Plagegeister aller Art und deren Bekämpfung: Maus klickt doppelt - Notebook-Sensormaus aber nicht
| ![]() Maus klickt doppelt - Notebook-Sensormaus aber nicht Hallo, ich weiß nicht ob es genau ein Virus oder so ist, aber ich vermute es beziehungsweise kann es mir nicht anders erklären. Meine externe Maus (ich besitze ein Notebook, habe also noch so einen Sensor vor mir) klickt nach einer Zeit immer doppelt. Am Anfang habe ich gedacht, das kommt, weil sie überhitzt. Aber es ist unterschiedlich, manchmal beginnt es, nachdem ich sie 5 Minuten nutze, und manchmal, nachdem ich sie 5 Stunden nutze... Hatte das Problem vor nem' halben Jahr schonmal, aber ich dachte, ich sei es endlich los. Mit einer anderen Maus hatte ich das selbe Problem auch. Es ist halt schon sehr stark nervend, deswegen hoffe ich hier auf Hilfe! Vielen Dank im Vorraus :3 |
hi,
__________________wenn das Touchpad fehlerfrei geht, ist die Maus kaputt oder die Software/Treiber der Maus haben nen Schuss. Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
| ![]() Maus klickt doppelt - Notebook-Sensormaus aber nichtCode:
ATTFilter C:\Windows\SysWOW64\scrrun.dll 2015-05-25 10:55 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2015-05-25 10:55 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2015-05-25 10:55 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2015-05-25 10:55 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2015-05-25 10:55 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2015-05-25 10:55 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2015-05-25 10:55 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2015-05-25 10:55 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2015-05-25 10:55 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2015-05-25 10:55 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2015-05-25 10:55 - 2011-12-16 10:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2015-05-25 10:55 - 2011-12-16 09:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll 2015-05-25 10:54 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-05-25 10:54 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2015-05-25 10:54 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll 2015-05-25 10:54 - 2013-10-12 04:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2015-05-25 10:54 - 2013-10-12 04:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2015-05-25 10:54 - 2013-10-12 04:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2015-05-25 10:54 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2015-05-25 10:54 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2015-05-25 10:53 - 2012-05-14 07:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2015-05-25 10:52 - 2012-06-06 08:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2015-05-25 10:52 - 2012-06-06 07:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2015-05-25 10:52 - 2011-10-15 08:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2015-05-25 10:52 - 2011-10-15 07:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2015-05-25 10:52 - 2011-08-27 07:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll 2015-05-25 10:52 - 2011-08-27 06:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll 2015-05-25 10:49 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2015-05-25 10:46 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-05-25 10:46 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2015-05-25 10:45 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-05-25 10:45 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2015-05-25 09:25 - 2015-06-02 08:30 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Windows Live 2015-05-25 09:24 - 2015-05-25 09:25 - 00000000 ____D () C:\Users\Niclas\AppData\Local\{7B3DA95D-AF4E-498C-9C66-1A1907EE3DA9} 2015-05-25 09:05 - 2015-05-25 09:08 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Wise Registry Cleaner 2015-05-24 22:28 - 2015-05-24 22:28 - 00000000 _____ () C:\Windows\AsRunBar.txt 2015-05-24 22:28 - 2011-11-11 03:46 - 00000031 _____ () C:\Windows\AsToolCDVer.txt 2015-05-24 22:27 - 2015-05-24 18:53 - 00000000 ____D () C:\eSupport 2015-05-24 21:59 - 2015-06-02 17:25 - 00002669 _____ () C:\Windows\setupact.log 2015-05-24 21:59 - 2015-05-24 21:59 - 00000000 _____ () C:\Windows\setuperr.log 2015-05-24 21:57 - 2015-05-24 21:57 - 00013017 _____ () C:\devlist.txt 2015-05-24 21:57 - 2015-05-24 21:57 - 00000009 _____ () C:\Finish.log 2015-05-24 21:47 - 2015-05-24 21:47 - 00000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2015-05-24 21:46 - 2015-05-24 21:47 - 00000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2015-05-24 21:45 - 2015-05-24 21:47 - 00000000 ____D () C:\ProgramData\Temp 2015-05-24 21:45 - 2015-05-24 21:46 - 00000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log 2015-05-24 21:45 - 2015-05-24 21:45 - 00059248 _____ () C:\Windows\AsChkDev.txt 2015-05-24 21:45 - 2015-05-24 21:45 - 00000000 ____N () C:\Windows\SysWOW64\Drivers\1043_ASUSTEK_K54C_V30_WIN7.MRK 2015-05-24 21:45 - 2015-05-24 21:45 - 00000000 ____D () C:\ProgramData\CyberLink 2015-05-24 21:45 - 2015-05-24 19:05 - 00000000 ____D () C:\Program Files (x86)\CyberLink 2015-05-24 21:43 - 2015-05-24 21:43 - 03058304 _____ (ASUS) C:\Windows\AsScrPro.exe 2015-05-24 21:43 - 2015-05-24 21:43 - 00520192 ____N (ScreenTime Media) C:\Windows\SysWOW64\ASUS_Screensaver.scr 2015-05-24 21:43 - 2015-05-24 21:43 - 00002984 _____ () C:\Windows\System32\Tasks\ASUS SmartLogon Console Sensor 2015-05-24 21:43 - 2015-05-24 21:43 - 00001061 _____ () C:\Windows\system32\ServiceFilter.ini 2015-05-24 21:43 - 2015-05-24 21:43 - 00000000 ____D () C:\Windows\SysWOW64\ASUS_Screensaver dir 2015-05-24 21:43 - 2015-05-24 21:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS Utility 2015-05-24 21:43 - 2015-05-24 11:02 - 00001812 _____ () C:\Windows\system32\AutoRunFilter.ini 2015-05-24 21:43 - 2015-05-24 11:01 - 00000080 _____ () C:\Windows\system32\Defrag.ini 2015-05-24 21:43 - 2011-12-07 01:21 - 00162456 ____N (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe 2015-05-24 21:43 - 2011-03-04 01:57 - 00379520 _____ (ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe 2015-05-24 21:43 - 2009-06-13 02:55 - 00000105 _____ () C:\Windows\system32\FastBoot.ini 2015-05-24 21:43 - 2009-06-05 22:35 - 00000052 _____ () C:\Windows\system32\RemoveFont.ini 2015-05-24 21:43 - 2009-06-05 22:35 - 00000015 _____ () C:\Windows\system32\BootTime.ini 2015-05-24 21:42 - 2015-05-24 21:43 - 00003230 _____ () C:\Windows\System32\Tasks\SidebarExecute 2015-05-24 21:42 - 2015-05-24 21:42 - 00002984 _____ () C:\Windows\System32\Tasks\ATKOSD2 2015-05-24 21:42 - 2015-05-24 18:48 - 00000000 ____D () C:\Program Files\ASUS 2015-05-24 21:41 - 2015-05-24 21:42 - 00000000 ____D () C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation 2015-05-24 21:41 - 2015-05-24 21:41 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM 2015-05-24 21:41 - 2015-05-24 21:41 - 00000000 ____D () C:\ProgramData\SonicFocus 2015-05-24 21:41 - 2015-05-24 21:41 - 00000000 ____D () C:\ProgramData\Qualcomm Atheros 2015-05-24 21:41 - 2015-05-24 21:41 - 00000000 ____D () C:\Program Files\Realtek 2015-05-24 21:41 - 2011-10-06 15:15 - 00070753 _____ () C:\Windows\system32\athrextx.cat 2015-05-24 21:41 - 2011-10-04 08:49 - 02770944 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys 2015-05-24 21:41 - 2011-10-04 08:49 - 02770944 _____ (Atheros Communications, Inc.) C:\Windows\system32\athrx.sys 2015-05-24 21:41 - 2011-08-30 07:00 - 00001083 _____ () C:\setup.iss 2015-05-24 21:40 - 2015-05-24 21:41 - 00002532 _____ () C:\RHDSetup.log 2015-05-24 21:40 - 2015-05-24 21:41 - 00000000 ___HD () C:\Program Files (x86)\Temp 2015-05-24 21:40 - 2015-05-24 21:40 - 00015410 _____ () C:\Windows\system32\results.xml 2015-05-24 21:40 - 2015-05-24 21:40 - 00000000 ____D () C:\ProgramData\Intel 2015-05-24 21:40 - 2015-05-24 21:40 - 00000000 ____D () C:\Program Files (x86)\Realtek 2015-05-24 21:40 - 2011-09-06 13:58 - 03074536 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2015-05-24 21:40 - 2011-09-06 04:16 - 02519656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2015-05-24 21:40 - 2011-09-05 11:06 - 00097896 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInst64.dll 2015-05-24 21:40 - 2011-09-02 07:27 - 03201128 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2015-05-24 21:40 - 2011-09-01 09:08 - 01510912 