|
Netzwerk und Hardware: Steamprobleme: werbung, lange seitenladezeitenWindows 7 Hilfe zu Motherboards, CPUs, Lüfter, Raid-Controller, Digitalkameras, Treiber usw. Bitte alle relevanten Angaben zur Hardware machen. Welche Hardware habe ich? Themen zum Trojaner Entfernen oder Viren Beseitigung bitte in den Bereinigungsforen des Trojaner-Boards posten. |
29.07.2015, 07:31 | #1 |
| Steamprobleme: werbung, lange seitenladezeiten Hallo Leute, ich brauche bitte eure Hilfe. Mein Steam client macht mir große (nervige) Probleme und zwar sind die Ladezeiten der Spieleseiten teilweise extrem lang bei meiner Kabeldeutschland 100 verbindung. Dann öffnen sich immer wieder lästige Werbungen egal worauf man klickt. (kleine Info, ich habe mir bei Steam Anno Online geladen und sogar wenn ich das Spiel starte, ist im Login Bildschirm des Spiels Werbung) Und ich bin mir nicht sicher ob das normal ist aber sobald der Steamclient im Vordergrund ist habe ich einen kleinen Pfeil neben meinem Cursor (sieht so ähnlich aus wie der Pfeil zum Aktuallisieren der Seite bei Firefox) Ich hoffe mir kann hier jemand helfen. Vielen dank im vorraus. MfG asroC |
29.07.2015, 10:15 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Steamprobleme: werbung, lange seitenladezeiten Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
29.07.2015, 12:19 | #3 |
| Steamprobleme: werbung, lange seitenladezeitenCode:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:28-07-2015 durchgeführt von dima (Administrator) auf DIMA-PC (29-07-2015 13:12:54) Gestartet von E:\ Geladene Profile: dima (Verfügbare Profile: dima) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Reputation\fsorsp.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\fsgk32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSMA32.EXE (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSHDLL64.EXE (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\fssm32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSM32.EXE (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (Valve Corporation) F:\Steam\Steam.exe (Valve Corporation) F:\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) F:\Steam\bin\steamwebhelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Valve Corporation) F:\Steam\bin\steamwebhelper.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Nicht auf der Ausnahmeliste) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-24] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672152 2014-05-09] (Realtek Semiconductor) HKLM-x32\...\Run: [F-Secure Hoster (44553)] => C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe [187432 2015-04-02] (F-Secure Corporation) HKLM-x32\...\Run: [F-Secure Manager] => C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSM32.EXE [310312 2015-06-12] (F-Secure Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation) HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-08-08] (Microsoft Corporation) Startup: C:\Users\dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2015-03-13] () CHR HKLM\SOFTWARE\Policies\Google: Richtlinienbeschränkung <======= ATTENTION ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..) HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\S-1-5-21-2825088377-2055153963-3447657259-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://de.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2825088377-2055153963-3447657259-1001 -> {94A87168-FE2A-401F-A56C-01C7B43BC6E0} URL = https://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default BHO: Browsing Protection -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https64.dll [2015-07-28] (F-Secure Corporation) BHO-x32: Browsing Protection -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll [2015-07-28] (F-Secure Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Java\bin\ssv.dll [2015-07-29] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Java\bin\jp2ssv.dll [2015-07-29] (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{0373DD93-ECE7-4CA9-A78C-A7A8464926AC}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{B4DCCF8B-5EAA-4307-86FF-CA4A7CBB8471}: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\dima\AppData\Roaming\Mozilla\Firefox\Profiles\da84kea6.default FF DefaultSearchEngine: 1&1 Suche FF SelectedSearchEngine: Safe Search FF Homepage: https://de.yahoo.com/?fr=yset_ff_syc_oracle&type=orcl_hpset FF Keyword.URL: hxxp://search.f-secure.com/kabeldeutschland/search?query= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-29] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-29] () FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> D:\Java\bin\dtplugin\npDeployJava1.dll [2015-07-29] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> D:\Java\bin\plugin2\npjp2.dll [2015-07-29] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-06-17] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-06-17] (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF SearchPlugin: C:\Users\dima\AppData\Roaming\Mozilla\Firefox\Profiles\da84kea6.default\searchplugins\f-secure-safe-search.xml [2015-07-14] FF SearchPlugin: C:\Users\dima\AppData\Roaming\Mozilla\Firefox\Profiles\da84kea6.default\searchplugins\yahoo-ysp.xml [2015-07-29] FF Extension: GMX MailCheck - C:\Users\dima\AppData\Roaming\Mozilla\Firefox\Profiles\da84kea6.default\Extensions\mailcheck@gmx.net [2015-07-14] FF Extension: Firefox Helper - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\e68829ca6b0caddec6012a89eae272fb [2015-04-12] FF HKLM-x32\...\Firefox\Extensions: [{25229c00-7179-4193-84ae-557da142fdcf}] - C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\bin\browser\deploy\fs_firefox_https FF Extension: Browsing Protection - C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\bin\browser\deploy\fs_firefox_https [2015-04-25] FF HKU\S-1-5-21-2825088377-2055153963-3447657259-1001\...\Firefox\Extensions: [safesearch@f-secure.com] - C:\Users\dima\AppData\Roaming\F-Secure\SafeSearch\FFPlugIn FF Extension: Safe Search - C:\Users\dima\AppData\Roaming\F-Secure\SafeSearch\FFPlugIn [2015-04-25] Chrome: ======= CHR Profile: C:\Users\dima\AppData\Local\Google\Chrome\User Data\Default CHR HKLM-x32\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - C:/Program Files (x86)/Kabel Deutschland/apps/CCF_Scanning/bin/browser/install/fs_chrome_https/fs_chrome_https.crx [2014-09-08] ==================== Services (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [238376 2015-07-29] (EasyAntiCheat Ltd) R2 fshoster; C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe [187432 2015-04-02] (F-Secure Corporation) R3 FSMA; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSMA32.EXE [216104 2015-06-12] (F-Secure Corporation) R2 FSORSPClient; C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Reputation\fsorsp.exe [60456 2015-04-25] (F-Secure Corporation) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-06-24] (NVIDIA Corporation) R2 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144 2009-09-30] (Intel Corporation) [Datei ist nicht signiert] R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [Datei ist nicht signiert] R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1868432 2015-06-24] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23007376 2015-06-24] (NVIDIA Corporation) R2 UNS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation) [Datei ist nicht signiert] S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 F-Secure Gatekeeper; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [208424 2015-07-25] (F-Secure Corporation) R1 F-Secure HIPS; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\HIPS\drivers\fshs.sys [71080 2015-07-14] (F-Secure Corporation) R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [55336 2015-07-25] () R3 fsni; C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\bin\fsni64.sys [97832 2015-07-28] (F-Secure Corporation) R1 fsvista; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [13352 2015-06-12] () R3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech Inc.) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-06-24] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46768 2015-05-19] (NVIDIA Corporation) R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions) S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-07-29 13:12 - 2015-07-29 13:12 - 00000000 ____D C:\FRST 2015-07-29 12:12 - 2015-07-29 12:12 - 00000000 ____D C:\Users\dima\AppData\Roaming\7DaysToDie 2015-07-29 11:20 - 2015-07-29 11:23 - 00000000 ____D C:\Users\dima\Documents\HeroesOfSoulcraft 2015-07-29 08:44 - 2015-07-29 08:45 - 00000000 ____D C:\AdwCleaner 2015-07-29 08:05 - 2015-07-29 09:04 - 00000504 _____ C:\Windows\setupact.log 2015-07-29 08:05 - 2015-07-29 08:05 - 00000000 _____ C:\Windows\setuperr.log 2015-07-29 08:04 - 2015-07-29 08:04 - 00001664 _____ C:\Windows\PFRO.log 2015-07-29 07:57 - 2015-07-29 07:57 - 00000000 ____D C:\Windows\pss 2015-07-29 07:47 - 2015-07-29 07:47 - 00000020 _____ C:\Windows\Tø¯ 2015-07-29 07:35 - 2015-07-29 07:35 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-07-29 07:35 - 2015-07-29 07:35 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-29 07:14 - 2015-07-29 07:14 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-07-29 07:14 - 2015-07-29 07:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-07-29 07:01 - 2015-07-29 07:02 - 00000090 _____ C:\ProgramData\PS.log 2015-07-29 06:38 - 2015-07-29 13:00 - 00000000 ____D C:\Users\dima\AppData\Local\Anno Online 2015-07-28 23:59 - 2015-07-28 23:59 - 00000000 ____D C:\Users\dima\AppData\Local\CEF 2015-07-25 00:50 - 2015-07-15 05:19 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2015-07-25 00:50 - 2015-07-15 05:19 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-07-25 00:50 - 2015-07-15 05:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2015-07-25 00:50 - 2015-07-15 05:19 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2015-07-25 00:50 - 2015-07-15 04:55 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2015-07-25 00:50 - 2015-07-15 04:55 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2015-07-25 00:50 - 2015-07-15 04:55 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2015-07-25 00:50 - 2015-07-15 04:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2015-07-25 00:50 - 2015-07-15 03:59 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-07-25 00:50 - 2015-07-15 03:52 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2015-07-15 17:33 - 2015-06-25 20:09 - 00389832 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-07-15 17:33 - 2015-06-25 19:43 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-07-15 17:33 - 2015-06-20 22:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-07-15 17:33 - 2015-06-20 21:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-07-15 17:33 - 2015-06-20 21:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-07-15 17:33 - 2015-06-20 21:49 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-07-15 17:33 - 2015-06-20 21:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-07-15 17:33 - 2015-06-20 21:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-07-15 17:33 - 2015-06-20 21:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-07-15 17:33 - 2015-06-20 21:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-07-15 17:33 - 2015-06-20 21:34 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-07-15 17:33 - 2015-06-20 21:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-07-15 17:33 - 2015-06-20 21:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-07-15 17:33 - 2015-06-20 21:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-07-15 17:33 - 2015-06-20 21:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-07-15 17:33 - 2015-06-20 21:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-07-15 17:33 - 2015-06-20 21:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-07-15 17:33 - 2015-06-20 21:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-07-15 17:33 - 2015-06-20 21:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-07-15 17:33 - 2015-06-20 20:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-07-15 17:33 - 2015-06-20 20:48 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-07-15 17:33 - 2015-06-20 20:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-07-15 17:33 - 2015-06-20 20:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-07-15 17:33 - 2015-06-20 20:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-07-15 17:33 - 2015-06-20 20:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-07-15 17:33 - 2015-06-19 20:25 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-07-15 17:33 - 2015-06-19 20:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-07-15 17:33 - 2015-06-19 20:24 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-07-15 17:33 - 2015-06-19 20:24 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-07-15 17:33 - 2015-06-19 20:23 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-07-15 17:33 - 2015-06-19 20:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-07-15 17:33 - 2015-06-19 20:16 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-07-15 17:33 - 2015-06-19 20:13 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-07-15 17:33 - 2015-06-19 20:13 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-07-15 17:33 - 2015-06-19 20:03 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-07-15 17:33 - 2015-06-19 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-07-15 17:33 - 2015-06-19 19:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-07-15 17:33 - 2015-06-19 19:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-07-15 17:33 - 2015-06-19 19:51 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-07-15 