Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 25.07.2014
Suchlauf-Zeit: 18:03:09
Logdatei:
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.25.05
Rootkit Datenbank: v2014.07.17.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: user
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 400043
Verstrichene Zeit: 11 Min, 1 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 3
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}, In Quarantäne, [5849930df18a3cfa60ab3c5c22e06997],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, In Quarantäne, [5849930df18a3cfa60ab3c5c22e06997],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, In Quarantäne, [5849930df18a3cfa60ab3c5c22e06997],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[a7fa6838e5965adc1666a60dfb0917e9]
Ordner: 9
PUP.Optional.CrossRider.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_olnkgiapbjhdboldbhkagdodklkphaip_0, In Quarantäne, [6041732ddd9ed95da858694617eb32ce],
PUP.Optional.CrossRider.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\olnkgiapbjhdboldbhkagdodklkphaip, In Quarantäne, [01a09e0284f72a0c1af2edc2758dde22],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\images, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
Dateien: 75
PUP.Optional.OneFloorApp, C:\Users\user\Downloads\PDF_Creator.exe, In Quarantäne, [7a27584823585bdb18f9a5fe897b06fa],
PUP.Optional.Amonetize, C:\Windows\Installer\2ed38ed.msi, In Quarantäne, [138e1888c2b91620d2521482ae538b75],
PUP.Optional.CrossRider.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_olnkgiapbjhdboldbhkagdodklkphaip_0.localstorage, In Quarantäne, [0d94ffa191eab086c2535c89b15106fa],
PUP.Optional.CrossRider.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_olnkgiapbjhdboldbhkagdodklkphaip_0.localstorage-journal, In Quarantäne, [a2ff0c9443380234b4616f7660a2e61a],
PUP.Optional.QuickStart.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage, In Quarantäne, [8021633d6c0f49edb4dabe699d6750b0],
PUP.Optional.QuickStart.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage-journal, In Quarantäne, [653cfaa6067565d1e0ae23046b99d32d],
PUP.Optional.CrossRider.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_olnkgiapbjhdboldbhkagdodklkphaip_0\2, In Quarantäne, [6041732ddd9ed95da858694617eb32ce],
PUP.Optional.CrossRider.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\olnkgiapbjhdboldbhkagdodklkphaip\000005.ldb, In Quarantäne, [01a09e0284f72a0c1af2edc2758dde22],
PUP.Optional.CrossRider.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\olnkgiapbjhdboldbhkagdodklkphaip\000026.log, In Quarantäne, [01a09e0284f72a0c1af2edc2758dde22],
PUP.Optional.CrossRider.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\olnkgiapbjhdboldbhkagdodklkphaip\CURRENT, In Quarantäne, [01a09e0284f72a0c1af2edc2758dde22],
PUP.Optional.CrossRider.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\olnkgiapbjhdboldbhkagdodklkphaip\LOCK, In Quarantäne, [01a09e0284f72a0c1af2edc2758dde22],
PUP.Optional.CrossRider.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\olnkgiapbjhdboldbhkagdodklkphaip\LOG, In Quarantäne, [01a09e0284f72a0c1af2edc2758dde22],
PUP.Optional.CrossRider.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\olnkgiapbjhdboldbhkagdodklkphaip\MANIFEST-000024, In Quarantäne, [01a09e0284f72a0c1af2edc2758dde22],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\AUTHORS.txt, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\config.txt, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\default.action, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\default.filter, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\LICENSE.txt, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\match-all.action, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\mgwz.dll, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\privoxy.exe, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\privoxy.log, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\privoxy_uninstall.exe, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\README.txt, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\trust.txt, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.action, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.action_empty, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.filter, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.filter_old, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\p_doc.css, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\coding.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\cvs.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\documentation.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\index.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\introduction.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\newrelease.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\testing.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\webserver-update.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\configuration.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\contact.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\copyright.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\general.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\index.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\installation.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\misc.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\trouble.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\images\files-in-use.jpg, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\images\proxy_setup.jpg, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\actions-file.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\appendix.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\config.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\configuration.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\contact.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\copyright.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\files-in-use.jpg, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\filter-file.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\index.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\installation.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\introduction.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\proxy2.jpg, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\proxy_setup.jpg, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\p_doc.css, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\quickstart.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\seealso.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\startup.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\templates.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\whatsnew.html, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\cgi-style.css, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\connect-failed, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-local-help, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-support-and-service, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-title, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-unstable-warning, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\no-such-domain, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\url-info-osd.xml, In Quarantäne, [29787828f883e94dfa3d3981aa5850b0],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=1216db46e8ee6b43b1620e8a8282cd91
