|
Alles rund um Windows: Windows 7 Bootvorgang bricht ständig ab!Windows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
24.12.2014, 15:19 | #1 |
| Problem: Windows 7 Bootvorgang bricht ständig ab! Hallo TB-Leute, Ersteinmal: Frohes Fest euch Zu meinem Problem: Seit ca. einer Woche, bricht mein Rechner ständig den Bootvorgang ab, startet dann neu und bricht wieder ab... Kurz: Es bedarf in der Regel ca. 5-10 Anläufe, bis er komplett durchbootet. Manchmal beginnt er einen Festplattencheck, wobei nicht wirklich was bei rumkommt. Ich verwende Windows 7 - Ultimate 32-Bit - Deutsch Standard. Ich kann wirklich nicht einschätzen, ob es ein Hard- oder Software Problem ist, da meine Erfahrungswerte durch mehr Eindeutigkeit geprägt wurden und ich bei Win7 sowieso nicht mehr durchsteige. Ich hab mit FRST mal 'n Scan gemacht und gebe euch das Ergebnis mal rein: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-12-2014 Ran by Alex (administrator) on ALEX-PC on 24-12-2014 14:57:00 Running from C:\Users\Alex\Desktop Loaded Profiles: Alex & UpdatusUser (Available profiles: Alex & UpdatusUser) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Yuna Software) C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Elaborate Bytes AG) C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (ROCCAT GmbH) C:\Program Files\ROCCAT\Savu Mouse\Savu Monitor.exe () C:\Windows\PLFSetI.exe (Space Sciences Laboratory) C:\Program Files\BOINC\boinctray.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe () C:\Windows\System32\PnkBstrA.exe () C:\Windows\System32\PAStiSvc.exe (Google Inc.) C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (Safer Networking Limited) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Facebook Inc.) C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Spotify Ltd) C:\Users\Alex\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Google Inc.) C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (ROCCAT GmbH Co., Ltd.) C:\Program Files\ROCCAT\Ryos Keyboard\Ryos MK Monitor.exe (Google Inc.) C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ZF Electronics GmbH) C:\Program Files\Cherry\CDI\cdi.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Google Inc.) C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8120864 2009-11-30] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1565992 2009-09-17] (Synaptics Incorporated) HKLM\...\Run: [PlusService] => C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe [801792 2012-02-07] (Yuna Software) HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM\...\Run: [CherryKeyMan] => C:\Program Files\Cherry\KeyMan\KeyMan.exe [254004 2010-09-01] (ZF Electronics GmbH) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.) HKLM\...\Run: [VirtualCloneDrive] => C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG) HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [ROCCAT Savu Gaming Mouse] => C:\Program Files\ROCCAT\Savu Mouse\Savu Monitor.exe [872048 2012-09-10] (ROCCAT GmbH) HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [200704 2007-10-23] () HKLM\...\Run: [boincmgr] => C:\Program Files\BOINC\boincmgr.exe [3663024 2012-05-15] (Space Sciences Laboratory) HKLM\...\Run: [boinctray] => C:\Program Files\BOINC\boinctray.exe [70832 2012-05-15] (Space Sciences Laboratory) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [ApnTBMon] => C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [2039192 2014-11-21] (APN) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [USB2Check] => RUNDLL32.EXE "C:\Windows\system32\PCLECoInst.dll",CheckUSBController HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) Winlogon\Notify\!SASWinLogon: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com) HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\Run: [Google Update] => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-26] (Google Inc.) HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [4617600 2012-01-20] (SUPERAntiSpyware.com) HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\Run: [SpybotSD TeaTimer] => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2144088 2009-01-26] (Safer Networking Limited) HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\Run: [Facebook Update] => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-10-13] (Facebook Inc.) HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\Run: [Pando Media Booster] => C:\Program Files\Pando Networks\Media Booster\PMB.exe [3093624 2013-02-02] () HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\Run: [Spotify Web Helper] => C:\Users\Alex\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-13] (Spotify Ltd) HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\Run: [GoogleChromeAutoLaunch_AD2529C7DB5B63D28C23362385276129] => C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe [856904 2014-12-06] (Google Inc.) HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\MountPoints2: D - D:\ HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\MountPoints2: G - G:\Setup.exe HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\MountPoints2: {26957606-d49e-11e1-813a-806e6f6e6963} - G:\AutoInstall.exe HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\MountPoints2: {31a9cbcb-b118-11e2-816a-00262d6a21f7} - G:\Setup.exe HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\MountPoints2: {82c445f2-6c5e-11e1-bfea-00262d6a21f7} - E:\install.bat HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\MountPoints2: {bcdbfa34-d43d-11e1-a208-00262d6a21f7} - G:\AutoInstall.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ryos Driver.lnk ShortcutTarget: Ryos Driver.lnk -> C:\Program Files\ROCCAT\Ryos Keyboard\Ryos MK Monitor.exe (ROCCAT GmbH Co., Ltd.