____ () C:\Windows\system32\perfh007.dat
2014-06-05 19:12 - 2014-03-20 14:58 - 00149232 _____ () C:\Windows\system32\perfc007.dat
2014-06-05 19:12 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-05 19:11 - 2014-03-20 07:29 - 01307177 _____ () C:\Windows\WindowsUpdate.log
2014-06-05 19:08 - 2014-06-05 19:00 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-05 19:08 - 2014-03-20 07:50 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-05 19:08 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-05 19:08 - 2009-07-14 06:51 - 00008281 _____ () C:\Windows\setupact.log
2014-06-05 19:07 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch
2014-06-05 19:07 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater
2014-06-05 19:07 - 2010-11-21 05:47 - 00379404 _____ () C:\Windows\PFRO.log
2014-06-05 19:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas
2014-06-05 19:06 - 2014-05-27 22:15 - 00000000 ____D () C:\temp
2014-06-05 18:59 - 2014-06-05 18:59 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-05 18:59 - 2014-06-03 17:08 - 00105580 _____ () C:\Windows\SysWOW64\console.log
2014-06-05 18:55 - 2014-03-20 07:50 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-05 18:53 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-05 18:53 - 2009-07-14 04:34 - 00000580 _____ () C:\Windows\win.ini
2014-06-03 22:52 - 2014-06-03 22:52 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-03 18:24 - 2014-06-03 18:24 - 01350991 _____ (Openersoft ) C:\Users\Rike\Downloads\Flash-3-Update5232014.exe
2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Component Manager
2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\Program Files (x86)\Flash Component Manager
2014-06-03 18:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources
2014-06-03 18:07 - 2014-05-27 22:30 - 00000444 __RSH () C:\ProgramData\ntuser.pol
2014-06-03 17:26 - 2014-03-20 07:29 - 00000000 ___RD () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-03 17:11 - 2014-04-03 20:07 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-06-03 17:11 - 2014-04-03 20:07 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-06-02 21:14 - 2014-06-02 21:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér
2014-06-02 21:14 - 2014-03-20 07:50 - 00002317 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-05-29 19:28 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets
2014-05-29 19:28 - 2014-03-20 07:29 - 00001425 _____ () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-27 22:30 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-05-27 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-05-27 22:29 - 2014-05-27 22:29 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Macromedia
2014-05-27 22:23 - 2014-05-27 22:23 - 00003112 _____ () C:\Windows\System32\Tasks\{094D1062-7EF6-4178-B435-6D5112E30493}
2014-05-27 22:19 - 2014-05-27 22:19 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-05-27 22:17 - 2014-05-27 22:17 - 00000000 ____D () C:\Users\Rike\AppData\Local\com
2014-05-22 18:19 - 2014-06-03 22:21 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys
2014-05-17 15:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-16 19:08 - 2014-05-16 19:08 - 00000000 ____D () C:\Users\Rike\AppData\Local\Microsoft Corporation
2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieUserList
2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieSiteList
2014-05-16 19:02 - 2014-04-09 16:18 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-05-16 07:40 - 2014-03-20 07:29 - 00000000 ___RD () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 07:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-15 23:41 - 2014-04-05 15:00 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 23:40 - 2014-04-05 18:24 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-15 23:40 - 2014-04-05 18:24 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-13 17:05 - 2014-04-03 19:59 - 00001133 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-05-13 17:05 - 2014-04-03 19:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-05-13 17:05 - 2014-04-03 19:59 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-13 17:05 - 2014-03-20 07:37 - 00000000 ____D () C:\ProgramData\Package Cache
2014-05-12 07:26 - 2014-06-05 18:59 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-06-05 18:59 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-06-05 18:59 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-09 08:14 - 2014-06-03 17:23 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-06-03 17:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-06 06:40 - 2014-05-15 23:41 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-15 23:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-15 23:41 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-15 23:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-15 23:41 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-15 23:41 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

