|
Log-Analyse und Auswertung: PC bootet in safemode und fährt dann runterWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
07.09.2014, 18:43 | #1 |
| PC bootet in safemode und fährt dann runter Hallo, beim Starten kommt die Meldung: "System is booting in safemode - minimal Services" Dann erscheint kurz der Anmeldeschirm. Dann fährt der Rechner runter. Das wars. Könnt ihr helfen? Den FRST Scan habe ich angehängt. Vielleicht ist dies die Ursachen: Mein Sohn hat im MSCONFIG ausgewählt: "Beim Hochfahren minimale Dienste. Das Ergebnis ist, dass wir ihn jetzt gar nicht mehr starten können (s.o.) Vielen Dank schon mal für eure Mühen. Dirk Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-09-2014 Ran by SYSTEM on MININT-KI8199L on 07-09-2014 18:40:56 Running from F:\ Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log. The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12666984 2011-08-09] (Realtek Semiconductor) HKLM\...\Run: [Cm106Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190472 2009-09-17] (Logitech Inc.) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation) HKLM-x32\...\Run: [ChicoSys] => C:\Windows\SysWOW64\cc32\webtmr.exe [6484352 2009-07-14] (Salfeld Computer) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3816784 2014-07-21] (LogMeIn Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [161584 2014-08-04] (Avira Operations GmbH & Co. KG) HKLM\...\RunOnce: [*Restore] => C:\Windows\system32\rstrui.exe [296960 2010-11-21] (Microsoft Corporation) HKU\Dirk\...\Run: [CCWinTray] => C:\Windows\tray\wintmr.exe [6864256 2009-07-14] (Salfeld Computer) HKU\Dirk\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\Dirk\...\Policies\system: [DisableLockWorkstation] 0 HKU\Dirk\...\Policies\system: [DisableClock] 0 HKU\Dirk\...\Policies\system: [LogonHoursAction] 2 HKU\Dirk\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Dirk\...\Policies\Explorer: [NoControlPanel] 0 HKU\Dirk\...\Policies\Explorer: [NoFind] 0 HKU\Luca\...\Policies\system: [DisableClock] 1 HKU\Luca\...\Policies\system: [DisableLockWorkstation] 0 HKU\Luca\...\Policies\system: [LogonHoursAction] 2 HKU\Luca\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Luca\...\Policies\Explorer: [NoControlPanel] 0 HKU\Luca\...\Policies\Explorer: [NoSaveSettings] 0 HKU\Luca\...\Policies\Explorer: [NoFind] 0 AppInit_DLLs: c:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL => c:\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll [4139336 2013-11-21] () Startup: C:\Users\Dirk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (No File) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-3000299772-3109549842-2761917205-1002\User: Group Policy restriction detected <======= ATTENTION ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 70e6ca8c; c:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll [191128 2013-11-21] () S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-17] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-17] (Avira Operations GmbH & Co. KG) S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG) S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36392 2014-03-14] (Just Develop It) S2 ksupmgr; C:\Windows\SysWOW64\ksupmgr.exe [765592 2010-08-25] (Salfeld Computer) S2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-07-16] (LogMeIn, Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) S2 MgAssistService; C:\Program Files (x86)\Mobogenie\MgAssist.exe [70848 2014-04-08] () S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation) S2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-06-28] () S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-26] () S2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2144056 2013-10-22] (TuneUp Software) S2 VOsrv; C:\Users\Dirk\AppData\Roaming\VOPackage\VOsrv.exe [353792 2014-02-25] () S4 OtShotUpdateService; C:\Program Files (x86)\OtShot\OtshotUpdateServiceEx.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-01-14] () S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-26] (Avira Operations GmbH & Co. KG) S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG) S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-01-14] () S2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation) S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) S3 StarOpen; No ImagePath S3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-12-12] (TuneUp Software) S3 USBMULCD; C:\Windows\System32\drivers\CM10664.sys [1307648 2011-03-31] (C-Media Electronics Inc) S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] ========================== Drivers MD5 ======================= C:\Windows\System32\DRIVERS\1394ohci.sys ==> MD5 is legit C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\afcdp.sys AE1FCE2CD1E99BEA89183BA8CD320872 C:\Windows\system32\drivers\afd.sys FA886682CFC5D36718D3E436AACF10B9 C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\amdppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\amdsata.sys 53D8D46D51D390ABDB54ECA623165CB7 C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit C:\Windows\System32\drivers\amdxata.sys 75C51148154E34EB3D7BB84749A758D5 C:\Windows\system32\drivers\appid.sys ==> MD5 is legit C:\Windows\system32\drivers\arc.sys ==> MD5 is legit C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\athrx.sys 7D89B0C443F6068E5B27AA3B972069FF C:\Windows\System32\DRIVERS\atksgt.sys FC0E8778C000291CAF60EB88C011E931 C:\Windows\System32\DRIVERS\avgntflt.sys 4663C5AD76FE8E19592DE808156FA07D C:\Windows\System32\DRIVERS\avipbb.sys 8902AEC2382A37E9E99A4E0D52DBD42B C:\Windows\System32\DRIVERS\avkmgr.sys 390184FAD8FCC1B6DA25AEBAE928C3B6 C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys ==> MD5 is legit C:\Windows\system32\drivers\CmBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys EBF28856F69CF094A902F884CF989706 C:\Windows\system32\drivers\compbatt.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\drivers\disk.sys ==> MD5 is legit C:\Windows\system32\drivers\drmkaud.sys ==> MD5 is legit C:\Windows\System32\drivers\dxgkrnl.sys 87CE5C8965E101CCCED1F4675557E868 C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit C:\Windows\System32\Drivers\EtronHub3.sys DB6AEC32FAF5BD002D9ED6C38692D42B C:\Windows\System32\Drivers\EtronXHCI.sys 9CC2F24274741E12F9DF92125EA6D6D8 C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0 C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\GEARAspiWDM.sys 8E98D21EE06192492A5671A6144D092F C:\Windows\System32\DRIVERS\hamachi.sys 1E6438D4EA6E1174A3B3B1EDC4DE660B C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\i8042prt.sys ==> MD5 is legit C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366 C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit C:\Windows\System32\drivers\RTKVHD64.sys 4BBB5A55EEB5EC11B20FCBB4CBB49357 C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit C:\Windows\system32\drivers\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit C:\Windows\system32\drivers\msiscsi.sys 96BB922A0981BC7432C8CF52B5410FE6 C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit C:\Windows\System32\Drivers\ksecdd.sys 353009DEDF918B2A51414F330CF72DEC C:\Windows\System32\Drivers\ksecpkg.sys 1C2D8E18AA8FD50CD04C15CC27F7F5AB C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\lirsgt.sys 156AB2E56DC3CA0B582E3362E07CDED7 C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\mrxdav.sys 1A4F75E63C9FB84B85DFFC6B63FD5404 C:\Windows\System32\DRIVERS\mrxsmb.sys A5D9106A73DC88564C825D317CAC68AC C:\Windows\System32\DRIVERS\mrxsmb10.sys D711B3C1D5F42C0C2415687BE09FC163 C:\Windows\System32\DRIVERS\mrxsmb20.sys 9423E9D355C8D303E76B8CFBD8A5C30C C:\Windows\System32\drivers\msahci.sys ==> MD5 is legit C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88 C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit C:\Windows\System32\drivers\npf.sys ==> MD5 is legit C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\System32\Drivers\Ntfs.sys 1A29A59A4C5BA6F8C85062A613B7E2B2 C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit C:\Windows\System32\drivers\nvhda64v.sys 554964B900AE2954B8B589B6287034AC C:\Windows\System32\DRIVERS\nvlddmkm.sys 91695E69E760C4B9C199051C995FAFDE C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys A0D870DCE152EE5B92A41AD927201D19 C:\Windows\System32\drivers\nvvad64v.sys 75034A4D7C02327D150B617571D4196A C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit C:\Windows\system32\drivers\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C C:\Windows\System32\drivers\pci.sys ==> MD5 is legit C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\drivers\processr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit C:\Windows\system32\drivers\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34 C:\Windows\System32\Drivers\RDPWD.sys E61608AA35E98999AF9AAEEEA6114B0A C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Rt64win7.sys 6D3C7E7D82D3DC92DC2A8B0DF9F20F8A C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\serenum.sys ==> MD5 is legit C:\Windows\system32\drivers\serial.sys ==> MD5 is legit C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\snapman.sys 10450F432811D7FDA60A97FCC674D7B2 C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28 C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3 C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit C:\Windows\System32\drivers\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E C:\Windows\System32\DRIVERS\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\tdrpm273.sys 99527D49EE0A96FC25537C61B270A372 C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8 C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\timntr.sys EBBAEA02F0095A798000C7E06B16D41B C:\Windows\System32\DRIVERS\tssecsrv.sys 4CE278FC9671BA81A138D70823FCAA09 C:\Windows\System32\drivers\tsusbflt.sys 17C6B51CBCCDED95B3CC14E22791F85E C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07 C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys DCC94C51D27C7EC0DADECA8F64C94FCF C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit C:\Windows\System32\Drivers\usbaapl64.sys C9E9D59C0099A9FF51697E9306A44240 C:\Windows\System32\drivers\usbaudio.sys B0435098C81D04CAFFF80DDB746CD3A2 C:\Windows\System32\DRIVERS\usbccgp.sys DCA68B0943D6FA415F0C56C92158A83A C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31 C:\Windows\System32\DRIVERS\usbehci.sys 18A85013A3E0F7E1755365D287443965 C:\Windows\System32\DRIVERS\usbfilter.sys 2C780746DC44A28FE67004DC58173F05 C:\Windows\System32\DRIVERS\usbhub.sys 8D1196CFBB223621F2C67D45710F25BA C:\Windows\System32\drivers\CM10664.sys F9B3054339A71F16430F6585EBC8BE96 C:\Windows\System32\DRIVERS\usbohci.sys 765A92D428A8DB88B960DA5A8D6089DC C:\Windows\system32\drivers\usbprint.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6 C:\Windows\system32\drivers\usbuhci.sys DD253AFC3BC6CBA412342DE60C3647F3 C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\system32\drivers\wd.sys ==> MD5 is legit C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8 C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D C:\Windows\System32\drivers\WmBEnum.sys E7F4937B613B1E4294100C9D4EFC36A9 C:\Windows\System32\drivers\WmFilter.sys 6F6F2B263002B243D3501C7E6C8FC11D C:\Windows\System32\DRIVERS\wmiacpi.sys ==> MD5 is legit C:\Windows\System32\drivers\WmVirHid.sys 52B4FCC6AFAEC0FFD80BDA63F9B140CD C:\Windows\System32\drivers\WmXlCore.sys 395B3E7FBA81BDC4501641B3B2CF2E20 C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659 ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-07 18:34 - 2014-09-07 18:40 - 00000000 ____D () C:\FRST 2014-09-07 12:44 - 2014-09-07 12:47 - 00000000 ___HD () C:\System Shared 2014-09-07 12:44 - 2014-09-07 12:44 - 00000000 ___HD () C:\Device 2014-08-30 09:35 - 2014-08-30 09:37 - 17088592 _____ (Electronic Arts, Inc.) C:\Users\Luca\Downloads\OriginThinSetup.exe 2014-08-29 18:24 - 2014-08-29 18:24 - 01101648 _____ () C:\Users\Luca\Downloads\LogMeIn Hamachi - CHIP-Installer.exe 2014-08-29 17:27 - 2013-03-04 05:34 - 01808510 _____ () C:\Users\Luca\Downloads\TekkitLite.jar 2014-08-29 17:27 - 2013-03-04 05:33 - 02061638 _____ () C:\Users\Luca\Downloads\minecraft_server.jar 2014-08-29 17:27 - 2013-01-12 04:40 - 00000000 ____D () C:\Users\Luca\Downloads\mods 2014-08-29 17:27 - 2013-01-12 04:39 - 00000000 ____D () C:\Users\Luca\Downloads\coremods 2014-08-29 17:27 - 2013-01-04 08:42 - 00000555 _____ () C:\Users\Luca\Downloads\server.properties 2014-08-29 17:27 - 2013-01-04 08:20 - 00000054 _____ () C:\Users\Luca\Downloads\launch.sh 2014-08-29 17:27 - 2013-01-04 08:20 - 00000051 _____ () C:\Users\Luca\Downloads\launch.bat 2014-08-29 17:17 - 2014-08-29 17:22 - 00001376 _____ () C:\Users\Luca\Desktop\TechnicLauncher - Verknüpfung.lnk 2014-08-29 17:17 - 2014-08-29 17:19 - 00000000 ____D () C:\Users\Luca\Documents\Tekkit 2014-08-29 17:14 - 2014-08-29 17:16 - 20827501 _____ () C:\Users\Luca\Downloads\Tekkit_Lite_Server_0.6.5.zip 2014-08-28 16:44 - 2014-08-28 16:44 - 01397992 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.5.0_148.exe 2014-08-28 14:01 - 2014-08-23 03:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll 2014-08-28 14:01 - 2014-08-23 02:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-28 14:01 - 2014-08-23 01:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2014-08-27 16:27 - 2014-08-27 16:27 - 02249144 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.4.0_147.exe 2014-08-21 11:20 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2014-08-21 11:20 - 2014-05-14 17:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2014-08-21 11:20 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-08-21 11:20 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2014-08-21 11:20 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll 2014-08-21 11:20 - 2014-05-14 17:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll 2014-08-21 11:20 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2014-08-21 11:20 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2014-08-21 11:20 - 2014-05-14 17:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2014-08-21 11:20 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-08-21 11:19 - 2014-05-14 08:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2014-08-21 11:19 - 