17:33 - 2015-06-19 19:40 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-07-15 17:33 - 2015-06-19 19:40 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-07-15 17:33 - 2015-06-19 19:39 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-07-15 17:33 - 2015-06-19 19:15 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-07-15 17:33 - 2015-06-19 19:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-07-15 17:26 - 2015-07-02 23:21 - 19877376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-07-15 17:26 - 2015-07-02 23:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-07-15 17:26 - 2015-07-02 22:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-07-15 17:26 - 2015-07-02 22:49 - 25193984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-07-15 17:26 - 2015-07-02 22:46 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-07-15 17:26 - 2015-07-02 22:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-07-15 17:26 - 2015-07-02 22:19 - 12855296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-07-15 17:26 - 2015-07-02 22:12 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-07-15 17:26 - 2015-07-02 21:55 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-07-15 17:26 - 2015-07-02 21:20 - 14453248 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-07-15 17:26 - 2015-07-02 20:59 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-07-15 17:26 - 2015-06-27 04:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-07-15 17:26 - 2015-06-27 04:43 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-07-15 17:26 - 2015-06-27 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-07-15 17:26 - 2015-06-27 03:39 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-07-15 17:26 - 2015-06-25 10:57 - 03207168 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-07-15 17:26 - 2015-06-17 19:47 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-07-15 17:26 - 2015-06-17 19:37 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-07-15 17:26 - 2015-06-02 02:07 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll 2015-07-15 17:26 - 2015-06-02 01:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll 2015-07-15 17:25 - 2015-07-02 22:23 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-07-15 17:21 - 2015-07-04 20:07 - 02087424 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2015-07-15 17:21 - 2015-07-04 19:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2015-07-15 17:21 - 2015-07-01 22:56 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-07-15 17:21 - 2015-07-01 22:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-07-15 17:21 - 2015-07-01 22:49 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-07-15 17:21 - 2015-07-01 22:48 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2015-07-15 17:21 - 2015-07-01 22:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-07-15 17:21 - 2015-07-01 22:47 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-07-15 17:21 - 2015-07-01 22:47 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-07-15 17:21 - 2015-07-01 22:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-07-15 17:21 - 2015-07-01 22:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-07-15 17:21 - 2015-07-01 22:39 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-07-15 17:21 - 2015-07-01 22:29 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2015-07-15 17:21 - 2015-07-01 22:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-07-15 17:21 - 2015-07-01 22:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-07-15 17:21 - 2015-07-01 22:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-07-15 17:21 - 2015-07-01 22:26 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-07-15 17:21 - 2015-07-01 22:24 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-07-15 17:21 - 2015-07-01 21:27 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-07-15 17:21 - 2015-07-01 21:26 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-07-15 17:21 - 2015-07-01 21:26 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-07-15 17:21 - 2015-06-15 23:45 - 03242496 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2015-07-15 17:21 - 2015-06-15 23:45 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-07-15 17:21 - 2015-06-15 23:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2015-07-15 17:20 - 2015-06-15 23:50 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2015-07-15 17:20 - 2015-06-15 23:45 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2015-07-15 17:20 - 2015-06-15 23:45 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2015-07-15 17:20 - 2015-06-15 23:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2015-07-15 17:20 - 2015-06-15 23:43 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2015-07-15 17:20 - 2015-06-15 23:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2015-07-15 17:20 - 2015-06-15 23:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2015-07-15 17:20 - 2015-06-15 23:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2015-07-15 17:20 - 2015-06-15 23:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2015-07-14 19:12 - 2015-07-14 19:12 - 00000320 _____ C:\Users\dima\Desktop\Magic The Gathering Online .appref-ms 2015-07-14 19:12 - 2015-07-14 19:12 - 00000000 ____D C:\Users\dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wizards of the Coast 2015-07-14 19:12 - 2015-07-14 19:12 - 00000000 ____D C:\Users\dima\AppData\Local\Wizards of the Coast 2015-07-14 19:12 - 2015-07-14 19:12 - 00000000 ____D C:\ProgramData\Gibraltar 2015-07-14 19:09 - 2015-06-17 08:03 - 00571024 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2015-07-14 19:06 - 2015-07-14 19:06 - 00000000 ____D C:\ProgramData\boost_interprocess 2015-07-14 19:06 - 2015-06-17 11:10 - 42729104 _____ C:\Windows\system32\nvcompiler.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 37748880 ____N C:\Windows\SysWOW64\nvcompiler.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 30481552 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 22947144 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 16145200 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 14497520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 13263056 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 11831856 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 11011216 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-07-14 19:06 - 2015-06-17 11:10 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 02599752 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 01898128 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435330.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 01557832 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435330.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 01099992 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 01060168 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 01050768 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00982672 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00975176 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00938752 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00204648 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2015-07-14 19:06 - 2015-06-17 11:10 - 00176904 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00155280 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00128696 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00040280 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2015-07-14 19:00 - 2015-05-19 05:29 - 00046768 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2015-07-14 19:00 - 2015-05-19 05:14 - 00057520 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2015-07-14 17:53 - 2015-05-09 05:27 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-07-14 17:53 - 2015-05-09 05:27 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-07-14 17:53 - 2015-05-09 05:27 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-07-14 17:53 - 2015-05-09 05:27 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-07-14 17:53 - 2015-05-09 05:26 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-07-14 17:53 - 2015-05-09 05:26 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-07-14 17:53 - 2015-05-09 05:26 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-07-14 17:53 - 2015-05-09 05:25 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-07-14 17:53 - 2015-05-09 05:20 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:13 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-07-14 17:53 - 2015-05-09 05:13 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-07-14 17:53 - 2015-05-09 05:12 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-07-14 17:53 - 2015-05-09 05:12 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-07-14 17:53 - 2015-05-09 05:12 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 04:01 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-07-14 17:53 - 2015-05-09 04:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-07-14 17:53 - 2015-05-09 03:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 03:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-07-14 17:53 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-07-14 17:53 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-07-14 17:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-07-14 17:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-07-14 17:53 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-07-14 17:53 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2015-07-14 17:53 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2015-07-14 17:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2015-07-14 17:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2015-07-14 17:53 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2015-07-14 17:53 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-07-14 17:53 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-07-29 13:03 - 2015-03-13 20:11 - 00000000 ____D C:\Users\dima\AppData\Local\Deployment 2015-07-29 12:09 - 2014-09-25 17:21 - 00238376 _____ (EasyAntiCheat Ltd) C:\Windows\SysWOW64\EasyAntiCheat.exe 2015-07-29 11:55 - 2014-08-06 21:50 - 00000000 ____D C:\Users\dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2015-07-29 09:12 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-29 09:12 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-29 09:07 - 2014-08-06 18:34 - 01836384 _____ C:\Windows\WindowsUpdate.log 2015-07-29 09:04 - 2014-08-06 18:39 - 00000000 ____D C:\ProgramData\NVIDIA 2015-07-29 09:04 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-29 08:03 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2015-07-29 07:56 - 2014-08-06 20:58 - 00000000 ____D C:\Users\dima 2015-07-29 07:55 - 2010-08-31 13:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer 2015-07-29 07:55 - 2010-08-31 13:27 - 00000000 ____D C:\Program Files (x86)\Acer 2015-07-29 07:36 - 2015-03-25 12:25 - 00000000 ____D C:\Users\dima\AppData\Local\Adobe 2015-07-29 07:19 - 2015-04-25 23:03 - 00000000 ____D C:\Users\dima\AppData\Local\F-Secure 2015-07-29 07:15 - 2015-04-11 15:48 - 00000000 ____D C:\ProgramData\Oracle 2015-07-29 07:02 - 2014-08-06 18:42 - 00000000 ____D C:\ProgramData\CyberLink 2015-07-29 07:02 - 2010-08-31 13:15 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2015-07-29 06:52 - 2015-05-03 01:06 - 00000000 ____D C:\Program Files (x86)\Universal Media Server 2015-07-29 06:52 - 2010-08-31 13:31 - 00000000 ____D C:\ProgramData\Nero 2015-07-29 06:51 - 2010-08-31 13:31 - 00000000 ____D C:\Program Files (x86)\Nero 2015-07-29 06:50 - 2015-04-27 17:16 - 00000000 __SHD C:\Users\dima\AppData\Local\EmieUserList 2015-07-29 06:50 - 2015-04-27 17:16 - 00000000 __SHD C:\Users\dima\AppData\Local\EmieSiteList 2015-07-29 06:50 - 2015-04-27 17:16 - 00000000 __SHD C:\Users\dima\AppData\Local\EmieBrowserModeList 2015-07-29 06:45 - 2015-05-03 01:06 - 00000000 ____D C:\Program Files (x86)\AviSynth 2015-07-29 06:45 - 2015-04-27 17:33 - 00000000 ____D C:\Program Files (x86)\Ava MetaTrader 2015-07-29 06:44 - 2015-04-10 09:35 - 00000000 ____D C:\Program Files (x86)\SlySoft 2015-07-29 06:43 - 2010-08-31 13:33 - 00000000 ____D C:\ProgramData\Adobe 2015-07-29 02:17 - 2015-05-28 15:50 - 00119296 ____N C:\Windows\SysWOW64\zlib.dll 2015-07-28 23:49 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2015-07-28 23:48 - 2015-04-25 23:03 - 00000000 ____D C:\ProgramData\F-Secure 2015-07-25 10:21 - 2015-04-25 23:07 - 00055336 _____ C:\Windows\system32\Drivers\fsbts.sys 2015-07-25 10:17 - 2015-04-25 23:07 - 00020521 _____ C:\Windows\prodsett_copy.ini 2015-07-25 10:11 - 2009-07-14 06:45 - 00265696 _____ C:\Windows\system32\FNTCACHE.DAT 2015-07-17 21:23 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2015-07-15 23:47 - 2014-08-07 10:01 - 00000000 ____D C:\Windows\system32\MRT 2015-07-15 17:05 - 2014-08-11 01:52 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2015-07-15 17:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2015-07-14 19:09 - 2014-08-07 23:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-07-14 19:09 - 2014-08-06 18:36 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2015-07-14 19:01 - 2014-08-07 23:48 - 00001385 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2015-07-14 18:59 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther 2015-07-14 17:51 - 2015-04-12 01:14 - 00000000 ____D C:\Program Files (x86)\Megasoft Security 2015-07-14 17:36 - 2009-07-14 09:45 - 00000000 ____D C:\Program Files\Windows Journal 2015-07-03 08:43 - 2014-08-07 10:01 - 130333168 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-04-12 01:14 - 2015-04-12 