Some content of TEMP:
====================
C:\Users\Rike\AppData\Local\Temp\1_Offer_4.exe
C:\Users\Rike\AppData\Local\Temp\1_Offer_5.exe
C:\Users\Rike\AppData\Local\Temp\1_Offer_6.exe
C:\Users\Rike\AppData\Local\Temp\amsetup_activeris_default_010414_installer.exe
C:\Users\Rike\AppData\Local\Temp\AutoRun.exe
C:\Users\Rike\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Rike\AppData\Local\Temp\avgnt.exe
C:\Users\Rike\AppData\Local\Temp\BackupSetup.exe
C:\Users\Rike\AppData\Local\Temp\cloud_backup_setup.exe
C:\Users\Rike\AppData\Local\Temp\devcon64.exe
C:\Users\Rike\AppData\Local\Temp\eauninstall.exe
C:\Users\Rike\AppData\Local\Temp\lly_webssearches.exe
C:\Users\Rike\AppData\Local\Temp\MSIAFTERBURNERSETUP.EXE
C:\Users\Rike\AppData\Local\Temp\nsuB1D7.exe
C:\Users\Rike\AppData\Local\Temp\ose00000.exe
C:\Users\Rike\AppData\Local\Temp\SETUP_AFTERBURNER.EXE
C:\Users\Rike\AppData\Local\Temp\speedupmypc.exe
C:\Users\Rike\AppData\Local\Temp\SpOrder.dll
C:\Users\Rike\AppData\Local\Temp\The Sims 2 Deluxe_uninst.exe
C:\Users\Rike\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Rike\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Rike\AppData\Local\Temp\vopackage.exe
C:\Users\Rike\AppData\Local\Temp\VP6Install.exe
C:\Users\Rike\AppData\Local\Temp\VP6VFW.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-31 15:51

==================== End Of Log ============================
         
Gmer
Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-06-05 19:31:01
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-1 ADATA_SP900 rev.5.0.7b 119,24GB
Running: olz5zuq7.exe; Driver: C:\Users\Rike\AppData\Local\Temp\kxldrpow.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                                                 fffff80003001000 8 bytes [00, 00, 22, 00, 43, 63, 53, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 544                                                                 fffff80003001010 47 bytes [90, 94, AA, 0A, 80, FA, FF, ...]