2014-05-14 08:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-08-21 11:19 - 2014-05-14 08:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2014-08-21 11:19 - 2014-05-14 08:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-08-18 13:08 - 2014-08-18 13:09 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8(1).exe 2014-08-18 13:01 - 2014-08-18 13:09 - 00001033 _____ () C:\Users\Dirk\Desktop\FlyVPN.lnk 2014-08-18 13:01 - 2014-08-18 13:09 - 00000000 ____D () C:\Program Files (x86)\FlyVPN 2014-08-18 13:01 - 2014-08-18 13:01 - 00000000 ____D () C:\ProgramData\FlyVPN 2014-08-18 13:00 - 2014-08-18 13:00 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8.exe 2014-08-18 12:56 - 2014-08-22 17:09 - 00001149 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-17 21:37 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\System32\icardres.dll 2014-08-17 21:37 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-17 21:37 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-17 21:37 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\System32\TsWpfWrp.exe 2014-08-17 21:37 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\System32\icardagt.exe 2014-08-17 21:37 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\System32\infocardapi.dll 2014-08-17 21:37 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-17 21:37 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-17 18:24 - 2014-08-17 19:36 - 620143037 _____ () C:\Users\Luca\Downloads\mb_warband_setup_1160.exe 2014-08-17 17:20 - 2014-08-01 00:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2014-08-17 17:20 - 2014-08-01 00:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-17 17:20 - 2014-07-25 15:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2014-08-17 17:20 - 2014-07-25 15:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2014-08-17 17:20 - 2014-07-25 15:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll 2014-08-17 17:20 - 2014-07-25 14:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-17 17:20 - 2014-07-25 14:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2014-08-17 17:20 - 2014-07-25 14:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2014-08-17 17:20 - 2014-07-25 14:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll 2014-08-17 17:20 - 2014-07-25 14:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2014-08-17 17:20 - 2014-07-25 14:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll 2014-08-17 17:20 - 2014-07-25 14:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2014-08-17 17:20 - 2014-07-25 14:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2014-08-17 17:20 - 2014-07-25 14:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-17 17:20 - 2014-07-25 14:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2014-08-17 17:20 - 2014-07-25 14:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2014-08-17 17:20 - 2014-07-25 14:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe 2014-08-17 17:20 - 2014-07-25 13:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll 2014-08-17 17:20 - 2014-07-25 13:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2014-08-17 17:20 - 2014-07-25 13:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2014-08-17 17:20 - 2014-07-25 13:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-17 17:20 - 2014-07-25 13:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-17 17:20 - 2014-07-25 13:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-17 17:20 - 2014-07-25 13:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-17 17:20 - 2014-07-25 13:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2014-08-17 17:20 - 2014-07-25 13:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll 2014-08-17 17:20 - 2014-07-25 13:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-17 17:20 - 2014-07-25 13:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll 2014-08-17 17:20 - 2014-07-25 13:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-17 17:20 - 2014-07-25 13:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2014-08-17 17:20 - 2014-07-25 13:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-17 17:20 - 2014-07-25 13:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-17 17:20 - 2014-07-25 13:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2014-08-17 17:20 - 2014-07-25 13:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-17 17:20 - 2014-07-25 13:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-17 17:20 - 2014-07-25 13:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-17 17:20 - 2014-07-25 12:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-17 17:20 - 2014-07-25 12:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2014-08-17 17:20 - 2014-07-25 12:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-17 17:20 - 2014-07-25 12:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2014-08-17 17:20 - 2014-07-25 12:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2014-08-17 17:20 - 2014-07-25 12:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2014-08-17 17:20 - 2014-07-25 12:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-17 17:20 - 2014-07-25 12:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-17 17:20 - 2014-07-25 12:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-17 17:20 - 2014-07-25 12:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2014-08-17 17:20 - 2014-07-25 12:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-17 17:20 - 2014-07-25 12:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-17 17:20 - 2014-07-25 12:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-17 17:20 - 2014-07-25 12:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-17 17:20 - 2014-07-25 11:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2014-08-17 17:20 - 2014-07-25 11:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2014-08-17 17:20 - 2014-07-25 11:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2014-08-17 17:20 - 2014-07-25 11:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-17 17:20 - 2014-07-25 11:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-17 17:20 - 2014-07-25 11:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-17 17:16 - 2014-07-16 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll 2014-08-17 17:16 - 2014-07-16 03:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-17 17:16 - 2014-06-25 03:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll 2014-08-17 17:16 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-17 17:16 - 2014-06-16 03:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2014-08-17 17:16 - 2014-06-03 11:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\System32\msi.dll 2014-08-17 17:16 - 2014-06-03 11:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll 2014-08-17 17:16 - 2014-06-03 11:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\System32\msihnd.dll 2014-08-17 17:16 - 2014-06-03 11:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\System32\consent.exe 2014-08-17 17:16 - 2014-06-03 10:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-17 17:16 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-17 17:16 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-17 17:11 - 2014-07-14 03:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll 2014-08-17 17:11 - 2014-07-14 02:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-07 18:40 - 2014-09-07 18:34 - 00000000 ____D () C:\FRST 2014-09-07 15:30 - 2012-01-22 17:47 - 00000016 _____ () C:\Windows\SysWOW64\excltmp~.dat 2014-09-07 15:30 - 2012-01-22 17:46 - 00000415 _____ () C:\NET.INI 2014-09-07 14:01 - 2012-01-13 23:02 - 00000000 ____D () C:\users\Luca 2014-09-07 14:01 - 2012-01-12 13:26 - 00000000 ____D () C:\users\Dirk 2014-09-07 14:00 - 2014-07-22 11:15 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi 2014-09-07 14:00 - 2013-11-07 20:53 - 00000000 ____D () C:\Windows\pss 2014-09-07 14:00 - 2013-10-01 13:10 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-09-07 14:00 - 2013-03-24 10:42 - 00000000 ____D () C:\Users\Luca\AppData\Roaming\Skype 2014-09-07 14:00 - 2012-07-11 18:42 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-09-07 14:00 - 2012-02-19 11:48 - 00000000 ____D () C:\Users\Luca\AppData\Local\LogMeIn Hamachi 2014-09-07 14:00 - 2012-01-14 00:35 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-09-07 14:00 - 2012-01-12 13:51 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-09-07 14:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\System32\NDF 2014-09-07 14:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-09-07 14:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2014-09-07 13:11 - 2010-11-21 08:00 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-09-07 12:47 - 2014-09-07 12:44 - 00000000 ___HD () C:\System Shared 2014-09-07 12:44 - 2014-09-07 12:44 - 00000000 ___HD () C:\Device 2014-09-02 16:09 - 2012-01-12 13:25 - 02009606 _____ () C:\Windows\WindowsUpdate.log 2014-09-02 16:05 - 2012-11-02 18:25 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-02 16:03 - 2013-09-30 15:07 - 00000000 ____D () C:\ProgramData\Origin 2014-09-02 16:02 - 2013-09-30 15:07 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-09-02 16:01 - 2009-07-14 05:51 - 00211254 _____ () C:\Windows\setupact.log 2014-09-02 16:00 - 2012-01-13 23:52 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-09-02 16:00 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-01 16:39 - 2013-08-22 17:35 - 00000282 _____ () C:\Windows\Tasks\DSite.job 2014-09-01 16:35 - 2013-08-22 17:35 - 00000288 _____ () C:\Windows\Tasks\MetaCrawler.job 2014-09-01 15:55 - 2012-01-13 23:52 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-09-01 15:35 - 2013-08-22 18:35 - 00000204 _____ () C:\Users\Luca\AppData\Roaming\WB.CFG 2014-09-01 15:10 - 2013-09-30 15:59 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-09-01 15:03 - 2009-07-14 05:45 - 00022512 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-01 15:03 - 2009-07-14 05:45 - 00022512 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-31 16:58 - 2013-09-30 15:59 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-08-31 08:41 - 2014-04-25 09:24 - 00000000 ____D () C:\Users\Dirk\AppData\Roaming\Systweak 2014-08-30 09:37 - 2014-08-30 09:35 - 17088592 _____ (Electronic Arts, Inc.) C:\Users\Luca\Downloads\OriginThinSetup.exe 2014-08-29 20:00 - 2013-03-10 09:53 - 00000000 ____D () C:\Users\Luca\AppData\Roaming\.minecraft 2014-08-29 18:35 - 2012-02-19 19:28 - 00000000 ____D () C:\Users\Dirk\AppData\Local\LogMeIn Hamachi 2014-08-29 18:24 - 2014-08-29 18:24 - 01101648 _____ () C:\Users\Luca\Downloads\LogMeIn Hamachi - CHIP-Installer.exe 2014-08-29 17:29 - 2012-07-08 10:02 - 00003072 ___SH () C:\Users\Luca\Thumbs.db 2014-08-29 17:22 - 2014-08-29 17:17 - 00001376 _____ () C:\Users\Luca\Desktop\TechnicLauncher - Verknüpfung.lnk 2014-08-29 17:19 - 2014-08-29 17:17 - 00000000 ____D () C:\Users\Luca\Documents\Tekkit 2014-08-29 17:16 - 2014-08-29 17:14 - 20827501 _____ () C:\Users\Luca\Downloads\Tekkit_Lite_Server_0.6.5.zip 2014-08-29 13:20 - 2013-04-19 16:37 - 00000000 ____D () C:\Users\Luca\AppData\Roaming\.technic 2014-08-29 13:03 - 2010-11-21 04:47 - 00685762 _____ () C:\Windows\PFRO.log 2014-08-28 16:44 - 2014-08-28 16:44 - 01397992 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.5.0_148.exe 2014-08-28 16:34 - 2009-07-14 05:45 - 00414096 _____ () C:\Windows\System32\FNTCACHE.DAT 2014-08-27 16:27 - 2014-08-27 16:27 - 02249144 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.4.0_147.exe 2014-08-23 03:07 - 2014-08-28 14:01 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll 2014-08-23 02:45 - 2014-08-28 14:01 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-23 01:59 - 2014-08-28 14:01 - 03163648 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2014-08-22 17:40 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-08-22 17:09 - 2014-08-18 12:56 - 00001149 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-22 17:09 - 2013-12-26 03:56 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-22 17:09 - 2013-05-24 09:48 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-19 06:45 - 2012-01-12 14:18 - 00309819 _____ () C:\Windows\DirectX.log 2014-08-18 13:09 - 2014-08-18 13:08 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8(1).exe 2014-08-18 13:09 - 2014-08-18 13:01 - 00001033 _____ () C:\Users\Dirk\Desktop\FlyVPN.lnk 2014-08-18 13:09 - 2014-08-18 13:01 - 00000000 ____D () C:\Program Files (x86)\FlyVPN 2014-08-18 13:01 - 2014-08-18 13:01 - 00000000 ____D () C:\ProgramData\FlyVPN 2014-08-18 13:00 - 2014-08-18 13:00 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8.exe 2014-08-18 12:59 - 2012-11-02 18:25 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-08-18 12:59 - 2012-11-02 18:25 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-08-18 12:59 - 2012-01-12 13:46 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-08-18 12:56 - 2013-05-24 09:48 - 00000000 ____D () C:\ProgramData\Avira 2014-08-18 12:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-17 21:51 - 2012-01-15 17:47 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-17 21:44 - 2013-08-18 11:38 - 00000000 ____D () C:\Windows\System32\MRT 2014-08-17 21:42 - 2012-01-12 15:21 - 99218768 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2014-08-17 20:16 - 2012-05-28 20:44 - 00001156 _____ () C:\Users\Dirk\Desktop\Mount&Blade Warband.lnk 2014-08-17 20:16 - 2012-01-21 15:58 - 00001156 _____ () C:\Users\Luca\Desktop\Mount&Blade Warband.lnk 2014-08-17 20:15 - 2012-01-21 15:58 - 00000000 ____D () C:\Program Files (x86)\Mount&Blade Warband 2014-08-17 19:36 - 2014-08-17 18:24 - 620143037 _____ () C:\Users\Luca\Downloads\mb_warband_setup_1160.exe 2014-08-17 18:00 - 2013-10-01 18:39 - 00297088 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-08-17 17:47 - 2013-03-15 18:32 - 00000000 ____D () C:\ProgramData\Skype Some content of TEMP: ==================== C:\Users\Dirk\AppData\Local\Temp\6_Offer_11.exe C:\Users\Dirk\AppData\Local\Temp\avgnt.exe C:\Users\Dirk\AppData\Local\Temp\BackupSetup.exe C:\Users\Dirk\AppData\Local\Temp\comver.dll C:\Users\Dirk\AppData\Local\Temp\instract.exe C:\Users\Dirk\AppData\Local\Temp\nsbA7C9.exe C:\Users\Dirk\AppData\Local\Temp\nsgFC04.exe C:\Users\Dirk\AppData\Local\Temp\nsl9DF7.exe