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat 2015-05-24 21:40 - 2011-08-31 13:12 - 01698408 ____N (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll 2015-05-24 21:40 - 2011-08-19 08:54 - 01881704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2015-05-24 21:40 - 2011-07-27 18:55 - 02604376 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll 2015-05-24 21:40 - 2011-07-27 18:55 - 02132824 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll 2015-05-24 21:40 - 2011-07-22 13:35 - 01247848 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2015-05-24 21:40 - 2011-06-30 10:14 - 01560168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2015-05-24 21:40 - 2011-05-31 03:42 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll 2015-05-24 21:40 - 2011-05-31 03:42 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll 2015-05-24 21:40 - 2011-05-31 03:42 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll 2015-05-24 21:40 - 2011-05-31 03:42 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll 2015-05-24 21:40 - 2011-05-31 03:42 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll 2015-05-24 21:40 - 2011-05-31 03:42 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll 2015-05-24 21:40 - 2011-05-31 03:42 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll 2015-05-24 21:40 - 2011-05-31 03:42 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll 2015-05-24 21:40 - 2011-05-31 03:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll 2015-05-24 21:40 - 2011-05-31 03:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll 2015-05-24 21:40 - 2011-05-05 09:24 - 02085440 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2015-05-24 21:40 - 2011-05-05 08:15 - 00220512 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll 2015-05-24 21:40 - 2011-05-05 08:14 - 00081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll 2015-05-24 21:40 - 2011-05-05 08:14 - 00078176 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll 2015-05-24 21:40 - 2010-11-08 01:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2015-05-24 21:40 - 2010-11-08 01:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2015-05-24 21:40 - 2010-11-08 01:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2015-05-24 21:40 - 2010-11-08 01:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2015-05-24 21:40 - 2010-11-08 01:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2015-05-24 21:40 - 2010-11-08 01:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2015-05-24 21:40 - 2010-11-03 12:31 - 00332392 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2015-05-24 21:40 - 2010-11-03 12:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2015-05-24 21:40 - 2010-09-27 03:34 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2015-05-24 21:40 - 2010-07-22 10:48 - 00074064 ____N (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll 2015-05-24 21:40 - 2010-07-22 10:37 - 00200800 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2015-05-24 21:40 - 2010-07-11 15:28 - 00180048 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFProc64.dll 2015-05-24 21:40 - 2010-07-11 15:28 - 00086352 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFComm64.dll 2015-05-24 21:40 - 2010-07-11 15:28 - 00083792 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFSAPO64.dll 2015-05-24 21:40 - 2010-07-11 15:28 - 00082768 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFHAPO64.dll 2015-05-24 21:40 - 2010-07-11 15:28 - 00082768 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFDAPO64.dll 2015-05-24 21:40 - 2009-11-24 03:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2015-05-24 21:40 - 2009-11-24 03:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll 2015-05-24 21:40 - 2009-11-24 03:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll 2015-05-24 21:40 - 2009-11-24 03:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2015-05-24 21:40 - 2009-11-17 12:12 - 00108960 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2015-05-24 21:38 - 2015-05-24 21:38 - 00000000 ____D () C:\ProgramData\AmUStor 2015-05-24 21:38 - 2015-05-24 21:38 - 00000000 ____D () C:\Program Files (x86)\ASM104xUSB3 2015-05-24 21:38 - 2015-05-24 21:38 - 00000000 ____D () C:\Program Files (x86)\AmIcoSingLun 2015-05-24 21:37 - 2015-05-24 21:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2015-05-24 21:37 - 2015-05-24 21:37 - 00000000 ____D () C:\Program Files\Common Files\Intel 2015-05-24 21:37 - 2015-05-24 19:10 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-05-24 21:37 - 2010-12-21 03:08 - 00008192 _____ () C:\Windows\system32\Drivers\IntelMEFWVer.dll 2015-05-24 21:37 - 2010-10-20 01:34 - 00056344 _____ (Intel Corporation) C:\Windows\system32\Drivers\HECIx64.sys 2015-05-24 21:36 - 2015-05-24 21:37 - 00000000 ____D () C:\Program Files (x86)\Intel 2015-05-24 21:36 - 2011-07-29 08:15 - 00053248 ____N (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll 2015-05-24 21:35 - 2015-05-24 21:36 - 00000000 ____D () C:\Intel 2015-05-24 21:34 - 2011-01-28 21:03 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\ifsutil.dll 2015-05-24 21:34 - 2011-01-28 07:46 - 00148992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ifsutil.dll 2015-05-24 21:33 - 2015-06-02 18:14 - 01322030 _____ () C:\Windows\WindowsUpdate.log 2015-05-24 20:33 - 2015-05-24 20:33 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Macromedia 2015-05-24 20:25 - 2015-05-24 20:25 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Steam 2015-05-24 20:08 - 2015-05-30 11:14 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\NCH Software 2015-05-24 20:08 - 2015-05-30 11:14 - 00000000 ____D () C:\ProgramData\NCH Software 2015-05-24 20:08 - 2015-05-30 11:14 - 00000000 ____D () C:\Program Files (x86)\NCH Software 2015-05-24 20:08 - 2015-05-25 16:54 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Apple Computer 2015-05-24 20:08 - 2015-05-25 10:39 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software 2015-05-24 20:08 - 2015-05-24 20:08 - 00001755 _____ () C:\Users\Public\Desktop\iTunes.lnk 2015-05-24 20:08 - 2015-05-24 20:08 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Apple Computer 2015-05-24 20:08 - 2015-05-24 20:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-05-24 20:08 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2015-05-24 20:07 - 2015-05-24 20:08 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-05-24 20:07 - 2015-05-24 20:08 - 00000000 ____D () C:\Program Files\iTunes 2015-05-24 20:07 - 2015-05-24 20:07 - 00000000 ____D () C:\ProgramData\Apple Computer 2015-05-24 20:07 - 2015-05-24 20:07 - 00000000 ____D () C:\Program Files\iPod 2015-05-24 20:07 - 2015-05-24 20:07 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-05-24 20:06 - 2015-05-24 20:06 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2015-05-24 20:06 - 2015-05-24 20:06 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Apple 2015-05-24 20:06 - 2015-05-24 20:06 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2015-05-24 20:05 - 2015-05-24 20:07 - 00000000 ____D () C:\Program Files\Common Files\Apple 2015-05-24 20:05 - 2015-05-24 20:05 - 00000000 ____D () C:\Program Files\Bonjour 2015-05-24 20:05 - 2015-05-24 20:05 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2015-05-24 20:04 - 2015-05-24 20:06 - 00000000 ____D () C:\ProgramData\Apple 2015-05-24 20:01 - 2013-01-13 23:17 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 23:17 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 23:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2015-05-24 20:01 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2015-05-24 20:01 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 23:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 22:35 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 22:35 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 22:35 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 22:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2015-05-24 20:01 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2015-05-24 20:01 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 22:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2015-05-24 20:01 - 2013-01-13 22:20 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2015-05-24 20:01 - 2013-01-13 22:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2015-05-24 20:01 - 2013-01-13 22:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2015-05-24 