---- User code sections - GMER 2.1 ----

.text     C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[1740] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                00000000762a1465 2 bytes [2A, 76]
.text     C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[1740] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155               00000000762a14bb 2 bytes [2A, 76]
.text     ...                                                                                                                                * 2
.text     C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[1984] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   00000000762a1465 2 bytes [2A, 76]
.text     C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[1984] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  00000000762a14bb 2 bytes [2A, 76]
.text     ...                                                                                                                                * 2
.text     C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2144] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69       00000000762a1465 2 bytes [2A, 76]
.text     C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2144] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155      00000000762a14bb 2 bytes [2A, 76]
.text     ...                                                                                                                                * 2
.text     C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69            00000000762a1465 2 bytes [2A, 76]
.text     C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155           00000000762a14bb 2 bytes [2A, 76]
.text     ...                                                                                                                                * 2
?         C:\Windows\system32\mssprxy.dll [2256] entry point in ".rdata" section                                                             00000000665271e6
.text     C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[2200] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69           00000000762a1465 2 bytes [2A, 76]
.text     C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[2200] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155          00000000762a14bb 2 bytes [2A, 76]
.text     ...                                                                                                                                * 2
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69          00000000762a1465 2 bytes [2A, 76]
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155         00000000762a14bb 2 bytes [2A, 76]
.text     ...                                                                                                                                * 2
?         C:\Windows\system32\mssprxy.dll [4836] entry point in ".rdata" section                                                             00000000665271e6
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5         0000000076f2f9b1 7 bytes {MOV EDX, 0xfcbe28; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5              0000000076f2fbf5 7 bytes {MOV EDX, 0xfcbe68; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5                  0000000076f2fc25 7 bytes {MOV EDX, 0xfcbda8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5           0000000076f2fc3d 7 bytes {MOV EDX, 0xfcbd28; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5             0000000076f2fc55 7 bytes {MOV EDX, 0xfcbf28; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5           0000000076f2fc85 7 bytes {MOV EDX, 0xfcbf68; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5            0000000076f2fd05 7 bytes {MOV EDX, 0xfcbee8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5           0000000076f2fd1d 7 bytes {MOV EDX, 0xfcbea8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5                     0000000076f2fd69 7 bytes {MOV EDX, 0xfcbc68; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5          0000000076f2fe61 7 bytes {MOV EDX, 0xfcbca8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5                   0000000076f300b9 7 bytes {MOV EDX, 0xfcbc28; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5             0000000076f310c5 7 bytes {MOV EDX, 0xfcbde8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5                   0000000076f3113d 7 bytes {MOV EDX, 0xfcbd68; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5      0000000076f31341 7 bytes {MOV EDX, 0xfcbce8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69          00000000762a1465 2 bytes [2A, 76]
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155         00000000762a14bb 2 bytes [2A, 76]
.text     ...                                                                                                                                * 2
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5         0000000076f2f9b1 7 bytes {MOV EDX, 0x1075e28; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5              0000000076f2fbf5 7 bytes {MOV EDX, 0x1075e68; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5                  0000000076f2fc25 7 bytes {MOV EDX, 0x1075da8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5           0000000076f2fc3d 7 bytes {MOV EDX, 0x1075d28; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5             0000000076f2fc55 7 bytes {MOV EDX, 0x1075f28; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5           0000000076f2fc85 7 bytes {MOV EDX, 0x1075f68; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5            0000000076f2fd05 7 bytes {MOV EDX, 0x1075ee8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5           0000000076f2fd1d 7 bytes {MOV EDX, 0x1075ea8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5                     0000000076f2fd69 7 bytes {MOV EDX, 0x1075c68; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5          0000000076f2fe61 7 bytes {MOV EDX, 0x1075ca8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5                   0000000076f300b9 7 bytes {MOV EDX, 0x1075c28; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5             0000000076f310c5 7 bytes {MOV EDX, 0x1075de8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5                   0000000076f3113d 7 bytes {MOV EDX, 0x1075d68; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5      0000000076f31341 7 bytes {MOV EDX, 0x1075ce8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69          00000000762a1465 2 bytes [2A, 76]
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155         00000000762a14bb 2 bytes [2A, 76]
.text     ...                                                                                                                                * 2
.text     C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe[2884] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69            00000000762a1465 2 bytes [2A, 76]
.text     C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe[2884] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155           00000000762a14bb 2 bytes [2A, 76]
.text     ...                                                                                                                                * 2
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5          0000000076f2f9b1 7 bytes {MOV EDX, 0xdaa28; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5               0000000076f2fbf5 7 bytes {MOV EDX, 0xdaa68; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5                   0000000076f2fc25 7 bytes {MOV EDX, 0xda9a8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5            0000000076f2fc3d 7 bytes {MOV EDX, 0xda928; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5              0000000076f2fc55 7 bytes {MOV EDX, 0xdab28; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5            0000000076f2fc85 7 bytes {MOV EDX, 0xdab68; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5             0000000076f2fd05 7 bytes {MOV EDX, 0xdaae8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5            0000000076f2fd1d 7 bytes {MOV EDX, 0xdaaa8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5                      0000000076f2fd69 7 bytes {MOV EDX, 0xda868; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5           0000000076f2fe61 7 bytes {MOV EDX, 0xda8a8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5                    0000000076f300b9 7 bytes {MOV EDX, 0xda828; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5              0000000076f310c5 7 bytes {MOV EDX, 0xda9e8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5                    0000000076f3113d 7 bytes {MOV EDX, 0xda968; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5       0000000076f31341 7 bytes {MOV EDX, 0xda8e8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69           00000000762a1465 2 bytes [2A, 76]
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155          00000000762a14bb 2 bytes [2A, 76]
.text     ...                                                                                                                                * 2
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5          0000000076f2f9b1 7 bytes {MOV EDX, 0xf51228; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5               0000000076f2fbf5 7 bytes {MOV EDX, 0xf51268; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5                   0000000076f2fc25 7 bytes {MOV EDX, 0xf511a8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5            0000000076f2fc3d 7 bytes {MOV EDX, 0xf51128; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5              0000000076f2fc55 7 bytes {MOV EDX, 0xf51328; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5            0000000076f2fc85 7 bytes {MOV EDX, 0xf51368; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5             0000000076f2fd05 7 bytes {MOV EDX, 0xf512e8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5            0000000076f2fd1d 7 bytes {MOV EDX, 0xf512a8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5                      0000000076f2fd69 7 bytes {MOV EDX, 0xf51068; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5           0000000076f2fe61 7 bytes {MOV EDX, 0xf510a8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5                    0000000076f300b9 7 bytes {MOV EDX, 0xf51028; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5              0000000076f310c5 7 bytes {MOV EDX, 0xf511e8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5                    0000000076f3113d 7 bytes {MOV EDX, 0xf51168; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5       0000000076f31341 7 bytes {MOV EDX, 0xf510e8; JMP RDX}
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69           00000000762a1465 2 bytes [2A, 76]
.text     C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155          00000000762a14bb 2 bytes [2A, 76]
.text     ...                                                                                                                                * 2