C:\Users\Dirk\AppData\Local\Temp\nslA2D8.exe C:\Users\Dirk\AppData\Local\Temp\nsmDF4A.exe C:\Users\Dirk\AppData\Local\Temp\nsr124.exe C:\Users\Dirk\AppData\Local\Temp\nsw5D6.exe C:\Users\Dirk\AppData\Local\Temp\SearchProtectINT.exe C:\Users\Dirk\AppData\Local\Temp\sonarinst.exe C:\Users\Luca\AppData\Local\Temp\avgnt.exe C:\Users\Luca\AppData\Local\Temp\vlc-2.1.3-win32.exe ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== Restore Points ========================= Restore point made on: 2014-06-27 13:55:12 Restore point made on: 2014-07-01 14:35:34 Restore point made on: 2014-07-04 20:45:44 Restore point made on: 2014-07-08 08:27:53 Restore point made on: 2014-07-10 11:57:48 Restore point made on: 2014-07-20 17:31:45 Restore point made on: 2014-07-25 08:19:21 Restore point made on: 2014-07-29 08:41:36 Restore point made on: 2014-07-30 08:05:49 Restore point made on: 2014-08-01 10:40:52 Restore point made on: 2014-08-17 17:02:50 Restore point made on: 2014-08-17 20:15:44 Restore point made on: 2014-08-17 21:36:33 Restore point made on: 2014-08-19 06:43:02 Restore point made on: 2014-08-21 11:19:46 Restore point made on: 2014-08-22 13:18:16 Restore point made on: 2014-08-26 14:12:48 Restore point made on: 2014-08-28 14:21:46 Restore point made on: 2014-09-02 16:10:37 ==================== BCD ================================ Windows-Start-Manager --------------------- Bezeichner {bootmgr} device partition=Y: description Windows Boot Manager locale de-DE inherit {globalsettings} default {default} resumeobject {4ce375f1-3d17-11e1-bc5e-86918ed0c13b} displayorder {default} toolsdisplayorder {memdiag} timeout 0 Windows-Startladeprogramm ------------------------- Bezeichner {default} device partition=C: path \Windows\system32\winload.exe description Windows 7 locale de-DE inherit {bootloadersettings} recoverysequence {current} recoveryenabled Yes osdevice partition=C: systemroot \Windows resumeobject {4ce375f1-3d17-11e1-bc5e-86918ed0c13b} nx OptIn safeboot Minimal Windows-Startladeprogramm ------------------------- Bezeichner {current} device ramdisk=[C:]\Recovery\4ce375f3-3d17-11e1-bc5e-86918ed0c13b\Winre.wim,{4ce375f4-3d17-11e1-bc5e-86918ed0c13b} path \windows\system32\winload.exe description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\4ce375f3-3d17-11e1-bc5e-86918ed0c13b\Winre.wim,{4ce375f4-3d17-11e1-bc5e-86918ed0c13b} systemroot \windows nx OptIn winpe Yes Wiederaufnahme aus dem Ruhezustand ---------------------------------- Bezeichner {4ce375f1-3d17-11e1-bc5e-86918ed0c13b} device partition=C: path \Windows\system32\winresume.exe description Windows Resume Application locale de-DE inherit {resumeloadersettings} filedevice partition=C: filepath \hiberfil.sys debugoptionenabled No Windows-Speichertestprogramm ---------------------------- Bezeichner {memdiag} device partition=Y: path \boot\memtest.exe description Windows-Speicherdiagnose locale de-DE inherit {globalsettings} badmemoryaccess Yes EMS-Einstellungen ----------------- Bezeichner {emssettings} bootems Yes Debuggereinstellungen --------------------- Bezeichner {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM-Defekte ----------- Bezeichner {badmemory} Globale Einstellungen --------------------- Bezeichner {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Startladeprogramm-Einstellungen ------------------------------- Bezeichner {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisoreinstellungen ------------------- Bezeichner {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Einstellungen zur Ladeprogrammfortsetzung ----------------------------------------- Bezeichner {resumeloadersettings} inherit {globalsettings} Ger„teoptionen -------------- Bezeichner {4ce375f4-3d17-11e1-bc5e-86918ed0c13b} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\4ce375f3-3d17-11e1-bc5e-86918ed0c13b\boot.sdi ==================== Memory info =========================== Percentage of memory in use: 10% Total physical RAM: 8173.22 MB Available physical RAM: 7290.12 MB Total Pagefile: 8171.42 MB Available Pagefile: 7280.64 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Drives ================================ Drive c: (SYSTEM_500GB) (Fixed) (Total:465.66 GB) (Free:79.58 GB) NTFS Drive f: () (Removable) (Total:0.46 GB) (Free:0.46 GB) FAT Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 6D6CA26F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 471 MB) (Disk ID: 73696420) No partition Table on disk 1. LastRegBack: 2014-08-29 18:18 ==================== End Of Log ============================ |
07.09.2014, 20:38 | #2 |
/// the machine /// TB-Ausbilder | PC bootet in safemode und fährt dann runter hi,
__________________Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter GroupPolicy: Group Policy on Chrome detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-3000299772-3109549842-2761917205-1002\User: Group Policy restriction detected <======= ATTENTION S2 70e6ca8c; c:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll [191128 2013-11-21] ()
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.
__________________ |
07.09.2014, 20:59 | #3 |
| PC bootet in safemode und fährt dann runter Hallo, anbei die Fixlog.txt
__________________Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-09-2014 Ran by SYSTEM at 2014-09-07 22:55:25 Run:1 Running from F:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** GroupPolicy: Group Policy on Chrome detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-3000299772-3109549842-2761917205-1002\User: Group Policy restriction detected <======= ATTENTION S2 70e6ca8c; c:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll [191128 2013-11-21] () ***************** C:\Windows\System32\GroupPolicy\Machine => Moved successfully. C:\Windows\System32\GroupPolicy\GPT.ini => Moved successfully. C:\Windows\System32\GroupPolicyUsers\S-1-5-21-3000299772-3109549842-2761917205-1002\User => Moved successfully. 70e6ca8c => Service deleted successfully. ==== End of Fixlog ==== |
08.09.2014, 18:25 | #4 |
/// the machine /// TB-Ausbilder | PC bootet in safemode und fährt dann runter Besser?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.09.2014, 20:12 | #5 |
| PC bootet in safemode und fährt dann runter Hallo, leider nein. VG, Dirk |
09.09.2014, 20:32 | #6 |
/// the machine /// TB-Ausbilder | PC bootet in safemode und fährt dann runter Systemwiederherstellung schon versucht?
__________________ --> PC bootet in safemode und fährt dann runter |
09.09.2014, 20:44 | #7 |
| PC bootet in safemode und fährt dann runter Ja, habe älteren Wiederherstellungspunkt geladen. Leider ohne Erfolg. |
10.09.2014, 17:31 | #8 |
/// the machine /// TB-Ausbilder | PC bootet in safemode und fährt dann runter Kannst Du bei FRST in der Recovery nen Haken bei BCD setzen?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.09.2014, 18:08 | #9 |
| PC bootet in safemode und fährt dann runter Hallo, ja habe ich gemacht. Hier die log: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-09-2014 Ran by SYSTEM on MININT-H10MIVF on 10-09-2014 20:04:26 Running from F:\ Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12666984 2011-08-09] (Realtek Semiconductor) HKLM\...\Run: [Cm106Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190472 2009-09-17] (Logitech Inc.) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation) HKLM-x32\...\Run: [ChicoSys] => C:\Windows\SysWOW64\cc32\webtmr.exe [6484352 2009-07-14] (Salfeld Computer) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3816784 2014-07-21] (LogMeIn Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [161584 2014-08-04] (Avira Operations GmbH & Co. KG) HKLM\...\RunOnce: [*Restore] => C:\Windows\system32\rstrui.exe [296960 2010-11-21] (Microsoft Corporation) HKU\Dirk\...\Run: [CCWinTray] => C:\Windows\tray\wintmr.exe [6864256 2009-07-14] (Salfeld Computer) HKU\Dirk\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\Dirk\...\Policies\system: [DisableLockWorkstation] 0 HKU\Dirk\...\Policies\system: [DisableClock] 0 HKU\Dirk\...\Policies\system: [LogonHoursAction] 2 HKU\Dirk\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Dirk\...\Policies\Explorer: [NoControlPanel] 0 HKU\Dirk\...\Policies\Explorer: [NoFind] 0 HKU\Luca\...\Policies\system: [DisableClock] 1 HKU\Luca\...\Policies\system: [DisableLockWorkstation] 0 HKU\Luca\...\Policies\system: [LogonHoursAction] 2 HKU\Luca\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Luca\...\Policies\Explorer: [NoControlPanel] 0 HKU\Luca\...\Policies\Explorer: [NoSaveSettings] 0 HKU\Luca\...\Policies\Explorer: [NoFind] 0 AppInit_DLLs: c:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL => c:\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll [4139336 2013-11-21] () Startup: C:\Users\Dirk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (No File) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-3000299772-3109549842-2761917205-1002\User: Group Policy restriction detected <======= ATTENTION ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 70e6ca8c; c:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll [191128 2013-11-21] () S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-17] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-17] (Avira Operations GmbH & Co. KG) S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG) S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36392 2014-03-14] (Just Develop It) S2 ksupmgr; C:\Windows\SysWOW64\ksupmgr.exe [765592 2010-08-25] (Salfeld Computer) S2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-07-16] (LogMeIn, Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) S2 MgAssistService; C:\Program Files (x86)\Mobogenie\MgAssist.exe [70848 2014-04-08] () S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation) S2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-06-28] () S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-26] () S2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2144056 2013-10-22] (TuneUp Software) S2 VOsrv; C:\Users\Dirk\AppData\Roaming\VOPackage\VOsrv.exe [353792 2014-02-25] () S4 OtShotUpdateService; C:\Program Files (x86)\OtShot\OtshotUpdateServiceEx.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-01-14] () S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-26] (Avira Operations GmbH & Co. KG) S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG) S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-01-14] () S2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation) S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) S3 StarOpen; No ImagePath S3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-12-12] (TuneUp Software) S3 USBMULCD; C:\Windows\System32\drivers\CM10664.sys [1307648 2011-03-31] (C-Media Electronics Inc) S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-07 18:34 - 2014-09-10 20:04 - 00000000 ____D () C:\FRST 2014-09-07 12:44 - 2014-09-07 12:47 - 00000000 ___HD () C:\System Shared 2014-09-07 12:44 - 2014-09-07 12:44 - 00000000 ___HD () C:\Device 2014-08-30 09:35 - 2014-08-30 09:37 - 17088592 _____ (Electronic Arts, Inc.) C:\Users\Luca\Downloads\OriginThinSetup.exe 2014-08-29 18:24 - 2014-08-29 18:24 - 01101648 _____ () C:\Users\Luca\Downloads\LogMeIn Hamachi - CHIP-Installer.exe 2014-08-29 17:27 - 2013-03-04 05:34 - 01808510 _____ () C:\Users\Luca\Downloads\TekkitLite.jar 2014-08-29 17:27 - 2013-03-04 05:33 - 02061638 _____ () C:\Users\Luca\Downloads\minecraft_server.jar 2014-08-29 17:27 - 2013-01-12 04:40 - 00000000 ____D () C:\Users\Luca\Downloads\mods 2014-08-29 17:27 - 2013-01-12 04:39 - 00000000 ____D () C:\Users\Luca\Downloads\coremods 2014-08-29 17:27 - 2013-01-04 08:42 - 00000555 _____ () C:\Users\Luca\Downloads\server.properties 2014-08-29 17:27 - 2013-01-04 08:20 - 00000054 _____ () C:\Users\Luca\Downloads\launch.sh 2014-08-29 17:27 - 2013-01-04 08:20 - 00000051 _____ () C:\Users\Luca\Downloads\launch.bat 2014-08-29 17:17 - 2014-08-29 17:22 - 00001376 _____ () C:\Users\Luca\Desktop\TechnicLauncher - Verknüpfung.lnk 2014-08-29 17:17 - 2014-08-29 17:19 - 00000000 ____D () C:\Users\Luca\Documents\Tekkit 2014-08-29 17:14 - 2014-08-29 17:16 - 20827501 _____ () C:\Users\Luca\Downloads\Tekkit_Lite_Server_0.6.5.zip 2014-08-28 16:44 - 2014-08-28 16:44 - 01397992 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.5.0_148.exe 2014-08-28 14:01 - 2014-08-23 03:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll 2014-08-28 14:01 - 2014-08-23 02:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-28 14:01 - 2014-08-23 01:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2014-08-27 16:27 - 2014-08-27 16:27 - 02249144 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.4.0_147.exe 2014-08-21 11:20 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2014-08-21 11:20 - 2014-05-14 17:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2014-08-21 11:20 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-08-21 11:20 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2014-08-21 11:20 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll 2014-08-21 11:20 - 2014-05-14 17:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll 2014-08-21 11:20 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2014-08-21 11:20 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2014-08-21 11:20 - 2014-05-14 17:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2014-08-21 11:20 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-08-21 11:19 - 2014-05-14 08:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2014-08-21 11:19 - 2014-05-14 08:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-08-21 11:19 - 2014-05-14 08:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2014-08-21 11:19 - 2014-05-14 08:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-08-18 13:08 - 2014-08-18 13:09 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8(1).exe 2014-08-18 13:01 - 2014-08-18 13:09 - 00001033 _____ () C:\Users\Dirk\Desktop\FlyVPN.lnk 2014-08-18 13:01 - 2014-08-18 13:09 - 00000000 ____D () C:\Program Files (x86)\FlyVPN 2014-08-18 13:01 - 2014-08-18 13:01 - 00000000 ____D () C:\ProgramData\FlyVPN 2014-08-18 13:00 - 2014-08-18 13:00 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8.exe 2014-08-18 12:56 - 2014-08-22 17:09 - 