|
Log-Analyse und Auswertung: Windows 8.1: Fenster blinken und bei Videos erscheint immer wieder die Playleiste trotz keiner MausbewegungWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
01.05.2015, 18:03 | #1 |
| Windows 8.1: Fenster blinken und bei Videos erscheint immer wieder die Playleiste trotz keiner Mausbewegung Hallo, das Problem hab ich schon länger und es nervt nun auch langsam wirklich. Wenn ich ein Video gucke egal ob auf YT oder anderen Seiten erscheint irgendwann immer wieder die Playleiste geht kurz weg und kommt wieder bis ich die Maus bewege dann funktioniert es wieder für ein paar Minuten bis es wieder von vorne los geht. Was mir auch aufgefallen ist, ist das wenn ich die Maus länger nicht benutze und ein Fenster offen habe dass dann weiß/blau blinkt bis ich sie wieder bewege dann ist es wieder normal. Fehler an Maus und Tastatur kann ich ausschließen. Ich benutze Wirless bei beidem und hab schon beide sowohl ausgemacht als auch den USB-Empfänger raus genommen. Andere Geräte habe ich nicht in Benutzung die irgendwas machen könnten. Was mir dazu noch auffällt ist das das Ladesymbol bei der Maus immer ganz kurz aufblinkt im 5 sekunden Takt etwa. Zu anfang ist es ganz normal und nichts passiert aber lasse ich die paar Minuten verstreichen ohne was zu tun blinkt mit dem Ladesymbol auch die Fenster mit und erst bei Mausbewegung geht das blinken wieder weg aber das Mausladesymbol bleibt. Neustart hilft nicht, Bitdefender sowie Malewarebytes haben nichts besonderes Gefunden. Im Taskmanager finde ich auch keine wirkliche ursache für diese kurzen Ladestöße bis auf eine kleine erhöhung von der Prozessurnutzlast von 4-5% auf 14-15% bis sie wieder in den nächsten 2 sekunden wieder unten ist. Neu aufsetzen will ich eigentlich vermeiden aber wenn es nötig ist werde ich es wohl machen. Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-04-2015 01 Ran by Peter (administrator) on PKO on 01-05-2015 18:38:07 Running from C:\Users\Peter\Desktop Loaded Profiles: Peter & (Available profiles: Peter) Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\LogiAppBroker.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7575768 2014-06-29] (Realtek Semiconductor) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM\...\Run: [ISCT Tray] => C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe [5860656 2014-04-24] (Intel Corporation) HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe [1691112 2015-04-06] (Bitdefender) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.) HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [3468240 2014-08-26] (Micro-Star International) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [Steam] => D:\Program Files (x86)\Steam\Steam.exe [2889408 2015-04-14] (Valve Corporation) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [ACEStream] => C:\Users\Peter\AppData\Roaming\ACEStream\engine\ace_engine.exe [27904 2014-10-14] () HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [Spotify Web Helper] => C:\Users\Peter\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920 2015-04-25] (Spotify Ltd) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [Octoshape Streaming Services] => C:\Users\Peter\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [107800 2011-03-24] (Octoshape ApS) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 5\CyberGhost.exe [410216 2014-11-03] (CyberGhost S.R.L.) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [Bitdefender-Geldbörse-Agent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe [790880 2015-02-24] (Bitdefender) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [Spotify] => C:\Users\Peter\AppData\Roaming\Spotify\Spotify.exe [7168568 2015-04-25] (Spotify Ltd) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\MountPoints2: F - "F:\Start.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\MountPoints2: {1922f9d8-ff38-11e3-beeb-806e6f6e6963} - "F:\Start.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\MountPoints2: {5c056940-5109-11e2-be66-50e549534846} - "G:\pushinst.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\MountPoints2: {5d20c502-570a-11e3-824f-806e6f6e6963} - "F:\Start.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\MountPoints2: {923fd65d-042d-11e3-beab-50e549534846} - "J:\pushinst.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Steam] => D:\Program Files (x86)\Steam\Steam.exe [2889408 2015-04-14] (Valve Corporation) HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ACEStream] => C:\Users\Peter\AppData\Roaming\ACEStream\engine\ace_engine.exe [27904 2014-10-14] () HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Users\Peter\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920 2015-04-25] (Spotify Ltd) HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Octoshape Streaming Services] => C:\Users\Peter\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [107800 2011-03-24] (Octoshape ApS) HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 5\CyberGhost.exe [410216 2014-11-03] (CyberGhost S.R.L.) HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Bitdefender-Geldbörse-Agent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe [790880 2015-02-24] (Bitdefender) HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify] => C:\Users\Peter\AppData\Roaming\Spotify\Spotify.exe [7168568 2015-04-25] (Spotify Ltd) HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: F - "F:\Start.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {1922f9d8-ff38-11e3-beeb-806e6f6e6963} - "F:\Start.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {5c056940-5109-11e2-be66-50e549534846} - "G:\pushinst.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {5d20c502-570a-11e3-824f-806e6f6e6963} - "F:\Start.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {923fd65d-042d-11e3-beab-50e549534846} - "J:\pushinst.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Alternative Flash Player Auto-Updater.lnk [2013-07-25] ShortcutTarget: Alternative Flash Player Auto-Updater.lnk -> C:\Program Files (x86)\Alternative Flash Player Auto-Updater\Alternative Flash Player Auto-Updater.exe (pXc-coding.com) ShellIconOverlayIdentifiers: [__SafeBox1] -> {152C96EB-288E-4EDC-B7C6-D21F8250ADF3} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll [2014-07-04] (Bitdefender) ShellIconOverlayIdentifiers: [__SafeBox2] -> {342DAA0B-D796-460D-8566-901E08A1CCAD} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll [2014-07-04] (Bitdefender) ShellIconOverlayIdentifiers: [__SafeBox3] -> {57595DAE-1AE1-4D97-A49E-67CBB53B52DF} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll [2014-07-04] (Bitdefender) ShellIconOverlayIdentifiers: [__SafeBox4] -> {33816773-98AE-4723-ADE0-EBE54C8B5A67} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll [2014-07-04] (Bitdefender) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-3741966532-150782217-4257482019-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3741966532-150782217-4257482019-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKU\S-1-5-21-3741966532-150782217-4257482019-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/ HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-02-24] (Bitdefender) BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.) BHO-x32: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-02-24] (Bitdefender) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-04-05] (Oracle Corporation) BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-04-05] (Oracle Corporation) Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-02-24] (Bitdefender) Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-02-24] (Bitdefender) DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab Tcpip\Parameters: [DhcpNameServer] 192.168.188.1 FireFox: ======== FF ProfilePath: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default FF SearchEngineOrder.1: FF SelectedSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-17] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-17] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-04-05] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-04-05] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-11-27] (Nero AG) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-04-08] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-04-08] (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files (x86)\Veetle\plugins\npVeetle.dll [2012-01-14] (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files (x86)\Veetle\Player\npvlc.dll [2012-01-14] (Veetle Inc) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3741966532-150782217-4257482019-1001: @acestream.net/acestreamplugin,version=2.0.14 -> C:\Users\Peter\AppData\Roaming\ACEStream\player\npace_plugin.dll [2014-06-13] (Innovative Digital Technologies) FF Plugin HKU\S-1-5-21-3741966532-150782217-4257482019-1001: @octoshape.com/Octoshape Streaming Services,version=1.0 -> C:\Users\Peter\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll [2011-03-23] (Octoshape ApS) FF Plugin HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @acestream.net/acestreamplugin,version=2.0.14 -> C:\Users\Peter\AppData\Roaming\ACEStream\player\npace_plugin.dll [2014-06-13] (Innovative Digital Technologies) FF Plugin HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @octoshape.com/Octoshape Streaming Services,version=1.0 -> C:\Users\Peter\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll [2011-03-23] (Octoshape ApS) FF Plugin ProgramFiles/Appdata: C:\Users\Peter\AppData\Roaming\mozilla\plugins\npoctoshape.dll [2013-07-23] (Octoshape ApS) FF Extension: Amazon-Icon - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\amazon-icon@giga.de [2014-07-05] FF Extension: Garmin Communicator - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013-02-17] FF Extension: Sopcast Toolbar - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\toolbar_SPCV7@apn.ask.com.xpi [2013-06-13] FF Extension: 1-Click YouTube Video Downloader - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2013-02-17] FF Extension: Video DownloadHelper - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-05-01] FF Extension: Adblock Plus - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-12-29] FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext FF Extension: Bitdefender Antispam Toolbar - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext [2014-11-27] FF HKLM-x32\...\Firefox\Extensions: [bdwteff@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff [2014-11-27] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-01-18] FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext Chrome: ======= CHR HomePage: Default -> https://de.search.yahoo.com/?type=994519&fr=yo-yhp-ch CHR StartupUrls: Default -> "https://de.search.yahoo.com/?type=994519&fr=yo-yhp-ch", "hxxp://www.giga.de/" CHR Profile: C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-09] CHR Extension: (Google Drive) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-09] CHR Extension: (YouTube) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-09] CHR Extension: (Adblock Plus) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-09] CHR Extension: (Google Search) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-09] CHR Extension: (Bitdefender Wallet) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabcmochhfpldjekobfaaggijgohadih [2014-11-27] CHR Extension: (Bookmark Manager) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-26] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-20] CHR Extension: (Google Wallet) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-09] CHR Extension: (Gmail) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-09] CHR HKLM-x32\...\Chrome\Extension: [fabcmochhfpldjekobfaaggijgohadih] - https://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S4 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed] S3 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2015\bdparentalservice.exe [78144 2015-01-20] (Bitdefender) S4 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2014-12-12] (BitRaider, LLC) S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) S4 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64616 2014-11-03] (CyberGhost S.R.L) R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-06-29] (IvoSoft) [File not signed] S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-06-29] (Creative Labs) [File not signed] R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [File not signed] R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3736520 2015-01-29] (devolo AG) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [209712 2014-04-24] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-17] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) S4 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [1722320 2014-08-26] (Micro-Star International) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [75136 2014-07-13] () R2 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [94624 2013-07-08] (Bitdefender) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448976 2015-04-17] (TeamViewer GmbH) R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2014-10-27] (Bitdefender) R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe [1547936 2015-04-06] (Bitdefender) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) S3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices) [File not signed] R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1306464 2015-02-24] (BitDefender) R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [262544 2015-02-24] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [677104 2015-02-24] (BitDefender) S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender) R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2015-02-24] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC) S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL) S3 BDSandBox; C:\WINDOWS\system32\drivers\bdsandbox.sys [82824 2015-02-24] (BitDefender SRL) R1 BDVEDISK; C:\Windows\system32\DRIVERS\bdvedisk.sys [79192 2013-07-30] (BitDefender) S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2015-03-12] (BitRaider) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-01-13] (Disc Soft Ltd) S3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH) [File not signed] R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [160544 2015-04-06] (BitDefender LLC) R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [22216 2014-02-03] () R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [22728 2014-02-03] () R3 INETMON; C:\WINDOWS\System32\Drivers\INETMON.sys [25800 2014-04-03] () R3 ISCT; C:\Windows\System32\drivers\ISCTD.sys [44744 2014-02-03] () R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-01] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-17] (Intel Corporation) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2015-01-29] (CACE Technologies) S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [14136 2010-10-22] (MSI) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) S3 RivaTuner64; C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [19952 2013-12-29] () S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) R3 XSplit_Dummy; C:\Windows\system32\drivers\xspltspk.sys [26200 2014-07-02] (SplitmediaLabs Limited) S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation) S2 AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X] S2 AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-01 18:38 - 2015-05-01 18:38 - 00030629 _____ () C:\Users\Peter\Desktop\FRST.txt 2015-05-01 18:38 - 2015-05-01 18:38 - 00000000 ____D () C:\FRST 2015-05-01 18:36 - 2015-05-01 18:36 - 02101248 _____ (Farbar) C:\Users\Peter\Desktop\FRST64.exe 2015-05-01 18:35 - 2015-05-01 18:35 - 00050477 _____ () C:\Users\Peter\Desktop\Defogger.exe 2015-05-01 18:35 - 2015-05-01 18:35 - 00000542 _____ () C:\Users\Peter\Desktop\defogger_disable.log 2015-05-01 18:35 - 2015-05-01 18:35 - 00000168 _____ () C:\Users\Peter\defogger_reenable 2015-05-01 16:39 - 2015-05-01 16:59 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-05-01 16:38 - 2015-05-01 16:38 - 00001114 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-05-01 16:38 - 2015-05-01 16:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-05-01 16:38 - 2015-05-01 16:38 