---- EOF - GMER 2.1 ----
         
Addition
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-06-2014
Ran by Rike at 2014-06-05 19:25:02
Running from E:\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Adobe Flash Player ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 9.0.124.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
AMD Accelerated Video Transcoding (Version: 13.20.100.31206 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden
AMD Catalyst Install Manager (HKLM\...\{308051DA-0048-7A07-FE8B-9B6EC119A9E8}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Media Foundation Decoders (Version: 1.0.81206.1620 - Advanced Micro Devices, Inc.) Hidden
AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden
ANNO 1404 - Königsedition (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 3.10.0000 - Ubisoft)
Avira (HKLM-x32\...\{70a79d1f-686d-4d5c-962b-07aa1294eae0}) (Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.1.0.0 - Electronic Arts)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.50.56 - Electronic Arts)
Die Sims™ 3 70er, 80er & 90er Accessoires (HKLM-x32\...\{E1868CAE-E3B9-4099-8C18-AA8944D336FD}) (Version: 17.0.77 - Electronic Arts)
Die Sims™ 3 Design-Garten-Accessoires (HKLM-x32\...\{117B6BF6-82C3-420C-B284-9247C8568E53}) (Version: 7.0.55 - Electronic Arts)
Die Sims™ 3 Diesel Accessoires (HKLM-x32\...\{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}) (Version: 14.0.48 - Electronic Arts)
Die Sims™ 3 Einfach tierisch (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts)
Die Sims™ 3 Gib Gas-Accessoires (HKLM-x32\...\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts)
Die Sims™ 3 Jahreszeiten (HKLM-x32\...\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts)
Die Sims™ 3 Katy Perry Süße Welt (HKLM-x32\...\{9B2506E3-9A3F-45B5-96BF-509CAD584650}) (Version: 13.0.62 - Electronic Arts)
Die Sims™ 3 Late Night (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts)
Die Sims™ 3 Lebensfreude (HKLM-x32\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts)
Die Sims™ 3 Luxus-Accessoires (HKLM-x32\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts)
Die Sims™ 3 Reiseabenteuer (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts)
Die Sims™ 3 Showtime (HKLM-x32\...\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts)
Die Sims™ 3 Stadt-Accessoires (HKLM-x32\...\{7B11296A-F894-449C-8DF6-6AAAA7D4D118}) (Version: 9.0.73 - Electronic Arts)
Die Sims™ 3 Supernatural (HKLM-x32\...\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts)
Die Sims™ 3 Traumkarrieren (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts)
Die Sims™ 3 Traumsuite-Accessoires (HKLM-x32\...\{08A25478-C5DD-4EA7-B168-3D687CA987FF}) (Version: 11.0.84 - Electronic Arts)
Die Sims™ 3 Wildes Studentenleben (HKLM-x32\...\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}) (Version: 18.0.126 - Electronic Arts)
Die*Sims™*3 Erstelle einen Sim (HKLM-x32\...\{89173B88-384A-459B-B687-9C0BBC934EF4}) (Version: 1.0.25 - Electronic Arts)
EPSON BX535WD Series Printer Uninstall (HKLM\...\EPSON BX535WD Series) (Version:  - SEIKO EPSON Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 26.0.1410.40 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.0 - Google Inc.) Hidden
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Java 8 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418000FF}) (Version: 8.0.0 - Oracle Corporation)
Java Auto Updater (x32 Version: 2.8.00.132 - Oracle, Inc.) Hidden
Java SE Development Kit 8 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180000}) (Version: 8.0.0 - Oracle Corporation)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7069 - Realtek Semiconductor Corp.)
SupraSavings (Version: 1.0.0.0 - SupraSavings) Hidden <==== ATTENTION
TERA (HKLM-x32\...\{A2F166A0-F031-4E27-A057-C69733219434}_is1) (Version: 7 - Gameforge Productions GmbH)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2880505) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{2720451F-5D04-43EC-AB1F-26D948FD971B}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
WindowsProtectManger20.0.0.339 (HKLM-x32\...\WindowsProtectManger) (Version: 20.0.0.339 - Fuyu LIMITED)
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)