00001149 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-17 21:37 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\System32\icardres.dll 2014-08-17 21:37 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-17 21:37 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-17 21:37 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\System32\TsWpfWrp.exe 2014-08-17 21:37 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\System32\icardagt.exe 2014-08-17 21:37 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\System32\infocardapi.dll 2014-08-17 21:37 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-17 21:37 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-17 18:24 - 2014-08-17 19:36 - 620143037 _____ () C:\Users\Luca\Downloads\mb_warband_setup_1160.exe 2014-08-17 17:20 - 2014-08-01 00:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2014-08-17 17:20 - 2014-08-01 00:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-17 17:20 - 2014-07-25 15:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2014-08-17 17:20 - 2014-07-25 15:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2014-08-17 17:20 - 2014-07-25 15:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll 2014-08-17 17:20 - 2014-07-25 14:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-17 17:20 - 2014-07-25 14:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2014-08-17 17:20 - 2014-07-25 14:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2014-08-17 17:20 - 2014-07-25 14:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll 2014-08-17 17:20 - 2014-07-25 14:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2014-08-17 17:20 - 2014-07-25 14:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll 2014-08-17 17:20 - 2014-07-25 14:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2014-08-17 17:20 - 2014-07-25 14:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2014-08-17 17:20 - 2014-07-25 14:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-17 17:20 - 2014-07-25 14:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2014-08-17 17:20 - 2014-07-25 14:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2014-08-17 17:20 - 2014-07-25 14:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe 2014-08-17 17:20 - 2014-07-25 13:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll 2014-08-17 17:20 - 2014-07-25 13:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2014-08-17 17:20 - 2014-07-25 13:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2014-08-17 17:20 - 2014-07-25 13:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-17 17:20 - 2014-07-25 13:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-17 17:20 - 2014-07-25 13:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-17 17:20 - 2014-07-25 13:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-17 17:20 - 2014-07-25 13:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2014-08-17 17:20 - 2014-07-25 13:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll 2014-08-17 17:20 - 2014-07-25 13:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-17 17:20 - 2014-07-25 13:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll 2014-08-17 17:20 - 2014-07-25 13:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-17 17:20 - 2014-07-25 13:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2014-08-17 17:20 - 2014-07-25 13:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-17 17:20 - 2014-07-25 13:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-17 17:20 - 2014-07-25 13:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2014-08-17 17:20 - 2014-07-25 13:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-17 17:20 - 2014-07-25 13:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-17 17:20 - 2014-07-25 13:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-17 17:20 - 2014-07-25 12:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-17 17:20 - 2014-07-25 12:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2014-08-17 17:20 - 2014-07-25 12:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-17 17:20 - 2014-07-25 12:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2014-08-17 17:20 - 2014-07-25 12:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2014-08-17 17:20 - 2014-07-25 12:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2014-08-17 17:20 - 2014-07-25 12:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-17 17:20 - 2014-07-25 12:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-17 17:20 - 2014-07-25 12:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-17 17:20 - 2014-07-25 12:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2014-08-17 17:20 - 2014-07-25 12:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-17 17:20 - 2014-07-25 12:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-17 17:20 - 2014-07-25 12:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-17 17:20 - 2014-07-25 12:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-17 17:20 - 2014-07-25 11:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2014-08-17 17:20 - 2014-07-25 11:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2014-08-17 17:20 - 2014-07-25 11:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2014-08-17 17:20 - 2014-07-25 11:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-17 17:20 - 2014-07-25 11:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-17 17:20 - 2014-07-25 11:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-17 17:16 - 2014-07-16 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll 2014-08-17 17:16 - 2014-07-16 03:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-17 17:16 - 2014-06-25 03:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll 2014-08-17 17:16 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-17 17:16 - 2014-06-16 03:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2014-08-17 17:16 - 2014-06-03 11:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\System32\msi.dll 2014-08-17 17:16 - 2014-06-03 11:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll 2014-08-17 17:16 - 2014-06-03 11:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\System32\msihnd.dll 2014-08-17 17:16 - 2014-06-03 11:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\System32\consent.exe 2014-08-17 17:16 - 2014-06-03 10:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-17 17:16 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-17 17:16 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-17 17:11 - 2014-07-14 03:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll 2014-08-17 17:11 - 2014-07-14 02:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-10 20:04 - 2014-09-07 18:34 - 00000000 ____D () C:\FRST 2014-09-09 22:45 - 2014-07-22 11:15 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi 2014-09-09 22:45 - 2013-11-07 20:53 - 00000000 ____D () C:\Windows\pss 2014-09-09 22:45 - 2013-10-01 13:10 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-09-09 22:45 - 2013-03-24 10:42 - 00000000 ____D () C:\Users\Luca\AppData\Roaming\Skype 2014-09-09 22:45 - 2012-07-11 18:42 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-09-09 22:45 - 2012-02-19 11:48 - 00000000 ____D () C:\Users\Luca\AppData\Local\LogMeIn Hamachi 2014-09-09 22:45 - 2012-01-14 00:35 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-09-09 22:45 - 2012-01-13 23:02 - 00000000 ____D () C:\users\Luca 2014-09-09 22:45 - 2012-01-12 13:51 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-09-09 22:45 - 2012-01-12 13:26 - 00000000 ____D () C:\users\Dirk 2014-09-09 22:45 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\System32\GroupPolicy 2014-09-09 22:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\System32\NDF 2014-09-09 22:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-09-09 22:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2014-09-09 22:00 - 2012-01-22 17:47 - 00000016 _____ () C:\Windows\SysWOW64\excltmp~.dat 2014-09-07 13:11 - 2010-11-21 08:00 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-09-07 12:47 - 2014-09-07 12:44 - 00000000 ___HD () C:\System Shared 2014-09-07 12:44 - 2014-09-07 12:44 - 00000000 ___HD () C:\Device 2014-09-02 16:09 - 2012-01-12 13:25 - 02009606 _____ () C:\Windows\WindowsUpdate.log 2014-09-02 16:05 - 2012-11-02 18:25 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-02 16:03 - 2013-09-30 15:07 - 00000000 ____D () C:\ProgramData\Origin 2014-09-02 16:02 - 2013-09-30 15:07 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-09-02 16:01 - 2009-07-14 05:51 - 00211254 _____ () C:\Windows\setupact.log 2014-09-02 16:00 - 2012-01-13 23:52 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-09-02 16:00 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-01 16:39 - 2013-08-22 17:35 - 00000282 _____ () C:\Windows\Tasks\DSite.job 2014-09-01 16:35 - 2013-08-22 17:35 - 00000288 _____ () C:\Windows\Tasks\MetaCrawler.job 2014-09-01 15:55 - 2012-01-13 23:52 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-09-01 15:35 - 2013-08-22 18:35 - 00000204 _____ () C:\Users\Luca\AppData\Roaming\WB.CFG 2014-09-01 15:10 - 2013-09-30 15:59 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-09-01 15:03 - 2009-07-14 05:45 - 00022512 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-01 15:03 - 2009-07-14 05:45 - 00022512 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-31 16:58 - 2013-09-30 15:59 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-08-31 08:41 - 2014-04-25 09:24 - 00000000 ____D () C:\Users\Dirk\AppData\Roaming\Systweak 2014-08-30 09:37 - 2014-08-30 09:35 - 17088592 _____ (Electronic Arts, Inc.) C:\Users\Luca\Downloads\OriginThinSetup.exe 2014-08-29 20:00 - 2013-03-10 09:53 - 00000000 ____D () C:\Users\Luca\AppData\Roaming\.minecraft 2014-08-29 18:35 - 2012-02-19 19:28 - 00000000 ____D () C:\Users\Dirk\AppData\Local\LogMeIn Hamachi 2014-08-29 18:24 - 2014-08-29 18:24 - 01101648 _____ () C:\Users\Luca\Downloads\LogMeIn Hamachi - CHIP-Installer.exe 2014-08-29 17:29 - 2012-07-08 10:02 - 00003072 ___SH () C:\Users\Luca\Thumbs.db 2014-08-29 17:22 - 2014-08-29 17:17 - 00001376 _____ () C:\Users\Luca\Desktop\TechnicLauncher - Verknüpfung.lnk 2014-08-29 17:19 - 2014-08-29 17:17 - 00000000 ____D () C:\Users\Luca\Documents\Tekkit 2014-08-29 17:16 - 2014-08-29 17:14 - 20827501 _____ () C:\Users\Luca\Downloads\Tekkit_Lite_Server_0.6.5.zip 2014-08-29 13:20 - 2013-04-19 16:37 - 00000000 ____D () C:\Users\Luca\AppData\Roaming\.technic 2014-08-29 13:03 - 2010-11-21 04:47 - 00685762 _____ () C:\Windows\PFRO.log 2014-08-28 16:44 - 2014-08-28 16:44 - 01397992 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.5.0_148.exe 2014-08-28 16:34 - 2009-07-14 05:45 - 00414096 _____ () C:\Windows\System32\FNTCACHE.DAT 2014-08-27 16:27 - 2014-08-27 16:27 - 02249144 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.4.0_147.exe 2014-08-23 03:07 - 2014-08-28 14:01 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll 2014-08-23 02:45 - 2014-08-28 14:01 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-23 01:59 - 2014-08-28 14:01 - 03163648 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2014-08-22 17:40 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-08-22 17:09 - 2014-08-18 12:56 - 00001149 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-22 17:09 - 2013-12-26 03:56 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-22 17:09 - 2013-05-24 09:48 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-19 06:45 - 2012-01-12 14:18 - 00309819 _____ () C:\Windows\DirectX.log 2014-08-18 13:09 - 2014-08-18 13:08 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8(1).exe 2014-08-18 13:09 - 2014-08-18 13:01 - 00001033 _____ () C:\Users\Dirk\Desktop\FlyVPN.lnk 2014-08-18 13:09 - 2014-08-18 13:01 - 00000000 ____D () C:\Program Files (x86)\FlyVPN 2014-08-18 13:01 - 2014-08-18 13:01 - 00000000 ____D () C:\ProgramData\FlyVPN 2014-08-18 13:00 - 2014-08-18 13:00 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8.exe 2014-08-18 12:59 - 2012-11-02 18:25 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-08-18 12:59 - 2012-11-02 18:25 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-08-18 12:59 - 2012-01-12 13:46 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-08-18 12:56 - 2013-05-24 09:48 - 00000000 ____D () C:\ProgramData\Avira 2014-08-18 12:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-17 21:51 - 2012-01-15 17:47 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-17 21:44 - 2013-08-18 11:38 - 00000000 ____D () C:\Windows\System32\MRT 2014-08-17 21:42 - 2012-01-12 15:21 - 99218768 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2014-08-17 20:16 - 2012-05-28 20:44 - 00001156 _____ () C:\Users\Dirk\Desktop\Mount&Blade Warband.lnk 2014-08-17 20:16 - 2012-01-21 15:58 - 00001156 _____ () C:\Users\Luca\Desktop\Mount&Blade Warband.lnk 2014-08-17 20:15 - 2012-01-21 15:58 - 00000000 ____D () C:\Program Files (x86)\Mount&Blade Warband 2014-08-17 19:36 - 2014-08-17 18:24 - 620143037 _____ () C:\Users\Luca\Downloads\mb_warband_setup_1160.exe 2014-08-17 18:00 - 2013-10-01 18:39 - 00297088 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-08-17 17:47 - 2013-03-15 18:32 - 00000000 ____D () C:\ProgramData\Skype Some content of TEMP: ==================== C:\Users\Dirk\AppData\Local\Temp\6_Offer_11.exe C:\Users\Dirk\AppData\Local\Temp\avgnt.exe C:\Users\Dirk\AppData\Local\Temp\BackupSetup.exe C:\Users\Dirk\AppData\Local\Temp\comver.dll C:\Users\Dirk\AppData\Local\Temp\instract.exe C:\Users\Dirk\AppData\Local\Temp\nsbA7C9.exe C:\Users\Dirk\AppData\Local\Temp\nsgFC04.exe C:\Users\Dirk\AppData\Local\Temp\nsl9DF7.exe C:\Users\Dirk\AppData\Local\Temp\nslA2D8.exe C:\Users\Dirk\AppData\Local\Temp\nsmDF4A.exe C:\Users\Dirk\AppData\Local\Temp\nsr124.exe C:\Users\Dirk\AppData\Local\Temp\nsw5D6.exe C:\Users\Dirk\AppData\Local\Temp\SearchProtectINT.exe C:\Users\Dirk\AppData\Local\Temp\sonarinst.exe C:\Users\Luca\AppData\Local\Temp\avgnt.exe C:\Users\Luca\AppData\Local\Temp\vlc-2.1.3-win32.exe ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== Restore Points ========================= Restore point made on: 2014-06-27 13:55:12 Restore point made on: 2014-07-01 14:35:34 Restore point made on: 2014-07-04 20:45:44 Restore point made on: 2014-07-08 08:27:53 Restore point made on: 