01:14 - 0000000 _____ () C:\Users\dima\AppData\Roaming\B338.tmp 2015-04-13 16:46 - 2015-04-13 16:46 - 0009662 _____ () C:\Users\dima\AppData\Roaming\em_64x64.ico 2015-04-10 09:38 - 2015-04-12 00:38 - 0000040 ___SH () C:\ProgramData\.zreglib 2014-08-06 18:42 - 2014-08-06 18:45 - 0015553 _____ () C:\ProgramData\ArcadeDeluxe4.log 2015-03-06 23:07 - 2015-03-06 23:07 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2015-07-29 07:01 - 2015-07-29 07:02 - 0000090 _____ () C:\ProgramData\PS.log Einige Dateien in TEMP: ==================== C:\Users\dima\AppData\Local\Temp\Quarantine.exe C:\Users\dima\AppData\Local\Temp\sqlite3.dll C:\Users\dima\AppData\Local\Temp\ytb.exe ==================== Bamital & volsnap Check ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\System32\winlogon.exe => Datei ist digital signiert C:\Windows\System32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\System32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\System32\services.exe => Datei ist digital signiert C:\Windows\System32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\System32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\System32\rpcss.dll => Datei ist digital signiert C:\Windows\System32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-07-25 01:22 ==================== Ende von log ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:28-07-2015 durchgeführt von dima (2015-07-29 13:13:50) Gestartet von E:\ Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-2825088377-2055153963-3447657259-500 - Administrator - Disabled) dima (S-1-5-21-2825088377-2055153963-3447657259-1001 - Administrator - Enabled) => C:\Users\dima Gast (S-1-5-21-2825088377-2055153963-3447657259-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2825088377-2055153963-3447657259-1002 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Computer Sicherheit (Enabled - Up to date) {15414183-282E-D62C-CA37-EF24860A2F17} AS: Computer Sicherheit (Enabled - Up to date) {AE20A067-0E14-D9A2-F087-D456FD8D65AA} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7 Days to Die (HKLM-x32\...\Steam App 251570) (Version: - The Fun Pimps) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Acer Incorporated) Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3003 - Acer Incorporated) Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0909 - Acer Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated) Anno Online (HKLM-x32\...\Steam App 336510) (Version: - Blue Byte) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) CCleaner (HKLM\...\CCleaner) (Version: 5.04 - Piriform) Computer Security 14.121.103.0 (release) (x32 Version: 14.121.103.0 - F-Secure Corporation) Hidden DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive) Dead Pixels (HKLM-x32\...\Steam App 222980) (Version: - CSR-Studios) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve) Euro Truck Simulator 2 (HKLM-x32\...\Steam App 227300) (Version: - SCS Software) Firefall (HKLM-x32\...\Steam App 227700) (Version: - Red 5 Studios) F-Secure CCF Reputation (x32 Version: 2.0.1337.0 - F-Secure) Hidden F-Secure CCF Scanning 1.51.112.309 (release) (x32 Version: 1.51.112.309 - F-Secure Corporation) Hidden F-Secure Network CCF 1.03.102 (x32 Version: 1.03.102 - F-Secure Corporation) Hidden F-Secure SafeSearch 1.03.159.0 (release) (x32 Version: 1.03.159.0 - F-Secure Corporation) Hidden Guns and Robots (HKLM-x32\...\Steam App 293540) (Version: - Masthead Studios Ltd) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation) Kabel Deutschland Sicherheitspaket (HKLM-x32\...\F-Secure ServiceEnabler 44553) (Version: 2.21.285.0 - F-Secure Corporation) Kabel Deutschland Sicherheitspaket (x32 Version: 2.21.285.0 - F-Secure Corporation) Hidden League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Logitech Gaming Software 8.57 (HKLM\...\Logitech Gaming Software) (Version: 8.57.145 - Logitech Inc.) Magic The Gathering Online (HKU\S-1-5-21-2825088377-2055153963-3447657259-1001\...\35c9d60442fbb010) (Version: 3.4.87.519 - Wizards of the Coast) Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Mozilla Firefox 37.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.1 (x86 de)) (Version: 37.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Netzmanager (HKLM-x32\...\Netzmanager) (Version: 1.081 - Deutsche Telekom AG) Netzmanager (Version: 1.081 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 353.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.30 - NVIDIA Corporation) NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5933 - NVIDIA Corporation) NVIDIA GeForce Experience 2.4.5.57 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.57 - NVIDIA Corporation) NVIDIA Grafiktreiber 353.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.30 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Online Safety 2.115.2786.1676 (x32 Version: 2.115.2786.1676 - F-Secure Corporation) Hidden Prison Architect (HKLM-x32\...\Steam App 233450) (Version: - Introversion Software) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.) RIFT™ (HKLM-x32\...\Steam App 39120) (Version: - Trion Worlds) SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.5.57 - NVIDIA Corporation) Hidden Spotify (HKU\S-1-5-21-2825088377-2055153963-3447657259-1001\...\Spotify) (Version: 1.0.3.101.gbfa97dfe - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) Tap Tap Infinity (HKLM-x32\...\Steam App 380360) (Version: - Scary Bee LLC) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Time Clickers (HKLM-x32\...\Steam App 385770) (Version: - Proton Studio Inc) Tom Clancy's Ghost Recon Phantoms - EU (HKLM-x32\...\Steam App 272350) (Version: - Ubisoft Singapore) Villagers and Heroes (HKLM-x32\...\Steam App 263540) (Version: - Mad Otter Games) VLC media player (HKLM\...\VLC media player) (Version: 2.2.0 - VideoLAN) WinRAR 5.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH) World of Guns: Gun Disassembly (HKLM-x32\...\Steam App 262410) (Version: - Noble Empire Corp.) World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) World of Warcraft Beta (HKLM-x32\...\World of Warcraft Beta) (Version: - Blizzard Entertainment) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-2825088377-2055153963-3447657259-1001_Classes\CLSID\{46b865c7-0d58-497e-b2fc-80dfc92fae7f}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation) ==================== Wiederherstellungspunkte ========================= 25-07-2015 01:29:49 Geplanter Prüfpunkt 25-07-2015 02:34:58 Windows Update 29-07-2015 06:41:47 Removed Acrobat.com 29-07-2015 06:42:42 Removed Adobe Reader 9.1 MUI. 29-07-2015 06:46:39 Configured eSobi v2 29-07-2015 06:48:48 Removed Java 8 Update 45 29-07-2015 06:49:32 Removed Microsoft Xbox 360 Accessories 1.2 29-07-2015 06:50:12 Removed Nero 9 Essentials 4.4.9.0 29-07-2015 06:57:46 Entfernt MyWinLocker Suite 29-07-2015 07:00:15 Konfiguriert PowerCinema 29-07-2015 07:03:31 Removed Pinnacle Game Profiler 29-07-2015 07:47:41 Removed Microsoft SQL Server 2005 Compact Edition [ENU] 29-07-2015 07:48:49 Microsoft Office 2010 wird entfernt 29-07-2015 08:00:32 Windows Live Anmelde-Assistent wird entfernt 29-07-2015 08:03:21 Windows Live Sync wird entfernt 29-07-2015 08:03:34 Windows Live-Uploadtool wird entfernt ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {06223770-F8EF-4135-B51E-EB298727EC1D} - System32\Tasks\{2D5C3A2E-B072-4456-813E-E58E0119C695} => C:\Program Files (x86)\NEXON\Europe MapleStory\MapleStoryLauncher.exe Task: {2F1E9F4B-070A-44D1-B927-77EFA11BE9FE} - System32\Tasks\Recovery Management\Burn Notification => C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe [2010-06-24] (Acer) Task: {8A42C40A-B996-4045-87A0-F131CA8F689F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd) Task: {986F0329-B164-48EF-AA31-7D397691F4E6} - System32\Tasks\{EB7D0D16-BD5E-49EB-B7AE-811035C13023} => pcalua.exe -a "C:\Program Files (x86)\NEXON\Europe MapleStory\Setup.exe" -d "C:\Program Files (x86)\NEXON\Europe MapleStory" Task: {AB19068D-4873-4D05-8F3F-55473C38B34B} - System32\Tasks\{AF18576C-7386-43DA-8B8C-94CEFD1A3909} => pcalua.exe -a "F:\Europe MapleStory\Setup.exe" -d "F:\Europe MapleStory" Task: {C688F477-DA93-4E0A-B1F8-4B92A2E68EBE} - System32\Tasks\Megasoft Security Viewer => C:\Program Files (x86)\Megasoft Security\jptask.exe Task: {D9B8E3E5-1862-4F2C-985E-9DA4CC08DC97} - System32\Tasks\Security Installer => C:\Users\dima\AppData\Local\Updater\winupd.exe <==== ATTENTION Task: {DA10F77D-0EFB-405C-8DE8-7E278526A2DE} - System32\Tasks\AV Service Viewer => C:\Program Files (x86)\AV Service\AVService.exe [2015-04-21] (Secure Updater) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2014-08-07 23:47 - 2015-06-17 08:48 - 00116368 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-09-18 09:23 - 2014-09-18 09:23 - 00866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-10-14 20:51 - 2014-10-14 20:51 - 01050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-09-18 09:23 - 2014-09-18 09:23 - 00059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2014-10-14 20:51 - 2014-10-14 20:51 - 00242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2015-04-25 23:06 - 2015-06-12 14:35 - 00045608 _____ () C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\FSAVHRES.eng 2015-04-02 10:25 - 2015-04-02 10:25 - 00220200 _____ () C:\Program Files (x86)\Kabel Deutschland\daas2.dll 2015-05-25 20:16 - 2015-06-24 13:37 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-04-25 23:10 - 2015-04-25 23:10 - 00029224 _____ () C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\hashlib_x86.dll 2015-04-25 23:06 - 2015-07-14 17:42 - 00175144 _____ () C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Gemini\fsgem.dll 2015-04-25 23:06 - 2015-07-25 10:17 - 00212008 _____ () C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Spam Control\fsas.dll 2015-04-25 23:06 - 2015-07-14 17:42 - 00949288 _____ () C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\fm4av.dll 2015-04-25 23:06 - 2015-04-25 23:06 - 00592936 _____ () C:\Windows\WinSxS\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.482.79_none_b59ec33311fcd586\QtMultimediaKit1.dll 2015-07-25 10:16 - 2015-06-12 14:35 - 00056360 _____ () C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\FSGUI\fsavures.eng 2014-08-07 17:40 - 2015-07-03 18:12 - 00778240 _____ () F:\Steam\SDL2.dll 2015-03-14 08:07 - 2015-07-03 18:12 - 04962816 _____ () F:\Steam\v8.dll 2015-03-14 08:07 - 2015-07-03 18:12 - 01556992 _____ () F:\Steam\icui18n.dll 2015-03-14 08:07 - 2015-07-03 18:12 - 01187840 _____ () F:\Steam\icuuc.dll 2014-08-07 17:40 - 2015-07-24 01:24 - 02410176 _____ () F:\Steam\video.dll 2014-09-06 23:43 - 2014-12-01 23:31 - 02396672 _____ () F:\Steam\libavcodec-56.dll 2014-09-06 23:43 - 2014-12-01 23:31 - 00442880 _____ () F:\Steam\libavutil-54.dll 2014-09-06 23:43 - 2014-12-01 23:31 - 00479744 _____ () F:\Steam\libavformat-56.dll 2014-09-06 23:43 - 2014-12-01 23:31 - 00332800 _____ () F:\Steam\libavresample-2.dll 2014-09-06 23:43 - 2014-12-01 23:31 - 00485888 _____ () F:\Steam\libswscale-3.dll 2014-08-07 17:40 - 2015-07-24 01:23 - 00703168 _____ () F:\Steam\bin\chromehtml.DLL 2015-07-28 23:59 - 2015-07-07 22:41 - 00169984 _____ () F:\Steam\bin\openvr_api.dll 2014-08-07 17:40 - 2015-07-03 18:12 - 39553928 _____ () F:\Steam\bin\libcef.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:DocumentSummaryInformation AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:SummaryInformation AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer trusted/restricted =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-2825088377-2055153963-3447657259-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\dima\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Universal Media Server.lnk => C:\Windows\pss\Universal Media Server.