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-05-01 16:38 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2015-05-01 16:38 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2015-05-01 16:38 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2015-05-01 16:37 - 2015-05-01 16:38 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Peter\Downloads\mbam-setup-2.1.6.1022.exe 2015-05-01 16:13 - 2015-05-01 16:13 - 00243592 _____ () C:\Users\Peter\Downloads\Firefox Setup Stub 37.0.2.exe 2015-05-01 16:12 - 2015-05-01 16:12 - 00000000 ____D () C:\Users\Peter\AppData\Temp 2015-05-01 15:10 - 2015-05-01 16:50 - 00203894 _____ () C:\WINDOWS\PFRO.log 2015-05-01 15:02 - 2015-01-06 05:01 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys 2015-05-01 15:02 - 2015-01-06 04:59 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys 2015-05-01 15:02 - 2015-01-06 03:12 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascfg.dll 2015-05-01 15:02 - 2015-01-06 03:02 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rascfg.dll 2015-05-01 15:01 - 2015-03-20 03:56 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys 2015-05-01 15:01 - 2015-03-17 19:26 - 00467776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2015-05-01 15:01 - 2015-03-13 04:49 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2015-05-01 15:01 - 2015-03-13 04:28 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2015-05-01 15:01 - 2015-03-09 04:02 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys 2015-05-01 15:00 - 2015-04-03 02:35 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll 2015-05-01 15:00 - 2015-04-03 02:14 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll 2015-05-01 15:00 - 2015-04-02 00:22 - 02985984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2015-05-01 15:00 - 2015-04-02 00:20 - 04417536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2015-05-01 15:00 - 2015-04-01 05:45 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll 2015-05-01 15:00 - 2015-04-01 04:31 - 01207296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll 2015-05-01 15:00 - 2015-03-14 04:03 - 04179968 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2015-05-01 15:00 - 2015-03-13 06:03 - 00239424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2015-05-01 15:00 - 2015-03-13 06:03 - 00154432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2015-05-01 15:00 - 2015-03-13 04:59 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2015-05-01 15:00 - 2015-03-13 04:38 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2015-05-01 15:00 - 2015-03-13 04:02 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys 2015-05-01 15:00 - 2015-03-13 03:11 - 02162176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2015-05-01 15:00 - 2015-03-13 02:39 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2015-05-01 15:00 - 2015-03-13 02:29 - 00410017 _____ () C:\WINDOWS\system32\ApnDatabase.xml 2015-05-01 15:00 - 2015-03-11 03:49 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe 2015-05-01 15:00 - 2015-03-11 03:09 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe 2015-05-01 15:00 - 2015-03-06 05:08 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll 2015-05-01 15:00 - 2015-03-06 04:47 - 01696256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2015-05-01 15:00 - 2015-03-06 04:43 - 01969664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll 2015-05-01 15:00 - 2015-03-04 03:32 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2015-05-01 15:00 - 2015-03-04 03:12 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2015-05-01 15:00 - 2015-02-18 01:19 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2015-05-01 15:00 - 2015-02-13 04:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2015-05-01 15:00 - 2015-02-13 03:46 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2015-05-01 15:00 - 2015-01-30 02:53 - 02819584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll 2015-04-29 19:59 - 2015-04-29 19:59 - 00000000 ____D () C:\Program Files\Rockstar Games 2015-04-29 19:59 - 2015-04-29 19:59 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games 2015-04-29 19:58 - 2015-04-29 19:58 - 00000000 ____D () C:\Users\Peter\AppData\Local\Rockstar Games 2015-04-29 19:57 - 2015-04-29 19:57 - 00000000 ____D () C:\Users\Peter\Documents\Rockstar Games 2015-04-27 21:35 - 2015-05-01 16:50 - 00001424 _____ () C:\WINDOWS\setupact.log 2015-04-27 21:35 - 2015-04-27 21:35 - 00000000 _____ () C:\WINDOWS\setuperr.log 2015-04-26 21:54 - 2015-04-26 21:54 - 00012080 _____ () C:\Users\Peter\AppData\Local\recently-used.xbel 2015-04-26 09:41 - 2015-04-26 09:41 - 00088330 _____ () C:\Users\Peter\Downloads\[kickass.to]grand.theft.auto.v.gta.5.v1.0.331.1.crack.v3.multi11.fitgirl.ultra.repack.torrent 2015-04-17 00:25 - 2015-03-23 23:59 - 07476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2015-04-17 00:25 - 2015-03-23 23:59 - 01733952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2015-04-17 00:25 - 2015-03-23 23:59 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll 2015-04-17 00:25 - 2015-03-23 23:58 - 01498872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2015-04-17 00:25 - 2015-03-23 23:45 - 00257216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll 2015-04-17 00:25 - 2015-03-20 06:12 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll 2015-04-17 00:25 - 2015-03-20 06:10 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll 2015-04-17 00:25 - 2015-03-20 06:10 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll 2015-04-17 00:25 - 2015-03-20 05:17 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\tracerpt.exe 2015-04-17 00:25 - 2015-03-20 04:41 - 00369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tracerpt.exe 2015-04-17 00:25 - 2015-03-20 04:40 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll 2015-04-17 00:25 - 2015-03-20 04:16 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll 2015-04-17 00:25 - 2015-03-13 06:32 - 24980480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-04-17 00:25 - 2015-03-13 06:08 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2015-04-17 00:25 - 2015-03-13 06:07 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-04-17 00:25 - 2015-03-13 05:53 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-04-17 00:25 - 2015-03-13 05:50 - 06025216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2015-04-17 00:25 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-04-17 00:25 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2015-04-17 00:25 - 2015-03-13 05:26 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2015-04-17 00:25 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-04-17 00:25 - 2015-03-13 05:17 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2015-04-17 00:25 - 2015-03-13 05:16 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-04-17 00:25 - 2015-03-13 05:08 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2015-04-17 00:25 - 2015-03-13 05:07 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2015-04-17 00:25 - 2015-03-13 05:00 - 14397440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-04-17 00:25 - 2015-03-13 04:58 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll 2015-04-17 00:25 - 2015-03-13 04:50 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2015-04-17 00:25 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2015-04-17 00:25 - 2015-03-13 04:45 - 02358784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-04-17 00:25 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2015-04-17 00:25 - 2015-03-13 04:37 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll 2015-04-17 00:25 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-04-17 00:25 - 2015-03-13 04:33 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-04-17 00:25 - 2015-03-13 04:22 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2015-04-17 00:25 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-04-17 00:25 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-04-17 00:25 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-04-17 00:24 - 2015-03-04 12:25 - 00377152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2015-04-17 00:24 - 2015-03-04 05:04 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll 2015-04-17 00:24 - 2015-03-04 04:19 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clfsw32.dll 2015-04-17 00:24 - 2015-02-24 10:32 - 00991552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys 2015-04-14 00:53 - 2015-04-08 22:32 - 00560968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe 2015-04-14 00:50 - 2015-04-09 02:58 - 31570064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 30397072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 25375048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 24053576 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 15716232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 14006752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 12852784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 11380728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 10423952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys 2015-04-14 00:50 - 2015-04-09 02:58 - 02896528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 02573456 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 01895568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435012.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 01557648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435012.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 01086424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 01047368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 01037640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00970568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00962192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00927440 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00849552 _____ () C:\WINDOWS\system32\nvmcumd.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00499344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00402576 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00390472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00346256 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00175880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00154256 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00150648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll 2015-04-12 22:31 - 2015-03-23 00:45 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 01111552 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 00769024 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2015-04-12 22:31 - 2015-03-14 10:54 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2015-04-12 22:31 - 2015-03-14 03:56 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2015-04-12 22:31 - 2015-03-14 03:56 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2015-04-12 22:31 - 2015-03-14 03:51 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll 2015-04-12 22:31 - 2015-03-14 03:37 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll 2015-04-12 22:31 - 2015-03-14 03:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2015-04-12 22:31 - 2015-03-14 02:22 - 03678720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2015-04-12 22:31 - 2015-03-14 02:12 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll 2015-04-12 22:31 - 2015-03-14 02:12 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe 2015-04-12 22:31 - 2015-03-14 02:09 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2015-04-12 22:31 - 2015-03-14 02:08 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 2015-04-12 22:31 - 2015-03-14 02:08 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2015-04-12 22:31 - 2015-03-14 02:06 - 02373632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 2015-04-12 22:31 - 2015-03-14 02:06 - 00891392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2015-04-12 22:31 - 2015-03-14 02:02 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll 2015-04-12 22:31 - 2015-03-14 02:02 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe 2015-04-12 22:31 - 2015-03-14 01:59 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2015-04-12 22:31 - 2015-03-14 01:59 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2015-04-12 22:31 - 2015-02-21 01:49 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll 2015-04-12 20:09 - 2013-09-24 12:10 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr70.dll 2015-04-12 20:05 - 2015-04-25 21:28 - 00000300 _____ () C:\WINDOWS\Tasks\DLL-Files.Com Fixer_Updates.job 2015-04-12 20:05 - 2015-04-25 21:28 - 00000292 _____ () C:\WINDOWS\Tasks\DLL-Files FixerASKUSER.job 2015-04-12 20:05 - 2015-04-25 21:28 - 00000284 _____ () C:\WINDOWS\Tasks\DLL-Files.Com Fixer_MONTHLY.job 2015-04-12 20:05 - 2015-04-12 23:16 - 00003116 _____ () C:\WINDOWS\System32\Tasks\RDReminder 2015-04-12 20:05 - 2015-04-12 23:16 - 00003012 _____ () C:\WINDOWS\System32\Tasks\DLL-Files.Com Fixer_Updates 2015-04-12 20:05 - 2015-04-12 23:16 - 00002998 _____ () C:\WINDOWS\System32\Tasks\DLL-Files.Com Fixer_MONTHLY 2015-04-12 20:05 - 2015-04-12 20:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dll-Files Fixer 2015-04-12 20:05 - 2015-04-12 20:07 - 00000000 ____D () C:\Program Files (x86)\Dll-Files.com Fixer 2015-04-12 20:05 - 2015-04-12 20:05 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70.dll 2015-04-12 20:05 - 2015-04-12 20:05 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\dll-files.com 2015-04-12 20:05 - 2015-02-17 11:20 - 00021040 _____ (Dll-Files.com) C:\WINDOWS\system32\roboot64.exe 2015-04-12 20:04 - 2005-03-26 12:42 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70.dll 2015-04-12 20:02 - 2015-04-12 20:11 - 00000000 ____D () C:\Users\Peter\Desktop\FMXML 2015-04-12 18:11 - 2015-04-27 00:39 - 00000000 ____D () C:\Users\Peter\.thumbnails 2015-04-12 18:11 - 2015-04-12 22:47 - 00000000 ____D () C:\Users\Peter\AppData\Local\gtk-2.0 2015-04-12 18:09 - 2015-04-26 23:52 - 00000000 ____D () C:\Users\Peter\.gimp-2.8 2015-04-12 18:09 - 2015-04-12 18:09 - 00000773 _____ () C:\Users\Public\Desktop\GIMP 2.lnk 2015-04-12 18:09 - 2015-04-12 18:09 - 00000773 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2015-04-12 18:09 - 2015-04-12 18:09 - 00000000 ____D () C:\Users\Peter\AppData\Local\gegl-0.2 2015-04-06 20:45 - 2015-04-06 20:45 - 00160544 _____ (BitDefender LLC) C:\WINDOWS\system32\Drivers\gzflt.sys 2015-04-05 20:34 - 2015-04-12 14:39 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Skype 2015-04-05 20:34 - 2015-04-05 20:34 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ___SD () C:\WINDOWS\SysWOW64\GWX 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ___SD () C:\WINDOWS\system32\GWX 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ____D () C:\Users\Peter\AppData\Local\Skype 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ____D () C:\ProgramData\Skype 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-04-05 20:22 - 2015-03-14 10:20 - 01385256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2015-04-05 20:22 - 2015-03-14 10:13 - 01124352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2015-04-05 20:11 - 2015-04-05 20:11 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\AVG 2015-04-05 20:11 - 2015-04-05 20:11 - 00000000 ____D () C:\Users\Peter\AppData\Local\Avg 2015-04-05 20:11 - 2015-04-05 20:11 - 00000000 ____D () C:\Program Files (x86)\AVG 2015-04-05 20:10 - 2015-05-01 15:26 - 00000000 ____D () C:\ProgramData\AVG 2015-04-05 20:07 - 2015-05-01 15:10 - 00349856 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2015-04-05 09:39 - 2015-04-05 09:39 - 00000000 ____D () C:\Users\Peter\AppData\Local\Funcom 2015-04-05 01:03 - 2015-04-05 01:03 - 00000222 _____ () C:\Users\Peter\Desktop\The Secret World.url ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-01 18:35 - 2013-11-27 04:27 - 00000000 ____D () C:\Users\Peter 2015-05-01 18:23 - 2013-11-27 04:30 - 01313495 _____ () C:\WINDOWS\WindowsUpdate.log 2015-05-01 18:16 - 2012-12-29 02:54 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-05-01 18:15 - 2012-12-28 18:26 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3741966532-150782217-4257482019-1001 2015-05-01 18:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-05-01 16:57 - 2013-09-30 