Ecatarina | 29.07.2014 13:58 | Additons 3 Code:
==================== Restore Points =========================
08-07-2014 16:31:15 Geplanter Prüfpunkt
18-07-2014 18:04:07 Geplanter Prüfpunkt
24-07-2014 16:30:46 Installed Intel(R) Network Connections.
26-07-2014 11:28:33 Installed Call of Duty(R) 2 Patch 1.3
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {053EF6E7-16DE-4258-BEE3-1DADBAC73A09} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {0A1C816A-29A0-4631-A445-F9E23DB5C150} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-05-20] (Microsoft Corporation)
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {25DDAD78-0024-42BE-84D6-68D9ED3179EA} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-07-10] (Microsoft Corporation)
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {3BBB4225-153D-4E1B-82D6-3714BA825F2D} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {5A8EF8A8-E74C-48A8-A23C-BF0D8AC653DD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-15] (Google Inc.)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6D96ACA0-E4D7-455C-A71D-34292EF187B6} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {6E9AF6F5-9DDE-4961-9EA3-9FC509CCE79F} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-06-19] (Microsoft Corporation)
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {7B103321-BA92-47CE-B7B7-C526AAF72C5E} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {7B6DCCB1-1200-486F-8019-AA0F21D9EF2F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-15] (Google Inc.)
Task: {7E714BC0-FE4C-4083-AE8B-070D679768E4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-05-20] (Microsoft Corporation)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {8FA21A80-209D-42A7-90AA-3C114A474F1F} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D599CDDB-F88D-47E3-AD2C-E2A1C3106889} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated)
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DE2F13FB-3FB3-4C41-9B58-57DD87950128} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {E61DD97C-0F2B-4503-84A9-F23630F9ABBB} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {FB6723D9-5065-4DA6-992F-DA066F1646D8} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-07-25 15:45 - 2014-06-06 15:11 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\txmlutil.dll
2014-07-25 15:45 - 2014-06-30 13:26 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\UI\accessl.ui
2014-07-25 15:45 - 2012-10-29 15:22 - 00152816 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdfwcore.dll
2014-05-28 16:11 - 2014-05-20 03:25 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-05-30 19:05 - 2013-05-28 17:58 - 00454656 _____ () C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\IOMonitorSrv.exe
2014-05-28 17:23 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2013-08-12 19:06 - 2013-08-12 19:06 - 00198120 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2013-08-12 19:06 - 2013-08-12 19:06 - 00054760 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2013-08-12 19:06 - 2013-08-12 19:06 - 00034792 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll
2014-05-29 16:10 - 2014-06-14 12:41 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-07-25 15:45 - 2013-03-25 16:16 - 01117920 _____ () C:\Program Files\Bitdefender\Bitdefender SafeBox\System.Data.SQLite.dll
2014-05-28 16:50 - 2014-05-28 16:51 - 00183296 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\ErrorReporting.dll
2014-05-28 16:45 - 2008-07-11 15:04 - 00200704 ____N () C:\Windows\SysWOW64\HsMgr.exe
2014-05-28 16:45 - 2008-07-11 15:03 - 00282112 ____N () C:\Windows\System\HsMgr64.exe
2014-02-11 20:21 - 2014-02-11 20:21 - 00860160 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2014-02-11 20:22 - 2014-02-11 20:22 - 01043968 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-02-11 20:21 - 2014-02-11 20:21 - 00052736 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2014-02-11 20:22 - 2014-02-11 20:22 - 00236032 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2014-05-31 00:52 - 2009-11-10 18:05 - 00248320 _____ () C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
2014-05-31 00:52 - 2009-11-04 16:28 - 00143360 _____ () C:\Program Files (x86)\Razer\Lachesis\razertra.exe
2014-05-28 16:45 - 2012-06-06 09:56 - 00143360 ____N () C:\Program Files\ASUS Xonar DGX Audio\Customapp\VmixP8.dll
2014-06-11 16:56 - 2014-06-11 16:56 - 00316584 _____ () C:\Program Files\Microsoft Office 15\root\office15\AppVIsvStream32.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Windows\SysWOW64\pbsvc.exe:BDU
AlternateDataStreams: C:\Users\*\SkyDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\StartupFolder: => "Server4PC.lnk"
HKLM\...\StartupApproved\Run32: => "SFAUpdater"
HKLM\...\StartupApproved\Run32: => "PowerDVD13Agent"
HKCU\...\StartupApproved\StartupFolder: => "Samsung Magician.lnk"
HKCU\...\StartupApproved\Run: => "Desura"
HKCU\...\StartupApproved\Run: => "Spotify Web Helper"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/29/2014 02:31:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: FRST64.exe, Version: 26.7.2014.0, Zeitstempel: 0x53d35ae0
Name des fehlerhaften Moduls: FRST64.exe, Version: 26.7.2014.0, Zeitstempel: 0x53d35ae0
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000047cf5
ID des fehlerhaften Prozesses: 0x15d0
Startzeit der fehlerhaften Anwendung: 0xFRST64.exe0
Pfad der fehlerhaften Anwendung: FRST64.exe1
Pfad des fehlerhaften Moduls: FRST64.exe2
Berichtskennung: FRST64.exe3