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^dima^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Netzmanager.lnk => C:\Windows\pss\Netzmanager.lnk.Startup MSCONFIG\startupreg: AnyDVD => C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe MSCONFIG\startupreg: DriveUtilitiesHelper => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe MSCONFIG\startupreg: IAAnotif => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe MSCONFIG\startupreg: MDS_Menu => "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6" MSCONFIG\startupreg: Spotify => "C:\Users\dima\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\dima\AppData\Roaming\Spotify\SpotifyWebHelper.exe" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{7912D884-A1CB-43E9-A0D8-B8877F5737B4}] => (Allow) F:\Steam\Steam.exe FirewallRules: [{4F44819E-7A67-49B7-A65C-EA89806C5C00}] => (Allow) F:\Steam\Steam.exe FirewallRules: [{050FC262-5D92-41D0-82B3-6641A3E42AA7}] => (Allow) F:\SteamLibrary\SteamApps\common\Firefall\system\bin\FirefallClient.exe FirewallRules: [{894C9F79-E4C2-451C-A1E8-824BF28DFEE5}] => (Allow) F:\SteamLibrary\SteamApps\common\Firefall\system\bin\FirefallClient.exe FirewallRules: [{0BFDA220-506E-4156-80EE-E65DAB43AC08}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{1229518F-C1F2-43AC-BFCF-A22A33E91E0C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{6F61CF8C-C6DD-4CDC-BD98-B5C21CA80C33}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{72DCF385-4E30-4E94-9B3A-B071A555CAAC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{376F7E5A-D36D-452D-890F-A6A066B84E0F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{79FB55AF-D664-404A-A67E-DD74F5CD31FB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{43305C83-4543-430D-8AD9-823D99C88650}] => (Allow) F:\Steam\bin\steamwebhelper.exe FirewallRules: [{CA09BFAB-C299-4EDB-BD47-F02CDABD0942}] => (Allow) F:\Steam\bin\steamwebhelper.exe FirewallRules: [{DA6387E7-850D-4C49-A5B9-0FA494C0EB3A}] => (Allow) F:\SteamLibrary\SteamApps\common\Firefall\system\bin\FirefallClient.exe FirewallRules: [{A7F3FF20-5153-4E56-80F2-DDE47D75178C}] => (Allow) F:\SteamLibrary\SteamApps\common\Firefall\system\bin\FirefallClient.exe FirewallRules: [{C0E250B0-186F-4E92-96D7-7C73443B5F7C}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{7D8DB03C-67F1-4F1C-B293-EE331B5E324E}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{292C59E9-401E-4022-8414-4553AA1EDF6B}] => (Allow) F:\SteamLibrary\SteamApps\common\WOG\disasm.exe FirewallRules: [{AB9CB112-6EB1-4851-9C08-C03A1689A7BD}] => (Allow) F:\SteamLibrary\SteamApps\common\WOG\disasm.exe FirewallRules: [{AA429B26-798E-4ACE-9BC8-043F759DB4AB}] => (Allow) F:\SteamLibrary\SteamApps\common\Tom Clancy's Ghost Recon Phantoms - EU\Launcher.exe FirewallRules: [{7D2B0324-4265-432F-ACF9-94E80873D193}] => (Allow) F:\SteamLibrary\SteamApps\common\Tom Clancy's Ghost Recon Phantoms - EU\Launcher.exe FirewallRules: [TCP Query User{F4F38403-D6CC-4DBF-907D-F2B2A7D42CFC}F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe] => (Allow) F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe FirewallRules: [UDP Query User{58A966CA-C50C-455F-9724-0B39DFDEA6E5}F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe] => (Allow) F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe FirewallRules: [{0375DF92-E308-4E26-8006-CAAE0AB2C57E}] => (Allow) F:\SteamLibrary\SteamApps\common\deadpixels\Dead Pixels Launcher.exe FirewallRules: [{955F6B9C-6001-4FBD-B40F-43BFA76A5140}] => (Allow) F:\SteamLibrary\SteamApps\common\deadpixels\Dead Pixels Launcher.exe FirewallRules: [TCP Query User{35665A9A-E201-4FF0-9012-E727021A9449}F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe] => (Allow) F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe FirewallRules: [UDP Query User{4E99FEB7-E322-4D32-B4EA-6A39B9B61B78}F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe] => (Allow) F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe FirewallRules: [TCP Query User{8EC8C003-FCF4-4EF1-916A-80BC85998CC5}F:\world of tanks\wotlauncher.exe] => (Allow) F:\world of tanks\wotlauncher.exe FirewallRules: [UDP Query User{340ED9AF-37F7-46BB-8D2B-7046E7F9720F}F:\world of tanks\wotlauncher.exe] => (Allow) F:\world of tanks\wotlauncher.exe FirewallRules: [TCP Query User{62D0362D-7F20-49DB-86C1-1488704A0FC3}F:\world of tanks\worldoftanks.exe] => (Allow) F:\world of tanks\worldoftanks.exe FirewallRules: [UDP Query User{522E2C01-B624-439F-8917-4D3F8EE7711A}F:\world of tanks\worldoftanks.exe] => (Allow) F:\world of tanks\worldoftanks.exe FirewallRules: [{E08DFDDD-2833-43B4-9B48-4BA06099CC53}] => (Allow) F:\SteamLibrary\SteamApps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{4842EBBB-EB2F-43EB-9FBC-508DAF3BD762}] => (Allow) F:\SteamLibrary\SteamApps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{2A1F462F-40BE-4497-ADFF-FD6274B33319}] => (Allow) F:\SteamLibrary\SteamApps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [{F2BFA70F-294A-4F8F-9CB0-CCAC569C958E}] => (Allow) F:\SteamLibrary\SteamApps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [{A61E2B04-B754-4BB8-B3A5-42AB62DE9BD7}] => (Allow) F:\SteamLibrary\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{A44427C6-0804-4CAB-A70E-831CBD3DD7C5}] => (Allow) F:\SteamLibrary\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{6F0C51A8-77E5-45D6-BCC9-207BCA49B303}] => (Allow) F:\SteamLibrary\SteamApps\common\RIFT\riftpatchlive.exe FirewallRules: [{00C29877-2F74-4946-884E-5F42FFEAA7AA}] => (Allow) F:\SteamLibrary\SteamApps\common\RIFT\riftpatchlive.exe FirewallRules: [{99E42DE2-DA48-436F-9B31-E684C166DF2E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{6F00D806-2828-4693-9427-8C63F7F951D6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{94FDDAC8-0DDD-4AF8-8BF9-F5E1D61B34E5}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe FirewallRules: [{8E814B41-F335-4190-ADA1-8427D57A3927}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe FirewallRules: [{4F4DA2FB-011A-4042-AAAD-158D208A2E03}] => (Allow) F:\Steam\SteamApps\common\Prison Architect\Prison Architect.exe FirewallRules: [{44A4DC74-29E9-4CC7-9BFC-C48E12F4F698}] => (Allow) F:\Steam\SteamApps\common\Prison Architect\Prison Architect.exe FirewallRules: [TCP Query User{E5FFC2FD-C844-4106-89B9-9FDAA83647E6}C:\users\dima\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\dima\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{BBC979AA-0EEE-4589-854F-FB03846D454C}C:\users\dima\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\dima\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{FCD40EDF-D9C0-4A9D-B939-0888F3E3F535}F:\d3\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe] => (Allow) F:\d3\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{BE7CAB4B-3D33-46EB-8F78-227517FC75D5}F:\d3\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe] => (Allow) F:\d3\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe FirewallRules: [{0B0AB208-4A37-447B-B224-EFD73837203A}] => (Allow) F:\SteamLibrary\SteamApps\common\GAR\GAR.exe FirewallRules: [{ECDB11BF-7B89-4063-941E-7DBA7B0AE0BC}] => (Allow) F:\SteamLibrary\SteamApps\common\GAR\GAR.exe FirewallRules: [{189EE390-12B6-4EC8-A4F8-468F2C0B4940}] => (Allow) F:\SteamLibrary\SteamApps\common\VillagersAndHeroes\AMysticalLandSAC\VillagersAndHeroes.exe FirewallRules: [{5DD7CA20-E657-4510-8379-B3A00655C973}] => (Allow) F:\SteamLibrary\SteamApps\common\VillagersAndHeroes\AMysticalLandSAC\VillagersAndHeroes.exe FirewallRules: [{52692D0F-257E-46BC-86C6-72CAE3CFE3EA}] => (Allow) F:\SteamLibrary\SteamApps\common\Anno Online\nw.exe FirewallRules: [{5B5DC70B-EA1C-4281-B766-B69E264A0120}] => (Allow) F:\SteamLibrary\SteamApps\common\Anno Online\nw.exe FirewallRules: [{698CBB61-0101-437C-9E49-A8E3A7110716}] => (Allow) F:\SteamLibrary\SteamApps\common\TimeClickers\TimeClickers.exe FirewallRules: [{FB2E4189-37DE-4611-A0C0-02EC623A3CF0}] => (Allow) F:\SteamLibrary\SteamApps\common\TimeClickers\TimeClickers.exe FirewallRules: [{15B9D460-2387-42E3-8AF3-0016C10220F8}] => (Allow) F:\SteamLibrary\SteamApps\common\Tap Tap Infinity\TapTapInfinity.exe FirewallRules: [{8DF987DD-BEEB-4EAF-A7C8-4345D68B26E0}] => (Allow) F:\SteamLibrary\SteamApps\common\Tap Tap Infinity\TapTapInfinity.exe ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Standardtastatur (PS/2) Description: Standardtastatur (PS/2) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDVDisk. System Error: Das System kann die angegebene Datei nicht finden. . Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDNServ. System Error: Das System kann die angegebene Datei nicht finden. . Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDFilter. System Error: Das System kann die angegebene Datei nicht finden. . Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDVDisk. System Error: Das System kann die angegebene Datei nicht finden. . Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDNServ. System Error: Das System kann die angegebene Datei nicht finden. . Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDFilter. System Error: Das System kann die angegebene Datei nicht finden. . Error: (07/29/2015 06:53:37 AM) (Source: FSecure-FSecure-F-Secure DeepGuard) (EventID: 103) (User: ) Description: 2 2015-07-29 06:53:37+02:00 DIMA-PC SYSTEM F-Secure DeepGuard Application was blocked. This was determined to be a high-risk application by system control heuristics. Application path: \\?\c:\users\dima\appdata\roaming\inetstat\inetstat.exe File hash: bb5260311d84a367fe98dd13f29c43205faa58cf Error: (07/29/2015 06:48:07 AM) (Source: FSecure-FSecure-F-Secure DeepGuard) (EventID: 103) (User: ) Description: 1 2015-07-29 06:48:07+02:00 DIMA-PC SYSTEM F-Secure DeepGuard Application was blocked. This was determined to be a high-risk application by system control heuristics. Application path: \\?\c:\users\dima\appdata\roaming\inetstat\inetstat.exe File hash: bb5260311d84a367fe98dd13f29c43205faa58cf Error: (07/29/2015 04:06:57 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: inetstat.exe, Version: 0.0.0.0, Zeitstempel: 0x0005a814 Name des fehlerhaften Moduls: inetstat.exe, Version: 0.0.0.0, Zeitstempel: 0x0005a814 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00030ae3 ID des fehlerhaften Prozesses: 0xe4c Startzeit der fehlerhaften Anwendung: 0xinetstat.exe0 Pfad der fehlerhaften Anwendung: inetstat.exe1 Pfad des fehlerhaften Moduls: inetstat.exe2 Berichtskennung: inetstat.exe3 Error: (07/29/2015 02:17:32 AM) (Source: ESENT) (EventID: 455) (User: ) Description: taskhost (2780) WebCacheLocal: Fehler -1811 beim Öffnen von Protokolldatei C:\Users\dima\AppData\Local\Microsoft\Windows\WebCache\V0100050.log. Systemfehler: ============= Error: (07/29/2015 08:45:45 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/29/2015 08:45:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Steam Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/29/2015 08:45:44 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/29/2015 08:45:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Intel(R) Management & Security Application User Notification Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/29/2015 08:45:44 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Microsoft .NET Framework NGEN v4.0.30319_X86" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/29/2015 08:45:44 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/29/2015 08:45:43 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "FSMA" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/29/2015 08:45:43 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Intel(R) Matrix Storage Event Monitor" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/29/2015 08:45:43 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Updater Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/29/2015 08:45:43 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Privoxy (PrivoxyService)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Microsoft Office: ========================= Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDVDisk. System Error: Das System kann die angegebene Datei nicht finden. Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDNServ. System Error: Das System kann die angegebene Datei nicht finden. Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDFilter. System Error: Das System kann die angegebene Datei nicht finden. Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDVDisk. System Error: Das System kann die angegebene Datei nicht finden. Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDNServ. System Error: Das System kann die angegebene Datei nicht finden. Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDFilter. System Error: Das System kann die angegebene Datei nicht finden. Error: (07/29/2015 06:53:37 AM) (Source: FSecure-FSecure-F-Secure DeepGuard) (EventID: 103) (User: ) Description: 2 2015-07-29 06:53:37+02:00 DIMA-PC SYSTEM F-Secure DeepGuard Application was blocked. This was determined to be a high-risk application by system control heuristics. Application path: \\?\c:\users\dima\appdata\roaming\inetstat\inetstat.exe File hash: bb5260311d84a367fe98dd13f29c43205faa58cf Error: (07/29/2015 06:48:07 AM) (Source: FSecure-FSecure-F-Secure DeepGuard) (EventID: 103) (User: ) Description: 1 2015-07-29 06:48:07+02:00 DIMA-PC SYSTEM F-Secure DeepGuard Application was blocked. This was determined to be a high-risk application by system control heuristics. Application path: \\?\c:\users\dima\appdata\roaming\inetstat\inetstat.exe File hash: bb5260311d84a367fe98dd13f29c43205faa58cf Error: (07/29/2015 04:06:57 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: inetstat.exe0.0.0.00005a814inetstat.exe0.0.0.00005a814c000000500030ae3e4c01d0c993faef8b1fC:\Users\dima\AppData\Roaming\InetStat\inetstat.exeC:\Users\dima\AppData\Roaming\InetStat\inetstat.exe7d62445e-3596-11e5-ae5e-90fba688c2c0 Error: (07/29/2015 02:17:32 AM) (Source: ESENT) (EventID: 455) (User: ) Description: taskhost2780WebCacheLocal: C:\Users\dima\AppData\Local\Microsoft\Windows\WebCache\V0100050.log-1811 ==================== Speicherinformationen =========================== Processor: Intel(R) Core(TM) i7 CPU 870 @ 2.93GHz Percentage of memory in use: 35% Total physical RAM: 12247.09 MB Available physical RAM: 7867.57 MB Total Virtual: 24492.38 MB Available Virtual: 19714.05 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:455.71 GB) (Free:379.98 GB) NTFS Drive d: (DATA) (Fixed) (Total:455.71 GB) (Free:455.47 GB) NTFS Drive e: (DOWNLOADS) (Fixed) (Total:97.65 GB) (Free:14.29 GB) NTFS Drive f: (GAMES) (Fixed) (Total:457.76 GB) (Free:243.33 GB) NTFS Drive g: () (Fixed) (Total:368.1 GB) (Free:368 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 4A83361A) Partition 1: (Not Active) - (Size=20 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=455.7 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=455.7 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 39999E66) Partition 1: (Active) - (Size=97.7 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=368.1 GB) - (Type=OF Extended) ======================================================== Disk: 2 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 91082E45) Partition 1: (Not Active) - (Size=8 GB) - (Type=27) Partition 2: (Active) - (Size=457.8 GB) - (Type=07 NTFS) ==================== Ende von log ============================ |
29.07.2015, 12:20 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Steamprobleme: werbung, lange seitenladezeiten Was ist mit meiner Frage nach bisherigen Funden und wenn es welche gab, den Logs dazu?