06:14 - 01804092 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-05-01 16:57 - 2013-09-30 05:56 - 00774346 _____ () C:\WINDOWS\system32\perfh007.dat 2015-05-01 16:57 - 2013-09-30 05:56 - 00163568 _____ () C:\WINDOWS\system32\perfc007.dat 2015-05-01 16:50 - 2014-06-29 05:18 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-05-01 16:50 - 2014-04-09 00:12 - 00001122 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-05-01 16:50 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\System 2015-05-01 16:50 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-05-01 16:40 - 2014-09-01 10:18 - 00000365 _____ () C:\Users\Peter\AppData\Roaming\XKJSF 2015-05-01 16:30 - 2014-11-14 17:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-05-01 16:30 - 2012-12-28 19:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-05-01 16:22 - 2015-02-15 18:49 - 00000000 ____D () C:\Program Files (x86)\WinRAR 2015-05-01 16:21 - 2014-07-24 21:40 - 00000000 ____D () C:\Program Files (x86)\DivX 2015-05-01 16:21 - 2014-01-27 03:09 - 00000000 ____D () C:\ProgramData\DivX 2015-05-01 16:20 - 2014-01-19 23:09 - 00880128 ___SH () C:\Users\Peter\Desktop\Thumbs.db 2015-05-01 16:14 - 2012-12-28 19:52 - 00001171 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-05-01 16:14 - 2012-12-28 19:52 - 00001159 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-05-01 15:09 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-05-01 15:04 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel 2015-05-01 15:04 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\AdvancedInstallers 2015-05-01 15:03 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-05-01 14:51 - 2013-12-10 13:45 - 00003910 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2510119F-F773-436C-AB90-254EFC0713C7} 2015-05-01 12:58 - 2013-07-22 18:54 - 00000000 ____D () C:\Users\Peter\AppData\Local\Spotify 2015-05-01 12:57 - 2013-02-17 01:56 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Azureus 2015-05-01 11:00 - 2013-07-22 18:53 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Spotify 2015-05-01 05:45 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2015-04-27 19:12 - 2013-07-21 23:34 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\.ACEStream 2015-04-27 19:01 - 2013-10-20 12:34 - 00000000 ____D () C:\Users\Peter\Documents\The Lord of the Rings Online 2015-04-27 19:00 - 2013-03-13 21:43 - 00000000 ____D () C:\Users\Peter\Documents\Sports Interactive 2015-04-27 18:33 - 2015-01-18 15:41 - 00018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys 2015-04-26 21:25 - 2013-02-18 23:39 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\To the Moon - Freebird Games 2015-04-26 19:55 - 2012-12-29 05:08 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\vlc 2015-04-26 17:35 - 2015-02-17 00:23 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\dvdcss 2015-04-26 17:35 - 2013-05-14 02:30 - 00001082 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2015-04-25 21:28 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2015-04-25 10:26 - 2014-12-12 01:38 - 00000983 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-04-25 10:26 - 2014-12-12 01:38 - 00000971 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk 2015-04-25 10:26 - 2012-12-28 19:12 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2015-04-24 23:59 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF 2015-04-22 05:22 - 2013-07-21 23:34 - 00000000 ___HD () C:\_acestream_cache_ 2015-04-19 00:31 - 2013-08-13 17:43 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-04-19 00:29 - 2012-12-28 19:59 - 128913832 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-04-15 00:15 - 2014-03-23 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FMRTE 2015-04-14 01:24 - 2013-08-22 17:38 - 00792056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-04-14 01:24 - 2013-08-22 17:38 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-04-13 00:25 - 2014-12-16 14:05 - 00000000 ____D () C:\Program Files (x86)\a444df1f-4cc8-4e1c-9fdb-aafc21a0799e 2015-04-12 22:31 - 2014-12-12 02:42 - 00000000 ____D () C:\WINDOWS\system32\appraiser 2015-04-12 22:31 - 2014-07-09 21:57 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2015-04-12 14:46 - 2013-12-26 10:59 - 00000000 ____D () C:\Users\Public\Documents\The Witcher 2015-04-12 14:39 - 2014-03-23 19:32 - 00000000 ____D () C:\BraCa Soft 2015-04-09 02:58 - 2015-02-10 14:38 - 12689592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll 2015-04-09 02:58 - 2015-02-10 14:38 - 02935416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2015-04-09 02:58 - 2014-12-24 03:24 - 15818528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll 2015-04-09 02:58 - 2014-10-07 06:41 - 14617288 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll 2015-04-09 02:58 - 2014-06-29 05:17 - 17176128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll 2015-04-09 02:58 - 2014-06-29 05:17 - 03317344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2015-04-09 02:58 - 2014-06-29 05:17 - 00029329 _____ () C:\WINDOWS\system32\nvinfo.pb 2015-04-08 23:30 - 2014-06-29 05:18 - 06841488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2015-04-08 23:30 - 2014-06-29 05:18 - 03478344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2015-04-08 23:30 - 2014-06-29 05:18 - 02558608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2015-04-08 23:30 - 2014-06-29 05:18 - 00936264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2015-04-08 23:30 - 2014-06-29 05:18 - 00385168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2015-04-08 23:30 - 2014-06-29 05:18 - 00062608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2015-04-08 19:52 - 2014-06-29 05:18 - 04336074 _____ () C:\WINDOWS\system32\nvcoproc.bin 2015-04-08 19:22 - 2014-09-04 00:28 - 00000000 ____D () C:\Users\Peter\Desktop\Games 2015-04-06 10:41 - 2013-01-28 07:25 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2015-04-05 20:21 - 2013-10-01 12:53 - 00000000 ____D () C:\ProgramData\Oracle 2015-04-05 20:21 - 2013-10-01 12:53 - 00000000 ____D () C:\Program Files (x86)\Java 2015-04-05 20:20 - 2014-10-26 11:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-04-05 20:20 - 2014-01-18 14:56 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2015-04-05 20:17 - 2014-06-01 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ 2015-04-05 20:17 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep 2015-04-05 20:17 - 2013-05-13 22:43 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2015-04-05 20:17 - 2013-02-17 01:56 - 00000000 ____D () C:\Program Files\Vuze 2015-04-05 20:17 - 2013-01-24 20:53 - 00000000 ____D () C:\ProgramData\Temp 2015-04-05 12:24 - 2015-01-22 16:57 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\HpUpdate 2015-04-05 12:22 - 2014-06-29 05:42 - 00002856 _____ () C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Peter) 2015-04-05 12:22 - 2013-01-08 03:04 - 00003696 _____ () C:\WINDOWS\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2015-04-05 09:39 - 2014-08-10 19:03 - 00000000 ____D () C:\WINDOWS\SysWOW64\directx 2015-04-02 21:31 - 2013-07-22 18:54 - 00001846 _____ () C:\Users\Peter\Desktop\Spotify.lnk 2015-04-02 21:31 - 2013-07-22 18:54 - 00001832 _____ () C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk ==================== Files in the root of some directories ======= 2014-09-01 10:18 - 2014-12-19 21:20 - 0001171 _____ () C:\Users\Peter\AppData\Roaming\DURCKM 2014-09-01 10:18 - 2015-05-01 16:40 - 0000365 _____ () C:\Users\Peter\AppData\Roaming\XKJSF 2013-10-20 12:31 - 2013-10-20 12:31 - 0000093 _____ () C:\Users\Peter\AppData\Local\fusioncache.dat 2015-04-26 21:54 - 2015-04-26 21:54 - 0012080 _____ () C:\Users\Peter\AppData\Local\recently-used.xbel 2014-11-27 22:07 - 2014-11-27 22:07 - 0759571 _____ () C:\ProgramData\1417118063.bdinstall.bin 2015-01-22 16:57 - 2015-01-22 16:57 - 0000057 _____ () C:\ProgramData\Ament.ini Some content of TEMP: ==================== C:\Users\Peter\AppData\Local\Temp\DseShExt-x64.dll C:\Users\Peter\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Peter\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Peter\AppData\Local\Temp\SDShelEx-x64.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-28 07:49 ==================== End Of Log ============================ |
01.05.2015, 18:05 | #2 |
| Windows 8.1: Fenster blinken und bei Videos erscheint immer wieder die Playleiste trotz keiner MausbewegungCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-04-2015 01 Ran by Peter at 2015-05-01 18:38:34 Running from C:\Users\Peter\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3741966532-150782217-4257482019-500 - Administrator - Disabled) ASPNET (S-1-5-21-3741966532-150782217-4257482019-1006 - Limited - Enabled) Gast (S-1-5-21-3741966532-150782217-4257482019-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3741966532-150782217-4257482019-1008 - Limited - Enabled) Peter (S-1-5-21-3741966532-150782217-4257482019-1001 - Administrator - Enabled) => C:\Users\Peter ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Bitdefender Antivirus (Enabled - Up to date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Bitdefender Spyware-Schutz (Enabled - Up to date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) „Der Herr der Ringe Online™“ v1100.0052.1373.8030 (HKLM-x32\...\12bbe590-c890-11d9-9669-0800200c9a66_is1) (Version: 1100.0052.1373.8030 - Turbine, Inc.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) ACE Stream Media 2.0.14 (HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\ACEStream) (Version: 2.0.14 - ACE Stream Media) <==== ATTENTION! ACE Stream Media 2.0.14 (HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\ACEStream) (Version: 2.0.14 - ACE Stream Media) <==== ATTENTION! Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Alternative Flash Player Auto-Updater (HKLM-x32\...\{2FB1052B-2F3D-48CE-A65D-006240516ECE}_is1) (Version: 1.1.0.3 - pXc-coding.com) Assassin's Creed (HKLM-x32\...\Steam App 15100) (Version: - Ubisoft Montreal) Assassin's Creed Brotherhood (HKLM-x32\...\Steam App 48190) (Version: - Ubisoft Montreal) Assassin's Creed II (HKLM-x32\...\Steam App 33230) (Version: - Ubisoft Montreal) AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version: - AVM Berlin) Banished (HKLM-x32\...\Steam App 242920) (Version: - Shining Rock Software LLC) Bitdefender Total Security 2015 (HKLM\...\Bitdefender) (Version: 18.19.0.1369 - Bitdefender) BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC) Borderlands (HKLM-x32\...\Steam App 8980) (Version: - Gearbox Software) Bully: Scholarship Edition (HKLM-x32\...\Steam App 12200) (Version: - Rockstar) Call of Duty (HKLM-x32\...\Steam App 2620) (Version: - Infinity Ward) Call of Duty 2 (HKLM-x32\...\Steam App 2630) (Version: - Infinity Ward) Cheat Engine 6.3 (HKLM-x32\...\Cheat Engine 6.3_is1) (Version: - Cheat Engine) Children of the Nile (HKLM-x32\...\Steam App 17100) (Version: - Tilted Mill) Children of the Nile: Alexandria (HKLM-x32\...\Steam App 17120) (Version: - Tilted Mill) Cities in Motion (HKLM-x32\...\Steam App 73010) (Version: - ) ContinueToSave (HKLM\...\{C41BC1A3-875F-42B4-A05F-CF7D1FF8E355}) (Version: 1.0 - ) Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited) Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.41 - Creative Technology Limited) Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.03 - Creative Technology Limited) CyberGhost 5 (HKLM\...\CyberGhost 5_is1) (Version: - CyberGhost S.R.L.) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd) Dead Island (HKLM-x32\...\Steam App 91310) (Version: - Techland) devolo Cockpit (HKLM-x32\...\dlancockpit) (Version: 4.3.0.0 - devolo AG) Die Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.0.677.20 - Electronic Arts Inc.) Dishonored (HKLM-x32\...\Steam App 205100) (Version: - ) Euro Truck Simulator 2 (HKLM-x32\...\Steam App 227300) (Version: - ) Europa Universalis III (HKLM-x32\...\Steam App 25800) (Version: - Paradox Development Studio) Europa Universalis IV (HKLM-x32\...\Steam App 236850) (Version: - Paradox Development Studio) FMRTE 15.3.0.12 (HKLM\...\{6D986DE6-CA9D-4E83-B49C-18C0BFEB6AD6}_is1) (Version: 15.3.0.12 - FMRTE) Football Manager 2013 Editor (HKLM-x32\...\Steam App 220600) (Version: - Sports Interactive) Football Manager 2014 Editor (HKLM-x32\...\Steam App 242460) (Version: - ) Football Manager 2015 (HKLM-x32\...\Steam App 295270) (Version: - Sports Interactive) Football Manager 2015 Editor (HKLM-x32\...\Steam App 295350) (Version: - ) GamersGoMakers (HKLM-x32\...\Steam App 314320) (Version: - gnifrebel Games UG) GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.135 - Google Inc.) Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.) Hex-Editor MX (HKLM-x32\...\{7FC7AD70-1DF3-4B84-9AA2-4FB680F45572}_is1) (Version: 6.0 - NEXT-Soft) HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard) HP Officejet 6600 - Grundlegende Software für das Gerät (HKLM\...\{F58934BD-F483-43EB-B307-CFFD88B18455}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Officejet 6600 Hilfe (HKLM-x32\...\{2FA81482-5570-4CF0-9A10-D61D2F164916}) (Version: 140.0.2.2 - Hewlett Packard) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (x32 Version: 10.0.20 - Intel(R) Corporation) Hidden Java 8 Update 40 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation) JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) JDownloader 2 (HKLM-x32\...\0630-0716-3135-7887) (Version: 2 - AppWork GmbH) Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech) Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation) MegaTrainer eXperience V1.2.3.6 (HKLM-x32\...\MegaTrainer eXperience_is1) (Version: - ) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Minion (HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\{Minion}}_is1) (Version: 2.0 - ZAM Network LLC) Minion (HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\{Minion}}_is1) (Version: 2.0 - ZAM Network LLC) Mount and Blade Warband - Viking Conquest (HKLM-x32\...\Mount and Blade Warband - Viking Conquest_is1) (Version: - ) Mount&Blade Warband (HKLM-x32\...\Mount&Blade Warband) (Version: - ) Mozilla Firefox 37.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 de)) (Version: 37.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 37.0.2 - Mozilla) MSI Live Update (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.0.009 - MSI) Nero Info (HKLM-x32\...\{B791E0AB-87A9-41A4-8D98-D13C2E37D928}) (Version: 16.0.1006 - Nero AG) Nero Prerequisite Installer 3.0 (HKLM-x32\...\{929FAC65-06DD-4577-882C-E8A558C47B75}) (Version: 15.0.00900 - Nero AG) New Star Soccer 5 (HKLM-x32\...\Steam App 212780) (Version: - New Star Games) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.52.3 - Black Tree Gaming) NVIDIA 3D Vision Controller-Treiber 349.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 349.95 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 350.12 - NVIDIA Corporation) NVIDIA Grafiktreiber 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 350.12 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation) NVIDIA Miracast Virtueller Ton 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 350.12 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.15.0324 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0324 - NVIDIA Corporation) Octoshape Streaming Services (HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Octoshape Streaming Services) (Version: - Octoshape ApS) Octoshape Streaming Services (HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Octoshape Streaming Services) (Version: - Octoshape ApS) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 9.4.22.2815 - Electronic Arts, Inc.) Prerequisite installer (x32 Version: 15.0.0010 - Nero AG) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.23.1126.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.5.8 - Rockstar Games) Roll (HKLM-x32\...\RollerCoaster Tycoon Setup) (Version: - ) RollerCoaster Tycoon: Deluxe (HKLM-x32\...\Steam App 285310) (Version: - Chris Sawyer Productions) Saints Row 2 (HKLM-x32\...\Steam App 9480) (Version: - Volition) Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition) Saints Row: The Third (HKLM-x32\...\Steam App 55230) (Version: - Volition) SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) SopCast 3.8.3 (HKLM-x32\...