# engine=19349
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-07-25 04:23:22
# local_time=2014-07-25 06:23:22 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 8556308 29285796 0 0
# scanned=3276
# found=21
# cleaned=0
# scan_time=115
sh=E12820C3C449E8DF12132666647822B9FE266BA3 ft=1 fh=661cdf041cef5cb3 vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\Installer.dll.vir"
sh=E99D65BD24FAF328D7314F02B98EE8C3BD793B77 ft=1 fh=8661b13c20727ec0 vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\InstallerLibrary.dll.vir"
sh=B11B91F706EA1AFD3D4D625201192EAB850FD3CE ft=1 fh=04b2478a5da86198 vn="MSIL/Adware.Proxomoto.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\InstallFirefoxExtension.dll.vir"
sh=5BD97BEAE0E1E79B233B821DA6813A831B5075FB ft=1 fh=5310de0062903084 vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\NewVersionUploader.exe.vir"
sh=49DEEED4E6B0E6134D47A582E209511FCBFD2B72 ft=1 fh=14e2fb72d7f3d82c vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\WindowsUpdater.exe.vir"
sh=E99D65BD24FAF328D7314F02B98EE8C3BD793B77 ft=1 fh=8661b13c20727ec0 vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\backup\InstallerLibrary.dll.vir"
sh=0DAFA42039405F8D49A6790180194076BD57C833 ft=1 fh=c71c001147036410 vn="Variante von Win32/AdWare.MultiPlug.N Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\savie on\Zu.dll.vir"
sh=61CB4B5228E6253863391EF3346C2F9920DBC554 ft=1 fh=c71c00112b13579c vn="Variante von Win64/Adware.MultiPlug.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\savie on\Zu.x64.dll.vir"
sh=C7C0F42A23562AA6DCCD60326FD8CC2AA41B5448 ft=1 fh=c053642cee9f3def vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir"
sh=125B1C393F2104CBA08183E495C0907BFF7EDA22 ft=1 fh=ea25908c8365106f vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface64.dll.vir"
sh=8E85792765D0E0BF52107CFF4A6620995DB19BB0 ft=1 fh=627da500ea2e265f vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterfacef32.dll.vir"
sh=2FCA2173F2DD16DF8F1F990170FA4479FC5D5BFC ft=1 fh=c528dd1cda99a111 vn="Variante von Win32/ELEX.AR evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir"
sh=6043D1ACD51FD373472020FBB748C405AAF22397 ft=1 fh=4c716dbbae6c21b9 vn="Win32/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect32.dll.vir"
sh=FF431CD8693F4045BD7BD87DBCE54B820F000FC0 ft=1 fh=16c2e1bd3fd6b7e2 vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect64.dll.vir"
sh=5836A5DF3860241F6B69F2292ABCE592A13689B6 ft=1 fh=a3db04555f559ea8 vn="Variante von Win32/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SpAPPSv32.dll.vir"
sh=E97CBDBD7CFED2C58464C1ABF186520022DE5666 ft=1 fh=7a2ea5ecc33ad0e3 vn="Variante von Win64/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SpAPPSv64.dll.vir"
sh=9DC13DB9C123270C2356ED410128E11D5ADF7C6E ft=1 fh=023ab782f0a9b07d vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir"
sh=246DDBC3A2C223A6B9072637D93DC2A2832D097A ft=1 fh=c71c0011b04f613a vn="Win32/Toolbar.Babylon.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\DSearchLink\DSearchLink.exe.vir"
sh=56659F7FF1F1FA7906A77228E315F65F38BCEF73 ft=1 fh=0ff759dfc352fd03 vn="Variante von Win32/ELEX.AD evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir"
sh=A506AEDE7D055BAA580C7657DBAFD498EF0B2E58 ft=1 fh=c71c00117d7abedf vn="Variante von Win32/AdWare.MultiPlug.Y Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\savie on\klD.exe.vir"
sh=C4420C6E94B8CAACCB3811384280D8A93CB0A37D ft=1 fh=25f111c507a31a21 vn="Win32/Toolbar.Conduit.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\users\user\AppData\Roaming\OpenCandy\16EDD084AECD424B91F869D491C9AF0F\sp-downloader.exe.vir"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=1216db46e8ee6b43b1620e8a8282cd91
# engine=19349
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-07-25 05:12:51
# local_time=2014-07-25 07:12:51 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 8559277 29288765 0 0
# scanned=193706
# found=26
# cleaned=0
# scan_time=2854
sh=E12820C3C449E8DF12132666647822B9FE266BA3 ft=1 fh=661cdf041cef5cb3 vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\Installer.dll.vir"
sh=E99D65BD24FAF328D7314F02B98EE8C3BD793B77 ft=1 fh=8661b13c20727ec0 vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\InstallerLibrary.dll.vir"
sh=B11B91F706EA1AFD3D4D625201192EAB850FD3CE ft=1 fh=04b2478a5da86198 vn="MSIL/Adware.Proxomoto.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\InstallFirefoxExtension.dll.vir"
sh=5BD97BEAE0E1E79B233B821DA6813A831B5075FB ft=1 fh=5310de0062903084 vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\NewVersionUploader.exe.vir"
sh=49DEEED4E6B0E6134D47A582E209511FCBFD2B72 ft=1 fh=14e2fb72d7f3d82c vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\WindowsUpdater.exe.vir"
sh=E99D65BD24FAF328D7314F02B98EE8C3BD793B77 ft=1 fh=8661b13c20727ec0 vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\backup\InstallerLibrary.dll.vir"
sh=0DAFA42039405F8D49A6790180194076BD57C833 ft=1 fh=c71c001147036410 vn="Variante von Win32/AdWare.MultiPlug.N Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\savie on\Zu.dll.vir"
sh=61CB4B5228E6253863391EF3346C2F9920DBC554 ft=1 fh=c71c00112b13579c vn="Variante von Win64/Adware.MultiPlug.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\savie on\Zu.x64.dll.vir"
sh=C7C0F42A23562AA6DCCD60326FD8CC2AA41B5448 ft=1 fh=c053642cee9f3def vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir"
sh=125B1C393F2104CBA08183E495C0907BFF7EDA22 ft=1 fh=ea25908c8365106f vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface64.dll.vir"
sh=8E85792765D0E0BF52107CFF4A6620995DB19BB0 ft=1 fh=627da500ea2e265f vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterfacef32.dll.vir"
sh=2FCA2173F2DD16DF8F1F990170FA4479FC5D5BFC ft=1 fh=c528dd1cda99a111 vn="Variante von Win32/ELEX.AR evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir"
sh=6043D1ACD51FD373472020FBB748C405AAF22397 ft=1 fh=4c716dbbae6c21b9 vn="Win32/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect32.dll.vir"
sh=FF431CD8693F4045BD7BD87DBCE54B820F000FC0 ft=1 fh=16c2e1bd3fd6b7e2 vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect64.dll.vir"
sh=5836A5DF3860241F6B69F2292ABCE592A13689B6 ft=1 fh=a3db04555f559ea8 vn="Variante von Win32/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SpAPPSv32.dll.vir"