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-399720636-3795779118-2281500929-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKU\S-1-5-21-399720636-3795779118-2281500929-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1408901273&from=cvs2&uid=ST9320325AS_6VE2J3LHXXXX6VE2J3LH SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1408901273&from=cvs2&uid=ST9320325AS_6VE2J3LHXXXX6VE2J3LH&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1408901273&from=cvs2&uid=ST9320325AS_6VE2J3LHXXXX6VE2J3LH&q={searchTerms} SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-399720636-3795779118-2281500929-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1408901273&from=cvs2&uid=ST9320325AS_6VE2J3LHXXXX6VE2J3LH&q={searchTerms} SearchScopes: HKU\S-1-5-21-399720636-3795779118-2281500929-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3331213&octid=EB_ORIGINAL_CTID&ISID=M806646FD-A182-4DCE-BD9C-581DACBE4506&SearchSource=58&CUI=&UM=6&UP=SP574C9890-0257-4F59-BC82-A14C11680302&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-399720636-3795779118-2281500929-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1408901273&from=cvs2&uid=ST9320325AS_6VE2J3LHXXXX6VE2J3LH&q={searchTerms} BHO: No Name -> {11111111-1111-1111-1111-110011221158} -> No File BHO: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO: Avira SearchFree Toolbar -> {41564952-412D-5637-00A7-7A786E7484D7} -> C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: No Name -> {ba14329e-9550-4989-b3f2-9732e92d17cc} -> No File BHO: No Name -> {C1AF5FA5-852C-4C90-812E-A7F75E011D87} -> No File BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-19] (SuperAdBlocker.com) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) FireFox: ======== FF ProfilePath: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xljvsmld.default FF NewTab: hxxp://istart.webssearches.com/newtab/?type=nt&ts=1408901273&from=cvs2&uid=ST9320325AS_6VE2J3LHXXXX6VE2J3LH FF DefaultSearchEngine: webssearches FF SearchEngineOrder.1: FF SelectedSearchEngine: webssearches FF Homepage: hxxp://istart.webssearches.com/?type=hp&ts=1408901273&from=cvs2&uid=ST9320325AS_6VE2J3LHXXXX6VE2J3LH FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_239.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-399720636-3795779118-2281500929-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Alex\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKU\S-1-5-21-399720636-3795779118-2281500929-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-399720636-3795779118-2281500929-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-399720636-3795779118-2281500929-1001: pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\webssearches.xml FF Extension: Avira Browser Safety - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xljvsmld.default\Extensions\abs@avira.com [2014-11-22] FF Extension: Fast Start - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xljvsmld.default\Extensions\faststartff@gmail.com [2014-08-24] FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xljvsmld.default\Extensions\toolbar_AVIRA-V7@apn.ask.com [2013-08-10] FF Extension: Forecastfox - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xljvsmld.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2013-05-20] FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xljvsmld.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi [2014-11-26] FF Extension: Torntv - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xljvsmld.default\Extensions\torntv@torntv.com.xpi [2013-03-17] FF Extension: Live IP Address - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xljvsmld.default\Extensions\{7C9AE782-DB21-4e40-81FB-AD8A53A6233A}.xpi [2012-02-26] FF Extension: StockFox - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xljvsmld.default\Extensions\{d39a0050-191f-11df-8a39-0800200c9a66}.xpi [2012-03-03] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2012-02-26] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} [2012-03-01] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} [2012-03-03] FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-08-18] FF HKLM\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xljvsmld.default\extensions\faststartff@gmail.com FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe hxxp://istart.webssearches.com/?type=sc&ts=1408901273&from=cvs2&uid=ST9320325AS_6VE2J3LHXXXX6VE2J3LH Chrome: ======= CHR HomePage: Default -> hxxp://www.google.de/ CHR StartupUrls: Default -> "hxxp://www.google.de/" CHR DefaultSearchURL: Default -> hxxp://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&aq=t CHR DefaultSuggestURL: Default -> hxxp://suggestqueries.google.com/complete/search?q={searchTerms} CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh [2013-08-11] CHR Extension: (Wetter (Erweiterung)) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\beapnbfmjmjhhfpaoajfhjbbfnnlfpnc [2012-02-26] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-06] CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-02-26] CHR Extension: (Google-Suche) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-02-26] CHR Extension: (Empty New Tab Page) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpjamkmjmigaoobjbekmfgabipmfilij [2014-03-02] CHR Extension: (Avira Browserschutz) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-12-02] CHR Extension: (IP-Adresse) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnjjlbngpejmmhgcaagljaomgnginml [2012-02-26] CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2012-09-30] CHR Extension: (Google Wallet) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-08] CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-02-26] CHR Extension: (Google Mail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-02-26] CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [2014-11-26] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12] CHR HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\Alex\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-09-30] CHR StartMenuInternet: Google Chrome - C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [116608 2011-08-12] (SUPERAntiSpyware.com) [File not signed] S2 AndroidDesktopRemote; C:\Program Files\Android Desktop Remote\AndroidDesktopRemoteService.exe [190464 2012-03-04] (David Straw) [File not signed] R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [992560 2014-12-16] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166296 2014-10-30] (APN LLC.) S2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [484592 2013-11-02] (BitRaider, LLC) R3 Cherry Device Interface; C:\Program Files\Cherry\CDI\cdi.exe [577582 2010-08-25] (ZF Electronics GmbH) [File not signed] S4 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1682256 2014-04-15] (LogMeIn Inc.) S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed] R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [694784 2014-08-24] (Cherished Technololgy LIMITED) [File not signed] R2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [375056 2014-04-08] (LogMeIn, Inc.) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75136 2014-12-13] () R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) R2 STI Simulator; C:\Windows\System32\PAStiSvc.exe [53248 2005-01-14] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [26032 2013-06-02] (Wondershare) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-30] (Avira Operations GmbH & Co. KG) R3 Ch2kPS2; C:\Windows\System32\DRIVERS\Ch2kPS2.sys [131072 2010-01-21] (ZF Electronics GmbH) S3 Ch2kUSB; C:\Windows\System32\drivers\Ch2kUSB.sys [112512 2010-01-21] (Cherry GmbH) S3 DCamUSBEMPIA; C:\Windows\System32\DRIVERS\emDevice.sys [100957 2005-12-21] (eMPIA Technology, Inc.) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-16] (Elaborate Bytes AG) S3 emAudio; C:\Windows\System32\drivers\emAudio.sys [22528 2006-12-12] (Pinnacle Systems GmbH) R3 EuMusDesignVirtualAudioCableWdm; C:\Windows\System32\DRIVERS\vrtaucbl.sys [90400 2014-08-24] (Eugene V. Muzychenko) S3 ffusb2audio; C:\Windows\System32\DRIVERS\ffusb2audio.sys [101680 2013-09-25] (Focusrite Audio Engineering Limited.) S3 FiltUSBEMPIA; C:\Windows\System32\DRIVERS\emFilter.sys [5245 2005-12-21] (eMPIA Technology, Inc.) R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R3 hidshim; C:\Windows\System32\DRIVERS\hidshim.sys [5632 2009-07-21] (Windows (R) Win 7 DDK provider) R3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171520 2005-09-23] (Pinnacle Systems GmbH) R3 nuvotonhidgeneric; C:\Windows\System32\DRIVERS\nuvotonhidgeneric.sys [22528 2009-07-21] (Nuvoton Technology Corporation) S3 PAC7311; C:\Windows\System32\DRIVERS\PA707UCM.SYS [154752 2005-10-18] (PixArt Imaging Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 ScanUSBEMPIA; C:\Windows\System32\DRIVERS\emScan.sys [4493 2005-12-21] (eMPIA Technology, Inc.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-10] (Avira GmbH) R3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [172416 2010-11-20] (Microsoft Corporation) R1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [48128 2010-11-20] (Microsoft Corporation) R3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2010-11-20] (Microsoft Corporation) R1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [296064 2010-11-20] (Microsoft Corporation) S3 BRDriver; \??\C:\ProgramData\BitRaider\BRDriver.sys [X] S3 C7xxUSB; system32\DRIVERS\C7xUSB73.sys [X] S1 dmdholcm; \??\C:\Windows\system32\drivers\dmdholcm.sys [X] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-24 14:57 - 2014-12-24 14:59 - 00028274 _____ () C:\Users\Alex\Desktop\FRST.txt 2014-12-24 14:56 - 2014-12-24 14:57 - 00000000 ____D () C:\FRST 2014-12-24 14:54 - 2014-12-24 14:55 - 01114112 _____ (Farbar) C:\Users\Alex\Desktop\FRST.exe 2014-12-20 15:44 - 2014-12-20 17:37 - 00000438 _____ () C:\Users\Alex\Desktop\nondescript.txt 2014-12-19 14:39 - 2014-12-19 14:39 - 00155928 _____ () C:\Windows\Minidump\121914-25490-01.dmp 2014-12-19 13:44 - 2014-12-19 13:44 - 00000000 ____D () C:\Users\Alex\Desktop\old_school_pack 2014-12-17 21:42 - 2014-12-17 21:42 - 00153840 _____ () C:\Windows\Minidump\121714-28080-01.dmp 2014-12-17 21:36 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-16 15:35 - 2014-12-16 15:46 - 00000000 ____D () C:\Users\Alex\Desktop\ProjektManagement Deutsche POP 2014-12-14 16:50 - 2014-12-14 16:50 - 00000000 ____D () C:\Windows\system32\appraiser 2014-12-14 16:49 - 2014-12-14 16:49 - 00003224 ____N () C:\bootsqm.dat 2014-12-13 19:39 - 2014-12-13 19:41 - 00000000 ____D () C:\Users\Alex\AppData\Local\Ubisoft Game Launcher 2014-12-13 19:39 - 2014-12-13 19:39 - 00000000 ____D () C:\Users\Alex\Documents\Assassin's Creed Revelations 2014-12-13 19:39 - 2014-12-13 19:39 - 00000000 ____D () C:\ProgramData\Ubisoft 2014-12-13 19:14 - 2014-12-13 19:14 - 00001731 _____ () C:\Users\Alex\Desktop\Assassin's Creed - Revelations.lnk 2014-12-13 19:09 - 2014-12-13 19:09 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\PunkBuster 2014-12-13 18:48 - 2014-12-13 19:08 - 00000000 ____D () C:\Program Files\Ubisoft 2014-12-13 14:47 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2014-12-13 14:47 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2014-12-13 14:47 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2014-12-13 14:47 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2014-12-13 14:47 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2014-12-11 19:17 - 2014-12-04 05:38 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2014-12-11 19:17 - 2014-12-04 05:38 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2014-12-11 19:17 - 2014-12-04 05:38 - 00337920 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-12-11 19:17 - 2014-12-04 05:38 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-12-11 19:17 - 2014-12-04 05:38 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-12-11 19:17 - 2014-12-04 05:38 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-12-11 19:17 - 2014-12-04 05:34 - 00873984 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-12-11 19:17 - 2014-12-02 00:28 - 01160872 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2014-12-11 19:17 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-11 19:17 - 2014-11-11 02:32 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2014-12-11 19:16 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-12-11 19:16 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-11 19:16 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-11 19:16 - 2014-11-22 03:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-12-11 19:16 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-11 19:16 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-12-11 19:16 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-12-11 19:16 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-12-11 19:16 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-11 19:16 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-11 19:16 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-12-11 19:16 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-11 19:16 - 2014-11-22 02:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-12-11 19:16 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-12-11 19:16 - 2014-11-22 02:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-12-11 19:16 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-11 19:16 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-12-11 19:16 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-12-11 19:16 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-11 19:16 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-11 19:16 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-11 19:16 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-11 19:16 - 2014-11-22 02:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-12-11 19:16 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-11 19:16 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-12-11 19:16 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-11 19:16 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-11 19:16 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-11 19:16 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-12-11 19:16 