\SopCast) (Version: 3.8.3 - www.sopcast.com) South Park Der Stab der Wahrheit Update 3 Incl. DLCs MULTI-2 1.00 (HKLM-x32\...\South Park Der Stab der Wahrheit Update 3 Incl. DLCs MULTI-2 1.00) (Version: - ) South Park™: The Stick of Truth™ (HKLM-x32\...\Steam App 213670) (Version: - Obsidian Entertainment) Spacebase DF-9 (HKLM-x32\...\Steam App 246090) (Version: - Double Fine Productions) Spotify (HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Spotify) (Version: 1.0.4.90.g0b6df40b - Spotify AB) Spotify (HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Spotify) (Version: 1.0.4.90.g0b6df40b - Spotify AB) Stalker Complete 2009 (HKLM-x32\...\{Stalker Complete 2009 v1.4.4}}_is1) (Version: - ) Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version: - Bioware/EA) Star Wars: Knights of the Old Republic (HKLM-x32\...\Steam App 32370) (Version: - BioWare) Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.) Starbound (HKLM-x32\...\Steam App 211820) (Version: - ) StreamTorrent 1.0 (HKLM-x32\...\StreamTorrent 1.0) (Version: - ) TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - ) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.41459 - TeamViewer) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) The Forest (HKLM-x32\...\Steam App 242760) (Version: - Endnight Games Ltd) The Secret World (HKLM-x32\...\Steam App 215280) (Version: - Funcom) The Witcher 2: Assassins of Kings Enhanced Edition (HKLM-x32\...\Steam App 20920) (Version: - CD Projekt RED) The Witcher Enhanced Edition (HKLM-x32\...\{F138762F-5A1F-4CF0-A5E1-1588EF6088A4}) (Version: 1.4.5.1280 - CD Projekt Red) Thief Gold (HKLM-x32\...\Steam App 211600) (Version: - Looking Glass Studios) To the Moon (HKLM-x32\...\Steam App 206440) (Version: - ) TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.4000.245 - TuneUp Software) Hidden TWC4: Fight! (HKLM-x32\...\TWC4: Fight!) (Version: - MPire Mall) Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft) UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.) Veetle TV (HKLM-x32\...\Veetle TV) (Version: 0.9.19 - Veetle, Inc) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) Vuze (HKLM\...\8461-7759-5462-8226) (Version: 5.6.0.0 - Azureus Software, Inc.) Watch_Dogs (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft) win8codecs (HKLM-x32\...\{898E81AD-6DB9-4750-866B-B8958C5DC7AA}) (Version: 1.3.5 - Shark007) WinRAR 5.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH) Wrestling MPire Remix (Career) (HKLM-x32\...\Wrestling MPire Remix (Career)) (Version: - MDickie) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 01-05-2015 16:20:43 AVG PC TuneUp 2015 wird entfernt ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {093FEF4C-0C23-4EF6-B9C1-D643D92FCB44} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation) Task: {09F40268-5D36-4BFD-94FA-29D424374B6A} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-03-07] (Oracle Corporation) Task: {0F017FA1-EC96-408F-8E00-C5052C276ECB} - System32\Tasks\RDReminder => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe [2015-02-17] (Dll-FIles.Com) Task: {1B49CE2B-0DA1-4E03-9395-AC4753F1E74F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-09] (Google Inc.) Task: {239C28CE-F903-456F-A067-1C73F3220208} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {28D123F7-83D9-4C81-B29C-28F99330599A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-09] (Google Inc.) Task: {3900460C-B117-4C06-990C-1FBFBB00B2E3} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {3E9DCBCC-905B-4C7E-9EBF-8125D6C78FFC} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {42370B11-A25E-4159-BFA5-23286148F34C} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {498BB0B4-E87F-4DC2-9DCD-84FF51B79AF6} - System32\Tasks\DLL-Files.Com Fixer_Updates => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe [2015-02-17] (Dll-FIles.Com) Task: {4A808E8A-E2C2-4EEA-8CF4-F034550022CF} - \b96f09aa-67ad-4eda-8dbc-30892345d498-4 No Task File <==== ATTENTION Task: {4BBD2E7F-0B8E-45F0-8205-8715B41EBCB8} - \b96f09aa-67ad-4eda-8dbc-30892345d498-7 No Task File <==== ATTENTION Task: {4C5530B0-F53D-4F3A-BFE0-3726C9DBEDDE} - \b96f09aa-67ad-4eda-8dbc-30892345d498-6 No Task File <==== ATTENTION Task: {524222B3-E983-4748-88A4-AC2380DCE9DF} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {6F86512C-2767-4EC8-AB02-B03C1C2527DB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-14] (Adobe Systems Incorporated) Task: {7B7EDFCB-5984-4BD0-9A64-D840F7CFFE89} - System32\Tasks\DLL-Files FixerASKUSER => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe [2015-02-17] (Dll-FIles.Com) Task: {7BEC6DF6-E91E-4D65-B815-6E7EF02B9C4D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-04-19] (Microsoft Corporation) Task: {883324C6-74E4-4EFF-96D2-C0E5AF56BC7D} - System32\Tasks\DivX-Online-Aktualisierungsprogramm => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe Task: {93DD7DF4-9F6B-4DEF-86CE-757E051CD54D} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {9D7B2B66-574B-4403-9E3A-38C707D9C742} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation) Task: {A2467DE2-DFF5-49C8-9294-4D81DCD4B91B} - \b96f09aa-67ad-4eda-8dbc-30892345d498-11 No Task File <==== ATTENTION Task: {B75DAB47-60F4-4B95-B425-F8A4834A3222} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {B9E44182-E179-4CFB-A0A0-A6F3DE280657} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation) Task: {BEB5BF2D-2442-4A9B-8706-D92736EF9F37} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation) Task: {CB76FB70-69FE-47B9-B958-EB1E6EE50BF0} - System32\Tasks\Driver Booster SkipUAC (Peter) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: {D281BCB6-52B0-4D1F-855B-BF7F940DBB3B} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2014-12-11] (Nero AG) Task: {D77BC18D-8DC6-4343-B7BE-A7155A8EED57} - \b96f09aa-67ad-4eda-8dbc-30892345d498-1 No Task File <==== ATTENTION Task: {D9C69C4C-07F5-451F-BE6D-BEFA504F07DC} - \b96f09aa-67ad-4eda-8dbc-30892345d498-2 No Task File <==== ATTENTION Task: {DAA19050-7E04-4BC0-9BCA-0240C1BF80AA} - \b96f09aa-67ad-4eda-8dbc-30892345d498-5 No Task File <==== ATTENTION Task: {E1A796FB-79CA-4D68-870F-C83C8F5AA511} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {E4A8DCD3-600B-403F-9398-4FF865212AB7} - System32\Tasks\DLL-Files.Com Fixer_MONTHLY => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe [2015-02-17] (Dll-FIles.Com) Task: {FAF42F86-229C-49E5-9E3D-1A25551AB46F} - \b96f09aa-67ad-4eda-8dbc-30892345d498-3 No Task File <==== ATTENTION Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\DLL-Files FixerASKUSER.job => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe Task: C:\WINDOWS\Tasks\DLL-Files.Com Fixer_MONTHLY.job => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe Task: C:\WINDOWS\Tasks\DLL-Files.Com Fixer_Updates.job => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2014-11-27 22:05 - 2014-08-27 17:31 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\txmlutil.dll 2014-11-27 22:05 - 2013-09-03 15:29 - 00101328 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdmetrics.dll 2014-11-27 22:05 - 2014-11-19 21:28 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\UI\accessl.ui 2014-11-27 22:05 - 2012-10-29 15:22 - 00152816 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdfwcore.dll 2015-04-20 17:43 - 2015-04-20 17:43 - 00789856 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00250_004\ashttpbr.mdl 2015-04-20 17:43 - 2015-04-20 17:43 - 00710016 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00250_004\ashttpdsp.mdl 2015-04-20 17:43 - 2015-04-20 17:43 - 02683008 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00250_004\ashttpph.mdl 2015-04-20 17:43 - 2015-04-20 17:43 - 01325480 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00250_004\ashttprbl.mdl 2014-06-29 05:18 - 2015-04-08 23:30 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-04-24 12:24 - 2014-04-24 12:24 - 00209712 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe 2014-04-24 12:24 - 2014-04-24 12:24 - 00057648 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll 2014-04-24 12:24 - 2014-04-24 12:24 - 00057648 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTEncryptionCheck.dll 2014-04-24 12:24 - 2014-04-24 12:24 - 00037168 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll 2014-07-13 16:22 - 2014-07-13 16:22 - 00075136 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2014-11-27 22:05 - 2013-03-25 16:16 - 01117920 _____ () C:\Program Files\Bitdefender\Bitdefender SafeBox\System.Data.SQLite.dll 2014-06-29 05:19 - 2015-03-28 05:45 - 00721552 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\gamecaster64.dll 2014-06-29 05:19 - 2015-03-28 05:45 - 00854160 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\twitchsdk64.dll 2015-03-31 06:53 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2014-09-02 15:49 - 2013-09-17 03:20 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2014-11-27 22:05 - 2014-08-27 17:30 - 00204280 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff\components\txmlutil.dll 2014-11-27 22:05 - 2015-02-24 23:07 - 00067808 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff\components\bdwtxff.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Users\Peter\Downloads\Firefox Setup Stub 37.0.2.exe:BDU AlternateDataStreams: C:\Users\Peter\Downloads\mbam-setup-2.1.6.1022.exe:BDU ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, the associated entry will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\Control Panel\Desktop\\Wallpaper -> HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Theme1\img1.jpg DNS Servers: 192.168.188.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "Alternative Flash Player Auto-Updater.lnk" HKLM\...\StartupApproved\Run: => "XboxStat" HKLM\...\StartupApproved\Run32: => "AVMWlanClient" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "ApnTBMon" HKLM\...\StartupApproved\Run32: => "DivXUpdate" HKLM\...\StartupApproved\Run32: => "Live Update" HKLM\...\StartupApproved\Run32: => "HP Software Update" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\StartupApproved\Run: => "icq" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\StartupApproved\Run: => "ACEStream" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\StartupApproved\Run: => "Spotify" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\StartupApproved\Run: => "Spotify Web Helper" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\StartupApproved\Run: => "Octoshape Streaming Services" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\StartupApproved\Run: => "DAEMON Tools Lite" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\StartupApproved\Run: => "CyberGhost" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "icq" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "ACEStream" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Spotify" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Spotify Web Helper" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Octoshape Streaming Services" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "DAEMON Tools Lite" HKU\S-1-5-21-3741966532-150782217-4257482019-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "CyberGhost" ==================== FirewallRules (whitelisted) =============== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe FirewallRules: [{2A5F26EB-AA8E-41E1-852B-FD5AE668778D}] => (Allow) C:\Program Files (x86)\Veetle\Player\VeetleNet.exe FirewallRules: [{A6CADB9D-035D-43EB-AEDE-2901286ADE0B}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{22F9B976-2CF6-424B-8474-C8950EE2360D}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{BFA6D53B-347D-4011-840F-D0C605EBF3FF}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{D9071327-7763-49F6-8DCD-B260AD25CDA0}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{4F02AD75-D206-437F-9FF9-4409F97BF57B}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{0C85FC12-9782-44E3-9338-1041FEC136B6}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{27C537FF-70D0-41B1-8DA7-6DBFABD64D09}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\thief_gold\THIEF.EXE FirewallRules: [{44989320-4158-4439-85BF-50EACB060137}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\thief_gold\THIEF.EXE FirewallRules: [{592E3258-36BB-421F-8C0D-9C66D8986BA0}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\New Star Soccer 5\NSS5.exe FirewallRules: [{BE8F2823-A31F-4ED8-9505-A1291C296643}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\New Star Soccer 5\NSS5.exe FirewallRules: [{B2B56F22-5B82-487F-AB8F-C3CA97EDC974}] => (Allow) C:\Program Files\Vuze\Azureus.exe FirewallRules: [{824DF5B4-0373-4840-A642-8F30C88BC568}] => (Allow) C:\Program Files\Vuze\Azureus.exe FirewallRules: [{F2154ACE-F3A6-4FAE-A623-596F839876B2}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe FirewallRules: [{80775D48-D084-4DF9-8CBF-2CB1ECFFF5B8}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe FirewallRules: [{17B4F2CA-D14E-4788-BCDA-A290915FED80}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Football Manager 2013 Editor\editor.exe FirewallRules: [{B07B22D3-4A2D-4539-8D37-128A783C4349}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Football Manager 2013 Editor\editor.exe FirewallRules: [{A02EB9F6-BF80-4CB7-8229-82E87556ED03}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\dead island\DeadIslandGame.exe FirewallRules: [{03A07461-0E1A-462A-B6F0-EAF822861000}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\dead island\DeadIslandGame.exe FirewallRules: [{60CCB7BC-7A31-41F8-BC9A-CB3CCEBCA824}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe FirewallRules: [{DF5325A0-D668-4307-ACBD-7085DA05B474}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe FirewallRules: [{8691EAB9-4B8D-4D07-9AFC-7DF2E904025C}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Europa Universalis III - Complete\EU3.EXE FirewallRules: [{2CD01460-BE1B-46C3-B825-13A676E10811}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\To the Moon\To the Moon\To the Moon.exe FirewallRules: [{84CE3C16-A6F4-46FA-9A74-3692E3B8B4B2}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\To the Moon\To the Moon\To the Moon.exe FirewallRules: [{102B561D-F5E3-474E-AC9D-BAE4D9BD0A9F}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe FirewallRules: [{01FF6B89-92FB-400E-B2BD-532D5885DBBC}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe FirewallRules: [{CE4F35A8-D5E5-483A-A1E2-77C275E04FBF}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{61967D57-9929-4FD1-BA9F-D996E899D3AF}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{D3A6FAF9-4DDA-4D83-B47D-19D852A81E4A}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\the witcher 2\Launcher.exe FirewallRules: [{E19FB4E5-EC2D-4F46-8F9E-936270B80A61}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\the witcher 2\Launcher.exe FirewallRules: [{9FD9F9B3-8730-4EDD-A8F7-3789506B8085}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\To the Moon\To the Moon\To the Moon.exe FirewallRules: [{84C4810D-9AD2-4A09-8589-7ECFC96E7DE5}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\To the Moon\To the Moon\To the Moon.exe FirewallRules: [{170BAFFE-5E0B-4DC8-AE14-997E8F67385B}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\borderlands\Binaries\Borderlands.exe FirewallRules: [{96EF6D79-5BB0-4449-BED5-CF4411B5125F}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\borderlands\Binaries\Borderlands.exe FirewallRules: [TCP Query User{8F53B7D0-1F4E-4EF0-8454-53FC6E96924F}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\peter\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{EB597144-E0A8-4C4D-9A05-1D7F66407139}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\peter\appdata\roaming\spotify\spotify.exe FirewallRules: [{47280DCF-CE34-46CA-80B5-1C08FBF4EA1E}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Europa Universalis III - Complete\eu3game.exe FirewallRules: [{61F62F1A-79EB-490F-85C1-DA76526E1730}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Europa Universalis III - Complete\eu3game.exe FirewallRules: [{35B52A1E-55C7-4FF6-A3E8-3323DDF012C1}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{787BDF82-ADEC-4520-95A5-40D58824747E}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{79E1B97F-46C3-4E5D-B023-63ABF6B9AEDB}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Banished\Application-steam-x64.exe