sh=E97CBDBD7CFED2C58464C1ABF186520022DE5666 ft=1 fh=7a2ea5ecc33ad0e3 vn="Variante von Win64/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SpAPPSv64.dll.vir"
sh=9DC13DB9C123270C2356ED410128E11D5ADF7C6E ft=1 fh=023ab782f0a9b07d vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir"
sh=246DDBC3A2C223A6B9072637D93DC2A2832D097A ft=1 fh=c71c0011b04f613a vn="Win32/Toolbar.Babylon.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\DSearchLink\DSearchLink.exe.vir"
sh=56659F7FF1F1FA7906A77228E315F65F38BCEF73 ft=1 fh=0ff759dfc352fd03 vn="Variante von Win32/ELEX.AD evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir"
sh=A506AEDE7D055BAA580C7657DBAFD498EF0B2E58 ft=1 fh=c71c00117d7abedf vn="Variante von Win32/AdWare.MultiPlug.Y Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\savie on\klD.exe.vir"
sh=C4420C6E94B8CAACCB3811384280D8A93CB0A37D ft=1 fh=25f111c507a31a21 vn="Win32/Toolbar.Conduit.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\users\user\AppData\Roaming\OpenCandy\16EDD084AECD424B91F869D491C9AF0F\sp-downloader.exe.vir"
sh=E12820C3C449E8DF12132666647822B9FE266BA3 ft=1 fh=661cdf041cef5cb3 vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Windows\Microsoft\SystemUpdatekb70007\Installer.dll.vir"
sh=E99D65BD24FAF328D7314F02B98EE8C3BD793B77 ft=1 fh=8661b13c20727ec0 vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Windows\Microsoft\SystemUpdatekb70007\InstallerLibrary.dll.vir"
sh=49DEEED4E6B0E6134D47A582E209511FCBFD2B72 ft=1 fh=14e2fb72d7f3d82c vn="MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Windows\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe.vir"
sh=21A7728CEAC323C137D992A941E5C056FC83EA2F ft=1 fh=2ec8eb5ba41e7380 vn="Win32/InstalleRex.M evtl. unerwünschte Anwendung" ac=I fn="C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\003\t\00\00000000"
sh=168A3F2B9AB8C712B98AC0288AB012784D6224D4 ft=1 fh=c71c001198f425ea vn="Win32/InstalleRex.M evtl. unerwünschte Anwendung" ac=I fn="C:\zoek_backup\C_PROGRA~3_InstallMate\{EA58153E-1EB9-4805-AAEE-569B31BB37C8}\Custom.dll" FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-07-2014 01
Ran by user (administrator) on USER-PC on 25-07-2014 19:19:21
Running from C:\Users\user\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Akamai Technologies, Inc.) C:\Users\user\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\user\AppData\Local\Akamai\netsession_win.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7982112 2009-07-29] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2199840 2014-04-30] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKU\S-1-5-21-850184543-3320550329-2664725720-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20917408 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-850184543-3320550329-2664725720-1000\...\Run: [Akamai NetSession Interface] => C:\Users\user\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: http=127.0.0.1:8118;https=127.0.0.1:8118
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 195.34.133.21 212.186.211.21
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-20]
CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-20]
CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-20]
CHR Extension: (Google-Suche) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-20]
CHR Extension: (Google Wallet) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-20]
CHR Extension: (Google Mail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-20]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-05-18] () [File not signed]
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-04-30] (BitRaider, LLC)
R2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-28] (Hi-Rez Studios) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1617696 2014-04-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21007192 2014-04-30] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-29] ()
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 MWAC; \??\C:\Windows\system32\drivers\ [0 ] () [File not signed]
S3 MWAC; \??\C:\Windows\SysWOW64\drivers\ [0 ] () [File not signed]
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18776 2014-04-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-25 18:20 - 2014-07-25 18:20 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-07-25 18:19 - 2014-07-25 18:19 - 02347384 _____ (ESET) C:\Users\user\Downloads\esetsmartinstaller_deu.exe
2014-07-25 18:01 - 2014-07-25 18:17 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-25 18:00 - 2014-07-25 18:00 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-25 18:00 - 2014-07-25 18:00 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-25 18:00 - 2014-07-25 18:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-25 18:00 - 2014-07-25 18:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-25 18:00 - 2014-07-25 18:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-25 18:00 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-25 18:00 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-25 18:00 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-25 17:49 - 2014-07-25 17:49 - 00024743 _____ () C:\ComboFix.txt
2014-07-25 17:36 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-25 17:36 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-25 17:36 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-25 17:36 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-25 17:36 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-25 17:36 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-25 17:36 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-25 17:36 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-25 17:30 - 2014-07-25 17:49 - 00000000 ____D () C:\Qoobox
2014-07-25 17:30 - 2014-07-25 17:48 - 00000000 ____D () C:\Windows\erdnt
2014-07-25 17:29 - 2014-07-25 17:29 - 05563277 ____R (Swearware) C:\Users\user\Downloads\ComboFix.exe
2014-07-25 17:07 - 2014-07-25 17:07 - 00025457 _____ () C:\Users\user\Desktop\Addition.txt
2014-07-25 17:06 - 2014-07-25 19:19 - 00012137 _____ () C:\Users\user\Desktop\FRST.txt
2014-07-25 16:52 - 2014-07-25 18:14 - 00000000 ____D () C:\Program Files (x86)\MSR
2014-07-25 16:51 - 2014-07-25 16:37 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-07-25 16:38 - 2014-07-25 16:53 - 00026624 _____ () C:\zoek-results.log
2014-07-25 16:37 - 2014-07-25 16:49 - 00000000 ____D () C:\zoek_backup
2014-07-25 16:37 - 2014-07-25 16:37 - 01287168 _____ () C:\Users\user\Downloads\zoek.exe
2014-07-25 16:31 - 2014-07-25 16:32 - 00000000 ____D () C:\AdwCleaner
2014-07-25 16:31 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-25 16:30 - 2014-07-25 16:30 - 01354223 _____ () C:\Users\user\Downloads\adwcleaner_3.216.exe
2014-07-25 16:18 - 2014-07-25 16:19 - 00053570 _____ () C:\Users\user\Downloads\FRST.txt
2014-07-25 16:18 - 2014-07-25 16:19 - 00025490 _____ () C:\Users\user\Downloads\Addition.txt
2014-07-25 16:17 - 2014-07-25 19:19 - 00000000 ____D () C:\FRST