==================== Restore Points  =========================

16-05-2014 17:19:05 Windows 7 Upgrade Advisor wird entfernt
25-05-2014 13:00:26 Geplanter Prüfpunkt
27-05-2014 20:15:00 Uniblue SpeedUpMyPC installation
28-05-2014 15:53:16 Windows Update
29-05-2014 17:44:42 Uniblue SpeedUpMyPC installation
03-06-2014 15:11:42 Windows 7 Upgrade Advisor wird installiert
03-06-2014 15:29:56 Windows 7 Upgrade Advisor wird entfernt
03-06-2014 20:52:52 Windows Update

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {3CA0BDA4-F691-4B4A-88BD-C3B2845FD68E} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {3D0C9D22-EE20-493E-92FB-BC73441C03D7} - \pricemeterwatcher No Task File <==== ATTENTION
Task: {60931F6D-E815-4C87-9496-F3604D509BC6} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {63A38366-90C8-469B-BB67-EF64FD413970} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20] (Google Inc.)
Task: {69ECAADD-4631-4AA8-8330-A6E0DC00619D} - \Browser Updater\Browser Updater No Task File <==== ATTENTION
Task: {830435D2-63A9-4EAA-95E4-0D7B8D268103} - \pricemetertask No Task File <==== ATTENTION
Task: {885674BE-AC97-41C5-8525-D35C15E927C6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20] (Google Inc.)
Task: {8B7C3666-0168-45EC-8D9A-C00FDA29577F} - \PCHelpers_period No Task File <==== ATTENTION
Task: {990C68CD-B079-425A-B425-D003C2120148} - \PCHelpers1st No Task File <==== ATTENTION
Task: {B1DCDD67-ED3D-4B6A-9657-6020215D921A} - \ProtectedSearch\Protected Search No Task File <==== ATTENTION
Task: {C534D9B9-EA45-404E-A926-B04760126944} - System32\Tasks\SystemSockets\SystemSockets => C:\Program Files (x86)\HomeTab\WBrokerHandler.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2014-06-03 18:24 - 2014-05-23 13:11 - 00640512 _____ () C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe
2014-05-05 10:37 - 2014-05-05 10:37 - 00138320 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll
2014-05-05 10:37 - 2014-05-05 10:37 - 00065616 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll
2014-04-03 20:07 - 2014-05-05 10:37 - 00049744 _____ () C:\Users\Rike\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
2014-06-03 18:24 - 2014-03-14 22:25 - 00236544 _____ () C:\Program Files (x86)\Flash Component Manager\sqlite3.dll
2014-03-20 07:50 - 2013-03-20 08:03 - 00598480 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libglesv2.dll
2014-03-20 07:50 - 2013-03-20 08:03 - 00124368 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libegl.dll
2014-03-20 07:50 - 2013-03-20 08:04 - 04050896 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll
2014-03-20 07:50 - 2013-03-20 08:04 - 00390096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll
2014-03-20 07:50 - 2013-03-20 08:03 - 01606096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ffmpegsumo.dll
2014-03-20 07:50 - 2013-03-20 08:04 - 12662224 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SecureAssist => ""="service"