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-11 19:15 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2014-12-11 19:15 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2014-12-11 19:15 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2014-12-11 19:15 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2014-12-11 19:15 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2014-12-11 19:15 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2014-12-11 19:06 - 2014-12-11 19:06 - 00002505 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-12-11 19:06 - 2014-12-11 19:06 - 00000000 ___RD () C:\Program Files\Skype 2014-12-11 19:06 - 2014-12-11 19:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-12-11 19:06 - 2014-12-11 19:06 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-12-08 21:56 - 2014-12-08 21:56 - 00000000 ____D () C:\Users\Alex\Desktop\FIX YOU 2014-12-08 21:52 - 2014-12-08 21:52 - 00041142 _____ () C:\Users\Alex\Desktop\coldplay-fix_you.mid 2014-12-08 01:32 - 2014-12-08 01:32 - 00003584 _____ () C:\Users\Alex\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-12-08 00:49 - 2014-12-16 15:55 - 00000000 ____D () C:\Users\Alex\Desktop\TonTechnik Deutsche POP 2014-12-02 16:32 - 2014-12-02 17:21 - 00034850 _____ () C:\Users\Alex\Desktop\Rock meets Orchestra.odt 2014-11-30 16:35 - 2014-11-30 16:35 - 00000000 __SHD () C:\Users\Alex\AppData\Local\EmieUserList 2014-11-30 16:35 - 2014-11-30 16:35 - 00000000 __SHD () C:\Users\Alex\AppData\Local\EmieSiteList 2014-11-30 16:35 - 2014-11-30 16:35 - 00000000 __SHD () C:\Users\Alex\AppData\Local\EmieBrowserModeList ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-24 14:59 - 2014-08-26 23:32 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird 2014-12-24 14:47 - 2013-02-02 20:49 - 00000000 ____D () C:\Users\Alex\AppData\Local\PMB Files 2014-12-24 14:38 - 2013-04-21 20:49 - 00000000 ____D () C:\ProgramData\BOINC 2014-12-24 14:37 - 2012-02-26 16:30 - 01291630 _____ () C:\Windows\WindowsUpdate.log 2014-12-24 14:25 - 2009-07-14 05:34 - 00019456 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-24 14:25 - 2009-07-14 05:34 - 00019456 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-24 14:14 - 2009-07-14 05:39 - 00105058 _____ () C:\Windows\setupact.log 2014-12-20 18:12 - 2014-07-16 12:33 - 00000000 ____D () C:\Users\Alex\Desktop\WegoEGO 2014-12-20 01:34 - 2012-02-26 19:44 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Skype 2014-12-19 16:08 - 2014-08-22 13:31 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Spotify 2014-12-19 16:03 - 2014-08-22 13:32 - 00000000 ____D () C:\Users\Alex\AppData\Local\Spotify 2014-12-19 14:39 - 2014-02-07 22:31 - 00000000 ____D () C:\Windows\Minidump 2014-12-17 21:58 - 2014-09-01 22:45 - 00000000 ____D () C:\Users\Alex\Documents\Cubase LE AI Elements Projects 2014-12-17 21:16 - 2012-02-26 17:51 - 00209482 _____ () C:\Windows\PFRO.log 2014-12-16 15:53 - 2014-09-23 18:45 - 00181760 ___SH () C:\Users\Alex\Desktop\Thumbs.db 2014-12-16 12:58 - 2014-11-22 20:33 - 00001055 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-12-16 12:58 - 2014-11-22 20:28 - 00000000 ____D () C:\ProgramData\Package Cache 2014-12-16 12:58 - 2013-08-10 12:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-12-16 12:58 - 2013-08-10 12:17 - 00000000 ____D () C:\Program Files\Avira 2014-12-15 20:47 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-12-14 16:50 - 2014-05-08 10:18 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-12-14 16:50 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ru-RU 2014-12-14 16:50 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-12-14 16:50 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\AppCompat 2014-12-13 19:10 - 2012-03-12 18:20 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Azureus 2014-12-13 19:10 - 2012-03-12 18:18 - 00000000 ____D () C:\Program Files\Vuze 2014-12-13 19:09 - 2013-07-04 14:12 - 00189248 _____ () C:\Windows\system32\PnkBstrB.exe 2014-12-13 19:09 - 2013-07-04 14:12 - 00075136 _____ () C:\Windows\system32\PnkBstrA.exe 2014-12-13 19:08 - 2012-02-26 18:31 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-12-13 19:07 - 2009-07-14 05:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-12-13 14:55 - 2012-02-26 18:02 - 00002350 _____ () C:\Users\Alex\Desktop\Google Chrome.lnk 2014-12-11 19:06 - 2012-02-26 19:44 - 00000000 ____D () C:\ProgramData\Skype 2014-12-08 13:28 - 2012-02-26 17:55 - 02487976 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-08 13:28 - 2009-08-16 04:32 - 00717302 _____ () C:\Windows\system32\perfh019.dat 2014-12-08 13:28 - 2009-08-16 04:32 - 00151608 _____ () C:\Windows\system32\perfc019.dat 2014-12-08 13:20 - 2012-02-26 17:53 - 00000000 ____D () C:\Users\Alex\Desktop\Mukke 2014-12-08 05:44 - 2013-03-15 05:53 - 00000000 ____D () C:\Users\Alex\Desktop\Bilderr 2014-12-06 20:52 - 2012-02-26 18:07 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-12-03 05:26 - 2014-09-01 21:38 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Steinberg 2014-12-03 00:00 - 2014-09-01 22:43 - 00000000 ____D () C:\Users\Alex\Documents\VST3 Presets 2014-12-02 00:29 - 2013-11-09 10:30 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-12-02 00:29 - 2012-04-08 23:31 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-12-02 00:29 - 2012-02-26 19:16 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-11-24 14:04 - 2012-02-26 18:07 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\Alex\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2013-08-25 22:36 ==================== End Of Log ============================ Falls euch der Addtional LOG auch noch wichtig ist: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-12-2014 Ran by Alex at 2014-12-24 14:59:55 Running from C:\Users\Alex\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acer Crystal Eye Webcam 2.0.7 (HKLM\...\{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}) (Version: 2.0.7 - SuYin) Acer Crystal Eye Webcam 2.0.7 (Version: 2.0.7 - SuYin) Hidden Acoustica Mixcraft 6 (HKLM\...\Acoustica Mixcraft 6) (Version: b217 - Acoustica) Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.2.0.2070 - Adobe Systems Incorporated) Adobe Flash Player 11 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 11.7.700.224 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated) Adobe Reader X (10.1.7) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.7 - Adobe Systems Incorporated) Adobe Shockwave Player (HKLM\...\{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}) (Version: 11.5.1.601 - Adobe Systems, Inc.) Age of Empires III (HKLM\...\InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}) (Version: 1.00.0000 - Microsoft Game Studios) Age of Empires III (Version: 1.00.0000 - Microsoft Game Studios) Hidden Android Desktop Remote (HKLM\...\{D3947ED4-D1E7-44C0-9755-EA84620C26C5}) (Version: 1.6.0 - David Straw) Apowersoft kostenloser Bildschirmrekorder V1.2.4 (HKLM\...\{4EFA42DB-E4EC-4537-9DF3-5158D08A9785}_is1) (Version: 1.2.4 - Apowersoft) Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Applian FLV and Media Player 3.1.1.12 (HKLM\...\Applian FLV and Media Player) (Version: 3.1.1.12 - Applian Technologies) ASIO4ALL (HKLM\...\ASIO4ALL) (Version: 2.10 - Michael Tippach) Assassin's Creed Revelations (HKLM\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.00 - Ubisoft) Atheros Driver Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 8.0.0.225 - Atheros) Audacity 2.0 (HKLM\...\Audacity_is1) (Version: - Audacity Team) Avira (HKLM\...\{e7c7c227-b742-4878-9425-f09bbf9951db}) (Version: 1.1.27.25527 - Avira Operations & Co. KG) Avira (Version: 1.1.27.25527 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) Avira SearchFree Toolbar (HKLM\...\{41564952-412D-5637-00A7-A758B70C1500}) (Version: 12.21.0.3946 - APN, LLC) BitRaider Web Client (HKLM\...\BitRaider Web Client) (Version: 1.1.9.4 - BitRaider, LLC) Blobby Volley 2 Version 1.0RC3 (HKLM\...\Blobby Volley 2 Version 1.0RC3_is1) (Version: - ) BMW M3 Challenge (HKLM\...\{C4CD208D-E3A2-488B-A4F4-FD8DE3DADD25}_is1) (Version: BMW M3 Challenge v1.0.0.0 - 10TACLE STUDIOS AG) BOINC (HKLM\...\{3885BE54-851B-4662-89F9-EB9F0DCCB14E}) (Version: 7.0.28 - Space Sciences Laboratory, U.C. Berkeley) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Broadcom Gigabit Integrated Controller (HKLM\...\{49F3D04B-B849-4C89-AB31-2366A004EA28}) (Version: 12.24.02 - Broadcom Corporation) Broadcom Gigabit NetLink Controller (HKLM\...\{96F70DF8-160F-4F9C-9B9E-2A9B439B4EB9}) (Version: 12.26.02 - Broadcom Corporation) Call of Duty(R) 4 - Modern Warfare(TM) (HKLM\...\InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.00.0000 - Activision) Call of Duty(R) 4 - Modern Warfare(TM) (Version: 1.00.0000 - Activision) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.16 - Piriform) CDCheck (HKLM\...\CDCheck) (Version: - ) Counter-Strike (HKLM\...\Steam App 10) (Version: - Valve) Counter-Strike: Source (HKLM\...\Steam App 240) (Version: - Valve) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden Day of Defeat: Source (HKLM\...\Steam App 300) (Version: - Valve) Delphi 7 Second Edition (HKLM\...\Delphi 7 Second Edition v7.2_is1) (Version: - Lite Applications) DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.1.9 - DivX, LLC) Dota 2 (HKLM\...\Steam App 570) (Version: - Valve) EA SPORTS online 2004 (HKLM\...\82A44D22-9452-49FB-00FB-CEC7DCAF7E23) (Version: - ) eLicenser Control (HKLM\...\eLicenser Control) (Version: 6.6.6.2133 - Steinberg Media Technologies GmbH) EVEREST Home Edition v2.20 (HKLM\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc) Facebook Video Calling 3.1.0.521 (HKLM\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited) FIFA 12 (c) EA version 1 (HKLM\...\FIFA 12 (c) EA_is1) (Version: 1 - ) Finanzen.net Börsenticker 1.4 (HKLM\...\Finanzen.net Börsenticker 1.4) (Version: - ) FL Studio 10 (HKLM\...\FL Studio 10) (Version: - Image-Line) Focusrite USB 2.0 Audio Driver 2.5.1 (HKLM\...\Focusrite USB 2.0 Audio Driver_is1) (Version: 2.5.1 - Focusrite Audio Engineering Limited.) Fotogalerie (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Free Video Dub version 2.0.21.822 (HKLM\...\Free Video Dub_is1) (Version: 2.0.21.822 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.41.623 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.41.623 - DVDVideoSoft Ltd.) FrenzelSoft Stock Ticker (HKLM\...\{EC663A85-7749-429C-A99B-C3B5BE44E25A}) (Version: 1.7.2 - FrenzelSoft) GameRanger (HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\GameRanger) (Version: - GameRanger Technologies) Ghost Recon Online (EU) (HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\d8be6c3f847d7d92) (Version: 1.33.8542.1 - Ubisoft) Google Chrome (HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.) Grand Theft Auto IV (HKLM\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games) GTA San Andreas (HKLM\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games) GUILD WARS (HKLM\...\Guild Wars) (Version: - ) Half-Life 2: Deathmatch (HKLM\...\Steam App 320) (Version: - Valve) HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDA_HSF) (Version: 7.80.4.55 - Conexant Systems) Hold 'Em (HKLM\...\HoldEm) (Version: 6.0.6000.17034 - Microsoft Corporation) ICQ7.7 (HKLM\...\{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE}) (Version: 7.7 - ICQ) IL Download Manager (HKLM\...\IL Download Manager) (Version: - Image-Line) Insurgency: Modern Infantry Combat (HKLM\...\Steam App 17700) (Version: - InterWave Studios) Intel(R) Control Center (HKLM\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.0 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) IsoBuster 2.8.5 (HKLM\...\IsoBuster_is1) (Version: 2.8.5 - Smart Projects) iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.) Java 7 Update 55 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle) Java(TM) 6 Update 22 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216022F0}) (Version: 6.0.220 - Oracle) Java(TM) 6 Update 29 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216029F0}) (Version: 6.0.290 - Oracle) Java(TM) 6 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle) JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) KeyMan V3.6 Build 6 (HKLM\...\{DC627AE5-A2B1-4D16-AF56-178D10EC3E81}) (Version: 3.6.0.6 - ZF Electronics GmbH) League of Legends (HKLM\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games) Left 4 Dead 2 (HKLM\...\Steam App 550) (Version: - Valve) LogMeIn Hamachi (HKLM\...\LogMeIn Hamachi) (Version: 2.2.0.188 - LogMeIn, Inc.) LogMeIn Hamachi (Version: 2.2.0.188 - LogMeIn, Inc.) Hidden Messenger Plus! 5 (HKLM\...\Messenger Plus!) (Version: 5.11.0.759 - Yuna Software) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Age of Empires II (HKLM\...\Age of Empires 2.0) (Version: - ) Microsoft Age of Empires II: The Conquerors Expansion (HKLM\...\Age of Empires II: The Conquerors Expansion 1.0) (Version: - ) Microsoft Combat Flight Simulator 3.0 (HKLM\...\Combat Flight Simulator 3.0) (Version: - ) Microsoft Flight (HKLM\...\Steam App 203850) (Version: - ) Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Movie Maker (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 10.0.2 (x86 de) (HKLM\...\Mozilla Firefox 10.0.2 (x86 de)) (Version: 10.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 24.2.0 - Mozilla) Mozilla Thunderbird 24.2.0 (x86 de) (HKLM\...