FirewallRules: [{7B16B3AA-5C2E-4073-9E54-553152C7E16E}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Banished\Application-steam-x64.exe FirewallRules: [{049AFF3C-8161-45F8-B8F1-1575482305ED}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Football Manager 2014 Editor\editor.exe FirewallRules: [{DF969D94-0557-4205-B13E-86C98FE47174}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Football Manager 2014 Editor\editor.exe FirewallRules: [{4CEA6737-07EE-4112-8130-9FF43F873B3A}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe FirewallRules: [{72BD4EA1-EB56-4C4B-94C5-8AEC998BCD56}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe FirewallRules: [{1F5D5BC5-96E4-4266-B080-A767320C6531}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe FirewallRules: [{B39D1BAA-F819-4177-90CD-522009878AA4}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe FirewallRules: [{F1348DDF-77FB-4355-BB2D-11B0D3E0B677}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\RollerCoaster Tycoon Deluxe\RCT.EXE FirewallRules: [{CCA2E8EC-9BDE-4653-B872-40B7F8C30530}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\RollerCoaster Tycoon Deluxe\RCT.EXE FirewallRules: [{EFA62265-69FF-483B-928B-071395A77D0D}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{15E56D69-ABE8-4869-98F8-B3BEF9A7D3A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{C661EE4F-7ABD-4F5C-A5DA-C03713125504}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{68BBCFC1-E2BE-4F92-8EE6-EA44AE0ECEE7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{70D70184-B379-4785-B07E-7FD9D138D68D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{D1E82659-405A-4C24-928F-2AC4D4C53BFA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{25B23818-21E9-489C-B5FF-BD5E344BCD9B}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Assassins Creed\AssassinsCreed_Game.exe FirewallRules: [{73ED9B93-4B75-4C02-8887-EE31546BB1DA}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Assassins Creed\AssassinsCreed_Game.exe FirewallRules: [{95B6CB78-47DA-4E36-97EE-70FD52439F09}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed 2\AssassinsCreedIIGame.exe FirewallRules: [{AC955CF6-7A23-47FF-952D-92CFC52C0B66}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed 2\AssassinsCreedIIGame.exe FirewallRules: [{D5D0A117-A562-47BF-B9A0-293D6F82FF20}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Assassins Creed Brotherhood\ACBSP.exe FirewallRules: [{D818EF74-6DFF-4CDA-BF12-2E9E80E3E2EE}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Assassins Creed Brotherhood\ACBSP.exe FirewallRules: [{5FED4C3B-6D03-4691-A6F5-B907AF35ADF4}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{29DC4C81-9852-4866-B086-1EF4077C72CC}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{CA8DE762-D615-4AF0-9481-44F233CBD217}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{2591920C-0FE4-425D-ABCA-8014B940CF6A}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{7DC236AC-6705-46F1-B922-E5591AD121E9}] => (Allow) D:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{3C1A2057-D415-4AC3-9FC8-B517ACD28256}] => (Allow) D:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{EEE0380D-A9A2-4C2D-BA66-F3AA67062D04}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Call of Duty\CoDSP.exe FirewallRules: [{DFEDA5DE-21BA-4085-9977-F8408751A24A}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Call of Duty\CoDSP.exe FirewallRules: [{6E30483E-01B4-4CC7-9D6B-327FC6F0CF02}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Call of Duty\CoDMP.exe FirewallRules: [{08C8A659-8300-48BB-84BA-73719DBE5718}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Call of Duty\CoDMP.exe FirewallRules: [{8F5673AC-0D42-4679-B053-1A8930B0553E}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 2\CoD2SP_s.exe FirewallRules: [{4F600F1C-3488-4FD5-BC90-4D78D52D6133}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 2\CoD2SP_s.exe FirewallRules: [{0854F704-4E1D-456E-AFAB-34178DF18DEB}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 2\CoD2MP_s.exe FirewallRules: [{D04A5299-DDEC-4B87-AFF3-7742C0222469}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 2\CoD2MP_s.exe FirewallRules: [{05C4CFFF-00C6-4C0F-92A7-6651512A0078}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\GamersGoMakers\ggm.exe FirewallRules: [{C46D15A6-CEA3-4DFC-BC2A-BF74A70EC4AA}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\GamersGoMakers\ggm.exe FirewallRules: [{B805B01F-A04A-4288-8B9F-05493622C49C}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\SpacebaseDF9\Space.exe FirewallRules: [{A375E0FF-94DD-4CFA-A3E0-01C382E2D722}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\SpacebaseDF9\Space.exe FirewallRules: [{EC5A9B10-0958-4931-96D3-0689754773DD}] => (Allow) D:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{BC842E9E-407F-4CB2-BB8A-DAC0531E0824}] => (Allow) D:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{3216D561-CFE8-4335-9C55-8269249F29BA}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\swkotor\swkotor.exe FirewallRules: [{F65BE3C6-5F04-4646-BF6E-DBD1B7050D25}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\swkotor\swkotor.exe FirewallRules: [{EC1F3868-5D6A-4017-A1E2-C53E4C880343}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Europa Universalis IV\eu4.exe FirewallRules: [{6C280584-6D9C-4C20-BC90-E3C18621FAC9}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Europa Universalis IV\eu4.exe FirewallRules: [{6FED90EE-76F4-47DE-9C46-4E0CC5B1E3B3}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Saints Row 2\SR2_pc.exe FirewallRules: [{B3782500-D877-440D-856E-DE00D7CAE54C}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Saints Row 2\SR2_pc.exe FirewallRules: [{6E43B510-F7E8-4EA6-8CB7-1D33C3855A4B}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Saints Row the Third\game_launcher.exe FirewallRules: [{ED3D5B2D-B9F0-4789-AB80-2CDCA0CE460A}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Saints Row the Third\game_launcher.exe FirewallRules: [{C44CE675-52F6-4CC7-BFF5-D36A27DE7A3C}] => (Allow) E:\Program Files (x86)\Electronic Arts\BioWare\Star Wars-The Old Republic\launcher.exe FirewallRules: [{49CA90F3-8BCA-45A0-9D0F-3D35DF651981}] => (Allow) E:\Program Files (x86)\Electronic Arts\BioWare\Star Wars-The Old Republic\launcher.exe FirewallRules: [{6DD03EB5-F5A6-42D9-9385-26E025207648}] => (Allow) E:\Program Files (x86)\Electronic Arts\BioWare\Star Wars-The Old Republic\launcher.exe FirewallRules: [{C1303D7E-0301-4BD7-B879-F26A4A6CBE64}] => (Allow) E:\Program Files (x86)\Electronic Arts\BioWare\Star Wars-The Old Republic\launcher.exe FirewallRules: [{F3807C04-31EE-4A27-BC3C-DF10C8544AE3}] => (Allow) C:\Program Files\HP\HP Officejet 6600\bin\FaxApplications.exe FirewallRules: [{4F3D2958-0193-48BD-B295-AB5399F9CFD3}] => (Allow) C:\Program Files\HP\HP Officejet 6600\bin\DigitalWizards.exe FirewallRules: [{BD3DED28-A67A-44B3-9938-FBAA8A147779}] => (Allow) C:\Program Files\HP\HP Officejet 6600\bin\SendAFax.exe FirewallRules: [{2DDEF536-8B7C-4FB1-BB2A-0738299AD8C3}] => (Allow) C:\Program Files\HP\HP Officejet 6600\Bin\DeviceSetup.exe FirewallRules: [{3E38AC43-D443-48F9-B281-5ED8548F7778}] => (Allow) C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe FirewallRules: [{D6A86408-D063-4AFB-BC5C-65D468F02E57}] => (Allow) C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{505C2A6F-B2DD-4576-A800-80B5B1C858BA}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{F1A5A423-3D65-427F-99F8-119E8ADD18AA}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{C6442E3D-4DBA-4241-9A25-C3ED4E5DAF81}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe FirewallRules: [{5A8FB8E1-3CCE-437E-87FF-DC9C96154D64}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{AB21B7F4-F4F4-4DEB-A8A9-C4F23B094572}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{FCB28799-C105-4AF4-BC39-1B968CF6F0F7}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Football Manager 2015\fm.exe FirewallRules: [{66BA0459-5D50-4698-9928-CE0DC3862053}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Football Manager 2015\fm.exe FirewallRules: [{C97A6AAA-C055-4427-AB49-D31048AAF857}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Football Manager 2015 Editor\editor.exe FirewallRules: [{DC255BF1-9762-4A1A-BC33-D18ABF3389B9}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Football Manager 2015 Editor\editor.exe FirewallRules: [{E8F2CD26-C3E8-499A-9AEE-3388AD486502}] => (Allow) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe FirewallRules: [{EDE88109-E6AB-4B34-A436-B314CA0CF57F}] => (Allow) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe FirewallRules: [{A7F27513-C299-4096-8CFC-879C9F5FECEB}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{9D443E9E-8841-47F2-BC25-1398AF8B8BC3}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{48680E27-99A5-49EF-A19A-B3828EE8E9D5}] => (Allow) C:\Program Files\Vuze\Azureus.exe FirewallRules: [{FCFAFC71-9514-4A54-97B8-6F4D71720443}] => (Allow) C:\Program Files\Vuze\Azureus.exe FirewallRules: [{AD8BDE85-414A-4F73-8EE4-6726C141349F}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe FirewallRules: [{47637B78-CC25-418E-8192-3B97F88BDCD5}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe FirewallRules: [{0D0A156E-FB43-4358-BEB6-5BDDF28DA35E}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe FirewallRules: [{11D5A556-945E-4855-84DB-2153E47614DC}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe FirewallRules: [{6C11D367-4C37-4579-8916-65C4DFAEABBB}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe FirewallRules: [{D582011E-E1C5-446C-AE8C-D4B2AFA8E4D5}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe FirewallRules: [{BE103EE3-055C-4E78-881B-DA27D789B0AC}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{843CE1D4-66D3-4349-B4A2-1F72E3C27187}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{0166D53E-4045-4962-BFBA-F6A61E5F1501}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{D4A54D73-78CC-42EE-B226-093F8805C14A}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{69B8F5F6-6DEE-46EB-A7E1-C90F547A5FCB}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\To the Moon\Minisode_1\Sigmund Holiday Special 1\Siggy - Holiday Special.exe FirewallRules: [{6762AF20-7A00-4FF6-BC09-929E2F814BFB}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\To the Moon\Minisode_1\Sigmund Holiday Special 1\Siggy - Holiday Special.exe FirewallRules: [{69E4D139-0625-47BF-ACA7-0F8586E50B1F}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\To the Moon\Minisode_2\Sigmund Holiday Special 2\SigCorp Minisode 2.exe FirewallRules: [{117CB96D-1B4E-4B66-929D-04039091076F}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\To the Moon\Minisode_2\Sigmund Holiday Special 2\SigCorp Minisode 2.exe FirewallRules: [{55D35465-EB65-4E10-88B2-2461BD1C2D4B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{B84BFB17-EDD4-45F5-99A7-6BFA7A0AF94F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{A5B4C275-F2E0-4C7C-8661-1D313001F8DC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{B28BB436-0137-4BB6-9C8C-2D12A13BEB58}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{6A61EA0E-F527-476F-9EE6-7B5DF03792FD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{8726E924-3EF6-4D9B-A07E-903BC3B8359E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{50BE7252-1D7A-4E25-B298-92D7001F9E89}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/01/2015 06:38:44 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004e920f ID des fehlerhaften Prozesses: 0x184c Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0 Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1 Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2 Berichtskennung: NvStreamNetworkService.exe3 Vollständiger Name des fehlerhaften Pakets: NvStreamNetworkService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NvStreamNetworkService.exe5 Error: (05/01/2015 06:38:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004e920f ID des fehlerhaften Prozesses: 0x17a8 Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0 Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1 Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2 Berichtskennung: NvStreamNetworkService.exe3 Vollständiger Name des fehlerhaften Pakets: NvStreamNetworkService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NvStreamNetworkService.exe5 Error: (05/01/2015 06:38:38 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004e920f ID des fehlerhaften Prozesses: 0x6c0 Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0 Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1 Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2 Berichtskennung: NvStreamNetworkService.exe3 Vollständiger Name des fehlerhaften Pakets: NvStreamNetworkService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NvStreamNetworkService.exe5 Error: (05/01/2015 06:38:36 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004e920f ID des fehlerhaften Prozesses: 0x624 Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0 Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1 Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2 Berichtskennung: NvStreamNetworkService.exe3 Vollständiger Name des fehlerhaften Pakets: NvStreamNetworkService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NvStreamNetworkService.exe5 Error: (05/01/2015 06:38:33 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004e920f ID des fehlerhaften Prozesses: 0x1098 Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0 Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1 Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2 Berichtskennung: NvStreamNetworkService.exe3 Vollständiger Name des fehlerhaften Pakets: NvStreamNetworkService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NvStreamNetworkService.exe5 Error: (05/01/2015 06:38:31 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004e920f ID des fehlerhaften Prozesses: 0x1270 Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0 Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1 Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2 Berichtskennung: NvStreamNetworkService.exe3 Vollständiger Name des fehlerhaften Pakets: NvStreamNetworkService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NvStreamNetworkService.exe5 Error: (05/01/2015 06:38:28 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004e920f ID des fehlerhaften Prozesses: 0x1340 Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0 Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1 Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2 Berichtskennung: NvStreamNetworkService.exe3 Vollständiger Name des fehlerhaften Pakets: NvStreamNetworkService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NvStreamNetworkService.exe5 Error: (05/01/2015 06:38:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004e920f ID des fehlerhaften Prozesses: 0x18c Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0 Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1 Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2 Berichtskennung: NvStreamNetworkService.exe3 Vollständiger Name des fehlerhaften Pakets: NvStreamNetworkService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NvStreamNetworkService.exe5 Error: (05/01/2015 06:38:24 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004e920f ID des fehlerhaften Prozesses: 0x75c Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0 Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1 Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2 Berichtskennung: NvStreamNetworkService.exe3 Vollständiger Name des fehlerhaften Pakets: NvStreamNetworkService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NvStreamNetworkService.exe5 Error: (05/01/2015 06:38:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x551399be Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000004e920f ID des fehlerhaften Prozesses: 0x1358 Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0 Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1 Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2 Berichtskennung: NvStreamNetworkService.exe3 Vollständiger Name des fehlerhaften Pakets: NvStreamNetworkService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NvStreamNetworkService.exe5 System errors: ============= Error: (05/01/2015 04:52:41 PM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (05/01/2015 04:52:41 PM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (05/01/2015 04:50:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "AODDriver4.3" wurde aufgrund folgenden Fehlers nicht gestartet: %%3 Error: (05/01/2015 04:50:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "AODDriver4.2.