2014-07-10 11:57:48 Restore point made on: 2014-07-20 17:31:45 Restore point made on: 2014-07-25 08:19:21 Restore point made on: 2014-07-29 08:41:36 Restore point made on: 2014-07-30 08:05:49 Restore point made on: 2014-08-01 10:40:52 Restore point made on: 2014-08-17 17:02:50 Restore point made on: 2014-08-17 20:15:44 Restore point made on: 2014-08-17 21:36:33 Restore point made on: 2014-08-19 06:43:02 Restore point made on: 2014-08-21 11:19:46 Restore point made on: 2014-08-22 13:18:16 Restore point made on: 2014-08-26 14:12:48 Restore point made on: 2014-08-28 14:21:46 Restore point made on: 2014-09-02 16:10:37 ==================== BCD ================================ Windows-Start-Manager --------------------- Bezeichner {bootmgr} device partition=Y: description Windows Boot Manager locale de-DE inherit {globalsettings} default {default} resumeobject {4ce375f1-3d17-11e1-bc5e-86918ed0c13b} displayorder {default} toolsdisplayorder {memdiag} timeout 0 Windows-Startladeprogramm ------------------------- Bezeichner {default} device partition=C: path \Windows\system32\winload.exe description Windows 7 locale de-DE inherit {bootloadersettings} recoverysequence {current} recoveryenabled Yes osdevice partition=C: systemroot \Windows resumeobject {4ce375f1-3d17-11e1-bc5e-86918ed0c13b} nx OptIn safeboot Minimal Windows-Startladeprogramm ------------------------- Bezeichner {current} device ramdisk=[C:]\Recovery\4ce375f3-3d17-11e1-bc5e-86918ed0c13b\Winre.wim,{4ce375f4-3d17-11e1-bc5e-86918ed0c13b} path \windows\system32\winload.exe description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\4ce375f3-3d17-11e1-bc5e-86918ed0c13b\Winre.wim,{4ce375f4-3d17-11e1-bc5e-86918ed0c13b} systemroot \windows nx OptIn winpe Yes Wiederaufnahme aus dem Ruhezustand ---------------------------------- Bezeichner {4ce375f1-3d17-11e1-bc5e-86918ed0c13b} device partition=C: path \Windows\system32\winresume.exe description Windows Resume Application locale de-DE inherit {resumeloadersettings} filedevice partition=C: filepath \hiberfil.sys debugoptionenabled No Windows-Speichertestprogramm ---------------------------- Bezeichner {memdiag} device partition=Y: path \boot\memtest.exe description Windows-Speicherdiagnose locale de-DE inherit {globalsettings} badmemoryaccess Yes EMS-Einstellungen ----------------- Bezeichner {emssettings} bootems Yes Debuggereinstellungen --------------------- Bezeichner {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM-Defekte ----------- Bezeichner {badmemory} Globale Einstellungen --------------------- Bezeichner {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Startladeprogramm-Einstellungen ------------------------------- Bezeichner {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisoreinstellungen ------------------- Bezeichner {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Einstellungen zur Ladeprogrammfortsetzung ----------------------------------------- Bezeichner {resumeloadersettings} inherit {globalsettings} Ger„teoptionen -------------- Bezeichner {4ce375f4-3d17-11e1-bc5e-86918ed0c13b} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\4ce375f3-3d17-11e1-bc5e-86918ed0c13b\boot.sdi ==================== Memory info =========================== Percentage of memory in use: 10% Total physical RAM: 8173.22 MB Available physical RAM: 7276.79 MB Total Pagefile: 8171.42 MB Available Pagefile: 7266.02 MB Total Virtual: 8192 MB Available Virtual: 8191.89 MB ==================== Drives ================================ Drive c: (SYSTEM_500GB) (Fixed) (Total:465.66 GB) (Free:79.56 GB) NTFS Drive f: () (Removable) (Total:0.46 GB) (Free:0.46 GB) FAT Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 6D6CA26F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 471 MB) (Disk ID: 73696420) No partition Table on disk 1. LastRegBack: 2014-08-29 18:18 ==================== End Of Log ============================ |
11.09.2014, 11:19 | #10 |
/// the machine /// TB-Ausbilder | PC bootet in safemode und fährt dann runter Nochmal in den Reparaturmodus booten, in der Eingabeauforderung nicht FRST eingeben udn starten, sondern folgendes eingeben: bcdedit /deletevalue {default} safeboot Enter drücken. Reboot, versuch den Rechner normal zu starten.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.09.2014, 18:12 | #11 |
| PC bootet in safemode und fährt dann runter Hi, das war's. Jetzt startet er wieder. Spende ist erfolgt. Vielen Dank!! |
12.09.2014, 10:57 | #12 |
/// the machine /// TB-Ausbilder | PC bootet in safemode und fährt dann runter Bitte jetzt FRST vom Desktop aus, da is noch bissl Arbeit Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.09.2014, 17:04 | #13 |
| PC bootet in safemode und fährt dann runter Ok, hier nochmal das Ergebnis von FRST: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-09-2014 Ran by Luca at 2014-09-13 18:01:36 Running from C:\Users\Luca\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acronis*True*Image*Home 2011 (HKLM-x32\...\{04A3A6B0-8E19-49BB-82FF-65C5A55F917D}) (Version: 14.0.6696 - Acronis) Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.3.633 - Adobe Systems, Inc.) Age of Empires III - The WarChiefs (HKLM-x32\...\InstallShield_{1C08A24C-B168-407E-A826-68FAF5F20710}) (Version: 1.00.0000 - Microsoft Game Studios) Age of Empires III - The WarChiefs (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden Age of Empires III (HKLM-x32\...\InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}) (Version: 1.00.0000 - Microsoft Game Studios) Age of Empires III (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden AMD USB Filter Driver (x32 Version: 1.0.15.94 - Advanced Micro Devices, Inc.) Hidden ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.00.0000 - Ubisoft) Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Arctic Combat (HKLM-x32\...\{9C84DFF4-A98C-42d5-A09F-6985A05205B2}_is1) (Version: 1.0.0.1 - Webzen) Avira (HKLM-x32\...\{70e83cd8-4bd5-4039-ab5a-6b94a8abb641}) (Version: 1.1.21.25162 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.21.25162 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.6.570 - Avira) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.0.0.0 - Electronic Arts) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.3.2.3825 - Electronic Arts) Battlefield 4™ CTE (HKLM-x32\...\{551A08D1-B60E-4DED-9B67-C3B38258CCA3}) (Version: 1.0.2.13779 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.5.1 - EA Digital Illusions CE AB) Blobby Volley 2 Version 1.0 (HKLM-x32\...\Blobby Volley 2 Version 1.0_is1) (Version: - ) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Call of Duty: Modern Warfare 2 - Multiplayer (HKLM-x32\...\Steam App 10190) (Version: - Infinity Ward) Call of Duty: Modern Warfare 2 (HKLM-x32\...\Steam App 10180) (Version: - Infinity Ward) Chivalry: Medieval Warfare (HKLM-x32\...\Steam App 219640) (Version: - ) Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{650DE870-ECA3-4E63-8D77-778512BE5D4C}) (Version: - Microsoft) Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.29.55 - Electronic Arts) easyTEACHER Version 10.3.R178.MOFA (HKCU\...\easyTEACHER_is1) (Version: 10.3.R178.MOFA - admigro media GmbH) Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.104 - Etron Technology) Etron USB3.0 Host Controller (x32 Version: 0.104 - Etron Technology) Hidden Farming Simulator 2011 (HKLM-x32\...\Steam App 90200) (Version: - GIANTS Software) FlexiiblEShopper (HKLM-x32\...\{A30F3754-C0DC-8242-F3A9-52B360AE9798}) (Version: - FFLexIibleShhoppeer) Flight Simulator X (HKLM-x32\...\RTMshadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version: - ) Flight Simulator X Service Pack 1 (HKLM-x32\...\SP1shadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version: - ) FlyVPN (HKLM-x32\...\FlyVPN) (Version: 3.0.1.8 - FlyVPN) GameSpy Arcade (HKLM-x32\...\GameSpy Arcade) (Version: - ) Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Facepunch Studios) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 31.0.1650.63 - Google Inc.) Google Earth (HKLM-x32\...\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}) (Version: 6.1.0.5001 - Google) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.4805.320 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden greatsavIng (HKLM-x32\...\{439763FF-59EC-FF1D-B0B5-CB9E213A7A5C}) (Version: - greeatsaVing) Hotspot Shield 2.84 (HKCU\...\HotspotShield) (Version: 2.84 - AnchorFree) Iminent (x32 Version: 6.20.11.0 - Iminent) Hidden <==== ATTENTION IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle) Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden Just Flight - 757 Captain FSX (HKLM-x32\...\{B2279642-0349-4C26-8CA3-D79775F43F4C}) (Version: 1.00.000 - Just Flight) Just Flight - C-130 Hercules FSX (HKLM-x32\...\{3D42025D-A83A-42A3-B2E2-95CD5F74ED00}) (Version: 1.00.000 - Just Flight) Just Flight - World Airports 3 FSX (HKLM-x32\...\{8A265EE0-9527-4807-B946-D79C7364774B}) (Version: 1.00.000 - Just Flight) Kindersicherung 2013 (HKLM-x32\...\Kindersicherung_is1) (Version: - Salfeld Computer GmbH) Logitech Gaming Software 5.08 (HKLM\...\{96F1BA99-300F-4DD5-A26B-788EF63B53B1}) (Version: 5.08.146 - Logitech) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.236 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.236 - LogMeIn, Inc.) Hidden MediaMonkey 4.0 (HKLM-x32\...\MediaMonkey_is1) (Version: 4.0 - Ventis Media Inc.) MEDUSA NX USB 5.1 Gaming Headset (HKLM\...\C-Media CM106 Like Sound Driver) (Version: - ) MegaStore Game Controller (Ver. 3.0) (HKLM-x32\...\InstallShield_{D1A6B95D-4A95-4E33-8F5A-7A79F383A31B}) (Version: 3.0 - MegaStore Holdings Ltd.) MegaStore Game Controller (Ver. 3.0) (x32 Version: 3.0 - MegaStore Holdings Ltd.) Hidden metaCrawler (HKLM-x32\...\metaCrawler) (Version: - metaCrawler) <==== ATTENTION Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Flight Simulator X (x32 Version: 10.0.60905 - Microsoft Game Studios) Hidden Microsoft Flight Simulator X: Acceleration (HKLM-x32\...\FlightSim_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version: 10.0.61637.0 - Microsoft Game Studios) Microsoft Flight Simulator X: Acceleration (x32 Version: 10.0.61637.0 - Microsoft Game Studios) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mobogenie (HKLM-x32\...\Mobogenie) (Version: - Mobogenie.com) <==== ATTENTION Mount&Blade Warband (HKLM-x32\...\Mount&Blade Warband) (Version: - ) Mount&Blade With Fire and Sword (HKLM-x32\...\Mount&Blade With Fire and Sword) (Version: - ) Mount&Blade: Warband - Napoleonic Wars (HKLM-x32\...\Mount&Blade: Warband - Napoleonic Wars) (Version: - ) MountMusket Battalion (HKLM-x32\...\{8AF7479C-B28D-4BFF-867B-4755DE019259}_is1) (Version: 0.4.2 - MountMusket Battalion Team) Mozilla Firefox 32.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0.1 (x86 de)) (Version: 32.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP2 Parser und SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) MyPC Backup (HKLM\...\MyPC Backup) (Version: - JDi Backup Ltd) <==== ATTENTION Napoleon: Total War (HKLM-x32\...\Steam App 34030) (Version: - The Creative Assembly) NVIDIA 3D Vision Controller-Treiber 331.93 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.93 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 331.93 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.93 - NVIDIA Corporation) NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 331.93 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.93 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.157.1165 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation) NVIDIA ShadowPlay 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3193 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 331.93 (Version: 331.93 - NVIDIA Corporation) Hidden NVIDIA Update 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 15.3.33 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.23 (Version: 1.2.23 - NVIDIA Corporation) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Optimizer Pro v3.2 (HKLM-x32\...\Optimizer Pro_is1) (Version: - PC Utilities Software Limited) <==== ATTENTION Origin (HKLM-x32\...\Origin) (Version: 9.4.22.2815 - Electronic Arts, Inc.) PT Boats: South Gambit (HKLM-x32\...\PT Boats: South Gambit_is1) (Version: Relise - Akella) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Pure (HKLM-x32\...\{FF3C203A-2F19-43A2-9C7C-EC1B5A0FC873}) (Version: 1.0 - Disney Interactive Studios) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.38.113.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6433 - Realtek Semiconductor Corp.) Sauerbraten (HKLM-x32\...\Sauerbraten) (Version: - ) saver boox (HKLM-x32\...\{CA8C94BE-9F47-1B2E-90F8-D8C07119BD96}) (Version: - saver box) <==== ATTENTION Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.) SnagIt 7 (HKLM-x32\...\SnagIt7) (Version: 7.0 - TechSmith Corporation) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve) Stronghold (HKLM-x32\...\{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}) (Version: 1.20.0000 - Firefly Studios) Stronghold 2 (HKLM-x32\...\{16D2C649-CBA8-44EE-B730-12584667D487}) (Version: 1.40.1000 - Firefly Studios) Stronghold Crusader Extreme (HKLM-x32\...\{8C3727F2-8E37-49E4-820C-03B1677F53B6}) (Version: 1.20.0000 - Firefly Studios) Stronghold Legends (HKLM-x32\...\{66A405D2-BA14-4594-BF36-B3B544F0754E}) (Version: 1.20.0000 - Firefly Studios) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TableConveRter (HKLM-x32\...\{CEE99428-A50B-3829-A0F0-B9B52C222A9F}) (Version: - TabbloeCoonvertter) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.6 - TeamSpeak Systems GmbH) theHunter (remove only) (HKLM-x32\...\theHunter) (Version: - Expansive Worlds) Tomb Raider (HKLM-x32\...\Steam App 203160) (Version: - Crystal Dynamics) Total War: SHOGUN 2 (HKLM-x32\...\Steam App 34330) (Version: - The Creative Assembly) trivia (HKLM-x32\...\trivia) (Version: - logia Games) TuneUp Utilities 2012 (HKLM-x32\...\TuneUp Utilities 2012) (Version: 12.0.3600.151 - TuneUp Software) TuneUp Utilities 2012 (x32 Version: 12.0.3600.151 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.151 - TuneUp Software) Hidden Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Excel 2010 (KB2889836) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{9179FC17-97A8-4D98-9E09-05720AF5D44E}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B0D672F7-883E-4279-8E75-D97A5445AB46}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version: - Microsoft) Update for Zip Opener (HKCU\...