\Mozilla Thunderbird 24.2.0 (x86 de)) (Version: 24.2.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Need For Speed™ World (HKLM\...\{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1) (Version: 1.0.0.1055 - Electronic Arts) NHL 2004 (HKLM\...\{4816702A-0879-4499-0085-ACFC0F65E811}) (Version: - ) Nuvoton EC Generic HID Driver (HKLM\...\{92975DF9-EA36-4F36-A9AC-D412BC1D709E}) (Version: 8.80.1001 - Nuvoton Technology Corporation) NVIDIA Grafiktreiber 306.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 306.23 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.18.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.18.0 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.12.0604 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0604 - NVIDIA Corporation) NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation) ooVoo (HKLM\...\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}) (Version: 3.5.9052 - ooVoo LLC.) OpenAL (HKLM\...\OpenAL) (Version: - ) OpenOffice.org 3.3 (HKLM\...\{4286716B-1287-48E7-9078-3DC8248DBA96}) (Version: 3.3.9567 - OpenOffice.org) Pando Media Booster (HKLM\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.8 - Pando Networks Inc.) PAP project files (HKLM\...\PAP project files_is1) (Version: - ) Pinnacle Systems USB-2 Device Drivers (HKLM\...\{9870C7AE-7C6A-478D-9A75-35827382220F}) (Version: 2.00.0014 - Pinnacle Systems) PunkBuster Services (HKLM\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.) Quake Live (HKLM\...\Quake Live) (Version: - id Software) RaceRoom Racing Experience (HKLM\...\Steam App 211500) (Version: - SimBin Studios AB) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5992 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7100.30093 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.45 - Piriform) ROCCAT Ryos Keyboard Driver (HKLM\...\{70F3EF93-44F4-446A-90B8-33DAB2799AF1}) (Version: 1.13.0000 - Roccat GmbH) Rockstar Games Social Club (HKLM\...\{08B3869E-D282-424C-9AFC-870E04A4BA14}) (Version: 1.00.0000 - Rockstar Games) Savu Mouse (HKLM\...\{6F4B8EA6-4546-4160-A05F-0706F7DC1EFF}) (Version: 1.1.9 - ROCCAT GmbH) Silkroad (HKLM\...\Silkroad) (Version: - ) Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.100 - Skype Technologies S.A.) Source SDK Base 2007 (HKLM\...\Steam App 218) (Version: - Valve) Spotify (HKU\S-1-5-21-399720636-3795779118-2281500929-1001\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) Star Wars The Old Republic (HKLM\...\swtor_swtor) (Version: 7.0.0.22 - Bioware/EA) Star Wars: The Old Republic (HKLM\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.) Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Steinberg Cubase LE AI Elements 7 (HKLM\...\{5C73FC14-D3B1-45FC-A50C-7B41CB0D9DED}) (Version: 7.0.6 - Steinberg Media Technologies GmbH) Steinberg Drum Loop Expansion 01 (HKLM\...\{490BF87E-1F75-4453-BF55-9F540543A3CA}) (Version: 2.0.0.0 - Steinberg Media Technologies GmbH) Steinberg Groove Agent ONE Content (HKLM\...\{BD86F1AC-B594-46E4-85DC-1258AC9E2232}) (Version: 1.0.0.003 - Steinberg Media Technologies GmbH) Steinberg Groove Agent ONE Vintage Beatboxes (HKLM\...\{DBF4BC99-53F1-4C97-84C3-7557D103E182}) (Version: 1.0.0.000 - Steinberg Media Technologies GmbH) Steinberg HALion Sonic SE (HKLM\...\{EF7800A8-575E-4776-95A5-A9D904A85D5F}) (Version: 1.6.3 - Steinberg Media Technologies GmbH) Steinberg HALion Sonic SE Content for Cubase LE AI Elements (HKLM\...\{CF45002F-2205-4116-BB51-2D015F436CAC}) (Version: 1.6.3 - Steinberg Media Technologies GmbH) Steinberg Midi Loop Library (HKLM\...\{89DE2651-6DD9-4C15-AC94-8348362D456C}) (Version: 1.0.0 - Steinberg Media Technologies GmbH) Steinberg REVerence Content 01 (HKLM\...\{532B917B-8235-4FA5-BE36-643A8BB053A5}) (Version: 2.0.1.000 - Steinberg Media Technologies GmbH) Steinberg Upload Manager (HKLM\...\{88BBBD8F-4C19-4809-B84B-7A8F8238B48D}) (Version: 1.0.1 - Steinberg Media Technologies GmbH) Steinberg VST Amp Rack Content 01 (HKLM\...\{8CBA7E47-48DA-47DC-8E98-6984BA830295}) (Version: 1.0.1 - Steinberg Media Technologies GmbH) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1144 - SUPERAntiSpyware.com) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.6.0 - Synaptics Incorporated) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) Text-To-Speech-Runtime (HKLM\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH) TmNationsForever (HKLM\...\TmNationsForever_is1) (Version: - Nadeo) Ubisoft Game Launcher (HKLM\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden Virtual Audio Cable 4.14 (HKLM\...\Virtual Audio Cable 4.14) (Version: - ) VirtualCloneDrive (HKLM\...\VirtualCloneDrive) (Version: - Elaborate Bytes) Vuze (HKLM\...\8461-7759-5462-8226) (Version: 4.7 - Vuze Inc.) Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405) (HKLM\...\A6A8668C0A13640CA28FE2A7D9654BE4AE478B13) (Version: 07/30/2009 6.2.0.9405 - Broadcom) Windows Driver Package - Broadcom Bluetooth (09/11/2009 6.2.0.9407) (HKLM\...\755087041320E005CB1E8A67C5C55A260EB81B90) (Version: 09/11/2009 6.2.0.9407 - Broadcom) Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\BF20603967CFDCB2BBF91950E8A56DFBC5C833FE) (Version: 07/28/2009 6.2.0.9800 - Broadcom) Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Mobile-Gerätecenter (HKLM\...\{904CCF62-818D-4675-BC76-D37EB399F917}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows Mobile-Gerätecenter: Treiberupdate (HKLM\...\{E7044E25-3038-4A76-9064-344AC038043E}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows-Treiberpaket - Focusrite USB 2.0 Audio Driver (09/25/2013 2.5.128.1) (HKLM\...\CF1FC201D237269A9CD51A3A6B14ADBF67175C32) (Version: 09/25/2013 2.5.128.1 - Focusrite) WinRAR 4.11 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH) WinZip 15.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}) (Version: 15.0.9334 - WinZip Computing, S.L. ) World of Warplanes (HKLM\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C813EU}_is1) (Version: - Wargaming.net) X2 - Die Bedrohung (V1.4) (HKLM\...\{4E47844E-4A18-454B-A977-EC2CCF3F1472}) (Version: 1.04.0000 - EGOSOFT) X3: Reunion v2.0.02 (HKLM\...\X3-Reunion2.0.02DE_is1) (Version: - EGOSOFT) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.21.135\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.21.99\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.25.5\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{31261F21-2B16-45EE-BEAB-07C4CFA18B65}\InprocServer32 -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.23.9\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\Alex\AppData\Local\Google\Chrome\Application\39.0.2171.95\delegate_execute.