==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: USB (Universal Serial Bus)-Controller
Description: USB (Universal Serial Bus)-Controller
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/05/2014 07:09:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/05/2014 06:52:34 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/03/2014 06:07:18 PM) (Source: MsiInstaller) (EventID: 11606) (User: Rike-PC)
Description: Produkt: Driver Detective -- Fehler 1606. Zugriff auf die Netzwerkadresse hxxp://c4213555.r55.cf2.rackcdn.com/Produc~1.cab war nicht möglich.

Error: (06/03/2014 05:20:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/03/2014 05:06:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 05:43:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/01/2014 00:42:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/31/2014 03:27:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/29/2014 07:49:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BlockAndSurfIx171.exe, Version: 1.171.0.0, Zeitstempel: 0x537e5167
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00038e19
ID des fehlerhaften Prozesses: 0x5d8
Startzeit der fehlerhaften Anwendung: 0xBlockAndSurfIx171.exe0
Pfad der fehlerhaften Anwendung: BlockAndSurfIx171.exe1
Pfad des fehlerhaften Moduls: BlockAndSurfIx171.exe2
Berichtskennung: BlockAndSurfIx171.exe3

Error: (05/29/2014 07:32:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (06/05/2014 07:06:59 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{EBE666C3-F26C-4CF6-8ABA-3D5F5D2625E1}Nicht verfügbarNT-AUTORITÄTLOKALER DIENSTS-1-5-19LocalHost (unter Verwendung von LRPC)

Error: (06/05/2014 07:06:59 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{EBE666C3-F26C-4CF6-8ABA-3D5F5D2625E1}Nicht verfügbarNT-AUTORITÄTNETZWERKDIENSTS-1-5-20LocalHost (unter Verwendung von LRPC)

Error: (06/05/2014 06:56:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Service Component of VO" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (06/03/2014 06:06:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Search Protect Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (06/03/2014 05:26:46 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Computer Backup (MyPC Backup)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (06/02/2014 05:43:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (06/02/2014 05:43:29 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Computer Backup (MyPC Backup) erreicht.

Error: (05/29/2014 07:49:00 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "BlockAndSurf" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (05/29/2014 07:28:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Wajam Internet Enhancer Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (05/29/2014 07:28:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "IePlugin Services" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


Microsoft Office Sessions:
=========================

==================== Memory info =========================== 

Percentage of memory in use: 20%
Total physical RAM: 8119.99 MB
Available physical RAM: 6426.7 MB
Total Pagefile: 16238.16 MB
Available Pagefile: 13939.59 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:119.14 GB) (Free:75.63 GB) NTFS
Drive e: (Standard Laufwerk) (Fixed) (Total:931.51 GB) (Free:812.63 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 37FEC212)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 9FDCDD08)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=119 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         