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%3 Error: (05/01/2015 04:49:48 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {5DC4F9AD-3A2B-4DF4-AC39-3FF5A19FCF4C} Error: (05/01/2015 04:32:50 PM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (05/01/2015 04:32:50 PM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (05/01/2015 04:30:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "AODDriver4.3" wurde aufgrund folgenden Fehlers nicht gestartet: %%3 Error: (05/01/2015 04:30:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "AODDriver4.2.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%3 Error: (05/01/2015 04:30:07 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {5DC4F9AD-3A2B-4DF4-AC39-3FF5A19FCF4C} Microsoft Office Sessions: ========================= Error: (05/01/2015 06:38:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f1b5001d0842d4af0bd8dC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe88ac741c-f020-11e4-bf2d-448a5b881981 Error: (05/01/2015 06:38:44 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f184c01d0842d49f057e0C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe87a9c470-f020-11e4-bf2d-448a5b881981 Error: (05/01/2015 06:38:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f17a801d0842d47f420aeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe85b15df2-f020-11e4-bf2d-448a5b881981 Error: (05/01/2015 06:38:38 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f6c001d0842d4699afafC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe8454a2f4-f020-11e4-bf2d-448a5b881981 Error: (05/01/2015 06:38:36 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f62401d0842d44f6c076C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe82b3fdc9-f020-11e4-bf2d-448a5b881981 Error: (05/01/2015 06:38:33 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f109801d0842d435c360eC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe8117eca6-f020-11e4-bf2d-448a5b881981 Error: (05/01/2015 06:38:31 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f127001d0842d41fa240dC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe7fb69d90-f020-11e4-bf2d-448a5b881981 Error: (05/01/2015 06:38:28 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f134001d0842d40a07672C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe7e5cefe9-f020-11e4-bf2d-448a5b881981 Error: (05/01/2015 06:38:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f18c01d0842d3efcc3d7C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe7cb93d60-f020-11e4-bf2d-448a5b881981 Error: (05/01/2015 06:38:24 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f75c01d0842d3ddc50ffC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe7b98cae9-f020-11e4-bf2d-448a5b881981 CodeIntegrity Errors: =================================== Date: 2014-01-18 13:43:23.714 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Definition Updates\{62B42C86-6359-437E-BABD-DD10110876F2}\mpengine.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-01-18 13:43:20.223 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-12-29 11:00:05.704 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-12-29 11:00:04.676 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-12-29 11:00:03.666 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-12-29 11:00:02.654 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-12-29 10:59:39.744 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-12-29 10:59:38.712 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-12-29 10:59:37.702 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-12-29 10:59:36.691 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz Percentage of memory in use: 49% Total physical RAM: 8135.98 MB Available physical RAM: 4102.45 MB Total Pagefile: 11591.99 MB Available Pagefile: 7260.48 MB Total Virtual: 131072 MB Available Virtual: 131071.77 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:59.28 GB) (Free:3.56 GB) NTFS Drive d: (Spiele) (Fixed) (Total:390.62 GB) (Free:35.95 GB) NTFS Drive e: (Filme) (Fixed) (Total:540.89 GB) (Free:61.09 GB) NTFS Drive f: (GS0515DVD) (CDROM) (Total:7.52 GB) (Free:0 GB) UDF Drive g: (PKO) (Fixed) (Total:465.76 GB) (Free:113.48 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 59.6 GB) (Disk ID: 06059A12) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=59.3 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 953313CD) Partition 1: (Not Active) - (Size=390.6 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=540.9 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3998C396) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
01.05.2015, 18:27 | #3 |
/// the machine /// TB-Ausbilder | Windows 8.1: Fenster blinken und bei Videos erscheint immer wieder die Playleiste trotz keiner Mausbewegung hi,
__________________Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
01.05.2015, 19:28 | #4 |
| Windows 8.1: Fenster blinken und bei Videos erscheint immer wieder die Playleiste trotz keiner MausbewegungCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 01.05.2015 Suchlauf-Zeit: 20:11:34 Logdatei: mbam.txt Administrator: Ja Version: 2.01.6.1022 Malware Datenbank: v2015.05.01.05 Rootkit Datenbank: v2015.04.21.01 Lizenz: Premium Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Peter Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 378722 Verstrichene Zeit: 5 Min, 35 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente gefunden) Module: 0 (Keine schädliche Elemente gefunden) Registrierungsschlüssel: 0 (Keine schädliche Elemente gefunden) Registrierungswerte: 0 (Keine schädliche Elemente gefunden) Registrierungsdaten: 0 (Keine schädliche Elemente gefunden) Ordner: 0 (Keine schädliche Elemente gefunden) Dateien: 0 (Keine schädliche Elemente gefunden) Physische Sektoren: 0 (Keine schädliche Elemente gefunden) (end) Code:
ATTFilter # AdwCleaner v4.203 - Bericht erstellt 01/05/2015 um 20:21:53 # Aktualisiert 30/04/2015 von Xplode # Datenbank : 2015-04-30.2 [Server] # Betriebssystem : Windows 8.1 Pro (x64) # Benutzername : Peter - PKO # Gestarted von : C:\Users\Peter\Downloads\adwcleaner_4.203.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Program Files (x86)\Dll-Files.com Fixer Ordner Gelöscht : C:\Users\Peter\AppData\Roaming\dll-files.com Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe Datei Gelöscht : C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Dll-Files Fixer.lnk Datei Gelöscht : C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_de.reimageplus.com_0.localstorage Datei Gelöscht : C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_de.reimageplus.com_0.localstorage-journal Datei Gelöscht : C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_primeshare.tv_0.localstorage Datei Gelöscht : C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage Datei Gelöscht : C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal Datei Gelöscht : C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage Datei Gelöscht : C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage-journal ***** [ Geplante Tasks ] ***** Task Gelöscht : DLL-Files.Com Fixer_MONTHLY Task Gelöscht : DLL-Files.Com Fixer_Updates Task Gelöscht : globalUpdateUpdateTaskMachineCore Task Gelöscht : globalUpdateUpdateTaskMachineUA Task Gelöscht : RDReminder ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\3fac6c91-175a-4782-b027-0b999efff9cf Schlüssel Gelöscht : HKCU\Software\AskPartnerNetwork Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\DriverTuner_Init Schlüssel Gelöscht : HKCU\Software\DriverTuner Schlüssel Gelöscht : HKCU\Software\dll-files.com Schlüssel Gelöscht : HKLM\SOFTWARE\dll-files.com Schlüssel Gelöscht : HKU\.DEFAULT\Software\AskPartnerNetwork Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\EFEE0228DC83E77358593193D847A0EC Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\EFEE0228DC83E77358593193D847A0EC Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EFEE0228DC83E77358593193D847A0EC Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17416 -\\ Mozilla Firefox v37.0.2 (x86 de) [c3yi4pxp.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.enabledAddons", "toolbar_SPCV7%40apn.ask.com:30.1,amazon-icon%40giga.de:1.1,bdwteff%40bitdefender.com:2.0,%7BF003DA68-8256-4b37-A6C4-350FA04494DF%7D:6.5,YoutubeDownloader%40Peter[...] [c3yi4pxp.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar_SPCV7@apn.ask.com.install-event-fired", true); [c3yi4pxp.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.xpiState", "{\"app-profile\":{\"amazon-icon@giga.de\":{\"d\":\"C:\\\\Users\\\\Peter\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\c3yi4pxp.default\\\\extensions\\\\a[...] -\\ Google Chrome v42.0.2311.135 [C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Extension] : mkcedibhemacmilmkpndpkoidlnmgngg -\\ Chromium v ************************* AdwCleaner[R0].txt - [13758 Bytes] - [24/12/2014 04:01:30] AdwCleaner[R1].txt - [4064 Bytes] - [24/12/2014 04:04:39] AdwCleaner[R2].txt - [4416 Bytes] - [01/05/2015 20:20:51] AdwCleaner[S0].txt - [10913 Bytes] - [24/12/2014 04:03:10] AdwCleaner[S1].txt - [3979 Bytes] - [24/12/2014 04:05:23] AdwCleaner[S2].txt - [4080 Bytes] - [01/05/2015 20:21:53] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [4139 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.6.7 (04.30.2015:1) OS: Windows 8.1 Pro x64 Ran by Peter on 01.05.2015 at 20:24:53,82 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Tasks Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Driver Booster SkipUAC (Peter) Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-3741966532-150782217-4257482019-1001 ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL ~~~ Registry Keys ~~~ Files Successfully deleted: [File] C:\Users\Peter\appdata\local\google\chrome\user data\default\local storage\http_lyrics.wikia.com_0.localstorage-journal Successfully deleted: [File] C:\Users\Peter\appdata\local\google\chrome\user data\default\local storage\http_lyrics.wikia.com_0.localstorage ~~~ Folders Successfully deleted: [Folder] C:\WINDOWS\syswow64\ai_recyclebin ~~~ FireFox Successfully deleted: [Folder] C:\Users\Peter\AppData\Roaming\mozilla\firefox\profiles\c3yi4pxp.default\conduitcommon Successfully deleted the following from C:\Users\Peter\AppData\Roaming\mozilla\firefox\profiles\c3yi4pxp.default\prefs.js user_pref(extensions.gophoto@gophoto.it.install-event-fired, true); user_pref(extensions.iobitascsurfingprotection@iobit.com.install-event-fired, true); Emptied folder: C:\Users\Peter\AppData\Roaming\mozilla\firefox\profiles\c3yi4pxp.default\minidumps [11 files] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 01.05.2015 at 20:26:18,14 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-04-2015 01 Ran by Peter (administrator) on PKO on 01-05-2015 20:27:32 Running from C:\Users\Peter\Desktop Loaded Profiles: Peter (Available profiles: Peter) Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7575768 2014-06-29] (Realtek Semiconductor) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM\...\Run: [ISCT Tray] => C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe [5860656 2014-04-24] (Intel Corporation) HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe [1691112 2015-04-06] (Bitdefender) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.) HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [3468240 2014-08-26] (Micro-Star International) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [Steam] => D:\Program Files (x86)\Steam\Steam.exe [2889408 2015-04-14] (Valve Corporation) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [Spotify Web Helper] => C:\Users\Peter\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920 2015-04-25] (Spotify Ltd) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [Octoshape Streaming Services] => C:\Users\Peter\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [107800 2011-03-24] (Octoshape ApS) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 5\CyberGhost.exe [410216 2014-11-03] (CyberGhost S.R.L.) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [Bitdefender-Geldbörse-Agent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe [790880 2015-02-24] (Bitdefender) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\Run: [Spotify] => C:\Users\Peter\AppData\Roaming\Spotify\Spotify.exe [7168568 2015-04-25] (Spotify Ltd) HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\MountPoints2: F - "F:\Start.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\MountPoints2: {1922f9d8-ff38-11e3-beeb-806e6f6e6963} - "F:\Start.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\MountPoints2: {5c056940-5109-11e2-be66-50e549534846} - "G:\pushinst.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\MountPoints2: {5d20c502-570a-11e3-824f-806e6f6e6963} - "F:\Start.exe" HKU\S-1-5-21-3741966532-150782217-4257482019-1001\...\MountPoints2: {923fd65d-042d-11e3-beab-50e549534846} - "J:\pushinst.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Alternative Flash Player Auto-Updater.lnk [2013-07-25] ShortcutTarget: Alternative Flash Player Auto-Updater.lnk -> C:\Program Files (x86)\Alternative Flash Player Auto-Updater\Alternative Flash Player Auto-Updater.exe (pXc-coding.com) ShellIconOverlayIdentifiers: [__SafeBox1] -> {152C96EB-288E-4EDC-B7C6-D21F8250ADF3} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll [2014-07-04] (Bitdefender) ShellIconOverlayIdentifiers: [__SafeBox2] -> {342DAA0B-D796-460D-8566-901E08A1CCAD} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll [2014-07-04] (Bitdefender) ShellIconOverlayIdentifiers: [__SafeBox3] -> {57595DAE-1AE1-4D97-A49E-67CBB53B52DF} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll [2014-07-04] (Bitdefender) ShellIconOverlayIdentifiers: [__SafeBox4] -> {33816773-98AE-4723-ADE0-EBE54C8B5A67} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll [2014-07-04] (Bitdefender) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-3741966532-150782217-4257482019-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3741966532-150782217-4257482019-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKU\S-1-5-21-3741966532-150782217-4257482019-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-02-24] (Bitdefender) BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.) BHO-x32: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-02-24] (Bitdefender) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-04-05] (Oracle Corporation) BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-04-05] (Oracle Corporation) Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-02-24] (Bitdefender) Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-02-24] (Bitdefender) DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab Tcpip\Parameters: [DhcpNameServer] 192.168.188.1 FireFox: ======== FF ProfilePath: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default FF SearchEngineOrder.1: FF SelectedSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-17] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-17] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-04-05] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-04-05] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-11-27] (Nero AG) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-04-08] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-04-08] (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files (x86)\Veetle\plugins\npVeetle.dll [2012-01-14] (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files (x86)\Veetle\Player\npvlc.dll [2012-01-14] (Veetle Inc) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3741966532-150782217-4257482019-1001: @octoshape.com/Octoshape Streaming Services,version=1.0 -> C:\Users\Peter\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll [2011-03-23] (Octoshape ApS) FF Plugin ProgramFiles/Appdata: C:\Users\Peter\AppData\Roaming\mozilla\plugins\npoctoshape.dll [2013-07-23] (Octoshape ApS) FF Extension: Amazon-Icon - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\amazon-icon@giga.de [2014-07-05] FF Extension: Garmin Communicator - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013-02-17] FF Extension: Sopcast Toolbar - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\toolbar_SPCV7@apn.ask.com.xpi [2013-06-13] FF Extension: 1-Click YouTube Video Downloader - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2013-02-17] FF Extension: Video DownloadHelper - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-05-01] FF Extension: Adblock Plus - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\c3yi4pxp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-12-29] FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext FF Extension: Bitdefender Antispam Toolbar - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext [2014-11-27] FF HKLM-x32\...