\DSite) (Version: - ) <==== ATTENTION VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) VO Package (HKLM-x32\...\VOPackage) (Version: 1.0.0.0 - ) <==== ATTENTION VTrain (Vokabeltrainer) 5.2 (HKLM-x32\...\VTrain_is1) (Version: - Paul Rädle) War Thunder Launcher 1.0.1.195 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - 2012 Gaijin Entertainment Corporation) Warface Launcher (Beta) (HKLM-x32\...\{28D1723C-31C4-4A83-9799-DFFB3739026D}) (Version: 1.0.0 - Crytek GmbH) WEBZEN Browser Extension (HKLM-x32\...\{95723791-2C44-454B-9220-C65D47D70E9C}) (Version: 1.01.020 - WEBZEN) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinRAR 4.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.10.0 - win.rar GmbH) WinZip (HKLM-x32\...\WinZip) (Version: 8.1 (4331g) - WinZip Computing, Inc.) World of Tanks - Common Test (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812CT}_is1) (Version: - Wargaming.net) World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= Could not list Restore Points. Check "winmgmt" service or repair WMI. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ? Task: C:\Windows\Tasks\DSite.job => C:\Users\Luca\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ? Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ? Task: C:\Windows\Tasks\MetaCrawler.job => ? ==================== Loaded Modules (whitelisted) ============= 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2012-04-04 21:37 - 2012-01-09 19:44 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll 2014-04-25 10:26 - 2014-04-08 05:41 - 00748736 _____ () C:\Program Files (x86)\Mobogenie\DaemonProcess.exe 2013-12-17 21:07 - 2014-06-21 05:03 - 00014200 _____ () C:\Program Files (x86)\Origin Games\Battlefield 4\Engine.BuildInfo_Win64_retail.dll 2013-12-26 10:26 - 2014-09-13 17:18 - 00662016 _____ () C:\Users\Luca\AppData\Local\PunkBuster\BF4\pb\pbcl.d64 2013-12-26 10:26 - 2013-12-26 10:27 - 00055808 _____ () C:\Users\Luca\AppData\Local\PunkBuster\BF4\pb\pbag.d64 ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:373E1720 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ksupmgr => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ksupmgr => ""="Service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: OtShotUpdateService => 2 MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart ==================== Faulty Device Manager Devices ============= Name: Hamachi Network Interface #2 Description: Hamachi Network Interface Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: LogMeIn, Inc. Service: hamachi Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: TP-LINK 300Mbps Wireless N Adapter Description: TP-LINK 300Mbps Wireless N Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: TP-LINK Service: athr Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (09/13/2014 04:27:10 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 14102 Error: (09/13/2014 04:27:10 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 14102 Error: (09/13/2014 04:27:10 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (09/13/2014 04:27:09 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 13104 Error: (09/13/2014 04:27:09 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 13104 Error: (09/13/2014 04:27:09 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (09/13/2014 04:27:08 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 12105 Error: (09/13/2014 04:27:08 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 12105 Error: (09/13/2014 04:27:08 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (09/13/2014 04:27:07 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 11107 System errors: ============= Error: (09/13/2014 03:39:13 AM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80070422 Error: (09/13/2014 03:36:14 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Adobe Acrobat Update Service erreicht. Error: (09/12/2014 00:21:36 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80070422 Error: (09/12/2014 00:20:43 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "LogMeIn Hamachi Tunneling Engine" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (09/12/2014 00:20:19 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80070422 Error: (09/12/2014 00:19:24 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Avira Service Host erreicht. Error: (09/11/2014 08:11:51 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80070422 Error: (09/11/2014 08:11:07 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80070422 Error: (09/11/2014 08:08:01 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (09/11/2014 08:07:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Microsoft Office Sessions: ========================= Error: (09/13/2014 04:27:10 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 14102 Error: (09/13/2014 04:27:10 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 14102 Error: (09/13/2014 04:27:10 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (09/13/2014 04:27:09 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 13104 Error: (09/13/2014 04:27:09 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 13104 Error: (09/13/2014 04:27:09 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (09/13/2014 04:27:08 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 12105 Error: (09/13/2014 04:27:08 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 12105 Error: (09/13/2014 04:27:08 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (09/13/2014 04:27:07 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 11107 CodeIntegrity Errors: =================================== Date: 2014-09-13 06:43:07.696 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\wdrvtd64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-01 16:04:24.908 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\wdrvtd64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-23 10:04:28.271 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\wdrvtd64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-21 13:57:17.009 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\wdrvtd64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-10 10:21:17.848 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\wdrvtd64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-09 10:15:45.623 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\wdrvtd64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-02 20:52:45.111 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\wdrvtd64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-02 11:04:56.743 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\wdrvtd64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-02 11:04:56.743 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\wdrvtd64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-02 11:04:56.743 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\wdrvtd64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: AMD FX(tm)-4100 Quad-Core Processor Percentage of memory in use: 58% Total physical RAM: 8173.22 MB Available physical RAM: 3430.46 MB Total Pagefile: 16344.63 MB Available Pagefile: 10371.61 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (SYSTEM_500GB) (Fixed) (Total:465.66 GB) (Free:71.9 GB) NTFS Drive e: () (Removable) (Total:0.46 GB) (Free:0.46 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 1 (Size: 471 MB) (Disk ID: 73696420) No partition Table on disk 1. ==================== End Of Log ============================ |
14.09.2014, 12:19 | #14 |
/// the machine /// TB-Ausbilder | PC bootet in safemode und fährt dann runter Das ist aber nur die Addition.txt
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.09.2014, 16:15 | #15 |
| PC bootet in safemode und fährt dann runter Ach so, ich glaub das ist die Richtige: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014 Ran by Luca (ATTENTION: The logged in user is not administrator) on LUCA-PC on 13-09-2014 17:59:13 Running from C:\Users\Luca\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (WinZip Computing, Inc. and H.C. Top Systems B.V.) C:\Program Files (x86)\WinZip\WZQKPICK.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe () C:\Program Files (x86)\Mobogenie\DaemonProcess.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (EA Digital Illusions CE AB) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12666984 2011-08-09] (Realtek Semiconductor) HKLM\...\Run: [Cm106Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190472 2009-09-17] (Logitech Inc.) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation) HKLM-x32\...\Run: [ChicoSys] => C:\Windows\SysWOW64\cc32\webtmr.exe [6484352 2009-07-14] (Salfeld Computer) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3802448 2014-09-04] (LogMeIn Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [164656 2014-08-27] (Avira Operations GmbH & Co. KG) HKLM\...\RunOnce: [*Restore] => C:\Windows\system32\rstrui.exe [296960 2010-11-21] (Microsoft Corporation) HKU\.DEFAULT\...\Run: [CCWinTray] => C:\Windows\tray\wintmr.exe [6864256 2009-07-14] (Salfeld Computer) HKU\S-1-5-21-3000299772-3109549842-2761917205-1002\...\Policies\system: [DisableClock] 1 HKU\S-1-5-21-3000299772-3109549842-2761917205-1002\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-3000299772-3109549842-2761917205-1002\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3000299772-3109549842-2761917205-1002\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-3000299772-3109549842-2761917205-1002\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-3000299772-3109549842-2761917205-1002\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-21-3000299772-3109549842-2761917205-1002\...\Policies\Explorer: [NoFind] 0 AppInit_DLLs: c:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL => c:\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll [4139336 2013-11-21] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk ShortcutTarget: WinZip Quick Pick.lnk -> C:\Program Files (x86)\WinZip\WZQKPICK.EXE (WinZip Computing, Inc. and H.C. Top Systems B.V.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-3000299772-3109549842-2761917205-1002\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?gd=&ctid=CT3323900&octid=EB_ORIGINAL_CTID&ISID=M5AE8E295-B993-47C6-8DDD-8940876D483D&SearchSource=55&CUI=&UM=5&UP=SP3142CD60-8666-44CB-9353-9A6443C1AC0A&SSPV= HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9E34843840D2CC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://i.search.metacrawler.com/?f=1&a=ironmc2&cd=2XzuyEtN2Y1L1Qzu0BtDyEzzyB0A0F0AyEzyyB0B0FtCtA0AtN0D0Tzu0CyCtDtDtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu&cr=614645060&ir= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://i.search.metacrawler.com/?f=1&a=ironmc2&cd=2XzuyEtN2Y1L1Qzu0BtDyEzzyB0A0F0AyEzyyB0B0FtCtA0AtN0D0Tzu0CyCtDtDtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu&cr=614645060&ir= SearchScopes: HKLM - DefaultScope {7C2360B9-08CA-8C54-843A-689F5B9F2EBE} URL = hxxp://i.search.metacrawler.com/results.php?f=4&q={searchTerms}&a=ironmc2&cd=2XzuyEtN2Y1L1Qzu0BtDyEzzyB0A0F0AyEzyyB0B0FtCtA0AtN0D0Tzu0CyCtDtDtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu&cr=614645060&ir= SearchScopes: HKLM - {7C2360B9-08CA-8C54-843A-689F5B9F2EBE} URL = hxxp://i.search.metacrawler.com/results.php?f=4&q={searchTerms}&a=ironmc2&cd=2XzuyEtN2Y1L1Qzu0BtDyEzzyB0A0F0AyEzyyB0B0FtCtA0AtN0D0Tzu0CyCtDtDtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu&cr=614645060&ir= SearchScopes: HKLM-x32 - DefaultScope {3237C8AF-001A-4C1F-9C64-26DD38C58B87} URL = hxxp://i.search.metacrawler.com/results.php?f=4&q={searchTerms}&a=ironmc2&cd=2XzuyEtN2Y1L1Qzu0BtDyEzzyB0A0F0AyEzyyB0B0FtCtA0AtN0D0Tzu0CyCtDtDtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu&cr=614645060&ir= SearchScopes: HKLM-x32 - {3237C8AF-001A-4C1F-9C64-26DD38C58B87} URL = hxxp://i.search.metacrawler.com/results.php?f=4&q={searchTerms}&a=ironmc2&cd=2XzuyEtN2Y1L1Qzu0BtDyEzzyB0A0F0AyEzyyB0B0FtCtA0AtN0D0Tzu0CyCtDtDtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu&cr=614645060&ir= SearchScopes: HKCU - {C888714D-D117-487A-81A0-D4AF51BFC142} URL = hxxp://www.search.ask.com/web?p2=%5EADN%5EOSJ000%5EYY%5EDE&gct=&itbv=12.6.0.11&o=APN10616&tpid=ORJ-V7&apn_uid=47CA41B7-1F3E-4120-9C21-38501944B538&apn_ptnrs=ADN&apn_dtid=%5EOSJ000%5EYY%5EDE&apn_dbr=ie_10.0.9200.16720&doi=2013-11-11&trgb=IE&q={searchTerms}&psv= BHO: No Name -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> No File BHO: No Name -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> No File BHO: No Name -> {53707962-6F74-2D53-2644-206D7942484F} -> No File BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HelperObject Class -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> C:\Program Files (x86)\TechSmith\SnagIt 7\SnagItBHO.dll (TechSmith Corporation) BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: metacrawler Helper Object -> {D4EF7D75-52C9-4BCE-B6DC-0976EFAB4B0B} -> C:\Program Files (x86)\metaCrawler\1.8.19.0\bh\metacrawler.dll (Info Space) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 7\SnagItIEAddin.dll (TechSmith Corporation) Toolbar: HKLM-x32 - metacrawler Toolbar - {7EACAC38-B7F6-4514-9DC1-3428A7964ABD} - C:\Program Files (x86)\metaCrawler\1.8.19.0\metacrawlerTlbr.dll (Info Space) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - No Name - {4F524A2D-5637-006A-76A7-7A786E7484D7} - No File DPF: HKLM {166B1BCA-3F9C-11CF-8075-444553540000} DPF: HKLM {8AD9C840-044E-11D1-B3E9-00805F499D93} DPF: HKLM {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} DPF: HKLM {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: HKLM-x32 {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Luca\AppData\Roaming\Mozilla\Firefox\Profiles\316ztsti.default FF DefaultSearchEngine: Conduit Search FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: Conduit Search FF Homepage: hxxp://www.google.de/ig FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelogx64.dll No File FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB) FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @ei.FromDocToPDF_65.com/Plugin -> C:\Program Files (x86)\FromDocToPDF_65EI\Installr\1.bin\NP65EISB.dll (FromDocToPDF) FF Plugin-x32: @esn/npbattlelog,version=2.3.