20:01 - 2013-01-13 21:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2015-05-24 20:01 - 2013-01-13 21:53 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2015-05-24 20:01 - 2013-01-13 21:53 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2015-05-24 20:01 - 2013-01-13 21:49 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2015-05-24 20:01 - 2013-01-13 21:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2015-05-24 20:01 - 2013-01-13 21:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2015-05-24 20:01 - 2013-01-13 21:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2015-05-24 20:01 - 2013-01-13 21:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2015-05-24 20:01 - 2013-01-13 21:25 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2015-05-24 20:01 - 2013-01-13 21:24 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2015-05-24 20:01 - 2013-01-13 21:24 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2015-05-24 20:01 - 2013-01-13 21:20 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2015-05-24 20:01 - 2013-01-13 21:20 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2015-05-24 20:01 - 2013-01-13 20:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2015-05-24 20:01 - 2013-01-13 20:09 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2015-05-24 20:01 - 2013-01-13 19:26 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2015-05-24 20:01 - 2013-01-13 19:05 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2015-05-24 19:59 - 2015-05-24 19:59 - 00000000 ____D () C:\Users\Niclas\AppData\Local\IsolatedStorage 2015-05-24 19:58 - 2015-05-29 21:33 - 00000000 ____D () C:\Program Files\Elgato 2015-05-24 19:58 - 2015-05-24 19:58 - 00001136 _____ () C:\Users\Public\Desktop\Game Capture HD.lnk 2015-05-24 19:58 - 2015-05-24 19:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elgato 2015-05-24 19:58 - 2014-11-13 11:43 - 00052456 _____ (UB658) C:\Windows\system32\Drivers\ElgatoGC658.sys 2015-05-24 19:57 - 2015-05-24 19:57 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Elgato 2015-05-24 19:57 - 2015-05-24 19:57 - 00000000 ____D () C:\Program Files (x86)\Elgato 2015-05-24 19:48 - 2015-04-30 10:07 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-05-24 19:44 - 2015-05-24 19:44 - 00002792 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2015-05-24 19:44 - 2015-05-24 19:44 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2015-05-24 19:44 - 2015-05-24 19:44 - 00000000 ____D () C:\Program Files\CCleaner 2015-05-24 19:39 - 2015-05-24 19:39 - 00000000 ____D () C:\Users\Niclas\Tracing 2015-05-24 19:38 - 2015-06-02 18:58 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Skype 2015-05-24 19:38 - 2015-05-24 19:38 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-05-24 19:38 - 2015-05-24 19:38 - 00000949 _____ () C:\ProgramData\Turn Off Monitor.ini 2015-05-24 19:38 - 2015-05-24 19:38 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-05-24 19:38 - 2015-05-24 19:38 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Skype 2015-05-24 19:38 - 2015-05-24 19:38 - 00000000 ____D () C:\ProgramData\Skype 2015-05-24 19:38 - 2015-05-24 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-05-24 19:36 - 2015-05-24 19:38 - 00000000 ____D () C:\Program Files (x86)\Turn Off Monitor 2015-05-24 19:35 - 2015-05-24 19:35 - 00001229 _____ () C:\Users\Public\Desktop\Wise Registry Cleaner.lnk 2015-05-24 19:35 - 2015-05-24 19:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner 2015-05-24 19:35 - 2015-05-24 19:35 - 00000000 ____D () C:\Program Files (x86)\Wise 2015-05-24 19:35 - 2015-02-24 04:17 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-05-24 19:34 - 2015-05-30 23:08 - 00000000 ____D () C:\Program Files (x86)\Steam 2015-05-24 19:34 - 2015-05-24 19:34 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-05-24 19:34 - 2015-05-24 19:34 - 00001021 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk 2015-05-24 19:34 - 2015-05-24 19:34 - 00001009 _____ () C:\Users\Public\Desktop\Audacity.lnk 2015-05-24 19:34 - 2015-05-24 19:34 - 00000965 _____ () C:\Users\Public\Desktop\Steam.lnk 2015-05-24 19:34 - 2015-05-24 19:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2015-05-24 19:34 - 2015-05-24 19:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-05-24 19:34 - 2015-05-24 19:34 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-05-24 19:34 - 2015-05-24 19:34 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-05-24 19:34 - 2015-05-24 19:34 - 00000000 ____D () C:\Program Files (x86)\Audacity 2015-05-24 19:34 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-05-24 19:34 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-05-24 19:34 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-05-24 19:33 - 2015-05-24 19:33 - 00000969 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2015-05-24 19:33 - 2015-05-24 19:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client 2015-05-24 19:33 - 2015-05-24 19:33 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2015-05-24 19:31 - 2015-05-24 19:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\puush 2015-05-24 19:31 - 2015-05-24 19:32 - 00000000 ____D () C:\Program Files (x86)\puush 2015-05-24 19:31 - 2015-05-24 19:31 - 00000945 _____ () C:\Users\Niclas\Desktop\puush.lnk 2015-05-24 19:31 - 2015-05-24 19:31 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\puush 2015-05-24 19:09 - 2015-05-24 19:09 - 00000000 ____D () C:\Windows\pss 2015-05-24 19:06 - 2012-02-17 08:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2015-05-24 19:06 - 2012-02-17 07:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2015-05-24 19:06 - 2012-02-17 06:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2015-05-24 19:02 - 2010-12-31 12:30 - 00252712 _____ (ELAN Microelectronics Corp.) C:\Windows\ETDUninst.dll 2015-05-24 19:00 - 2015-05-24 19:00 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Zeon 2015-05-24 18:59 - 2015-05-24 19:16 - 00003824 _____ () C:\Windows\system32\TmInstall.log 2015-05-24 18:59 - 2015-05-24 18:59 - 00004280 ____N () C:\Windows\SysWOW64\TmInstall.log 2015-05-24 18:55 - 2015-06-01 17:19 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\.minecraft 2015-05-24 18:55 - 2015-05-24 18:55 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\java 2015-05-24 18:53 - 2015-05-24 18:55 - 00000000 ____D () C:\Program Files (x86)\Minecraft 2015-05-24 18:53 - 2015-05-24 18:53 - 00000963 _____ () C:\Users\Public\Desktop\Minecraft.lnk 2015-05-24 18:53 - 2015-05-24 18:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft 2015-05-24 11:54 - 2015-05-24 11:59 - 00000000 ____D () C:\Users\Niclas\Desktop\Minecraft 2015-05-24 11:54 - 2015-05-24 11:58 - 00000000 ____D () C:\Users\Niclas\Desktop\FSX 2015-05-24 11:54 - 2015-05-24 11:54 - 00000000 ____D () C:\Users\Niclas\Desktop\Slender - The Eight Pages_Data 2015-05-24 11:54 - 2014-02-10 13:40 - 00412672 _____ () C:\Users\Niclas\Desktop\samp.exe 2015-05-24 11:54 - 2012-12-26 19:26 - 09152000 _____ () C:\Users\Niclas\Desktop\Slender - The Eight Pages.exe 2015-05-24 11:24 - 2015-05-24 11:24 - 00000000 ____D () C:\Users\Niclas\Documents\convert2mp3_chrome_addon-2.4 2015-05-24 11:24 - 2015-05-23 07:28 - 00021963 _____ () C:\Users\Niclas\Documents\bookmarks_23.05.15.html 2015-05-24 11:23 - 2015-05-24 11:23 - 00003504 _____ () C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-Computer-Niclas 2015-05-24 11:23 - 2015-05-24 11:23 - 00000112 ____H () C:\FD3391613910 2015-05-24 11:23 - 2015-05-24 11:23 - 00000040 ____H () C:\24F61239984E 2015-05-24 11:23 - 2015-05-24 11:23 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2015-05-24 11:22 - 2015-05-24 11:23 - 00000000 ____D () C:\ProgramData\Adobe 2015-05-24 11:21 - 2015-06-02 15:41 - 00000000 ____D () C:\Users\Niclas\Desktop\Photoshop 2015-05-24 11:21 - 2015-06-02 15:41 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Adobe 2015-05-24 11:21 - 2015-05-24 11:21 - 00000000 ____D () C:\Users\Niclas\Desktop\YouTube 2015-05-24 11:19 - 2015-05-24 11:23 - 00000000 ____D () C:\Users\Niclas\Desktop\Schule 2015-05-24 11:17 - 2015-05-26 04:05 - 00002177 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-05-24 11:17 - 2015-05-24 11:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-05-24 11:14 - 2015-06-02 18:04 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-05-24 11:14 - 2015-06-02 14:51 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-05-24 