\Firefox\Extensions: [bdwteff@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff [2014-11-27] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-01-18] FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext Chrome: ======= CHR HomePage: Default -> https://de.search.yahoo.com/?type=994519&fr=yo-yhp-ch CHR StartupUrls: Default -> "https://de.search.yahoo.com/?type=994519&fr=yo-yhp-ch", "hxxp://www.giga.de/" CHR Profile: C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-09] CHR Extension: (Google Drive) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-09] CHR Extension: (YouTube) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-09] CHR Extension: (Adblock Plus) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-09] CHR Extension: (Google Search) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-09] CHR Extension: (Bitdefender Wallet) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabcmochhfpldjekobfaaggijgohadih [2014-11-27] CHR Extension: (Bookmark Manager) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-26] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-20] CHR Extension: (Google Wallet) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-09] CHR Extension: (Gmail) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-09] CHR HKLM-x32\...\Chrome\Extension: [fabcmochhfpldjekobfaaggijgohadih] - https://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S4 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed] S3 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2015\bdparentalservice.exe [78144 2015-01-20] (Bitdefender) S4 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2014-12-12] (BitRaider, LLC) S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) S4 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64616 2014-11-03] (CyberGhost S.R.L) S2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-06-29] (IvoSoft) [File not signed] S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-06-29] (Creative Labs) [File not signed] S2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [File not signed] S2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3736520 2015-01-29] (devolo AG) S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [209712 2014-04-24] () S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-17] (Intel Corporation) S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) S4 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [1722320 2014-08-26] (Micro-Star International) S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation) S2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [75136 2014-07-13] () R2 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [94624 2013-07-08] (Bitdefender) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448976 2015-04-17] (TeamViewer GmbH) R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2014-10-27] (Bitdefender) R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe [1547936 2015-04-06] (Bitdefender) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) S3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices) [File not signed] R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1306464 2015-02-24] (BitDefender) R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [262544 2015-02-24] (BitDefender) S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [677104 2015-02-24] (BitDefender) S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender) R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2015-02-24] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC) S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL) S3 BDSandBox; C:\WINDOWS\system32\drivers\bdsandbox.sys [82824 2015-02-24] (BitDefender SRL) R1 BDVEDISK; C:\Windows\system32\DRIVERS\bdvedisk.sys [79192 2013-07-30] (BitDefender) S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2015-03-12] (BitRaider) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-01-13] (Disc Soft Ltd) S3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH) [File not signed] R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [160544 2015-04-06] (BitDefender LLC) R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [22216 2014-02-03] () R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [22728 2014-02-03] () R3 INETMON; C:\WINDOWS\System32\Drivers\INETMON.sys [25800 2014-04-03] () R3 ISCT; C:\Windows\System32\drivers\ISCTD.sys [44744 2014-02-03] () R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-01] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-17] (Intel Corporation) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2015-01-29] (CACE Technologies) S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [14136 2010-10-22] (MSI) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) S3 RivaTuner64; C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [19952 2013-12-29] () S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) R3 XSplit_Dummy; C:\Windows\system32\drivers\xspltspk.sys [26200 2014-07-02] (SplitmediaLabs Limited) S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation) S2 AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X] S2 AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-01 20:25 - 2015-05-01 20:25 - 00000207 _____ () C:\WINDOWS\tweaking.com-regbackup-PKO-Windows-8.1-Pro-(64-bit).dat 2015-05-01 20:24 - 2015-05-01 20:24 - 02716306 _____ (Thisisu) C:\Users\Peter\Desktop\JRT.exe 2015-05-01 20:24 - 2015-05-01 20:24 - 00000000 ____D () C:\RegBackup 2015-05-01 20:20 - 2015-05-01 20:20 - 02204160 _____ () C:\Users\Peter\Downloads\adwcleaner_4.203.exe 2015-05-01 20:08 - 2015-05-01 20:08 - 00001280 _____ () C:\Users\Peter\Desktop\Revo Uninstaller.lnk 2015-05-01 20:08 - 2015-05-01 20:08 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-05-01 20:05 - 2015-05-01 20:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Peter\Desktop\revosetup95.exe 2015-05-01 18:55 - 2015-05-01 18:55 - 00332886 _____ () C:\Users\Peter\Desktop\Gmer.log 2015-05-01 18:38 - 2015-05-01 20:27 - 00024266 _____ () C:\Users\Peter\Desktop\FRST.txt 2015-05-01 18:38 - 2015-05-01 20:27 - 00000000 ____D () C:\FRST 2015-05-01 18:38 - 2015-05-01 18:38 - 00380416 _____ () C:\Users\Peter\Desktop\Gmer-19357.exe 2015-05-01 18:36 - 2015-05-01 18:36 - 02101248 _____ (Farbar) C:\Users\Peter\Desktop\FRST64.exe 2015-05-01 18:35 - 2015-05-01 18:35 - 00050477 _____ () C:\Users\Peter\Desktop\Defogger.exe 2015-05-01 18:35 - 2015-05-01 18:35 - 00000168 _____ () C:\Users\Peter\defogger_reenable 2015-05-01 16:39 - 2015-05-01 20:22 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-05-01 16:38 - 2015-05-01 16:38 - 00001114 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-05-01 16:38 - 2015-05-01 16:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-05-01 16:38 - 2015-05-01 16:38 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-05-01 16:38 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2015-05-01 16:38 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2015-05-01 16:38 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2015-05-01 16:37 - 2015-05-01 16:38 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Peter\Downloads\mbam-setup-2.1.6.1022.exe 2015-05-01 16:13 - 2015-05-01 16:13 - 00243592 _____ () C:\Users\Peter\Downloads\Firefox Setup Stub 37.0.2.exe 2015-05-01 16:12 - 2015-05-01 16:12 - 00000000 ____D () C:\Users\Peter\AppData\Temp 2015-05-01 15:10 - 2015-05-01 20:06 - 00204240 _____ () C:\WINDOWS\PFRO.log 2015-05-01 15:02 - 2015-01-06 05:01 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys 2015-05-01 15:02 - 2015-01-06 04:59 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys 2015-05-01 15:02 - 2015-01-06 03:12 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascfg.dll 2015-05-01 15:02 - 2015-01-06 03:02 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rascfg.dll 2015-05-01 15:01 - 2015-03-20 03:56 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys 2015-05-01 15:01 - 2015-03-17 19:26 - 00467776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2015-05-01 15:01 - 2015-03-13 04:49 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2015-05-01 15:01 - 2015-03-13 04:28 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2015-05-01 15:01 - 2015-03-09 04:02 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys 2015-05-01 15:00 - 2015-04-03 02:35 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll 2015-05-01 15:00 - 2015-04-03 02:14 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll 2015-05-01 15:00 - 2015-04-02 00:22 - 02985984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2015-05-01 15:00 - 2015-04-02 00:20 - 04417536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2015-05-01 15:00 - 2015-04-01 05:45 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll 2015-05-01 15:00 - 2015-04-01 04:31 - 01207296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll 2015-05-01 15:00 - 2015-03-14 04:03 - 04179968 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2015-05-01 15:00 - 2015-03-13 06:03 - 00239424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2015-05-01 15:00 - 2015-03-13 06:03 - 00154432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2015-05-01 15:00 - 2015-03-13 04:59 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2015-05-01 15:00 - 2015-03-13 04:38 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2015-05-01 15:00 - 2015-03-13 04:02 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys 2015-05-01 15:00 - 2015-03-13 03:11 - 02162176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2015-05-01 15:00 - 2015-03-13 02:39 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2015-05-01 15:00 - 2015-03-13 02:29 - 00410017 _____ () C:\WINDOWS\system32\ApnDatabase.xml 2015-05-01 15:00 - 2015-03-11 03:49 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe 2015-05-01 15:00 - 2015-03-11 03:09 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe 2015-05-01 15:00 - 2015-03-06 05:08 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll 2015-05-01 15:00 - 2015-03-06 04:47 - 01696256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2015-05-01 15:00 - 2015-03-06 04:43 - 01969664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll 2015-05-01 15:00 - 2015-03-04 03:32 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2015-05-01 15:00 - 2015-03-04 03:12 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2015-05-01 15:00 - 2015-02-18 01:19 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2015-05-01 15:00 - 2015-02-13 04:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2015-05-01 15:00 - 2015-02-13 03:46 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2015-05-01 15:00 - 2015-01-30 02:53 - 02819584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll 2015-04-29 19:59 - 2015-04-29 19:59 - 00000000 ____D () C:\Program Files\Rockstar Games 2015-04-29 19:59 - 2015-04-29 19:59 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games 2015-04-29 19:58 - 2015-04-29 19:58 - 00000000 ____D () C:\Users\Peter\AppData\Local\Rockstar Games 2015-04-29 19:57 - 2015-04-29 19:57 - 00000000 ____D () C:\Users\Peter\Documents\Rockstar Games 2015-04-27 21:35 - 2015-05-01 20:22 - 00002245 _____ () C:\WINDOWS\setupact.log 2015-04-27 21:35 - 2015-04-27 21:35 - 00000000 _____ () C:\WINDOWS\setuperr.log 2015-04-26 21:54 - 2015-04-26 21:54 - 00012080 _____ () C:\Users\Peter\AppData\Local\recently-used.xbel 2015-04-26 09:41 - 2015-04-26 09:41 - 00088330 _____ () C:\Users\Peter\Downloads\[kickass.to]grand.theft.auto.v.gta.5.v1.0.331.1.crack.v3.multi11.fitgirl.ultra.repack.torrent 2015-04-17 00:25 - 2015-03-23 23:59 - 07476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2015-04-17 00:25 - 2015-03-23 23:59 - 01733952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2015-04-17 00:25 - 2015-03-23 23:59 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll 2015-04-17 00:25 - 2015-03-23 23:58 - 01498872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2015-04-17 00:25 - 2015-03-23 23:45 - 00257216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll 2015-04-17 00:25 - 2015-03-20 06:12 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll 2015-04-17 00:25 - 2015-03-20 06:10 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll 2015-04-17 00:25 - 2015-03-20 06:10 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll 2015-04-17 00:25 - 2015-03-20 05:17 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\tracerpt.exe 2015-04-17 00:25 - 2015-03-20 04:41 - 00369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tracerpt.exe 2015-04-17 00:25 - 2015-03-20 04:40 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll 2015-04-17 00:25 - 2015-03-20 04:16 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll 2015-04-17 00:25 - 2015-03-13 06:32 - 24980480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-04-17 00:25 - 2015-03-13 06:08 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2015-04-17 00:25 - 2015-03-13 06:07 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-04-17 00:25 - 2015-03-13 05:53 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-04-17 00:25 - 2015-03-13 05:50 - 06025216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2015-04-17 00:25 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-04-17 00:25 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2015-04-17 00:25 - 2015-03-13 05:26 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2015-04-17 00:25 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-04-17 00:25 - 2015-03-13 05:17 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2015-04-17 00:25 - 2015-03-13 05:16 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-04-17 00:25 - 2015-03-13 05:08 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2015-04-17 00:25 - 2015-03-13 05:07 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2015-04-17 00:25 - 2015-03-13 05:00 - 14397440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-04-17 00:25 - 2015-03-13 04:58 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll 2015-04-17 00:25 - 2015-03-13 04:50 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2015-04-17 00:25 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2015-04-17 00:25 - 2015-03-13 04:45 - 02358784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-04-17 00:25 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2015-04-17 00:25 - 2015-03-13 04:37 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll 2015-04-17 00:25 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-04-17 00:25 - 2015-03-13 04:33 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-04-17 00:25 - 2015-03-13 04:22 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2015-04-17 00:25 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-04-17 00:25 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-04-17 00:25 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-04-17 00:24 - 2015-03-04 12:25 - 00377152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2015-04-17 00:24 - 2015-03-04 05:04 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll 2015-04-17 00:24 - 2015-03-04 04:19 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clfsw32.dll 2015-04-17 00:24 - 2015-02-24 10:32 - 00991552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys 2015-04-14 00:53 - 2015-04-08 22:32 - 00560968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe 2015-04-14 00:50 - 2015-04-09 02:58 - 31570064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 30397072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 25375048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 24053576 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 15716232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 14006752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 12852784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 11380728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 10423952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys 2015-04-14 00:50 - 2015-04-09 02:58 - 02896528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 02573456 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 01895568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435012.