2014-07-25 16:17 - 2014-07-25 16:17 - 02093568 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2014-07-24 18:35 - 2014-07-24 18:35 - 00000000 ____D () C:\Users\Mike\AppData\Local\Apps\2.0
2014-07-24 18:34 - 2014-07-24 18:34 - 00000000 __SHD () C:\Users\Mike\AppData\Local\EmieUserList
2014-07-24 18:34 - 2014-07-24 18:34 - 00000000 __SHD () C:\Users\Mike\AppData\Local\EmieSiteList
2014-07-24 18:33 - 2014-07-24 18:33 - 00000000 ____D () C:\Users\Mike\AppData\Roaming\Macromedia
2014-07-24 18:32 - 2014-07-24 18:58 - 00000000 ____D () C:\Users\Mike
2014-07-24 18:32 - 2014-07-24 18:32 - 00064408 _____ () C:\Users\Mike\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Vorlagen
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Startmenü
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Netzwerkumgebung
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Lokale Einstellungen
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Eigene Dateien
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Druckumgebung
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Documents\Eigene Musik
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Documents\Eigene Bilder
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\AppData\Local\Verlauf
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\AppData\Local\Anwendungsdaten
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Anwendungsdaten
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Roaming\ATI
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Roaming\Adobe
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Local\VirtualStore
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Local\NVIDIA Corporation
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Local\NVIDIA
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Local\Google
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Local\ATI
2014-07-24 18:07 - 2014-07-24 18:07 - 00000000 __SHD () C:\Users\Gast.user-PC\AppData\Local\EmieUserList
2014-07-24 18:07 - 2014-07-24 18:07 - 00000000 __SHD () C:\Users\Gast.user-PC\AppData\Local\EmieSiteList
2014-07-24 18:07 - 2014-07-24 18:07 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Roaming\Macromedia
2014-07-24 18:06 - 2014-07-24 18:06 - 00064408 _____ () C:\Users\Gast.user-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-24 18:06 - 2014-07-24 18:06 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Roaming\ATI
2014-07-24 18:06 - 2014-07-24 18:06 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Roaming\Adobe
2014-07-24 18:06 - 2014-07-24 18:06 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Local\Google
2014-07-24 18:06 - 2014-07-24 18:06 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Local\ATI
2014-07-24 18:05 - 2014-07-24 19:23 - 00000000 ___RD () C:\Users\Gast.user-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-07-24 18:05 - 2014-07-24 19:23 - 00000000 ___RD () C:\Users\Gast.user-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-24 18:05 - 2014-07-24 19:23 - 00000000 ____D () C:\Users\Gast.user-PC
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Vorlagen
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Startmenü
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Netzwerkumgebung
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Lokale Einstellungen
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Eigene Dateien
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Druckumgebung
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Documents\Eigene Musik
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Documents\Eigene Bilder
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\AppData\Local\Verlauf
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\AppData\Local\Anwendungsdaten
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Anwendungsdaten
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Local\VirtualStore
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Local\NVIDIA Corporation
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Local\NVIDIA
2014-07-24 16:26 - 2014-07-24 16:26 - 00000000 ____D () C:\Users\user\AppData\Roaming\Mozilla
2014-07-24 16:26 - 2014-07-24 16:26 - 00000000 ____D () C:\Users\user\AppData\Local\Mozilla
2014-07-24 16:26 - 2014-07-24 16:26 - 00000000 ____D () C:\ProgramData\Mozilla
2014-07-19 02:51 - 2014-07-19 02:51 - 00000003 _____ () C:\Windows\system32\HRUPPROG.TXT
2014-07-10 03:33 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-10 03:33 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-10 03:33 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-10 03:33 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-10 03:33 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-10 03:33 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-10 03:33 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-10 03:33 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-10 03:33 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-10 03:33 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-10 03:33 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-10 03:33 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-10 03:33 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-10 03:33 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-10 03:33 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-10 03:33 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-10 03:33 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-10 03:33 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-10 03:33 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-10 03:33 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-10 03:33 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-10 03:33 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-10 03:33 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-10 03:33 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-10 03:33 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-10 03:33 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-10 03:33 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-10 03:33 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-10 03:33 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-10 03:33 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-10 03:33 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-10 03:33 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-10 03:33 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-10 03:33 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-10 03:33 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-10 03:33 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-10 03:33 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-10 03:33 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-10 03:33 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-10 03:33 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-10 03:33 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-10 03:33 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-10 