11:14 - 2015-05-24 11:59 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-05-24 11:14 - 2015-05-24 11:59 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-05-24 11:14 - 2015-05-24 11:17 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Google 2015-05-24 11:14 - 2015-05-24 11:16 - 00000000 ____D () C:\Program Files (x86)\Google 2015-05-24 11:14 - 2015-05-24 11:14 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Deployment 2015-05-24 11:14 - 2015-05-24 11:14 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Apps\2.0 2015-05-24 11:13 - 2015-06-02 15:41 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Adobe 2015-05-24 11:04 - 2015-05-24 11:04 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\ASUS WebStorage 2015-05-24 11:02 - 2015-05-29 23:08 - 00061936 _____ () C:\Users\Niclas\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-24 11:02 - 2015-05-26 03:55 - 00001423 _____ () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-05-24 11:02 - 2015-05-24 19:59 - 00000000 ____D () C:\Users\Niclas\AppData\Local\VirtualStore 2015-05-24 11:02 - 2015-05-24 19:39 - 00000000 ____D () C:\Users\Niclas 2015-05-24 11:02 - 2015-05-24 11:03 - 00000000 ___HD () C:\ASUS.DAT 2015-05-24 11:02 - 2015-05-24 11:02 - 00045056 ____N () C:\Windows\SysWOW64\acovcnt.exe 2015-05-24 11:02 - 2015-05-24 11:02 - 00000020 ___SH () C:\Users\Niclas\ntuser.ini 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\Vorlagen 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\Startmenü 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\Netzwerkumgebung 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\Lokale Einstellungen 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\Eigene Dateien 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\Druckumgebung 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\Documents\Eigene Musik 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\Documents\Eigene Bilder 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\AppData\Local\Verlauf 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\AppData\Local\Anwendungsdaten 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 _SHDL () C:\Users\Niclas\Anwendungsdaten 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 ____D () C:\Users\Niclas\AppData\Local\ASUS 2015-05-24 11:02 - 2015-05-24 11:02 - 00000000 ____D () C:\ProgramData\FolderView 2015-05-24 11:02 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-05-24 11:02 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-02 16:04 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-06-02 16:04 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-06-01 15:36 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-06-01 15:36 - 2009-07-14 06:45 - 00280128 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-05-31 11:02 - 2011-02-19 06:24 - 00710980 _____ () C:\Windows\system32\perfh007.dat 2015-05-31 11:02 - 2011-02-19 06:24 - 00153428 _____ () C:\Windows\system32\perfc007.dat 2015-05-31 11:02 - 2009-07-14 07:13 - 01650956 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-05-27 23:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2015-05-26 03:53 - 2009-07-29 08:03 - 00000000 ____D () C:\Windows\Panther 2015-05-26 03:53 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-05-26 03:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\he-IL 2015-05-26 03:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\ar-SA 2015-05-26 03:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\he-IL 2015-05-26 03:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\ar-SA 2015-05-26 03:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-05-26 03:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System 2015-05-26 03:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2015-05-26 03:04 - 2011-10-19 06:11 - 01625236 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-05-26 01:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat 2015-05-25 19:24 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2015-05-25 16:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2015-05-25 16:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism 2015-05-25 16:25 - 2009-07-14 09:45 - 00000000 ____D () C:\Program Files\Windows Journal 2015-05-25 16:25 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Defender 2015-05-25 16:25 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2015-05-25 16:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing 2015-05-25 16:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers 2015-05-25 08:39 - 2011-02-19 06:18 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer 2015-05-25 08:39 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\SysWOW64\winrm 2015-05-25 08:39 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\SysWOW64\WCN 2015-05-25 08:39 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\SysWOW64\sysprep 2015-05-25 08:39 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\SysWOW64\slmgr 2015-05-25 08:39 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts 2015-05-25 08:39 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\system32\winrm 2015-05-25 08:39 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\system32\WCN 2015-05-25 08:39 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\system32\slmgr 2015-05-25 08:39 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts 2015-05-25 08:39 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar 2015-05-25 08:39 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Setup 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\oobe 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\com 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sysprep 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Setup 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\oobe 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\MUI 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\migwiz 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\com 2015-05-25 08:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\servicing 2015-05-25 08:38 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\DigitalLocker 2015-05-25 08:38 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Sidebar 2015-05-25 08:38 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer 2015-05-25 08:38 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\IME 2015-05-25 08:29 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\DVD Maker 2015-05-25 08:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Globalization 2015-05-24 22:27 - 2009-07-29 07:20 - 00000000 ____D () C:\Windows\ASUS 2015-05-24 21:57 - 2009-07-29 07:20 - 00000000 ____D () C:\Windows\Log 2015-05-24 20:47 - 2008-07-14 04:48 - 00087040 _____ (Redmond Pie) C:\Users\Niclas\Desktop\Turn Off LCD.exe 2015-05-24 20:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK 2015-05-24 20:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR 2015-05-24 20:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\zh-HK 2015-05-24 20:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\tr-TR 2015-05-24 19:23 - 2011-10-19 06:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2015-05-24 19:23 - 2011-10-19 06:24 - 00000000 ____D () C:\Program Files (x86)\ASUS 2015-05-24 19:20 - 2011-10-19 06:34 - 00000000 ____D () C:\AsusVibeData 2015-05-24 19:02 - 2011-10-19 06:26 - 00000000 ____D () C:\ProgramData\Deadtime Stories 2015-05-24 19:01 - 2011-10-19 06:34 - 00000000 ____D () C:\ProgramData\Asus 2015-05-24 19:01 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-05-24 18:55 - 2011-10-19 06:36 - 00000000 ____D () C:\ProgramData\Trend Micro 2015-05-24 12:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2015-05-24 11:10 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\restore 2015-05-24 11:05 - 2011-10-19 06:34 - 00000000 ____D () C:\ProgramData\ChangeFolderView 2015-05-24 11:00 - 2009-07-29 07:10 - 00000000 __SHD () C:\Recovery ==================== Files in the root of some directories ======= 2015-05-25 20:34 - 2015-06-02 15:40 - 0001456 _____ () C:\Users\Niclas\AppData\Local\Adobe Save for Web 13.0 Prefs 2011-10-19 06:26 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe 2015-05-24 19:38 - 2015-05-24 19:38 - 0000949 _____ () C:\ProgramData\Turn Off Monitor.ini 2015-05-24 21:47 - 2015-05-24 21:47 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2015-05-24 21:46 - 2015-05-24 21:47 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2015-05-24 21:45 - 2015-05-24 21:46 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log Some files in TEMP: ==================== C:\Users\Niclas\AppData\Local\Temp\selfupdt.exe C:\Users\Niclas\AppData\Local\Temp\wpsetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-24 22:02 ==================== End of log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-05-2015 Ran by Niclas at 2015-06-02 19:02:22 Running from C:\Users\Niclas\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3861039383-3584637288-95791406-500 - Administrator - Disabled) Gast (S-1-5-21-3861039383-3584637288-95791406-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3861039383-3584637288-95791406-1002 - Limited - Enabled) Niclas (S-1-5-21-3861039383-3584637288-95791406-1000 - Administrator - Enabled) => C:\Users\Niclas ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated) Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated) Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.) Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden Apple Application Support (32-Bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.) Apple Application Support (64-Bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: - Apple Inc.) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: - Asmedia Technology) ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.19 - ASUS) ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0013 - ASUS) ASUS FancyStart (HKLM-x32\...\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}) (Version: 1.1.1 - ASUSTeK Computer Inc.) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.28 - ASUS) ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.24 - asus) ASUS_Screensaver (HKLM-x32\...\ASUS_Screensaver) (Version: - ) ATK Hotkey (HKLM-x32\...\{7C05592D-424B-46CB-B505-E0013E8E75C9}) (Version: 1.0.0056 - ASUS) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0014 - ASUS) Audacity 2.1.0 (HKLM-x32\...\Audacity_is1) (Version: 2.1.0 - Audacity Team) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: - Apple Inc.) Cain & Abel 4.9.56 (HKLM-x32\...\Cain & Abel 4.9.56) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.05 - Piriform) Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Elgato Game Capture HD (HKLM-x32\...\{4DB7DE87-F483-4FEF-8633-C48957AB0567}) (Version: - Elgato Systems GmbH) Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS) FFmpeg (Windows) for Audacity Version 2.2.2 (HKLM-x32\...\{9C7E31E3-017F-434C-AC40-24431A354A1E}_is1) (Version: 2.2.2 - ) FFmpeg v0.6.2 for Audacity (HKLM-x32\...\FFmpeg for Audacity_is1) (Version: - ) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Capture HD v2.3.3.38 (HKLM-x32\...\Software_Elgato_Game Capture HD) (Version: - Elgato Systems) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.81 - Google Inc.) Google Update Helper (x32 Version: - Google Inc.) Hidden InstantOn for NB (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 2.1.8 - ASUS) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation) iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: - Apple Inc.) Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) Malwarebytes Anti-Malware Version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5 DEU Language Pack (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: - Mojang) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) puush (HKLM-x32\...\{C3592426-531E-4110-911D-BFECE2CE284B}) (Version: - Dean Herbert) Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 9.2 - Qualcomm Atheros) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.) Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.101 - Skype Technologies S.A.) Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: - Synopsys ) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Vegas Pro 13.0 (64-bit) (HKLM\...\{787F5FA1-CCC3-11E4-ABD4-F04DA23A5C58}) (Version: 13.0.444 - Sony) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.32.3 - ASUS) WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: - Riverbed Technology, Inc.) WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.25 - ASUS) Wise Registry Cleaner 8.52 (HKLM-x32\...\Wise Registry Cleaner_is1) (Version: 8.52 - WiseCleaner.com, Inc.) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= 30-05-2015 08:15:32 DirectX wurde installiert 02-06-2015 14:56:37 Windows Update ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {1B03FBC9-20E7-43B0-915A-4A44333BFC03} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2011-10-03] (ASUS) Task: {27EEF4FF-64D3-4A27-84C9-806AE5AA2EC6} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-05-28] (Avast Software s.r.o.) Task: {30136E5C-C0A6-45D2-A0F2-25311055FBEF} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {4B623A66-5696-42F0-917B-690C6526240F} - System32\Tasks\AdobeAAMUpdater-1.0-Computer-Niclas => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe Task: {9089856D-3446-4133-B6C7-B04FC68FFBB2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-23] (Piriform Ltd) Task: {B6B1F170-C060-4B6F-8C00-B2DE0FC46448} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {B99C47FB-0FB3-4587-8647-382239BA63C1} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation) Task: {D0490536-24DF-4C43-B23D-75C69B706CE8} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-07] (Microsoft Corporation) Task: {D58080A4-6FF5-490E-8D19-8F32FDD6A25A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-24] (Google Inc.) Task: {D66DF0A8-7F41-4C0F-8C0A-B0B879AE5EF1} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks Task: {F567F850-B110-4BF9-A193-6D4FA67F390F} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {FBE58694-944C-40C4-865D-A4CB230B9C38} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22] (ASUS) Task: {FEF665F4-6FEA-4D49-85A8-C3FDF9073801} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-24] (Google Inc.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2015-03-20 18:12 - 2015-03-20 18:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-03-20 18:12 - 2015-03-20 18:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-02-28 11:14 - 2014-02-28 11:14 - 00173568 _____ () C:\Program Files\TeamSpeak 3 Client\quazip.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 01080832 _____ () C:\Program Files\TeamSpeak 3 Client\platforms\qwindows.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00833024 _____ () C:\Program Files\TeamSpeak 3 Client\sqldrivers\qsqlite.dll 2014-08-04 15:43 - 2014-08-04 15:43 - 00102344 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win64.dll 2014-08-04 15:43 - 2014-08-04 15:43 - 00108488 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00030208 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qgif.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00233984 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qjpeg.dll 2014-02-27 16:51 - 2014-02-27 16:51 - 00159232 _____ () C:\Program Files\TeamSpeak 3 Client\accessible\qtaccessiblewidgets.dll 2014-08-04 15:46 - 2014-08-04 15:46 - 00563656 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll 2014-08-04 15:46 - 2014-08-04 15:46 - 00579016 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll 2015-03-20 18:12 - 2015-03-20 18:12 - 00306984 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll 2015-05-28 21:31 - 2015-05-28 21:31 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-05-28 21:31 - 2015-05-28 21:31 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-05-31 13:49 - 2015-05-31 13:49 - 02951680 _____ () C:\Program Files\AVAST Software\Avast\defs\15053100\algo.dll 2015-06-02 18:43 - 2015-06-02 18:43 - 02951680 _____ () C:\Program Files\AVAST Software\Avast\defs\15060201\algo.dll 2015-05-28 21:31 - 2015-05-28 21:31 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-03-20 18:12 - 2015-03-20 18:12 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2011-08-18 00:37 - 2011-08-18 00:37 - 00204800 _____ () C:\Program Files (x86)\asus\VirtualCamera\virtualCamera.ax 2015-05-26 04:05 - 2015-05-22 22:22 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libglesv2.dll 2015-05-26 04:05 - 2015-05-22 22:22 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libegl.dll 2015-03-20 18:12 - 2015-03-20 18:12 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2015-05-26 04:05 - 2015-05-22 22:22 - 14982472 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3861039383-3584637288-95791406-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: AFBAgent => 2 MSCONFIG\Services: ASLDRService => 2 MSCONFIG\Services: ASUS InstantOn => 2 MSCONFIG\Services: ATKGFNEXSrv => 2 MSCONFIG\Services: Avira.OE.ServiceHost => 2 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: LMS => 2 MSCONFIG\Services: UNS => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AsusVibeLauncher.lnk => C:\Windows\pss\AsusVibeLauncher.