 

Themen zu Windows 7: angeklickt flash player nicht aktuell
4d36e972-e325-11ce-bfc1-08002be10318, antivirus, association, branding, homepage, msil/domaiq.a, pup.optional.bundleinstaller.a, pup.optional.findright.a, pup.optional.installcore.a, realtek, software, super, svchost.exe, teredo, tr/trash.gen, vcredist, werbung, win32/anyprotect.d, win32/browsefox.e, win32/domaiq.bb, win32/domaiq.bh, win32/installcore.az, win32/installcore.jw, win32/softpulse.b, win32/tivmonk.b, win32/vopackage.h, win32/wajam.f, windowsprotectmanger




Ähnliche Themen: Windows 7: angeklickt flash player nicht aktuell


  1. Adobe Flash-Player funktioniert nicht
    Alles rund um Windows - 26.10.2015 (0)
  2. Windows 8: Adobe Flash Player Script Fehler bei GMX
    Log-Analyse und Auswertung - 16.09.2015 (11)
  3. Windows 7: Keine Verbindung zum Windowsdienst/Flash Player stürzt ab.
    Plagegeister aller Art und deren Bekämpfung - 26.06.2015 (5)
  4. Windows 7, System langsam und Installation von Adobe Flash Player geht nicht
    Plagegeister aller Art und deren Bekämpfung - 09.04.2015 (10)
  5. Windows 8.1: Flash Player Virus auf Streaming-Websites
    Log-Analyse und Auswertung - 09.12.2014 (7)
  6. Win7_Rechner hängt/Internet langsam/ständig Meldung: Plug-in (Shockwave Flash / oder Flash Player) hängt oder reagiert nicht
    Plagegeister aller Art und deren Bekämpfung - 15.11.2014 (19)
  7. Kann Flash player nicht installieren weil Antivirus es nicht zulässt obwohl nicht vorhanden ?
    Alles rund um Windows - 26.10.2014 (8)
  8. Pop ups von Flash Player Updates etc. + Flash Player funktioniert nicht mehr
    Plagegeister aller Art und deren Bekämpfung - 24.07.2014 (8)
  9. in PPopup vom flash Player: Seite kann nicht angezeigt werden! Aktualisieren sie Player auf die neueste Version!
    Plagegeister aller Art und deren Bekämpfung - 26.06.2014 (21)
  10. Windows XP: Virus Win 32/Trojaner nach Flash player update
    Log-Analyse und Auswertung - 24.01.2014 (20)
  11. Adobe Flash Player lässt sich nicht installieren
    Alles rund um Windows - 23.01.2014 (1)
  12. trotz flash player update funktioniert youtube etc nicht
    Log-Analyse und Auswertung - 15.01.2014 (2)
  13. Neuster Adobe Flash Player lässt sich nicht installieren
    Plagegeister aller Art und deren Bekämpfung - 12.01.2014 (3)
  14. Windows 7: Adobe Flash Player - ZeroAccess
    Log-Analyse und Auswertung - 08.09.2013 (21)
  15. Adobe Flash Player funktioniert nicht mehr
    Plagegeister aller Art und deren Bekämpfung - 23.09.2012 (33)
  16. Flash Player Update funktioniert nicht
    Alles rund um Windows - 03.09.2011 (6)
  17. Flash Player lässt sich nicht für Firefox (nur für Opera) installieren!
    Alles rund um Windows - 06.07.2008 (1)

Zum Thema Windows 7: angeklickt flash player nicht aktuell - Hallo, meine Freundin hat leider auf diese irreführende "Werbung" geklickt die besagt das der Flash player nicht mehr aktuell ist oder java nicht mehr aktuell ist und hat sich damit - Windows 7: angeklickt flash player nicht aktuell...
Archiv
Du betrachtest: Windows 7: angeklickt flash player nicht aktuell auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.