03:33 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-10 03:33 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-10 03:33 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-10 03:33 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-10 03:33 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-10 03:33 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-10 03:33 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-10 03:33 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-10 03:33 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-10 03:33 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-10 03:33 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-10 03:33 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-10 03:33 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-10 03:33 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-10 03:33 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-10 03:33 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-10 03:33 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-10 03:33 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-10 03:33 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-10 03:33 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-10 03:33 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-10 03:33 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-10 03:33 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-10 03:33 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-10 03:33 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-10 03:33 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-10 03:33 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-10 03:33 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-10 03:33 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-10 03:33 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-10 03:33 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-10 03:33 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-10 03:33 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-10 03:33 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-10 03:32 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-10 03:32 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-10 03:32 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-10 03:32 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-10 03:32 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-09 21:20 - 2014-07-24 18:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TERA
2014-07-09 21:20 - 2014-07-09 21:20 - 00001044 _____ () C:\Users\user\Desktop\TERA.lnk
2014-07-09 21:20 - 2014-07-09 21:20 - 00000000 ____D () C:\Users\user\AppData\Roaming\TERA
2014-07-09 21:20 - 2014-07-09 21:20 - 00000000 ____D () C:\Program Files (x86)\TERA
2014-07-06 14:58 - 2014-07-24 18:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
2014-07-06 14:58 - 2014-07-24 18:56 - 00000000 ____D () C:\Users\Public\Documents\Tunngle
2014-07-06 14:58 - 2014-07-24 18:56 - 00000000 ____D () C:\Program Files (x86)\Tunngle
2014-07-06 14:58 - 2009-09-16 07:02 - 00031232 _____ (Tunngle.net) C:\Windows\system32\Drivers\tap0901t.sys
2014-07-06 14:10 - 2014-07-06 14:14 - 00000000 ____D () C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-07-06 14:09 - 2014-07-24 18:57 - 00000000 ____D () C:\Users\user\Downloads\Warcraft 3
2014-07-06 12:30 - 2014-07-06 12:30 - 00000000 ____D () C:\Users\user\Documents\MGR
2014-07-06 12:29 - 2014-07-06 12:29 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-07-06 12:22 - 2014-07-06 14:01 - 1207728765 _____ () C:\Users\user\Downloads\Warcraft 3.rar
2014-07-03 08:35 - 2014-07-24 18:57 - 00000000 ____D () C:\Users\user\Desktop\Desmumu
2014-07-03 08:06 - 2014-07-03 08:06 - 00000000 ____D () C:\Users\user\Desktop\pokemon
2014-07-01 19:37 - 2014-07-01 19:37 - 00000000 ____D () C:\Users\user\AppData\Local\mslug3
2014-06-30 04:44 - 2014-06-30 04:44 - 00000000 ____D () C:\Users\user\AppData\Local\Aeria Games
2014-06-30 04:43 - 2014-06-30 04:43 - 00000000 ____D () C:\ProgramData\Aeria Games
2014-06-30 04:42 - 2014-07-24 23:30 - 00000000 ____D () C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeriaGames
2014-06-30 04:40 - 2014-06-30 04:40 - 00000000 ____D () C:\Users\user\AppData\Roaming\Aeria Games & Entertainment
2014-06-30 04:32 - 2014-07-24 23:30 - 00000000 ____D () C:\AeriaGames
2014-06-30 04:32 - 2014-07-24 18:56 - 00000000 ____D () C:\Users\user\AppData\Local\Akamai
2014-06-29 05:07 - 2014-06-29 05:07 - 00000000 ____D () C:\Users\user\Documents\Telltale Games
2014-06-27 04:17 - 2014-06-27 04:18 - 00000000 ____D () C:\Users\user\Documents\Orcs Must Die
2014-06-25 14:26 - 2014-06-25 14:26 - 00000000 ____D () C:\Users\user\AppData\Local\4A Games
2014-06-25 14:23 - 2014-06-25 14:23 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-25 19:19 - 2014-07-25 17:06 - 00012137 _____ () C:\Users\user\Desktop\FRST.txt
2014-07-25 19:19 - 2014-07-25 16:17 - 00000000 ____D () C:\FRST
2014-07-25 19:17 - 2014-03-20 17:20 - 00000000 ____D () C:\Users\user\AppData\Roaming\Skype
2014-07-25 18:59 - 2014-03-20 16:31 - 01716795 _____ () C:\Windows\WindowsUpdate.log
2014-07-25 18:34 - 2014-04-28 15:20 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-25 18:24 - 2009-07-14 06:45 - 00022096 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-25 18:24 - 2009-07-14 06:45 - 00022096 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-25 18:20 - 2014-07-25 18:20 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-07-25 18:19 - 2014-07-25 18:19 - 02347384 _____ (ESET) C:\Users\user\Downloads\esetsmartinstaller_deu.exe
2014-07-25 18:17 - 2014-07-25 18:01 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-25 18:16 - 2014-06-08 22:26 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-25 18:16 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-25 18:16 - 2009-07-14 06:51 - 00050550 _____ () C:\Windows\setupact.log
2014-07-25 18:15 - 2010-11-21 05:47 - 00038194 _____ () C:\Windows\PFRO.log
2014-07-25 18:14 - 2014-07-25 16:52 - 00000000 ____D () C:\Program Files (x86)\MSR
2014-07-25 18:00 - 2014-07-25 18:00 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-25 18:00 - 2014-07-25 18:00 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-25 18:00 - 2014-07-25 18:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-25 18:00 - 2014-07-25 18:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-25 18:00 - 2014-07-25 18:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-25 17:49 - 2014-07-25 17:49 - 00024743 _____ () C:\ComboFix.txt
2014-07-25 17:49 - 2014-07-25 17:30 - 00000000 ____D () C:\Qoobox
2014-07-25 17:49 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-07-25 17:48 - 2014-07-25 17:30 - 00000000 ____D () C:\Windows\erdnt
2014-07-25 17:45 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-25 17:43 - 2009-07-14 04:34 - 56098816 _____ () C:\Windows\system32\config\software.bak