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk => C:\Windows\pss\FancyStart daemon.lnk.CommonStartup MSCONFIG\startupreg: AmIcoSinglun64 => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: ASUSPRP => "C:\Program Files (x86)\ASUS\APRP\APRP.EXE" MSCONFIG\startupreg: ASUSWebStorage => C:\Program Files (x86)\ASUS\ASUS WebStorage\\AsusWSPanel.exe /S MSCONFIG\startupreg: ATKMEDIA => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe MSCONFIG\startupreg: ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe MSCONFIG\startupreg: Auto LogOff => C:\Program Files (x86)\Turn Off Monitor\AutoLogOff.exe :silent MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: HControlUser => C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe MSCONFIG\startupreg: RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3 MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s MSCONFIG\startupreg: SonicMasterTray => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent MSCONFIG\startupreg: Turn Off Monitor => C:\Program Files (x86)\Turn Off Monitor\TurnOffMon.exe :silent MSCONFIG\startupreg: Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{FDD96A5B-D830-49E1-B8D6-3C634B41B339}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{728C3760-A594-4DED-8B6E-8DD1C4E77369}] => (Allow) LPort=2869 FirewallRules: [{AC882C1F-EBF3-48BF-83D5-5954B640008A}] => (Allow) LPort=1900 FirewallRules: [{58629E3E-7D21-4FC5-8B74-2BCCDB9ECEDF}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{209F67F8-9274-4899-AF62-8973792805E9}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe FirewallRules: [{65EACC38-BBB6-41A2-B5AD-72E68E1B6D81}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{D70C2D34-B8E3-41B4-8FC6-6B93C948E3BB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{64C5BDE7-E76B-4EF0-A68A-5E91C4F65A7D}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{DE2630AE-CBBF-4038-A621-ECDDD1DE4BFC}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C37BC890-BD15-4122-B1AC-7D70E34E1AC4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{905C9208-8DCE-435F-90F0-2CA750F385A5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{5E188568-2B2C-4B99-85B1-3D6F50C0637C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{E779624F-0076-47E4-923C-ACA413E8C5A0}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{C0D1FDF2-9AE4-47A6-BBEA-D583E3F8414B}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{5142A343-47B5-4D60-B328-68AFE6AD724B}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{4B6C5810-784B-4510-BE99-4F3CE73968BA}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{44E70C38-EE68-4358-A5E8-530E5E2867F9}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [{484E9384-3CB9-43D0-AB78-D8867137AD59}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{1A3C763F-02F1-4E37-9528-60DCE4276541}] => (Block) %ProgramFiles%\Sony\Vegas Pro 13.0\vegas130.exe FirewallRules: [{F58503A8-3CD4-4F0D-9553-BC9CD836E8C7}] => (Block) %USERPROFILE%\Desktop\Slender - The Eight Pages.exe FirewallRules: [{25CA935D-19B8-48CB-8DD3-DDB84D007E5A}] => (Block) %USERPROFILE%\Desktop\Turn Off LCD.exe FirewallRules: [{22DAF33D-3485-4D74-8503-13ED68002920}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{BF90597D-E966-45B2-B2E6-B98ABF02B0E0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [TCP Query User{6484B7DD-4618-43E9-ADE0-0C5FF32A5D2A}C:\program files (x86)\cain\cain.exe] => (Allow) C:\program files (x86)\cain\cain.exe FirewallRules: [UDP Query User{BD554B89-8036-413F-B77E-72A363A2C965}C:\program files (x86)\cain\cain.exe] => (Allow) C:\program files (x86)\cain\cain.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/02/2015 09:00:36 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2543 Error: (06/02/2015 09:00:36 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2543 Error: (06/02/2015 09:00:36 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/30/2015 07:59:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15615 Error: (05/30/2015 07:59:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15615 Error: (05/30/2015 07:59:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/30/2015 04:42:00 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm IEXPLORE.EXE, Version 11.0.9600.17801 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1764 Startzeit: 01d09ae6b45fc8fd Endzeit: 5 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: Error: (05/29/2015 03:45:48 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9500 Error: (05/29/2015 03:45:48 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9500 Error: (05/29/2015 03:45:48 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (05/29/2015 02:44:57 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Windows Search" wurde nicht richtig gestartet. Error: (05/29/2015 02:42:07 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1000) (User: NT-AUTORITÄT) Description: Fehler bei der CBS-Clientinitialisierung. Letzter Fehler: 0x80080005 Error: (05/29/2015 02:42:07 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {752073A1-23F2-4396-85F0-8FDB879ED0ED} Error: (05/28/2015 04:42:16 PM) (Source: volsnap) (EventID: 36) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (05/27/2015 02:05:24 PM) (Source: DCOM) (EventID: 10016) (User: Computer) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ComputerNiclasS-1-5-21-3861039383-3584637288-95791406-1000LocalHost (unter Verwendung von LRPC) Error: (05/27/2015 02:04:23 PM) (Source: DCOM) (EventID: 10016) (User: Computer) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ComputerNiclasS-1-5-21-3861039383-3584637288-95791406-1000LocalHost (unter Verwendung von LRPC) Error: (05/27/2015 02:03:53 PM) (Source: DCOM) (EventID: 10016) (User: Computer) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ComputerNiclasS-1-5-21-3861039383-3584637288-95791406-1000LocalHost (unter Verwendung von LRPC) Error: (05/27/2015 00:45:24 PM) (Source: DCOM) (EventID: 10016) (User: Computer) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ComputerNiclasS-1-5-21-3861039383-3584637288-95791406-1000LocalHost (unter Verwendung von LRPC) Error: (05/27/2015 00:45:11 PM) (Source: DCOM) (EventID: 10016) (User: Computer) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ComputerNiclasS-1-5-21-3861039383-3584637288-95791406-1000LocalHost (unter Verwendung von LRPC) Error: (05/26/2015 03:58:49 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80242016 fehlgeschlagen: Kumulatives Sicherheitsupdate für Internet Explorer 9 für Windows 7 für x64-Systeme (KB3049563) Microsoft Office: ========================= Error: (06/02/2015 09:00:36 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2543 Error: (06/02/2015 09:00:36 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2543 Error: (06/02/2015 09:00:36 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/30/2015 07:59:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15615 Error: (05/30/2015 07:59:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15615 Error: (05/30/2015 07:59:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/30/2015 04:42:00 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: IEXPLORE.EXE11.0.9600.17801176401d09ae6b45fc8fd5C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Error: (05/29/2015 03:45:48 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9500 Error: (05/29/2015 03:45:48 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9500 Error: (05/29/2015 03:45:48 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU B940 @ 2.00GHz Percentage of memory in use: 47% Total physical RAM: 4000.13 MB Available physical RAM: 2097.97 MB Total Pagefile: 7998.44 MB Available Pagefile: 5394.3 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:125.03 GB) (Free:52.45 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Data) (Fixed) (Total:148.06 GB) (Free:141.64 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: E3102A4B) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=125 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=148.1 GB) - (Type=07 NTFS) ==================== End of log ============================ |