Vollständiger Name des fehlerhaften Pakets: FRST64.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: FRST64.exe5
Error: (07/28/2014 08:02:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Awesomenauts.exe, Version: 0.0.0.0, Zeitstempel: 0x53d248bb
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17114, Zeitstempel: 0x53648f36
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0001ec81
ID des fehlerhaften Prozesses: 0x119c
Startzeit der fehlerhaften Anwendung: 0xAwesomenauts.exe0
Pfad der fehlerhaften Anwendung: Awesomenauts.exe1
Pfad des fehlerhaften Moduls: Awesomenauts.exe2
Berichtskennung: Awesomenauts.exe3
Vollständiger Name des fehlerhaften Pakets: Awesomenauts.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Awesomenauts.exe5
Error: (07/27/2014 01:29:43 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: WmiApRplC:\Windows\system32\wbem\wmiaprpl.dll8
Error: (07/26/2014 06:39:04 PM) (Source: MsiInstaller) (EventID: 11316) (User: *)
Description: Produkt: NVIDIA PhysX -- Fehler 1316. Beim Lesen der Datei D:\Program Files (x86)\Steam\steamapps\common\nosgoth\_CommonRedist\PhysX\9.12.1031\PhysX_9.12.1031_SystemSoftware.msi ist ein Netzwerkfehler aufgetreten
Error: (07/26/2014 03:09:54 PM) (Source: MsiInstaller) (EventID: 11316) (User: *)
Description: Produkt: NVIDIA PhysX -- Fehler 1316. Beim Lesen der Datei D:\Program Files (x86)\Steam\steamapps\common\nosgoth\_CommonRedist\PhysX\9.12.1031\PhysX_9.12.1031_SystemSoftware.msi ist ein Netzwerkfehler aufgetreten
Error: (07/26/2014 01:28:34 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.
System Error:
Zugriff verweigert
.
Error: (07/25/2014 10:44:35 PM) (Source: MsiInstaller) (EventID: 11316) (User: *)
Description: Produkt: NVIDIA PhysX -- Fehler 1316. Beim Lesen der Datei D:\Program Files (x86)\Steam\steamapps\common\nosgoth\_CommonRedist\PhysX\9.12.1031\PhysX_9.12.1031_SystemSoftware.msi ist ein Netzwerkfehler aufgetreten
Error: (07/25/2014 03:26:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: LogonUI.exe, Version: 6.3.9600.16384, Zeitstempel: 0x5215f6c5
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17114, Zeitstempel: 0x53649e73
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000004d89f
ID des fehlerhaften Prozesses: 0x50
Startzeit der fehlerhaften Anwendung: 0xLogonUI.exe0
Pfad der fehlerhaften Anwendung: LogonUI.exe1
Pfad des fehlerhaften Moduls: LogonUI.exe2
Berichtskennung: LogonUI.exe3
Vollständiger Name des fehlerhaften Pakets: LogonUI.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: LogonUI.exe5
System errors:
=============
Error: (07/27/2014 02:17:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "RTCore64" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (07/27/2014 02:17:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "RTCore64" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (07/27/2014 02:16:39 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "RTCore64" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (07/27/2014 02:16:39 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "RTCore64" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (07/27/2014 02:16:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "RTCore64" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (07/27/2014 02:16:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "RTCore64" wurde aufgrund folgenden Fehlers nicht gestartet:
%%577
Error: (07/27/2014 02:10:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "7ByteIo" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (07/27/2014 02:10:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "7ByteIo" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (07/27/2014 02:10:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "7ByteIo" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (07/27/2014 02:10:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "7ByteIo" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Microsoft Office Sessions:
=========================
Error: (07/29/2014 02:31:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: FRST64.exe26.7.2014.053d35ae0FRST64.exe26.7.2014.053d35ae0c00000050000000000047cf515d001cfab29127dc79fF:\*\Deskop\trojaner board\FRST64.exeF:\*\Deskop\trojaner board\FRST64.exe5557a74e-171c-11e4-829e-0008c9e1a702
Error: (07/28/2014 08:02:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Awesomenauts.exe0.0.0.053d248bbntdll.dll6.3.9600.1711453648f36c00000050001ec81119c01cfaa8e23f9f14bC:\Steam\steamapps\common\Awesomenauts\Awesomenauts.exeC:\Windows\SYSTEM32\ntdll.dll62ec0fc9-1681-11e4-829d-0008c9e1a702
Error: (07/27/2014 01:29:43 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: WmiApRplC:\Windows\system32\wbem\wmiaprpl.dll8
Error: (07/26/2014 06:39:04 PM) (Source: MsiInstaller) (EventID: 11316) (User: *)
Description: Produkt: NVIDIA PhysX -- Fehler 1316. Beim Lesen der Datei D:\Program Files (x86)\Steam\steamapps\common\nosgoth\_CommonRedist\PhysX\9.12.1031\PhysX_9.12.1031_SystemSoftware.msi ist ein Netzwerkfehler aufgetreten(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (07/26/2014 03:09:54 PM) (Source: MsiInstaller) (EventID: 11316) (User: *)
Description: Produkt: NVIDIA PhysX -- Fehler 1316. Beim Lesen der Datei D:\Program Files (x86)\Steam\steamapps\common\nosgoth\_CommonRedist\PhysX\9.12.1031\PhysX_9.12.1031_SystemSoftware.msi ist ein Netzwerkfehler aufgetreten(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (07/26/2014 01:28:34 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.