2014-07-25 17:43 - 2009-07-14 04:34 - 20185088 _____ () C:\Windows\system32\config\system.bak
2014-07-25 17:43 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\security.bak
2014-07-25 17:43 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\sam.bak
2014-07-25 17:43 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\default.bak
2014-07-25 17:29 - 2014-07-25 17:29 - 05563277 ____R (Swearware) C:\Users\user\Downloads\ComboFix.exe
2014-07-25 17:07 - 2014-07-25 17:07 - 00025457 _____ () C:\Users\user\Desktop\Addition.txt
2014-07-25 17:01 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-07-25 16:53 - 2014-07-25 16:38 - 00026624 _____ () C:\zoek-results.log
2014-07-25 16:49 - 2014-07-25 16:37 - 00000000 ____D () C:\zoek_backup
2014-07-25 16:37 - 2014-07-25 16:51 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-07-25 16:37 - 2014-07-25 16:37 - 01287168 _____ () C:\Users\user\Downloads\zoek.exe
2014-07-25 16:32 - 2014-07-25 16:31 - 00000000 ____D () C:\AdwCleaner
2014-07-25 16:30 - 2014-07-25 16:30 - 01354223 _____ () C:\Users\user\Downloads\adwcleaner_3.216.exe
2014-07-25 16:19 - 2014-07-25 16:18 - 00053570 _____ () C:\Users\user\Downloads\FRST.txt
2014-07-25 16:19 - 2014-07-25 16:18 - 00025490 _____ () C:\Users\user\Downloads\Addition.txt
2014-07-25 16:17 - 2014-07-25 16:17 - 02093568 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2014-07-24 23:30 - 2014-06-30 04:42 - 00000000 ____D () C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeriaGames
2014-07-24 23:30 - 2014-06-30 04:32 - 00000000 ____D () C:\AeriaGames
2014-07-24 23:28 - 2014-04-28 15:22 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-07-24 22:56 - 2014-04-28 15:17 - 00000000 ____D () C:\Users\user\AppData\Roaming\TS3Client
2014-07-24 19:23 - 2014-07-24 18:05 - 00000000 ___RD () C:\Users\Gast.user-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-07-24 19:23 - 2014-07-24 18:05 - 00000000 ___RD () C:\Users\Gast.user-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-24 19:23 - 2014-07-24 18:05 - 00000000 ____D () C:\Users\Gast.user-PC
2014-07-24 18:58 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike
2014-07-24 18:58 - 2014-07-06 14:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
2014-07-24 18:58 - 2014-03-20 16:54 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1
2014-07-24 18:58 - 2014-03-20 16:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-07-24 18:57 - 2014-07-06 14:09 - 00000000 ____D () C:\Users\user\Downloads\Warcraft 3
2014-07-24 18:57 - 2014-07-03 08:35 - 00000000 ____D () C:\Users\user\Desktop\Desmumu
2014-07-24 18:57 - 2014-06-09 16:42 - 00000000 ____D () C:\Users\user\Downloads\Minecraft
2014-07-24 18:57 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-07-24 18:57 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-07-24 18:57 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-24 18:57 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-07-24 18:56 - 2014-07-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TERA
2014-07-24 18:56 - 2014-07-06 14:58 - 00000000 ____D () C:\Users\Public\Documents\Tunngle
2014-07-24 18:56 - 2014-07-06 14:58 - 00000000 ____D () C:\Program Files (x86)\Tunngle
2014-07-24 18:56 - 2014-06-30 04:32 - 00000000 ____D () C:\Users\user\AppData\Local\Akamai
2014-07-24 18:56 - 2014-06-23 02:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-24 18:56 - 2014-06-21 22:35 - 00000000 ____D () C:\Program Files (x86)\OpenAL
2014-07-24 18:56 - 2014-06-19 17:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-07-24 18:56 - 2014-06-08 22:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-07-24 18:56 - 2014-06-08 22:31 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-07-24 18:56 - 2014-06-08 22:28 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-07-24 18:56 - 2014-05-29 02:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
2014-07-24 18:56 - 2014-05-29 02:05 - 00000000 ____D () C:\Program Files (x86)\Hi-Rez Studios
2014-07-24 18:56 - 2014-05-27 22:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2014-07-24 18:56 - 2014-05-17 00:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2014-07-24 18:56 - 2014-05-07 17:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-07-24 18:56 - 2014-04-30 19:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2014-07-24 18:56 - 2014-04-30 17:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2014-07-24 18:56 - 2014-04-28 15:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-07-24 18:56 - 2014-03-20 17:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-07-24 18:56 - 2014-03-20 16:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-07-24 18:56 - 2014-03-20 16:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-07-24 18:56 - 2014-03-20 16:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-24 18:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-07-24 18:55 - 2014-06-08 22:32 - 00000000 ____D () C:\Users\user\AppData\Local\NVIDIA
2014-07-24 18:52 - 2014-06-23 02:25 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-24 18:52 - 2014-06-08 22:30 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-07-24 18:35 - 2014-07-24 18:35 - 00000000 ____D () C:\Users\Mike\AppData\Local\Apps\2.0
2014-07-24 18:34 - 2014-07-24 18:34 - 00000000 __SHD () C:\Users\Mike\AppData\Local\EmieUserList
2014-07-24 18:34 - 2014-07-24 18:34 - 00000000 __SHD () C:\Users\Mike\AppData\Local\EmieSiteList
2014-07-24 18:33 - 2014-07-24 18:33 - 00000000 ____D () C:\Users\Mike\AppData\Roaming\Macromedia
2014-07-24 18:32 - 2014-07-24 18:32 - 00064408 _____ () C:\Users\Mike\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Vorlagen
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Startmenü
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Netzwerkumgebung
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Lokale Einstellungen
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Eigene Dateien
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Druckumgebung
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Documents\Eigene Musik
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Documents\Eigene Bilder
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\AppData\Local\Verlauf
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\AppData\Local\Anwendungsdaten
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 _SHDL () C:\Users\Mike\Anwendungsdaten
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Roaming\ATI
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Roaming\Adobe
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Local\VirtualStore
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Local\NVIDIA Corporation
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Local\NVIDIA
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Local\Google
2014-07-24 18:32 - 2014-07-24 18:32 - 00000000 ____D () C:\Users\Mike\AppData\Local\ATI
2014-07-24 18:07 - 2014-07-24 18:07 - 00000000 __SHD () C:\Users\Gast.user-PC\AppData\Local\EmieUserList