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\Alex\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.21.145\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{8B9F5BF4-0407-4BB2-9FED-4C0372DABD00}\localserver32 -> C:\Users\Alex\AppData\Local\Facebook\Video\Skype\FacebookVideoCallingProxy.exe (Skype Limited) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.24.15\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.22.3\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.21.165\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.21.115\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Users\Alex\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.22.5\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.21.111\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Alex\AppData\Local\Google\Update\1.3.24.7\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> C:\Users\UpdatusUser\AppData\Local\Google\Update\1.3.21.99\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> "C:\Users\Alex\AppData\Local\Google\Update\1.3.21.123\GoogleUpdateOnDemand.exe" No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> "C:\Users\Alex\AppData\Local\Google\Update\1.3.21.123\GoogleUpdateOnDemand.exe" No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> "C:\Users\Alex\AppData\Local\Google\Update\1.3.21.123\GoogleUpdateOnDemand.exe" No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> "C:\Users\Alex\AppData\Local\Google\Chrome\Application\24.0.1312.56\delegate_execute.exe" No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\UpdatusUser\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\UpdatusUser\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\UpdatusUser\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\UpdatusUser\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\UpdatusUser\AppData\Local\Google\Update\1.3.21.115\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Users\UpdatusUser\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> "C:\Users\Alex\AppData\Local\Google\Update\1.3.21.123\GoogleUpdateOnDemand.exe" No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\UpdatusUser\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File CustomCLSID: HKU\S-1-5-21-399720636-3795779118-2281500929-1004_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\UpdatusUser\AppData\Local\Google\Update\1.3.21.111\psuser.dll No File ==================== Restore Points ========================= 06-12-2014 17:49:30 Windows Update 11-12-2014 19:15:31 Windows Update 13-12-2014 14:42:30 Windows Update 13-12-2014 18:47:02 Installiert Assassin's Creed Revelations 17-12-2014 22:19:49 Windows Update 23-12-2014 14:41:17 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {03366435-F4A8-4E72-9EE4-8A53A233EEC1} - System32\Tasks\{73D10A2D-BA5D-45AF-B934-9DDE978A8B78} => C:\Users\Alex\Desktop\Fruity_Loops_Studio_9___Crack\Fruity_Loops_Studio_9___Crack\Fruity_Loops_Studio_9_&_Crack\flstudio_9.0_final.exe Task: {11F73BDF-8AA6-4738-996F-8DBB67D97EED} - System32\Tasks\{CCA6CE70-362F-4BD8-A9A2-7F2C1ECFEBE3} => C:\Program Files\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-06-07] () Task: {1D9761BD-5FB2-4D21-ABCB-20678909A634} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION Task: {3F98832D-2747-42E7-8CF7-4D5D2C7C8B80} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION Task: {426A5735-BF37-4BB1-8631-7E31DE716357} - System32\Tasks\{8888EAAC-A41A-4C6B-9B47-8FC46A0C18C1} => C:\Users\Alex\Desktop\Fruity_Loops_Studio_9___Crack\Fruity_Loops_Studio_9___Crack\Fruity_Loops_Studio_9_&_Crack\flstudio_9.0_final.exe Task: {629B525C-BBBA-42A9-B326-0E087F602C06} - System32\Tasks\{31B2D215-F700-43A6-B658-B394F7BA2520} => C:\Program Files\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-06-07] () Task: {8F829AA8-E1D3-402E-8DCA-73EED0CB1BF7} - System32\Tasks\{883579F9-8B5F-495F-A8ED-46BF39B6EA99} => C:\Program Files\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-06-07] () Task: {9A51D7EC-6C4C-4BCA-B5CA-085835E9A3AB} - System32\Tasks\{9BC66623-2BF4-4A13-875B-C278CF14F4A4} => pcalua.exe -a C:\Users\Alex\Documents\Downloads\Integrated_CT2325506.exe -d C:\Users\Alex\Documents\Downloads Task: {9C09D87A-3A1C-4FC6-9116-962B676C2B93} - System32\Tasks\{5B8703DE-321A-45A3-BA92-D04E3E667F55} => pcalua.exe -a E:\setup.exe -d E:\ Task: {A8DDB5EE-628A-45EC-8725-B6418B6BCCC9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-399720636-3795779118-2281500929-1001UA => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-26] (Google Inc.) Task: {ADDC42F2-E11F-4A7F-A287-FB4AAD6A1D6A} - System32\Tasks\{4EB7F8E8-4295-4974-8AF5-DE8F31A02BF9} => C:\Program Files\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-06-07] () Task: {BD38D855-1C4B-468C-87F1-3C44628F1F19} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-399720636-3795779118-2281500929-1001Core => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-26] (Google Inc.) Task: {D5EA5ED6-6471-48F0-B4E0-A11FA11696D2} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-399720636-3795779118-2281500929-1001UA => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-10-13] (Facebook Inc.) Task: {E525AD90-8FC3-4C40-B6DF-E0EB2F107592} - System32\Tasks\{F0AB7A7A-3787-4B39-B9E9-7C957EAD7E02} => C:\Users\Alex\Desktop\Fruity_Loops_Studio_9___Crack\Fruity_Loops_Studio_9___Crack\Fruity_Loops_Studio_9_&_Crack\flstudio_9.0_final.exe Task: {FC7DEDC0-12E0-41CB-8D02-886ACC321F55} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-399720636-3795779118-2281500929-1001Core => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-10-13] (Facebook Inc.) Task: {FDBEE44D-F854-4ED4-9F32-9FB8BC3D927B} - \Adobe Flash Player Updater No Task File <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-399720636-3795779118-2281500929-1001Core.job => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-399720636-3795779118-2281500929-1001UA.job => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-399720636-3795779118-2281500929-1001Core1cf8bb6d614250b.job => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-399720636-3795779118-2281500929-1001Core1cff1411cf161ce.job => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-399720636-3795779118-2281500929-1001Core1d001f89727ec26.job => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-399720636-3795779118-2281500929-1001UA.job => C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-02-02 12:47 - 2012-08-30 16:57 - 00079208 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2012-03-04 15:12 - 2012-02-17 20:55 - 00166912 _____ () C:\Program Files\WinRAR\rarext.dll 2011-07-29 00:08 - 2011-07-29 00:08 - 01259376 