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Downloade dir bitte ![]()
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
ATTFilter Malwarebytes Anti-Rootkit BETA www.malwarebytes.org Database version: main: v2015.06.04.03 rootkit: v2015.06.02.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.17801 Niclas :: COMPUTER [administrator] 04.06.2015 12:04:40 mbar-log-2015-06-04 (12-04-40).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 352302 Time elapsed: 21 minute(s), 31 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Code:
ATTFilter 11:57:47.0229 0x1558 TDSS rootkit removing tool Jan 22 2015 08:27:04 11:57:49.0351 0x1558 ============================================================ 11:57:49.0351 0x1558 Current date / time: 2015/06/04 11:57:49.0351 11:57:49.0351 0x1558 SystemInfo: 11:57:49.0351 0x1558 11:57:49.0351 0x1558 OS Version: 6.1.7601 ServicePack: 1.0 11:57:49.0352 0x1558 Product type: Workstation 11:57:49.0352 0x1558 ComputerName: COMPUTER 11:57:49.0352 0x1558 UserName: Niclas 11:57:49.0352 0x1558 Windows directory: C:\Windows 11:57:49.0352 0x1558 System windows directory: C:\Windows 11:57:49.0352 0x1558 Running under WOW64 11:57:49.0352 0x1558 Processor architecture: Intel x64 11:57:49.0352 0x1558 Number of processors: 2 11:57:49.0352 0x1558 Page size: 0x1000 11:57:49.0352 0x1558 Boot type: Normal boot 11:57:49.0352 0x1558 ============================================================ 11:57:49.0489 0x1558 KLMD registered as C:\Windows\system32\drivers\96015528.sys 11:57:49.0972 0x1558 System UUID: {69FF62BA-24D7-FD3B-E5ED-9BECFC19F07A} 11:57:50.0525 0x1558 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 11:57:50.0529 0x1558 ============================================================ 11:57:50.0529 0x1558 \Device\Harddisk0\DR0: 11:57:50.0529 0x1558 MBR partitions: 11:57:50.0529 0x1558 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3200800, BlocksNum 0xFA0E000 11:57:50.0529 0x1558 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x12C0E800, BlocksNum 0x1281F800 11:57:50.0529 0x1558 ============================================================ 11:57:50.0550 0x1558 C: <-> \Device\Harddisk0\DR0\Partition1 11:57:50.0594 0x1558 D: <-> \Device\Harddisk0\DR0\Partition2 11:57:50.0594 0x1558 ============================================================ 11:57:50.0595 0x1558 Initialize success 11:57:50.0595 0x1558 ============================================================ 11:57:51.0767 0x11e8 ============================================================ 11:57:51.0767 0x11e8 Scan started 11:57:51.0767 0x11e8 Mode: Manual; 11:57:51.0767 0x11e8 ============================================================ 11:57:51.0767 0x11e8 KSN ping started 11:57:54.0243 0x11e8 KSN ping finished: true 11:57:54.0773 0x11e8 ================ Scan system memory ======================== 11:57:54.0773 0x11e8 Scan was interrupted by user! 11:57:54.0821 0x11e8 AV detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 10.2.2218.942 ), 0x41000 ( enabled : updated ) 11:57:54.0826 0x11e8 Win FW state via NFP2: enabled 11:57:57.0351 0x11e8 ============================================================ 11:57:57.0351 0x11e8 Scan finished 11:57:57.0351 0x11e8 ============================================================ 11:57:57.0362 0x103c Detected object count: 0 11:57:57.0362 0x103c Actual detected object count: 0 |
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
ATTFilter ComboFix 15-05-31.01 - Niclas 04.06.2015 22:08:43.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4000.1785 [GMT 2:00] ausgeführt von:: c:\users\Niclas\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2015-05-04 bis 2015-06-04 )))))))))))))))))))))))))))))) . . 2015-06-04 20:17 . 2015-06-04 20:17 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-06-04 20:14 . 2015-06-04 20:14 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2A0D57BF-A2E0-467F-A21F-57E0621E8C94}\offreg.5432.dll 2015-06-03 20:08 . 2015-06-04 10:59 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable) 2015-06-03 20:08 . 2015-06-04 10:04 136408 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2015-06-03 15:23 . 2015-06-03 15:23 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2A0D57BF-A2E0-467F-A21F-57E0621E8C94}\offreg.2140.dll 2015-06-02 17:00 . 2015-06-02 17:03 -------- d-----w- C:\FRST 2015-06-02 12:57 . 2015-05-18 02:57 12214312 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2A0D57BF-A2E0-467F-A21F-57E0621E8C94}\mpengine.dll 2015-05-30 14:44 . 2015-05-30 14:44 -------- d-----w- c:\program files (x86)\WinPcap 2015-05-30 14:43 . 2015-06-03 20:34 -------- d-----w- c:\program files (x86)\Cain 2015-05-28 19:32 . 2015-05-28 19:32 93528 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2015-05-28 19:32 . 2015-05-28 19:32 89944 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2015-05-28 19:32 . 2015-05-28 19:32 65736 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2015-05-28 19:32 . 2015-05-28 19:32 442264 ----a-w- c:\windows\system32\drivers\aswSP.sys 2015-05-28 19:32 . 2015-05-28 19:32 29168 ----a-w- c:\windows\system32\drivers\aswHwid.sys 2015-05-28 19:32 . 2015-05-28 19:32 272248 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2015-05-28 19:32 . 2015-05-28 19:32 137288 ----a-w- c:\windows\system32\drivers\aswStm.sys 2015-05-28 19:32 . 2015-05-28 19:31 1047320 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2015-05-28 19:32 . 2015-05-28 19:32 364472 ----a-w- c:\windows\system32\aswBoot.exe 2015-05-28 19:31 . 2015-05-28 19:31 43112 ----a-w- c:\windows\avastSS.scr 2015-05-28 19:28 . 2015-05-28 19:28 -------- d-----w- c:\program files\AVAST Software 2015-05-28 19:27 . 2015-05-28 19:27 -------- d-----w- c:\programdata\AVAST Software 2015-05-27 10:29 . 2015-05-27 11:05 -------- d-----w- c:\program files (x86)\Ffmpeg For Audacity 2015-05-27 10:05 . 2015-05-27 10:05 -------- d-s---w- c:\windows\SysWow64\GWX 2015-05-27 10:05 . 2015-05-27 10:06 -------- d-s---w- c:\windows\system32\GWX 2015-05-26 15:05 . 2015-04-21 16:26 968704 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2015-05-26 15:01 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe 2015-05-26 15:01 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe 2015-05-26 07:38 . 2015-05-26 07:38 -------- d-----w- c:\programdata\Sony 2015-05-26 07:38 . 2015-05-26 07:38 -------- d-----w- c:\program files (x86)\Sony 2015-05-26 07:38 . 2015-05-26 07:38 -------- d-----w- c:\program files\Sony 2015-05-26 07:13 . 2015-05-26 07:13 -------- d-----w- c:\program files\WinRAR 2015-05-26 01:22 . 2013-10-14 16:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE 2015-05-26 01:00 . 2014-06-27 02:08 2777088 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2015-05-26 01:00 . 2014-06-27 01:45 2285056 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2015-05-26 01:00 . 2015-05-26 01:00 -------- d-----w- c:\program files (x86)\MSXML 4.0 2015-05-25 14:25 . 2015-05-25 14:25 -------- d-s---w- c:\windows\system32\CompatTel 2015-05-25 14:25 . 2015-05-25 14:25 -------- d-----w- c:\windows\system32\appraiser 2015-05-25 13:14 . 2015-05-25 13:14 -------- d-----w- c:\program files (x86)\Lame For Audacity 2015-05-25 11:19 . 2015-05-25 11:19 -------- d-----w- c:\windows\Migration 2015-05-25 10:56 . 2012-07-26 07:46 2560 ----a-w- c:\windows\system32\drivers\de-DE\wdf01000.sys.mui 2015-05-25 10:25 . 2015-05-25 10:25 -------- d-----w- c:\program files (x86)\Common Files\Java 2015-05-25 10:25 . 2015-05-25 10:23 97888 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2015-05-25 10:23 . 2015-05-25 10:23 -------- d-----w- c:\program files (x86)\Java 2015-05-25 10:15 . 2015-05-25 10:23 -------- d-----w- c:\programdata\Oracle 2015-05-25 10:09 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll 2015-05-25 10:09 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2015-05-25 10:09 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll 2015-05-25 10:09 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2015-05-25 10:09 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2015-05-25 10:09 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe 2015-05-25 10:09 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll 2015-05-25 10:04 . 2015-05-01 13:17 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-05-25 10:04 . 