2014-07-24 18:07 - 2014-07-24 18:07 - 00000000 __SHD () C:\Users\Gast.user-PC\AppData\Local\EmieSiteList
2014-07-24 18:07 - 2014-07-24 18:07 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Roaming\Macromedia
2014-07-24 18:06 - 2014-07-24 18:06 - 00064408 _____ () C:\Users\Gast.user-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-24 18:06 - 2014-07-24 18:06 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Roaming\ATI
2014-07-24 18:06 - 2014-07-24 18:06 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Roaming\Adobe
2014-07-24 18:06 - 2014-07-24 18:06 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Local\Google
2014-07-24 18:06 - 2014-07-24 18:06 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Local\ATI
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Vorlagen
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Startmenü
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Netzwerkumgebung
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Lokale Einstellungen
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Eigene Dateien
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Druckumgebung
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Documents\Eigene Musik
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Documents\Eigene Bilder
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\AppData\Local\Verlauf
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\AppData\Local\Anwendungsdaten
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 _SHDL () C:\Users\Gast.user-PC\Anwendungsdaten
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Local\VirtualStore
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Local\NVIDIA Corporation
2014-07-24 18:05 - 2014-07-24 18:05 - 00000000 ____D () C:\Users\Gast.user-PC\AppData\Local\NVIDIA
2014-07-24 17:55 - 2014-06-08 18:37 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-24 17:09 - 2014-03-20 16:33 - 00000000 ____D () C:\Recovery
2014-07-24 17:05 - 2014-03-20 17:20 - 00064408 _____ () C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-24 17:03 - 2014-06-08 22:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-24 16:26 - 2014-07-24 16:26 - 00000000 ____D () C:\Users\user\AppData\Roaming\Mozilla
2014-07-24 16:26 - 2014-07-24 16:26 - 00000000 ____D () C:\Users\user\AppData\Local\Mozilla
2014-07-24 16:26 - 2014-07-24 16:26 - 00000000 ____D () C:\ProgramData\Mozilla
2014-07-22 22:02 - 2014-05-27 22:46 - 00000000 ____D () C:\Users\user\AppData\Local\PMB Files
2014-07-19 02:51 - 2014-07-19 02:51 - 00000003 _____ () C:\Windows\system32\HRUPPROG.TXT
2014-07-12 13:20 - 2014-04-28 15:48 - 00185593 _____ () C:\Windows\DirectX.log
2014-07-11 09:31 - 2009-07-14 06:45 - 00294776 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-11 00:54 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-11 00:54 - 2010-11-21 09:01 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-11 00:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-11 00:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-10 21:45 - 2014-06-05 21:48 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-10 21:43 - 2014-06-09 03:00 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-10 00:02 - 2014-06-09 17:06 - 00000000 ____D () C:\Users\user\AppData\Roaming\Tunngle
2014-07-09 21:20 - 2014-07-09 21:20 - 00001044 _____ () C:\Users\user\Desktop\TERA.lnk
2014-07-09 21:20 - 2014-07-09 21:20 - 00000000 ____D () C:\Users\user\AppData\Roaming\TERA
2014-07-09 21:20 - 2014-07-09 21:20 - 00000000 ____D () C:\Program Files (x86)\TERA
2014-07-09 12:34 - 2014-04-28 15:20 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 12:34 - 2014-04-28 15:20 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-09 12:34 - 2014-04-28 15:20 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-06 14:14 - 2014-07-06 14:10 - 00000000 ____D () C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-07-06 14:01 - 2014-07-06 12:22 - 1207728765 _____ () C:\Users\user\Downloads\Warcraft 3.rar
2014-07-06 12:30 - 2014-07-06 12:30 - 00000000 ____D () C:\Users\user\Documents\MGR
2014-07-06 12:29 - 2014-07-06 12:29 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-07-05 18:01 - 2014-05-27 22:46 - 00000000 ____D () C:\ProgramData\PMB Files
2014-07-03 08:06 - 2014-07-03 08:06 - 00000000 ____D () C:\Users\user\Desktop\pokemon
2014-07-02 16:18 - 2014-04-30 19:47 - 00000000 ____D () C:\ProgramData\BitRaider
2014-07-02 04:37 - 2014-05-11 03:32 - 00000145 _____ () C:\Users\user\Desktop\arma 3 royal.txt
2014-07-01 19:37 - 2014-07-01 19:37 - 00000000 ____D () C:\Users\user\AppData\Local\mslug3
2014-06-30 04:44 - 2014-06-30 04:44 - 00000000 ____D () C:\Users\user\AppData\Local\Aeria Games
2014-06-30 04:43 - 2014-06-30 04:43 - 00000000 ____D () C:\ProgramData\Aeria Games
2014-06-30 04:40 - 2014-06-30 04:40 - 00000000 ____D () C:\Users\user\AppData\Roaming\Aeria Games & Entertainment
2014-06-30 04:09 - 2014-07-10 03:33 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-30 04:04 - 2014-07-10 03:33 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-29 05:07 - 2014-06-29 05:07 - 00000000 ____D () C:\Users\user\Documents\Telltale Games
2014-06-27 04:18 - 2014-06-27 04:17 - 00000000 ____D () C:\Users\user\Documents\Orcs Must Die
2014-06-25 14:35 - 2014-06-22 00:54 - 00000000 ____D () C:\Users\user\Documents\4a games
2014-06-25 14:26 - 2014-06-25 14:26 - 00000000 ____D () C:\Users\user\AppData\Local\4A Games
2014-06-25 14:23 - 2014-06-25 14:23 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-06-25 12:27 - 2010-11-21 08:50 - 00699092 _____ () C:\Windows\system32\perfh007.dat
2014-06-25 12:27 - 2010-11-21 08:50 - 00149232 _____ () C:\Windows\system32\perfc007.dat
2014-06-25 12:27 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-08 13:30
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-07-2014 01
Ran by user at 2014-07-25 19:19:54
Running from C:\Users\user\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc)
AMD Accelerated Video Transcoding (Version: 13.20.100.31206 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden
AMD Catalyst Install Manager (HKLM\...\{308051DA-0048-7A07-FE8B-9B6EC119A9E8}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Media Foundation Decoders (Version: 1.0.81206.1620 - Advanced Micro Devices, Inc.) Hidden
AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden
Arma 3 (HKLM-x32\...\Steam App 107410) (Version: - Bohemia Interactive)
BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - )
BitRaider Web Client (HKLM-x32\...\BitRaider Web Client) (Version: 1.1.9.9 - BitRaider, LLC)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve)
DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive)
Dead Island (HKLM-x32\...\Steam App 91310) (Version: - Techland)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
Free YouTube to MP3 Converter version 3.12.34.430 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.34.430 - DVDVideoSoft Ltd.)