__________________ Logfiles bitte immer in CODE-Tags posten |
29.07.2015, 12:34 | #5 |
| Steamprobleme: werbung, lange seitenladezeiten Tut mir leid ich kann nicht genau sagen seit wann das Problem besteht, ich habe den pc ca. 3 Monate nicht mehr benutzt und als ich ihn gestern Abend startete war mein beschriebenes problem schon vorhanden. Heute früh habe ich einen scan mit AdwCleaner gemacht und es gab keine funde. Den Log habe ich leider nicht. Ps: ohne dass ich irgendwas gemacht habe ist nun diese Werbung auch bei Firefox. ich muss grad von meinem Handy schreiben weil Firefox extreme hänger hat und immer wieder abstürzt (keine rückmeldung) |
29.07.2015, 12:41 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Steamprobleme: werbung, lange seitenladezeiten Adware/Junkware/Toolbars entfernen 1. Schritt: Malwarebytes Downloade Dir bitte Malwarebytes Anti-Malware
(alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!) 2. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
3. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
4. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ --> Steamprobleme: werbung, lange seitenladezeiten |
29.07.2015, 13:33 | #7 |
| Steamprobleme: werbung, lange seitenladezeiten mbam Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 29.07.2015 Suchlaufzeit: 13:52 Protokolldatei: mbam.txt Administrator: Ja Version: 2.1.8.1057 Malware-Datenbank: v2015.07.29.02 Rootkit-Datenbank: v2015.07.29.01 Lizenz: Kostenlose Version Malware-Schutz: Deaktiviert Schutz vor bösartigen Websites: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: dima Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 347730 Abgelaufene Zeit: 10 Min., 44 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 3 PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [fd8955923852ca6c4bedf9a2f80c4fb1], PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [1175c225593174c256e2b3e8a46042be], PUP.Optional.SuperOptimizer.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, In Quarantäne, [bdc9e205c6c4db5b82a97a2361a339c7], Registrierungswerte: 2 PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [fd8955923852ca6c4bedf9a2f80c4fb1] PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [1175c225593174c256e2b3e8a46042be] Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 1 PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Megasoft Security, In Quarantäne, [b8ce26c12f5b8ea8727667a1d330a957], Dateien: 9 PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Megasoft Security\amint64.dll, In Quarantäne, [b8ce26c12f5b8ea8727667a1d330a957], PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Megasoft Security\config.txt, In Quarantäne, [b8ce26c12f5b8ea8727667a1d330a957], PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Megasoft Security\default.action, In Quarantäne, [b8ce26c12f5b8ea8727667a1d330a957], PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Megasoft Security\default.filter, In Quarantäne, [b8ce26c12f5b8ea8727667a1d330a957], PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Megasoft Security\jpchromium64.exe, In Quarantäne, [b8ce26c12f5b8ea8727667a1d330a957], PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Megasoft Security\mgwz.dll, In Quarantäne, [b8ce26c12f5b8ea8727667a1d330a957], PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Megasoft Security\privoxy.exe, In Quarantäne, [b8ce26c12f5b8ea8727667a1d330a957], PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Megasoft Security\privoxy.log, In Quarantäne, [b8ce26c12f5b8ea8727667a1d330a957], PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Megasoft Security\ssie.dll, In Quarantäne, [b8ce26c12f5b8ea8727667a1d330a957], Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter # AdwCleaner v4.208 - Bericht erstellt 29/07/2015 um 14:10:36 # Aktualisiert 09/07/2015 von Xplode # Datenbank : 2015-07-26.2 [Server] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64) # Benutzername : dima - DIMA-PC # Gestarted von : C:\Users\dima\Desktop\AdwCleaner_4.208(1).exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17909 -\\ Mozilla Firefox v37.0.1 (x86 de) [da84kea6.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.enabledAddons", "mailcheck%40gmx.net:3.0.8,safesearch%40f-secure.com:1.0,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:37.0.1"); [da84kea6.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.xpiState", "{\"app-profile\":{\"mailcheck@gmx.net\":{\"d\":\"C:\\\\Users\\\\dima\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\da84kea6.default\\\\extensions\\\\mail[...] -\\ Google Chrome v ************************* AdwCleaner[R0].txt - [6906 Bytes] - [29/07/2015 08:44:25] AdwCleaner[R1].txt - [1369 Bytes] - [29/07/2015 14:09:37] AdwCleaner[S0].txt - [6408 Bytes] - [29/07/2015 08:45:44] AdwCleaner[S1].txt - [1307 Bytes] - [29/07/2015 14:10:36] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1366 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 7.5.4 (07.27.2015:1) OS: Windows 7 Home Premium x64 Ran by dima on 29.07.2015 at 14:13:51,63 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Tasks ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] C:\ProgramData\t122078ed Successfully deleted: [Folder] C:\Windows\SysWOW64\ai_recyclebin ~~~ FireFox Successfully deleted the following from C:\Users\dima\AppData\Roaming\mozilla\firefox\profiles\da84kea6.default\prefs.js user_pref(browser.search.searchengine.desc, this is my first firefox searchEngine); user_pref(browser.search.searchengine.ptid, tti); user_pref(browser.search.searchengine.uid, HitachiXHDT721010SLA360_STF6L7MS394GTK394GTKX); user_pref(extensions.unitedinternet.email.runonceNewUsersShown, true); Emptied folder: C:\Users\dima\AppData\Roaming\mozilla\firefox\profiles\da84kea6.default\minidumps [7 files] ~~~ Chrome [C:\Users\dima\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset [C:\Users\dima\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted: [C:\Users\dima\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset [C:\Users\dima\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 29.07.2015 at 14:20:17,69 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:28-07-2015 durchgeführt von dima (Administrator) auf DIMA-PC (29-07-2015 14:27:01) Gestartet von C:\Users\dima\Desktop Geladene Profile: dima (Verfügbare Profile: dima) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Reputation\fsorsp.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\fsgk32.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSMA32.EXE (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\fssm32.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSHDLL64.EXE (Microsoft Corporation) C:\Windows\System32\dllhost.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Users\dima\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe ==================== Registry (Nicht auf der Ausnahmeliste) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-24] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672152 2014-05-09] (Realtek Semiconductor) HKLM-x32\...\Run: [F-Secure Hoster (44553)] => C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe [187432 2015-04-02] (F-Secure Corporation) HKLM-x32\...\Run: [F-Secure Manager] => C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSM32.EXE [310312 2015-06-12] (F-Secure Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation) HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-08-08] (Microsoft Corporation) Startup: C:\Users\dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2015-03-13] () CHR HKLM\SOFTWARE\Policies\Google: Richtlinienbeschränkung <======= ATTENTION ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..) HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\S-1-5-21-2825088377-2055153963-3447657259-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://de.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2825088377-2055153963-3447657259-1001 -> {94A87168-FE2A-401F-A56C-01C7B43BC6E0} URL = https://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default BHO: Browsing Protection -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https64.dll [2015-07-28] (F-Secure Corporation) BHO-x32: Browsing Protection -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll [2015-07-28] (F-Secure Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Java\bin\ssv.dll [2015-07-29] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Java\bin\jp2ssv.dll [2015-07-29] (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{0373DD93-ECE7-4CA9-A78C-A7A8464926AC}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{B4DCCF8B-5EAA-4307-86FF-CA4A7CBB8471}: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\dima\AppData\Roaming\Mozilla\Firefox\Profiles\da84kea6.default FF DefaultSearchEngine: 1&1 Suche FF SelectedSearchEngine: Safe Search FF Homepage: https://de.yahoo.com/?fr=yset_ff_syc_oracle&type=orcl_hpset FF Keyword.URL: hxxp://search.f-secure.com/kabeldeutschland/search?query= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-29] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-29] () FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> D:\Java\bin\dtplugin\npDeployJava1.dll [2015-07-29] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> D:\Java\bin\plugin2\npjp2.dll [2015-07-29] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-06-17] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-06-17] (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF SearchPlugin: C:\Users\dima\AppData\Roaming\Mozilla\Firefox\Profiles\da84kea6.default\searchplugins\f-secure-safe-search.xml [2015-07-14] FF SearchPlugin: C:\Users\dima\AppData\Roaming\Mozilla\Firefox\Profiles\da84kea6.default\searchplugins\yahoo-ysp.xml [2015-07-29] FF Extension: GMX MailCheck - C:\Users\dima\AppData\Roaming\Mozilla\Firefox\Profiles\da84kea6.default\Extensions\mailcheck@gmx.net [2015-07-14] FF Extension: Firefox Helper - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\e68829ca6b0caddec6012a89eae272fb [2015-04-12] FF HKLM-x32\...\Firefox\Extensions: [{25229c00-7179-4193-84ae-557da142fdcf}] - C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\bin\browser\deploy\fs_firefox_https FF Extension: Browsing Protection - C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\bin\browser\deploy\fs_firefox_https [2015-04-25] FF HKU\S-1-5-21-2825088377-2055153963-3447657259-1001\...\Firefox\Extensions: [safesearch@f-secure.com] - C:\Users\dima\AppData\Roaming\F-Secure\SafeSearch\FFPlugIn FF Extension: Safe Search - C:\Users\dima\AppData\Roaming\F-Secure\SafeSearch\FFPlugIn [2015-04-25] Chrome: ======= CHR Profile: C:\Users\dima\AppData\Local\Google\Chrome\User Data\Default CHR HKLM-x32\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - C:/Program Files (x86)/Kabel Deutschland/apps/CCF_Scanning/bin/browser/install/fs_chrome_https/fs_chrome_https.crx [2014-09-08] ==================== Services (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [238376 2015-07-29] (EasyAntiCheat Ltd) R2 fshoster; C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe [187432 2015-04-02] (F-Secure Corporation) R3 FSMA; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSMA32.EXE [216104 2015-06-12] (F-Secure Corporation) R2 FSORSPClient; C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Reputation\fsorsp.exe [60456 2015-04-25] (F-Secure Corporation) S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-06-24] (NVIDIA Corporation) R2 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144 2009-09-30] (Intel Corporation) [Datei ist nicht signiert] S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [Datei ist nicht signiert] S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1868432 2015-06-24] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23007376 2015-06-24] (NVIDIA Corporation) S2 UNS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation) [Datei ist nicht signiert] S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 F-Secure Gatekeeper; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [208424 2015-07-25] (F-Secure Corporation) R1 F-Secure HIPS; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\HIPS\drivers\fshs.sys [71080 2015-07-14] (F-Secure Corporation) R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [55336 2015-07-25] () R3 fsni; C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\bin\fsni64.sys [97832 2015-07-28] (F-Secure Corporation) R1 fsvista; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [13352 2015-06-12] () R3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech Inc.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-06-24] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46768 2015-05-19] (NVIDIA Corporation) R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions) S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-07-29 14:27 - 2015-07-29 14:27 - 00012631 _____ C:\Users\dima\Desktop\FRST.txt 2015-07-29 14:26 - 2015-07-29 13:12 - 02169856 _____ (Farbar) C:\Users\dima\Desktop\FRST64.exe 2015-07-29 14:20 - 2015-07-29 14:25 - 00001733 _____ C:\Users\dima\Desktop\JRT.txt 2015-07-29 14:12 - 2015-07-29 14:12 - 00001446 _____ C:\Users\dima\Desktop\AdwCleaner[S1].txt 2015-07-29 14:07 - 2015-07-29 14:07 - 00003162 _____ C:\Users\dima\Desktop\mbam.txt 2015-07-29 14:02 - 2015-07-29 14:01 - 01798176 _____ (Malwarebytes Corporation) C:\Users\dima\Desktop\JRT.exe 2015-07-29 14:01 - 2015-07-29 14:00 - 02248704 _____ C:\Users\dima\Desktop\AdwCleaner_4.208(1).exe 2015-07-29 13:49 - 2015-07-29 14:06 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-07-29 13:49 - 2015-07-29 13:51 - 00001110 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-07-29 13:49 - 2015-07-29 13:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-07-29 13:49 - 2015-07-29 13:51 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-07-29 13:49 - 2015-07-29 13:49 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-07-29 13:49 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-07-29 13:49 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-07-29 13:49 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-07-29 13:12 - 2015-07-29 14:27 - 00000000 ____D C:\FRST 2015-07-29 12:12 - 2015-07-29 12:12 - 00000000 ____D C:\Users\dima\AppData\Roaming\7DaysToDie 2015-07-29 11:20 - 2015-07-29 11:23 - 00000000 ____D C:\Users\dima\Documents\HeroesOfSoulcraft 2015-07-29 08:44 - 2015-07-29 14:10 - 00000000 ____D C:\AdwCleaner 2015-07-29 08:05 - 2015-07-29 14:11 - 00000840 _____ C:\Windows\setupact.log 2015-07-29 08:05 - 2015-07-29 08:05 - 00000000 _____ C:\Windows\setuperr.log 2015-07-29 08:04 - 2015-07-29 14:11 - 00004814 _____ C:\Windows\PFRO.log 2015-07-29 07:57 - 2015-07-29 07:57 - 00000000 ____D C:\Windows\pss 2015-07-29 07:47 - 2015-07-29 07:47 - 00000020 _____ C:\Windows\Tø¯ 2015-07-29 07:35 - 2015-07-29 07:35 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-07-29 07:35 - 2015-07-29 07:35 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-29 07:14 - 2015-07-29 07:14 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-07-29 07:14 - 2015-07-29 07:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-07-29 07:01 - 2015-07-29 07:02 - 00000090 _____ C:\ProgramData\PS.log 2015-07-29 06:38 - 2015-07-29 13:00 - 00000000 ____D C:\Users\dima\AppData\Local\Anno Online 2015-07-28 23:59 - 2015-07-28 23:59 - 00000000 ____D C:\Users\dima\AppData\Local\CEF 2015-07-25 