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 01557648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435012.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 01086424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 01047368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 01037640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00970568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00962192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00927440 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00849552 _____ () C:\WINDOWS\system32\nvmcumd.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00499344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00402576 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00390472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00346256 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00175880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00154256 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00150648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll 2015-04-14 00:50 - 2015-04-09 02:58 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll 2015-04-12 22:31 - 2015-03-23 00:45 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 01111552 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 00769024 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2015-04-12 22:31 - 2015-03-23 00:09 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2015-04-12 22:31 - 2015-03-14 10:54 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2015-04-12 22:31 - 2015-03-14 03:56 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2015-04-12 22:31 - 2015-03-14 03:56 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2015-04-12 22:31 - 2015-03-14 03:51 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll 2015-04-12 22:31 - 2015-03-14 03:37 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll 2015-04-12 22:31 - 2015-03-14 03:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2015-04-12 22:31 - 2015-03-14 02:22 - 03678720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2015-04-12 22:31 - 2015-03-14 02:12 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll 2015-04-12 22:31 - 2015-03-14 02:12 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe 2015-04-12 22:31 - 2015-03-14 02:09 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2015-04-12 22:31 - 2015-03-14 02:08 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 2015-04-12 22:31 - 2015-03-14 02:08 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2015-04-12 22:31 - 2015-03-14 02:06 - 02373632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 2015-04-12 22:31 - 2015-03-14 02:06 - 00891392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2015-04-12 22:31 - 2015-03-14 02:02 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll 2015-04-12 22:31 - 2015-03-14 02:02 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe 2015-04-12 22:31 - 2015-03-14 01:59 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2015-04-12 22:31 - 2015-03-14 01:59 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2015-04-12 22:31 - 2015-02-21 01:49 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll 2015-04-12 20:09 - 2013-09-24 12:10 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr70.dll 2015-04-12 20:05 - 2015-04-25 21:28 - 00000292 _____ () C:\WINDOWS\Tasks\DLL-Files FixerASKUSER.job 2015-04-12 20:05 - 2015-04-12 20:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dll-Files Fixer 2015-04-12 20:05 - 2015-04-12 20:05 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70.dll 2015-04-12 20:04 - 2005-03-26 12:42 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc70.dll 2015-04-12 20:02 - 2015-04-12 20:11 - 00000000 ____D () C:\Users\Peter\Desktop\FMXML 2015-04-12 18:11 - 2015-04-27 00:39 - 00000000 ____D () C:\Users\Peter\.thumbnails 2015-04-12 18:11 - 2015-04-12 22:47 - 00000000 ____D () C:\Users\Peter\AppData\Local\gtk-2.0 2015-04-12 18:09 - 2015-04-26 23:52 - 00000000 ____D () C:\Users\Peter\.gimp-2.8 2015-04-12 18:09 - 2015-04-12 18:09 - 00000773 _____ () C:\Users\Public\Desktop\GIMP 2.lnk 2015-04-12 18:09 - 2015-04-12 18:09 - 00000773 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2015-04-12 18:09 - 2015-04-12 18:09 - 00000000 ____D () C:\Users\Peter\AppData\Local\gegl-0.2 2015-04-06 20:45 - 2015-04-06 20:45 - 00160544 _____ (BitDefender LLC) C:\WINDOWS\system32\Drivers\gzflt.sys 2015-04-05 20:34 - 2015-04-12 14:39 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Skype 2015-04-05 20:34 - 2015-04-05 20:34 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ___SD () C:\WINDOWS\SysWOW64\GWX 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ___SD () C:\WINDOWS\system32\GWX 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ____D () C:\Users\Peter\AppData\Local\Skype 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ____D () C:\ProgramData\Skype 2015-04-05 20:34 - 2015-04-05 20:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-04-05 20:22 - 2015-03-14 10:20 - 01385256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2015-04-05 20:22 - 2015-03-14 10:13 - 01124352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2015-04-05 20:11 - 2015-04-05 20:11 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\AVG 2015-04-05 20:11 - 2015-04-05 20:11 - 00000000 ____D () C:\Users\Peter\AppData\Local\Avg 2015-04-05 20:11 - 2015-04-05 20:11 - 00000000 ____D () C:\Program Files (x86)\AVG 2015-04-05 20:10 - 2015-05-01 15:26 - 00000000 ____D () C:\ProgramData\AVG 2015-04-05 20:07 - 2015-05-01 15:10 - 00349856 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2015-04-05 09:39 - 2015-04-05 09:39 - 00000000 ____D () C:\Users\Peter\AppData\Local\Funcom 2015-04-05 01:03 - 2015-04-05 01:03 - 00000222 _____ () C:\Users\Peter\Desktop\The Secret World.url ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-01 20:25 - 2014-04-09 00:12 - 00001122 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-05-01 20:22 - 2014-06-29 05:18 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-05-01 20:22 - 2013-11-27 04:30 - 01365401 _____ () C:\WINDOWS\WindowsUpdate.log 2015-05-01 20:22 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-05-01 20:21 - 2014-12-24 03:56 - 00000000 ____D () C:\AdwCleaner 2015-05-01 20:16 - 2012-12-29 02:54 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-05-01 20:13 - 2013-09-30 06:14 - 01804092 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-05-01 20:13 - 2013-09-30 05:56 - 00774346 _____ () C:\WINDOWS\system32\perfh007.dat 2015-05-01 20:13 - 2013-09-30 05:56 - 00163568 _____ () C:\WINDOWS\system32\perfc007.dat 2015-05-01 20:10 - 2013-07-21 23:34 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\.ACEStream 2015-05-01 20:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-05-01 18:55 - 2012-12-28 19:12 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2015-05-01 18:35 - 2013-11-27 04:27 - 00000000 ____D () C:\Users\Peter 2015-05-01 16:50 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\System 2015-05-01 16:40 - 2014-09-01 10:18 - 00000365 _____ () C:\Users\Peter\AppData\Roaming\XKJSF 2015-05-01 16:30 - 2014-11-14 17:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-05-01 16:30 - 2012-12-28 19:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-05-01 16:22 - 2015-02-15 18:49 - 00000000 ____D () C:\Program Files (x86)\WinRAR 2015-05-01 16:21 - 2014-07-24 21:40 - 00000000 ____D () C:\Program Files (x86)\DivX 2015-05-01 16:21 - 2014-01-27 03:09 - 00000000 ____D () C:\ProgramData\DivX 2015-05-01 16:20 - 2014-01-19 23:09 - 00880128 ___SH () C:\Users\Peter\Desktop\Thumbs.db 2015-05-01 16:14 - 2012-12-28 19:52 - 00001171 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-05-01 16:14 - 2012-12-28 19:52 - 00001159 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-05-01 15:09 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-05-01 15:04 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel 2015-05-01 15:04 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\AdvancedInstallers 2015-05-01 15:03 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-05-01 14:51 - 2013-12-10 13:45 - 00003910 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2510119F-F773-436C-AB90-254EFC0713C7} 2015-05-01 12:58 - 2013-07-22 18:54 - 00000000 ____D () C:\Users\Peter\AppData\Local\Spotify 2015-05-01 12:57 - 2013-02-17 01:56 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Azureus 2015-05-01 11:00 - 2013-07-22 18:53 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Spotify 2015-05-01 05:45 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2015-04-27 19:01 - 2013-10-20 12:34 - 00000000 ____D () C:\Users\Peter\Documents\The Lord of the Rings Online 2015-04-27 19:00 - 2013-03-13 21:43 - 00000000 ____D () C:\Users\Peter\Documents\Sports Interactive 2015-04-27 18:33 - 2015-01-18 15:41 - 00018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys 2015-04-26 21:25 - 2013-02-18 23:39 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\To the Moon - Freebird Games 2015-04-26 19:55 - 2012-12-29 05:08 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\vlc 2015-04-26 17:35 - 2015-02-17 00:23 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\dvdcss 2015-04-26 17:35 - 2013-05-14 02:30 - 00001082 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2015-04-25 21:28 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2015-04-25 10:26 - 2014-12-12 01:38 - 00000983 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-04-25 10:26 - 2014-12-12 01:38 - 00000971 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk 2015-04-24 23:59 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF 2015-04-22 05:22 - 2013-07-21 23:34 - 00000000 ___HD () C:\_acestream_cache_ 2015-04-19 00:31 - 2013-08-13 17:43 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-04-19 00:29 - 2012-12-28 19:59 - 128913832 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-04-15 00:15 - 2014-03-23 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FMRTE 2015-04-14 01:24 - 2013-08-22 17:38 - 00792056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-04-14 01:24 - 2013-08-22 17:38 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-04-13 00:25 - 2014-12-16 14:05 - 00000000 ____D () C:\Program Files (x86)\a444df1f-4cc8-4e1c-9fdb-aafc21a0799e 2015-04-12 22:31 - 2014-12-12 02:42 - 00000000 ____D () C:\WINDOWS\system32\appraiser 2015-04-12 22:31 - 2014-07-09 21:57 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2015-04-12 14:46 - 2013-12-26 10:59 - 00000000 ____D () C:\Users\Public\Documents\The Witcher 2015-04-12 14:39 - 2014-03-23 19:32 - 00000000 ____D () C:\BraCa Soft 2015-04-09 02:58 - 2015-02-10 14:38 - 12689592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll 2015-04-09 02:58 - 2015-02-10 14:38 - 02935416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2015-04-09 02:58 - 2014-12-24 03:24 - 15818528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll 2015-04-09 02:58 - 2014-10-07 06:41 - 14617288 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll 2015-04-09 02:58 - 2014-06-29 05:17 - 17176128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll 2015-04-09 02:58 - 2014-06-29 05:17 - 03317344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2015-04-09 02:58 - 2014-06-29 05:17 - 00029329 _____ () C:\WINDOWS\system32\nvinfo.pb 2015-04-08 23:30 - 2014-06-29 05:18 - 06841488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2015-04-08 23:30 - 2014-06-29 05:18 - 03478344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2015-04-08 23:30 - 2014-06-29 05:18 - 02558608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2015-04-08 23:30 - 2014-06-29 05:18 - 00936264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2015-04-08 23:30 - 2014-06-29 05:18 - 00385168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2015-04-08 23:30 - 2014-06-29 05:18 - 00062608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2015-04-08 19:52 - 2014-06-29 05:18 - 04336074 _____ () C:\WINDOWS\system32\nvcoproc.bin 2015-04-08 19:22 - 2014-09-04 00:28 - 00000000 ____D () C:\Users\Peter\Desktop\Games 2015-04-06 10:41 - 2013-01-28 07:25 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2015-04-05 20:21 - 2013-10-01 12:53 - 00000000 ____D () C:\ProgramData\Oracle 2015-04-05 20:21 - 2013-10-01 12:53 - 00000000 ____D () C:\Program Files (x86)\Java 2015-04-05 20:20 - 2014-10-26 11:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-04-05 20:20 - 2014-01-18 14:56 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2015-04-05 20:17 - 2014-06-01 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ 2015-04-05 20:17 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep 2015-04-05 20:17 - 2013-05-13 22:43 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2015-04-05 20:17 - 2013-02-17 01:56 - 00000000 ____D () C:\Program Files\Vuze 2015-04-05 20:17 - 2013-01-24 20:53 - 00000000 ____D () C:\ProgramData\Temp 2015-04-05 12:24 - 2015-01-22 16:57 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\HpUpdate 2015-04-05 12:22 - 2013-01-08 03:04 - 00003696 _____ () C:\WINDOWS\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2015-04-05 09:39 - 2014-08-10 19:03 - 00000000 ____D () C:\WINDOWS\SysWOW64\directx 2015-04-02 21:31 - 2013-07-22 18:54 - 00001846 _____ () C:\Users\Peter\Desktop\Spotify.lnk 2015-04-02 21:31 - 2013-07-22 18:54 - 00001832 _____ () C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk ==================== Files in the root of some directories ======= 2014-09-01 10:18 - 2014-12-19 21:20 - 0001171 _____ () C:\Users\Peter\AppData\Roaming\DURCKM 2014-09-01 10:18 - 2015-05-01 16:40 - 0000365 _____ () C:\Users\Peter\AppData\Roaming\XKJSF 2013-10-20 12:31 - 2013-10-20 12:31 - 0000093 _____ () C:\Users\Peter\AppData\Local\fusioncache.dat 2015-04-26 21:54 - 2015-04-26 21:54 - 0012080 _____ () C:\Users\Peter\AppData\Local\recently-used.xbel 2014-11-27 22:07 - 2014-11-27 22:07 - 0759571 _____ () C:\ProgramData\1417118063.bdinstall.bin 2015-01-22 16:57 - 2015-01-22 16:57 - 0000057 _____ () C:\ProgramData\Ament.ini Some content of TEMP: ==================== C:\Users\Peter\AppData\Local\Temp\DseShExt-x64.dll C:\Users\Peter\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Peter\AppData\Local\Temp\Quarantine.exe C:\Users\Peter\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Peter\AppData\Local\Temp\SDShelEx-x64.dll C:\Users\Peter\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-28 07:49 ==================== End Of Log ============================ |
02.05.2015, 14:03 | #5 |
/// the machine /// TB-Ausbilder | Windows 8.1: Fenster blinken und bei Videos erscheint immer wieder die Playleiste trotz keiner MausbewegungESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.05.2015, 12:19 | #6 |
| Windows 8.1: Fenster blinken und bei Videos erscheint immer wieder die Playleiste trotz keiner Mausbewegung Hat schon noch dem zweiten durchlauf geklappt. Danke! |
03.05.2015, 17:22 | #7 |
/// the machine /// TB-Ausbilder | Windows 8.1: Fenster blinken und bei Videos erscheint immer wieder die Playleiste trotz keiner Mausbewegung Kontrollscans bitte trotzdem machen, sonst biste in ner Woche wieder hier
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 8.1: Fenster blinken und bei Videos erscheint immer wieder die Playleiste trotz keiner Mausbewegung |
blinkt, browser, cyberghost, downloader, driver booster, fehler, firefox, flash player, helper, homepage, langsam, maus, mozilla, problem, realtek, registry, rundll, scan, sekunden, services.exe, software, stick, svchost.exe, system, taskmanager, tastatur, windows |