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
Google Chrome (HKLM-x32\...\{FBD50733-2ABE-3D23-88B4-7B0C0A0ADDA0}) (Version: 65.181.32922 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
Infestation: Survivor Stories (HKLM-x32\...\Steam App 226700) (Version: - Hammerpoint Interactive)
Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217060FF}) (Version: 7.0.600 - Oracle)
Killing Floor (HKLM-x32\...\Steam App 1250) (Version: - Tripwire Interactive)
Killing Floor Mod: Defence Alliance 2 (HKLM-x32\...\Steam App 35420) (Version: - Defence Alliance Team)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.5 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 337.88 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 337.88 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.0.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.0.1 - NVIDIA Corporation)
NVIDIA Grafiktreiber 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.154.1168 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA ShadowPlay 12.4.67 (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6514 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 337.88 (Version: 337.88 - NVIDIA Corporation) Hidden
NVIDIA Update 12.4.67 (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.23 (Version: 1.2.23 - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
PlanetSide 2 (HKLM-x32\...\Steam App 218230) (Version: - Sony Online Entertainment)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5904 - Realtek Semiconductor Corp.)
SHIELD Streaming (Version: 2.1.108 - NVIDIA Corporation) Hidden
Skype™ 6.14 (HKLM-x32\...\{1845470B-EB14-4ABC-835B-E36C693DC07D}) (Version: 6.14.104 - Skype Technologies S.A.)
Smite (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 1.0.2189.2 - Hi-Rez Studios)
Sniper Elite V2 (HKLM-x32\...\Steam App 63380) (Version: - Rebellion)
Star Wars - Battlefront II (HKLM-x32\...\Steam App 6060) (Version: - Pandemic Studios)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version: 7.0.0.40 - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
System Update kb70007 (x32 Version: 1.0.0 - MSR) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
TERA (HKLM-x32\...\{A2F166A0-F031-4E27-A057-C69733219434}_is1) (Version: 28 - Gameforge Productions GmbH)
Tunngle beta (HKLM-x32\...\Tunngle beta_is1) (Version: - Tunngle.net GmbH)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
18-07-2014 13:18:52 Windows Update
22-07-2014 13:29:00 Windows Update
24-07-2014 13:26:34 Removed Aeria Ignite
24-07-2014 14:27:59 Installed Java 7 Update 65
24-07-2014 14:49:29 DirectX wurde installiert
24-07-2014 14:59:21 Wiederherstellungsvorgang
24-07-2014 15:26:45 Windows Update
24-07-2014 15:54:29 Installed Java 7 Update 65
24-07-2014 16:36:15 Windows Update
24-07-2014 16:38:04 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
24-07-2014 16:49:21 Wiederherstellungsvorgang
24-07-2014 17:08:58 Windows Update
24-07-2014 21:29:42 Removed Aeria Ignite
25-07-2014 14:38:43 zoek.exe restore point
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2014-07-25 17:45 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {3A49BE3B-C0E9-4070-B4AB-A78DF69C6026} - System32\Tasks\{77245E9B-B20B-4898-B5D7-D462B0BD13D5} => C:\Breaking Point\BreakingPoint.exe [2014-05-17] (Alderon Games)
Task: {73EC966E-3D69-4FD3-BCBD-55EAF1C596CB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2014-06-08 22:31 - 2014-05-20 03:25 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-04-29 10:23 - 2014-04-29 10:23 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/25/2014 07:18:49 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (07/25/2014 06:23:59 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (07/25/2014 06:23:57 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (07/25/2014 06:23:57 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (07/25/2014 06:23:43 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (07/25/2014 06:20:05 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (07/25/2014 06:19:43 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (07/25/2014 06:17:41 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/25/2014 05:45:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/25/2014 05:05:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (07/25/2014 06:18:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (07/25/2014 05:46:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (07/25/2014 05:43:04 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Error: (07/25/2014 05:42:56 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (07/25/2014 05:42:50 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (07/25/2014 05:42:31 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.
Error: (07/25/2014 05:40:42 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (07/25/2014 05:37:51 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "SystemUpdatekb70007" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (07/25/2014 05:06:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (07/25/2014 04:54:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Microsoft Office Sessions:
=========================
Error: (07/25/2014 07:18:49 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe
Error: (07/25/2014 06:23:59 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_deu.exe
Error: (07/25/2014 06:23:57 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_deu.exe
Error: (07/25/2014 06:23:57 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_deu.exe
Error: (07/25/2014 06:23:43 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_deu.exe
Error: (07/25/2014 06:20:05 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_deu.exe
Error: (07/25/2014 06:19:43 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\user\Downloads\esetsmartinstaller_deu.exe
Error: (07/25/2014 06:17:41 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/25/2014 05:45:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/25/2014 05:05:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
CodeIntegrity Errors:
===================================
Date: 2014-07-25 17:42:31.528
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-07-25 17:42:31.488
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 28%
Total physical RAM: 8191.05 MB
Available physical RAM: 5858.87 MB
Total Pagefile: 16380.29 MB
Available Pagefile: 13675.47 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:931.41 GB) (Free:668.09 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: B99ACCF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Problem ist weg und keine anderen Problem mehr ich danke dir vielmals |