00:50 - 2015-07-15 05:19 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2015-07-25 00:50 - 2015-07-15 05:19 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-07-25 00:50 - 2015-07-15 05:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2015-07-25 00:50 - 2015-07-15 05:19 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2015-07-25 00:50 - 2015-07-15 04:55 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2015-07-25 00:50 - 2015-07-15 04:55 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2015-07-25 00:50 - 2015-07-15 04:55 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2015-07-25 00:50 - 2015-07-15 04:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2015-07-25 00:50 - 2015-07-15 03:59 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-07-25 00:50 - 2015-07-15 03:52 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2015-07-15 17:33 - 2015-06-25 20:09 - 00389832 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-07-15 17:33 - 2015-06-25 19:43 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-07-15 17:33 - 2015-06-20 22:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-07-15 17:33 - 2015-06-20 21:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-07-15 17:33 - 2015-06-20 21:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-07-15 17:33 - 2015-06-20 21:49 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-07-15 17:33 - 2015-06-20 21:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-07-15 17:33 - 2015-06-20 21:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-07-15 17:33 - 2015-06-20 21:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-07-15 17:33 - 2015-06-20 21:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-07-15 17:33 - 2015-06-20 21:34 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-07-15 17:33 - 2015-06-20 21:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-07-15 17:33 - 2015-06-20 21:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-07-15 17:33 - 2015-06-20 21:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-07-15 17:33 - 2015-06-20 21:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-07-15 17:33 - 2015-06-20 21:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-07-15 17:33 - 2015-06-20 21:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-07-15 17:33 - 2015-06-20 21:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-07-15 17:33 - 2015-06-20 21:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-07-15 17:33 - 2015-06-20 20:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-07-15 17:33 - 2015-06-20 20:48 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-07-15 17:33 - 2015-06-20 20:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-07-15 17:33 - 2015-06-20 20:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-07-15 17:33 - 2015-06-20 20:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-07-15 17:33 - 2015-06-20 20:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-07-15 17:33 - 2015-06-19 20:25 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-07-15 17:33 - 2015-06-19 20:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-07-15 17:33 - 2015-06-19 20:24 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-07-15 17:33 - 2015-06-19 20:24 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-07-15 17:33 - 2015-06-19 20:23 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-07-15 17:33 - 2015-06-19 20:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-07-15 17:33 - 2015-06-19 20:16 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-07-15 17:33 - 2015-06-19 20:13 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-07-15 17:33 - 2015-06-19 20:13 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-07-15 17:33 - 2015-06-19 20:03 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-07-15 17:33 - 2015-06-19 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-07-15 17:33 - 2015-06-19 19:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-07-15 17:33 - 2015-06-19 19:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-07-15 17:33 - 2015-06-19 19:51 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-07-15 17:33 - 2015-06-19 19:40 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-07-15 17:33 - 2015-06-19 19:40 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-07-15 17:33 - 2015-06-19 19:39 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-07-15 17:33 - 2015-06-19 19:15 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-07-15 17:33 - 2015-06-19 19:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-07-15 17:26 - 2015-07-02 23:21 - 19877376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-07-15 17:26 - 2015-07-02 23:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-07-15 17:26 - 2015-07-02 22:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-07-15 17:26 - 2015-07-02 22:49 - 25193984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-07-15 17:26 - 2015-07-02 22:46 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-07-15 17:26 - 2015-07-02 22:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-07-15 17:26 - 2015-07-02 22:19 - 12855296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-07-15 17:26 - 2015-07-02 22:12 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-07-15 17:26 - 2015-07-02 21:55 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-07-15 17:26 - 2015-07-02 21:20 - 14453248 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-07-15 17:26 - 2015-07-02 20:59 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-07-15 17:26 - 2015-06-27 04:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-07-15 17:26 - 2015-06-27 04:43 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-07-15 17:26 - 2015-06-27 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-07-15 17:26 - 2015-06-27 03:39 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-07-15 17:26 - 2015-06-25 10:57 - 03207168 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-07-15 17:26 - 2015-06-17 19:47 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-07-15 17:26 - 2015-06-17 19:37 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-07-15 17:26 - 2015-06-02 02:07 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll 2015-07-15 17:26 - 2015-06-02 01:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll 2015-07-15 17:25 - 2015-07-02 22:23 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-07-15 17:21 - 2015-07-04 20:07 - 02087424 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2015-07-15 17:21 - 2015-07-04 19:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2015-07-15 17:21 - 2015-07-01 22:56 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-07-15 17:21 - 2015-07-01 22:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-07-15 17:21 - 2015-07-01 22:49 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-07-15 17:21 - 2015-07-01 22:49 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-07-15 17:21 - 2015-07-01 22:48 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2015-07-15 17:21 - 2015-07-01 22:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-07-15 17:21 - 2015-07-01 22:47 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-07-15 17:21 - 2015-07-01 22:47 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-07-15 17:21 - 2015-07-01 22:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-07-15 17:21 - 2015-07-01 22:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-07-15 17:21 - 2015-07-01 22:39 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-07-15 17:21 - 2015-07-01 22:30 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-07-15 17:21 - 2015-07-01 22:29 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2015-07-15 17:21 - 2015-07-01 22:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-07-15 17:21 - 2015-07-01 22:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-07-15 17:21 - 2015-07-01 22:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-07-15 17:21 - 2015-07-01 22:26 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-07-15 17:21 - 2015-07-01 22:24 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-07-15 17:21 - 2015-07-01 21:27 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-07-15 17:21 - 2015-07-01 21:26 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-07-15 17:21 - 2015-07-01 21:26 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-07-15 17:21 - 2015-06-15 23:45 - 03242496 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2015-07-15 17:21 - 2015-06-15 23:45 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-07-15 17:21 - 2015-06-15 23:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2015-07-15 17:20 - 2015-06-15 23:50 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2015-07-15 17:20 - 2015-06-15 23:45 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2015-07-15 17:20 - 2015-06-15 23:45 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2015-07-15 17:20 - 2015-06-15 23:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2015-07-15 17:20 - 2015-06-15 23:43 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2015-07-15 17:20 - 2015-06-15 23:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2015-07-15 17:20 - 2015-06-15 23:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2015-07-15 17:20 - 2015-06-15 23:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2015-07-15 17:20 - 2015-06-15 23:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2015-07-14 19:12 - 2015-07-14 19:12 - 00000320 _____ C:\Users\dima\Desktop\Magic The Gathering Online .appref-ms 2015-07-14 19:12 - 2015-07-14 19:12 - 00000000 ____D C:\Users\dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wizards of the Coast 2015-07-14 19:12 - 2015-07-14 19:12 - 00000000 ____D C:\Users\dima\AppData\Local\Wizards of the Coast 2015-07-14 19:12 - 2015-07-14 19:12 - 00000000 ____D C:\ProgramData\Gibraltar 2015-07-14 19:09 - 2015-06-17 08:03 - 00571024 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2015-07-14 19:06 - 2015-07-14 19:06 - 00000000 ____D C:\ProgramData\boost_interprocess 2015-07-14 19:06 - 2015-06-17 11:10 - 42729104 _____ C:\Windows\system32\nvcompiler.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 37748880 ____N C:\Windows\SysWOW64\nvcompiler.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 30481552 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 22947144 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 16145200 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 14497520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 13263056 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 11831856 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 11011216 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-07-14 19:06 - 2015-06-17 11:10 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 02599752 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 01898128 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435330.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 01557832 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435330.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 01099992 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 01060168 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 01050768 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00982672 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00975176 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00938752 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00204648 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2015-07-14 19:06 - 2015-06-17 11:10 - 00176904 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00155280 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00128696 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2015-07-14 19:06 - 2015-06-17 11:10 - 00040280 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2015-07-14 19:00 - 2015-05-19 05:29 - 00046768 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2015-07-14 19:00 - 2015-05-19 05:14 - 00057520 ____N (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2015-07-14 17:53 - 2015-05-09 05:27 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-07-14 17:53 - 2015-05-09 05:27 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-07-14 17:53 - 2015-05-09 05:27 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-07-14 17:53 - 2015-05-09 05:27 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-07-14 17:53 - 2015-05-09 05:26 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-07-14 17:53 - 2015-05-09 05:26 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-07-14 17:53 - 2015-05-09 05:26 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-07-14 17:53 - 2015-05-09 05:25 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-07-14 17:53 - 2015-05-09 05:20 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:20 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:13 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-07-14 17:53 - 2015-05-09 05:13 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-07-14 17:53 - 2015-05-09 05:12 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-07-14 17:53 - 2015-05-09 05:12 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-07-14 17:53 - 2015-05-09 05:12 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 04:01 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-07-14 17:53 - 2015-05-09 04:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-07-14 17:53 - 2015-05-09 03:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 03:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-07-14 17:53 - 2015-05-09 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-07-14 17:53 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-07-14 17:53 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-07-14 17:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-07-14 17:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-07-14 17:53 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-07-14 17:53 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2015-07-14 17:53 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2015-07-14 17:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2015-07-14 17:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2015-07-14 17:53 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2015-07-14 17:53 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-07-14 17:53 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-07-29 14:20 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-29 14:20 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-29 14:15 - 2014-08-06 18:34 - 01865648 _____ C:\Windows\WindowsUpdate.log 2015-07-29 14:12 - 2015-03-13 20:11 - 00000000 ____D C:\Users\dima\AppData\Local\Deployment 2015-07-29 14:11 - 2014-08-06 18:39 - 00000000 ____D C:\ProgramData\NVIDIA 2015-07-29 14:11 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-29 12:09 - 2014-09-25 17:21 - 00238376 _____ (EasyAntiCheat Ltd) C:\Windows\SysWOW64\EasyAntiCheat.exe 2015-07-29 11:55 - 2014-08-06 21:50 - 00000000 ____D C:\Users\dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2015-07-29 08:03 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2015-07-29 07:56 - 2014-08-06 20:58 - 00000000 ____D C:\Users\dima 2015-07-29 07:55 - 2010-08-31 13:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer 2015-07-29 07:55 - 2010-08-31 13:27 - 00000000 ____D