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe 2011-07-29 00:09 - 2011-07-29 00:09 - 00096112 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll 2013-02-11 23:22 - 2007-10-23 10:56 - 00200704 _____ () C:\Windows\PLFSetI.exe 2014-10-11 13:06 - 2014-10-11 13:06 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-07-04 14:12 - 2014-12-13 19:09 - 00075136 _____ () C:\Windows\system32\PnkBstrA.exe 2012-04-21 17:52 - 2005-01-14 15:32 - 00053248 _____ () C:\Windows\System32\PAStiSvc.exe 2012-02-26 19:14 - 2012-02-26 19:14 - 00052224 _____ () C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2012-02-26 19:14 - 2014-12-24 14:17 - 00065024 _____ () C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll 2012-02-26 19:14 - 2014-12-24 14:17 - 00052736 _____ () C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll 2012-02-26 19:14 - 2012-02-26 19:14 - 00117760 _____ () C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2014-12-13 14:54 - 2014-12-06 02:50 - 01077064 _____ () C:\Users\Alex\AppData\Local\Google\Chrome\Application\39.0.2171.95\libglesv2.dll 2014-12-13 14:54 - 2014-12-06 02:50 - 00211272 _____ () C:\Users\Alex\AppData\Local\Google\Chrome\Application\39.0.2171.95\libegl.dll 2014-12-13 14:54 - 2014-12-06 02:50 - 09009480 _____ () C:\Users\Alex\AppData\Local\Google\Chrome\Application\39.0.2171.95\pdf.dll 2014-12-13 14:54 - 2014-12-06 02:50 - 01677128 _____ () C:\Users\Alex\AppData\Local\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll 2014-12-13 14:54 - 2014-12-06 02:50 - 14913352 _____ () C:\Users\Alex\AppData\Local\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: Hamachi2Svc => 2 MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start ========================= Accounts: ========================== Administrator (S-1-5-21-399720636-3795779118-2281500929-500 - Administrator - Disabled) Alex (S-1-5-21-399720636-3795779118-2281500929-1001 - Administrator - Enabled) => C:\Users\Alex Gast (S-1-5-21-399720636-3795779118-2281500929-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-399720636-3795779118-2281500929-1002 - Limited - Enabled) UpdatusUser (S-1-5-21-399720636-3795779118-2281500929-1004 - Limited - Enabled) => C:\Users\UpdatusUser ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/16/2014 05:28:56 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6333 Error: (12/16/2014 05:28:56 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6333 Error: (12/16/2014 05:28:56 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (12/16/2014 05:28:55 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5335 Error: (12/16/2014 05:28:55 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5335 Error: (12/16/2014 05:28:55 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (12/16/2014 05:28:54 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4321 Error: (12/16/2014 05:28:54 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 4321 Error: (12/16/2014 05:28:54 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (12/16/2014 05:28:53 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 3307 System errors: ============= Error: (12/24/2014 02:39:22 PM) (Source: cdrom) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (12/24/2014 02:15:44 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (12/24/2014 02:15:37 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Avira Service Host erreicht. Error: (12/23/2014 02:33:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SBSD Security Center Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/23/2014 02:33:01 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SBSD Security Center Service erreicht. Error: (12/23/2014 02:32:29 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Avira Service Host erreicht. Error: (12/23/2014 02:33:15 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (12/21/2014 01:59:50 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (12/21/2014 01:59:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SBSD Security Center Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/21/2014 01:59:31 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SBSD Security Center Service erreicht. Microsoft Office Sessions: ========================= Error: (12/16/2014 05:28:56 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6333 Error: (12/16/2014 05:28:56 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6333 Error: (12/16/2014 05:28:56 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (12/16/2014 05:28:55 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5335 Error: (12/16/2014 05:28:55 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5335 Error: (12/16/2014 05:28:55 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (12/16/2014 05:28:54 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4321 Error: (12/16/2014 05:28:54 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 4321 Error: (12/16/2014 05:28:54 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (12/16/2014 05:28:53 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 3307 ==================== Memory info =========================== Processor: Pentium(R) Dual-Core CPU T4400 @ 2.20GHz Percentage of memory in use: 51% Total physical RAM: 3066.93 MB Available physical RAM: 1497.35 MB Total Pagefile: 6132.15 MB Available Pagefile: 3720.84 MB Total Virtual: 2047.88 MB Available Virtual: 1900.64 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.75 GB) (Free:21.37 GB) NTFS Drive f: (System Reserved) (Fixed) (Total:0.34 GB) (Free:0.11 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 11721172) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=297.7 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Ich bin dann mal gespannt auf eure Antworten. Danke im Voraus! Frohes Fest, extation |
24.12.2014, 17:06 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7 Bootvorgang bricht ständig ab! Anleitung / Hilfe Hallo und
__________________Zitat:
Lesestoff: Illegale Software: Cracks, Keygens und Co Bitte lesen => http://www.trojaner-board.de/95393-c...-software.html Es geht weiter wenn du alles Illegale entfernt hast. Bei wiederholten Crack/Keygen Verstößen behalte ich es mir vor, den Support einzustellen, d.h. Hilfe nur noch bei der Datensicherung und Neuinstallation des Betriebssystems.
__________________ |
Themen zu Windows 7 Bootvorgang bricht ständig ab! |
antivir, antivirus, avira, bonjour, bootabbruch, browser, converter, cubase, dvdvideosoft ltd., festplatte, flash player, google, homepage, iexplore.exe, installation, mozilla, mp3, newtab, problem, realtek, registry, safer networking, scan, security, server, software, svchost.exe, system, usb, windows, windows 7 32 bit |