2015-05-01 13:16 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll 2015-05-25 10:00 . 2015-05-25 10:00 -------- d-----w- c:\program files\Microsoft Silverlight 2015-05-25 10:00 . 2015-05-25 10:00 -------- d-----w- c:\program files (x86)\Microsoft Silverlight 2015-05-25 09:59 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2015-05-25 09:59 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll 2015-05-25 09:59 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll 2015-05-25 09:49 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll 2015-05-25 09:49 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe 2015-05-25 09:49 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll 2015-05-25 09:49 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe 2015-05-25 09:49 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll 2015-05-25 09:49 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll 2015-05-25 09:49 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe 2015-05-25 09:49 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe 2015-05-25 09:46 . 2015-04-11 03:19 69888 ----a-w- c:\windows\system32\drivers\stream.sys 2015-05-25 09:18 . 2015-02-03 03:31 5120 ----a-w- c:\windows\system32\msdxm.ocx 2015-05-25 09:17 . 2015-01-09 03:14 91136 ----a-w- c:\windows\system32\wdi.dll 2015-05-25 09:15 . 2014-03-04 09:44 722944 ----a-w- c:\windows\system32\objsel.dll 2015-05-25 09:14 . 2015-04-20 03:17 1647104 ----a-w- c:\windows\system32\DWrite.dll 2015-05-25 09:11 . 2012-10-03 17:44 216576 ----a-w- c:\windows\system32\ncsi.dll 2015-05-25 09:10 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll 2015-05-25 09:09 . 2014-01-29 02:32 484864 ----a-w- c:\windows\system32\wer.dll 2015-05-25 09:05 . 2015-03-05 05:12 404480 ----a-w- c:\windows\system32\gdi32.dll 2015-05-25 09:04 . 2015-03-10 03:25 1882624 ----a-w- c:\windows\system32\msxml3.dll 2015-05-25 09:03 . 2013-09-08 02:27 327168 ----a-w- c:\windows\system32\mswsock.dll 2015-05-25 09:02 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll 2015-05-25 09:02 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax 2015-05-25 09:02 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll 2015-05-25 09:02 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax 2015-05-25 09:01 . 2014-11-26 03:53 861696 ----a-w- c:\windows\system32\oleaut32.dll 2015-05-25 09:01 . 2014-11-26 03:32 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll 2015-05-25 09:01 . 2013-08-29 02:13 878080 ----a-w- c:\windows\system32\advapi32.dll 2015-05-25 09:01 . 2013-08-29 02:16 859648 ----a-w- c:\windows\system32\tdh.dll 2015-05-25 09:01 . 2013-08-29 01:50 619520 ----a-w- c:\windows\SysWow64\tdh.dll 2015-05-25 09:01 . 2013-08-29 01:48 640512 ----a-w- c:\windows\SysWow64\advapi32.dll 2015-05-25 09:00 . 2012-03-17 07:58 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys 2015-05-25 09:00 . 2015-02-18 07:06 123904 ----a-w- c:\windows\SysWow64\poqexec.exe 2015-05-25 09:00 . 2015-02-18 07:04 142336 ----a-w- c:\windows\system32\poqexec.exe 2015-05-25 09:00 . 2014-11-11 03:08 241152 ----a-w- c:\windows\system32\pku2u.dll 2015-05-25 09:00 . 2014-11-11 02:44 186880 ----a-w- c:\windows\SysWow64\pku2u.dll 2015-05-25 08:59 . 2015-02-25 03:18 754688 ----a-w- c:\windows\system32\drivers\http.sys 2015-05-25 08:59 . 2012-07-06 20:07 552960 ----a-w- c:\windows\system32\drivers\bthport.sys 2015-05-25 08:59 . 2014-02-04 02:35 190912 ----a-w- c:\windows\system32\drivers\storport.sys 2015-05-25 08:59 . 2014-02-04 02:35 274880 ----a-w- c:\windows\system32\drivers\msiscsi.sys 2015-05-25 08:59 . 2014-02-04 02:35 27584 ----a-w- c:\windows\system32\drivers\Diskdump.sys 2015-05-25 08:59 . 2014-02-04 02:28 2048 ----a-w- c:\windows\system32\iologmsg.dll 2015-05-25 08:59 . 2014-02-04 02:00 2048 ----a-w- c:\windows\SysWow64\iologmsg.dll 2015-05-25 08:59 . 2012-09-25 22:47 78336 ----a-w- c:\windows\SysWow64\synceng.dll 2015-05-25 08:59 . 2012-09-25 22:46 95744 ----a-w- c:\windows\system32\synceng.dll 2015-05-25 08:59 . 2013-07-26 02:24 197120 ----a-w- c:\windows\system32\shdocvw.dll 2015-05-25 08:57 . 2014-11-08 03:16 2048 ----a-w- c:\windows\system32\tzres.dll 2015-05-25 08:57 . 2014-11-08 02:45 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2015-05-25 08:57 . 2015-03-04 04:41 6656 ----a-w- c:\windows\system32\shimeng.dll 2015-05-25 08:57 . 2015-03-04 04:41 72192 ----a-w- c:\windows\system32\aelupsvc.dll 2015-05-25 08:57 . 2015-03-04 04:41 342016 ----a-w- c:\windows\system32\apphelp.dll 2015-05-25 08:57 . 2015-03-04 04:41 23552 ----a-w- c:\windows\system32\sdbinst.exe 2015-05-25 08:57 . 2015-03-04 04:11 5120 ----a-w- c:\windows\SysWow64\shimeng.dll 2015-05-25 08:57 . 2015-03-04 04:10 295936 ----a-w- c:\windows\SysWow64\apphelp.dll 2015-05-25 08:57 . 2015-03-04 04:10 20992 ----a-w- c:\windows\SysWow64\sdbinst.exe 2015-05-25 08:57 . 2014-10-25 01:57 77824 ----a-w- c:\windows\system32\packager.dll 2015-05-25 08:57 . 2014-10-25 01:32 67584 ----a-w- c:\windows\SysWow64\packager.dll 2015-05-25 08:55 . 2013-01-24 06:01 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys 2015-05-25 08:54 . 2013-10-12 02:29 859648 ----a-w- c:\windows\system32\IKEEXT.DLL 2015-05-25 08:54 . 2013-10-12 02:29 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL 2015-05-25 08:54 . 2013-10-12 02:30 830464 ----a-w- c:\windows\system32\nshwfp.dll 2015-05-25 08:54 . 2013-10-12 02:03 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll 2015-05-25 08:54 . 2013-10-12 02:01 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL 2015-05-25 08:54 . 2015-03-04 04:55 367552 ----a-w- c:\windows\system32\clfs.sys 2015-05-25 08:54 . 2015-03-04 04:41 79360 ----a-w- c:\windows\system32\clfsw32.dll 2015-05-25 08:54 . 2015-03-04 04:10 58880 ----a-w- c:\windows\SysWow64\clfsw32.dll 2015-05-25 08:53 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll 2015-05-25 08:49 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll 2015-05-25 08:46 . 2015-02-04 03:16 465920 ----a-w- c:\windows\system32\WMPhoto.dll . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-05-24 17:16 . 2011-03-29 01:36 23776 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2015-03-17 04:56 . 2015-05-25 09:04 44032 ----a-w- c:\windows\apppatch\acwow64.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-05-14 28917376] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2015-04-30 334896] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-05-28 5515496] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) . R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 MBAMService;MBAMService;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x] R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R4 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x] R4 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe;c:\program files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [x] R4 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x] S3 ElgatoGC658Y;Elgato Game Capture;c:\windows\system32\Drivers\ElgatoGC658.sys;c:\windows\SYSNATIVE\Drivers\ElgatoGC658.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - 41811398 *NewlyCreated* - 95934652 *Deregistered* - 41811398 *Deregistered* - 95934652 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2015-05-26 02:05 986440 ----a-w- c:\program files (x86)\Google\Chrome\Application\43.0.2357.81\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2015-06-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-05-24 09:14] . 2015-06-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-05-24 09:14] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2015-05-28 19:32 722400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://asus.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2015-06-04 22:21:04 ComboFix-quarantined-files.txt 2015-06-04 20:21 . Vor Suchlauf: 10 Verzeichnis(se), 54.384.656.384 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 55.624.798.208 Bytes frei . - - End Of File - - CEDCF0EF4BD03092117A540039E62519 |
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #11 |
![]() | #12 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Maus klickt doppelt - Notebook-Sensormaus aber nicht Herstellerseite deines Gerätes ansteuern, Seriennummer eintippen, Support > Treiber > Download (oder so ähnlich) und oben genannte Treiber neu laden und installieren ![]() Du hast nen Hardwarefehler an den USB Anschlüssen.
Themen zu Maus klickt doppelt - Notebook-Sensormaus aber nicht |