System Error:
Zugriff verweigert
Error: (07/25/2014 10:44:35 PM) (Source: MsiInstaller) (EventID: 11316) (User: *)
Description: Produkt: NVIDIA PhysX -- Fehler 1316. Beim Lesen der Datei D:\Program Files (x86)\Steam\steamapps\common\nosgoth\_CommonRedist\PhysX\9.12.1031\PhysX_9.12.1031_SystemSoftware.msi ist ein Netzwerkfehler aufgetreten(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (07/25/2014 03:26:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: LogonUI.exe6.3.9600.163845215f6c5ntdll.dll6.3.9600.1711453649e73c0000005000000000004d89f5001cfa7805188d3afC:\Windows\system32\LogonUI.exeC:\Windows\SYSTEM32\ntdll.dll37555c27-13ff-11e4-8295-0008c9e1a702
CodeIntegrity Errors:
===================================
Date: 2014-07-27 14:17:31.799
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\RightMark Memory Analyzer\RTCore64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-07-27 14:17:31.757
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\RightMark Memory Analyzer\RTCore64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-07-27 14:16:39.589
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\RightMark Memory Analyzer\RTCore64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-07-27 14:16:39.547
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\RightMark Memory Analyzer\RTCore64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-07-27 14:16:17.647
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\RightMark Memory Analyzer\RTCore64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-07-27 14:16:17.605
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\RightMark Memory Analyzer\RTCore64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-05-28 21:35:37.536
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-05-28 21:35:37.450
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-05-28 21:35:37.255
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-05-28 21:35:37.167
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Percentage of memory in use: 29%
Total physical RAM: 8111.09 MB
Available physical RAM: 5720.84 MB
Total Pagefile: 16303.09 MB
Available Pagefile: 13948.45 MB
Total Virtual: 131072 MB
Available Virtual: 131071.82 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:100.09 GB) (Free:34.47 GB) NTFS
Drive d: (Daten+Steam) (Fixed) (Total:1171.9 GB) (Free:64.81 GB) NTFS
Drive e: () (Fixed) (Total:341.82 GB) (Free:85.17 GB) NTFS
Drive f: (Volume) (Fixed) (Total:349.17 GB) (Free:231.02 GB) NTFS
Drive g: (IRM_CCSA_X64FRE_DE-DE_DV5) (CDROM) (Total:3.68 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 112 GB) (Disk ID: D1F38FD9)
Partition: GPT Partition Type.
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
==================== End Of Log ============================ GEMER Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-07-29 14:49:58
Windows 6.3.9600 x64 \Device\Harddisk0\DR0 -> \Device\0000002a Samsung_SSD_840_EVO_120GB rev.EXT0BB6Q 111,79GB
Running: i1rywqnf.exe; Driver: C:\Users\Arno\AppData\Local\Temp\kglyipow.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\system32\ntoskrnl.exe!NtCallbackReturn + 960 fffff80260fd2d00 4 bytes [C0, 52, AC, FF]
.text C:\Windows\system32\ntoskrnl.exe!NtCallbackReturn + 965 fffff80260fd2d05 87 bytes [AD, 4E, 03, 40, 6A, A5, 04, ...]
---- User code sections - GMER 2.1 ----
.text C:\Windows\Explorer.EXE[1284] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 714 00007ffb73fd154a 4 bytes [FD, 73, FB, 7F]
.text C:\Windows\Explorer.EXE[1284] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 722 00007ffb73fd1552 4 bytes [FD, 73, FB, 7F]
.text C:\Windows\Explorer.EXE[1284] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 98 00007ffb73fd162a 4 bytes [FD, 73, FB, 7F]
.text C:\Windows\Explorer.EXE[1284] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 122 00007ffb73fd1642 4 bytes [FD, 73, FB, 7F]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [512:520] fffff96000841b90
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- |