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll No File FF Plugin-x32: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelog.dll No File FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Windows\SysWOW64\npdeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @Webzen.com/NPBrowserExt -> C:\Program Files (x86)\WEBZEN\BrowserExtension\NPWZCmnCtrl.dll (WEBZEN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Google.com/GoogleEarthPlugin -> C:\Users\Luca\AppData\Local\Google\Google Earth\plugin\npgeplugin.dll (Google) FF SearchPlugin: C:\Users\Luca\AppData\Roaming\Mozilla\Firefox\Profiles\316ztsti.default\searchplugins\conduit-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Browser Safety - C:\Users\Luca\AppData\Roaming\Mozilla\Firefox\Profiles\316ztsti.default\Extensions\abs@avira.com [2014-08-28] FF Extension: Better Battlelog (BBLog) - C:\Users\Luca\AppData\Roaming\Mozilla\Firefox\Profiles\316ztsti.default\Extensions\jid1-qQSMEVsYTOjgYA@jetpack [2014-07-21] FF Extension: Adblock Plus - C:\Users\Luca\AppData\Roaming\Mozilla\Firefox\Profiles\316ztsti.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-04] FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox FF HKLM\...\Firefox\Extensions: [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] - C:\Program Files\Web Assistant\Firefox Chrome: ======= CHR HomePage: Default -> http:\/\/search.conduit.com\/?gd=&ctid=CT3323900&octid=EB_ORIGINAL_CTID&ISID=M5AE8E295-B993-47C6-8DDD-8940876D483D&SearchSource=55&CUI=&UM=5&UP=SP3142CD60-8666-44CB-9353-9A6443C1AC0A&SSPV= CHR RestoreOnStartup: Default -> "http:\/\/search.conduit.com\/?gd=&ctid=CT3323900&octid=EB_ORIGINAL_CTID&ISID=M5AE8E295-B993-47C6-8DDD-8940876D483D&SearchSource=55&CUI=&UM=5&UP=SP3142CD60-8666-44CB-9353-9A6443C1AC0A&SSPV=" CHR DefaultSearchKeyword: Default -> conduit.search CHR DefaultSearchURL: Default -> http:\/\/search.conduit.com\/Results.aspx?gd=&ctid=CT3323900&octid=EB_ORIGINAL_CTID&ISID=M5AE8E295-B993-47C6-8DDD-8940876D483D&SearchSource=58&CUI=&UM=5&UP=SP3142CD60-8666-44CB-9353-9A6443C1AC0A&q={searchTerms}&SSPV= CHR DefaultSuggestURL: Default -> http:\/\/suggest.search.conduit.com\/CSuggestJson.ashx?prefix={searchTerms} CHR Profile: C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-06] CHR Extension: (YouTube) - C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-06] CHR Extension: (Google Search) - C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-06] CHR Extension: (greatsavIng) - C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\fghkofpnnkjalaoiicophpbfedkenopm [2013-12-23] CHR Extension: (saver boox) - C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gencfebafahakkdhhdideplccaehjekp [2014-02-15] CHR Extension: (Torntv) - C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbpkiefagocgkmemidfngdkamloieekf [2013-03-06] CHR Extension: (New tab for Chrome™) - C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg [2012-12-06] CHR Extension: (Gmail) - C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-06] CHR Extension: (FlexiiblEShopper) - C:\ProgramData\bakhlbmofdjaipjmkapmkljccjnbpohj\ [2012-12-06] CHR HKLM-x32\...\Chrome\Extension: [abepbblpkilpjohncjbccmdjhdhbnhdj] - C:\Program Files (x86)\SingAlong\Chrome.crx [] CHR HKLM-x32\...\Chrome\Extension: [fgfdfcbeamjnjdejakdidpniblllnbpg] - C:\Windows\SysWOW64\jmdp\pnte.crx [] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 70e6ca8c; c:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll [191128 2013-11-21] () R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-17] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [160048 2014-08-27] (Avira Operations GmbH & Co. KG) R2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36392 2014-03-14] (Just Develop It) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S2 ksupmgr; C:\Windows\SysWOW64\ksupmgr.exe [765592 2010-08-25] (Salfeld Computer) R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-08-08] (LogMeIn, Inc.) R2 MgAssistService; C:\Program Files (x86)\Mobogenie\MgAssist.exe [70848 2014-04-08] () R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-09-13] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-09-13] () R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [215416 2014-09-13] () R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2144056 2013-10-22] (TuneUp Software) S4 OtShotUpdateService; C:\Program Files (x86)\OtShot\OtshotUpdateServiceEx.exe [X] R2 VOsrv; C:\Users\Dirk\AppData\Roaming\VOPackage\VOsrv.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-01-14] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-26] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-01-14] () R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) S3 StarOpen; No ImagePath R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-12-12] (TuneUp Software) S3 USBMULCD; C:\Windows\System32\drivers\CM10664.sys [1307648 2011-03-31] (C-Media Electronics Inc) S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-13 17:59 - 2014-09-13 18:00 - 00023252 _____ () C:\Users\Luca\Desktop\FRST.txt 2014-09-13 17:58 - 2014-09-13 17:58 - 02105856 _____ (Farbar) C:\Users\Luca\Desktop\FRST64.exe 2014-09-13 17:58 - 2014-09-13 17:58 - 00000000 ____D () C:\Users\Luca\Desktop\FRST-OlderVersion 2014-09-13 16:07 - 2014-09-13 16:11 - 00000000 ____D () C:\Users\Luca\Documents\Battlefield 4 CTE 2014-09-13 16:06 - 2014-09-13 16:07 - 01402920 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.5.1_149(1).exe 2014-09-13 16:02 - 2014-09-13 16:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 4 CTE 2014-09-13 11:38 - 2014-09-13 11:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-13 03:15 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-09-13 03:15 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-09-13 03:15 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-09-13 03:15 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-09-13 03:15 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-09-13 03:15 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-09-13 03:15 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-09-13 03:15 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-09-13 03:15 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-09-13 03:15 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-09-13 03:15 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-09-13 03:15 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-09-13 03:15 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-09-13 03:15 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-09-13 03:15 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-09-13 03:15 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-09-13 03:15 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-09-13 03:15 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-09-13 03:15 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-09-13 03:15 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-09-13 03:15 - 2014-08-18 23:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-09-13 03:15 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-09-13 03:15 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-09-13 03:15 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-09-13 03:15 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-09-13 03:15 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-09-13 03:15 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-09-13 03:15 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-09-13 03:15 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-09-13 03:15 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-09-13 03:15 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-09-13 03:15 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-09-13 03:15 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-09-13 03:15 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-09-13 03:15 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-09-13 03:15 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-09-13 03:15 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-09-13 03:15 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-09-13 03:15 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-09-13 03:15 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-09-13 03:15 - 2014-08-18 23:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-09-13 03:15 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-09-13 03:15 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-09-13 03:15 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-09-13 03:15 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-09-13 03:15 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-09-13 03:15 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-09-13 03:15 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-09-13 03:15 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-09-13 03:15 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-09-13 03:15 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-09-13 03:15 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-09-13 03:15 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-09-13 03:15 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-09-13 03:15 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-09-13 03:15 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-09-13 03:01 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-09-13 03:01 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2014-09-12 14:05 - 2014-09-12 14:05 - 10036224 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-09-12 12:38 - 2014-08-01 13:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-09-12 12:38 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-09-12 12:38 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-09-12 12:38 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-09-12 12:38 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-09-12 12:38 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-09-12 12:38 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-09-12 12:38 - 2014-06-24 05:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-09-12 12:38 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-09-12 12:25 - 2014-09-12 12:25 - 01402920 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.5.1_149.exe 2014-09-12 12:20 - 2014-09-12 12:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-09-12 12:20 - 2014-09-12 12:20 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi 2014-09-07 19:34 - 2014-09-13 17:59 - 00000000 ____D () C:\FRST 2014-09-07 13:44 - 2014-09-07 13:47 - 00000000 ___HD () C:\System Shared 2014-09-07 13:44 - 2014-09-07 13:44 - 00000000 ___HD () C:\Device 2014-08-30 10:35 - 2014-08-30 10:37 - 17088592 _____ (Electronic Arts, Inc.) C:\Users\Luca\Downloads\OriginThinSetup.exe 2014-08-29 19:24 - 2014-08-29 19:24 - 01101648 _____ () C:\Users\Luca\Downloads\LogMeIn Hamachi - CHIP-Installer.exe 2014-08-29 18:27 - 2013-03-04 06:34 - 01808510 _____ () C:\Users\Luca\Downloads\TekkitLite.jar 2014-08-29 18:27 - 2013-03-04 06:33 - 02061638 _____ () C:\Users\Luca\Downloads\minecraft_server.jar 2014-08-29 18:27 - 2013-01-12 05:40 - 00000000 ____D () C:\Users\Luca\Downloads\mods 2014-08-29 18:27 - 2013-01-12 05:39 - 00000000 ____D () C:\Users\Luca\Downloads\coremods 2014-08-29 18:27 - 2013-01-04 09:42 - 00000555 _____ () C:\Users\Luca\Downloads\server.properties 2014-08-29 18:27 - 2013-01-04 09:20 - 00000054 _____ () C:\Users\Luca\Downloads\launch.sh 2014-08-29 18:27 - 2013-01-04 09:20 - 00000051 _____ () C:\Users\Luca\Downloads\launch.bat 2014-08-29 18:17 - 2014-08-29 18:22 - 00001376 _____ () C:\Users\Luca\Desktop\TechnicLauncher - Verknüpfung.lnk 2014-08-29 18:17 - 2014-08-29 18:19 - 00000000 ____D () C:\Users\Luca\Documents\Tekkit 2014-08-29 18:14 - 2014-08-29 18:16 - 20827501 _____ () C:\Users\Luca\Downloads\Tekkit_Lite_Server_0.6.5.zip 2014-08-28 17:44 - 2014-08-28 17:44 - 01397992 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.5.0_148.exe 2014-08-28 15:01 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-28 15:01 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-28 15:01 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-27 17:27 - 2014-08-27 17:27 - 02249144 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.4.0_147.exe 2014-08-21 12:20 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-21 12:20 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-21 12:20 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-08-21 12:20 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-21 12:20 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-21 12:20 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-21 12:20 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2014-08-21 12:20 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-21 12:20 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-21 12:20 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-08-21 12:19 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-21 12:19 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-08-21 12:19 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-08-21 12:19 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-08-18 14:08 - 2014-08-18 14:09 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8(1).exe 2014-08-18 14:01 - 2014-08-18 14:09 - 00001033 _____ () C:\Users\Dirk\Desktop\FlyVPN.lnk 2014-08-18 14:01 - 2014-08-18 14:09 - 00000000 ____D () C:\Program Files (x86)\FlyVPN 2014-08-18 14:01 - 2014-08-18 14:01 - 00000000 ____D () C:\ProgramData\FlyVPN 2014-08-18 14:00 - 2014-08-18 14:00 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8.exe 2014-08-18 13:56 - 2014-09-13 03:43 - 00001149 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-17 22:37 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-17 22:37 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-17 22:37 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-17 22:37 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-17 22:37 