C:\Program Files (x86)\Acer 2015-07-29 07:36 - 2015-03-25 12:25 - 00000000 ____D C:\Users\dima\AppData\Local\Adobe 2015-07-29 07:19 - 2015-04-25 23:03 - 00000000 ____D C:\Users\dima\AppData\Local\F-Secure 2015-07-29 07:15 - 2015-04-11 15:48 - 00000000 ____D C:\ProgramData\Oracle 2015-07-29 07:02 - 2014-08-06 18:42 - 00000000 ____D C:\ProgramData\CyberLink 2015-07-29 07:02 - 2010-08-31 13:15 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2015-07-29 06:52 - 2015-05-03 01:06 - 00000000 ____D C:\Program Files (x86)\Universal Media Server 2015-07-29 06:52 - 2010-08-31 13:31 - 00000000 ____D C:\ProgramData\Nero 2015-07-29 06:51 - 2010-08-31 13:31 - 00000000 ____D C:\Program Files (x86)\Nero 2015-07-29 06:50 - 2015-04-27 17:16 - 00000000 __SHD C:\Users\dima\AppData\Local\EmieUserList 2015-07-29 06:50 - 2015-04-27 17:16 - 00000000 __SHD C:\Users\dima\AppData\Local\EmieSiteList 2015-07-29 06:50 - 2015-04-27 17:16 - 00000000 __SHD C:\Users\dima\AppData\Local\EmieBrowserModeList 2015-07-29 06:45 - 2015-05-03 01:06 - 00000000 ____D C:\Program Files (x86)\AviSynth 2015-07-29 06:45 - 2015-04-27 17:33 - 00000000 ____D C:\Program Files (x86)\Ava MetaTrader 2015-07-29 06:44 - 2015-04-10 09:35 - 00000000 ____D C:\Program Files (x86)\SlySoft 2015-07-29 06:43 - 2010-08-31 13:33 - 00000000 ____D C:\ProgramData\Adobe 2015-07-29 02:17 - 2015-05-28 15:50 - 00119296 ____N C:\Windows\SysWOW64\zlib.dll 2015-07-28 23:49 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2015-07-28 23:48 - 2015-04-25 23:03 - 00000000 ____D C:\ProgramData\F-Secure 2015-07-25 10:21 - 2015-04-25 23:07 - 00055336 _____ C:\Windows\system32\Drivers\fsbts.sys 2015-07-25 10:17 - 2015-04-25 23:07 - 00020521 _____ C:\Windows\prodsett_copy.ini 2015-07-25 10:11 - 2009-07-14 06:45 - 00265696 _____ C:\Windows\system32\FNTCACHE.DAT 2015-07-17 21:23 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2015-07-15 23:47 - 2014-08-07 10:01 - 00000000 ____D C:\Windows\system32\MRT 2015-07-15 17:05 - 2014-08-11 01:52 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2015-07-15 17:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2015-07-14 19:09 - 2014-08-07 23:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-07-14 19:09 - 2014-08-06 18:36 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2015-07-14 19:01 - 2014-08-07 23:48 - 00001385 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2015-07-14 18:59 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther 2015-07-14 17:36 - 2009-07-14 09:45 - 00000000 ____D C:\Program Files\Windows Journal 2015-07-03 08:43 - 2014-08-07 10:01 - 130333168 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-04-12 01:14 - 2015-04-12 01:14 - 0000000 _____ () C:\Users\dima\AppData\Roaming\B338.tmp 2015-04-13 16:46 - 2015-04-13 16:46 - 0009662 _____ () C:\Users\dima\AppData\Roaming\em_64x64.ico 2015-04-10 09:38 - 2015-04-12 00:38 - 0000040 ___SH () C:\ProgramData\.zreglib 2014-08-06 18:42 - 2014-08-06 18:45 - 0015553 _____ () C:\ProgramData\ArcadeDeluxe4.log 2015-03-06 23:07 - 2015-03-06 23:07 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2015-07-29 07:01 - 2015-07-29 07:02 - 0000090 _____ () C:\ProgramData\PS.log Einige Dateien in TEMP: ==================== C:\Users\dima\AppData\Local\Temp\Quarantine.exe C:\Users\dima\AppData\Local\Temp\sqlite3.dll C:\Users\dima\AppData\Local\Temp\ytb.exe ==================== Bamital & volsnap Check ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\System32\winlogon.exe => Datei ist digital signiert C:\Windows\System32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\System32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\System32\services.exe => Datei ist digital signiert C:\Windows\System32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\System32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\System32\rpcss.dll => Datei ist digital signiert C:\Windows\System32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-07-25 01:22 ==================== Ende von log ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:28-07-2015 durchgeführt von dima (2015-07-29 14:27:52) Gestartet von C:\Users\dima\Desktop Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-2825088377-2055153963-3447657259-500 - Administrator - Disabled) dima (S-1-5-21-2825088377-2055153963-3447657259-1001 - Administrator - Enabled) => C:\Users\dima Gast (S-1-5-21-2825088377-2055153963-3447657259-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2825088377-2055153963-3447657259-1002 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Computer Sicherheit (Enabled - Up to date) {15414183-282E-D62C-CA37-EF24860A2F17} AS: Computer Sicherheit (Enabled - Up to date) {AE20A067-0E14-D9A2-F087-D456FD8D65AA} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7 Days to Die (HKLM-x32\...\Steam App 251570) (Version: - The Fun Pimps) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Acer Incorporated) Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3003 - Acer Incorporated) Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0909 - Acer Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated) Anno Online (HKLM-x32\...\Steam App 336510) (Version: - Blue Byte) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) CCleaner (HKLM\...\CCleaner) (Version: 5.04 - Piriform) Computer Security 14.121.103.0 (release) (x32 Version: 14.121.103.0 - F-Secure Corporation) Hidden DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive) Dead Pixels (HKLM-x32\...\Steam App 222980) (Version: - CSR-Studios) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve) Euro Truck Simulator 2 (HKLM-x32\...\Steam App 227300) (Version: - SCS Software) Firefall (HKLM-x32\...\Steam App 227700) (Version: - Red 5 Studios) F-Secure CCF Reputation (x32 Version: 2.0.1337.0 - F-Secure) Hidden F-Secure CCF Scanning 1.51.112.309 (release) (x32 Version: 1.51.112.309 - F-Secure Corporation) Hidden F-Secure Network CCF 1.03.102 (x32 Version: 1.03.102 - F-Secure Corporation) Hidden F-Secure SafeSearch 1.03.159.0 (release) (x32 Version: 1.03.159.0 - F-Secure Corporation) Hidden Guns and Robots (HKLM-x32\...\Steam App 293540) (Version: - Masthead Studios Ltd) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation) Kabel Deutschland Sicherheitspaket (HKLM-x32\...\F-Secure ServiceEnabler 44553) (Version: 2.21.285.0 - F-Secure Corporation) Kabel Deutschland Sicherheitspaket (x32 Version: 2.21.285.0 - F-Secure Corporation) Hidden League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Logitech Gaming Software 8.57 (HKLM\...\Logitech Gaming Software) (Version: 8.57.145 - Logitech Inc.) Magic The Gathering Online (HKU\S-1-5-21-2825088377-2055153963-3447657259-1001\...\35c9d60442fbb010) (Version: 3.4.87.519 - Wizards of the Coast) Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Mozilla Firefox 37.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.1 (x86 de)) (Version: 37.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Netzmanager (HKLM-x32\...\Netzmanager) (Version: 1.081 - Deutsche Telekom AG) Netzmanager (Version: 1.081 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 353.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.30 - NVIDIA Corporation) NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5933 - NVIDIA Corporation) NVIDIA GeForce Experience 2.4.5.57 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.57 - NVIDIA Corporation) NVIDIA Grafiktreiber 353.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.30 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Online Safety 2.115.2786.1676 (x32 Version: 2.115.2786.1676 - F-Secure Corporation) Hidden Prison Architect (HKLM-x32\...\Steam App 233450) (Version: - Introversion Software) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.) RIFT™ (HKLM-x32\...\Steam App 39120) (Version: - Trion Worlds) SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.5.57 - NVIDIA Corporation) Hidden Spotify (HKU\S-1-5-21-2825088377-2055153963-3447657259-1001\...\Spotify) (Version: 1.0.3.101.gbfa97dfe - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) Tap Tap Infinity (HKLM-x32\...\Steam App 380360) (Version: - Scary Bee LLC) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Time Clickers (HKLM-x32\...\Steam App 385770) (Version: - Proton Studio Inc) Tom Clancy's Ghost Recon Phantoms - EU (HKLM-x32\...\Steam App 272350) (Version: - Ubisoft Singapore) Villagers and Heroes (HKLM-x32\...\Steam App 263540) (Version: - Mad Otter Games) VLC media player (HKLM\...\VLC media player) (Version: 2.2.0 - VideoLAN) WinRAR 5.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH) World of Guns: Gun Disassembly (HKLM-x32\...\Steam App 262410) (Version: - Noble Empire Corp.) World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) World of Warcraft Beta (HKLM-x32\...\World of Warcraft Beta) (Version: - Blizzard Entertainment) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-2825088377-2055153963-3447657259-1001_Classes\CLSID\{46b865c7-0d58-497e-b2fc-80dfc92fae7f}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation) ==================== Wiederherstellungspunkte ========================= 25-07-2015 02:34:58 Windows Update 29-07-2015 06:41:47 Removed Acrobat.com 29-07-2015 06:42:42 Removed Adobe Reader 9.1 MUI. 29-07-2015 06:46:39 Configured eSobi v2 29-07-2015 06:48:48 Removed Java 8 Update 45 29-07-2015 06:49:32 Removed Microsoft Xbox 360 Accessories 1.2 29-07-2015 06:50:12 Removed Nero 9 Essentials 4.4.9.0 29-07-2015 06:57:46 Entfernt MyWinLocker Suite 29-07-2015 07:00:15 Konfiguriert PowerCinema 29-07-2015 07:03:31 Removed Pinnacle Game Profiler 29-07-2015 07:47:41 Removed Microsoft SQL Server 2005 Compact Edition [ENU] 29-07-2015 07:48:49 Microsoft Office 2010 wird entfernt 29-07-2015 08:00:32 Windows Live Anmelde-Assistent wird entfernt 29-07-2015 08:03:21 Windows Live Sync wird entfernt 29-07-2015 08:03:34 Windows Live-Uploadtool wird entfernt 29-07-2015 14:13:54 JRT Pre-Junkware Removal ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {06223770-F8EF-4135-B51E-EB298727EC1D} - System32\Tasks\{2D5C3A2E-B072-4456-813E-E58E0119C695} => C:\Program Files (x86)\NEXON\Europe MapleStory\MapleStoryLauncher.exe Task: {2F1E9F4B-070A-44D1-B927-77EFA11BE9FE} - System32\Tasks\Recovery Management\Burn Notification => C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe [2010-06-24] (Acer) Task: {8A42C40A-B996-4045-87A0-F131CA8F689F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd) Task: {986F0329-B164-48EF-AA31-7D397691F4E6} - System32\Tasks\{EB7D0D16-BD5E-49EB-B7AE-811035C13023} => pcalua.exe -a "C:\Program Files (x86)\NEXON\Europe MapleStory\Setup.exe" -d "C:\Program Files (x86)\NEXON\Europe MapleStory" Task: {AB19068D-4873-4D05-8F3F-55473C38B34B} - System32\Tasks\{AF18576C-7386-43DA-8B8C-94CEFD1A3909} => pcalua.exe -a "F:\Europe MapleStory\Setup.exe" -d "F:\Europe MapleStory" Task: {C688F477-DA93-4E0A-B1F8-4B92A2E68EBE} - System32\Tasks\Megasoft Security Viewer => C:\Program Files (x86)\Megasoft Security\jptask.exe Task: {D9B8E3E5-1862-4F2C-985E-9DA4CC08DC97} - System32\Tasks\Security Installer => C:\Users\dima\AppData\Local\Updater\winupd.exe <==== ATTENTION Task: {DA10F77D-0EFB-405C-8DE8-7E278526A2DE} - System32\Tasks\AV Service Viewer => C:\Program Files (x86)\AV Service\AVService.exe [2015-04-21] (Secure Updater) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2014-08-07 23:47 - 2015-06-17 08:48 - 00116368 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-04-02 10:25 - 2015-04-02 10:25 - 00220200 _____ () C:\Program Files (x86)\Kabel Deutschland\daas2.dll 2015-04-25 23:06 - 2015-06-12 14:35 - 00045608 _____ () C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\FSAVHRES.eng 2015-04-25 23:10 - 2015-04-25 23:10 - 00029224 _____ () C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\hashlib_x86.dll 2015-04-25 23:06 - 2015-07-14 17:42 - 00175144 _____ () C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Gemini\fsgem.dll 2015-04-25 23:06 - 2015-07-25 10:17 - 00212008 _____ () C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Spam Control\fsas.dll 2015-05-25 20:16 - 2015-06-24 13:37 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:DocumentSummaryInformation AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:SummaryInformation AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer trusted/restricted =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-2825088377-2055153963-3447657259-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\dima\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Universal Media Server.lnk => C:\Windows\pss\Universal Media Server.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^dima^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Netzmanager.lnk => C:\Windows\pss\Netzmanager.lnk.Startup MSCONFIG\startupreg: AnyDVD => C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe MSCONFIG\startupreg: DriveUtilitiesHelper => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe MSCONFIG\startupreg: IAAnotif => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe MSCONFIG\startupreg: MDS_Menu => "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6" MSCONFIG\startupreg: Spotify => "C:\Users\dima\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\dima\AppData\Roaming\Spotify\SpotifyWebHelper.exe" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{7912D884-A1CB-43E9-A0D8-B8877F5737B4}] => (Allow) F:\Steam\Steam.exe FirewallRules: [{4F44819E-7A67-49B7-A65C-EA89806C5C00}] => (Allow) F:\Steam\Steam.exe FirewallRules: [{050FC262-5D92-41D0-82B3-6641A3E42AA7}] => (Allow) F:\SteamLibrary\SteamApps\common\Firefall\system\bin\FirefallClient.exe FirewallRules: [{894C9F79-E4C2-451C-A1E8-824BF28DFEE5}] => (Allow) F:\SteamLibrary\SteamApps\common\Firefall\system\bin\FirefallClient.exe FirewallRules: [{0BFDA220-506E-4156-80EE-E65DAB43AC08}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{1229518F-C1F2-43AC-BFCF-A22A33E91E0C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{6F61CF8C-C6DD-4CDC-BD98-B5C21CA80C33}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{72DCF385-4E30-4E94-9B3A-B071A555CAAC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{376F7E5A-D36D-452D-890F-A6A066B84E0F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{79FB55AF-D664-404A-A67E-DD74F5CD31FB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{43305C83-4543-430D-8AD9-823D99C88650}] => (Allow) F:\Steam\bin\steamwebhelper.exe FirewallRules: [{CA09BFAB-C299-4EDB-BD47-F02CDABD0942}] => (Allow) F:\Steam\bin\steamwebhelper.exe FirewallRules: [{DA6387E7-850D-4C49-A5B9-0FA494C0EB3A}] => (Allow) F:\SteamLibrary\SteamApps\common\Firefall\system\bin\FirefallClient.exe FirewallRules: [{A7F3FF20-5153-4E56-80F2-DDE47D75178C}] => (Allow) F:\SteamLibrary\SteamApps\common\Firefall\system\bin\FirefallClient.exe FirewallRules: [{C0E250B0-186F-4E92-96D7-7C73443B5F7C}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{7D8DB03C-67F1-4F1C-B293-EE331B5E324E}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{292C59E9-401E-4022-8414-4553AA1EDF6B}] => (Allow) F:\SteamLibrary\SteamApps\common\WOG\disasm.exe FirewallRules: [{AB9CB112-6EB1-4851-9C08-C03A1689A7BD}] => (Allow) F:\SteamLibrary\SteamApps\common\WOG\disasm.exe FirewallRules: [{AA429B26-798E-4ACE-9BC8-043F759DB4AB}] => (Allow) F:\SteamLibrary\SteamApps\common\Tom Clancy's Ghost Recon Phantoms - EU\Launcher.exe FirewallRules: [{7D2B0324-4265-432F-ACF9-94E80873D193}] => (Allow) F:\SteamLibrary\SteamApps\common\Tom Clancy's Ghost Recon Phantoms - EU\Launcher.exe FirewallRules: [TCP Query User{F4F38403-D6CC-4DBF-907D-F2B2A7D42CFC}F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe] => (Allow) F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe FirewallRules: [UDP Query User{58A966CA-C50C-455F-9724-0B39DFDEA6E5}F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe] => (Allow) F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe FirewallRules: [{0375DF92-E308-4E26-8006-CAAE0AB2C57E}] => (Allow) F:\SteamLibrary\SteamApps\common\deadpixels\Dead Pixels Launcher.exe FirewallRules: [{955F6B9C-6001-4FBD-B40F-43BFA76A5140}] => (Allow) F:\SteamLibrary\SteamApps\common\deadpixels\Dead Pixels Launcher.exe FirewallRules: [TCP Query User{35665A9A-E201-4FF0-9012-E727021A9449}F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe] => (Allow) F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe FirewallRules: [UDP Query User{4E99FEB7-E322-4D32-B4EA-6A39B9B61B78}F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe] => (Allow) F:\steamlibrary\steamapps\common\tom clancy's ghost recon phantoms - eu\game\pdc-live\ghostreconphantoms.exe FirewallRules: [TCP Query User{8EC8C003-FCF4-4EF1-916A-80BC85998CC5}F:\world of tanks\wotlauncher.exe] => (Allow) F:\world of tanks\wotlauncher.exe FirewallRules: [UDP Query User{340ED9AF-37F7-46BB-8D2B-7046E7F9720F}F:\world of tanks\wotlauncher.exe] => (Allow) F:\world of tanks\wotlauncher.exe FirewallRules: [TCP Query User{62D0362D-7F20-49DB-86C1-1488704A0FC3}F:\world of tanks\worldoftanks.exe] => (Allow) F:\world of tanks\worldoftanks.exe FirewallRules: [UDP Query User{522E2C01-B624-439F-8917-4D3F8EE7711A}F:\world of tanks\worldoftanks.exe] => (Allow) F:\world of tanks\worldoftanks.exe FirewallRules: [{E08DFDDD-2833-43B4-9B48-4BA06099CC53}] => (Allow) F:\SteamLibrary\SteamApps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{4842EBBB-EB2F-43EB-9FBC-508DAF3BD762}] => (Allow) F:\SteamLibrary\SteamApps\common\7 Days To Die\7DaysToDie_EAC.exe FirewallRules: [{2A1F462F-40BE-4497-ADFF-FD6274B33319}] => (Allow) F:\SteamLibrary\SteamApps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [{F2BFA70F-294A-4F8F-9CB0-CCAC569C958E}] => (Allow) F:\SteamLibrary\SteamApps\common\7 Days To Die\7DaysToDie.exe FirewallRules: [{A61E2B04-B754-4BB8-B3A5-42AB62DE9BD7}] => (Allow) F:\SteamLibrary\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{A44427C6-0804-4CAB-A70E-831CBD3DD7C5}] => (Allow) F:\SteamLibrary\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{6F0C51A8-77E5-45D6-BCC9-207BCA49B303}] => (Allow) F:\SteamLibrary\SteamApps\common\RIFT\riftpatchlive.exe FirewallRules: [{00C29877-2F74-4946-884E-5F42FFEAA7AA}] => (Allow) F:\SteamLibrary\SteamApps\common\RIFT\riftpatchlive.exe FirewallRules: [{99E42DE2-DA48-436F-9B31-E684C166DF2E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{6F00D806-2828-4693-9427-8C63F7F951D6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{94FDDAC8-0DDD-4AF8-8BF9-F5E1D61B34E5}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe FirewallRules: [{8E814B41-F335-4190-ADA1-8427D57A3927}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe FirewallRules: [{4F4DA2FB-011A-4042-AAAD-158D208A2E03}] => (Allow) F:\Steam\SteamApps\common\Prison Architect\Prison Architect.exe FirewallRules: [{44A4DC74-29E9-4CC7-9BFC-C48E12F4F698}] => (Allow) F:\Steam\SteamApps\common\Prison Architect\Prison Architect.exe FirewallRules: [TCP Query User{E5FFC2FD-C844-4106-89B9-9FDAA83647E6}C:\users\dima\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\dima\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{BBC979AA-0EEE-4589-854F-FB03846D454C}C:\users\dima\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\dima\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{FCD40EDF-D9C0-4A9D-B939-0888F3E3F535}F:\d3\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe] => (Allow) F:\d3\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{BE7CAB4B-3D33-46EB-8F78-227517FC75D5}F:\d3\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe] => (Allow) F:\d3\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe FirewallRules: [{0B0AB208-4A37-447B-B224-EFD73837203A}] => (Allow) F:\SteamLibrary\SteamApps\common\GAR\GAR.exe FirewallRules: [{ECDB11BF-7B89-4063-941E-7DBA7B0AE0BC}] => (Allow) F:\SteamLibrary\SteamApps\common\GAR\GAR.exe FirewallRules: [{189EE390-12B6-4EC8-A4F8-468F2C0B4940}] => (Allow) F:\SteamLibrary\SteamApps\common\VillagersAndHeroes\AMysticalLandSAC\VillagersAndHeroes.exe FirewallRules: [{5DD7CA20-E657-4510-8379-B3A00655C973}] => (Allow) F:\SteamLibrary\SteamApps\common\VillagersAndHeroes\AMysticalLandSAC\VillagersAndHeroes.exe FirewallRules: [{52692D0F-257E-46BC-86C6-72CAE3CFE3EA}] => (Allow) F:\SteamLibrary\SteamApps\common\Anno Online\nw.exe FirewallRules: [{5B5DC70B-EA1C-4281-B766-B69E264A0120}] => (Allow) F:\SteamLibrary\SteamApps\common\Anno Online\nw.exe FirewallRules: [{698CBB61-0101-437C-9E49-A8E3A7110716}] => (Allow) F:\SteamLibrary\SteamApps\common\TimeClickers\TimeClickers.exe FirewallRules: [{FB2E4189-37DE-4611-A0C0-02EC623A3CF0}] => (Allow) F:\SteamLibrary\SteamApps\common\TimeClickers\TimeClickers.exe FirewallRules: [{15B9D460-2387-42E3-8AF3-0016C10220F8}] => (Allow) F:\SteamLibrary\SteamApps\common\Tap Tap Infinity\TapTapInfinity.exe FirewallRules: [{8DF987DD-BEEB-4EAF-A7C8-4345D68B26E0}] => (Allow) F:\SteamLibrary\SteamApps\common\Tap Tap Infinity\TapTapInfinity.exe ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Standardtastatur (PS/2) Description: Standardtastatur (PS/2) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (07/29/2015 02:13:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FSM32.EXE, Version: 8.30.43153.0, Zeitstempel: 0x54184d39 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00006e61 ID des fehlerhaften Prozesses: 0x6e0 Startzeit der fehlerhaften Anwendung: 0xFSM32.EXE0 Pfad der fehlerhaften Anwendung: FSM32.EXE1 Pfad des fehlerhaften Moduls: FSM32.EXE2 Berichtskennung: FSM32.EXE3 Error: (07/29/2015 01:40:13 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm firefox.exe, Version 37.0.1.5570 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1368 Startzeit: 01d0c9f2a9aee92b Endzeit: 85 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: 90df6624-35e6-11e5-a12f-90fba688c2c0 Error: (07/29/2015 01:29:49 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm firefox.exe, Version 37.0.1.5570 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c24 Startzeit: 01d0c9f006fe2e1e Endzeit: 91 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: 91343f09-35e4-11e5-a12f-90fba688c2c0 Error: (07/29/2015 01:16:32 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm firefox.exe, Version 37.0.1.5570 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 16c4 Startzeit: 01d0c9ef04c9e301 Endzeit: 173 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: 3edbb031-35e3-11e5-a12f-90fba688c2c0 Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDVDisk. System Error: Das System kann die angegebene Datei nicht finden. . Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDNServ. System Error: Das System kann die angegebene Datei nicht finden. . Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDFilter. System Error: Das System kann die angegebene Datei nicht finden. . Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDVDisk. System Error: Das System kann die angegebene Datei nicht finden. . Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDNServ. System Error: Das System kann die angegebene Datei nicht finden. . Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDFilter. System Error: Das System kann die angegebene Datei nicht finden. . Systemfehler: ============= Error: (07/29/2015 02:16:28 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Software Protection" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (07/29/2015 02:14:28 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Software Protection" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/29/2015 02:14:28 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/29/2015 02:14:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Intel(R) Management & Security Application User Notification Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/29/2015 02:14:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "FSMA" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/29/2015 02:14:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Intel(R) Matrix Storage Event Monitor" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/29/2015 02:14:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Updater Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/29/2015 02:14:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "NVIDIA Streamer Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/29/2015 02:14:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "NVIDIA Network Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/29/2015 02:14:27 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Netzmanager Infrastruktur Informationssystem Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts. Microsoft Office: ========================= Error: (07/29/2015 02:13:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: FSM32.EXE8.30.43153.054184d39unknown0.0.0.000000000c000000500006e616e001d0c9f7c9573afdC:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSM32.EXEunknown2f57bd2e-35eb-11e5-813b-90fba688c2c0 Error: (07/29/2015 01:40:13 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: firefox.exe37.0.1.5570136801d0c9f2a9aee92b85C:\Program Files (x86)\Mozilla Firefox\firefox.exe90df6624-35e6-11e5-a12f-90fba688c2c0 Error: (07/29/2015 01:29:49 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: firefox.exe37.0.1.5570c2401d0c9f006fe2e1e91C:\Program Files (x86)\Mozilla Firefox\firefox.exe91343f09-35e4-11e5-a12f-90fba688c2c0 Error: (07/29/2015 01:16:32 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: firefox.exe37.0.1.557016c401d0c9ef04c9e301173C:\Program Files (x86)\Mozilla Firefox\firefox.exe3edbb031-35e3-11e5-a12f-90fba688c2c0 Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDVDisk. System Error: Das System kann die angegebene Datei nicht finden. Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDNServ. System Error: Das System kann die angegebene Datei nicht finden. Error: (07/29/2015 07:03:31 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDFilter. System Error: Das System kann die angegebene Datei nicht finden. Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDVDisk. System Error: Das System kann die angegebene Datei nicht finden. Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDNServ. System Error: Das System kann die angegebene Datei nicht finden. Error: (07/29/2015 07:00:16 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary mwlPSDFilter. System Error: Das System kann die angegebene Datei nicht finden. ==================== Speicherinformationen =========================== Processor: Intel(R) Core(TM) i7 CPU 870 @ 2.93GHz Percentage of memory in use: 17% Total physical RAM: 12247.09 MB Available physical RAM: 10108.29 MB Total Virtual: 24492.38 MB Available Virtual: 22354.1 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:455.71 GB) (Free:377.64 GB) NTFS Drive d: (DATA) (Fixed) (Total:455.71 GB) (Free:455.47 GB) NTFS Drive e: (DOWNLOADS) (Fixed) (Total:97.65 GB) (Free:14.27 GB) NTFS Drive f: (GAMES) (Fixed) (Total:457.76 GB) (Free:243.33 GB) NTFS Drive g: () (Fixed) (Total:368.1 GB) (Free:368 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 4A83361A) Partition 1: (Not Active) - (Size=20 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=455.7 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=455.7 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 39999E66) Partition 1: (Active) - (Size=97.7 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=368.1 GB) - (Type=OF Extended) ======================================================== Disk: 2 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 91082E45) Partition 1: (Not Active) - (Size=8 GB) - (Type=27) Partition 2: (Active) - (Size=457.8 GB) - (Type=07 NTFS) ==================== Ende von log ============================ |
29.07.2015, 15:53 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Steamprobleme: werbung, lange seitenladezeiten FRST-Fix Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft! Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter CHR HKLM\SOFTWARE\Policies\Google: Richtlinienbeschränkung <======= ATTENTION FF SelectedSearchEngine: Safe Search FF Extension: Firefox Helper - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\e68829ca6b0caddec6012a89eae272fb [2015-04-12] FF Extension: Safe Search - C:\Users\dima\AppData\Roaming\F-Secure\SafeSearch\FFPlugIn [2015-04-25] Task: {D9B8E3E5-1862-4F2C-985E-9DA4CC08DC97} - System32\Tasks\Security Installer => C:\Users\dima\AppData\Local\Updater\winupd.exe <==== ATTENTION C:\Users\dima\AppData\Local\Updater EmptyTemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
30.07.2015, 00:41 | #9 |
| Steamprobleme: werbung, lange seitenladezeiten Fixlog Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:28-07-2015 durchgeführt von dima (2015-07-30 01:37:04) Run:1 Gestartet von C:\Users\dima\Desktop Geladene Profile: dima (Verfügbare Profile: dima) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** CHR HKLM\SOFTWARE\Policies\Google: Richtlinienbeschränkung <======= ATTENTION FF SelectedSearchEngine: Safe Search FF Extension: Firefox Helper - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\e68829ca6b0caddec6012a89eae272fb [2015-04-12] FF Extension: Safe Search - C:\Users\dima\AppData\Roaming\F-Secure\SafeSearch\FFPlugIn [2015-04-25] Task: {D9B8E3E5-1862-4F2C-985E-9DA4CC08DC97} - System32\Tasks\Security Installer => C:\Users\dima\AppData\Local\Updater\winupd.exe <==== ATTENTION C:\Users\dima\AppData\Local\Updater EmptyTemp: ***************** "HKLM\SOFTWARE\Policies\Google" => Schlüssel erfolgreich entfernt Firefox SelectedSearchEngine erfolgreich entfernt C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\e68829ca6b0caddec6012a89eae272fb => erfolgreich verschoben. C:\Users\dima\AppData\Roaming\F-Secure\SafeSearch\FFPlugIn => erfolgreich verschoben. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D9B8E3E5-1862-4F2C-985E-9DA4CC08DC97}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D9B8E3E5-1862-4F2C-985E-9DA4CC08DC97}" => Schlüssel erfolgreich entfernt C:\Windows\System32\Tasks\Security Installer => erfolgreich verschoben. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Installer" => Schlüssel erfolgreich entfernt "C:\Users\dima\AppData\Local\Updater" => Datei/Ordner nicht gefunden. EmptyTemp: => 316.9 MB temporäre Dateien entfernt. Das System musste neu gestartet werden.. ==== Ende von Fixlog 01:37:45 ==== |
30.07.2015, 01:00 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Steamprobleme: werbung, lange seitenladezeiten Okay, dann Kontrollscans mit ESET und SC bitte: ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Steamprobleme: werbung, lange seitenladezeiten |
bildschirm, brauche, client, cursor, firefox, geladen, gen, große, hoffe, kleine, kleinen, klick, lange, leute, login, lästige, nervige, online, probleme, seite, starte, steam, vordergrund, werbung, öffnen |