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-17 22:37 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-17 22:37 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-17 22:37 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-17 19:24 - 2014-08-17 20:36 - 620143037 _____ () C:\Users\Luca\Downloads\mb_warband_setup_1160.exe 2014-08-17 18:16 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-17 18:16 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-17 18:16 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-17 18:16 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-17 18:16 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-17 18:16 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-17 18:16 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-17 18:16 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-17 18:16 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-17 18:16 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-17 18:16 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-17 18:16 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-17 18:11 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-17 18:11 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-13 18:01 - 2010-11-21 08:50 - 00718866 _____ () C:\Windows\system32\perfh007.dat 2014-09-13 18:01 - 2010-11-21 08:50 - 00156680 _____ () C:\Windows\system32\perfc007.dat 2014-09-13 18:01 - 2009-07-14 07:13 - 01662620 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-13 18:00 - 2014-09-13 17:59 - 00023252 _____ () C:\Users\Luca\Desktop\FRST.txt 2014-09-13 17:59 - 2014-09-07 19:34 - 00000000 ____D () C:\FRST 2014-09-13 17:58 - 2014-09-13 17:58 - 02105856 _____ (Farbar) C:\Users\Luca\Desktop\FRST64.exe 2014-09-13 17:58 - 2014-09-13 17:58 - 00000000 ____D () C:\Users\Luca\Desktop\FRST-OlderVersion 2014-09-13 17:57 - 2012-01-17 22:53 - 00000000 ____D () C:\Users\Luca\Documents\Outlook-Dateien 2014-09-13 17:56 - 2012-01-22 18:47 - 00001268 _____ () C:\Windows\SysWOW64\excltmp~.dat 2014-09-13 17:55 - 2012-01-14 00:52 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-09-13 17:35 - 2013-08-22 18:35 - 00000288 _____ () C:\Windows\Tasks\MetaCrawler.job 2014-09-13 17:35 - 2013-08-22 18:35 - 00000282 _____ () C:\Windows\Tasks\DSite.job 2014-09-13 17:18 - 2013-09-30 16:59 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-09-13 17:18 - 2013-09-30 16:59 - 00214392 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-09-13 17:05 - 2012-11-02 19:25 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-13 16:29 - 2012-01-12 14:25 - 01305042 _____ () C:\Windows\WindowsUpdate.log 2014-09-13 16:11 - 2014-09-13 16:07 - 00000000 ____D () C:\Users\Luca\Documents\Battlefield 4 CTE 2014-09-13 16:10 - 2014-06-28 10:23 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe 2014-09-13 16:07 - 2014-09-13 16:06 - 01402920 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.5.1_149(1).exe 2014-09-13 16:07 - 2013-10-01 14:10 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-09-13 16:04 - 2013-06-03 20:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-09-13 16:02 - 2014-09-13 16:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 4 CTE 2014-09-13 16:02 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-09-13 16:01 - 2013-09-30 16:59 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-09-13 16:00 - 2012-01-12 15:18 - 00328254 _____ () C:\Windows\DirectX.log 2014-09-13 14:55 - 2012-01-14 00:52 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-09-13 11:38 - 2014-09-13 11:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-13 10:25 - 2009-07-14 06:51 - 00211982 _____ () C:\Windows\setupact.log 2014-09-13 06:44 - 2012-01-12 14:26 - 00000000 ____D () C:\Users\Dirk 2014-09-13 06:43 - 2013-09-30 16:07 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-09-13 06:43 - 2012-02-19 12:48 - 00000000 ____D () C:\Users\Luca\AppData\Local\LogMeIn Hamachi 2014-09-13 04:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-09-13 03:43 - 2014-08-18 13:56 - 00001149 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-09-13 03:43 - 2013-12-26 04:56 - 00000000 ____D () C:\ProgramData\Package Cache 2014-09-13 03:43 - 2013-05-24 10:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-09-13 03:43 - 2013-05-24 10:48 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-09-13 03:42 - 2009-07-14 06:45 - 00022512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-13 03:42 - 2009-07-14 06:45 - 00022512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-13 03:35 - 2012-01-12 14:51 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-09-13 03:35 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-13 03:15 - 2012-01-15 18:47 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-09-13 03:13 - 2013-05-20 18:48 - 01635964 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-09-13 03:12 - 2013-08-18 12:38 - 00000000 ____D () C:\Windows\system32\MRT 2014-09-13 03:02 - 2012-01-12 16:21 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-09-13 02:35 - 2013-08-22 19:35 - 00000199 _____ () C:\Users\Luca\AppData\Roaming\WB.CFG 2014-09-12 14:06 - 2012-11-02 19:25 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-09-12 14:06 - 2012-01-12 14:46 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-09-12 14:05 - 2014-09-12 14:05 - 10036224 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-09-12 12:27 - 2013-09-30 16:22 - 00000000 ____D () C:\Program Files (x86)\Origin Games 2014-09-12 12:25 - 2014-09-12 12:25 - 01402920 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.5.1_149.exe 2014-09-12 12:24 - 2013-09-30 16:07 - 00000000 ____D () C:\ProgramData\Origin 2014-09-12 12:20 - 2014-09-12 12:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-09-12 12:20 - 2014-09-12 12:20 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi 2014-09-12 12:18 - 2010-11-21 05:47 - 00686332 _____ () C:\Windows\PFRO.log 2014-09-11 20:07 - 2012-01-14 00:02 - 00000000 ____D () C:\Users\Luca 2014-09-09 23:45 - 2013-11-07 21:53 - 00000000 ____D () C:\Windows\pss 2014-09-09 23:45 - 2013-03-24 11:42 - 00000000 ____D () C:\Users\Luca\AppData\Roaming\Skype 2014-09-09 23:45 - 2012-07-11 19:42 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-09-09 23:45 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-09-09 23:45 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-09-09 23:45 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-09-09 23:45 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat 2014-09-07 14:11 - 2010-11-21 09:00 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-09-07 13:47 - 2014-09-07 13:44 - 00000000 ___HD () C:\System Shared 2014-09-07 13:44 - 2014-09-07 13:44 - 00000000 ___HD () C:\Device 2014-08-31 09:41 - 2014-04-25 10:24 - 00000000 ____D () C:\Users\Dirk\AppData\Roaming\Systweak 2014-08-30 10:37 - 2014-08-30 10:35 - 17088592 _____ (Electronic Arts, Inc.) C:\Users\Luca\Downloads\OriginThinSetup.exe 2014-08-29 21:00 - 2013-03-10 10:53 - 00000000 ____D () C:\Users\Luca\AppData\Roaming\.minecraft 2014-08-29 19:24 - 2014-08-29 19:24 - 01101648 _____ () C:\Users\Luca\Downloads\LogMeIn Hamachi - CHIP-Installer.exe 2014-08-29 18:29 - 2012-07-08 11:02 - 00003072 ___SH () C:\Users\Luca\Thumbs.db 2014-08-29 18:22 - 2014-08-29 18:17 - 00001376 _____ () C:\Users\Luca\Desktop\TechnicLauncher - Verknüpfung.lnk 2014-08-29 18:19 - 2014-08-29 18:17 - 00000000 ____D () C:\Users\Luca\Documents\Tekkit 2014-08-29 18:16 - 2014-08-29 18:14 - 20827501 _____ () C:\Users\Luca\Downloads\Tekkit_Lite_Server_0.6.5.zip 2014-08-29 14:20 - 2013-04-19 17:37 - 00000000 ____D () C:\Users\Luca\AppData\Roaming\.technic 2014-08-28 17:44 - 2014-08-28 17:44 - 01397992 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.5.0_148.exe 2014-08-28 17:34 - 2009-07-14 06:45 - 00414096 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-27 17:27 - 2014-08-27 17:27 - 02249144 _____ () C:\Users\Luca\Downloads\battlelog-web-plugins_2.4.0_147.exe 2014-08-23 04:07 - 2014-08-28 15:01 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-23 03:45 - 2014-08-28 15:01 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-23 02:59 - 2014-08-28 15:01 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-19 20:05 - 2014-09-13 03:15 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-19 19:39 - 2014-09-13 03:15 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-19 07:41 - 2013-01-27 15:40 - 00000000 ____D () C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-08-19 01:01 - 2014-09-13 03:15 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-19 00:29 - 2014-09-13 03:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-19 00:29 - 2014-09-13 03:15 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-19 00:26 - 2014-09-13 03:15 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-19 00:20 - 2014-09-13 03:15 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-19 00:19 - 2014-09-13 03:15 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-19 00:15 - 2014-09-13 03:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-19 00:15 - 2014-09-13 03:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-19 00:14 - 2014-09-13 03:15 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-19 00:14 - 2014-09-13 03:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-19 00:08 - 2014-09-13 03:15 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-19 00:08 - 2014-09-13 03:15 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-19 00:08 - 2014-09-13 03:15 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-19 00:05 - 2014-09-13 03:15 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-19 00:03 - 2014-09-13 03:15 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-19 00:03 - 2014-09-13 03:15 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-19 00:03 - 2014-09-13 03:15 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-18 23:57 - 2014-09-13 03:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-18 23:56 - 2014-09-13 03:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-18 23:51 - 2014-09-13 03:15 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-18 23:46 - 2014-09-13 03:15 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-18 23:45 - 2014-09-13 03:15 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-18 23:45 - 2014-09-13 03:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-18 23:44 - 2014-09-13 03:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-18 23:44 - 2014-09-13 03:15 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-18 23:42 - 2014-09-13 03:15 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-18 23:40 - 2014-09-13 03:15 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-18 23:39 - 2014-09-13 03:15 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-18 23:39 - 2014-09-13 03:15 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-18 23:39 - 2014-09-13 03:15 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-18 23:38 - 2014-09-13 03:15 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-18 23:37 - 2014-09-13 03:15 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-18 23:36 - 2014-09-13 03:15 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-18 23:35 - 2014-09-13 03:15 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-18 23:27 - 2014-09-13 03:15 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-18 23:25 - 2014-09-13 03:15 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-18 23:25 - 2014-09-13 03:15 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-18 23:23 - 2014-09-13 03:15 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-18 23:23 - 2014-09-13 03:15 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-18 23:22 - 2014-09-13 03:15 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-18 23:19 - 2014-09-13 03:15 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-18 23:17 - 2014-09-13 03:15 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-18 23:17 - 2014-09-13 03:15 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-18 23:16 - 2014-09-13 03:15 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-18 23:15 - 2014-09-13 03:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-18 23:15 - 2014-09-13 03:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-18 23:09 - 2014-09-13 03:15 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-18 23:08 - 2014-09-13 03:15 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-18 23:07 - 2014-09-13 03:15 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-18 22:55 - 2014-09-13 03:15 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-18 22:46 - 2014-09-13 03:15 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-18 22:38 - 2014-09-13 03:15 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-18 22:38 - 2014-09-13 03:15 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-18 22:36 - 2014-09-13 03:15 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-18 14:09 - 2014-08-18 14:08 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8(1).exe 2014-08-18 14:09 - 2014-08-18 14:01 - 00001033 _____ () C:\Users\Dirk\Desktop\FlyVPN.lnk 2014-08-18 14:09 - 2014-08-18 14:01 - 00000000 ____D () C:\Program Files (x86)\FlyVPN 2014-08-18 14:01 - 2014-08-18 14:01 - 00000000 ____D () C:\ProgramData\FlyVPN 2014-08-18 14:00 - 2014-08-18 14:00 - 02836320 _____ (FlyVPN) C:\Users\Luca\Downloads\FlyClientInstaller_3.0.1.8.exe 2014-08-18 13:56 - 2013-05-24 10:48 - 00000000 ____D () C:\ProgramData\Avira 2014-08-18 13:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-17 21:16 - 2012-05-28 21:44 - 00001156 _____ () C:\Users\Dirk\Desktop\Mount&Blade Warband.lnk 2014-08-17 21:16 - 2012-01-21 16:58 - 00001156 _____ () C:\Users\Luca\Desktop\Mount&Blade Warband.lnk 2014-08-17 21:15 - 2012-01-21 16:58 - 00000000 ____D () C:\Program Files (x86)\Mount&Blade Warband 2014-08-17 20:36 - 2014-08-17 19:24 - 620143037 _____ () C:\Users\Luca\Downloads\mb_warband_setup_1160.exe 2014-08-17 19:00 - 2013-10-01 19:39 - 00297088 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-08-17 18:47 - 2013-03-15 19:32 - 00000000 ____D () C:\ProgramData\Skype Some content of TEMP: ==================== C:\Users\Luca\AppData\Local\Temp\avgnt.exe C:\Users\Luca\AppData\Local\Temp\vlc-2.1.3-win32.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================ |